fix(security): high — live authz, XFF, SSE buffering, atomicity, pagination

H1: auth extractor re-reads the live user row — trusts the DB role (not the
    JWT claim) and rejects banned users mid-session. e2e proves a demoted
    host loses powers and a banned host is locked out and can't self-unban.
H2: client_ip takes the right-most XFF hop (the one Caddy appends); spoofed
    left-most entries are ignored, restoring IP-based throttles.
H3: Caddy excludes /api/v1/stream from `encode` so SSE isn't buffered.
H4: upload — quota increment + row insert + hashtag links now one txn.
H5: feed keyset pagination tiebroken on (created_at, id) + composite index
    (migration 010); feed_delta bounded with LIMIT.
H7: LightboxModal keys its comment load off upload.id, ending the
    SSE-driven refetch storm.
H8: CSP via SvelteKit kit.csp (svelte.config.js) hardens the localStorage
    token model against injection.

Migration 010 also adds the latent comment/comment_hashtag indexes.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
fabi
2026-07-01 21:25:50 +02:00
parent 498b4e256b
commit f08d858281
12 changed files with 248 additions and 83 deletions

View File

@@ -6,7 +6,28 @@ const config = {
runes: true
},
kit: {
adapter: adapter()
adapter: adapter(),
// Content-Security-Policy — the highest-value header for this UGC app and the
// cheapest hardening of the localStorage-based auth (the whole model rests on
// never having an XSS). `mode: 'auto'` lets SvelteKit nonce/hash its own inline
// hydration script, so script-src stays free of 'unsafe-inline'.
csp: {
mode: 'auto',
directives: {
'default-src': ['self'],
'script-src': ['self'],
// Svelte emits inline style attributes (style: directives); allow them.
'style-src': ['self', 'unsafe-inline'],
'img-src': ['self', 'data:', 'blob:'],
'media-src': ['self', 'blob:'],
'font-src': ['self'],
'connect-src': ['self'],
'object-src': ['none'],
'base-uri': ['self'],
'form-action': ['self'],
'frame-ancestors': ['none']
}
}
}
};