fix(security): server-authoritative approval gate + auth/session/file hardening
Remediate the HIGH and security-relevant findings from the 2026-07-11 audit. H1 — the per-env approval gate is now server-authoritative. The governing project is resolved from the target node's nearest-claimed ancestor (`governing_env_policy`/`_tree` + `governing_project_id` + `ProjectRepository::get_environments_by_id`), independent of the client-supplied `[project]`. Omitting or spoofing the project block can no longer skip a gate the owning project established; a to-create group resolves its declared parent's chain so a fresh subtree node inherits the gate. Fails closed on any read error. H2 — the API-key prefix slice (`&rest[..8]`) is now the boundary-safe `rest.get(..8)`, so an attacker-supplied multibyte bearer can't panic the request task (unauthenticated per-request DoS). Regression test added. C1 — admin sessions gain an absolute lifetime cap (migration 0070, `PICLOUD_SESSION_ABSOLUTE_TTL_HOURS`, default 30d): `lookup` filters it, `touch` clamps the sliding bump to it, so a continuously-used or stolen-but-warm token self-expires. Mirrors the data-plane app-user cap. C2 — `Cache-Control: no-store` on the login and API-key-mint responses (the two that return a raw credential), so a proxy/CDN/browser cache can't retain it. B8 — file downloads are header-safe: `sanitize_stored_filename` guarantees a valid `HeaderValue` (no panic on a control-char name) and BOTH the per-app and group download paths now set attachment + `X-Content-Type-Options: nosniff` + a restrictive CSP, closing a group-path stored-XSS gap. Also folds in the server-side plan-warning plumbing (`plan_warnings`, `PlanResult::warnings`) and the `app_only_reject` message helper that the CLI plan-preview change builds on, plus operator security notes (reads-open shared- topic SSE; the `--env` label is advisory, not a boundary). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1381,3 +1381,22 @@ to take, not yet taken:
|
||||
§11.3. The remaining contract work here is only for script-body inheritance, Phase 4.)*
|
||||
- The **full manifest schema** spelling every block (scripts, routes, the 8 trigger kinds, storage
|
||||
config, env-scoped vars, secret-refs, domains, `[project.environments]` + confirm policy).
|
||||
|
||||
---
|
||||
|
||||
## 13. Operator security notes (audit 2026-07-11)
|
||||
|
||||
Two behaviors that are correct-by-design but easy to misread — call them out for operators:
|
||||
|
||||
- **Shared-topic SSE is world-readable by anyone who can name a subtree domain.** A group
|
||||
`kind='topic'` shared collection is *reads-open by design* (the declaration is the grant, matching
|
||||
shared KV/docs/files reads). An anonymous request to any descendant app's host can subscribe to the
|
||||
group's shared topic. This is intentional — but if a topic carries sensitive data, do NOT rely on
|
||||
obscurity: gate it at the app (an authed route that proxies the stream) or don't share it. Per-topic
|
||||
opt-in read gating is a possible future addition.
|
||||
- **The `--env` label is a client assertion, not an identity.** The env-approval gate governs *whether
|
||||
a confirm-required environment needs `--approve`*, but the label an apply carries (`--env production`)
|
||||
is chosen by the client. It does not by itself grant or restrict reach — the governing project's
|
||||
persisted policy (resolved server-side from the node's nearest-claimed ancestor, audit 2026-07-11 H1)
|
||||
is what's authoritative. Mislabeling `production` content as `staging` cannot dodge a gate the owning
|
||||
project set on the *node*, but operators should treat the label as advisory metadata, not a boundary.
|
||||
|
||||
Reference in New Issue
Block a user