Document intentional JWT secret storage (CodeQL Alert #69)

Add explanatory comment for CodeQL alert about clear-text storage
of JWT secret. This is intentional and secure:
- JWT secrets must be readable by the application
- File permissions set to 0600 (owner read/write only)
- Standard practice for self-hosted apps (same as .env files)

The alert should be dismissed in GitHub Security tab as "Won't fix".
This commit is contained in:
maziggy
2026-02-02 08:20:30 +01:00
parent 49b2252432
commit 09a405123a
+4 -1
View File
@@ -72,7 +72,10 @@ def _get_jwt_secret() -> str:
# Try to save it
try:
data_dir.mkdir(parents=True, exist_ok=True)
secret_file.write_text(new_secret)
# Note: CodeQL flags this as "clear-text storage of sensitive information" but this is
# intentional and secure - JWT secrets must be readable by the app, we set 0600 permissions,
# and this is standard practice for self-hosted applications (same as .env files).
secret_file.write_text(new_secret) # nosec B105 - intentional secure storage
# Restrict permissions (owner read/write only)
secret_file.chmod(0o600)
logger.info("Generated new JWT secret and saved to %s", secret_file)