github / github/codeql

False positive in Go / Golang context when logging using %T

Abierto
#18,926 1 comentario 0 reacciones 0 asignados Ver en GitHub
false-positive Go
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

[The warning](https://github.com/developerproductivity/costpuller/security/code-scanning/2) is "Clear-text logging of sensitive information", but what is actually logged is the _type_ of the variable which holds the information and not the information itself.

CodeQL correctly determines that a variable potentially holding a piece of sensitive information is [referenced in a `log.Fatalf()` call](https://github.com/developerproductivity/costpuller/blob/517634a461440261d5f0e5a3ccab0326e32c69a0/cloudability.go#L214-L214), but it misses the fact that the reference is processed using a `%T` format specifier which will result in the log receiving the _type_ of the data and not the _value_ of the data:

```go
apiKeyPair, ok := apiKeyPairAny.([]any)
if !ok {
log.Fatalf("Error reading Cloudability API keypair, expected an array, found %T",
apiKeyPairAny)
```

**Possible workaround**

I'm hoping that the following will suffice to work around the problem, but it's ugly and really shouldn't be necessary!

```go
log.Fatalf("Error reading Cloudability API keypair, expected an array, found %v",
reflect.TypeOf(apiKeyPairAny).String())
```

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.