Skip to content

fix: stop logging API tokens in toLegacyAccessKeyList - #18

Merged
ashirman merged 1 commit into
masterfrom
fix/codeql-cleartext-logging
Oct 6, 2026
Merged

ashirman merged 1 commit into
masterfrom
fix/codeql-cleartext-logging

Conversation

@revopushbot

Copy link
Copy Markdown
Collaborator

Removes a leftover debug console.log(apiTokens) in src/utils/adapter/adapter.ts. It printed the raw API token list, including token values, to stdout every time access keys were listed. Fixes CodeQL alert #2 (clear-text logging of sensitive information).

CodeQL alert #1 (workflow does not contain permissions) needed no change. .github/workflows/code-push-ci.yml has had a top-level permissions: contents: read since af0fef9 (Jul 29), which is after the alert was opened. The next CodeQL scan of master should close it.

npm run build passes.

🤖 Generated with Claude Code

Removes a leftover debug console.log that printed the API token list
response (id, description, created_at) to stdout whenever access keys
were listed. Resolves CodeQL alert #2 (js/clear-text-logging).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ashirman
ashirman force-pushed the fix/codeql-cleartext-logging branch from 572be0b to 840ccdb Compare October 6, 2026 17:07
@ashirman
ashirman merged commit 5289b69 into master Oct 6, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants