mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-29 11:36:36 +08:00
security: fix SSRF, restrict CORS, add rate limiting on auth endpoints
- Add isPrivateHost() to block image proxy requests to loopback/private/ link-local IPs (SSRF mitigation) - Add isAllowedLocalPath() to restrict local file reads to configured data/cache/media directories only - CORS middleware now takes debug flag; wildcard only when debug=true, production omits headers (same-origin enforced) - Add per-IP sliding-window rate limiter (10 req/min) on login/register and Emby AuthenticateByName endpoints Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
@@ -5,6 +5,8 @@
|
||||
package handler
|
||||
|
||||
import (
|
||||
"time"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"go.uber.org/zap"
|
||||
|
||||
@@ -23,8 +25,12 @@ func Register(r *gin.Engine, cfg *config.Config, log *zap.Logger, svc *service.C
|
||||
// Telegram Bot webhook — called by Telegram servers, no auth.
|
||||
api.POST("/telegram/webhook", telegramWebhookHandler(svc))
|
||||
|
||||
// Rate limiter for auth endpoints: 10 attempts per minute per IP.
|
||||
authLimiter := middleware.NewRateLimiter(10, 1*time.Minute)
|
||||
|
||||
// Public auth.
|
||||
auth := api.Group("/auth")
|
||||
auth.Use(middleware.RateLimit(authLimiter))
|
||||
{
|
||||
auth.POST("/login", loginHandler(svc))
|
||||
auth.POST("/register", registerHandler(svc))
|
||||
|
||||
Reference in New Issue
Block a user