mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-11 21:57:14 +03:00
Harden API endpoints: input validation, error sanitization, security headers
- Add shared validation helper (server/lib/validation.js) with ID regex, provider/type allowlists - Validate all route params against allowlists before filesystem operations to prevent path traversal - Strip stack traces and error.message from production error responses (generic "Internal server error") - Sanitize filenames in Content-Disposition headers - Add X-Content-Type-Options: nosniff and X-Frame-Options: DENY to dev server static responses - Add path traversal (.. ) checks to all static file handlers and catch-all fetch Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
f0d37e48c7
commit
b628e208e3
@@ -6,9 +6,16 @@ const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = dirname(__filename);
|
||||
const PROJECT_ROOT = join(__dirname, "../..");
|
||||
|
||||
const VALID_ID = /^[a-zA-Z0-9_-]+$/;
|
||||
|
||||
export default function handler(req, res) {
|
||||
try {
|
||||
const { id } = req.query;
|
||||
|
||||
if (!id || !VALID_ID.test(id)) {
|
||||
return res.status(400).json({ error: "Invalid command ID" });
|
||||
}
|
||||
|
||||
const commandPath = join(PROJECT_ROOT, "source", "skills", id, "SKILL.md");
|
||||
|
||||
if (!existsSync(commandPath)) {
|
||||
@@ -19,6 +26,6 @@ export default function handler(req, res) {
|
||||
res.status(200).json({ content });
|
||||
} catch (error) {
|
||||
console.error("Error in /api/command-source:", error);
|
||||
res.status(500).json({ error: error.message });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
+1
-1
@@ -42,7 +42,7 @@ export default function handler(req, res) {
|
||||
res.status(200).json(commands);
|
||||
} catch (error) {
|
||||
console.error("Error in /api/commands:", error);
|
||||
res.status(500).json({ error: error.message, stack: error.stack });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -33,6 +33,9 @@ function getFilePath(type, provider, id) {
|
||||
return null;
|
||||
}
|
||||
|
||||
const VALID_ID = /^[a-zA-Z0-9_-]+$/;
|
||||
const ALLOWED_PROVIDERS = ['cursor', 'claude-code', 'gemini', 'codex', 'agents', 'universal'];
|
||||
|
||||
export default function handler(req, res) {
|
||||
try {
|
||||
const { type, provider, id } = req.query;
|
||||
@@ -41,6 +44,14 @@ export default function handler(req, res) {
|
||||
return res.status(400).json({ error: "Invalid type" });
|
||||
}
|
||||
|
||||
if (!provider || !ALLOWED_PROVIDERS.includes(provider)) {
|
||||
return res.status(400).json({ error: "Invalid provider" });
|
||||
}
|
||||
|
||||
if (!id || !VALID_ID.test(id)) {
|
||||
return res.status(400).json({ error: "Invalid file ID" });
|
||||
}
|
||||
|
||||
const filePath = getFilePath(type, provider, id);
|
||||
|
||||
if (!filePath) {
|
||||
@@ -52,13 +63,13 @@ export default function handler(req, res) {
|
||||
}
|
||||
|
||||
const content = readFileSync(filePath);
|
||||
const fileName = basename(filePath);
|
||||
const fileName = basename(filePath).replace(/[^a-zA-Z0-9._-]/g, '');
|
||||
res.setHeader("Content-Type", "application/octet-stream");
|
||||
res.setHeader("Content-Disposition", `attachment; filename="${fileName}"`);
|
||||
res.send(content);
|
||||
} catch (error) {
|
||||
console.error("Error downloading file:", error);
|
||||
res.status(500).json({ error: error.message });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -6,9 +6,16 @@ const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = dirname(__filename);
|
||||
const PROJECT_ROOT = join(__dirname, "../../..");
|
||||
|
||||
const ALLOWED_PROVIDERS = ['cursor', 'claude-code', 'gemini', 'codex', 'agents', 'universal'];
|
||||
|
||||
export default function handler(req, res) {
|
||||
try {
|
||||
const { provider } = req.query;
|
||||
|
||||
if (!provider || !ALLOWED_PROVIDERS.includes(provider)) {
|
||||
return res.status(400).json({ error: "Invalid provider" });
|
||||
}
|
||||
|
||||
const distDir = join(PROJECT_ROOT, "dist");
|
||||
const zipPath = join(distDir, `${provider}.zip`);
|
||||
|
||||
@@ -18,11 +25,12 @@ export default function handler(req, res) {
|
||||
|
||||
const content = readFileSync(zipPath);
|
||||
res.setHeader("Content-Type", "application/zip");
|
||||
