fix(security): comprehensive security audit and hardening

Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was
unlimited), password/username max lengths on all Zod schemas, session
invalidation on role change, API key legacy scan bounded to 100 keys.

SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding,
set/animate/iframe/embed blocking, comprehensive data: URI blocking,
use element external href blocking. 11 attack payload fixtures added.

SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom
HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges.

Docker: capability dropping (cap_drop ALL + minimal cap_add), resource
limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password
removed from startup banner, default password warning comments.

Network: CSP and HSTS applied in all environments (not just production),
stack traces removed from all error responses, internal paths stripped
from error details, per-route rate limits on uploads (60/min) and URL
fetches (200/hour).

Files: exclusive temp file creation (O_EXCL), disk space circuit
breaker, per-user storage quotas, settings payload 64KB size guard.

Python sidecar: script name allowlist in dispatcher, minimal environment
for subprocess spawns.

Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri,
@fastify/static, next, archiver/lodash). Pinned all GitHub Actions to
SHA hashes.

114 security tests added. Full OWASP Top 10 penetration test matrix
verified against production Docker container (30/30 pass after
hardening).
This commit is contained in:
SnapOtter
2026-05-13 21:33:50 +08:00
parent bc0cac42e3
commit 4e64ee2779
58 changed files with 2572 additions and 3677 deletions
+1 -1
View File
@@ -295,7 +295,7 @@ RUN chmod +x /usr/local/bin/entrypoint.sh
EXPOSE 1349
HEALTHCHECK --interval=30s --timeout=5s --start-period=60s --retries=3 \
CMD curl -f http://localhost:1349/api/v1/health || exit 1
CMD curl -sf --max-time 5 http://localhost:1349/api/v1/health || exit 1
# tini as PID 1 for zombie reaping + signal forwarding
ENTRYPOINT ["tini", "--", "entrypoint.sh"]
+23
View File
@@ -13,6 +13,8 @@ services:
image: snapotter:latest
container_name: SnapOtter
ports:
# For internet-facing deployments, bind to localhost only:
# - "127.0.0.1:1349:1349"
- "1349:1349"
volumes:
- SnapOtter-data:/data # Database, AI models, user files
@@ -20,6 +22,8 @@ services:
environment:
- AUTH_ENABLED=true
- DEFAULT_USERNAME=admin
# Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment.
# - DEFAULT_PASSWORD=your-strong-password-here
- DEFAULT_PASSWORD=admin
- SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false}
- MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0}
@@ -34,6 +38,25 @@ services:
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
- TRUST_PROXY=${TRUST_PROXY:-true}
restart: unless-stopped
# --- Security hardening ---
mem_limit: 8g
memswap_limit: 8g
cpus: 8
pids_limit: 1024
cap_drop:
- ALL
cap_add:
- CHOWN
- SETUID
- SETGID
- DAC_OVERRIDE
- FOWNER
# NOTE: security_opt: [no-new-privileges:true] is intentionally omitted.
# gosu requires setuid to drop from root to the snapotter user.
# Mitigation: cap_drop: ALL limits available capabilities after privilege drop.
# NOTE: read_only: true is not set because PUID/PGID remapping requires
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
# instead of PUID/PGID for read-only rootfs support.
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
interval: 30s
+23
View File
@@ -12,6 +12,8 @@ services:
image: snapotter:latest
container_name: SnapOtter
ports:
# For internet-facing deployments, bind to localhost only:
# - "127.0.0.1:1349:1349"
- "1349:1349"
volumes:
- SnapOtter-data:/data # Database, AI models, user files
@@ -19,6 +21,8 @@ services:
environment:
- AUTH_ENABLED=true
- DEFAULT_USERNAME=admin
# Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment.
# - DEFAULT_PASSWORD=your-strong-password-here
- DEFAULT_PASSWORD=admin
- SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false}
- MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0}
@@ -33,6 +37,25 @@ services:
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
- TRUST_PROXY=${TRUST_PROXY:-true}
restart: unless-stopped
# --- Security hardening ---
mem_limit: 4g
memswap_limit: 4g
cpus: 4
pids_limit: 512
cap_drop:
- ALL
cap_add:
- CHOWN
- SETUID
- SETGID
- DAC_OVERRIDE
- FOWNER
# NOTE: security_opt: [no-new-privileges:true] is intentionally omitted.
# gosu requires setuid to drop from root to the snapotter user.
# Mitigation: cap_drop: ALL limits available capabilities after privilege drop.
# NOTE: read_only: true is not set because PUID/PGID remapping requires
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
# instead of PUID/PGID for read-only rootfs support.
healthcheck:
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
interval: 30s
+1 -1
View File
@@ -32,7 +32,7 @@ print_banner() {
printf ' \033[2m────────────────────────────────────────%b\n' "$RST"
printf '\n'
printf ' \033[32m➜%b Open \033[1;4mhttp://localhost:%s%b\n' "$RST" "${PORT:-1349}" "$RST"
printf ' \033[33m➜%b Login \033[1m%s%b / \033[1m%s%b\n' "$RST" "${DEFAULT_USERNAME}" "$RST" "${DEFAULT_PASSWORD}" "$RST"
printf ' \033[33m➜%b Login \033[1m%s%b / \033[1m[CHANGE ON FIRST LOGIN]%b\n' "$RST" "${DEFAULT_USERNAME}" "$RST" "$RST"
printf ' \033[36m➜%b Docs \033[2mhttps://docs.snapotter.com%b\n' "$RST" "$RST"
printf '\n'
}