Skip to content

fix(security): resolve CodeQL findings - #762

Merged
XiaoSeS merged 1 commit into
iflytek:mainfrom
FenjuFu:fix/code-scanning-alerts-2026-08
Aug 28, 2026
Merged

XiaoSeS merged 1 commit into
iflytek:mainfrom
FenjuFu:fix/code-scanning-alerts-2026-08

Conversation

@FenjuFu

@FenjuFu FenjuFu commented Aug 27, 2026

Copy link
Copy Markdown
Member

Summary

  • parse uploaded SKILL.md frontmatter with a bounded SnakeYAML SafeConstructor
  • replace the polynomial placeholder regex with linear marker matching
  • restrict public label security matching to GET and retain default CSRF protection
  • validate CLI callbacks as credential-free HTTP loopback URL objects, discard supplied fragments, and remove sensitive debug logging
  • use cryptographic UUIDs for E2E account identifiers
  • add YAML tag, label security-chain, and CLI callback regression tests

Code scanning coverage

Addresses alerts #1, #2, #4, #5, #6, #7, #8, and #9. The CLI callback is intentionally limited to HTTP localhost, 127.0.0.1, and IPv6 loopback; the remote CodeQL result will confirm whether the analyzer recognizes the returned validated URL object.

Validation

  • backend app reactor: 773 tests passed, 1 skipped
  • frontend unit tests: 695 passed
  • frontend typecheck: passed
  • frontend lint: passed
  • frontend production build: passed

Full staging and Playwright E2E were not run locally because they require the complete service stack; PR CI provides the real-services E2E job.

Use a bounded safe YAML constructor, remove the polynomial placeholder regex, keep public label access GET-only with CSRF protection, validate CLI callbacks as loopback URL objects, and use cryptographic UUIDs for E2E identities.

Signed-off-by: FenjuFu <92919259+FenjuFu@users.noreply.github.com>
@XiaoSeS
XiaoSeS merged commit c825d89 into iflytek:main Aug 28, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants