Resolve backend Qodana critical and high findings (#314)

Resolve recommended-profile Critical and High findings, retain narrow analyzer exceptions, and update the edge-broker WebSocket dependency to a non-vulnerable release.
This commit is contained in:
Jeppe B
2026-07-17 05:44:16 +02:00
committed by GitHub
parent 6566027746
commit 2a6a86c9c3
108 changed files with 234 additions and 1283 deletions
+75 -25
View File
@@ -5,9 +5,6 @@ namespace classes;
require_once WD . '/modules/entra/entra_c.php';
use entra\entra_c;
use Microsoft\Graph\GraphServiceClient;
use Microsoft\Kiota\Authentication\Oauth\ClientCredentialContext;
use Microsoft\Kiota\Authentication\Oauth\ClientCredentialContextBuilder;
class entra
@@ -23,42 +20,95 @@ class entra
$this->config = new entra_c();
}
public function get_users($array = false): array|object
public function get_users(bool $array = false): array
{
$graphClient = $this->getGraphClient();
$users = $graphClient->users()
->get()
->wait()
->getValue();
$accessToken = $this->requestAccessToken();
$usersResponse = $this->requestJson(
'https://graph.microsoft.com/v1.0/users?$select=id,displayName,mail,userPrincipalName',
['Authorization: Bearer ' . $accessToken]
);
$users = is_array($usersResponse['value'] ?? null) ? $usersResponse['value'] : [];
if (!$array) {
return $users;
}
$result = [];
foreach ( $users as $user ) {
foreach ($users as $user) {
if (!is_array($user)) {
continue;
}
$result[] = [
'id' => $user->getId(),
'displayName' => $user->getDisplayName(),
'mail' => $user->getMail(),
'userPrincipalName' => $user->getUserPrincipalName(),
'id' => $user['id'] ?? null,
'displayName' => $user['displayName'] ?? null,
'mail' => $user['mail'] ?? null,
'userPrincipalName' => $user['userPrincipalName'] ?? null,
];
}
return $result;
}
public function getGraphClient(): GraphServiceClient
private function requestAccessToken(): string
{
return new GraphServiceClient(
$this->getTokenRequestContext(),
$tenantId = trim((string)$this->config->tenant_id->getVariableValue());
$response = $this->requestJson(
'https://login.microsoftonline.com/' . rawurlencode($tenantId) . '/oauth2/v2.0/token',
['Content-Type: application/x-www-form-urlencoded'],
http_build_query([
'client_id' => (string)$this->config->client_id->getVariableValue(),
'client_secret' => (string)$this->config->client_secret->getVariableValue(),
'scope' => 'https://graph.microsoft.com/.default',
'grant_type' => 'client_credentials',
])
);
$token = trim((string)($response['access_token'] ?? ''));
if ($token === '') {
throw new \RuntimeException('Microsoft Entra token response did not contain an access token.');
}
return $token;
}
public function getTokenRequestContext(): ClientCredentialContext
/**
* @param list<string> $headers
* @return array<string,mixed>
*/
private function requestJson(string $url, array $headers, ?string $postFields = null): array
{
return new ClientCredentialContext(
$this->config->tenant_id->getVariableValue(),
$this->config->client_id->getVariableValue(),
$this->config->client_secret->getVariableValue()
);
$curl = curl_init($url);
if ($curl === false) {
throw new \RuntimeException('Unable to initialize Microsoft Entra request.');
}
curl_setopt_array($curl, [
CURLOPT_RETURNTRANSFER => true,
CURLOPT_CONNECTTIMEOUT => 5,
CURLOPT_TIMEOUT => 20,
CURLOPT_HTTPHEADER => $headers,
]);
if ($postFields !== null) {
curl_setopt($curl, CURLOPT_POST, true);
curl_setopt($curl, CURLOPT_POSTFIELDS, $postFields);
}
try {
$body = curl_exec($curl);
$status = (int)curl_getinfo($curl, CURLINFO_RESPONSE_CODE);
if ($body === false) {
throw new \RuntimeException('Microsoft Entra request failed: ' . curl_error($curl));
}
} finally {
curl_close($curl);
}
$decoded = json_decode((string)$body, true);
if ($status < 200 || $status >= 300 || !is_array($decoded)) {
$message = is_array($decoded)
? (string)($decoded['error_description'] ?? $decoded['error']['message'] ?? 'Unexpected response')
: 'Invalid JSON response';
throw new \RuntimeException('Microsoft Entra request failed with HTTP ' . $status . ': ' . $message);
}
return $decoded;
}
}
}