mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-04 14:39:42 +02:00
fix: extract QR auth magic numbers into named constants, add 16 security tests
Replace hardcoded per-IP rate limit (10) and cookie maxAge (86400) in system-routes.ts with QR_AUTH_FAILURE_MAX and AUTH_SESSION_TTL_MS/1000 so both auth paths stay in sync if constants change. Add 16 new tests: grace period boundary precision, base62 charset validation, current+previous token during grace, stopTokenRotation state cleanup, rate limit reset, consumed token eviction, full end-to-end QR flow, per-IP 429, cookie attributes, concurrent race, regenerate invalidation, URL encoding, path traversal, /q without param, and session record method:qr. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -30,6 +30,9 @@ export const QR_RATE_LIMIT_MAX = 30;
|
||||
/** QR rate limit reset window (ms) */
|
||||
export const QR_RATE_LIMIT_WINDOW_MS = 60_000;
|
||||
|
||||
/** Per-IP rate limit for QR auth failures (separate from Basic Auth AUTH_FAILURE_MAX) */
|
||||
export const QR_AUTH_FAILURE_MAX = 10;
|
||||
|
||||
// ============================================================================
|
||||
// Tunnel Process Lifecycle
|
||||
// ============================================================================
|
||||
|
||||
@@ -27,6 +27,8 @@ import { getLifecycleLog } from '../../session-lifecycle-log.js';
|
||||
import { findSessionOrFail, formatUptime, SETTINGS_PATH } from '../route-helpers.js';
|
||||
import type { SessionPort, EventPort, ConfigPort, InfraPort, AuthPort } from '../ports/index.js';
|
||||
import { AUTH_COOKIE_NAME } from '../middleware/auth.js';
|
||||
import { QR_AUTH_FAILURE_MAX } from '../../config/tunnel-config.js';
|
||||
import { AUTH_SESSION_TTL_MS } from '../../config/auth-config.js';
|
||||
|
||||
// Maximum screenshot upload size (10MB)
|
||||
const MAX_SCREENSHOT_SIZE = 10 * 1024 * 1024;
|
||||
@@ -134,7 +136,7 @@ export function registerSystemRoutes(
|
||||
|
||||
// Per-IP rate limit (separate counter from Basic Auth failures)
|
||||
const qrFailures = ctx.qrAuthFailures?.get(clientIp) ?? 0;
|
||||
if (qrFailures >= 10) {
|
||||
if (qrFailures >= QR_AUTH_FAILURE_MAX) {
|
||||
return reply.code(429).send('Too Many Requests');
|
||||
}
|
||||
|
||||
@@ -171,7 +173,7 @@ export function registerSystemRoutes(
|
||||
httpOnly: true,
|
||||
secure: ctx.https,
|
||||
sameSite: 'lax',
|
||||
maxAge: 86400, // 24h
|
||||
maxAge: AUTH_SESSION_TTL_MS / 1000,
|
||||
path: '/',
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user