T09 · Insecure Skill Coding Practices
- Location
scripts/fb_post.py:285- Finding
Command-Line Dry-Run Override Can Still Publish Live Facebook Posts
- Content
View full analysis
- Remediation
View remediation
dict: ... if dry_run: await page.keyboard.press("Escape") return {"success": True, "dry_run": True} await btn.click() ``` Apply the same change to `post_with_photos()` and invoke the functions with `args.dry_run`. Alternatively, assign the resolved option to the global variable before posting, although explicit parameter passing is safer and easier to test. Avoid changing the environment after configuration has already been read. Add automated tests covering at least these combinations: - No environment setting and no option: dry-run remains enabled. - `FB_DRY_RUN=false` without `--dry-run`: live mode is enabled. - `FB_DRY_RUN=false` with `--dry-run`: posting is blocked. - Both text and photo posting paths honor the same resolved setting. For stronger safety, require an explicit positive option such as `--publish` for all live operations rather than relying only on a false-valued environment variable. ]]>
