From 4b59a01f36e01a5d4ab675f6ca7c5147073632a9 Mon Sep 17 00:00:00 2001 From: sriramveeraghanta Date: Wed, 29 Jul 2026 20:03:52 +0530 Subject: [PATCH] fix: resolve open CodeQL security alerts - adapter/oauth.py: stop logging request headers on user-info fetch failure; they carry the Bearer access token (py/clear-text-logging-sensitive-data) - adapter/base.py: drop the email value from the invalid-email warning log (py/clear-text-logging-sensitive-data) - provider/oauth/github.py: stop logging organization id / user login on org-membership failure (py/clear-text-logging-sensitive-data) - editor custom-link: rewrite the C0-control strip regex with escaped, non-overlapping ranges instead of raw control bytes overlapping \s (js/overly-large-range); also fixes the file being detected as binary --- apps/api/plane/authentication/adapter/base.py | 2 +- .../api/plane/authentication/adapter/oauth.py | 8 ++------ .../authentication/provider/oauth/github.py | 10 +++------- .../core/extensions/custom-link/extension.tsx | Bin 7570 -> 7716 bytes 4 files changed, 6 insertions(+), 14 deletions(-) diff --git a/apps/api/plane/authentication/adapter/base.py b/apps/api/plane/authentication/adapter/base.py index 112570d56f3..3a616a21c38 100644 --- a/apps/api/plane/authentication/adapter/base.py +++ b/apps/api/plane/authentication/adapter/base.py @@ -78,7 +78,7 @@ def sanitize_email(self, email): try: validate_email(email) except ValidationError: - self.logger.warning(f"Email is not valid: {email}") + self.logger.warning("Email is not valid") raise AuthenticationException( error_code=AUTHENTICATION_ERROR_CODES["INVALID_EMAIL"], error_message="INVALID_EMAIL", diff --git a/apps/api/plane/authentication/adapter/oauth.py b/apps/api/plane/authentication/adapter/oauth.py index 0bef76b2487..afb1a31325d 100644 --- a/apps/api/plane/authentication/adapter/oauth.py +++ b/apps/api/plane/authentication/adapter/oauth.py @@ -90,12 +90,8 @@ def get_user_response(self): response.raise_for_status() return response.json() except requests.RequestException: - self.logger.warning( - "Error getting user response", - extra={ - "headers": headers, - }, - ) + # Do not log headers here: they carry the access token + self.logger.warning("Error getting user response") code = self.authentication_error_code() raise AuthenticationException(error_code=AUTHENTICATION_ERROR_CODES[code], error_message=str(code)) diff --git a/apps/api/plane/authentication/provider/oauth/github.py b/apps/api/plane/authentication/provider/oauth/github.py index 852d8d0f66f..7b3f6a9e1e2 100644 --- a/apps/api/plane/authentication/provider/oauth/github.py +++ b/apps/api/plane/authentication/provider/oauth/github.py @@ -156,13 +156,9 @@ def set_user_data(self): if self.organization_id: if not self.is_user_in_organization(user_info_response.get("login")): - self.logger.warning( - "User is not in organization", - extra={ - "organization_id": self.organization_id, - "user_login": user_info_response.get("login"), - }, - ) + # Do not log the organization id or user login here: + # the configuration values must not end up in logs + self.logger.warning("User is not in organization") raise AuthenticationException( error_code=AUTHENTICATION_ERROR_CODES["GITHUB_USER_NOT_IN_ORG"], error_message="GITHUB_USER_NOT_IN_ORG", diff --git a/packages/editor/src/core/extensions/custom-link/extension.tsx b/packages/editor/src/core/extensions/custom-link/extension.tsx index 0b1022642581b6da5070603cff1b2904d44e3799..248f3ac47a435d944eb1f47e785ab35f1b54c909 100644 GIT binary patch delta 192 zcmXwvy$ZrG6oq$1aMtD0Nzs_PiMkZ=XK)gwgH>qjwGE_6xrvai@1U>X0|>sLrQkQ5 z!#RA<#e4Y)Iu+-jofOKln=o-AktuYR)enNwEY-@AmW(h%2aG{&qOwA(Sk9pkM4AkQ zyWkjZVdejQFqTAF3Y9^EcTEU3M>rk!VA325Y(dS0u;emMalo(V$V3mnhBY;7a@~yS U<}%`A@Vp^#{;Jyjuj}->KV1AiZU6uP delta 30 lcmZ2tGs${`Bd?%dQEEX>Vsfg6eq1zzu6#`K<|n)k0sx<03FZI*