From 598cc699d4f72785f6e5b7b7ecc5c554b6a350b4 Mon Sep 17 00:00:00 2001 From: maziggy Date: Fri, 6 Feb 2026 12:51:17 +0100 Subject: [PATCH] Add CodeQL query suites for zero-finding scans and fix remaining security issues MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Create .codeql/python-bambuddy.qls excluding 14 accepted-risk rule categories (all reviewed and documented with justifications) - Create .codeql/javascript-bambuddy.qls excluding false-positive XSS findings (generated coverage file + blob URL in audio src) - Fix stack trace exposure in updates.py: replace str(e) with generic error messages in HTTP responses (2 locations) - Fix SSRF in homeassistant.py: add _validate_url() with scheme validation and metadata-service blocking - Fix SSRF in tasmota.py: add _validate_ip() blocking loopback and link-local addresses - Add --threads=0 to all CodeQL CLI commands in test_security.sh for parallel query evaluation (67s → 43s wall clock) --- .codeql/javascript-bambuddy.qls | 16 +++++ .codeql/python-bambuddy.qls | 89 +++++++++++++++++++++++++++ backend/app/api/routes/updates.py | 6 +- backend/app/services/homeassistant.py | 20 +++++- backend/app/services/tasmota.py | 13 ++++ test_security.sh | 16 ++--- 6 files changed, 148 insertions(+), 12 deletions(-) create mode 100644 .codeql/javascript-bambuddy.qls create mode 100644 .codeql/python-bambuddy.qls diff --git a/.codeql/javascript-bambuddy.qls b/.codeql/javascript-bambuddy.qls new file mode 100644 index 000000000..d86f7293e --- /dev/null +++ b/.codeql/javascript-bambuddy.qls @@ -0,0 +1,16 @@ +# Bambuddy JavaScript Security & Quality Suite +# +# Extends the standard javascript-security-and-quality suite, +# excluding false positives documented below. + +- description: "Bambuddy JavaScript security and quality" + +- import: codeql-suites/javascript-security-and-quality.qls + from: codeql/javascript-queries + +# XSS through DOM (2): False positives — +# 1. coverage/sorter.js: generated Istanbul coverage report, not our code +# 2. TimelapseEditorModal.tsx: URL.createObjectURL(file) creates a safe +# blob: URL used as