From 686ad08bb5d2ddd6fca3fe6913c7b5629eceac43 Mon Sep 17 00:00:00 2001 From: Amin Ghadersohi Date: Thu, 23 Apr 2026 20:29:08 -0400 Subject: [PATCH] fix(mcp): remove prefixes from log to satisfy CodeQL Remove API key prefixes from log message to avoid CodeQL false positive about clear-text logging of sensitive data. --- superset/mcp_service/mcp_config.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/superset/mcp_service/mcp_config.py b/superset/mcp_service/mcp_config.py index 847c46cd603..7e7bf5ab3fe 100644 --- a/superset/mcp_service/mcp_config.py +++ b/superset/mcp_service/mcp_config.py @@ -348,7 +348,7 @@ def create_default_mcp_auth_factory(app: Flask) -> Optional[Any]: jwt_verifier=auth_provider, api_key_prefixes=api_key_prefixes, ) - logger.info("API key auth enabled for MCP (prefixes: %s)", api_key_prefixes) + logger.info("API key auth enabled for MCP") return auth_provider except Exception: