mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 08:06:37 +08:00
feat: replace cert_dir with support_dir in agent and server configurations
- Updated README.md to reflect the new support_dir for auxiliary files. - Refactored agent main.go to use support_dir instead of cert_dir. - Modified config.go to replace cert_dir with support_dir and added legacy support. - Adjusted config tests to validate support_dir usage. - Changed nginx manager to utilize support_dir for file paths. - Updated server configuration to use support_dir for SSL certificates. - Revised documentation to clarify the new configuration parameters. - Enhanced security checks for support file paths to prevent traversal attacks.
This commit is contained in:
@@ -59,7 +59,7 @@
|
||||
|
||||
维护期内优先处理以下高风险或高敏感问题:
|
||||
|
||||
* Agent 写入 `support_files` 时缺少对目标路径必须位于 `cert_dir` 内的强约束,存在路径穿越风险
|
||||
* Agent 写入 `support_files` 时缺少对目标路径必须位于 `support_dir` 内的强约束,存在路径穿越风险
|
||||
* 手动上传 Server 二进制后会执行 `--version` 检测,属于高敏感执行链路,必须进一步加固
|
||||
|
||||
---
|
||||
@@ -106,7 +106,7 @@
|
||||
* 为 Agent 支持文件写入增加安全路径校验
|
||||
* 拒绝绝对路径
|
||||
* 拒绝 `..` 跳目录
|
||||
* 通过 `filepath.Rel` 或安全辅助函数确认最终路径仍位于 `cert_dir` 内
|
||||
* 通过 `filepath.Rel` 或安全辅助函数确认最终路径仍位于 `support_dir` 内
|
||||
* `writeSupportFiles`、`restore`、未来新增的写文件入口全部复用同一套安全函数
|
||||
* 收紧手动上传升级链路
|
||||
* 明确只允许 root 用户
|
||||
@@ -214,4 +214,4 @@
|
||||
|
||||
* 评估配置接口压缩与更细粒度 manifest 同步
|
||||
* 评估手动上传升级链路的更安全替代实现
|
||||
* 根据实际运行数据决定是否继续做更细的持久化优化
|
||||
* 根据实际运行数据决定是否继续做更细的持久化优化
|
||||
|
||||
Reference in New Issue
Block a user