fix(security): close the gaps a full 2.0 re-audit left open (#620)

Follow-up to a full re-audit of the 2.0 tree. Most prior findings were already
fixed; this closes the ones that were not:

- SAML assertion replay: validateInResponseTo ifPresent plus a Redis-backed
  CacheProvider, so a captured signed assertion cannot be replayed. ifPresent
  keeps IdP-initiated SSO working.
- MFA login challenge burned after 5 wrong TOTP codes.
- api_keys.key_prefix indexed; the per-request lookup was a full table scan.
- MAX_AI_JOBS_PER_USER caps a user's in-flight single-file AI jobs (the AI pool
  runs at concurrency 1). Batch and pipeline AI stay uncapped.
- MAX_WORKSPACE_SIZE_GB enforced instead of being dead config.
- SUBPROCESS_MEMORY_LIMIT_MB (default off) for the native media and doc engines;
  not applied to the AI sidecar.
- SVG sanitizer closes unquoted and whitespace-prefixed javascript: hrefs and
  the animateTransform/animateMotion/handler/mpath elements.
- Windows-style paths stripped from error output to match the Sentry scrubber.
- Postgres and Redis compose services get cap_drop plus pids_limit and cpus.
- .env.example ships MAX_SVG_SIZE_MB=50 (0 disabled the cap).

