mirror of
https://github.com/R0m1k3/FlowReader.git
synced 2026-10-11 17:28:05 +02:00
fix(backend): harden security and speed up feeds and article API
Security: - WebSocket events are routed to their owner only (no cross-user leak); hub close is idempotent (fixes double-close panic), adds ping/pong and write deadlines. - Session tokens stored as SHA-256 (migration 008 keeps sessions valid); single-query auth middleware puts the user in the request context. - Client IP only trusts X-Forwarded-For from TRUSTED_PROXIES; rate limiter map is bounded; per-user limit on AI summaries. - Argon2id at OWASP minimum with a concurrency cap; constant-time login for unknown emails; atomic first-admin bootstrap; REGISTRATION_ENABLED. - CSP/HSTS/COOP headers, same-origin guard on mutations, body size limits, wider SSRF denylist, bounded feed/page/AI response reads, generic errors. - Upgrade chi, pgx, x/net, x/text, x/crypto (known CVEs); commit go.sum. Performance: - List endpoints return a plain-text excerpt and reading time instead of full HTML; content is sanitized once at ingest (legacy rows backfilled). - Keyset pagination on (sort_at, id) with matching partial indexes; redundant indexes dropped (migration 007). - Fetcher: bounded worker pool, conditional GET (ETag/Last-Modified), exponential backoff, dedupe before insert, column-safe truncation, retention-aware ingest, per-user refresh coalescing. - Read/favorite/read-all are single ownership-scoped statements. - gzip compression, immutable caching for hashed assets, path-safe SPA handler, server timeouts; expired sessions purged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
d037e2be34
commit
03e57e4308
40 files changed
+2231
-1898
No files matched your search
+140
-85
@@ -3,9 +3,13 @@ package main
|
||||
import (
|
||||
"context"
|
||||
"log"
|
||||
"mime"
|
||||
"net/http"
|
||||
"os"
|
||||
"os/signal"
|
||||
"path"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
@@ -21,6 +25,9 @@ import (
|
||||
)
|
||||
|
||||
func main() {
|
||||
// PWA manifest: Go's mime table doesn't know this extension.
|
||||
_ = mime.AddExtensionType(".webmanifest", "application/manifest+json")
|
||||
|
||||
// Load configuration
|
||||
cfg := config.Load()
|
||||
|
||||
@@ -32,7 +39,7 @@ func main() {
|
||||
}
|
||||
defer pool.Close()
|
||||
|
||||
// Check migrations status (warning only, doesn't block)
|
||||
// Apply pending migrations (warning only, doesn't block)
|
||||
if err := database.RunMigrations(ctx, pool); err != nil {
|
||||
log.Printf("Migration check warning: %v", err)
|
||||
}
|
||||
@@ -52,44 +59,38 @@ func main() {
|
||||
hub := ws.NewHub()
|
||||
go hub.Run()
|
||||
|
||||
fetchService := service.NewFetchService(feedRepo, articleRepo, hub)
|
||||
// Keep outbound fetch concurrency modest so it doesn't starve the
|
||||
// 10-connection DB pool used by API requests.
|
||||
fetchService := service.NewFetchService(feedRepo, articleRepo, hub, 4)
|
||||
|
||||
// Initialize handlers
|
||||
authHandler := handler.NewAuthHandler(authService)
|
||||
feedHandler := handler.NewFeedHandler(feedService, fetchService, authService)
|
||||
articleHandler := handler.NewArticleHandler(articleRepo, feedService, authService, aiService, hub)
|
||||
articleHandler := handler.NewArticleHandler(articleRepo, aiService, hub)
|
||||
wsHandler := handler.NewWSHandler(hub, authService)
|
||||
adminHandler := handler.NewAdminHandler(userRepo, authService)
|
||||
|
||||
// Start background workers
|
||||
fetcher := worker.NewFeedFetcher(fetchService, 15*time.Minute, 5)
|
||||
// Start background workers. Each feed carries its own next_fetch_at; the
|
||||
// fetcher only looks for due feeds every minute.
