mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 18:36:15 -08:00
fix(mock): address CodeQL findings in the new portal auth code
Two genuine defects in the code this PR added: - readBearerToken's /Bearer\s+(.*)$/ backtracks polynomially on "bearer" followed by a long run of spaces; require the token to start with a non-space character instead - the /stalker proxy route read query params as strings without narrowing, so a repeated key (?url=a&url=b) arrives as an array and String.prototype.includes silently changes meaning The remaining three alerts (missing rate limiting x2, sensitive data in a GET query) are web-service hygiene rules aimed at internet-facing services. The mock servers bind to localhost, serve fabricated data, ship in no artifact, and deliberately mirror the real backend proxy's token-in-query contract; a rate limiter would break the E2E suite that hammers them. Exclude only those two apps from analysis via a documented CodeQL config; every shipped path keeps full coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
1 parent
eeda703849
commit
6b30e8b9e9
4 files changed
+36
-7
No files matched your search
@@ -47,6 +47,9 @@ jobs:
|
||||
uses: github/codeql-action/init@v4
|
||||
with:
|
||||
languages: ${{ matrix.language }}
|
||||
# Excludes the localhost dev/E2E mock servers from analysis; see the
|
||||
# config file for why.
|
||||
config-file: ./.github/codeql/codeql-config.yml
|
||||
# If you wish to specify custom queries, you can do so here or in a config file.
|
||||
# By default, queries listed here will override any specified in a config file.
|
||||
# Prefix the list here with "+" to use these queries and those in the config file.
|
||||
|
||||
Reference in new issue
Block a user