security: fix vulnerabilities 1-7 from security audit
- Fix #1: Share handler IDOR - enforce owner check on share operations - Fix #2: list_files_query IDOR - bind folder queries to authenticated user - Fix #3: Dedup handler IDOR - restrict dedup operations to file owner - Fix #4: Trash handler OptionalAuthUser - require full AuthUser - Fix #5: Error info leakage - sanitize 500 error responses - Fix #6: Chunked upload IDOR - bind upload sessions to user_id, add verify_session_owner() check on all session operations - Fix #7: CSP unsafe-inline removal - migrate all inline scripts, styles and event handlers to external files, tighten CSP to script-src 'self'; style-src 'self' New files: - static/js/core/theme-init.js (render-blocking theme init) - static/js/core/sw-register.js (service worker registration) - static/css/views/device-verify.css (extracted inline styles) - static/js/views/device-verify/device-verify.js (extracted inline script)
This commit is contained in:
+4
-6
@@ -354,16 +354,14 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
app = app
|
||||
.layer(SetResponseHeaderLayer::overriding(
|
||||
HeaderName::from_static("content-security-policy"),
|
||||
// NOTE: script-src includes 'unsafe-inline' because several HTML
|
||||
// pages still use inline event handlers (onclick, onsubmit) and
|
||||
// <script> blocks. TODO: migrate these to external .js files so
|
||||
// 'unsafe-inline' can be removed.
|
||||
// All inline scripts and styles have been migrated to external
|
||||
// files, so 'unsafe-inline' is no longer needed.
|
||||
// frame-src is permissive (*) to allow WOPI editor iframes whose
|
||||
// origin is configured at runtime (Collabora, OnlyOffice, etc.).
|
||||
HeaderValue::from_static(
|
||||
"default-src 'self'; \
|
||||
script-src 'self' 'unsafe-inline'; \
|
||||
style-src 'self' 'unsafe-inline'; \
|
||||
script-src 'self'; \
|
||||
style-src 'self'; \
|
||||
img-src 'self' data: blob:; \
|
||||
connect-src 'self'; \
|
||||
font-src 'self' data:; \
|
||||
|
||||
Reference in New Issue
Block a user