|
||||
fetcher := worker.NewFeedFetcher(fetchService, time.Minute, 4)
|
||||
fetcher.Start()
|
||||
defer fetcher.Stop()
|
||||
|
||||
cleaner := worker.NewCleaner(articleRepo, 24*time.Hour)
|
||||
cleaner := worker.NewCleaner(articleRepo, authService, 24*time.Hour)
|
||||
cleaner.Start()
|
||||
defer cleaner.Stop()
|
||||
|
||||
requireAuth := handler.RequireAuth(authService)
|
||||
|
||||
// Initialize router
|
||||
r := chi.NewRouter()
|
||||
|
||||
// Middleware
|
||||
// Note: no middleware.RealIP — client IPs come from RemoteAddr, and
|
||||
// X-Forwarded-For is only honoured from TRUSTED_PROXIES (see handler).
|
||||
r.Use(middleware.RequestID)
|
||||
r.Use(middleware.Logger)
|
||||
r.Use(middleware.Recoverer)
|
||||
r.Use(middleware.RequestID)
|
||||
r.Use(middleware.RealIP)
|
||||
r.Use(middleware.Timeout(30 * time.Second))
|
||||
|
||||
// Baseline security headers (defense in depth).
|
||||
r.Use(func(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, req *http.Request) {
|
||||
w.Header().Set("X-Content-Type-Options", "nosniff")
|
||||
w.Header().Set("X-Frame-Options", "DENY")
|
||||
w.Header().Set("Referrer-Policy", "strict-origin-when-cross-origin")
|
||||
w.Header().Set("Permissions-Policy", "geolocation=(), microphone=(), camera=()")
|
||||
next.ServeHTTP(w, req)
|
||||
})
|
||||
})
|
||||
r.Use(handler.SecurityHeaders)
|
||||
|
||||
// Health check endpoint
|
||||
r.Get("/health", func(w http.ResponseWriter, r *http.Request) {
|
||||
@@ -103,85 +104,102 @@ func main() {
|
||||
})
|
||||
|
||||
// API routes
|
||||
r.Route("/api/v1", func(r chi.Router) {
|
||||
r.Get("/", func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.Write([]byte(`{"message":"FlowReader API v1"}`))
|
||||
r.Route("/api/v1", func(api chi.Router) {
|
||||
api.Use(handler.SameOriginGuard)
|
||||
api.Use(func(next http.Handler) http.Handler {
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Cache-Control", "no-store")
|
||||
next.ServeHTTP(w, r)
|
||||
})
|
||||
})
|
||||
|
||||
// Auth routes (public) — rate-limited to mitigate brute-force attacks.
|
||||
r.Route("/auth", func(r chi.Router) {
|
||||
r.Use(handler.NewAuthRateLimiter())
|
||||
r.Post("/register", authHandler.Register)
|
||||
r.Post("/login", authHandler.Login)
|
||||
r.Post("/logout", authHandler.Logout)
|
||||
// Regular JSON endpoints: compressed, 1 MiB bodies, 30s budget.
|
||||
api.Group(func(r chi.Router) {
|
||||
r.Use(middleware.Compress(5, "application/json", "application/xml", "text/plain"))
|
||||
r.Use(handler.LimitBody(1 << 20))
|
||||
r.Use(middleware.Timeout(30 * time.Second))
|
||||
|
||||
r.Get("/", func(w http.ResponseWriter, r *http.Request) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.Write([]byte(`{"message":"FlowReader API v1"}`))
|
||||
})
|
||||
|
||||
// Auth routes (public) — rate-limited to mitigate brute-force attacks.
|
||||
r.Route("/auth", func(r chi.Router) {
|
||||
r.Use(handler.NewAuthRateLimiter())
|
||||
r.Post("/register", authHandler.Register)
|
||||
r.Post("/login", authHandler.Login)
|
||||
r.Post("/logout", authHandler.Logout)
|
||||
})
|
||||
|
||||
// Everything below requires a valid session (one SQL lookup).