Adds security-focused unit and integration tests. typecheck, biome, and the
full unit and integration suites pass.
This commit is contained in:
SnapOtter
2026-07-23 00:18:16 +08:00
committed by GitHub
parent 10a2aabe58
commit 079fcd2631
33 changed files with 1747 additions and 57 deletions
@@ -0,0 +1,79 @@
import { and, eq } from "drizzle-orm";
import { afterEach, beforeAll, describe, expect, it } from "vitest";
const { buildTestApp, loginAsAdmin } = await import("../test-server.js");
const { db, schema } = await import("../../../apps/api/src/db/index.js");
const { countInFlightAiJobs } = await import("../../../apps/api/src/lib/ai-quota.js");
const { enqueueToolJob } = await import("../../../apps/api/src/jobs/enqueue.js");
const { env } = await import("../../../apps/api/src/config.js");
import type { TestApp } from "../test-server.js";
let testApp: TestApp;
let adminId: string;
async function seedAiJob(userId: string, status: "queued" | "processing", kind: string) {
const id = `test-aijob-${Math.random().toString(36).slice(2)}`;
await db.insert(schema.jobs).values({
id,
userId,
toolId: "colorize",
pool: "ai",
type: kind,
status,
inputRefs: [`uploads/${id}/x.png`],
settings: {},
});
return id;
}
beforeAll(async () => {
testApp = await buildTestApp();
await loginAsAdmin(testApp.app);
const [admin] = await db.select().from(schema.users).where(eq(schema.users.username, "admin"));
adminId = admin.id;
}, 30_000);
afterEach(async () => {
await db.delete(schema.jobs).where(and(eq(schema.jobs.userId, adminId)));
});
describe("countInFlightAiJobs", () => {
it("counts only queued/processing ai-tool jobs, ignoring other kinds and terminal states", async () => {
await seedAiJob(adminId, "queued", "ai-tool");
await seedAiJob(adminId, "processing", "ai-tool");
await seedAiJob(adminId, "queued", "batch-child"); // different kind: excluded
const done = await seedAiJob(adminId, "queued", "ai-tool");
await db.update(schema.jobs).set({ status: "completed" }).where(eq(schema.jobs.id, done));
expect(await countInFlightAiJobs(adminId)).toBe(2);
});
});
describe("enqueueToolJob AI quota enforcement", () => {
it("rejects a new ai-tool job with 429 once the user is at the cap", async () => {
const cap = env.MAX_AI_JOBS_PER_USER;
expect(cap).toBeGreaterThan(0);
for (let i = 0; i < cap; i++) await seedAiJob(adminId, "queued", "ai-tool");
await expect(
enqueueToolJob({
jobId: "test-over-cap-job",
toolId: "colorize",
userId: adminId,
pool: "ai",
inputRefs: ["uploads/test-over-cap-job/x.png"],
filename: "x.png",
settings: {},
kind: "ai-tool",
}),
).rejects.toMatchObject({ statusCode: 429 });
// The rejected job left no row behind.
const [row] = await db
.select()
.from(schema.jobs)
.where(eq(schema.jobs.id, "test-over-cap-job"));
expect(row).toBeUndefined();
});
});
@@ -377,6 +377,36 @@ describe("MFA login flow", () => {
expect(body.user.username).toBe("admin");
expect(body.expiresAt).toBeDefined();
});
it("burns the challenge after repeated wrong codes so the correct code no longer works", async () => {
const loginRes = await testApp.app.inject({
method: "POST",
url: "/api/auth/login",
payload: { username: "admin", password: "Adminpass1" },
});
const { mfaToken } = JSON.parse(loginRes.body);
// Exhaust the wrong-code budget. Each wrong attempt is a 401.
for (let i = 0; i < 5; i++) {
const bad = await testApp.app.inject({
method: "POST",
url: "/api/auth/mfa/complete",
payload: { mfaToken, code: "000000" },
});
expect(bad.statusCode).toBe(401);
}
// The challenge is now burned: even the correct TOTP is rejected as expired,
// forcing the attacker back through the login (and its rate limit).
const code = generateTotpCode(totpUri);
const res = await testApp.app.inject({
method: "POST",
url: "/api/auth/mfa/complete",
payload: { mfaToken, code },
});
expect(res.statusCode).toBe(401);
expect(JSON.parse(res.body).code).toBe("MFA_EXPIRED");
});
});
async function setMfaPolicy(value: "optional" | "admins_only" | "required"): Promise<void> {
@@ -0,0 +1,46 @@
import { describe, expect, it } from "vitest";
const { makeRedisSamlCacheProvider } = await import("../../../apps/api/src/lib/saml-cache.js");
const { sharedRedis } = await import("../../../apps/api/src/jobs/connection.js");
// Verifies the InResponseTo replay-prevention primitive behind SAML hardening:
// a request ID can be stored once, is rejected on a duplicate save (the replay
// signal node-saml keys off), and disappears after it is consumed.
describe("SAML Redis cache provider (InResponseTo replay protection)", () => {
it("stores a request id once, rejects a duplicate save, and consumes on remove", async () => {
const provider = makeRedisSamlCacheProvider();
const key = `test-${Math.random().toString(36).slice(2)}`;
const first = await provider.saveAsync(key, key);
expect(first).not.toBeNull();
expect(first?.value).toBe(key);
// A replayed response reuses the same InResponseTo id: the save must fail.
const duplicate = await provider.saveAsync(key, key);
expect(duplicate).toBeNull();
expect(await provider.getAsync(key)).toBe(key);
// Consuming (as node-saml does on a valid first use) removes it, so a later
// replay finds nothing and is rejected.
expect(await provider.removeAsync(key)).toBe(key);
expect(await provider.getAsync(key)).toBeNull();
expect(await provider.removeAsync(key)).toBeNull();
});
it("returns null from removeAsync when given a null key", async () => {
const provider = makeRedisSamlCacheProvider();
expect(await provider.removeAsync(null)).toBeNull();
});
it("honors the TTL so stale request ids self-expire", async () => {
const provider = makeRedisSamlCacheProvider(1); // 1 second
const key = `test-ttl-${Math.random().toString(36).slice(2)}`;
await provider.saveAsync(key, key);
// Confirm the TTL was actually set on the namespaced key (not persisted).
const ttl = await sharedRedis().ttl(`saml:req:${key}`);
expect(ttl).toBeGreaterThan(0);
expect(ttl).toBeLessThanOrEqual(1);
await provider.removeAsync(key);
});
});