mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-04 22:49:41 +02:00
Hardens `/api/sessions/:id/paste-image` against the seven findings flagged in the dismissed security review on #84. Each commit addresses one finding. - LOW: Collision-free filenames (`paste-${ts}-${rand4}${ext}`) - MED: Symlink check on image dir (`lstat` + non-recursive mkdir + `O_EXCL|O_NOFOLLOW`) - MED: Magic-byte validation (PNG/JPEG/GIF/WebP/BMP) - HIGH: CSRF protection (Origin/Referer match req.host; non-browser clients send `X-Codeman-CSRF`) - MED: Swap hand-rolled multipart parser to @fastify/multipart with `limits: { fileSize: 10MB, files: 1, fields: 4 }` - MED: Rate limit (30/min per IP+session) + hourly GC of `paste-*` files older than 7d - LOW: Use `terminal.paste(text)` instead of `sendInput(text)` so bracketed-paste markers survive Co-authored-by: Aamer Akhter <aakhter@gmail.com>
This commit is contained in:
@@ -52,6 +52,7 @@
|
||||
"dependencies": {
|
||||
"@fastify/compress": "^8.3.1",
|
||||
"@fastify/cookie": "^11.0.2",
|
||||
"@fastify/multipart": "^10.0.0",
|
||||
"@fastify/static": "^8.0.0",
|
||||
"@fastify/websocket": "^11.2.0",
|
||||
"@xterm/addon-fit": "^0.11.0",
|
||||
|
||||
Reference in New Issue
Block a user