other
- Location
scripts/lib/setup_wizard.py:477- Finding
Existing GitHub PAT Transmitted to ScrapeCreators Without Per-Transfer Consent
- Content
View full analysis
Optional[Dict[str, Any]]: """Authenticate with ScrapeCreators using a GitHub PAT. POSTs the token to the PAT auth endpoint. ScrapeCreators verifies it against GitHub's API, creates/finds the account, and returns an API key. Returns: Dict with api_key, github_username, etc. on success, None on failure. """ try: req = Request(f"{_PAT_BASE}/auth", data=b"", method="POST") req.add_header("Authorization", f"Bearer {github_token}") with urlopen(req, timeout=15) as resp: data = json.loads(resp.read()) except HTTPError as exc: if exc.code == 422: logger.warning("PAT auth: insufficient scope — user needs user:email") else: logger.warning("PAT auth failed: %s", exc) return None except (URLError, OSError) as exc: logger.warning("PAT auth request failed: %s", exc) return None if not data.get("api_key"): logger.warning("PAT auth returned no api_key: %s", data) return None return data ``` ```python def run_github_auth(timeout: int = 300) -> Dict[str, Any]: """Try PAT auth via gh CLI, fall back to device flow. 1. Check for `gh` CLI 2. If found, run `gh auth token` to get a PAT 3. POST PAT to ScrapeCreators — if it works, done 4. If PAT fails for any reason, fall through to device flow Returns JSON-serializable dict with status, method, and api_key. """ import sys # Step 1: Try PAT via gh CLI gh_path = shutil.which("gh") if gh_path: try: result = subprocess.run( ["gh", "auth", "token"], ...[truncated 2688 chars]- Remediation
View remediation
