mirror of
https://github.com/pbakaus/impeccable.git
synced 2026-09-12 22:26:38 +03:00
Harden API endpoints: input validation, error sanitization, security headers
- Add shared validation helper (server/lib/validation.js) with ID regex, provider/type allowlists - Validate all route params against allowlists before filesystem operations to prevent path traversal - Strip stack traces and error.message from production error responses (generic "Internal server error") - Sanitize filenames in Content-Disposition headers - Add X-Content-Type-Options: nosniff and X-Frame-Options: DENY to dev server static responses - Add path traversal (.. ) checks to all static file handlers and catch-all fetch Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
f0d37e48c7
commit
b628e208e3
@@ -6,9 +6,16 @@ const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = dirname(__filename);
|
||||
const PROJECT_ROOT = join(__dirname, "../..");
|
||||
|
||||
const VALID_ID = /^[a-zA-Z0-9_-]+$/;
|
||||
|
||||
export default function handler(req, res) {
|
||||
try {
|
||||
const { id } = req.query;
|
||||
|
||||
if (!id || !VALID_ID.test(id)) {
|
||||
return res.status(400).json({ error: "Invalid command ID" });
|
||||
}
|
||||
|
||||
const commandPath = join(PROJECT_ROOT, "source", "skills", id, "SKILL.md");
|
||||
|
||||
if (!existsSync(commandPath)) {
|
||||
@@ -19,6 +26,6 @@ export default function handler(req, res) {
|
||||
res.status(200).json({ content });
|
||||
} catch (error) {
|
||||
console.error("Error in /api/command-source:", error);
|
||||
res.status(500).json({ error: error.message });
|
||||
res.status(500).json({ error: "Internal server error" });
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user