Skip to content

Fix/codeql security findings - #20

Merged
KFilippopolitis merged 4 commits into
masterfrom
fix/codeql-security-findings
Sep 15, 2026
Merged

KFilippopolitis merged 4 commits into
masterfrom
fix/codeql-security-findings

Conversation

@KFilippopolitis

Copy link
Copy Markdown
Contributor

No description provided.

KFilippopolitis and others added 4 commits September 15, 2026 16:15
`authentication.enabled=0` disabled CSRF entirely, leaving state-changing
requests unprotected whenever the API is reachable without a login. The
double-submit cookie repository is now shared by both branches of the
filter chain and documented in the README for curl/Postman users.

Co-authored-by: ChatGPT <codex@openai.com>
`DataModelConverter.convertExcelToDataModel` joined the client-supplied
upload name onto `java.io.tmpdir`, so a crafted name could write outside
the temporary directory and the leftover file was never removed. The
upload now goes to a generated `Files.createTempFile` path that keeps only
an allow-listed extension, and is deleted in a `finally` block.

Co-authored-by: ChatGPT <codex@openai.com>
Both validation endpoints echoed the raw exception text, which CodeQL flags
as stack-trace exposure. `error_reporting.client_error_message` now keeps a
single line of the validator report, drops anything that looks like a trace
back, and truncates to 300 characters; the unhandled-exception branch logs
the full stack and returns a generic 500. `validate_json` also caught the
imported alias instead of the `json_validator` attribute the controller
raises, so domain errors were reported as 500.

Co-authored-by: ChatGPT <codex@openai.com>
The CodeQL security findings flagged the default write token: pin
`contents: read` on the data quality tool and EBRAINS sync jobs.

Co-authored-by: ChatGPT <codex@openai.com>
# client_error_message keeps the report to a single bounded line and replaces anything
# that looks like a stack trace, so no runtime detail reaches the caller.
# codeql[py/stack-trace-exposure] Validator report for the caller's own payload.
return jsonify({"error": client_error_message(e)}), 400
# Same as for /validate-json: a single bounded line describing the uploaded
# workbook, never a stack trace.
# codeql[py/stack-trace-exposure] Validator report for the uploaded workbook.
return jsonify({"error": client_error_message(e)}), 400
@KFilippopolitis
KFilippopolitis merged commit e13a16a into master Sep 15, 2026
7 checks passed
@KFilippopolitis
KFilippopolitis deleted the fix/codeql-security-findings branch September 15, 2026 19:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants