feat: add webhook bearer auth support#619
Conversation
|
There are 1 test cases, failed count 0:
Reported by api-testing. |
| w.Write([]byte(err.Error())) | ||
| } | ||
| if err == nil { | ||
| w.Write(data) |
Check warning
Code scanning / CodeQL
Reflected cross-site scripting Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI about 1 year ago
To fix the reflected cross-site scripting vulnerability, we need to ensure that any user-controlled data is properly sanitized or escaped before being written to the HTTP response. In this case, we can use the html.EscapeString function from the html package to escape any potentially dangerous characters in the data variable before writing it to the response.
| @@ -40,2 +40,3 @@ | ||
| "github.com/gorilla/mux" | ||
| "html" | ||
| ) | ||
| @@ -353,3 +354,4 @@ | ||
| if err == nil { | ||
| w.Write(data) | ||
| escapedData := html.EscapeString(string(data)) | ||
| w.Write([]byte(escapedData)) | ||
| } else { |
Coverage summary from CodacySee diff coverage on Codacy
Coverage variation details
Coverage variation is the difference between the coverage for the head and common ancestor commits of the pull request branch: Diff coverage details
Diff coverage is the percentage of lines that are covered by tests out of the coverable lines that the pull request added or modified: See your quality gate settings Change summary preferencesCodacy stopped sending the deprecated coverage status on June 5th, 2024. Learn more |
|


What type of PR is this?
What this PR does / why we need it:
Which issue(s) this PR fixes:
Fixes #