fix(security): comprehensive security audit and hardening

Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was
unlimited), password/username max lengths on all Zod schemas, session
invalidation on role change, API key legacy scan bounded to 100 keys.

SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding,
set/animate/iframe/embed blocking, comprehensive data: URI blocking,
use element external href blocking. 11 attack payload fixtures added.

SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom
HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges.

Docker: capability dropping (cap_drop ALL + minimal cap_add), resource
limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password
removed from startup banner, default password warning comments.

Network: CSP and HSTS applied in all environments (not just production),
stack traces removed from all error responses, internal paths stripped
from error details, per-route rate limits on uploads (60/min) and URL
fetches (200/hour).

Files: exclusive temp file creation (O_EXCL), disk space circuit
breaker, per-user storage quotas, settings payload 64KB size guard.

Python sidecar: script name allowlist in dispatcher, minimal environment
for subprocess spawns.

Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri,
@fastify/static, next, archiver/lodash). Pinned all GitHub Actions to
SHA hashes.

114 security tests added. Full OWASP Top 10 penetration test matrix
verified against production Docker container (30/30 pass after
hardening).
This commit is contained in:
SnapOtter
2026-05-13 21:33:50 +08:00
parent bc0cac42e3
commit 4e64ee2779
58 changed files with 2572 additions and 3677 deletions
+54 -1
View File
@@ -1,12 +1,65 @@
import { mkdir, rm } from "node:fs/promises";
import { existsSync } from "node:fs";
import { mkdir, rm, statfs } from "node:fs/promises";
import { join } from "node:path";
import { env } from "../config.js";
/**
* Check available disk space before creating a workspace.
* Triggers cleanup if free space is low, and rejects with 503 if
* space remains critically low after cleanup.
*/
async function checkWorkspaceCapacity(workspaceRoot: string): Promise<void> {
if (!existsSync(workspaceRoot)) return;
let stats;
try {
stats = await statfs(workspaceRoot);
} catch {
return;
}
const freeBytes = stats.bavail * stats.bsize;
const freeGB = freeBytes / 1024 ** 3;
if (freeGB < 1) {
// Attempt to reclaim space by cleaning up old workspaces
const { readdir, stat: fsStat } = await import("node:fs/promises");
const entries = await readdir(workspaceRoot, { withFileTypes: true }).catch(() => []);
const now = Date.now();
for (const entry of entries) {
const fullPath = join(workspaceRoot, entry.name);
try {
const s = await fsStat(fullPath);
// Remove workspaces older than 1 hour during emergency cleanup
if (now - s.mtimeMs > 60 * 60 * 1000) {
await rm(fullPath, { recursive: true, force: true });
}
} catch {
// Skip entries that can't be stat'd
}
}
// Recheck after cleanup
let stats2;
try {
stats2 = await statfs(workspaceRoot);
} catch {
return;
}
const freeGB2 = (stats2.bavail * stats2.bsize) / 1024 ** 3;
if (freeGB2 < 0.5) {
const error = new Error("Insufficient disk space for processing");
(error as Error & { statusCode: number }).statusCode = 503;
throw error;
}
}
}
/**
* Create a workspace directory structure for a processing job.
* Returns the workspace root path.
*/
export async function createWorkspace(jobId: string): Promise<string> {
await checkWorkspaceCapacity(env.WORKSPACE_PATH);
const root = getWorkspacePath(jobId);
await mkdir(join(root, "input"), { recursive: true });
await mkdir(join(root, "output"), { recursive: true });