fix(cms): implement v2 security and stability review findings
CI Pipeline with Test Management / 🧪 Run Tests & Generate Reports (push) Waiting to run
CI Pipeline with Test Management / 🐳 Docker Integration Tests (push) Blocked by required conditions
CI Pipeline with Test Management / 🏗️ Build Docker Image (push) Blocked by required conditions
CI Pipeline with Test Management / 📊 Generate Test Summary (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🧪 Run Tests & Generate Reports (push) Waiting to run
Test Reporting & Gherkin Analysis / 📊 Analyze Test Coverage (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / 🔄 Sync with Linear (push) Blocked by required conditions
Test Reporting & Gherkin Analysis / ⚡ Performance Monitoring (push) Blocked by required conditions

Resolves:
- CSRF false positive checked (global POST protection)
- Publish mutex to prevent git lock / double deploy
- Basic Auth rate limit checked before credential evaluation
- Memory leak in rate limiter (added GC interval)
- XSS in Toast messages
- XSS in data-path attribute
- CI healthcheck port mismatch (3000 -> 8080)
- Added security headers (X-Frame-Options, X-Content-Type-Options)
This commit is contained in:
Do Siki
2026-08-20 11:35:01 +02:00
parent 768297031d
commit c5d5198fbf
12 changed files with 132 additions and 61 deletions
+7 -3
View File
@@ -8,13 +8,17 @@ const SESSION_TTL_MS = 8 * 60 * 60 * 1000;
const sessions = new Map(); // token -> expiresAt (ms)
function timingSafeMatch(candidate, expected) {
if (typeof candidate !== 'string' || typeof expected !== 'string' || candidate.length !== expected.length) return false;
return crypto.timingSafeEqual(Buffer.from(candidate), Buffer.from(expected));
if (typeof candidate !== 'string' || typeof expected !== 'string') return false;
const cHash = crypto.createHash('sha256').update(candidate).digest();
const eHash = crypto.createHash('sha256').update(expected).digest();
return crypto.timingSafeEqual(cHash, eHash);
}
function validateLogin(user, pass, expectedUser, expectedPass) {
if (!expectedUser || !expectedPass) return false;
return timingSafeMatch(user, expectedUser) && timingSafeMatch(pass, expectedPass);
const userOk = timingSafeMatch(user, expectedUser);
const passOk = timingSafeMatch(pass, expectedPass);
return Boolean(userOk && passOk);
}
function createSessionCookie(isSecure) {