fix(security): V-01,V-02,V-04,V-05,V-06 - multiple vulnerability fixes
- V-01: CalDAV unbounded body limit → MAX_CALDAV_BODY = 1MB - V-02: CardDAV unbounded body limit → MAX_CARDDAV_BODY = 1MB - V-04: Batch operations without max size → MAX_BATCH_SIZE = 1000 - V-05: WOPI get_editor_url IDOR → authorize_wopi_access with ownership check - V-06: JWT secret without entropy validation → panic <16, warn 16-31, accept >=32
This commit is contained in:
+21
-1
@@ -569,10 +569,30 @@ impl AppConfig {
|
||||
|
||||
// Auth configuration
|
||||
if let Ok(jwt_secret) = env::var("OXICLOUD_JWT_SECRET") {
|
||||
// SECURITY: Validate JWT secret minimum entropy (RFC 7518 §3.2
|
||||
// recommends ≥256 bits for HS256). Panic on dangerously short
|
||||
// secrets, warn on sub-optimal ones.
|
||||
let len = jwt_secret.len();
|
||||
if config.features.enable_auth && len < 16 {
|
||||
panic!(
|
||||
"FATAL: OXICLOUD_JWT_SECRET is dangerously short ({} bytes). \
|
||||
Minimum: 32 bytes (256 bits) for HS256. \
|
||||
Generate a secure secret with: openssl rand -hex 32",
|
||||
len
|
||||
);
|
||||
} else if config.features.enable_auth && len < 32 {
|
||||
tracing::warn!("==========================================================");
|
||||
tracing::warn!(
|
||||
"OXICLOUD_JWT_SECRET is only {} bytes — recommended minimum is 32 (256 bits).",
|
||||
len
|
||||
);
|
||||
tracing::warn!("Generate a stronger secret with: openssl rand -hex 32");
|
||||
tracing::warn!("==========================================================");
|
||||
}
|
||||
config.auth.jwt_secret = jwt_secret;
|
||||
}
|
||||
|
||||
// SECURITY: Validate JWT secret when auth is enabled
|
||||
// SECURITY: Generate ephemeral secret when none is provided
|
||||
if config.features.enable_auth && config.auth.jwt_secret.is_empty() {
|
||||
// Generate a random secret for this session and warn loudly
|
||||
use rand_core::{OsRng, RngCore};
|
||||
|
||||
Reference in New Issue
Block a user