mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-27 18:57:09 +00:00
security: harden terminal WebSocket endpoints against three attack vectors
- Reject node_proxy scoped JWT tokens with 403 on host-console and container exec (/ws) upgrades; machine-to-machine credentials must not open interactive shells - Validate stackParam against path.resolve + startsWith(baseDir) to prevent directory traversal on the PTY cwd (Rule 9 pattern) - Strip JWT_SECRET, AUTH_PASSWORD, AUTH_PASSWORD_HASH, DATABASE_URL from the environment passed to node-pty spawned shells
This commit is contained in:
@@ -16,12 +16,19 @@ export class HostTerminalService {
|
||||
static spawnTerminal(ws: WebSocket, targetDirectory: string) {
|
||||
const shell = os.platform() === 'win32' ? 'powershell.exe' : getUnixShell();
|
||||
|
||||
// Strip sensitive backend secrets from the PTY environment so they are not
|
||||
// visible to the console user via `env` / `printenv`.
|
||||
const SENSITIVE_KEYS = ['JWT_SECRET', 'AUTH_PASSWORD', 'AUTH_PASSWORD_HASH', 'DATABASE_URL'];
|
||||
const safeEnv = Object.fromEntries(
|
||||
Object.entries(process.env as Record<string, string>).filter(([k]) => !SENSITIVE_KEYS.includes(k))
|
||||
);
|
||||
|
||||
const ptyProcess = pty.spawn(shell, [], {
|
||||
name: 'xterm-color',
|
||||
cols: 80,
|
||||
rows: 30,
|
||||
cwd: targetDirectory,
|
||||
env: process.env as Record<string, string>,
|
||||
env: safeEnv,
|
||||
});
|
||||
|
||||
ptyProcess.onData((data) => {
|
||||
|
||||
Reference in New Issue
Block a user