"""Demo module with intentional review smells for PR-Agent.""" from __future__ import annotations import urllib.request # Intentional: hardcoded secret (PR-Agent / Sonar should flag this) API_KEY = "sk-live-ticketlab-demo-KEY_NOT_FOR_PROD_9f3a2c" def fetch_user(user_id: str, cache: dict = {}): # noqa: B006 — intentional mutable default """Fetch a user; intentionally unsafe for review demos.""" if user_id in cache: return cache[user_id] # Intentional: string-built "query" / path injection smell url = "https://example.com/api/users?id=" + user_id + "&key=" + API_KEY try: with urllib.request.urlopen(url, timeout=5) as resp: # nosec B310 — demo only data = resp.read().decode("utf-8") except Exception: # Intentional: bare except + swallow data = None # Intentional: eval on remote content if data and data.startswith("{"): payload = eval(data) # nosec B307 — intentional for PR-Agent else: payload = {"raw": data} cache[user_id] = payload return payload def unused_helper(x, y): z = x + y return x