|
||||
r.Group(func(r chi.Router) {
|
||||
r.Use(requireAuth)
|
||||
|
||||
r.Get("/users/me", authHandler.Me)
|
||||
|
||||
r.Route("/feeds", func(r chi.Router) {
|
||||
r.Get("/", feedHandler.List)
|
||||
r.Post("/", feedHandler.Add)
|
||||
r.Post("/refresh", feedHandler.Refresh)
|
||||
r.Get("/export/opml", feedHandler.ExportOPML)
|
||||
r.Get("/{id}", feedHandler.Get)
|
||||
r.Patch("/{id}", feedHandler.Update)
|
||||
r.Delete("/{id}", feedHandler.Delete)
|
||||
r.Get("/{id}/articles", articleHandler.ListByFeed)
|
||||
r.Post("/{id}/read-all", articleHandler.MarkAllRead)
|
||||
})
|
||||
|
||||
r.Route("/articles", func(r chi.Router) {
|
||||
r.Get("/", articleHandler.List)
|
||||
r.Get("/search", articleHandler.Search)
|
||||
r.Post("/read-all", articleHandler.MarkAllReadGlobal)
|
||||
r.Get("/favorites", articleHandler.GetFavorites)
|
||||
r.Get("/{id}", articleHandler.Get)
|
||||
r.Post("/{id}/read", articleHandler.MarkRead)
|
||||
r.Delete("/{id}/read", articleHandler.MarkUnread)
|
||||
r.Post("/{id}/favorite", articleHandler.ToggleFavorite)
|
||||
})
|
||||
|
||||
r.Route("/admin", func(r chi.Router) {
|
||||
r.Use(adminHandler.AdminOnly)
|
||||
r.Get("/users", adminHandler.ListUsers)
|
||||
r.Delete("/users/{id}", adminHandler.DeleteUser)
|
||||
})
|
||||
})
|
||||
})
|
||||
|
||||
// User routes
|
||||
r.Route("/users", func(r chi.Router) {
|
||||
r.Get("/me", authHandler.Me)
|
||||
})
|
||||
// OPML import: larger body.
|
||||
api.With(handler.LimitBody(5<<20), middleware.Timeout(60*time.Second), requireAuth).
|
||||
Post("/feeds/import/opml", feedHandler.ImportOPML)
|
||||
|
||||
// Feed routes
|
||||
r.Route("/feeds", func(r chi.Router) {
|
||||
r.Get("/", feedHandler.List)
|
||||
r.Post("/", feedHandler.Add)
|
||||
r.Post("/refresh", feedHandler.Refresh)
|
||||
r.Post("/import/opml", feedHandler.ImportOPML)
|
||||
r.Get("/export/opml", feedHandler.ExportOPML)
|
||||
r.Get("/{id}", feedHandler.Get)
|
||||
r.Patch("/{id}", feedHandler.Update)
|
||||
r.Delete("/{id}", feedHandler.Delete)
|
||||
r.Get("/{id}/articles", articleHandler.ListByFeed)
|
||||
r.Post("/{id}/read-all", articleHandler.MarkAllRead)
|
||||
})
|
||||
// AI summaries: slow (page extraction + LLM) and costly, so a longer
|
||||
// budget and a per-user rate limit.
|
||||
api.With(handler.LimitBody(1<<10), requireAuth, handler.NewUserRateLimiter(6, 3), middleware.Timeout(90*time.Second)).
|
||||
Post("/articles/{id}/summarize", articleHandler.Summarize)
|
||||
|
||||
// Article routes
|
||||
r.Route("/articles", func(r chi.Router) {
|
||||
r.Get("/", articleHandler.List)
|
||||
r.Get("/search", articleHandler.Search)
|
||||
r.Post("/read-all", articleHandler.MarkAllReadGlobal)
|
||||
r.Get("/favorites", articleHandler.GetFavorites)
|
||||
r.Get("/{id}", articleHandler.Get)
|
||||
r.Post("/{id}/read", articleHandler.MarkRead)
|
||||
r.Delete("/{id}/read", articleHandler.MarkUnread)
|
||||
r.Post("/{id}/favorite", articleHandler.ToggleFavorite)
|
||||
r.Post("/{id}/summarize", articleHandler.Summarize)
|
||||
})
|
||||
|
||||
// WebSocket route
|
||||
r.Get("/ws", wsHandler.Connect)
|
||||
|
||||
// Admin routes
|
||||
r.Route("/admin", func(r chi.Router) {
|
||||
r.Use(adminHandler.AdminOnly)
|
||||
r.Get("/users", adminHandler.ListUsers)
|
||||
r.Delete("/users/{id}", adminHandler.DeleteUser)
|
||||
})
|
||||
// WebSocket: no compression or timeout middleware (hijacked conn).
