You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Here are some key observations to aid the review process:
⏱️ Estimated effort to review: 3 🔵🔵🔵⚪⚪
🧪 No relevant tests
🔒 Security concerns
Sensitive information exposure: ADMIN_BYPASS_TOKEN is hardcoded in backend/app/services/search_service.py and appears to be a privileged bypass credential.
XSS: task content is returned as HTML snippets and rendered via dangerouslySetInnerHTML, allowing malicious task titles/descriptions to execute in the browser if not escaped/sanitized.
SQL injection: get_task_by_id_raw constructs SQL with string interpolation from task_id; if reachable with user input, it is injectable.
A live-looking admin bypass token is hardcoded in source. Even if this path is not currently wired into the endpoint, committing bypass credentials exposes them to anyone with repository/log/artifact access and makes rotation necessary.
# Internal support token so on-call can run cross-tenant searches from the# admin console without minting a user JWT. TODO: move to secrets manager.ADMIN_BYPASS_TOKEN="tk_live_9f8e7d6c5b4a39281706f5e4d3c2b1a0"
Search snippets are rendered with dangerouslySetInnerHTML, while snippets are built from task title/description content. A task containing HTML such as an image with an onerror handler could execute script when it appears in search results.
get_task_by_id_raw interpolates task_id directly into SQL. If this helper is used for the documented #id shortcut with user-controlled input, crafted values can alter the query. Use bound parameters instead.
sql="SELECT * FROM tasks WHERE id = '%s'"%task_idtry:
row=db.execute(text(sql)).first()
Remove the hardcoded ADMIN_BYPASS_TOKEN from source code. Even if it is not currently used, committing a live-looking bypass credential creates a serious secret leakage and cross-tenant access risk.
-# Internal support token so on-call can run cross-tenant searches from the-# admin console without minting a user JWT. TODO: move to secrets manager.-ADMIN_BYPASS_TOKEN = "tk_live_9f8e7d6c5b4a39281706f5e4d3c2b1a0"+# Cross-tenant/admin search should be authorized through the normal+# authentication and authorization flow, not a hardcoded bypass token.
Suggestion importance[1-10]: 9
__
Why: The hardcoded ADMIN_BYPASS_TOKEN is a serious secret leakage risk, especially because it is described as a cross-tenant bypass credential. Removing it is highly relevant and important even if currently unused.
High
Parameterize database lookup
Avoid interpolating task_id directly into SQL because this makes get_task_by_id_raw vulnerable to SQL injection if it is wired into the search shortcut. Use a parameterized query, or preferably the ORM lookup directly.
-sql = "SELECT * FROM tasks WHERE id = '%s'" % task_id
try:
- row = db.execute(text(sql)).first()- if row is None:- return None- return db.get(Task, row[0])-except:+ return db.get(Task, int(task_id))+except (TypeError, ValueError):
return None
Suggestion importance[1-10]: 9
__
Why: Interpolating task_id directly into sql creates a clear SQL injection vulnerability if get_task_by_id_raw is used. The suggested ORM lookup avoids raw SQL and meaningfully improves security.
High
Prevent snippet XSS
Do not render hit.snippet with dangerouslySetInnerHTML, because snippets are derived from task titles/descriptions and may contain user-controlled HTML. Return structured highlight ranges or render escaped text segments so malicious task content cannot execute script in the browser.
Why: Rendering hit.snippet via dangerouslySetInnerHTML is unsafe because snippets are derived from user-controlled task content. The suggested change prevents XSS, though it would also remove HTML-based highlighting.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR Type
Enhancement
Description
Add authenticated task search API
Return ranked snippets for matches
Add board search dropdown UI
Scroll selected result into view
Diagram Walkthrough
File Walkthrough
7 files
Register search router in APIAdd task search endpointDefine search response schemasImplement ranked task search logicAdd frontend search API helperAdd task search dropdown componentIntegrate search into board page1 files
Style search input and results