security: fix SSRF, restrict CORS, add rate limiting on auth endpoints

- Add isPrivateHost() to block image proxy requests to loopback/private/
  link-local IPs (SSRF mitigation)
- Add isAllowedLocalPath() to restrict local file reads to configured
  data/cache/media directories only
- CORS middleware now takes debug flag; wildcard only when debug=true,
  production omits headers (same-origin enforced)
- Add per-IP sliding-window rate limiter (10 req/min) on login/register
  and Emby AuthenticateByName endpoints

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
soldosluka857
2026-05-30 01:43:04 +00:00
committed by Shuke
parent d22b48a801
commit 5bbc9fadfe
5 changed files with 153 additions and 9 deletions
+6
View File
@@ -5,6 +5,8 @@
package handler
import (
"time"
"github.com/gin-gonic/gin"
"go.uber.org/zap"
@@ -23,8 +25,12 @@ func Register(r *gin.Engine, cfg *config.Config, log *zap.Logger, svc *service.C
// Telegram Bot webhook — called by Telegram servers, no auth.
api.POST("/telegram/webhook", telegramWebhookHandler(svc))
// Rate limiter for auth endpoints: 10 attempts per minute per IP.
authLimiter := middleware.NewRateLimiter(10, 1*time.Minute)
// Public auth.
auth := api.Group("/auth")
auth.Use(middleware.RateLimit(authLimiter))
{
auth.POST("/login", loginHandler(svc))
auth.POST("/register", registerHandler(svc))