mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
+1
-1
@@ -295,7 +295,7 @@ RUN chmod +x /usr/local/bin/entrypoint.sh
|
||||
EXPOSE 1349
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \
|
||||
CMD curl -f http://localhost:1349/api/v1/health || exit 1
|
||||
CMD curl -sf --max-time 5 http://localhost:1349/api/v1/health || exit 1
|
||||
|
||||
# tini as PID 1 for zombie reaping + signal forwarding
|
||||
ENTRYPOINT ["tini", "--", "entrypoint.sh"]
|
||||
|
||||
@@ -13,6 +13,8 @@ services:
|
||||
image: snapotter:latest
|
||||
container_name: SnapOtter
|
||||
ports:
|
||||
# For internet-facing deployments, bind to localhost only:
|
||||
# - "127.0.0.1:1349:1349"
|
||||
- "1349:1349"
|
||||
volumes:
|
||||
- SnapOtter-data:/data # Database, AI models, user files
|
||||
@@ -20,6 +22,8 @@ services:
|
||||
environment:
|
||||
- AUTH_ENABLED=true
|
||||
- DEFAULT_USERNAME=admin
|
||||
# Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment.
|
||||
# - DEFAULT_PASSWORD=your-strong-password-here
|
||||
- DEFAULT_PASSWORD=admin
|
||||
- SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false}
|
||||
- MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0}
|
||||
@@ -34,6 +38,25 @@ services:
|
||||
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
|
||||
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||
restart: unless-stopped
|
||||
# --- Security hardening ---
|
||||
mem_limit: 8g
|
||||
memswap_limit: 8g
|
||||
cpus: 8
|
||||
pids_limit: 1024
|
||||
cap_drop:
|
||||
- ALL
|
||||
cap_add:
|
||||
- CHOWN
|
||||
- SETUID
|
||||
- SETGID
|
||||
- DAC_OVERRIDE
|
||||
- FOWNER
|
||||
# NOTE: security_opt: [no-new-privileges:true] is intentionally omitted.
|
||||
# gosu requires setuid to drop from root to the snapotter user.
|
||||
# Mitigation: cap_drop: ALL limits available capabilities after privilege drop.
|
||||
# NOTE: read_only: true is not set because PUID/PGID remapping requires
|
||||
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
|
||||
# instead of PUID/PGID for read-only rootfs support.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
|
||||
interval: 30s
|
||||
|
||||
@@ -12,6 +12,8 @@ services:
|
||||
image: snapotter:latest
|
||||
container_name: SnapOtter
|
||||
ports:
|
||||
# For internet-facing deployments, bind to localhost only:
|
||||
# - "127.0.0.1:1349:1349"
|
||||
- "1349:1349"
|
||||
volumes:
|
||||
- SnapOtter-data:/data # Database, AI models, user files
|
||||
@@ -19,6 +21,8 @@ services:
|
||||
environment:
|
||||
- AUTH_ENABLED=true
|
||||
- DEFAULT_USERNAME=admin
|
||||
# Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment.
|
||||
# - DEFAULT_PASSWORD=your-strong-password-here
|
||||
- DEFAULT_PASSWORD=admin
|
||||
- SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false}
|
||||
- MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0}
|
||||
@@ -33,6 +37,25 @@ services:
|
||||
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
|
||||
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||
restart: unless-stopped
|
||||
# --- Security hardening ---
|
||||
mem_limit: 4g
|
||||
memswap_limit: 4g
|
||||
cpus: 4
|
||||
pids_limit: 512
|
||||
cap_drop:
|
||||
- ALL
|
||||
cap_add:
|
||||
- CHOWN
|
||||
- SETUID
|
||||
- SETGID
|
||||
- DAC_OVERRIDE
|
||||
- FOWNER
|
||||
# NOTE: security_opt: [no-new-privileges:true] is intentionally omitted.
|
||||
# gosu requires setuid to drop from root to the snapotter user.
|
||||
# Mitigation: cap_drop: ALL limits available capabilities after privilege drop.
|
||||
# NOTE: read_only: true is not set because PUID/PGID remapping requires
|
||||
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
|
||||
# instead of PUID/PGID for read-only rootfs support.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
|
||||
interval: 30s
|
||||
|
||||
@@ -32,7 +32,7 @@ print_banner() {
|
||||
printf ' \033[2m────────────────────────────────────────%b\n' "$RST"
|
||||
printf '\n'
|
||||
printf ' \033[32m➜%b Open \033[1;4mhttp://localhost:%s%b\n' "$RST" "${PORT:-1349}" "$RST"
|
||||
printf ' \033[33m➜%b Login \033[1m%s%b / \033[1m%s%b\n' "$RST" "${DEFAULT_USERNAME}" "$RST" "${DEFAULT_PASSWORD}" "$RST"
|
||||
printf ' \033[33m➜%b Login \033[1m%s%b / \033[1m[CHANGE ON FIRST LOGIN]%b\n' "$RST" "${DEFAULT_USERNAME}" "$RST" "$RST"
|
||||
printf ' \033[36m➜%b Docs \033[2mhttps://docs.snapotter.com%b\n' "$RST" "$RST"
|
||||
printf '\n'
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user