fix: add CodeQL barrier model for sanitizeForLog against log injection (#935)

sanitizeForLog() already strips CR, LF, and control characters from user
input before logging, but CodeQL did not recognize the custom sanitizer.
This caused false-positive log-injection alerts at every call site.

Add a CodeQL data extension model that marks the return value of
sanitizeForLog() as a barrier against log-injection taint, and a
codeql-config.yml that references it.
This commit is contained in:
Anso
2026-05-06 08:47:34 -04:00
committed by GitHub
parent 0c3ce4b224
commit 0dcf309c48
3 changed files with 9 additions and 0 deletions
+2
View File
@@ -0,0 +1,2 @@
data_extensions:
- .github/codeql/extensions/safeLog.model.yml
@@ -0,0 +1,6 @@
extensions:
- addsTo:
pack: codeql/javascript-all
extensible: barrierModel
data:
- ["backend/src/utils/safeLog", "Member[sanitizeForLog].ReturnValue", "log-injection"]