mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
@@ -13,6 +13,8 @@ services:
|
||||
image: snapotter:latest
|
||||
container_name: SnapOtter
|
||||
ports:
|
||||
# For internet-facing deployments, bind to localhost only:
|
||||
# - "127.0.0.1:1349:1349"
|
||||
- "1349:1349"
|
||||
volumes:
|
||||
- SnapOtter-data:/data # Database, AI models, user files
|
||||
@@ -20,6 +22,8 @@ services:
|
||||
environment:
|
||||
- AUTH_ENABLED=true
|
||||
- DEFAULT_USERNAME=admin
|
||||
# Set a strong password. Default is 'admin' -- CHANGE THIS for any non-local deployment.
|
||||
# - DEFAULT_PASSWORD=your-strong-password-here
|
||||
- DEFAULT_PASSWORD=admin
|
||||
- SKIP_MUST_CHANGE_PASSWORD=${SKIP_MUST_CHANGE_PASSWORD:-false}
|
||||
- MAX_UPLOAD_SIZE_MB=${MAX_UPLOAD_SIZE_MB:-0}
|
||||
@@ -34,6 +38,25 @@ services:
|
||||
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
|
||||
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||
restart: unless-stopped
|
||||
# --- Security hardening ---
|
||||
mem_limit: 8g
|
||||
memswap_limit: 8g
|
||||
cpus: 8
|
||||
pids_limit: 1024
|
||||
cap_drop:
|
||||
- ALL
|
||||
cap_add:
|
||||
- CHOWN
|
||||
- SETUID
|
||||
- SETGID
|
||||
- DAC_OVERRIDE
|
||||
- FOWNER
|
||||
# NOTE: security_opt: [no-new-privileges:true] is intentionally omitted.
|
||||
# gosu requires setuid to drop from root to the snapotter user.
|
||||
# Mitigation: cap_drop: ALL limits available capabilities after privilege drop.
|
||||
# NOTE: read_only: true is not set because PUID/PGID remapping requires
|
||||
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
|
||||
# instead of PUID/PGID for read-only rootfs support.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
|
||||
interval: 30s
|
||||
|
||||
Reference in New Issue
Block a user