Skip to content

fix(security): Hide exception text and bound HTML strip regex - #21

Merged
KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-errors-redos
Oct 6, 2026
Merged

KeiaiLab-PHIL merged 1 commit into
mainfrom
fix/codeql-errors-redos

Conversation

@KeiaiLab-PHIL

Copy link
Copy Markdown
Contributor

CodeQL py/stack-trace-exposure: order sync, flow execution and
directory batch registration returned str(exception) to API
clients. Return fixed messages instead; details stay in server
logs (logger.exception) and integration_logs.

CodeQL py/polynomial-redos: _strip_html used <[^>]+>, which is
O(n^2) on input like "<<<<...". Excluding '<' from the tag body
makes it linear. Measured on 100k '<': 6.0s before, 0.001s after.
Adds a regression test with that input.

🤖 Generated with Claude Code

CodeQL py/stack-trace-exposure: order sync, flow execution and
directory batch registration returned str(exception) to API
clients. Return fixed messages instead; details stay in server
logs (logger.exception) and integration_logs.

CodeQL py/polynomial-redos: _strip_html used <[^>]+>, which is
O(n^2) on input like "<<<<...". Excluding '<' from the tag body
makes it linear. Measured on 100k '<': 6.0s before, 0.001s after.
Adds a regression test with that input.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Signed-off-by: phil <phil@keiailab.com>
@KeiaiLab-PHIL
KeiaiLab-PHIL merged commit bc0b741 into main Oct 6, 2026
6 of 7 checks passed
@KeiaiLab-PHIL
KeiaiLab-PHIL deleted the fix/codeql-errors-redos branch October 6, 2026 01:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant