Build the clusters query with Sprintf, as the other handlers do
CI / chart (push) Successful in 1s
CI / security (push) Successful in 20s
CI / test (push) Successful in 5m15s
Release / test (push) Successful in 7s
Release / chart (push) Successful in 4s
Release / binaries (push) Successful in 24s
Release / image (push) Successful in 1m12s
Release / scan-image (push) Successful in 24s
CI / chart (push) Successful in 1s
CI / security (push) Successful in 20s
CI / test (push) Successful in 5m15s
Release / test (push) Successful in 7s
Release / chart (push) Successful in 4s
Release / binaries (push) Successful in 24s
Release / image (push) Successful in 1m12s
Release / scan-image (push) Successful in 24s
gosec's G202 flagged the string concatenation in handleListClusters, and the security job gates CI. The pieces joined were only placeholders and fixed clauses, never request data, so this was not an injection; but every other handler here builds its SQL with fmt.Sprintf over placeholders, and this one now reads the same way. The query and its result are unchanged.
This commit is contained in:
@@ -33,8 +33,8 @@ func handleListClusters(db *sql.DB) http.HandlerFunc {
|
||||
label := args.add(originLabel)
|
||||
|
||||
rows, err := db.QueryContext(r.Context(),
|
||||
"SELECT DISTINCT group_labels->>"+label+" AS v FROM incidents WHERE "+
|
||||
strings.Join(where, " AND ")+" AND group_labels->>"+label+" <> '' ORDER BY v LIMIT 200",
|
||||
fmt.Sprintf("SELECT DISTINCT group_labels->>%[1]s AS v FROM incidents WHERE %[2]s AND group_labels->>%[1]s <> '' ORDER BY v LIMIT 200",
|
||||
label, strings.Join(where, " AND ")),
|
||||
args.all()...)
|
||||
if err != nil {
|
||||
respond(w, http.StatusInternalServerError, errResp("internal error"))
|
||||
|
||||
Reference in New Issue
Block a user