mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 01:56:16 -08:00
fix(mock): address CodeQL findings in the new portal auth code
Two genuine defects in the code this PR added: - readBearerToken's /Bearer\s+(.*)$/ backtracks polynomially on "bearer" followed by a long run of spaces; require the token to start with a non-space character instead - the /stalker proxy route read query params as strings without narrowing, so a repeated key (?url=a&url=b) arrives as an array and String.prototype.includes silently changes meaning The remaining three alerts (missing rate limiting x2, sensitive data in a GET query) are web-service hygiene rules aimed at internet-facing services. The mock servers bind to localhost, serve fabricated data, ship in no artifact, and deliberately mirror the real backend proxy's token-in-query contract; a rate limiter would break the E2E suite that hammers them. Exclude only those two apps from analysis via a documented CodeQL config; every shipped path keeps full coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
eeda703849
commit
6b30e8b9e9
4 files changed
+36
-7
No files matched your search
@@ -0,0 +1,16 @@
|
||||
name: 'IPTVnator CodeQL config'
|
||||
|
||||
# The mock servers are development/E2E fixtures. They bind to localhost, serve
|
||||
# fabricated data, ship in no released artifact, and deliberately imitate the
|
||||
# quirks of the upstream IPTV protocols — including reading a session token
|
||||
# from a GET query string, which is what the real Stalker backend proxy does
|
||||
# and therefore what the app must be tested against.
|
||||
#
|
||||
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
|
||||
# GET requests) assume an internet-facing service and produce only false
|
||||
# positives here; a rate limiter on a fixture that the E2E suite hammers would
|
||||
# actively break the tests. Injection, path-traversal and similar rules still
|
||||
# apply to everything the app itself ships.
|
||||
paths-ignore:
|
||||
- apps/stalker-mock-server
|
||||
- apps/xtream-mock-server
|
||||
Reference in new issue
Block a user