feat: security hardening, DB indexes, token revocation, and input validation
- SSRF protection: DNS resolution + private IP blocking on metadata fetcher - Upload security: CSP/X-Frame-Options headers, SVG forced download, nosniff - Auth hardening: JWT secret min length, password min 8 chars, token revocation via password_changed_at - Attachment ownership verification before linking to messages - Message length limit (4000 chars) enforced on client and server - Asset URL validation on avatar/banner updates - Federation instance validation (domain regex, origin scheme, length limits) - DB indexes on all FK columns for query performance - Migrations: nullable moderator columns, dm_messages reply_to FK constraint - File cleanup on avatar/banner replacement and space deletion - Fastify trustProxy, AbortController on fetches, typing map size cap
This commit is contained in:
@@ -318,6 +318,7 @@ CREATE TABLE users (
|
||||
avatar_color TEXT, -- avatar background color
|
||||
bio TEXT, -- user biography
|
||||
is_deleted INTEGER DEFAULT 0, -- soft-delete flag
|
||||
password_changed_at INTEGER, -- token revocation: tokens issued before this are rejected
|
||||
created_at INTEGER NOT NULL
|
||||
);
|
||||
|
||||
@@ -400,6 +401,7 @@ CREATE TABLE attachments (
|
||||
id TEXT PRIMARY KEY,
|
||||
message_id TEXT REFERENCES messages(id) ON DELETE CASCADE,
|
||||
dm_message_id TEXT,
|
||||
uploader_id TEXT, -- user who uploaded (null for legacy uploads)
|
||||
filename TEXT NOT NULL,
|
||||
original_name TEXT NOT NULL,
|
||||
mimetype TEXT NOT NULL,
|
||||
|
||||
Reference in New Issue
Block a user