- Provider-controlled strings (channel names, groups, file names, log lines, in-place mapping edits, client info) are rendered with textContent instead of innerHTML. PopupContent.description() takes an explicit isHTML flag that only the static help texts pass. - Websocket: drop the always-true CheckOrigin so gorilla's same-origin check applies; read the session token from the HttpOnly cookie sent with the handshake (the ?Token= query parameter is still accepted for older clients); the client no longer puts the token in the URL, rewrites the cookie, or console-logs request/response payloads. - Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped (expiry stays server side) and is cleared on logout. - Serving the first-run wizard no longer sets Settings.AuthenticationWEB to false; the wizard page simply bypasses login while it is active. - Upgrade failures no longer write a second error response. - Tests: src/websocket_test.go covers cross-origin refusal, same-origin and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
This commit is contained in:
+4
-4
@@ -13,10 +13,10 @@ Status: Phase 0 committed on branch `improvements` 2026-09-26.
|
||||
- [x] staticcheck baseline via `go run honnef.co/go/tools/cmd/staticcheck@latest ./...`: 408 findings (S1002 113, SA5008 79, S1039 67, S1038 40, S1023 35, ST1005 20, SA1019 14, SA4006 9, misc 11). Mostly style; SA5008/SA4006/SA1019 worth a pass in Phase 3 cleanup
|
||||
|
||||
## Phase 1: Security
|
||||
- [ ] Replace `innerHTML` with `textContent` for provider-controlled strings
|
||||
- [ ] Enforce websocket Origin check; move token from query string to cookie; stop console-logging tokens
|
||||
- [ ] Cookie `HttpOnly` + `SameSite`
|
||||
- [ ] Wizard GET must not set `AuthenticationWEB = false`
|
||||
- [x] `textContent` for provider-controlled strings (cells, client info, in-place edits, logs, popup descriptions with an explicit static-HTML flag)
|
||||
- [x] Websocket uses gorilla's same-origin check; token read from the HttpOnly cookie (query param kept for legacy clients); payload/token console logging removed. Tests in `src/websocket_test.go`
|
||||
- [x] Cookie `HttpOnly`, `SameSite=Strict`, `Path=/`, cleared on logout
|
||||
- [x] Wizard GET no longer mutates `AuthenticationWEB`; the wizard page just bypasses login while active
|
||||
- [ ] Sanitise `uploadLogo` filename
|
||||
- [ ] Zip-slip guard in backup restore
|
||||
- [ ] Restrict `ffmpeg.path` / `vlc.path` and reject non-http(s) stream URLs
|
||||
|
||||
Reference in New Issue
Block a user