Objective
2 open CodeQL findings (alerts #30–#31, rule: "Clear-text logging of sensitive information") in scanner/rules/az_idn_006.py.
Current code
except ValueError:
logger.debug(
"AZ-IDN-006: Invalid endDateTime for app_id=%s key_id=%s: %r",
app_id,
key_id,
end_dt_str,
)
Analysis
app_id and key_id here are Azure AD application object ID and password-credential key ID — GUID identifiers, not the actual secret value (Microsoft Graph never returns the secret text itself after creation). This is very likely CodeQL's naming-heuristic flagging variables named key_id/cred near a "credential" context, not an actual secret leak.
Regardless of true/false-positive status, the identifiers aren't needed to debug an invalid-date-format warning, so the cleanest fix removes the trigger entirely rather than arguing the classification.
Scope
Acceptance criteria
Category
Security / Bug fix
Objective
2 open CodeQL findings (alerts #30–#31, rule: "Clear-text logging of sensitive information") in
scanner/rules/az_idn_006.py.Current code
Analysis
app_idandkey_idhere are Azure AD application object ID and password-credential key ID — GUID identifiers, not the actual secret value (Microsoft Graph never returns the secret text itself after creation). This is very likely CodeQL's naming-heuristic flagging variables namedkey_id/crednear a "credential" context, not an actual secret leak.Regardless of true/false-positive status, the identifiers aren't needed to debug an invalid-date-format warning, so the cleanest fix removes the trigger entirely rather than arguing the classification.
Scope
key_id(andapp_idif still flagged after removingkey_id) from thelogger.debug(...)call at the two flagged linesendDateTimevalues without the identifiersAcceptance criteria
scanner/rules/az_idn_006.pytests still passCategory
Security / Bug fix