mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-06 15:25:08 +00:00
refactor(web): build the logged origin with urlunsplit, not an f-string
Semgrep's directly-returned-format-string rule read the helper as a Flask route returning a formatted string. Same output. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -47,7 +47,7 @@ Not covered: DNS rebinding (an attacker's hostname re-pointed at the Pi is
|
|||||||
Neither is new; the interface is still meant for a trusted network.
|
Neither is new; the interface is still meant for a trusted network.
|
||||||
"""
|
"""
|
||||||
import logging
|
import logging
|
||||||
from urllib.parse import urlsplit
|
from urllib.parse import urlsplit, urlunsplit
|
||||||
|
|
||||||
from flask import Flask, jsonify, request
|
from flask import Flask, jsonify, request
|
||||||
|
|
||||||
@@ -130,7 +130,7 @@ def _loggable(value: str) -> str:
|
|||||||
return '<unreadable>'
|
return '<unreadable>'
|
||||||
if not parts.scheme or not netloc:
|
if not parts.scheme or not netloc:
|
||||||
return '<unreadable>'
|
return '<unreadable>'
|
||||||
return f'{parts.scheme}://{netloc}'
|
return urlunsplit((parts.scheme, netloc, '', '', ''))
|
||||||
|
|
||||||
|
|
||||||
def check_request_origin():
|
def check_request_origin():
|
||||||
|
|||||||
Reference in New Issue
Block a user