mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
+7
-10
@@ -111,11 +111,9 @@ app.setErrorHandler((error: Error & { statusCode?: number }, request, reply) =>
|
||||
if (statusCode >= 500) {
|
||||
captureException(error, request);
|
||||
}
|
||||
const isProduction = process.env.NODE_ENV === "production";
|
||||
reply.status(statusCode).send({
|
||||
error: statusCode >= 500 ? "Internal server error" : error.message,
|
||||
...(statusCode < 500 && { details: error.message }),
|
||||
...(!isProduction && statusCode >= 500 && { details: error.stack ?? error.message }),
|
||||
});
|
||||
});
|
||||
|
||||
@@ -126,24 +124,23 @@ await app.register(cors, {
|
||||
: process.env.NODE_ENV !== "production",
|
||||
});
|
||||
|
||||
// Security headers
|
||||
// Security headers -- applied in all environments. HSTS is ignored over plain
|
||||
// HTTP so it is safe (and desirable) to send it in dev/staging too. CSP catches
|
||||
// injection issues early when applied during development.
|
||||
app.addHook("onSend", async (_request, reply) => {
|
||||
reply.header("X-Content-Type-Options", "nosniff");
|
||||
reply.header("X-Frame-Options", "DENY");
|
||||
reply.header("X-XSS-Protection", "0");
|
||||
reply.header("Referrer-Policy", "strict-origin-when-cross-origin");
|
||||
reply.header("Permissions-Policy", "camera=(), microphone=(), geolocation=()");
|
||||
if (process.env.NODE_ENV === "production") {
|
||||
reply.header("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
|
||||
reply.header("Content-Security-Policy", buildCsp(_request.url.startsWith("/api/docs")));
|
||||
}
|
||||
reply.header("Strict-Transport-Security", "max-age=31536000; includeSubDomains");
|
||||
reply.header("Content-Security-Policy", buildCsp(_request.url.startsWith("/api/docs")));
|
||||
});
|
||||
|
||||
// Always register rate-limit plugin so per-route limits (login brute-force protection) work.
|
||||
// When RATE_LIMIT_PER_MIN=0, the global limit is set high enough to be effectively unlimited
|
||||
// while still enabling per-route overrides like the login endpoint.
|
||||
// RATE_LIMIT_PER_MIN defaults to 300 via env schema; floor at 1 as a safety net.
|
||||
await app.register(rateLimit, {
|
||||
max: env.RATE_LIMIT_PER_MIN > 0 ? env.RATE_LIMIT_PER_MIN : 50000,
|
||||
max: Math.max(env.RATE_LIMIT_PER_MIN, 1),
|
||||
timeWindow: "1 minute",
|
||||
allowList: (request) => !request.url.startsWith("/api/"),
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user