mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): comprehensive security audit and hardening
Auth: login rate limit 30/min (was 500), global rate limit 1000/min (was unlimited), password/username max lengths on all Zod schemas, session invalidation on role change, API key legacy scan bounded to 100 keys. SVG: hardened regex sanitizer with CDATA stripping, XML entity decoding, set/animate/iframe/embed blocking, comprehensive data: URI blocking, use element external href blocking. 11 attack payload fixtures added. SSRF: fixed DNS rebinding TOCTOU by pinning resolved IPs via custom HTTP/HTTPS agents. Added 6to4 and NAT64 to blocked IPv6 ranges. Docker: capability dropping (cap_drop ALL + minimal cap_add), resource limits (4g/8g mem, 512/1024 pids), healthcheck timeout, password removed from startup banner, default password warning comments. Network: CSP and HSTS applied in all environments (not just production), stack traces removed from all error responses, internal paths stripped from error details, per-route rate limits on uploads (60/min) and URL fetches (200/hour). Files: exclusive temp file creation (O_EXCL), disk space circuit breaker, per-user storage quotas, settings payload 64KB size guard. Python sidecar: script name allowlist in dispatcher, minimal environment for subprocess spawns. Dependencies: fixed 6 production CVEs (drizzle-orm, fastify, fast-uri, @fastify/static, next, archiver/lodash). Pinned all GitHub Actions to SHA hashes. 114 security tests added. Full OWASP Top 10 penetration test matrix verified against production Docker container (30/30 pass after hardening).
This commit is contained in:
+48
-10
@@ -1,7 +1,7 @@
|
||||
import { existsSync, mkdirSync, readFileSync, readdirSync, writeFileSync } from "node:fs";
|
||||
import { existsSync, mkdirSync, readdirSync, readFileSync, writeFileSync } from "node:fs";
|
||||
import { createRequire } from "node:module";
|
||||
import { dirname, join } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { createRequire } from "node:module";
|
||||
|
||||
const require = createRequire(import.meta.url);
|
||||
const sharp = require("sharp");
|
||||
@@ -107,15 +107,43 @@ const CURATED_BOXES = {
|
||||
|
||||
function classifyCategory(name) {
|
||||
const n = name.toLowerCase();
|
||||
if (/brain|boyfriend|buff|vs|tuxedo|pooh|handshake|same picture|gru|clown|bike|exit|draw 25|horse|scroll|virgin|bell curve/i.test(n)) return "comparison";
|
||||
if (/change my mind|pills|lisa|hannibal|boardroom|balloon|salesman|getting paid|everywhere|megamind|presentation|bernie|roof/i.test(n)) return "opinion";
|
||||
if (/doge|cat|dog|skeleton|kermit|monkey|penguin|cheems|pigeon|spongebob|bird|frog|seal|bear/i.test(n)) return "animals";
|
||||
if (/simply|y u no|bad luck|success|aliens|batman|first time|well yes|flex|x everywhere|ancient|futurama|matrix|chuck/i.test(n)) return "classic";
|
||||
if (
|
||||
/brain|boyfriend|buff|vs|tuxedo|pooh|handshake|same picture|gru|clown|bike|exit|draw 25|horse|scroll|virgin|bell curve/i.test(
|
||||
n,
|
||||
)
|
||||
)
|
||||
return "comparison";
|
||||
if (
|
||||
/change my mind|pills|lisa|hannibal|boardroom|balloon|salesman|getting paid|everywhere|megamind|presentation|bernie|roof/i.test(
|
||||
n,
|
||||
)
|
||||
)
|
||||
return "opinion";
|
||||
if (
|
||||
/doge|cat|dog|skeleton|kermit|monkey|penguin|cheems|pigeon|spongebob|bird|frog|seal|bear/i.test(
|
||||
n,
|
||||
)
|
||||
)
|
||||
return "animals";
|
||||
if (
|
||||
/simply|y u no|bad luck|success|aliens|batman|first time|well yes|flex|x everywhere|ancient|futurama|matrix|chuck/i.test(
|
||||
n,
|
||||
)
|
||||
)
|
||||
return "classic";
|
||||
return "reaction";
|
||||
}
|
||||
|
||||
function generateTags(name) {
|
||||
return [...new Set(name.toLowerCase().replace(/[^a-z0-9\s]/g, "").split(/\s+/).filter((w) => w.length > 2))];
|
||||
return [
|
||||
...new Set(
|
||||
name
|
||||
.toLowerCase()
|
||||
.replace(/[^a-z0-9\s]/g, "")
|
||||
.split(/\s+/)
|
||||
.filter((w) => w.length > 2),
|
||||
),
|
||||
];
|
||||
}
|
||||
|
||||
async function downloadImage(url, dest) {
|
||||
@@ -135,7 +163,10 @@ async function main() {
|
||||
let downloaded = 0;
|
||||
|
||||
for (const meme of memes) {
|
||||
const slug = meme.name.toLowerCase().replace(/[^a-z0-9]+/g, "-").replace(/^-|-$/g, "");
|
||||
const slug = meme.name
|
||||
.toLowerCase()
|
||||
.replace(/[^a-z0-9]+/g, "-")
|
||||
.replace(/^-|-$/g, "");
|
||||
const filename = slug + ".jpg";
|
||||
const destPath = join(FULL_DIR, filename);
|
||||
|
||||
@@ -171,7 +202,11 @@ async function main() {
|
||||
|
||||
console.log(`\nDownloaded ${downloaded} new images`);
|
||||
|
||||
const manifest = { version: 1, categories: ["reaction", "comparison", "opinion", "animals", "classic"], templates };
|
||||
const manifest = {
|
||||
version: 1,
|
||||
categories: ["reaction", "comparison", "opinion", "animals", "classic"],
|
||||
templates,
|
||||
};
|
||||
writeFileSync(MANIFEST_PATH, JSON.stringify(manifest, null, 2));
|
||||
console.log(`Manifest: ${templates.length} templates`);
|
||||
|
||||
@@ -180,7 +215,10 @@ async function main() {
|
||||
for (const file of files) {
|
||||
const thumbPath = join(THUMBS_DIR, file.replace(".jpg", ".webp"));
|
||||
if (!existsSync(thumbPath)) {
|
||||
await sharp(join(FULL_DIR, file)).resize({ width: 200 }).webp({ quality: 80 }).toFile(thumbPath);
|
||||
await sharp(join(FULL_DIR, file))
|
||||
.resize({ width: 200 })
|
||||
.webp({ quality: 80 })
|
||||
.toFile(thumbPath);
|
||||
}
|
||||
}
|
||||
console.log(`Thumbnails: ${readdirSync(THUMBS_DIR).length}`);
|
||||
|
||||
Reference in New Issue
Block a user