Repository navigation
test: add sample code for pr-agent review - #1
Prateekbala wants to merge 1 commit into
Conversation
| function getUser(db: any, userId: string) { | ||
| return db.query("SELECT * FROM users WHERE id = " + userId); |
There was a problem hiding this comment.
🟠 Security · high — SQL injection via string concatenation
The getUser function builds a SQL query by concatenating userId directly, allowing an attacker to inject arbitrary SQL. This can lead to data leakage or modification.
| function getUser(db: any, userId: string) { | |
| return db.query("SELECT * FROM users WHERE id = " + userId); | |
| function getUser(db: any, userId: string) { | |
| return db.query('SELECT * FROM users WHERE id = ?', [userId]); // Use parameterized query | |
| } |
Confidence 96%
| } | ||
|
|
||
| // Hardcoded secret | ||
| const API_KEY = "sk-prod-abc123supersecretkey"; |
There was a problem hiding this comment.
🟠 Security · high — Hardcoded secret API key
A secret API key is committed in source code, exposing credentials that could be abused to access the production service. This constitutes a credential leakage risk.
| const API_KEY = "sk-prod-abc123supersecretkey"; | |
| const API_KEY = process.env.API_KEY; // Load from environment variable |
Confidence 95%
| async function fetchUser(id: string) { | ||
| const result = fetch(`https://api.example.com/users/${id}`); | ||
| return result; |
There was a problem hiding this comment.
🟡 Bug · medium — Missing await on async fetch call
The function fetchUser is declared async but calls fetch without awaiting, so it returns a Promise instead of the resolved response. Callers expecting a resolved value may get an unexpected Promise, leading to runtime errors.
| async function fetchUser(id: string) { | |
| const result = fetch(`https://api.example.com/users/${id}`); | |
| return result; | |
| async function fetchUser(id: string) { | |
| const result = await fetch(`https://api.example.com/users/${id}`); | |
| return result; | |
| } |
Confidence 90%
| // Empty catch | ||
| async function riskyOp() { | ||
| try { | ||
| await fetchUser("123"); | ||
| } catch (e) {} |
There was a problem hiding this comment.
🔵 Bug · low — Empty catch block swallows errors
The catch block catches exceptions from riskyOp but does nothing, silently ignoring failures. This makes debugging difficult and can hide runtime errors.
| // Empty catch | |
| async function riskyOp() { | |
| try { | |
| await fetchUser("123"); | |
| } catch (e) {} | |
| } catch (e) { | |
| console.error('riskyOp failed:', e); | |
| throw e; // Re‑throw or handle appropriately | |
| } |
Confidence 85%
ReviewThis PR adds a sample test file that contains multiple security and quality issues. The code builds a raw SQL query using string concatenation, includes a hard‑coded API key, calls fetch without awaiting, and swallows errors in a catch block. These defects expose the system to injection attacks, credential leakage, runtime failures and debugging difficulties. Risk: 🟠 high Highlights
Files reviewedTest review code — Verify that the SQL query uses parameterized statements, remove the embedded API key or externalize it, add await to the fetch call, and handle errors in the catch block.
Run cost: 6825 tokens |
No description provided.