From 71f11618fcad7d7214e059bc172bb48b026174c7 Mon Sep 17 00:00:00 2001 From: Xi Xu Date: Fri, 6 Mar 2026 21:24:53 +0800 Subject: [PATCH] Potential fix for code scanning alert no. 17: Information exposure through a stack trace Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> --- src/protocols/docker.js | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/protocols/docker.js b/src/protocols/docker.js index 6ccb7e5..d583760 100644 --- a/src/protocols/docker.js +++ b/src/protocols/docker.js @@ -262,7 +262,10 @@ export async function handleDockerAuth(request, url, config) { try { target = resolveDockerAuthTarget(url, config.PLATFORMS); } catch (error) { - return createErrorResponse(error instanceof Error ? error.message : String(error), 400); + // Log internal error details server-side without exposing them to the client + console.error('Failed to resolve Docker auth target:', error); + // Return a generic error response to avoid leaking implementation details + return createErrorResponse('Invalid Docker authentication request', 400); } const upstreamUrl = config.PLATFORMS[target.platformKey];