fix(security): harden PoW XSS, email header injection and UptimeKuma log redaction

This commit is contained in:
ryan
2026-08-08 21:52:46 +08:00
parent c4be34b214
commit 6487ce666d
8 changed files with 141 additions and 11 deletions
+37 -1
View File
@@ -17,6 +17,35 @@ import (
"time"
)
// redactSensitiveJSON masks values of sensitive keys (password, token, secret,
// api key) so credentials never appear in logs.
func redactSensitiveJSON(v any) any {
switch t := v.(type) {
case map[string]any:
for k, val := range t {
if isSensitiveLogKey(k) {
t[k] = "***"
} else {
t[k] = redactSensitiveJSON(val)
}
}
case []any:
for i, val := range t {
t[i] = redactSensitiveJSON(val)
}
}
return v
}
func isSensitiveLogKey(k string) bool {
switch strings.ToLower(k) {
case "password", "passwd", "secret", "token", "access_token", "api_key", "apikey":
return true
default:
return false
}
}
const emitAckTimeout = 10 * time.Second
// Monitor represents a monitor entry from Uptime Kuma.
@@ -292,7 +321,14 @@ func (c *SocketIOClient) Emit(event string, args ...any) (string, error) {
}
body := fmt.Sprintf("42%d%s", id, string(bs))
slog.Debug("Emitting Socket.IO event", "event", event, "ackID", id, "payload", string(bs))
logPayload := string(bs)
var decoded any
if err := json.Unmarshal(bs, &decoded); err == nil {
if redacted, err := json.Marshal(redactSensitiveJSON(decoded)); err == nil {
logPayload = string(redacted)
}
}
slog.Debug("Emitting Socket.IO event", "event", event, "ackID", id, "payload", logPayload)
u := fmt.Sprintf("%s/socket.io/?EIO=4&transport=polling&sid=%s", c.baseURL, c.sid)
req, err := http.NewRequestWithContext(c.ctx, http.MethodPost, u, strings.NewReader(body))