Address the seven findings from the security & deployment review. High: - upload: make infer authoritative — reject files it can't identify (SVG/HTML/JS) and require the detected MIME to be on an ALLOWED_MEDIA allowlist; derive the stored MIME and on-disk extension from the detected type, ignoring client filename/Content-Type. Closes the stored-XSS vector via media served on-origin. - deploy: rename docker-compose.override.yml -> docker-compose.dev.yml so the default `docker compose up -d` no longer publishes Postgres 5432 to the host; the port map is now opt-in via -f. README updated. Medium: - upload: DefaultBodyLimit::disable() -> max(576 MiB) as an HTTP-level OOM backstop; handler still enforces precise per-class size limits. - docker: run backend and frontend as non-root users. Low: - social/upload: event-scope toggle_like, list_comments, add_comment, delete_comment, edit_upload, delete_upload via find_by_id_and_event / soft_delete_in_event — cross-event IDs now resolve to 404. - Caddy: site-wide HSTS / nosniff / X-Frame-Options / Referrer-Policy, plus Content-Disposition: attachment on /media/originals/*. - .env.example: replace default Postgres password with a CHANGE_ME hint. Out of scope: localStorage JWT (root cause fixed; httpOnly cookies are a larger change tracked separately). Verified: cargo build (no new warnings), cargo test (3 passed), caddy validate, docker compose config (no 5432 published by default). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
36 lines
980 B
Docker
36 lines
980 B
Docker
# --- Build stage ---
|
|
FROM rust:1.88-alpine AS builder
|
|
|
|
RUN apk add --no-cache musl-dev pkgconfig openssl-dev
|
|
|
|
WORKDIR /app
|
|
COPY Cargo.toml Cargo.lock* ./
|
|
# Pre-fetch deps with a dummy build for layer caching
|
|
RUN mkdir src && echo "fn main(){}" > src/main.rs && \
|
|
cargo build --release && \
|
|
rm -rf src
|
|
|
|
COPY src ./src
|
|
COPY static ./static
|
|
COPY migrations ./migrations
|
|
RUN touch src/main.rs && cargo build --release
|
|
|
|
# --- Runtime stage ---
|
|
FROM alpine:3.21
|
|
|
|
RUN apk add --no-cache ca-certificates ffmpeg
|
|
|
|
# Run as a non-root user. Pre-create and chown the media mount path so the fresh
|
|
# named volume inherits the non-root ownership (Docker seeds an empty named volume
|
|
# from the image directory, preserving its uid/gid) and uploads can be written.
|
|
RUN addgroup -S app && adduser -S app -G app
|
|
|
|
WORKDIR /app
|
|
COPY --from=builder /app/target/release/eventsnap-backend ./
|
|
|
|
RUN mkdir -p /media && chown -R app:app /app /media
|
|
USER app
|
|
|
|
EXPOSE 3000
|
|
CMD ["./eventsnap-backend"]
|