Skip to content

security: audit follow-ups and 0.31.0 release - #13

Merged
solisoft merged 2 commits into
mainfrom
fix/security-audit
Sep 9, 2026
Merged

solisoft merged 2 commits into
mainfrom
fix/security-audit

Conversation

@solisoft

@solisoft solisoft commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Summary

Security audit follow-ups on the platform-hardening branch, plus the 0.31.0 version bump.

  • Dot-segment and encoded-slash paths are rejected before rule matching, now including ..; and ..\ spellings; [server] allow_encoded_slash opts %2F data paths back in.
  • docker_network is validated (host / container: refused) and the argv is built before the network is created.
  • Single-tenant docker_options denylist parses docker's real syntax (-v/:/host, --mount type=bind,source=/, --pid container:x, --volumes-from, --env-file, --group-add).
  • Multi-tenant bind mounts may only be the site directory itself, emitted by canonical path, closing the check-then-mount symlink race.
  • PUT /api/v1/config carries auth hashes forward by matcher instead of index.
  • Empty admin credentials count as unset everywhere.
  • _ accepted in app.infos hostnames so existing sites keep loading after upgrade.
  • Env allowlist reaches Docker apps as -e flags.
  • CHANGELOG, README and both changelog pages (www, admin UI) updated; version bumped to 0.31.0.

Test plan

  • cargo test (lib 209, integration 58, admin auth 7)
  • cargo clippy --all-targets
  • cargo fmt --check
  • CI green, then tag v0.31.0 on main

🤖 Generated with Claude Code

https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7

Olivier Bonnaure and others added 2 commits September 4, 2026 18:08
Audit follow-ups on top of the platform-hardening work:

- Reject dot-segment paths (`..`, `%2e`, `..;`, `..\`) and encoded slashes
  before rule matching; `[server] allow_encoded_slash` opts `%2F` data
  paths back in while `..%2F` stays rejected.
- Validate `docker_network` (no `host` / `container:`), and build the whole
  argv before the network is created.
- Single-tenant `docker_options` denylist parses docker's syntax: attached
  shorthand, `--mount` specs, normalised sources, and the volumes-from /
  env-file / group-add / namespace flags.
- Multi-tenant bind mounts may only be the site directory itself and are
  emitted by canonical path, closing the check-then-mount symlink race.
- `PUT /api/v1/config` carries auth hashes forward by matcher, not index.
- Empty admin credentials are dropped at load; `check_auth` and the bind
  guard share one definition of "configured".
- `_` accepted in app.infos hostnames so existing sites keep loading.
- Egress/toolchain env allowlist reaches Docker apps as `-e` flags.
- Document the `base64.decode` nil,err contract, the X-Requested-With CSRF
  guard, and add the missing changelog entries for this branch.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016w5Z3N3B8oAfEkvPSZE2X7
@solisoft
solisoft merged commit cf8821f into main Sep 9, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant