Skip to content

Conversation

@dmytrotsko
Copy link
Contributor

@dmytrotsko dmytrotsko commented Aug 16, 2023

Summary:

Replaced old admin endpoint with Flask-Admin lib.
Added new internal endpoints for API Key registration and removal request. Added two new tables to track registration/removal requests. Moved /diagnostics route to the main.py.
Added general send_email function to the _common.py and reused it for sending emails in places where it is needed.

Prerequisites:

  • Branch is up-to-date with the branch to be merged with, i.e. dev
  • Build is successful
  • Code is cleaned up and formatted

To open admin page, first you need to login with admin password (/login endpoint). After that you will be redirected to the admin page.

Added new internal endpoints for API Key registration and removal request.
Added two new tables to track registration/removal requests.
Moved /diagnostics route to the main.py.
Added general `send_email` function to the _common.py and reused it for sending emails in places where it is needed.
@dmytrotsko dmytrotsko requested a review from melange396 August 16, 2023 04:46
@sonarqubecloud
Copy link

sonarqubecloud bot commented Sep 7, 2023

SonarCloud Quality Gate failed.    Quality Gate failed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot E 7 Security Hotspots
Code Smell A 2 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

idea Catch issues before they fail your Quality Gate with our IDE extension sonarlint SonarLint

@sonarqubecloud
Copy link

SonarCloud Quality Gate failed.    Quality Gate failed

Bug A 0 Bugs
Vulnerability E 1 Vulnerability
Security Hotspot E 7 Security Hotspots
Code Smell A 2 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

idea Catch issues before they fail your Quality Gate with our IDE extension sonarlint SonarLint

@sonarqubecloud
Copy link

Quality Gate Failed Quality Gate failed

Failed conditions

7 Security Hotspots
E Security Rating on New Code (required ≥ A)

See analysis details on SonarCloud

idea Catch issues before they fail your Quality Gate with our IDE extension SonarLint SonarLint

'serving_host': serving_host,
'database_host': db_host,
}
return make_response(json.dumps(response_data), 200, {'content-type': 'text/plain'})

Check failure

Code scanning / SonarCloud

Endpoints should not be vulnerable to reflected cross-site scripting (XSS) attacks

<!--SONAR_ISSUE_KEY:AYz9PbiQIwkbfW94DFVa-->Change this code to not reflect user-controlled data. <p>See more on <a href="https://sonarcloud.io/project/issues?id=cmu-delphi_delphi-epidata&issues=AYz9PbiQIwkbfW94DFVa&open=AYz9PbiQIwkbfW94DFVa&pullRequest=1263">SonarCloud</a></p>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant