Skip to content

Potential fix for code scanning alert no. 6: Clear text storage of sensitive information - #1

Merged
albert-mueller merged 1 commit into
mainfrom
alert-autofix-6
Aug 5, 2026
Merged

Potential fix for code scanning alert no. 6: Clear text storage of sensitive information#1
albert-mueller merged 1 commit into
mainfrom
alert-autofix-6

Conversation

@albert-mueller

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/albert-mueller/albert-mueller.github.io/security/code-scanning/6

General fix: do not persist raw secrets in localStorage. Prefer not storing them at all, or store only non-sensitive metadata (such as selected provider). If persistence is required, use secure server-side storage and keep only a reference token client-side.

Best fix here without changing core translation functionality: keep runtime setApiKey(...) behavior (so translation still works in current session), but sanitize what is written to localStorage by removing secretKey/apiKey fields before JSON.stringify(...). This addresses all listed variants tied to cleartext storage while preserving existing UX as much as possible (service selection can still persist).
In others/translate/translate.js, replace the direct localStorage.setItem(... JSON.stringify(apiConfig)) calls with a redacted copy that keeps only non-secret fields (service, and optionally non-secret appId). Also avoid calling saveApiConfig with secrets in the bottom section; pass empty strings there so no secret is persisted via that path.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…nsitive information

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Signed-off-by: Albert Müller <p8bpg9zrw7@privaterelay.appleid.com>
@albert-mueller
albert-mueller marked this pull request as ready for review August 5, 2026 23:12
@albert-mueller
albert-mueller merged commit 1ed1e5a into main Aug 5, 2026
2 checks passed
if (safeApiConfig.google) {
delete safeApiConfig.google.apiKey;
}
localStorage.setItem('translateApiConfig', JSON.stringify(safeApiConfig));
if (safeApiConfig.google) {
delete safeApiConfig.google.apiKey;
}
localStorage.setItem('translateApiConfig', JSON.stringify(safeApiConfig));
@albert-mueller
albert-mueller deleted the alert-autofix-6 branch August 6, 2026 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants