From 01fb88d9deda6f05be8327c76372bbab86577403 Mon Sep 17 00:00:00 2001 From: Chuck <33324927+ChuckBuilds@users.noreply.github.com> Date: Tue, 29 Sep 2026 19:37:29 -0400 Subject: [PATCH] refactor(web): build the logged origin with urlunsplit, not an f-string Semgrep's directly-returned-format-string rule read the helper as a Flask route returning a formatted string. Same output. Co-Authored-By: Claude Opus 5.5 --- web_interface/origin_guard.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/web_interface/origin_guard.py b/web_interface/origin_guard.py index 2eeeb6e9..e12f27f5 100644 --- a/web_interface/origin_guard.py +++ b/web_interface/origin_guard.py @@ -47,7 +47,7 @@ Not covered: DNS rebinding (an attacker's hostname re-pointed at the Pi is Neither is new; the interface is still meant for a trusted network. """ import logging -from urllib.parse import urlsplit +from urllib.parse import urlsplit, urlunsplit from flask import Flask, jsonify, request @@ -130,7 +130,7 @@ def _loggable(value: str) -> str: return '' if not parts.scheme or not netloc: return '' - return f'{parts.scheme}://{netloc}' + return urlunsplit((parts.scheme, netloc, '', '', '')) def check_request_origin():