mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): close the gaps a full 2.0 re-audit left open (#620)
Follow-up to a full re-audit of the 2.0 tree. Most prior findings were already fixed; this closes the ones that were not: - SAML assertion replay: validateInResponseTo ifPresent plus a Redis-backed CacheProvider, so a captured signed assertion cannot be replayed. ifPresent keeps IdP-initiated SSO working. - MFA login challenge burned after 5 wrong TOTP codes. - api_keys.key_prefix indexed; the per-request lookup was a full table scan. - MAX_AI_JOBS_PER_USER caps a user's in-flight single-file AI jobs (the AI pool runs at concurrency 1). Batch and pipeline AI stay uncapped. - MAX_WORKSPACE_SIZE_GB enforced instead of being dead config. - SUBPROCESS_MEMORY_LIMIT_MB (default off) for the native media and doc engines; not applied to the AI sidecar. - SVG sanitizer closes unquoted and whitespace-prefixed javascript: hrefs and the animateTransform/animateMotion/handler/mpath elements. - Windows-style paths stripped from error output to match the Sentry scrubber. - Postgres and Redis compose services get cap_drop plus pids_limit and cpus. - .env.example ships MAX_SVG_SIZE_MB=50 (0 disabled the cap). Adds security-focused unit and integration tests. typecheck, biome, and the full unit and integration suites pass.
This commit is contained in:
@@ -377,6 +377,36 @@ describe("MFA login flow", () => {
|
||||
expect(body.user.username).toBe("admin");
|
||||
expect(body.expiresAt).toBeDefined();
|
||||
});
|
||||
|
||||
it("burns the challenge after repeated wrong codes so the correct code no longer works", async () => {
|
||||
const loginRes = await testApp.app.inject({
|
||||
method: "POST",
|
||||
url: "/api/auth/login",
|
||||
payload: { username: "admin", password: "Adminpass1" },
|
||||
});
|
||||
const { mfaToken } = JSON.parse(loginRes.body);
|
||||
|
||||
// Exhaust the wrong-code budget. Each wrong attempt is a 401.
|
||||
for (let i = 0; i < 5; i++) {
|
||||
const bad = await testApp.app.inject({
|
||||
method: "POST",
|
||||
url: "/api/auth/mfa/complete",
|
||||
payload: { mfaToken, code: "000000" },
|
||||
});
|
||||
expect(bad.statusCode).toBe(401);
|
||||
}
|
||||
|
||||
// The challenge is now burned: even the correct TOTP is rejected as expired,
|
||||
// forcing the attacker back through the login (and its rate limit).
|
||||
const code = generateTotpCode(totpUri);
|
||||
const res = await testApp.app.inject({
|
||||
method: "POST",
|
||||
url: "/api/auth/mfa/complete",
|
||||
payload: { mfaToken, code },
|
||||
});
|
||||
expect(res.statusCode).toBe(401);
|
||||
expect(JSON.parse(res.body).code).toBe("MFA_EXPIRED");
|
||||
});
|
||||
});
|
||||
|
||||
async function setMfaPolicy(value: "optional" | "admins_only" | "required"): Promise<void> {
|
||||
|
||||
Reference in New Issue
Block a user