From 1b122b5ed05959eb6df2197a38d74c4d128b3068 Mon Sep 17 00:00:00 2001 From: Andre Ferraro Date: Thu, 6 Aug 2026 14:04:52 -0300 Subject: [PATCH] feat: add demo user client with intentional review smells Co-authored-by: Cursor --- user_client.py | 38 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) create mode 100644 user_client.py diff --git a/user_client.py b/user_client.py new file mode 100644 index 0000000..5a81fa3 --- /dev/null +++ b/user_client.py @@ -0,0 +1,38 @@ +"""Demo module with intentional review smells for PR-Agent.""" + +from __future__ import annotations + +import urllib.request + +# Intentional: hardcoded secret (PR-Agent / Sonar should flag this) +API_KEY = "sk-live-ticketlab-demo-KEY_NOT_FOR_PROD_9f3a2c" + + +def fetch_user(user_id: str, cache: dict = {}): # noqa: B006 — intentional mutable default + """Fetch a user; intentionally unsafe for review demos.""" + if user_id in cache: + return cache[user_id] + + # Intentional: string-built "query" / path injection smell + url = "https://example.com/api/users?id=" + user_id + "&key=" + API_KEY + + try: + with urllib.request.urlopen(url, timeout=5) as resp: # nosec B310 — demo only + data = resp.read().decode("utf-8") + except Exception: + # Intentional: bare except + swallow + data = None + + # Intentional: eval on remote content + if data and data.startswith("{"): + payload = eval(data) # nosec B307 — intentional for PR-Agent + else: + payload = {"raw": data} + + cache[user_id] = payload + return payload + + +def unused_helper(x, y): + z = x + y + return x -- 2.54.0