From 34e4c70edb41f41e93922f0437eb94f9712b51d8 Mon Sep 17 00:00:00 2001 From: Darrell van Swinderen Date: Wed, 23 Sep 2026 14:55:10 +0200 Subject: [PATCH] fix(security): check a Stream Deck route is a function before calling it Code scanning still reported alert 17 on 3.5.1, at the call rather than the lookup: with a key chosen by the request, it wants the value checked as callable first. The Map from 3.5.1 already limits it to the listed routes; this adds the typeof guard the rule recognises. Co-Authored-By: Claude Opus 5.5 (1M context) --- src/main/services/streamdeck/server.ts | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/main/services/streamdeck/server.ts b/src/main/services/streamdeck/server.ts index 04a89f7..961834c 100644 --- a/src/main/services/streamdeck/server.ts +++ b/src/main/services/streamdeck/server.ts @@ -97,7 +97,10 @@ export async function startStreamDeck(): Promise { const path = (req.url ?? '').split('?')[0]; const route = ROUTES.get(`${req.method} ${path}`); - if (!route) return send(404, { error: 'No such key' }); + // Only ever something this file put there, and checked to be callable + // before it is called, which is the guard code scanning asks for when a + // request chooses what runs. + if (typeof route !== 'function') return send(404, { error: 'No such key' }); void readBody(req) .then((body) => route(body))