From d14ef3236c18fd62db2ed0609aec6ed21a4e5b2f Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 17 Aug 2026 10:22:09 +0000 Subject: [PATCH 1/2] Initial plan From f14d3068b117feb838b6edc9e4fc8074e0d5b9ee Mon Sep 17 00:00:00 2001 From: "copilot-swe-agent[bot]" <198982749+Copilot@users.noreply.github.com> Date: Mon, 17 Aug 2026 10:25:12 +0000 Subject: [PATCH 2/2] fix: prevent exception message exposure in /api/settings (CodeQL alert #61) Co-authored-by: dvir001 <39403717+dvir001@users.noreply.github.com> --- simple_org_chart/data_update.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/simple_org_chart/data_update.py b/simple_org_chart/data_update.py index c067289..115caf0 100644 --- a/simple_org_chart/data_update.py +++ b/simple_org_chart/data_update.py @@ -621,8 +621,8 @@ def update_new_status(node): logger.error(f"Failed to write recently disabled employees report cache: {report_error}") success = True except Exception as e: - error_message = str(e) logger.error(f"Error updating employee data: {e}") + error_message = 'Data update failed due to an internal error.' finally: if success: mark_data_update_finished(success=True, source=source)