Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering - H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src; move theme init to external JS file with meta tag for defaultDark - M1: Add SSRF protection for radio API URLs (block private IPs) - M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user) - M4: Document locale validation safety in i18n dynamic import - L1: Truncate stacktraces in admin commandocentrum to first 20 lines
This commit is contained in:
1 parent
5628e7d6b7
commit
10523e58ce
9 files changed
+52
-29
No files matched your search
@@ -6,12 +6,29 @@ import { siteSettings } from "@/lib/services/site-settings";
|
||||
* website_settings (AzureCast / Icecast / Shoutcast all differ), parsing the
|
||||
* common shapes. Everything fails soft (returns null) on error/missing config.
|
||||
*/
|
||||
|
||||
// Block SSRF — only allow http/https to public IPs (no private/loopback/link-local).
|
||||
const PRIVATE_IP_RE =
|
||||
/^(127\.|10\.|172\.(1[6-9]|2\d|3[01])\.|192\.168\.|169\.254\.|0\.0\.0\.0|::1|fe80:|fc00:|fd00:|localhost)/i;
|
||||
|
||||
function isSafeUrl(url: string): boolean {
|
||||
try {
|
||||
const u = new URL(url);
|
||||
if (u.protocol !== "http:" && u.protocol !== "https:") return false;
|
||||
if (PRIVATE_IP_RE.test(u.hostname)) return false;
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
export interface NowPlaying {
|
||||
title: string;
|
||||
artist: string | null;
|
||||
}
|
||||
|
||||
async function fetchJson(url: string, ms = 4000): Promise<unknown> {
|
||||
if (!isSafeUrl(url)) return null;
|
||||
const controller = new AbortController();
|
||||
const timer = setTimeout(() => controller.abort(), ms);
|
||||
try {
|
||||
|
||||
Reference in new issue
Block a user