Skip to content

fix: replace raw exception strings in HTTP responses (CWE-209) - #95

Merged
dvir001 merged 3 commits into
mainfrom
copilot/fix-code-scanning-alerts-57
Aug 17, 2026
Merged

fix: replace raw exception strings in HTTP responses (CWE-209)#95
dvir001 merged 3 commits into
mainfrom
copilot/fix-code-scanning-alerts-57

Conversation

Copilot AI commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

Raw str(exc) / str(e) values were being stored in state objects that get serialised and returned to HTTP clients, leaking internal implementation details (file paths, class names, internal logic) via GET /api/user-scanner/full-scan/status and the unauthenticated GET /api/settings endpoint.

Changes

  • simple_org_chart/app_main.py — three call sites replaced with generic error strings:
    • _background_full_scan: scan state dict error field
    • trigger_update: mark_data_update_finished error arg
    • clear_cached_data: mark_data_update_finished error arg
# Before
st['error'] = str(exc)
mark_data_update_finished(success=False, error=str(e), source='manual')

# After
st['error'] = 'An internal error occurred during the scan.'
mark_data_update_finished(success=False, error='An internal error occurred.', source='manual')

Server-side logger.error(...) calls are preserved in all three locations, so full exception details remain available to operators in logs.

Copilot AI changed the title [WIP] Fix code scanning alert #57 fix: replace raw exception strings in HTTP responses (CWE-209) Jul 21, 2026
Copilot AI requested a review from dvir001 July 21, 2026 12:50
@dvir001
dvir001 marked this pull request as ready for review August 17, 2026 10:23
Copilot AI lite review requested due to automatic review settings August 17, 2026 10:23
@dvir001
dvir001 merged commit 53d5cb6 into main Aug 17, 2026
7 checks passed

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR aims to mitigate CWE-209 (information exposure) by replacing raw exception strings previously stored in server-side state objects that are serialized back to HTTP clients (notably via /api/user-scanner/full-scan/status and the unauthenticated /api/settings GET).

Changes:

  • Sanitize the background full-scan state’s error field with a generic message.
  • Sanitize mark_data_update_finished(..., error=...) calls to avoid persisting raw exception strings into the data update status surfaced by /api/settings.
  • Preserve server-side logging at the failure sites (operators can still diagnose issues from logs).
Suppressed comments (2)

simple_org_chart/app_main.py:3791

  • Now that the client-facing scan error is intentionally generic, the logs become the primary place to diagnose failures. logger.error('Background full scan failed: %s', exc) does not record a traceback; using logger.exception(...) (or exc_info=True) will preserve full exception context for operators.
            logger.error('Background full scan failed: %s', exc)
            with _full_scan_lock:
                st = _read_scan_state()
                st['running'] = False
                st['error'] = 'An internal error occurred during the scan.'

simple_org_chart/app_main.py:4105

  • logger.error(f"Error triggering update after clearing data: {e}") drops the traceback, which makes diagnosing failures harder (especially now that the stored/returned error is generic). Prefer logger.exception(...) here to capture the stack trace.
        logger.error(f"Error triggering update after clearing data: {e}")
        mark_data_update_finished(success=False, error='An internal error occurred.', source='manual')

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 3787 to +3791
logger.error('Background full scan failed: %s', exc)
with _full_scan_lock:
st = _read_scan_state()
st['running'] = False
st['error'] = str(exc)
st['error'] = 'An internal error occurred during the scan.'
@@ -4050,7 +4050,7 @@
return jsonify({'message': 'Update started'}), 200
except Exception as e:
logger.error(f"Error triggering update: {e}")
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants