Files
iptvnator/.github/codeql/codeql-config.yml
T
4grayandClaude Fable 5 6b30e8b9e9 fix(mock): address CodeQL findings in the new portal auth code
Two genuine defects in the code this PR added:
- readBearerToken's /Bearer\s+(.*)$/ backtracks polynomially on
  "bearer" followed by a long run of spaces; require the token to start
  with a non-space character instead
- the /stalker proxy route read query params as strings without
  narrowing, so a repeated key (?url=a&url=b) arrives as an array and
  String.prototype.includes silently changes meaning

The remaining three alerts (missing rate limiting x2, sensitive data in
a GET query) are web-service hygiene rules aimed at internet-facing
services. The mock servers bind to localhost, serve fabricated data,
ship in no artifact, and deliberately mirror the real backend proxy's
token-in-query contract; a rate limiter would break the E2E suite that
hammers them. Exclude only those two apps from analysis via a documented
CodeQL config; every shipped path keeps full coverage.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-01 12:42:35 +02:00

17 lines
828 B
YAML

name: 'IPTVnator CodeQL config'
# The mock servers are development/E2E fixtures. They bind to localhost, serve
# fabricated data, ship in no released artifact, and deliberately imitate the
# quirks of the upstream IPTV protocols — including reading a session token
# from a GET query string, which is what the real Stalker backend proxy does
# and therefore what the app must be tested against.
#
# CodeQL's web-service hygiene rules (missing rate limiting, sensitive data in
# GET requests) assume an internet-facing service and produce only false
# positives here; a rate limiter on a fixture that the E2E suite hammers would
# actively break the tests. Injection, path-traversal and similar rules still
# apply to everything the app itself ships.
paths-ignore:
- apps/stalker-mock-server
- apps/xtream-mock-server