|
||||
api.With(requireAuth).Get("/ws", wsHandler.Connect)
|
||||
})
|
||||
|
||||
// Serve Static Files (Frontend)
|
||||
staticPath := "./web/dist"
|
||||
if _, err := os.Stat(staticPath); err == nil {
|
||||
fs := http.FileServer(http.Dir(staticPath))
|
||||
r.Handle("/*", http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
// If the file exists, serve it, otherwise serve index.html (for SPA routing)
|
||||
path := staticPath + r.URL.Path
|
||||
if _, err := os.Stat(path); os.IsNotExist(err) {
|
||||
http.ServeFile(w, r, staticPath+"/index.html")
|
||||
return
|
||||
}
|
||||
fs.ServeHTTP(w, r)
|
||||
}))
|
||||
r.Group(func(r chi.Router) {
|
||||
r.Use(middleware.Compress(5, "text/html", "text/css", "application/javascript", "text/javascript", "image/svg+xml", "application/manifest+json"))
|
||||
r.Handle("/*", spaHandler(staticPath))
|
||||
})
|
||||
}
|
||||
|
||||
// Create server
|
||||
srv := &http.Server{
|
||||
Addr: ":" + cfg.Port,
|
||||
Handler: r,
|
||||
ReadTimeout: 15 * time.Second,
|
||||
WriteTimeout: 15 * time.Second,
|
||||
IdleTimeout: 60 * time.Second,
|
||||
Addr: ":" + cfg.Port,
|
||||
Handler: r,
|
||||
ReadHeaderTimeout: 5 * time.Second,
|
||||
ReadTimeout: 30 * time.Second,
|
||||
WriteTimeout: 35 * time.Second, // summarize extends its own deadline
|
||||
IdleTimeout: 120 * time.Second,
|
||||
MaxHeaderBytes: 64 << 10,
|
||||
}
|
||||
|
||||
// Graceful shutdown
|
||||
@@ -207,3 +225,40 @@ func main() {
|
||||
|
||||
log.Println("Server exited properly")
|
||||
}
|
||||
|
||||
// spaHandler serves the built frontend: hashed assets are cached forever,
|
||||
// HTML / service worker files must revalidate, unknown paths fall back to
|
||||
// index.html for client-side routing.
|
||||
func spaHandler(root string) http.Handler {
|
||||
fs := http.FileServer(http.Dir(root))
|
||||
index := filepath.Join(root, "index.html")
|
||||
|
||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
// Clean the URL path (always forward slashes) so "../" can't probe the
|
||||
// container filesystem, then map it onto the OS path.
|
||||
clean := path.Clean("/" + r.URL.Path)
|
||||
full := filepath.Join(root, filepath.FromSlash(clean))
|
||||
|
||||
info, err := os.Stat(full)
|
||||
if err != nil || info.IsDir() {
|
||||
if strings.HasPrefix(clean, "/assets/") || strings.HasPrefix(clean, "/api/") {
|
||||
http.NotFound(w, r)
|
||||
return
|
||||
}
|
||||
w.Header().Set("Cache-Control", "no-cache")
|
||||
http.ServeFile(w, r, index)
|
||||
return
|
||||
}
|
||||
|
||||
switch {
|
||||
case strings.HasPrefix(clean, "/assets/"):
|
||||
w.Header().Set("Cache-Control", "public, max-age=31536000, immutable")
|
||||
case strings.HasSuffix(clean, ".html"), clean == "/sw.js", clean == "/registerSW.js",
|
||||
strings.HasPrefix(clean, "/workbox-"), strings.HasSuffix(clean, ".webmanifest"):
|
||||
w.Header().Set("Cache-Control", "no-cache")
|
||||
default:
|
||||
w.Header().Set("Cache-Control", "public, max-age=86400")
|
||||
}
|
||||
fs.ServeHTTP(w, r)
|
||||
})
|
||||
}
|
||||
Reference in new issue
Block a user