Skip to content

Drop credential identifiers from AZ-IDN-006 debug logging (CodeQL: clear-text logging) #178

Description

@TFT444

Objective

2 open CodeQL findings (alerts #30–#31, rule: "Clear-text logging of sensitive information") in scanner/rules/az_idn_006.py.

Current code

except ValueError:
    logger.debug(
        "AZ-IDN-006: Invalid endDateTime for app_id=%s key_id=%s: %r",
        app_id,
        key_id,
        end_dt_str,
    )

Analysis

app_id and key_id here are Azure AD application object ID and password-credential key ID — GUID identifiers, not the actual secret value (Microsoft Graph never returns the secret text itself after creation). This is very likely CodeQL's naming-heuristic flagging variables named key_id/cred near a "credential" context, not an actual secret leak.

Regardless of true/false-positive status, the identifiers aren't needed to debug an invalid-date-format warning, so the cleanest fix removes the trigger entirely rather than arguing the classification.

Scope

  • Remove key_id (and app_id if still flagged after removing key_id) from the logger.debug(...) call at the two flagged lines
  • Confirm the debug message remains useful for diagnosing malformed endDateTime values without the identifiers

Acceptance criteria

Category

Security / Bug fix

Activity

  1. added
    bugSomething isn't working
    priority: mediumShould be fixed soon but not blocking
    on Jul 12, 2026
  2. self-assigned this
    on Jul 12, 2026
  3. added a commit that references this issue on Jul 17, 2026
    9de0ce3
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingpriority: mediumShould be fixed soon but not blocking

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions