chaim
0340a670ed
security: address all findings from vulnerability assessment
...
Implements the fixes catalogued under Task Master tasks 1-19, derived
from the security audit at .claude/plans/adaptive-sleeping-diffie.md.
Critical
- C-1 SSRF userinfo bypass: PDF proxy now rejects URLs containing
userinfo or non-default ports, and asserts netloc == hostname.
- C-2 No authentication: optional NADLAN_API_KEY gate guards
/api/search/*, /api/appraisals/pdf and /mcp until Traefik mTLS
is wired up. Default behavior unchanged when env unset.
High
- H-1 Error info leak: HTTPException details replaced with generic
string; full exceptions still logged via logger.exception.
- H-2 Security headers middleware: HSTS, X-Frame-Options, nosniff,
Referrer-Policy, Permissions-Policy, CSP, server-banner stripped.
- H-3 Swagger gated: /api/docs and /api/openapi.json hidden when
ENVIRONMENT=production.
- H-4 PDF proxy DoS: streams in 8KB chunks, rejects upstream above
50MB Content-Length, also rejects mid-stream overrun. Magic-byte
check moved before StreamingResponse so we can 502 cleanly.
- H-5 Per-IP rate limit: token-bucket per (path, IP) on /mcp,
/api/search/*, /api/appraisals/pdf. Reads X-Forwarded-For for
client IP behind Traefik.
Medium
- M-1 CORS: ALLOWED_ORIGINS env, allow_headers narrowed, no creds.
- M-2 Deal model: extra="ignore" + explicit fields for gushNum,
parcelNum, subParcelNum, streetNameHeb, houseNum, deal_source,
deal_type, deal_type_description, distance_meters. Frontend now
reads snake_case.
- M-3 Input validators: regex on block, plot, appraiser names,
dates, address, free-text — Hebrew + Latin + safe punctuation.
- M-4 COOLIFY_UUID moved out of deploy.yaml into Gitea Actions
secret.
- M-5 Base images pinned to sha256 digests.
- M-6 Runtime deps tightened to ~= compatible-release.
- M-7 1MB request-body size limit middleware.
Low / privacy
- L-1 Heebo self-hosted via @fontsource. Removed Google Fonts links
and CSP entries. Added meta referrer + meta robots noindex.
- L-2 Cache-Control: immutable for /assets, no-cache for HTML.
- L-3 Logger no longer prints user-supplied addresses; emits length
only.
- L-4 Dockerfile healthcheck uses literal port 8000.
- L-5 PDF proxy stream cleanup uses contextlib.suppress.
Tests: 331 passed, 17 skipped. Frontend typecheck passes.
Findings file: .claude/plans/adaptive-sleeping-diffie.md
Tasks: .taskmaster/tasks/tasks.json
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-04-25 17:59:10 +00:00
chaim
e4e2fa5bc8
Fix: anchor lib/ ignore patterns to repo root, add web/src/lib/utils.ts
...
The catch-all `lib/` pattern in both .gitignore and .dockerignore (intended
to exclude Python venv lib dirs) silently swallowed `web/src/lib/utils.ts`.
That's why every Docker build got "ENOENT /web/src/lib/utils" — the file
was never committed and never copied into the container, but local builds
worked because the file existed on disk.
Anchor `lib/` and `lib64/` to the repo root with `/lib/` and `/lib64/`,
then add the previously-ignored utils.ts.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com >
2026-04-25 12:55:52 +00:00
Nitzan Pomerantz
f50b32b0ad
Docs: Add CHANGELOG, update CLAUDE.md, cleanup old files
...
- Add CHANGELOG.md with v2.0.0, v1.0.0, v0.1.0 history
- Update CLAUDE.md: v2.0.0 status, learnings section, CI/CD info
- Delete MCP_NORMALIZATION_FIX.md (already implemented)
- Archive start.prompt, start2.prompt to .archive/
- Update .gitignore to exclude .archive/
🤖 Generated with [Claude Code](https://claude.com/claude-code )
Co-Authored-By: Claude <noreply@anthropic.com >
2025-11-30 23:45:59 +02:00