From 5844720525aafb898cd0ddd007ab9cf75267ce99 Mon Sep 17 00:00:00 2001 From: arkon Date: Sat, 14 Mar 2026 17:57:20 +0100 Subject: [PATCH] fix: validate WS resize dimensions to match HTTP route bounds The HTTP resize route validates via ResizeSchema (cols: 1-500, rows: 1-200, integers only). The WS handler only checked typeof === 'number', allowing floats, negatives, and extreme values through to ptyProcess. Co-Authored-By: Claude Opus 4.6 --- src/web/routes/ws-routes.ts | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/src/web/routes/ws-routes.ts b/src/web/routes/ws-routes.ts index eca97788..e31b4f29 100644 --- a/src/web/routes/ws-routes.ts +++ b/src/web/routes/ws-routes.ts @@ -81,7 +81,15 @@ export function registerWsRoutes(app: FastifyInstance, ctx: SessionPort): void { if (msg.t === 'i' && typeof msg.d === 'string') { if (msg.d.length > MAX_INPUT_LENGTH) return; session.write(msg.d); - } else if (msg.t === 'z' && typeof msg.c === 'number' && typeof msg.r === 'number') { + } else if ( + msg.t === 'z' && + Number.isInteger(msg.c) && + Number.isInteger(msg.r) && + msg.c >= 1 && + msg.c <= 500 && + msg.r >= 1 && + msg.r <= 200 + ) { session.resize(msg.c, msg.r); } } catch {