fix(security): harden API against pentest findings

- Default TRUST_PROXY=false to prevent XFF rate limit bypass (PT-01)
- Return 400 instead of 500 on malformed JSON input (PT-03)
- Default MAX_PIPELINE_STEPS=20 to prevent DoS (PT-04)
- Validate clientJobId length (max 128) across all routes (PT-06)
- Add security headers to all reply.hijack() streaming responses (PT-07)
- Sanitize usernames in audit log to prevent stored XSS (PT-08)
- Block TRACE method with 405 response (PT-10)
- Add 429 RateLimited response to OpenAPI spec (PT-12)
- Default MAX_SVG_SIZE_MB=50 to limit SVGZ decompression (PT-13)
- Pin Dockerfile base images by digest
- Sanitize OIDC IdP error and sub claim in audit log
- Sync Docker compose/Dockerfile defaults with env.ts
This commit is contained in:
SnapOtter
2026-06-07 21:54:27 +08:00
parent 19f40f58c9
commit ace41168bc
20 changed files with 122 additions and 24 deletions
+25
View File
@@ -59,6 +59,31 @@ components:
scheme: bearer
description: Session token from login or API key (prefixed with si_)
responses:
RateLimited:
description: Too many requests. The client has exceeded the rate limit.
headers:
Retry-After:
schema:
type: integer
description: Seconds until the rate limit window resets
X-RateLimit-Limit:
schema:
type: integer
description: Maximum requests per time window
X-RateLimit-Remaining:
schema:
type: integer
description: Remaining requests in current window
content:
application/json:
schema:
type: object
properties:
error:
type: string
example: Rate limit exceeded
schemas:
Error:
type: object