mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-12 11:47:11 +00:00
security: pre-release hardening, automated testing, and production readiness
SECURITY (critical fixes):
- Add authMiddleware to /api/system/console-token (was publicly accessible)
- Validate api_url on node create/update to prevent SSRF (rejects localhost/loopback)
- Add rate limiting (5 req/15 min/IP) to /api/auth/login and /api/auth/setup
- Fix path traversal in env_file resolution — absolute/escaping paths rejected
- Add stack name validation to GET routes (was only on PUT/POST)
- Add helmet security headers middleware
- Restrict CORS to FRONTEND_URL in production
PRODUCTION READINESS:
- Add GET /api/health public endpoint + HEALTHCHECK in Dockerfile
- Add SIGTERM/SIGINT graceful shutdown handler (drains connections, closes DB)
- Run container as non-root sencho user in Dockerfile
QUALITY:
- Fix 4 silent empty catch{} blocks in EditorLayout (now show toast.error)
- Connect ErrorBoundary to root App in main.tsx
- Replace WebSocket.Server with named WebSocketServer import (ESM compat)
TESTING (new automated test suite):
- Install Vitest; 38 backend tests across 4 suites covering validation utilities,
health endpoint, auth middleware, login flows, SSRF protection, and path traversal
- Extract isValidStackName/isValidRemoteUrl/isPathWithinBase to utils/validation.ts
- Playwright E2E scaffolding: auth, stacks, nodes specs + shared login helper
- CI: run Vitest + ESLint on every PR
This commit is contained in:
@@ -410,7 +410,9 @@ export default function EditorLayout() {
|
||||
const data = await res.json();
|
||||
setStackUpdates(data);
|
||||
}
|
||||
} catch (e) { }
|
||||
} catch (e: unknown) {
|
||||
console.error('[ImageUpdates] fetch failed:', e);
|
||||
}
|
||||
};
|
||||
|
||||
const markAllRead = async () => {
|
||||
@@ -423,7 +425,10 @@ export default function EditorLayout() {
|
||||
: fetchForNode('/notifications/read', nodeId, { method: 'POST' })
|
||||
));
|
||||
setNotifications(prev => prev.map(n => ({ ...n, is_read: 1 })));
|
||||
} catch (e) { }
|
||||
} catch (e: unknown) {
|
||||
const err = e as { message?: string; error?: string };
|
||||
toast.error(err?.message || err?.error || 'Failed to mark notifications as read');
|
||||
}
|
||||
};
|
||||
|
||||
const deleteNotification = async (notif: Notification) => {
|
||||
@@ -435,7 +440,10 @@ export default function EditorLayout() {
|
||||
await fetchForNode(`/notifications/${notif.id}`, notif.nodeId, { method: 'DELETE' });
|
||||
}
|
||||
setNotifications(prev => prev.filter(n => !(n.id === notif.id && n.nodeId === notif.nodeId)));
|
||||
} catch (e) { }
|
||||
} catch (e: unknown) {
|
||||
const err = e as { message?: string; error?: string };
|
||||
toast.error(err?.message || err?.error || 'Failed to delete notification');
|
||||
}
|
||||
};
|
||||
|
||||
const clearAllNotifications = async () => {
|
||||
@@ -448,7 +456,10 @@ export default function EditorLayout() {
|
||||
: fetchForNode('/notifications', nodeId, { method: 'DELETE' })
|
||||
));
|
||||
setNotifications([]);
|
||||
} catch (e) { }
|
||||
} catch (e: unknown) {
|
||||
const err = e as { message?: string; error?: string };
|
||||
toast.error(err?.message || err?.error || 'Failed to clear notifications');
|
||||
}
|
||||
};
|
||||
|
||||
useEffect(() => {
|
||||
|
||||
Reference in New Issue
Block a user