mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 22:35:08 +00:00
fix(web): keep exception text out of calendar responses; annotate moved code
The split made scanners report existing findings in the moved code as new: - CodeQL: the calendar auth and calendar-list routes returned exception text (redacted, but still derived from the exception). Both now log the exception and return a fixed message pointing at the log. - MD5 in the asset upload only makes a filename unique: usedforsecurity=False. - pickle reads/writes the calendar plugin's own OAuth token (as before): annotated. Token-status labels and a log line naming the secrets path are false positives: annotated with the repo's nosec/nosemgrep convention. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -738,7 +738,7 @@ def get_github_auth_status():
|
||||
return jsonify({
|
||||
'status': 'success',
|
||||
'data': {
|
||||
'token_status': 'none',
|
||||
'token_status': 'none', # nosec B105 - a status label # nosemgrep
|
||||
'authenticated': False,
|
||||
'rate_limit': 60,
|
||||
'message': 'No GitHub token configured',
|
||||
@@ -753,7 +753,7 @@ def get_github_auth_status():
|
||||
return jsonify({
|
||||
'status': 'success',
|
||||
'data': {
|
||||
'token_status': 'valid',
|
||||
'token_status': 'valid', # nosec B105 - a status label # nosemgrep
|
||||
'authenticated': True,
|
||||
'rate_limit': 5000,
|
||||
'message': 'GitHub API authenticated',
|
||||
@@ -764,7 +764,7 @@ def get_github_auth_status():
|
||||
return jsonify({
|
||||
'status': 'success',
|
||||
'data': {
|
||||
'token_status': 'invalid',
|
||||
'token_status': 'invalid', # nosec B105 - a status label # nosemgrep
|
||||
'authenticated': False,
|
||||
'rate_limit': 60,
|
||||
'message': f'GitHub token is invalid: {error_message}' if error_message else 'GitHub token is invalid',
|
||||
|
||||
Reference in New Issue
Block a user