fix(web): keep exception text out of calendar responses; annotate moved code

The split made scanners report existing findings in the moved code as new:
- CodeQL: the calendar auth and calendar-list routes returned exception
  text (redacted, but still derived from the exception). Both now log the
  exception and return a fixed message pointing at the log.
- MD5 in the asset upload only makes a filename unique: usedforsecurity=False.
- pickle reads/writes the calendar plugin's own OAuth token (as before):
  annotated. Token-status labels and a log line naming the secrets path are
  false positives: annotated with the repo's nosec/nosemgrep convention.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-28 11:22:24 -04:00
co-authored by Claude Opus 5.5
parent f7bdb24772
commit 5e695b7c39
6 changed files with 23 additions and 19 deletions
+3 -2
View File
@@ -1466,8 +1466,9 @@ def _run_calendar_registration(plugin_dir: Path, stdin_payload: str):
except subprocess.TimeoutExpired:
return None, 'Authentication timed out after 120s'
except OSError as e:
logger.error('Could not run calendar_registration.py', exc_info=True)
return None, 'Could not run the authentication script: %s' % describe_exception(e)
# The exception (a path, an errno) goes to the log, not the client.
logger.error('Could not run calendar_registration.py: %s', e, exc_info=True)
return None, 'Could not run the authentication script; see the web service log'
for line in reversed((result.stdout or '').splitlines()):
line = line.strip()