Fix all high and medium severity security issues found by Bandit

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-02-07 19:35:40 +00:00
parent 68143a2689
commit edd1acb3a1
13 changed files with 55 additions and 23 deletions
+6 -4
View File
@@ -53,7 +53,7 @@ async def exchange_dropbox_token(
# Make the token request
logger.info("Sending POST request to Dropbox for token exchange")
response = requests.post(token_url, data=payload)
response = requests.post(token_url, data=payload, timeout=settings.http_request_timeout)
# Check if the request was successful
logger.info(f"Token exchange response status: {response.status_code}")
@@ -176,7 +176,8 @@ async def test_dropbox_token(request: Request):
headers = {"Authorization": f"Bearer {settings.dropbox_refresh_token}"}
response = requests.post(
"https://api.dropboxapi.com/2/users/get_current_account",
headers=headers
headers=headers,
timeout=settings.http_request_timeout
)
# If token is invalid, try refreshing it
@@ -192,7 +193,7 @@ async def test_dropbox_token(request: Request):
"client_secret": settings.dropbox_app_secret
}
refresh_response = requests.post(refresh_url, data=refresh_data)
refresh_response = requests.post(refresh_url, data=refresh_data, timeout=settings.http_request_timeout)
if refresh_response.status_code != 200:
logger.error(f"Failed to refresh Dropbox token: {refresh_response.text}")
@@ -209,7 +210,8 @@ async def test_dropbox_token(request: Request):
headers = {"Authorization": f"Bearer {access_token}"}
response = requests.post(
"https://api.dropboxapi.com/2/users/get_current_account",
headers=headers
headers=headers,
timeout=settings.http_request_timeout
)
if response.status_code != 200:
+1 -1
View File
@@ -53,7 +53,7 @@ async def exchange_google_drive_token(
# Make the token request
logger.info("Sending POST request to Google for token exchange")
response = requests.post(token_url, data=payload)
response = requests.post(token_url, data=payload, timeout=settings.http_request_timeout)
# Check if the request was successful
logger.info(f"Token exchange response status: {response.status_code}")
+3 -3
View File
@@ -55,7 +55,7 @@ async def exchange_onedrive_token(
# Make the token request
logger.info("Sending POST request to Microsoft for token exchange")
response = requests.post(token_url, data=payload)
response = requests.post(token_url, data=payload, timeout=settings.http_request_timeout)
# Check if the request was successful
logger.info(f"Token exchange response status: {response.status_code}")
@@ -139,7 +139,7 @@ async def test_onedrive_token(request: Request):
"scope": "offline_access Files.ReadWrite"
}
response = requests.post(token_url, data=refresh_data)
response = requests.post(token_url, data=refresh_data, timeout=settings.http_request_timeout)
if response.status_code != 200:
logger.error(f"Failed to refresh OneDrive token: {response.text}")
@@ -193,7 +193,7 @@ async def test_onedrive_token(request: Request):
user_info_url = "https://graph.microsoft.com/v1.0/me"
headers = {"Authorization": f"Bearer {access_token}"}
user_response = requests.get(user_info_url, headers=headers)
user_response = requests.get(user_info_url, headers=headers, timeout=settings.http_request_timeout)
if user_response.status_code != 200:
logger.error(f"OneDrive token test failed: {user_response.status_code} {user_response.text}")
+2 -1
View File
@@ -23,7 +23,8 @@ async def whoami_handler(request: Request):
raise HTTPException(status_code=400, detail="User has no email in session")
# Generate Gravatar URL from email
email_hash = md5(email.strip().lower().encode()).hexdigest()
# MD5 is used here for Gravatar's URL generation (not for security), so usedforsecurity=False
email_hash = md5(email.strip().lower().encode(), usedforsecurity=False).hexdigest()
gravatar_url = f"https://www.gravatar.com/avatar/{email_hash}?d=identicon"
# Add the gravatar URL to the user object instead of creating a new response