Repository navigation
fix: strip trigger variable brackets in one step - #1138
Conversation
replace() only removed the first angle bracket, so a token with more than one bracket would keep the rest. Trigger variables are a single <name> pair, and the key is now taken from the characters between those brackets. Co-authored-by: David <Klakurka@users.noreply.github.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 47 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
ChangesSignature payload parsing
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~8 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The token-key change preserves the existing signature payload behavior for supported tokens, so no merge-blocking issue is identified. Architecture SummaryArchitecture risk: 🔵 Low · up to The change affects 1 system. Changed systems: Architecture concerns Review detailsSystems and components
Before / after behavior
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The focused change preserves existing payload behavior and matches the established token definitions.
Review effort: Balanced
Findings: None
What changed in this PR
Simplifies trigger-variable key extraction while resolving CodeQL incomplete-sanitization findings.
Changes:
- Replaces chained bracket removal with deterministic token slicing.
- Documents the expected
<name>token format.
| File | Description |
|---|---|
utils/validators.ts |
Extracts trigger keys by removing the first and last characters. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/3
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/6
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/7
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/8
Description
CodeQL
js/incomplete-sanitizationreported two findings on the same line in the trigger signature payload:replace('<', '')andreplace('>', ''). Each call removes only the first match.Trigger variables are always a single
<name>token fromTRIGGER_POST_VARIABLES. The key is now the slice between the first and last character, so both brackets are removed together. One change clears both findings.The GitHub token for this run cannot read code-scanning alert bodies, so this is one of the fixes from a local CodeQL code-scanning run of the same default query suite.
Test plan
npx ts-node -O '{"module":"commonjs"}' node_modules/jest/bin/jest.js tests/unittests/validators.test.ts --forceExit<amount>→ amount, and the multi-variable payloads).Summary by CodeRabbit