From 5c5786a2425fb1a9d4b08a68bcb5e7155ad7d0cd Mon Sep 17 00:00:00 2001 From: Derek Date: Thu, 1 Oct 2026 00:51:28 +1000 Subject: [PATCH] fix: resolve the three high code-scanning alerts in the helper scripts The ancestor-override test now asserts the whole list, so the external origin's absence and the override's position are both checked and there is no URL membership test left to misread as a substring check. The two clear-text logging sinks carry a codeql marker with the reason: creds.py prints the admin login on a terminal because that is what make creds is for, and every flow traced into _print carries a key name, a committed default or an already-redacted fault. --- scripts/_common.py | 1 + scripts/creds.py | 1 + scripts/tests/test_origins.py | 7 +++++-- 3 files changed, 7 insertions(+), 2 deletions(-) diff --git a/scripts/_common.py b/scripts/_common.py index 9d87ea2..954caf3 100644 --- a/scripts/_common.py +++ b/scripts/_common.py @@ -119,6 +119,7 @@ def _print( # Resolved at call time, not bound as a default: a caller that replaces # sys.stderr (pytest's capture) must still see the message. print( + # codeql[py/clear-text-logging-sensitive-data] callers pass a secret's key or committed default, never a minted value f"{Path(sys.argv[0]).stem}{f' ({header})' if header else ''}: {msg}", file=file or sys.stderr, ) diff --git a/scripts/creds.py b/scripts/creds.py index 2548814..2732f86 100644 --- a/scripts/creds.py +++ b/scripts/creds.py @@ -313,6 +313,7 @@ def main(argv: list[str] | None = None) -> int: is_tty=sys.stdout.isatty(), setting=os.environ.get(_SHOW_KEY, "") ) for line in summary_lines(values=values, reveal=reveal): + # codeql[py/clear-text-logging-sensitive-data] `make creds` exists to show the admin login, on a terminal only print(line) if write: path = write_summary(values=values, path=ACCESS_SUMMARY_FILE) diff --git a/scripts/tests/test_origins.py b/scripts/tests/test_origins.py index 00b372d..1f17f14 100644 --- a/scripts/tests/test_origins.py +++ b/scripts/tests/test_origins.py @@ -80,8 +80,11 @@ def test_the_per_surface_override_still_wins() -> None: DFE_HYPERDX_APP_URL="http://dfe.example.test", ) - assert "http://dfe.example.test:3000" in found - assert "http://10.0.0.5:3000" not in found + assert found == [ + "http://localhost:3000", + "http://127.0.0.1:3000", + "http://dfe.example.test:3000", + ] @pytest.mark.parametrize(