mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): close the gaps a full 2.0 re-audit left open (#620)
Follow-up to a full re-audit of the 2.0 tree. Most prior findings were already fixed; this closes the ones that were not: - SAML assertion replay: validateInResponseTo ifPresent plus a Redis-backed CacheProvider, so a captured signed assertion cannot be replayed. ifPresent keeps IdP-initiated SSO working. - MFA login challenge burned after 5 wrong TOTP codes. - api_keys.key_prefix indexed; the per-request lookup was a full table scan. - MAX_AI_JOBS_PER_USER caps a user's in-flight single-file AI jobs (the AI pool runs at concurrency 1). Batch and pipeline AI stay uncapped. - MAX_WORKSPACE_SIZE_GB enforced instead of being dead config. - SUBPROCESS_MEMORY_LIMIT_MB (default off) for the native media and doc engines; not applied to the AI sidecar. - SVG sanitizer closes unquoted and whitespace-prefixed javascript: hrefs and the animateTransform/animateMotion/handler/mpath elements. - Windows-style paths stripped from error output to match the Sentry scrubber. - Postgres and Redis compose services get cap_drop plus pids_limit and cpus. - .env.example ships MAX_SVG_SIZE_MB=50 (0 disabled the cap). Adds security-focused unit and integration tests. typecheck, biome, and the full unit and integration suites pass.
This commit is contained in:
+7
-1
@@ -14,6 +14,10 @@ MAX_UPLOAD_SIZE_MB=0
|
||||
MAX_BATCH_SIZE=0
|
||||
CONCURRENT_JOBS=0
|
||||
MAX_MEGAPIXELS=0
|
||||
# Max single-file AI jobs one user may have in flight (AI pool is concurrency 1; 0 = unlimited)
|
||||
MAX_AI_JOBS_PER_USER=5
|
||||
# Optional per-process memory cap (MB) for the native media/doc engines (0 = disabled; container limit is the primary backstop)
|
||||
SUBPROCESS_MEMORY_LIMIT_MB=0
|
||||
# Max frames processed by animated background removal (0 = unlimited)
|
||||
GIF_BG_MAX_FRAMES=150
|
||||
|
||||
@@ -28,7 +32,9 @@ MAX_WORKER_THREADS=0
|
||||
PROCESSING_TIMEOUT_S=0
|
||||
MAX_PIPELINE_STEPS=0
|
||||
MAX_CANVAS_PIXELS=0
|
||||
MAX_SVG_SIZE_MB=0
|
||||
# SVG has no "auto" sizing: 0 here disables the pre-parse size cap entirely.
|
||||
# Ship the code default (50 MB) so copying this file does not remove the guard.
|
||||
MAX_SVG_SIZE_MB=50
|
||||
MAX_LOGO_SIZE_KB=2048
|
||||
MAX_SPLIT_GRID=100
|
||||
MAX_PDF_PAGES=0
|
||||
|
||||
Reference in New Issue
Block a user