mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
@@ -1,12 +1,65 @@
|
||||
import { mkdir, rm } from "node:fs/promises";
|
||||
import { existsSync } from "node:fs";
|
||||
import { mkdir, rm, statfs } from "node:fs/promises";
|
||||
import { join } from "node:path";
|
||||
import { env } from "../config.js";
|
||||
|
||||
/**
|
||||
* Check available disk space before creating a workspace.
|
||||
* Triggers cleanup if free space is low, and rejects with 503 if
|
||||
* space remains critically low after cleanup.
|
||||
*/
|
||||
async function checkWorkspaceCapacity(workspaceRoot: string): Promise<void> {
|
||||
if (!existsSync(workspaceRoot)) return;
|
||||
|
||||
let stats;
|
||||
try {
|
||||
stats = await statfs(workspaceRoot);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const freeBytes = stats.bavail * stats.bsize;
|
||||
const freeGB = freeBytes / 1024 ** 3;
|
||||
|
||||
if (freeGB < 1) {
|
||||
// Attempt to reclaim space by cleaning up old workspaces
|
||||
const { readdir, stat: fsStat } = await import("node:fs/promises");
|
||||
const entries = await readdir(workspaceRoot, { withFileTypes: true }).catch(() => []);
|
||||
const now = Date.now();
|
||||
for (const entry of entries) {
|
||||
const fullPath = join(workspaceRoot, entry.name);
|
||||
try {
|
||||
const s = await fsStat(fullPath);
|
||||
// Remove workspaces older than 1 hour during emergency cleanup
|
||||
if (now - s.mtimeMs > 60 * 60 * 1000) {
|
||||
await rm(fullPath, { recursive: true, force: true });
|
||||
}
|
||||
} catch {
|
||||
// Skip entries that can't be stat'd
|
||||
}
|
||||
}
|
||||
|
||||
// Recheck after cleanup
|
||||
let stats2;
|
||||
try {
|
||||
stats2 = await statfs(workspaceRoot);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const freeGB2 = (stats2.bavail * stats2.bsize) / 1024 ** 3;
|
||||
if (freeGB2 < 0.5) {
|
||||
const error = new Error("Insufficient disk space for processing");
|
||||
(error as Error & { statusCode: number }).statusCode = 503;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Create a workspace directory structure for a processing job.
|
||||
* Returns the workspace root path.
|
||||
*/
|
||||
export async function createWorkspace(jobId: string): Promise<string> {
|
||||
await checkWorkspaceCapacity(env.WORKSPACE_PATH);
|
||||
const root = getWorkspacePath(jobId);
|
||||
await mkdir(join(root, "input"), { recursive: true });
|
||||
await mkdir(join(root, "output"), { recursive: true });
|
||||
|
||||
Reference in New Issue
Block a user