res.setHeader("Content-Disposition", `attachment; filename="impeccable-style-${provider}.zip"`);
|
||||
const safeProvider = provider.replace(/[^a-zA-Z0-9._-]/g, '');
|
||||
res.setHeader("Content-Disposition", `attachment; filename="impeccable-style-${safeProvider}.zip"`);
|
||||
res.send(content);
|
||||
} catch (error) {
|
||||
console.error("Error downloading bundle:", error);
|
||||
res.status(500).json({ error: error.message });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+1
-1
@@ -13,6 +13,6 @@ export default function handler(req, res) {
|
||||
res.status(200).json({ patterns, antipatterns });
|
||||
} catch (error) {
|
||||
console.error("Error in /api/patterns:", error);
|
||||
res.status(500).json({ error: error.message, stack: error.stack });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
+1
-1
@@ -39,6 +39,6 @@ export default function handler(req, res) {
|
||||
res.status(200).json(skills);
|
||||
} catch (error) {
|
||||
console.error("Error in /api/skills:", error);
|
||||
res.status(500).json({ error: error.message });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
+19
-7
@@ -20,42 +20,48 @@ const server = serve({
|
||||
// Static assets - all public subdirectories
|
||||
"/assets/*": async (req) => {
|
||||
const url = new URL(req.url);
|
||||
if (url.pathname.includes('..')) return new Response("Bad Request", { status: 400 });
|
||||
const filePath = `./public${url.pathname}`;
|
||||
const assetFile = file(filePath);
|
||||
if (await assetFile.exists()) {
|
||||
return new Response(assetFile);
|
||||
return new Response(assetFile, {
|
||||
headers: { "X-Content-Type-Options": "nosniff", "X-Frame-Options": "DENY" }
|
||||
});
|
||||
}
|
||||
return new Response("Not Found", { status: 404 });
|
||||
},
|
||||
"/css/*": async (req) => {
|
||||
const url = new URL(req.url);
|
||||
if (url.pathname.includes('..')) return new Response("Bad Request", { status: 400 });
|
||||
const filePath = `./public${url.pathname}`;
|
||||
const assetFile = file(filePath);
|
||||
if (await assetFile.exists()) {
|
||||
return new Response(assetFile, {
|
||||
headers: { "Content-Type": "text/css" }
|
||||
headers: { "Content-Type": "text/css", "X-Content-Type-Options": "nosniff", "X-Frame-Options": "DENY" }
|
||||
});
|
||||
}
|
||||
return new Response("Not Found", { status: 404 });
|
||||
},
|
||||
"/js/*": async (req) => {
|
||||
const url = new URL(req.url);
|
||||
if (url.pathname.includes('..')) return new Response("Bad Request", { status: 400 });
|
||||
const filePath = `./public${url.pathname}`;
|
||||
const assetFile = file(filePath);
|
||||
if (await assetFile.exists()) {
|
||||
return new Response(assetFile, {
|
||||
headers: { "Content-Type": "application/javascript" }
|
||||
headers: { "Content-Type": "application/javascript", "X-Content-Type-Options": "nosniff", "X-Frame-Options": "DENY" }
|
||||
});
|
||||
}
|
||||
return new Response("Not Found", { status: 404 });
|
||||
},
|
||||
"/antipattern-examples/*": async (req) => {
|
||||
const url = new URL(req.url);
|
||||
if (url.pathname.includes('..')) return new Response("Bad Request", { status: 400 });
|
||||
const filePath = `./public${url.pathname}`;
|
||||
const assetFile = file(filePath);
|
||||
if (await assetFile.exists()) {
|
||||
return new Response(assetFile, {
|
||||
headers: { "Content-Type": "text/html" }
|
||||
headers: { "Content-Type": "text/html", "X-Content-Type-Options": "nosniff", "X-Frame-Options": "DENY" }
|
||||
});
|
||||
}
|
||||
return new Response("Not Found", { status: 404 });
|
||||
@@ -88,11 +94,14 @@ const server = serve({
|
||||
// API: Get command source content
|
||||
"/api/command-source/:id": async (req) => {
|
||||
const { id } = req.params;
|
||||
const content = await getCommandSource(id);
|
||||
if (!content) {
|
||||
const result = await getCommandSource(id);
|
||||
if (result && result.error) {
|
||||
return Response.json({ error: result.error }, { status: result.status });
|
||||
}
|
||||
if (!result) {
|
||||
return Response.json({ error: "Command not found" }, { status: 404 });
|
||||
}
|
||||
return Response.json({ content });
|
||||
return Response.json({ content: result });
|
||||
},
|
||||
|
||||
// API: Download individual file
|
||||
@@ -111,6 +120,9 @@ const server = serve({
|
||||
// Serve root-level static files (og-image.png, favicon, robots.txt, etc.)
