refactor(web): build the logged origin with urlunsplit, not an f-string

Semgrep's directly-returned-format-string rule read the helper as a Flask route returning a formatted string. Same output.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-29 19:37:29 -04:00
co-authored by Claude Opus 5.5
parent 9ce8d6c3c4
commit 01fb88d9de
+2 -2
View File
@@ -47,7 +47,7 @@ Not covered: DNS rebinding (an attacker's hostname re-pointed at the Pi is
Neither is new; the interface is still meant for a trusted network. Neither is new; the interface is still meant for a trusted network.
""" """
import logging import logging
from urllib.parse import urlsplit from urllib.parse import urlsplit, urlunsplit
from flask import Flask, jsonify, request from flask import Flask, jsonify, request
@@ -130,7 +130,7 @@ def _loggable(value: str) -> str:
return '<unreadable>' return '<unreadable>'
if not parts.scheme or not netloc: if not parts.scheme or not netloc:
return '<unreadable>' return '<unreadable>'
return f'{parts.scheme}://{netloc}' return urlunsplit((parts.scheme, netloc, '', '', ''))
def check_request_origin(): def check_request_origin():