Repository navigation
Potential fix for code scanning alert no. 13: Information exposure through an exception - #728
Merged
Merged
Conversation
Github security review found issues with this exmample. As it's only an example and not live code, it's considered to be a very low-priority security issue. Also, the file i smost likely not up to 2026-standards, so I've added a big disclaimer. Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
tobixen
force-pushed
the
security-fixes
branch
from
October 7, 2026 22:30
c08b9fc to
2192450
Compare
tobixen
marked this pull request as ready for review
October 7, 2026 23:20
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note: I did not write the text below, Github Copilot did on my behalf and without allowing me to review it. The file in question is an example file, already with a disclaimer at the top that the code has not been tested by the maintainer. The code is also likely to be far away from what's considered "best current practices" in 2026 and beyond. I will emphasize this in another commit.
Potential fix for https://github.com/python-caldav/caldav/security/code-scanning/13
The correct fix is to stop exposing exception content in API responses and replace it with a generic error payload, while preserving diagnostics in server logs. This keeps functionality (client still receives a 500 on failure) without leaking internals.
Best single fix in
examples/google-flask.py:loggingimport and configure a module logger.serve_calendar_ics, change theexcept Exception as ex:block to:logger.exception(...)(includes traceback),"An internal error has occurred"), with status500.Suggested fixes powered by Copilot Autofix. Review carefully before merging.