Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: @octokit-next/auth-token #79

Merged
merged 3 commits into from
Oct 5, 2022
Merged

feat: @octokit-next/auth-token #79

merged 3 commits into from
Oct 5, 2022

Conversation

gr2m
Copy link
Contributor

@gr2m gr2m commented Oct 5, 2022

part of #72

test('auth.hook(request, "GET /user")', async (t) => {
const expectedRequestHeaders = {
accept: "application/vnd.github.v3+json",
authorization: "token ghp_PersonalAccessToken01245678900000000",

Check failure

Code scanning / CodeQL

Hard-coded credentials

The hard-coded value "token ghp_PersonalAccessToken01245678900000000" is used as [authorization header](1).
const expectedRequestHeaders = {
accept: "application/vnd.github.v3+json",
authorization:
"bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJpYXQiOi0zMCwiZXhwIjo1NzAsImlzcyI6MX0.q3foRa78U3WegM5PrWLEh5N0bH1SD62OqW66ZYzArp95JBNiCbo8KAlGtiRENCIfBZT9ibDUWy82cI4g3F09mdTq3bD1xLavIfmTksIQCz5EymTWR5v6gL14LSmQdWY9lSqkgUG0XCFljWUglEP39H4yeHbFgdjvAYg3ifDS12z9oQz2ACdSpvxPiTuCC804HkPVw8Qoy0OSXvCkFU70l7VXCVUxnuhHnk8-oCGcKUspmeP6UdDnXk-Aus-eGwDfJbU2WritxxaXw6B4a3flTPojkYLSkPBr6Pi0H2-mBsW_Nvs0aLPVLKobQd4gqTkosX3967DoAG8luUMhrnxe8Q",

Check failure

Code scanning / CodeQL

Hard-coded credentials

The hard-coded value "bearer eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9.eyJpYXQiOi0zMCwiZXhwIjo1NzAsImlzcyI6MX0.q3foRa78U3WegM5PrWLEh5N0bH1SD62OqW66ZYzArp95JBNiCbo8KAlGtiRENCIfBZT9ibDUWy82cI4g3F09mdTq3bD1xLavIfmTksIQCz5EymTWR5v6gL14LSmQdWY9lSqkgUG0XCFljWUglEP39H4yeHbFgdjvAYg3ifDS12z9oQz2ACdSpvxPiTuCC804HkPVw8Qoy0OSXvCkFU70l7VXCVUxnuhHnk8-oCGcKUspmeP6UdDnXk-Aus-eGwDfJbU2WritxxaXw6B4a3flTPojkYLSkPBr6Pi0H2-mBsW_Nvs0aLPVLKobQd4gqTkosX3967DoAG8luUMhrnxe8Q" is used as [authorization header](1).
@gr2m gr2m added the Type: Feature New feature or request label Oct 5, 2022
@gr2m gr2m merged commit 8c6001d into main Oct 5, 2022
@gr2m gr2m deleted the 72/auth-token branch October 5, 2022 06:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Type: Feature New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant