Skip to content

Commit 58a43d0

Browse files
Potential fix for code scanning alert no. 439: Local information disclosure in a temporary directory
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
1 parent 035b459 commit 58a43d0

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

apps/onboarding-ms/src/main/java/it/pagopa/selfcare/onboarding/service/impl/TokenServiceDefault.java

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -99,8 +99,8 @@ public static File checkAndRepairPdf(File file) {
9999
}
100100

101101
// 2. Logica di Riparazione (Sanitizzazione)
102-
// Creiamo un temp file dove risalvare il PDF pulito
103-
File repairedFile = File.createTempFile("repaired_", ".pdf");
102+
// Creiamo un temp file dove risalvare il PDF pulito con permessi più restrittivi
103+
File repairedFile = Files.createTempFile("repaired_", ".pdf").toFile();
104104

105105
// Rimuoviamo sicurezze che potrebbero dar fastidio al browser
106106
doc.setAllSecurityToBeRemoved(true);

0 commit comments

Comments
 (0)