fix(security): server-authoritative approval gate + auth/session/file hardening
Remediate the HIGH and security-relevant findings from the 2026-07-11 audit. H1 — the per-env approval gate is now server-authoritative. The governing project is resolved from the target node's nearest-claimed ancestor (`governing_env_policy`/`_tree` + `governing_project_id` + `ProjectRepository::get_environments_by_id`), independent of the client-supplied `[project]`. Omitting or spoofing the project block can no longer skip a gate the owning project established; a to-create group resolves its declared parent's chain so a fresh subtree node inherits the gate. Fails closed on any read error. H2 — the API-key prefix slice (`&rest[..8]`) is now the boundary-safe `rest.get(..8)`, so an attacker-supplied multibyte bearer can't panic the request task (unauthenticated per-request DoS). Regression test added. C1 — admin sessions gain an absolute lifetime cap (migration 0070, `PICLOUD_SESSION_ABSOLUTE_TTL_HOURS`, default 30d): `lookup` filters it, `touch` clamps the sliding bump to it, so a continuously-used or stolen-but-warm token self-expires. Mirrors the data-plane app-user cap. C2 — `Cache-Control: no-store` on the login and API-key-mint responses (the two that return a raw credential), so a proxy/CDN/browser cache can't retain it. B8 — file downloads are header-safe: `sanitize_stored_filename` guarantees a valid `HeaderValue` (no panic on a control-char name) and BOTH the per-app and group download paths now set attachment + `X-Content-Type-Options: nosniff` + a restrictive CSP, closing a group-path stored-XSS gap. Also folds in the server-side plan-warning plumbing (`plan_warnings`, `PlanResult::warnings`) and the `app_only_reject` message helper that the CLI plan-preview change builds on, plus operator security notes (reads-open shared- topic SSE; the `--env` label is advisory, not a boundary). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -14,7 +14,8 @@
|
||||
use std::sync::Arc;
|
||||
|
||||
use axum::extract::{Path, Query, State};
|
||||
use axum::http::header::{CONTENT_LENGTH, CONTENT_TYPE};
|
||||
use axum::http::header::{CONTENT_DISPOSITION, CONTENT_LENGTH, CONTENT_TYPE};
|
||||
use axum::http::StatusCode;
|
||||
use axum::response::{IntoResponse, Json, Response};
|
||||
use axum::routing::get;
|
||||
use axum::{Extension, Router};
|
||||
@@ -287,14 +288,29 @@ async fn get_file(
|
||||
.await
|
||||
.map_err(|e| GroupBlobsError::Backend(e.to_string()))?
|
||||
.ok_or(GroupBlobsError::NotFound)?;
|
||||
Ok((
|
||||
[
|
||||
(CONTENT_TYPE, meta.content_type),
|
||||
(CONTENT_LENGTH, bytes.len().to_string()),
|
||||
],
|
||||
bytes,
|
||||
)
|
||||
.into_response())
|
||||
// Same download hardening as the per-app path (`files_api::get_file`): a
|
||||
// sanitized content-type, forced `attachment` disposition with a header-safe
|
||||
// filename, plus nosniff/CSP so a stored HTML/SVG shared file can't render
|
||||
// inline (stored-XSS) and no attacker-influenced byte can panic the builder.
|
||||
let safe_ct = picloud_shared::sanitize_stored_content_type(&meta.content_type);
|
||||
let disposition = format!(
|
||||
"attachment; filename=\"{}\"",
|
||||
picloud_shared::sanitize_stored_filename(&meta.name)
|
||||
);
|
||||
let len = bytes.len();
|
||||
Response::builder()
|
||||
.status(StatusCode::OK)
|
||||
.header(CONTENT_TYPE, safe_ct)
|
||||
.header(CONTENT_DISPOSITION, disposition)
|
||||
.header(CONTENT_LENGTH, len)
|
||||
.header("X-Content-Type-Options", "nosniff")
|
||||
.header(
|
||||
"Content-Security-Policy",
|
||||
"default-src 'none'; sandbox; frame-ancestors 'none'",
|
||||
)
|
||||
.header("Referrer-Policy", "no-referrer")
|
||||
.body(axum::body::Body::from(bytes))
|
||||
.map_err(|e| GroupBlobsError::Backend(e.to_string()))
|
||||
}
|
||||
|
||||
/// §11.6 D3: list a group's shared-queue dead-letters (newest-first). Guarded by
|
||||
|
||||
Reference in New Issue
Block a user