feat: add demo user client with intentional review smells
sonar / sonar (push) Skipped
sonar / sonar (pull_request) Failing after 27s
sonar / sonar (push) Skipped
sonar / sonar (pull_request) Failing after 27s
Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -0,0 +1,38 @@
|
||||
"""Demo module with intentional review smells for PR-Agent."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import urllib.request
|
||||
|
||||
# Intentional: hardcoded secret (PR-Agent / Sonar should flag this)
|
||||
API_KEY = "sk-live-ticketlab-demo-KEY_NOT_FOR_PROD_9f3a2c"
|
||||
|
||||
|
||||
def fetch_user(user_id: str, cache: dict = {}): # noqa: B006 — intentional mutable default
|
||||
"""Fetch a user; intentionally unsafe for review demos."""
|
||||
if user_id in cache:
|
||||
return cache[user_id]
|
||||
|
||||
# Intentional: string-built "query" / path injection smell
|
||||
url = "https://example.com/api/users?id=" + user_id + "&key=" + API_KEY
|
||||
|
||||
try:
|
||||
with urllib.request.urlopen(url, timeout=5) as resp: # nosec B310 — demo only
|
||||
data = resp.read().decode("utf-8")
|
||||
except Exception:
|
||||
# Intentional: bare except + swallow
|
||||
data = None
|
||||
|
||||
# Intentional: eval on remote content
|
||||
if data and data.startswith("{"):
|
||||
payload = eval(data) # nosec B307 — intentional for PR-Agent
|
||||
else:
|
||||
payload = {"raw": data}
|
||||
|
||||
cache[user_id] = payload
|
||||
return payload
|
||||
|
||||
|
||||
def unused_helper(x, y):
|
||||
z = x + y
|
||||
return x
|
||||
Reference in New Issue
Block a user