mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
@@ -1,8 +1,29 @@
|
||||
import { randomUUID } from "node:crypto";
|
||||
import { mkdir, readFile, unlink, writeFile } from "node:fs/promises";
|
||||
import { mkdir, readFile, statfs, unlink, writeFile } from "node:fs/promises";
|
||||
import { extname, join } from "node:path";
|
||||
import { env } from "../config.js";
|
||||
|
||||
/** Minimum free disk space (100 MB) before refusing writes. */
|
||||
const MIN_FREE_BYTES = 100 * 1024 * 1024;
|
||||
|
||||
/**
|
||||
* Check available disk space and throw 507 if below threshold.
|
||||
*/
|
||||
async function assertDiskSpace(dir: string): Promise<void> {
|
||||
try {
|
||||
const stats = await statfs(dir);
|
||||
const freeBytes = stats.bfree * stats.bsize;
|
||||
if (freeBytes < MIN_FREE_BYTES) {
|
||||
const err = new Error("Insufficient disk space") as Error & { statusCode: number };
|
||||
err.statusCode = 507;
|
||||
throw err;
|
||||
}
|
||||
} catch (e) {
|
||||
// Re-throw our own 507 errors; swallow statfs failures (e.g. unsupported OS)
|
||||
if (e instanceof Error && (e as Error & { statusCode?: number }).statusCode === 507) throw e;
|
||||
}
|
||||
}
|
||||
|
||||
const SAFE_STORAGE_EXTENSIONS = new Set([
|
||||
".jpg",
|
||||
".jpeg",
|
||||
@@ -41,6 +62,7 @@ export async function ensureStorageDir(): Promise<void> {
|
||||
|
||||
export async function saveFile(buffer: Buffer, originalName: string): Promise<string> {
|
||||
await ensureStorageDir();
|
||||
await assertDiskSpace(env.FILES_STORAGE_PATH);
|
||||
let ext = extname(originalName).toLowerCase() || ".bin";
|
||||
// Only allow known image extensions to be stored — reject dangerous extensions
|
||||
// even if they somehow pass upstream sanitization.
|
||||
|
||||
Reference in New Issue
Block a user