Incomplete naming schema and API usage patterns in py/insecure-cookie
还没有人认领这个 Issue。
评估
调研方向
从 py/insecure-cookie 规则开始,检查 issue 中描述的 cookie.isSensitive 谓词和 set_cookie 处理。将列出的 token 名称和直接的 Set-Cookie 示例与当前行为进行比较;当能够检测到受支持的身份验证 cookie 模式,且不只依赖 framework 方法时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
- The existing
cookie.isSensitivepredicate seems to miss common modern authentication token patterns. I have found some and listed them below. - The rule currently relies primarily on specific framework methods (e.g., set_cookie). It ignores direct HTTP manipulation, which is also very common.
code example:
from flask import Flask, Response, make_response
app = Flask(__name__)
@app.route("/login")
def login():
resp = make_response("Logged in")
resp.set_cookie("authKey", "secret123") # $ Alert[py/insecure-cookie]
resp.set_cookie("accessToken", "secret123") # $ missing
resp.set_cookie("access_token", "secret123") # missing
resp.set_cookie("auth_token", "secret123") # missing
resp.set_cookie("jwt", "secret123") # $ missing
resp.set_cookie("oauth_token", "secret123") # $ missing
# cannot support this
resp.headers.add("Set-Cookie", "authKey=secret123") # missing
# This is also common, but it seems more difficult to support this.
from http.cookies import SimpleCookie
resp = make_response("Logged in")
cookie = SimpleCookie()
cookie["session"]['authKey'] = "secret123" # missing
# cookie["session"]["httponly"] = True
# cookie["session"]["secure"] = True
for key, morsel in cookie.items():
resp.headers.add('Set-Cookie', morsel.OutputString())
return resp
- 主要语言
- CodeQL
- 星标
- 10.1k
- 派生
- 2.1k
- 平均合并
- 2 天 16 小时
- 30 天内合并 PR
- 143
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
github/codeql 的其他 Issue
-
agentic-workflows
难度 2/5 1-3 小时 新手友好度 70/100
-
false-positive javascript
难度 2/5 1-3 小时 新手友好度 84/100
-
难度 2/5 1-3 小时 新手友好度 82/100
-
难度 2/5 1-3 小时 新手友好度 78/100
-
false-positive
难度 2/5 1-3 小时 新手友好度 70/100
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 78/100
punkpeye/mcp-remote#369 ·
-
Mend: dependency security vulnerability untriaged
难度 1/5 1 小时以内 新手友好度 86/100
-
难度 2/5 1-3 小时 新手友好度 68/100
-
bug
难度 1/5 1 小时以内 新手友好度 90/100
cisagov/vulnrichment#337 ·
-
bug DUP Reservations
难度 2/5 1-3 小时 新手友好度 68/100
bcgov/reserve-rec-public#896 ·