mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-15 03:32:21 +03:00
Compare commits
1 Commits
dependabot
...
fix/codeql
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
ab36b35035 |
@@ -37,15 +37,26 @@ function nonEmptyString(value: unknown): string | null {
|
|||||||
return normalized || null;
|
return normalized || null;
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Keep the historical installation-id layout so existing accounts stay stable. */
|
/**
|
||||||
|
* Keep the historical installation-id layout so existing accounts stay stable.
|
||||||
|
* CodeQL: not password hashing — this derives a deterministic installation UUID
|
||||||
|
* from an account seed, never verified against a stored credential. Same
|
||||||
|
* false-positive class as src/lib/db/apiKeys.ts::hashKey.
|
||||||
|
* lgtm[js/insufficient-password-hash]
|
||||||
|
*/
|
||||||
function uuidFromLegacyInstallationValue(value: string): string {
|
function uuidFromLegacyInstallationValue(value: string): string {
|
||||||
const hash = createHash("sha256").update(value).digest("hex");
|
const hash = createHash("sha256").update(value).digest("hex"); // nosemgrep: insufficient-password-hash
|
||||||
return `${hash.slice(0, 8)}-${hash.slice(8, 12)}-4${hash.slice(13, 16)}-a${hash.slice(17, 20)}-${hash.slice(20, 32)}`;
|
return `${hash.slice(0, 8)}-${hash.slice(8, 12)}-4${hash.slice(13, 16)}-a${hash.slice(17, 20)}-${hash.slice(20, 32)}`;
|
||||||
}
|
}
|
||||||
|
|
||||||
/** RFC4122 v4 from SHA-256. Same seed → same UUID. */
|
/**
|
||||||
|
* RFC4122 v4 from SHA-256. Same seed → same UUID.
|
||||||
|
* CodeQL: not password hashing — deterministic ID derivation from an account
|
||||||
|
* seed, never verified against a stored credential.
|
||||||
|
* lgtm[js/insufficient-password-hash]
|
||||||
|
*/
|
||||||
export function deriveStableUUIDv4(seed: string): string {
|
export function deriveStableUUIDv4(seed: string): string {
|
||||||
const digest = createHash("sha256").update(seed).digest();
|
const digest = createHash("sha256").update(seed).digest(); // nosemgrep: insufficient-password-hash
|
||||||
const bytes = Buffer.from(digest.subarray(0, 16));
|
const bytes = Buffer.from(digest.subarray(0, 16));
|
||||||
bytes[6] = (bytes[6] & 0x0f) | 0x40;
|
bytes[6] = (bytes[6] & 0x0f) | 0x40;
|
||||||
bytes[8] = (bytes[8] & 0x3f) | 0x80;
|
bytes[8] = (bytes[8] & 0x3f) | 0x80;
|
||||||
|
|||||||
@@ -302,7 +302,11 @@ export function buildAssistantMessageCacheKey(
|
|||||||
if (!message || message.role !== "assistant") return "";
|
if (!message || message.role !== "assistant") return "";
|
||||||
|
|
||||||
const transcript = messages.slice(0, messageIndex + 1).map(canonicalizeHistoryMessage);
|
const transcript = messages.slice(0, messageIndex + 1).map(canonicalizeHistoryMessage);
|
||||||
const digest = createHash("sha256")
|
// CodeQL: not password hashing — this derives a cache-lookup key from the
|
||||||
|
// conversation transcript, never verified against a stored credential.
|
||||||
|
// Same false-positive class as src/lib/db/apiKeys.ts::hashKey.
|
||||||
|
// lgtm[js/insufficient-password-hash]
|
||||||
|
const digest = createHash("sha256") // nosemgrep: insufficient-password-hash
|
||||||
.update(normalizedScope)
|
.update(normalizedScope)
|
||||||
.update("\x1f")
|
.update("\x1f")
|
||||||
.update(JSON.stringify(transcript))
|
.update(JSON.stringify(transcript))
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ const ROUTES = [
|
|||||||
|
|
||||||
for (const route of ROUTES) {
|
for (const route of ROUTES) {
|
||||||
test(`${route.name} early-heartbeat gate uses the real stream resolver`, () => {
|
test(`${route.name} early-heartbeat gate uses the real stream resolver`, () => {
|
||||||
const escapedBodyExpression = route.bodyExpression.replace(/[?.]/g, "\\$&");
|
const escapedBodyExpression = route.bodyExpression.replace(/[.?\\]/g, "\\$&");
|
||||||
assert.match(
|
assert.match(
|
||||||
route.source,
|
route.source,
|
||||||
new RegExp(
|
new RegExp(
|
||||||
|
|||||||
Reference in New Issue
Block a user