Phase 1b/1c: server-side input handling and authentication
continuous-integration/drone/push Build encountered an error
continuous-integration/drone/push Build encountered an error
Input handling: - uploadLogo: client file name reduced to a safe base name with an image extension (path traversal and arbitrary-extension writes closed). - extractZIP: zip-slip guard; entries that resolve outside the target are refused. Per-entry closes no longer pile up as defers. - ffmpeg.path / vlc.path must be an existing regular file named ffmpeg, vlc or cvlc, checked both when saved and right before exec. - Stream URLs passed to the external buffer must use a network scheme (http, https, rtsp, rtmp, rtp, udp, mms); file:, concat:, pipe: are refused. - /download/ (backups with settings.json and authentication.json) requires the web session when web authentication is enabled. - settings.json is written 0600; the Plex token is masked in every payload sent to the UI and the mask round-trips as "unchanged" on save. Authentication: - Passwords are stored with bcrypt. Existing HMAC-SHA256 records still verify (constant time) and are re-hashed on the first successful login. Username lookups compare in constant time. - URL (?username=&password=) and HTTP Basic authentication verify the credentials per request via AuthenticateUser and no longer create a session token, which removes the unbounded token growth under Plex polling. Expired sessions are evicted whenever a new one is created. - createFirstUserForAuthentication and checkAuthorizationLevel now return real errors instead of calling no-op closures. Tests: src/security_test.go and src/internal/authentication/ authentication_test.go cover each of the above.
This commit is contained in:
+9
-9
@@ -17,15 +17,15 @@ Status: Phase 0 committed on branch `improvements` 2026-09-26.
|
||||
- [x] Websocket uses gorilla's same-origin check; token read from the HttpOnly cookie (query param kept for legacy clients); payload/token console logging removed. Tests in `src/websocket_test.go`
|
||||
- [x] Cookie `HttpOnly`, `SameSite=Strict`, `Path=/`, cleared on logout
|
||||
- [x] Wizard GET no longer mutates `AuthenticationWEB`; the wizard page just bypasses login while active
|
||||
- [ ] Sanitise `uploadLogo` filename
|
||||
- [ ] Zip-slip guard in backup restore
|
||||
- [ ] Restrict `ffmpeg.path` / `vlc.path` and reject non-http(s) stream URLs
|
||||
- [ ] Put `/download/` behind auth
|
||||
- [ ] Configured base URL instead of Host-header-derived domain
|
||||
- [ ] bcrypt with migrate-on-login; constant-time compare
|
||||
- [ ] Token expiry and eviction
|
||||
- [ ] Only admins may edit other users
|
||||
- [ ] Settings file mode 0600; redact Plex token in UI payload
|
||||
- [x] `uploadLogo` filename sanitised (base name, image extensions only)
|
||||
- [x] Zip-slip guard in `extractZIP` (also no more defer-in-loop there)
|
||||
- [x] `ffmpeg.path`/`vlc.path` must be a regular file named ffmpeg/vlc/cvlc; stream URLs handed to the external buffer must use a network scheme
|
||||
- [x] `/download/` requires the web session when web auth is on
|
||||
- [~] Host-header-derived URLs kept by design (LAN, many interfaces; URLs must match how the client reached the server)
|
||||
- [x] bcrypt for new passwords and credential changes; legacy SHA256 records verified in constant time and upgraded on first login; username compare constant-time
|
||||
- [x] Expired tokens evicted on every new session; URL/Basic auth no longer mint tokens at all (`AuthenticateUser`)
|
||||
- [~] Not applicable: xTeVe has no roles, every web user is an administrator by design (documented in README security notes)
|
||||
- [x] `settings.json` written 0600; Plex token masked in every payload to the UI, mask round-trips as "unchanged" on save
|
||||
- [x] Decide default for web auth on fresh installs (keep off; LAN only, decided 2026-09-25)
|
||||
|
||||
## Phase 2: Streaming stability
|
||||
|
||||
Reference in New Issue
Block a user