mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix(security): security audit and hardening (#207)
* fix(security): harden SVG sanitizer, rate limiting, and analytics defaults - SVG: add control-char stripping in href values to block whitespace/null-byte obfuscated javascript: URIs; block <feImage> with external href (SSRF via SVG filter primitives); expand test suite to 32 inline bypass payloads - Rate limiting: add per-route limits on tool endpoints (60/min) and batch (20/min); fix compose files defaulting RATE_LIMIT_PER_MIN to 0 which mapped to 50,000 in code; simplify rate limit registration to use env.ts default - Analytics: default ANALYTICS_ENABLED to false so self-hosters do not unknowingly send telemetry - Docker: add --max-time 5 and -s flags to compose healthcheck curl commands * fix: remove stale login limit bypass, reduce error log noise, clean up fixtures - Fix getLoginAttemptLimit() ignoring LOGIN_ATTEMPT_LIMIT when global rate limit exceeded 1000/min, which let the global limit override the stricter per-route login brute-force protection - Downgrade rate limit 429 responses from error to warn level in the global error handler to avoid log noise and unnecessary Sentry reports - Log 4xx client errors at warn level instead of error level - Remove 11 orphaned SVG attack fixture files replaced by inline test payloads
This commit is contained in:
@@ -33,7 +33,7 @@ services:
|
||||
- MAX_WORKER_THREADS=${MAX_WORKER_THREADS:-0}
|
||||
- PROCESSING_TIMEOUT_S=${PROCESSING_TIMEOUT_S:-0}
|
||||
- MAX_PIPELINE_STEPS=${MAX_PIPELINE_STEPS:-0}
|
||||
- RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-0}
|
||||
- RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-1000}
|
||||
- MAX_USERS=${MAX_USERS:-0}
|
||||
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
|
||||
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||
@@ -81,7 +81,7 @@ services:
|
||||
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
|
||||
# instead of PUID/PGID for read-only rootfs support.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
|
||||
test: ["CMD", "curl", "-sf", "--max-time", "5", "http://localhost:1349/api/v1/health"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
start_period: 60s
|
||||
|
||||
@@ -32,7 +32,7 @@ services:
|
||||
- MAX_WORKER_THREADS=${MAX_WORKER_THREADS:-0}
|
||||
- PROCESSING_TIMEOUT_S=${PROCESSING_TIMEOUT_S:-0}
|
||||
- MAX_PIPELINE_STEPS=${MAX_PIPELINE_STEPS:-0}
|
||||
- RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-0}
|
||||
- RATE_LIMIT_PER_MIN=${RATE_LIMIT_PER_MIN:-1000}
|
||||
- MAX_USERS=${MAX_USERS:-0}
|
||||
- SESSION_DURATION_HOURS=${SESSION_DURATION_HOURS:-168}
|
||||
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||
@@ -80,7 +80,7 @@ services:
|
||||
# writing to /etc/passwd and /etc/group. Consider using Docker --user flag
|
||||
# instead of PUID/PGID for read-only rootfs support.
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-f", "http://localhost:1349/api/v1/health"]
|
||||
test: ["CMD", "curl", "-sf", "--max-time", "5", "http://localhost:1349/api/v1/health"]
|
||||
interval: 30s
|
||||
timeout: 5s
|
||||
start_period: 60s
|
||||
|
||||
Reference in New Issue
Block a user