github / github/codeql

Incomplete naming schema and API usage patterns in py/insecure-cookie

Đang mở
#21,647 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

1. The existing `cookie.isSensitive` predicate seems to miss common modern authentication token patterns. I have found some and listed them below.
2. The rule currently relies primarily on specific framework methods (e.g., set_cookie). It ignores direct HTTP manipulation, which is also very common.

code example:
```python
from flask import Flask, Response, make_response

app = Flask(__name__)

@app.route("/login")
def login():
resp = make_response("Logged in")
resp.set_cookie("authKey", "secret123") # $ Alert[py/insecure-cookie]
resp.set_cookie("accessToken", "secret123") # $ missing
resp.set_cookie("access_token", "secret123") # missing
resp.set_cookie("auth_token", "secret123") # missing
resp.set_cookie("jwt", "secret123") # $ missing
resp.set_cookie("oauth_token", "secret123") # $ missing

# cannot support this
resp.headers.add("Set-Cookie", "authKey=secret123") # missing

# This is also common, but it seems more difficult to support this.
from http.cookies import SimpleCookie
resp = make_response("Logged in")
cookie = SimpleCookie()
cookie["session"]['authKey'] = "secret123" # missing
# cookie["session"]["httponly"] = True
# cookie["session"]["secure"] = True
for key, morsel in cookie.items():
resp.headers.add('Set-Cookie', morsel.OutputString())
return resp
```

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Bắt đầu từ rule py/insecure-cookie và kiểm tra predicate cookie.isSensitive cùng cách xử lý set_cookie được mô tả trong issue. So sánh các tên token được liệt kê và các ví dụ Set-Cookie trực tiếp với hành vi hiện tại; công việc được hoàn tất khi các mẫu cookie xác thực được hỗ trợ được phát hiện mà không chỉ dựa vào các phương thức của framework.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
security
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
52/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.