Satisfy gosec on the proxy count and the request log
G115: the trusted-proxy count is stored as an int64 instead of narrowing it to int32. G706: the request logger and serverError quote the request method and route; the logger's remaining taint comes from the wrapped response writer, so it carries a justified nosec like the other quoted log lines. Claude-Session: https://claude.ai/code/session_016mBLURvJoMuUEr9cB2RpUN
This commit is contained in:
@@ -447,6 +447,6 @@ func requestLogger(next http.Handler) http.Handler {
|
||||
if status == 0 {
|
||||
status = http.StatusOK
|
||||
}
|
||||
log.Printf("%s %s %d %dB %s", r.Method, route, status, ww.BytesWritten(), time.Since(start).Round(time.Millisecond))
|
||||
log.Printf("%q %q %d %dB %s", r.Method, route, status, ww.BytesWritten(), time.Since(start).Round(time.Millisecond)) // #nosec G706 -- method and route are %q-quoted, the route is a registered pattern, the rest are numbers
|
||||
})
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user