First SonarCloud scan (#149's second half) reported 118 issues. Triaged: 8 are valid across five distinct fixes, 110 are false positives in four groups.
** Valid
-
Protocol-relative redirect (
gosecurity:S5146, BLOCKER ×2).internal/httpd/pages.go:80and:107passr.URL.Pathtohttp.Redirectunnormalised, while the siblingreqPathon line 71 is alreadypath.Cleaned. A request for//evil.exampleproducesLocation: //evil.example/, which a browser follows off-site — confirmed by runninghttp.Redirectdirectly. Reaching it needs a public repo whose name is the target host, and repo names permit dots, soevil.comis legal. Low exploitability, real mechanism. -
Predictable runner workspace (
go:S5445, CRITICAL).cmd/gitbay-runner/main.godefaults-workdirto/tmp/gitbay-runnerand creates it0o755withMkdirAll, which succeeds against a directory someone else already owns. bay1 is not exposed — its unit passes-workdir /var/lib/gitbay-runner/work— but the default is what anyone gets running the binary by hand, and this is the process that executes untrusted build steps. -
Cookie clearing drops its attributes (
go:S3330×2,go:S2092×2). Logout (accounts.go:106) and flash consumption (flash.go:38) clear with a bare cookie while the setting calls specifyHttpOnly,SameSiteand conditionalSecure. Deletion still works, so this is consistency rather than a live bug — four findings for a two-line change, and it stops a reviewer comparing the two paths and wondering. -
Unlabelled input (
Web:InputWithoutLabelCheck).settings.htmltopics-remove has neitheridnor label while the input above it has both. A placeholder is not an accessible name. The class #133 fixed elsewhere and missed here. -
PL/SQL rules on SQLite migrations — config, not code.
internal/store/migrations/**is analysed as PL/SQL, where''isNULL; SQLite's is not, and both flagged lines compare to''onNOT NULL DEFAULT ''columns. Excluded insonar-project.propertiesso it does not recur.
** Dismissed, with reasons recorded in the scan
go:S4036×74 —PATHis systemd's and/usris read-only underProtectSystem, including for build steps.go:S2077×31 — all 31 checked: 29 join adjacent literals, 2 join aconstand two parameters whose only callers pass literals. No user value reaches SQL text.go:S2092×2 (the setting calls) —Secureis set, conditionally on TLS being on.Web:S5256×1 — the diff table is a code layout with no header semantics.
Worth deciding separately: 63% of the dashboard is go:S4036, and a dashboard that is mostly permanent noise stops being read — the same failure mode as #152. Resolving git once with exec.LookPath at startup would remove all 74 and turn a missing git into an explicit startup failure. Mechanical across ~74 call sites; not done here.
referenced in commit 6b5f1f02e9 by cmc: pages: a directory redirect cannot leave the site
2026-09-05 00:02 UTC