Potential fix for code scanning alert no. 17: Information exposure through a stack trace

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
xixu-meandCopilot Autofix powered by AI authored and GitHub committed 2026-03-06 21:24:53 +08:00
1 parent cc3abf89c3
commit 7cfcee61ba
1 file changed
+4 -1
+4 -1
View File
@@ -262,7 +262,10 @@ export async function handleDockerAuth(request, url, config) {
try {
target = resolveDockerAuthTarget(url, config.PLATFORMS);
} catch (error) {
return createErrorResponse(error instanceof Error ? error.message : String(error), 400);
// Log internal error details server-side without exposing them to the client
console.error('Failed to resolve Docker auth target:', error);
// Return a generic error response to avoid leaking implementation details
return createErrorResponse('Invalid Docker authentication request', 400);
}
const upstreamUrl = config.PLATFORMS[target.platformKey];