mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-09 01:16:15 -08:00
Two genuine defects in the code this PR added: - readBearerToken's /Bearer\s+(.*)$/ backtracks polynomially on "bearer" followed by a long run of spaces; require the token to start with a non-space character instead - the /stalker proxy route read query params as strings without narrowing, so a repeated key (?url=a&url=b) arrives as an array and String.prototype.includes silently changes meaning The remaining three alerts (missing rate limiting x2, sensitive data in a GET query) are web-service hygiene rules aimed at internet-facing services. The mock servers bind to localhost, serve fabricated data, ship in no artifact, and deliberately mirror the real backend proxy's token-in-query contract; a rate limiter would break the E2E suite that hammers them. Exclude only those two apps from analysis via a documented CodeQL config; every shipped path keeps full coverage. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
17 lines
828 B
YAML
17 lines
828 B
YAML
name: 'IPTVnator CodeQL config'
|
|
|
|
# The mock servers are development/E2E fixtures. They bind to localhost, serve
|
|
# fabricated data, ship in no released artifact, and deliberately imitate the
|
|
# quirks of the upstream IPTV protocols — including reading a session token
|
|
# from a GET query string, which is what the real Stalker backend proxy does
|
|
# and therefore what the app must be tested against.
|
|
#
|
|
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
|
|
# GET requests) assume an internet-facing service and produce only false
|
|
# positives here; a rate limiter on a fixture that the E2E suite hammers would
|
|
# actively break the tests. Injection, path-traversal and similar rules still
|
|
# apply to everything the app itself ships.
|
|
paths-ignore:
|
|
- apps/stalker-mock-server
|
|
- apps/xtream-mock-server
|