fix(web): keep exception text out of calendar responses; annotate moved code

The split made scanners report existing findings in the moved code as new:
- CodeQL: the calendar auth and calendar-list routes returned exception
  text (redacted, but still derived from the exception). Both now log the
  exception and return a fixed message pointing at the log.
- MD5 in the asset upload only makes a filename unique: usedforsecurity=False.
- pickle reads/writes the calendar plugin's own OAuth token (as before):
  annotated. Token-status labels and a log line naming the secrets path are
  false positives: annotated with the repo's nosec/nosemgrep convention.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-28 11:22:24 -04:00
co-authored by Claude Opus 5.5
parent f7bdb24772
commit 5e695b7c39
6 changed files with 23 additions and 19 deletions
@@ -402,8 +402,8 @@ class TestDiagnosticsAreRedacted:
tmp_path,
monkeypatch):
# OSError from the spawn carries the interpreter path and whatever the
# OS chose to say; it reaches the client through the redactor like
# everything else.
# OS chose to say; none of it reaches the client, which is pointed at
# the log instead.
script = tmp_path / 'calendar_registration.py'
script.write_text('', encoding='utf-8')
@@ -414,7 +414,8 @@ class TestDiagnosticsAreRedacted:
payload, error = mod._run_calendar_registration(tmp_path, '')
assert payload is None
assert 'abcd1234' not in error, error
assert 'OSError' in error, error
assert 'Exec format' not in error, error
assert 'log' in error, error
def test_a_missing_google_library_is_reported_without_raw_exception_text(
self, client, monkeypatch):