mirror of
https://github.com/R0m1k3/FlowReader.git
synced 2026-10-11 17:28:05 +02:00
sécurité : correctifs XSS, SSRF, CSWSH, rate-limit et durcissement
- XSS stocké (critique) : sanitisation bluemonday sur tous les endpoints d'articles (List, ListByFeed, Favorites, Search, Get), pas seulement Get - SSRF (élevé) : nouveau utils/safehttp.go (ValidateExternalURL + client durci via Dialer.Control, bloque IP privées/loopback/link-local/metadata, anti-DNS-rebinding et limite de redirections) appliqué à l'extracteur et au parser - WebSocket CSWSH (élevé) : politique same-origin + override WS_ALLOWED_ORIGINS - rate-limiting (moyen) : token-bucket en mémoire sur /auth/* - token de session retiré du corps JSON (json:"-"), livré uniquement par le cookie HttpOnly - cookie Secure correct derrière un reverse-proxy (X-Forwarded-Proto + override COOKIE_SECURE) - admin : interdiction de supprimer son propre compte - en-têtes de sécurité (nosniff, X-Frame-Options, Referrer-Policy, Permissions-Policy) Note : backend non compilé localement (pas de toolchain Go) ; à valider via Docker. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
10fdfdeccb
commit
3402e53954
11 files changed
+346
-23
No files matched your search
+36
-3
@@ -4,16 +4,49 @@ import (
|
||||
"encoding/json"
|
||||
"log"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"os"
|
||||
"strings"
|
||||
"sync"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/gorilla/websocket"
|
||||
)
|
||||
|
||||
// allowedWSOrigins holds optional extra origins (comma-separated) from the
|
||||
// WS_ALLOWED_ORIGINS env var, for deployments where the WS host differs.
|
||||
var allowedWSOrigins = parseAllowedOrigins(os.Getenv("WS_ALLOWED_ORIGINS"))
|
||||
|
||||
func parseAllowedOrigins(raw string) map[string]bool {
|
||||
out := make(map[string]bool)
|
||||
for _, o := range strings.Split(raw, ",") {
|
||||
if o = strings.TrimSpace(strings.ToLower(o)); o != "" {
|
||||
out[o] = true
|
||||
}
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// checkOrigin enforces a same-origin policy to prevent Cross-Site WebSocket
|
||||
// Hijacking (CSWSH). Requests without an Origin header (non-browser clients)
|
||||
// are allowed; browser requests must match the Host or an allow-listed origin.
|
||||
func checkOrigin(r *http.Request) bool {
|
||||
origin := r.Header.Get("Origin")
|
||||
if origin == "" {
|
||||
return true // non-browser client (e.g. native app, curl)
|
||||
}
|
||||
u, err := url.Parse(origin)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
if strings.EqualFold(u.Host, r.Host) {
|
||||
return true
|
||||
}
|
||||
return allowedWSOrigins[strings.ToLower(u.Host)]
|
||||
}
|
||||
|
||||
var upgrader = websocket.Upgrader{
|
||||
CheckOrigin: func(r *http.Request) bool {
|
||||
return true // In production, check origin properly
|
||||
},
|
||||
CheckOrigin: checkOrigin,
|
||||
}
|
||||
|
||||
// Event represents a websocket event.
|
||||
|
||||
Reference in new issue
Block a user