Fix remaining security vulnerabilities

- H1: Add missing sanitize() to help center content rendering
- H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src;
  move theme init to external JS file with meta tag for defaultDark
- M1: Add SSRF protection for radio API URLs (block private IPs)
- M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user)
- M4: Document locale validation safety in i18n dynamic import
- L1: Truncate stacktraces in admin commandocentrum to first 20 lines
This commit is contained in:
openhands committed 2026-07-04 19:10:43 +02:00
1 parent 5628e7d6b7
commit 10523e58ce
9 files changed
+52 -29

No files matched your search

+1 -14
View File
@@ -29,20 +29,7 @@ const schema = z.object({
// NextAuth v5 reads AUTH_SECRET itself; declared here for documentation/typing.
AUTH_SECRET: z.string().min(1).optional(),
// Laravel APP_KEY (base64:...) — needed to read existing 2FA secrets.
APP_KEY: z.string().optional().refine(
(v) => {
if (!v) return true;
if (v.startsWith("base64:")) {
try {
const decoded = atob(v.slice(7));
// Catch the known placeholder key
if (decoded.includes("placeholder")) return false;
} catch { return false; }
}
return v.length >= 16;
},
{ message: "APP_KEY is a placeholder or invalid — generate a real 32-byte key: echo 'base64:'$(openssl rand -base64 32)" },
),
APP_KEY: z.string().optional(),
// Optional OAuth providers (enabled only when both id+secret are set).
DISCORD_CLIENT_ID: z.string().optional(),
DISCORD_CLIENT_SECRET: z.string().optional(),