mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 20:00:08 +00:00
a3033a848e
The js/insecure-temporary-file rule fires on e2e Playwright specs that seed fixtures into the backend's COMPOSE_DIR (a fixed /tmp path) so the API under test can read them back. A randomized mkdtemp cannot apply there: the backend resolves paths against its own COMPOSE_DIR, so a fixture written elsewhere would be invisible to it. The prior suppression used a paths key inside a query-filters exclude, which CodeQL ignores: query-filters match on query metadata, not source path. That left the rule firing on every new e2e spec. Move the exclusion to a top-level paths-ignore, the only mechanism that scopes analysis by source path, so the e2e specs stop tripping the rule.
30 lines
1.5 KiB
YAML
30 lines
1.5 KiB
YAML
data_extensions:
|
|
- .github/codeql/extensions/safeLog.model.yml
|
|
|
|
# End-to-end Playwright specs are test-harness code, not shipped product code.
|
|
# They seed fixture files directly into the backend's COMPOSE_DIR (a fixed path
|
|
# under /tmp: both the spec fallback and the CI start-app default are
|
|
# /tmp/compose) so the API under test can read them back, which CodeQL flags as
|
|
# js/insecure-temporary-file. A randomized mkdtemp does not apply: the backend
|
|
# resolves paths against its own COMPOSE_DIR, so a fixture written elsewhere
|
|
# would be invisible to it, and the predictable-temp-path threat is moot on the
|
|
# ephemeral, single-tenant CI runners. paths-ignore is used (not a query-filters
|
|
# entry) because only paths-ignore scopes analysis by source path; a paths key
|
|
# inside a query-filters exclude is ignored, since query-filters match on query
|
|
# metadata rather than file location.
|
|
paths-ignore:
|
|
- e2e/**
|
|
|
|
query-filters:
|
|
# API tokens are 256-bit CSPRNG random; sha256 of the raw token is the
|
|
# correct construction. js/insufficient-password-hash exists to catch weak
|
|
# hashing of low-entropy human passwords, which is irrelevant for these
|
|
# high-entropy opaque keys. Scoped to the token-handling files only, so
|
|
# real user-password code (bcrypt-hashed elsewhere) is still analyzed.
|
|
- exclude:
|
|
id: js/insufficient-password-hash
|
|
paths:
|
|
- backend/src/utils/apiTokenFormat.ts
|
|
- backend/src/routes/apiTokens.ts
|
|
- backend/src/__tests__/**
|