curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/security/scan/ignore \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"fingerprint": "3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e",
"finding_type": "static_code",
"file_path": "src/pages/Orders.jsx",
"title": "Order lookup trusts a client-supplied ID"
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/ignore"
payload = {
"fingerprint": "3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e",
"finding_type": "static_code",
"file_path": "src/pages/Orders.jsx",
"title": "Order lookup trusts a client-supplied ID"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
fingerprint: '3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e',
finding_type: 'static_code',
file_path: 'src/pages/Orders.jsx',
title: 'Order lookup trusts a client-supplied ID'
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/ignore', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/ignore",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'fingerprint' => '3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e',
'finding_type' => 'static_code',
'file_path' => 'src/pages/Orders.jsx',
'title' => 'Order lookup trusts a client-supplied ID'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/ignore"
payload := strings.NewReader("{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/security/scan/ignore")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/ignore")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}"
response = http.request(request)
puts response.read_body{
"status": "ok"
}Ignore security finding
Ignores one finding in the app’s security scan, so it stays hidden across rescans for as long as it doesn’t change. Get the finding’s fingerprint from Get security scan, and send the list it came from as finding_type.
Ignoring doesn’t change the app, and it doesn’t remove the finding from the scan result. The finding stays in its list, and its fingerprint is added to ignored_fingerprints. The Base44 editor hides findings whose fingerprint is there.
A finding gets a new fingerprint when what it flags changes, for example when the file it points at is edited. It then shows up again, and the next scan drops the old ignore.
A successful call doesn’t confirm that anything was recorded. Nothing changes when the finding is already ignored, when the app has never been scanned, or when finding_type isn’t one of the five lists. Base44 doesn’t check fingerprint against the scan result either, so read ignored_fingerprints to confirm. Undo it with Restore security finding.
This is limited to 60 requests a minute per app for each workspace’s personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.
curl --request POST \
--url https://app.base44.com/api/apps/{app_id}/security/scan/ignore \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"fingerprint": "3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e",
"finding_type": "static_code",
"file_path": "src/pages/Orders.jsx",
"title": "Order lookup trusts a client-supplied ID"
}
'import requests
url = "https://app.base44.com/api/apps/{app_id}/security/scan/ignore"
payload = {
"fingerprint": "3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e",
"finding_type": "static_code",
"file_path": "src/pages/Orders.jsx",
"title": "Order lookup trusts a client-supplied ID"
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
fingerprint: '3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e',
finding_type: 'static_code',
file_path: 'src/pages/Orders.jsx',
title: 'Order lookup trusts a client-supplied ID'
})
};
fetch('https://app.base44.com/api/apps/{app_id}/security/scan/ignore', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://app.base44.com/api/apps/{app_id}/security/scan/ignore",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'fingerprint' => '3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e',
'finding_type' => 'static_code',
'file_path' => 'src/pages/Orders.jsx',
'title' => 'Order lookup trusts a client-supplied ID'
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://app.base44.com/api/apps/{app_id}/security/scan/ignore"
payload := strings.NewReader("{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://app.base44.com/api/apps/{app_id}/security/scan/ignore")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://app.base44.com/api/apps/{app_id}/security/scan/ignore")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"fingerprint\": \"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e\",\n \"finding_type\": \"static_code\",\n \"file_path\": \"src/pages/Orders.jsx\",\n \"title\": \"Order lookup trusts a client-supplied ID\"\n}"
response = http.request(request)
puts response.read_body{
"status": "ok"
}Authorizations
Personal access token, sent as Authorization: Bearer <token>.
Path Parameters
ID of the app.
Body
The security finding to ignore.
The finding's fingerprint, as returned by Get security scan. Up to 128 characters.
1 - 128"3f9a1c0e8b7d4a6f2e5c9b1d0a8f7e6c5b4a3d2e1f0c9b8a7d6e5f4c3b2a1d0e"
Which list in Get security scan the finding came from. Send rls for rls_recommendations, secret for hardcoded_secrets, backend_function for backend_functions, dependency for dependency_vulnerabilities, or static_code for static_code_findings. Any other value is accepted and nothing is recorded.
1 - 64"static_code"
Path of the file the finding points at, kept with the ignore as a record of what was ignored. Up to 1,024 characters. Defaults to an empty string.
1024"src/pages/Orders.jsx"
Short name for the finding, kept with the ignore as a record of what was ignored. Up to 2,000 characters. Defaults to an empty string.
2000"Order lookup trusts a client-supplied ID"
Response
The call was accepted.
Confirms the call was accepted.
Always ok, including when nothing changed.
"ok"
Was this page helpful?