Skip to content

Stop logging the Google Maps API key; archive security-alerts-2026-10 - #64

Merged
BlancaMunizaga merged 2 commits into
devfrom
BlancaMunizaga/security-alerts-followup
Oct 7, 2026
Merged

BlancaMunizaga merged 2 commits into
devfrom
BlancaMunizaga/security-alerts-followup

Conversation

@BlancaMunizaga

Copy link
Copy Markdown
Collaborator

Follow-up to #63: triages the first CodeQL results, fixes the one real finding, and archives the OpenSpec change security-alerts-2026-10.

Fix: the Google Maps API key no longer reaches the logs

CodeQL (py/clear-text-logging-sensitive-data) flagged the satellite image's debug line, which logged the full Static Maps URL, including key= and signature=. That line only appears at DEBUG.

The same method had a second path, active at the default INFO level, which CodeQL didn't flag. When Google answered with an HTTP error (an invalid key, an exhausted quota), raise_for_status() raised httpx.HTTPStatusError. Its message contains the URL, and it was logged at ERROR and chained into the traceback. The client only ever got a generic 500, but the server logs had the key.

Now:

  • the debug line logs only the center, zoom and size;
  • an HTTP error logs and raises only its status code, with from None.

A new test fails without the fix and checks that neither the logs nor the raised error contain the key or the signature.

Archive of security-alerts-2026-10

  • New spec repository-security-scanning:
    • secret scanning with push protection;
    • CodeQL default setup for Python, JS/TS and Actions, which is not a required check.
  • automated-dependency-updates: every alert is fixed or dismissed with a reason, and dependencies outside Dependabot's reach are listed.
  • frontend-dependency-toolchain: rules for tarballs from outside the registry and for scoped overrides.
  • docs/branch_protection.md: a new "Security scanning" section. The CHANGELOG's Security section is updated too.

Outcome recorded in the tasks

Verified

  • 282 API tests pass, and ruff, black and mypy are clean.
  • openspec validate --specs passes.

CodeQL (py/clear-text-logging-sensitive-data) flagged the satellite
image's debug line, which logged the full Static Maps URL with `key=` and
`signature=`. It now logs only center, zoom and size.

The same method had a second path CodeQL didn't flag, live at the default
INFO level: an HTTP error from Google raised httpx.HTTPStatusError, whose
message holds the URL; it was logged at ERROR and chained into the
traceback. It now logs and raises only the status code, `from None`.

The new test fails without the fix (the chained HTTPStatusError carried
the key) and checks neither the logs nor the error contain it.
- new spec repository-security-scanning (secret scanning with push
  protection, CodeQL; not a required check), with its Purpose
- automated-dependency-updates: alerts are fixed or dismissed with a
  reason; dependencies outside Dependabot's reach are listed
- frontend-dependency-toolchain: registry-external tarballs and scoped
  overrides
- docs/branch_protection.md: "Security scanning"; CHANGELOG Security
- tasks record the post-merge outcomes: 30 -> 0 Dependabot alerts (the
  xlsx ones closed on their own), orphaned Dependabot PRs closed, #58,
  #57 and #59 merged, scanning enabled, CodeQL #1-#2 dismissed as false
  positives and #3 fixed. 6.3 stays open for #60, a routine update
@BlancaMunizaga
BlancaMunizaga merged commit 208b7b8 into dev Oct 7, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant