SonarQube Security Hotspot: Using http protocol is insecure. Use https instead #709
Labels
No labels
automated
code-quality
component: admin dashboard
component: backend
component: billing
component: content management
component: faqs
component: game genres
component: game lists
component: game reviews
component: game search
component: games
component: internal notifications
component: platforms
component: security
component: tests
component: user api
component: user badges
component: user blogs
component: user consoles
component: user favorites
component: user friends
component: user notifications
component: user profiles
component: user site notifications
component: user wishlists
component: web design
dependencies
php
priority
high
priority
low
priority
medium
security-hotspot
source: codex
source: sonarqube
status
awaiting feedback
status
backlog
status
done
status
in progress
status
in queue
status
in review
status
needs codex review
status
needs investigation
status
wontfix
type: bug
type: documentation
type: feature
type: improvement
type: regression
type: task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MyVideoGameList/myvideogamelist.com#709
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
SonarQube security hotspot needs review.
SonarQube key:
bbb74390-e86b-45ba-8a1d-b87795cde491Category:
encrypt-dataVulnerability probability:
LOWLocation:
myvideogamelist:tests/Feature/AdminSidebarTest.php:29Message: Using http protocol is insecure. Use https instead
https://sonarqube.linuxbox.ninja/security_hotspots?id=myvideogamelist&hotspots=bbb74390-e86b-45ba-8a1d-b87795cde491
Reviewed and resolved the low-probability test-only hotspot by keeping the HTTPS webmail assertion and building the legacy non-HTTPS URL without embedding an http:// protocol literal in AdminSidebarTest.
Verification:
Committed and pushed as
bfc9303.