mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-05 06:45:09 +00:00
fix(web): keep exception text out of calendar responses; annotate moved code
The split made scanners report existing findings in the moved code as new: - CodeQL: the calendar auth and calendar-list routes returned exception text (redacted, but still derived from the exception). Both now log the exception and return a fixed message pointing at the log. - MD5 in the asset upload only makes a filename unique: usedforsecurity=False. - pickle reads/writes the calendar plugin's own OAuth token (as before): annotated. Token-status labels and a log line naming the secrets path are false positives: annotated with the repo's nosec/nosemgrep convention. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -142,7 +142,9 @@ def upload_plugin_asset():
|
||||
for file, file_ext, file_size, file_content in accepted:
|
||||
# Generate unique filename
|
||||
timestamp = int(_pkg.time.time())
|
||||
file_hash = hashlib.md5(file_content + file.filename.encode()).hexdigest()[:8]
|
||||
# Only makes the filename unique; nothing is verified with it.
|
||||
file_hash = hashlib.md5(file_content + file.filename.encode(),
|
||||
usedforsecurity=False).hexdigest()[:8]
|
||||
safe_filename = f"image_{timestamp}_{file_hash}{file_ext}"
|
||||
file_path = assets_dir / safe_filename
|
||||
|
||||
|
||||
Reference in New Issue
Block a user