From 09a405123a7f739736fdb0cf5959bc9d769376ce Mon Sep 17 00:00:00 2001 From: maziggy Date: Mon, 2 Feb 2026 08:18:54 +0100 Subject: [PATCH] Document intentional JWT secret storage (CodeQL Alert #69) Add explanatory comment for CodeQL alert about clear-text storage of JWT secret. This is intentional and secure: - JWT secrets must be readable by the application - File permissions set to 0600 (owner read/write only) - Standard practice for self-hosted apps (same as .env files) The alert should be dismissed in GitHub Security tab as "Won't fix". --- backend/app/core/auth.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/backend/app/core/auth.py b/backend/app/core/auth.py index 2dc5ec4e9..0386c1879 100644 --- a/backend/app/core/auth.py +++ b/backend/app/core/auth.py @@ -72,7 +72,10 @@ def _get_jwt_secret() -> str: # Try to save it try: data_dir.mkdir(parents=True, exist_ok=True) - secret_file.write_text(new_secret) + # Note: CodeQL flags this as "clear-text storage of sensitive information" but this is + # intentional and secure - JWT secrets must be readable by the app, we set 0600 permissions, + # and this is standard practice for self-hosted applications (same as .env files). + secret_file.write_text(new_secret) # nosec B105 - intentional secure storage # Restrict permissions (owner read/write only) secret_file.chmod(0o600) logger.info("Generated new JWT secret and saved to %s", secret_file)