0340a670ed
Implements the fixes catalogued under Task Master tasks 1-19, derived from the security audit at .claude/plans/adaptive-sleeping-diffie.md. Critical - C-1 SSRF userinfo bypass: PDF proxy now rejects URLs containing userinfo or non-default ports, and asserts netloc == hostname. - C-2 No authentication: optional NADLAN_API_KEY gate guards /api/search/*, /api/appraisals/pdf and /mcp until Traefik mTLS is wired up. Default behavior unchanged when env unset. High - H-1 Error info leak: HTTPException details replaced with generic string; full exceptions still logged via logger.exception. - H-2 Security headers middleware: HSTS, X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy, CSP, server-banner stripped. - H-3 Swagger gated: /api/docs and /api/openapi.json hidden when ENVIRONMENT=production. - H-4 PDF proxy DoS: streams in 8KB chunks, rejects upstream above 50MB Content-Length, also rejects mid-stream overrun. Magic-byte check moved before StreamingResponse so we can 502 cleanly. - H-5 Per-IP rate limit: token-bucket per (path, IP) on /mcp, /api/search/*, /api/appraisals/pdf. Reads X-Forwarded-For for client IP behind Traefik. Medium - M-1 CORS: ALLOWED_ORIGINS env, allow_headers narrowed, no creds. - M-2 Deal model: extra="ignore" + explicit fields for gushNum, parcelNum, subParcelNum, streetNameHeb, houseNum, deal_source, deal_type, deal_type_description, distance_meters. Frontend now reads snake_case. - M-3 Input validators: regex on block, plot, appraiser names, dates, address, free-text — Hebrew + Latin + safe punctuation. - M-4 COOLIFY_UUID moved out of deploy.yaml into Gitea Actions secret. - M-5 Base images pinned to sha256 digests. - M-6 Runtime deps tightened to ~= compatible-release. - M-7 1MB request-body size limit middleware. Low / privacy - L-1 Heebo self-hosted via @fontsource. Removed Google Fonts links and CSP entries. Added meta referrer + meta robots noindex. - L-2 Cache-Control: immutable for /assets, no-cache for HTML. - L-3 Logger no longer prints user-supplied addresses; emits length only. - L-4 Dockerfile healthcheck uses literal port 8000. - L-5 PDF proxy stream cleanup uses contextlib.suppress. Tests: 331 passed, 17 skipped. Frontend typecheck passes. Findings file: .claude/plans/adaptive-sleeping-diffie.md Tasks: .taskmaster/tasks/tasks.json Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
47 lines
1.5 KiB
Plaintext
47 lines
1.5 KiB
Plaintext
<context>
|
|
# Overview
|
|
[Provide a high-level overview of your product here. Explain what problem it solves, who it's for, and why it's valuable.]
|
|
|
|
# Core Features
|
|
[List and describe the main features of your product. For each feature, include:
|
|
- What it does
|
|
- Why it's important
|
|
- How it works at a high level]
|
|
|
|
# User Experience
|
|
[Describe the user journey and experience. Include:
|
|
- User personas
|
|
- Key user flows
|
|
- UI/UX considerations]
|
|
</context>
|
|
<PRD>
|
|
# Technical Architecture
|
|
[Outline the technical implementation details:
|
|
- System components
|
|
- Data models
|
|
- APIs and integrations
|
|
- Infrastructure requirements]
|
|
|
|
# Development Roadmap
|
|
[Break down the development process into phases:
|
|
- MVP requirements
|
|
- Future enhancements
|
|
- Do not think about timelines whatsoever -- all that matters is scope and detailing exactly what needs to be build in each phase so it can later be cut up into tasks]
|
|
|
|
# Logical Dependency Chain
|
|
[Define the logical order of development:
|
|
- Which features need to be built first (foundation)
|
|
- Getting as quickly as possible to something usable/visible front end that works
|
|
- Properly pacing and scoping each feature so it is atomic but can also be built upon and improved as development approaches]
|
|
|
|
# Risks and Mitigations
|
|
[Identify potential risks and how they'll be addressed:
|
|
- Technical challenges
|
|
- Figuring out the MVP that we can build upon
|
|
- Resource constraints]
|
|
|
|
# Appendix
|
|
[Include any additional information:
|
|
- Research findings
|
|
- Technical specifications]
|
|
</PRD> |