Harden API endpoints: input validation, error sanitization, security headers

- Add shared validation helper (server/lib/validation.js) with ID regex, provider/type allowlists
- Validate all route params against allowlists before filesystem operations to prevent path traversal
- Strip stack traces and error.message from production error responses (generic "Internal server error")
- Sanitize filenames in Content-Disposition headers
- Add X-Content-Type-Options: nosniff and X-Frame-Options: DENY to dev server static responses
- Add path traversal (.. ) checks to all static file handlers and catch-all fetch

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Paul Bakaus
2026-03-05 09:58:05 -08:00
co-authored by Claude Opus 4.6
parent f0d37e48c7
commit b628e208e3
9 changed files with 98 additions and 18 deletions
+1 -1
View File
@@ -13,6 +13,6 @@ export default function handler(req, res) {
res.status(200).json({ patterns, antipatterns });
} catch (error) {
console.error("Error in /api/patterns:", error);
res.status(500).json({ error: error.message, stack: error.stack });
res.status(500).json({ error: "Internal server error" });
}
}