mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
fix(security): push-endpoint SSRF guard + tmux name validation; document tail-file roots
- M7 (SSRF): add isSafePushEndpoint (https-only; reject internal/loopback/link-local/metadata IPs incl. IPv4-mapped); enforce in PushSubscribeSchema and re-check before webpush.sendNotification. + unit test. - M1 (command injection): validate tmux session names with isValidMuxName in sessionExists, killSession, and reconcileSessions before they reach a shell call site. - M5: keep the intentional /var/log + ~/logs log-tail roots (a tested feature) and document the wider read scope in docs/security-architecture.md section 5 instead of dropping it. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -395,8 +395,12 @@ export class FileStreamManager extends EventEmitter {
|
||||
// Normalize the working directory
|
||||
const normalizedWorkingDir = resolve(workingDir);
|
||||
|
||||
// Check if the resolved path is within the working directory
|
||||
// or common log directories (/tmp intentionally excluded — world-writable)
|
||||
// Allowed read roots for log tailing: the session working dir plus the
|
||||
// INTENTIONAL log directories (/var/log, ~/logs). This is wider than the
|
||||
// per-session boundary used by validateSessionFilePath — a deliberate,
|
||||
// tested design choice for tailing system/app logs, documented as such in
|
||||
// docs/security-architecture.md (security review M5). /tmp is excluded
|
||||
// (world-writable).
|
||||
const allowedPaths = [normalizedWorkingDir, '/var/log', resolve(homedir(), 'logs')];
|
||||
|
||||
const isAllowed = allowedPaths.some((allowed) => {
|
||||
|
||||
Reference in New Issue
Block a user