fix: suppress intentional ownership hash alerts

This commit is contained in:
jibanez-staticduo 2026-09-18 14:50:16 +02:00
parent a4accccac3
commit 5d36f155b6
No known key found for this signature in database
4 changed files with 6 additions and 0 deletions

View file

@ -265,6 +265,7 @@ def hash_token(token: str):
import hashlib
# This digest is an opaque lookup identifier, not a password hash.
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token

View file

@ -220,6 +220,7 @@ def decode_call(token: str, authorization: str) -> CodexRealtimeCall:
raise HTTPException(403, "Invalid realtime call") from exc
if (
call.expires_at < time.time()
# codeql[py/weak-sensitive-data-hashing]
or call.owner != hashlib.sha256(authorization.encode(), usedforsecurity=False).hexdigest()
):
raise HTTPException(403, "Invalid or expired realtime call")
@ -400,6 +401,7 @@ async def _create_codex_realtime_call(request: Request) -> Response:
call: Final = parse_call_response(
response,
alias=model,
# codeql[py/weak-sensitive-data-hashing]
owner=hashlib.sha256(
f"Bearer {owner_key}".encode(), usedforsecurity=False
).hexdigest(),

View file

@ -185,6 +185,7 @@ def rewrite_session_ids(value: JsonValue | Mapping[str, JsonValue], raw_id: str,
def _owner(auth: UserAPIKeyAuth) -> str:
if not auth.api_key:
raise HTTPException(403, "Live sessions require an authenticated API key")
# codeql[py/weak-sensitive-data-hashing]
return hashlib.sha256(auth.api_key.encode(), usedforsecurity=False).hexdigest()

View file

@ -4291,6 +4291,7 @@ class PrismaClient:
def hash_token(self, token: str):
# Hash the string using SHA-256
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token
@ -6718,6 +6719,7 @@ def hash_token(token: str):
import hashlib
# Hash the string using SHA-256
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token