Skip to content

fix(security): Stream Deck routes through a switch (alert 17) - #66

Merged
DarrellVS merged 1 commit into
mainfrom
fix/codeql-17-switch
Sep 23, 2026
Merged

DarrellVS merged 1 commit into
mainfrom
fix/codeql-17-switch

Conversation

@DarrellVS

Copy link
Copy Markdown
Owner

Code scanning alert 17 (js/unvalidated-dynamic-method-call) stayed open on 3.5.2. The typeof route === 'function' guard was on one side of readBody(...).then(...) and the call on the other, and CodeQL does not carry the narrowing into the closure. It now points at the call on line 106.

This replaces the handler Map with a Set of known keys (used for the early 404) and a switch that calls only the functions it names, so there is no dynamic dispatch left.

  • npm run check green
  • node scripts/streamdeck-check.mjs OK, including the unknown-key 404, tag, publish and the discard locks

🤖 Generated with Claude Code

Code scanning still flagged the Map lookup after 3.5.2's typeof guard,
because the check and the call sat either side of a promise. A switch
leaves nothing for a request to choose.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@DarrellVS
DarrellVS merged commit 09057f4 into main Sep 23, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant