mirror of
https://github.com/rcourtman/Pulse.git
synced 2026-10-03 12:42:43 +00:00
71abcb2a37
Addressed security concerns identified by Codex code review: 1. **Memory exhaustion protection** - Added http.MaxBytesReader with 32KB limit - Prevents malicious large POST from killing server 2. **Dangerous directive blocking** - Reject ProxyCommand, LocalCommand, RemoteCommand - Prevents command injection via SSH config 3. **Improved error handling** - Check all error returns properly - Return 5xx on failures - Log file size and path for debugging 4. **Scoped SSH config (critical fix)** - Changed from `Host *` to specific cluster nodes - Prevents overriding ALL SSH connections - Only affects Proxmox nodes for temperature monitoring - Preserves other SSH functionality (git, etc.) Before: Host * broke all SSH connections from Pulse After: Only Proxmox cluster nodes use ProxyJump Credit: Codex code review identified these issues
Internal API Package
This directory contains the API server implementation for Pulse.
Important Note About frontend-modern/
The frontend-modern/ subdirectory that appears here is:
- AUTO-GENERATED during builds
- NOT the source code - just a build artifact
- IN .gitignore - never committed
- REQUIRED BY GO - The embed directive needs it here
Frontend Development Location
👉 Edit frontend files at: /opt/pulse/frontend-modern/src/
Why This Structure?
Go's //go:embed directive has limitations:
- Cannot use
../paths to access parent directories - Cannot follow symbolic links
- Must embed files within the Go module
This is a known Go limitation and our structure works around it.