fix(security): close the five open CodeQL alerts on main - #719
Merged
Merged
Conversation
- js/polynomial-redos x2 (graphql-builtins.ts, open since May): slugifyForPrefix trimmed underscores with /^_+|_+$/g and the schema URL dropped trailing slashes with /\/+$/, both polynomial on long runs of the same character. Replaced with single linear passes; a test checks the new slug against the old regex on 2,000 random strings and that 50,000 underscores return at once. - js/remote-property-injection x2 (rest.engine.ts): the __rawquery fragment and form-encoded OAuth 1.0a bodies are parsed into plain objects keyed by whatever the tool argument says. Values are strings, so __proto__ could not pollute the prototype, but __proto__, constructor and prototype are now skipped; no API names a parameter like that. Test included. - js/reflected-xss (mcp-endpoint.controller.ts): the tools/list answer on the global endpoint echoes the request id into a text/event-stream body. Not renderable as HTML, but it now carries X-Content-Type-Options: nosniff so no browser sniffs it into one. The ReDoS flagged on #716 (e-mail check for OAuth 1.0a consumer keys) was already replaced by looksLikeEmail before that PR merged; no alert is open for it on main.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes every high-severity CodeQL alert currently open on
main.graphql-builtins.tsslugifyForPrefixand the schema-URL trim were polynomial on long runs of_//. Both are now single linear passes. A test compares the new slug with the old regex on 2,000 random strings and checks that 50,000 underscores return at once.rest.engine.ts__rawqueryfragment and form-encoded OAuth 1.0a bodies are parsed into plain objects keyed by the tool argument. The values are strings, so__proto__could not pollute the prototype.__proto__,constructorandprototypeare now skipped anyway, since no API names a parameter like that. Test included.mcp-endpoint.controller.tstools/listanswer echoes the request id in atext/event-streambody. That body is not renderable as HTML, but it now sendsX-Content-Type-Options: nosniff.The ReDoS GitHub flagged in a review comment on #716 (the e-mail check for OAuth 1.0a consumer keys) had already been replaced by
looksLikeEmailbefore that PR merged. No alert is open for it onmain.Backend suite (5,654 tests), tsc and eslint are green.