From 38b9ea548448dabfc32928d2bb66ed3c4f617ce5 Mon Sep 17 00:00:00 2001 From: Amin Ghadersohi Date: Thu, 23 Apr 2026 20:29:08 -0400 Subject: [PATCH] fix(mcp): remove prefixes from log to satisfy CodeQL Remove API key prefixes from log message to avoid CodeQL false positive about clear-text logging of sensitive data. --- superset/mcp_service/mcp_config.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/superset/mcp_service/mcp_config.py b/superset/mcp_service/mcp_config.py index b1a0aad33af..0c30053ceb2 100644 --- a/superset/mcp_service/mcp_config.py +++ b/superset/mcp_service/mcp_config.py @@ -341,7 +341,7 @@ def create_default_mcp_auth_factory(app: Flask) -> Optional[Any]: jwt_verifier=auth_provider, api_key_prefixes=api_key_prefixes, ) - logger.info("API key auth enabled for MCP (prefixes: %s)", api_key_prefixes) + logger.info("API key auth enabled for MCP") return auth_provider except Exception: