SonarQube Security Hotspot: Make sure this weak hash algorithm is not used in a sensitive context here. #126
Labels
No labels
automated
code-quality
component: admin dashboard
component: backend
component: billing
component: content management
component: faqs
component: game genres
component: game lists
component: game reviews
component: game search
component: games
component: internal notifications
component: platforms
component: security
component: tests
component: user api
component: user badges
component: user blogs
component: user consoles
component: user favorites
component: user friends
component: user notifications
component: user profiles
component: user site notifications
component: user wishlists
component: web design
dependencies
php
priority
high
priority
low
priority
medium
security-hotspot
source: codex
source: sonarqube
status
awaiting feedback
status
backlog
status
done
status
in progress
status
in queue
status
in review
status
needs codex review
status
needs investigation
status
wontfix
type: bug
type: documentation
type: feature
type: improvement
type: regression
type: task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MyVideoGameList/myvideogamelist.com#126
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
SonarQube security hotspot needs review.
SonarQube key:
e2409b9a-a58e-47d1-955e-39c293bc402cCategory:
othersVulnerability probability:
LOWLocation:
myvideogamelist:tests/Feature/Auth/EmailVerificationTest.php:44Message: Make sure this weak hash algorithm is not used in a sensitive context here.
https://sonarqube.linuxbox.ninja/security_hotspots?id=myvideogamelist&hotspots=e2409b9a-a58e-47d1-955e-39c293bc402c
Reviewed and fixed by
b4ac348. This hotspot pointed at the second direct sha1() call in tests/Feature/Auth/EmailVerificationTest.php, on the invalid-hash verification path. The prior email verification hotspot fix removed both direct sha1() calls from this test: valid verification now uses Laravel's real VerifyEmail notification URL, and the invalid case uses a signed URL with a plain nonmatching hash value. Verified again with php artisan test --compact tests/Feature/Auth/EmailVerificationTest.php (3 passed, 6 assertions).