security: audit follow-ups and 0.31.0 release - #13
Merged
Merged
Conversation
Audit follow-ups on top of the platform-hardening work: - Reject dot-segment paths (`..`, `%2e`, `..;`, `..\`) and encoded slashes before rule matching; `[server] allow_encoded_slash` opts `%2F` data paths back in while `..%2F` stays rejected. - Validate `docker_network` (no `host` / `container:`), and build the whole argv before the network is created. - Single-tenant `docker_options` denylist parses docker's syntax: attached shorthand, `--mount` specs, normalised sources, and the volumes-from / env-file / group-add / namespace flags. - Multi-tenant bind mounts may only be the site directory itself and are emitted by canonical path, closing the check-then-mount symlink race. - `PUT /api/v1/config` carries auth hashes forward by matcher, not index. - Empty admin credentials are dropped at load; `check_auth` and the bind guard share one definition of "configured". - `_` accepted in app.infos hostnames so existing sites keep loading. - Egress/toolchain env allowlist reaches Docker apps as `-e` flags. - Document the `base64.decode` nil,err contract, the X-Requested-With CSRF guard, and add the missing changelog entries for this branch. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Security audit follow-ups on the platform-hardening branch, plus the 0.31.0 version bump.
..;and..\spellings;[server] allow_encoded_slashopts%2Fdata paths back in.docker_networkis validated (host/container:refused) and the argv is built before the network is created.docker_optionsdenylist parses docker's real syntax (-v/:/host,--mount type=bind,source=/,--pid container:x,--volumes-from,--env-file,--group-add).PUT /api/v1/configcarries auth hashes forward by matcher instead of index._accepted inapp.infoshostnames so existing sites keep loading after upgrade.-eflags.Test plan
cargo test(lib 209, integration 58, admin auth 7)cargo clippy --all-targetscargo fmt --checkv0.31.0on main🤖 Generated with Claude Code
https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7