mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-09-04 14:45:41 +00:00
security: harden terminal WebSocket endpoints against three attack vectors
- Reject node_proxy scoped JWT tokens with 403 on host-console and container exec (/ws) upgrades; machine-to-machine credentials must not open interactive shells - Validate stackParam against path.resolve + startsWith(baseDir) to prevent directory traversal on the PTY cwd (Rule 9 pattern) - Strip JWT_SECRET, AUTH_PASSWORD, AUTH_PASSWORD_HASH, DATABASE_URL from the environment passed to node-pty spawned shells
This commit is contained in:
+28
-4
@@ -456,7 +456,11 @@ server.on('upgrade', async (req, socket, head) => {
|
||||
const settings = DatabaseService.getInstance().getGlobalSettings();
|
||||
const jwtSecret = settings.auth_jwt_secret;
|
||||
if (!jwtSecret) throw new Error('No JWT secret');
|
||||
jwt.verify(token, jwtSecret);
|
||||
const decoded = jwt.verify(token, jwtSecret) as { username?: string; scope?: string };
|
||||
|
||||
// Node proxy tokens are machine-to-machine credentials and must never be granted
|
||||
// interactive terminal access (host console or container exec).
|
||||
const isProxyToken = decoded.scope === 'node_proxy';
|
||||
|
||||
const url = req.url || '';
|
||||
const parsedUrl = new URL(url, `http://${req.headers.host || 'localhost'}`);
|
||||
@@ -520,15 +524,29 @@ server.on('upgrade', async (req, socket, head) => {
|
||||
}
|
||||
});
|
||||
} else if (hostConsoleMatch) {
|
||||
// Node proxy tokens must not access interactive host terminals
|
||||
if (isProxyToken) {
|
||||
socket.write('HTTP/1.1 403 Forbidden\r\n\r\n');
|
||||
socket.destroy();
|
||||
return;
|
||||
}
|
||||
const hostConsoleWss = new WebSocket.Server({ noServer: true });
|
||||
hostConsoleWss.handleUpgrade(req, socket, head, (ws) => {
|
||||
hostConsoleWss.close();
|
||||
let targetDirectory = '';
|
||||
try {
|
||||
targetDirectory = FileSystemService.getInstance(nodeId).getBaseDir();
|
||||
const baseDir = FileSystemService.getInstance(nodeId).getBaseDir();
|
||||
const stackParam = parsedUrl.searchParams.get('stack');
|
||||
if (stackParam) {
|
||||
targetDirectory = path.join(targetDirectory, stackParam);
|
||||
const resolved = path.resolve(baseDir, stackParam);
|
||||
if (!resolved.startsWith(path.resolve(baseDir))) {
|
||||
ws.send('Error: Invalid stack path\r\n');
|
||||
ws.close();
|
||||
return;
|
||||
}
|
||||
targetDirectory = resolved;
|
||||
} else {
|
||||
targetDirectory = baseDir;
|
||||
}
|
||||
} catch (e) {
|
||||
targetDirectory = FileSystemService.getInstance(NodeRegistry.getInstance().getDefaultNodeId()).getBaseDir();
|
||||
@@ -544,7 +562,13 @@ server.on('upgrade', async (req, socket, head) => {
|
||||
}
|
||||
});
|
||||
} else {
|
||||
// Generic terminal WebSocket
|
||||
// Generic terminal WebSocket (container exec)
|
||||
// Node proxy tokens must not access interactive container terminals
|
||||
if (isProxyToken) {
|
||||
socket.write('HTTP/1.1 403 Forbidden\r\n\r\n');
|
||||
socket.destroy();
|
||||
return;
|
||||
}
|
||||
wss.handleUpgrade(req, socket, head, (ws) => {
|
||||
wss.emit('connection', ws, req);
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user