Skip to content

Commit 035c7ee

Browse files
rubychildsclaude
andcommitted
fix: mark the holdout bucketing hash as non-security
CodeQL flags SHA-1 on a distinct id as weak hashing of sensitive data. The digest is a bucketing value the server also computes, so it cannot change; usedforsecurity=False states the intent without altering the output. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
1 parent d0a4a0b commit 035c7ee

1 file changed

Lines changed: 6 additions & 1 deletion

File tree

‎posthog/feature_flags.py‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -127,7 +127,12 @@ def _holdout_hash(bucketing_value: str) -> float:
127127
out a different set of people than the server does.
128128
"""
129129
hash_key = f"holdout-{bucketing_value}"
130-
hash_val = int(hashlib.sha1(hash_key.encode("utf-8")).hexdigest()[:15], 16)
130+
# SHA-1 is the bucketing algorithm the server uses, not a security control, so the
131+
# digest has to stay bit-identical. usedforsecurity=False says so without changing it.
132+
hash_val = int(
133+
hashlib.sha1(hash_key.encode("utf-8"), usedforsecurity=False).hexdigest()[:15],
134+
16,
135+
)
131136
return hash_val / __LONG_SCALE__
132137

133138

0 commit comments

Comments
 (0)