sonar / sonar (push) Skipped
sonar / sonar (pull_request) Failing after 27s
Co-authored-by: Cursor <cursoragent@cursor.com>
39 lines
1.1 KiB
Python
39 lines
1.1 KiB
Python
"""Demo module with intentional review smells for PR-Agent."""
|
|
|
|
from __future__ import annotations
|
|
|
|
import urllib.request
|
|
|
|
# Intentional: hardcoded secret (PR-Agent / Sonar should flag this)
|
|
API_KEY = "sk-live-ticketlab-demo-KEY_NOT_FOR_PROD_9f3a2c"
|
|
|
|
|
|
def fetch_user(user_id: str, cache: dict = {}): # noqa: B006 — intentional mutable default
|
|
"""Fetch a user; intentionally unsafe for review demos."""
|
|
if user_id in cache:
|
|
return cache[user_id]
|
|
|
|
# Intentional: string-built "query" / path injection smell
|
|
url = "https://example.com/api/users?id=" + user_id + "&key=" + API_KEY
|
|
|
|
try:
|
|
with urllib.request.urlopen(url, timeout=5) as resp: # nosec B310 — demo only
|
|
data = resp.read().decode("utf-8")
|
|
except Exception:
|
|
# Intentional: bare except + swallow
|
|
data = None
|
|
|
|
# Intentional: eval on remote content
|
|
if data and data.startswith("{"):
|
|
payload = eval(data) # nosec B307 — intentional for PR-Agent
|
|
else:
|
|
payload = {"raw": data}
|
|
|
|
cache[user_id] = payload
|
|
return payload
|
|
|
|
|
|
def unused_helper(x, y):
|
|
z = x + y
|
|
return x
|