added security settings
changed fixes and issues
This commit is contained in:
1 parent
28a453d87f
commit
8a80978aef
5 files changed
+169
-12
No files matched your search
+9
-1
@@ -1,5 +1,6 @@
|
||||
import cors from 'cors';
|
||||
import express from 'express';
|
||||
import crypto from 'node:crypto';
|
||||
import http from 'node:http';
|
||||
import https from 'node:https';
|
||||
import { readFile } from 'node:fs/promises';
|
||||
@@ -25,7 +26,7 @@ app.use((req, res, next) => {
|
||||
return;
|
||||
}
|
||||
const header = req.get('authorization') || '';
|
||||
if (header === `Bearer ${config.apiToken}`) {
|
||||
if (config.apiToken && timingSafeEqual(header, `Bearer ${config.apiToken}`)) {
|
||||
next();
|
||||
return;
|
||||
}
|
||||
@@ -36,6 +37,13 @@ function normalizeIp(value) {
|
||||
return String(value || '').replace(/^::ffff:/, '');
|
||||
}
|
||||
|
||||
function timingSafeEqual(a, b) {
|
||||
const bufA = Buffer.from(String(a));
|
||||
const bufB = Buffer.from(String(b));
|
||||
if (bufA.length !== bufB.length) return false;
|
||||
return crypto.timingSafeEqual(bufA, bufB);
|
||||
}
|
||||
|
||||
app.use('/api/health', healthRouter);
|
||||
app.use('/api/vms', vmsRouter);
|
||||
app.use('/api/snapshots', snapshotsRouter);
|
||||
|
||||
Reference in new issue
Block a user