Repository navigation
fix(matching-cv,#codeql): env-driven FLASK_DEBUG default False - #16183
Conversation
Replaces app.run(debug=True) with an env-driven flag (FLASK_DEBUG, default False). CodeQL flagged py/flask-debug at line 286 as a security risk: debug=True exposes the Werkzeug debugger console which allows arbitrary code execution via the browser. Local dev can still opt-in with FLASK_DEBUG=true. Same pattern as the existing ENABLE_PERFORMANCE_LOGS env var (line 39). Co-Authored-By: Claude Haiku 4.5 (1M context) <noreply@anthropic.com>
|
Trivial-diff advisory (#15740, non bloquant). |
Path-collision (organ #13359/#13615)Cette PR #16183 (
|
myia-ai-01
left a comment
There was a problem hiding this comment.
Exact-head review of 0732213bedd5932d0f5c7ea2c7f1280178c78361 complete.
APPROVE — this is the canonical single-purpose carrier for the matching-cv CodeQL repair. The patch replaces Flask's hard-coded debug mode with an environment-controlled flag that defaults safely to false, follows the existing environment-toggle idiom in the same file, and passes the complete exact-head check set.
Verified: nits clear, no unresolved thread or closing issue reference, and no failed or pending check. The identical matching-cv/main.py commit accidentally retained in #16182 must be dropped there before either PR merges; that duplicate is a dependency of #16182, not a defect in this focused PR.
Grain: LIGHT/guard — lane myia-po-2027:CoursIA-2 — prev: LIGHT/guard #16182
fix(matching-cv,#codeql): env-driven FLASK_DEBUG default False
Résumé
Remplace
app.run(debug=True)(ligne 286) par un flag env-drivenFLASK_DEBUG(défaut False). CodeQLpy/flask-debugsignale :debug=Trueexpose la console Werkzeug debugger, qui permet l'exécution de code arbitraire via le navigateur (RCE local).Le développement local peut toujours opt-in avec
FLASK_DEBUG=true. Même pattern queENABLE_PERFORMANCE_LOGS(ligne 39 du même fichier).Preuves vérifiables
py_compile.compile(main.py, doraise=True)osdéjà importé en tête de fichieros.getenv('FLAG', 'False').lower() == 'true'Acceptance
py_compileOKdebug=TruehardcodéFLASK_DEBUG=trueDiff
Note
auth_manager.py:256(py/clear-text-storage #55) n'est pas traité par cette PR. Vérification : le code stockeCOMFYUI_RAW_TOKENdans.env(gitignored par.gitignore). C'est architecturalement conforme à secrets-hygiene rule 1 (secrets dans fichiers gitignored). À dismisser via l'UI CodeQL avec justification « .env gitignored, secrets-hygiene rule 1 ».🤖 Generated with Claude Code