|
||||
fetch(req) {
|
||||
const url = new URL(req.url);
|
||||
if (url.pathname.includes('..')) {
|
||||
return new Response("Bad Request", { status: 400 });
|
||||
}
|
||||
const filePath = `./public${url.pathname}`;
|
||||
const staticFile = file(filePath);
|
||||
if (staticFile.size > 0) {
|
||||
|
||||
@@ -3,6 +3,7 @@ import { basename, join, dirname } from "path";
|
||||
import { existsSync } from "fs";
|
||||
import { fileURLToPath } from "url";
|
||||
import { readPatterns, parseFrontmatter } from "../../scripts/lib/utils.js";
|
||||
import { isValidId, isAllowedProvider, isAllowedType, sanitizeFilename } from "./validation.js";
|
||||
|
||||
// Get project root directory (works in both Node.js and Bun, including Vercel)
|
||||
const __filename = fileURLToPath(import.meta.url);
|
||||
@@ -47,6 +48,10 @@ export async function getCommands() {
|
||||
|
||||
// Get command/skill source content
|
||||
export async function getCommandSource(id) {
|
||||
if (!isValidId(id)) {
|
||||
return { error: "Invalid command ID", status: 400 };
|
||||
}
|
||||
|
||||
const skillPath = join(PROJECT_ROOT, "source", "skills", id, "SKILL.md");
|
||||
|
||||
try {
|
||||
@@ -87,10 +92,18 @@ export function getFilePath(type, provider, id) {
|
||||
|
||||
// Handle individual file download
|
||||
export async function handleFileDownload(type, provider, id) {
|
||||
if (type !== "skill" && type !== "command") {
|
||||
if (!isAllowedType(type)) {
|
||||
return new Response("Invalid type", { status: 400 });
|
||||
}
|
||||
|
||||
if (!isAllowedProvider(provider)) {
|
||||
return new Response("Invalid provider", { status: 400 });
|
||||
}
|
||||
|
||||
if (!isValidId(id)) {
|
||||
return new Response("Invalid file ID", { status: 400 });
|
||||
}
|
||||
|
||||
const filePath = getFilePath(type, provider, id);
|
||||
|
||||
if (!filePath) {
|
||||
@@ -103,7 +116,7 @@ export async function handleFileDownload(type, provider, id) {
|
||||
}
|
||||
|
||||
const content = await readFile(filePath);
|
||||
const fileName = basename(filePath);
|
||||
const fileName = sanitizeFilename(basename(filePath));
|
||||
return new Response(content, {
|
||||
headers: {
|
||||
"Content-Type": "application/octet-stream",
|
||||
@@ -128,6 +141,10 @@ export async function getPatterns() {
|
||||
|
||||
// Handle bundle download
|
||||
export async function handleBundleDownload(provider) {
|
||||
if (!isAllowedProvider(provider)) {
|
||||
return new Response("Invalid provider", { status: 400 });
|
||||
}
|
||||
|
||||
const distDir = join(PROJECT_ROOT, "dist");
|
||||
const zipPath = join(distDir, `${provider}.zip`);
|
||||
|
||||
@@ -137,10 +154,11 @@ export async function handleBundleDownload(provider) {
|
||||
}
|
||||
|
||||
const content = await readFile(zipPath);
|
||||
const safeProvider = sanitizeFilename(provider);
|
||||
return new Response(content, {
|
||||
headers: {
|
||||
"Content-Type": "application/zip",
|
||||
"Content-Disposition": `attachment; filename="impeccable-style-${provider}.zip"`,
|
||||
"Content-Disposition": `attachment; filename="impeccable-style-${safeProvider}.zip"`,
|
||||
},
|
||||
});
|
||||
} catch (error) {
|
||||
|
||||
@@ -0,0 +1,24 @@
|
||||
// Shared validation helpers for input sanitization
|
||||
|
||||
// Only allow alphanumeric, hyphens, and underscores in IDs
|
||||
export const VALID_ID = /^[a-zA-Z0-9_-]+$/;
|
||||
|
||||
export const ALLOWED_PROVIDERS = ['cursor', 'claude-code', 'gemini', 'codex', 'agents', 'universal'];
|
||||
export const ALLOWED_TYPES = ['skill', 'command'];
|
||||
|
||||
export function isValidId(id) {
|
||||
return typeof id === 'string' && VALID_ID.test(id);
|
||||
}
|
||||
|
||||
export function isAllowedProvider(provider) {
|
||||
return ALLOWED_PROVIDERS.includes(provider);
|
||||
}
|
||||
|
||||
export function isAllowedType(type) {
|
||||
return ALLOWED_TYPES.includes(type);
|
||||
}
|
||||
|
||||
// Sanitize a filename for use in Content-Disposition headers
|
||||
export function sanitizeFilename(filename) {
|
||||
return filename.replace(/[^a-zA-Z0-9._-]/g, '');
|
||||
}
|
||||
Reference in New Issue
Block a user