Fix/codeql security findings - #20
Merged
Merged
Conversation
`authentication.enabled=0` disabled CSRF entirely, leaving state-changing requests unprotected whenever the API is reachable without a login. The double-submit cookie repository is now shared by both branches of the filter chain and documented in the README for curl/Postman users. Co-authored-by: ChatGPT <codex@openai.com>
`DataModelConverter.convertExcelToDataModel` joined the client-supplied upload name onto `java.io.tmpdir`, so a crafted name could write outside the temporary directory and the leftover file was never removed. The upload now goes to a generated `Files.createTempFile` path that keeps only an allow-listed extension, and is deleted in a `finally` block. Co-authored-by: ChatGPT <codex@openai.com>
Both validation endpoints echoed the raw exception text, which CodeQL flags as stack-trace exposure. `error_reporting.client_error_message` now keeps a single line of the validator report, drops anything that looks like a trace back, and truncates to 300 characters; the unhandled-exception branch logs the full stack and returns a generic 500. `validate_json` also caught the imported alias instead of the `json_validator` attribute the controller raises, so domain errors were reported as 500. Co-authored-by: ChatGPT <codex@openai.com>
The CodeQL security findings flagged the default write token: pin `contents: read` on the data quality tool and EBRAINS sync jobs. Co-authored-by: ChatGPT <codex@openai.com>
| # client_error_message keeps the report to a single bounded line and replaces anything | ||
| # that looks like a stack trace, so no runtime detail reaches the caller. | ||
| # codeql[py/stack-trace-exposure] Validator report for the caller's own payload. | ||
| return jsonify({"error": client_error_message(e)}), 400 |
| # Same as for /validate-json: a single bounded line describing the uploaded | ||
| # workbook, never a stack trace. | ||
| # codeql[py/stack-trace-exposure] Validator report for the uploaded workbook. | ||
| return jsonify({"error": client_error_message(e)}), 400 |
ThanKarab
approved these changes
Sep 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.