fix: validate WS resize dimensions to match HTTP route bounds

The HTTP resize route validates via ResizeSchema (cols: 1-500, rows:
1-200, integers only). The WS handler only checked typeof === 'number',
allowing floats, negatives, and extreme values through to ptyProcess.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
arkon
2026-03-14 17:57:20 +01:00
co-authored by Claude Opus 4.6
parent ceaf4624a1
commit 5844720525
+9 -1
View File
@@ -81,7 +81,15 @@ export function registerWsRoutes(app: FastifyInstance, ctx: SessionPort): void {
if (msg.t === 'i' && typeof msg.d === 'string') {
if (msg.d.length > MAX_INPUT_LENGTH) return;
session.write(msg.d);
} else if (msg.t === 'z' && typeof msg.c === 'number' && typeof msg.r === 'number') {
} else if (
msg.t === 'z' &&
Number.isInteger(msg.c) &&
Number.isInteger(msg.r) &&
msg.c >= 1 &&
msg.c <= 500 &&
msg.r >= 1 &&
msg.r <= 200
) {
session.resize(msg.c, msg.r);
}
} catch {