feat: security hardening, DB indexes, token revocation, and input validation

- SSRF protection: DNS resolution + private IP blocking on metadata fetcher
- Upload security: CSP/X-Frame-Options headers, SVG forced download, nosniff
- Auth hardening: JWT secret min length, password min 8 chars, token revocation via password_changed_at
- Attachment ownership verification before linking to messages
- Message length limit (4000 chars) enforced on client and server
- Asset URL validation on avatar/banner updates
- Federation instance validation (domain regex, origin scheme, length limits)
- DB indexes on all FK columns for query performance
- Migrations: nullable moderator columns, dm_messages reply_to FK constraint
- File cleanup on avatar/banner replacement and space deletion
- Fastify trustProxy, AbortController on fetches, typing map size cap
This commit is contained in:
Jannis Braun
2026-03-15 00:06:15 +01:00
parent ed4dcdcf69
commit 7c544c1ff4
37 changed files with 892 additions and 178 deletions
@@ -54,10 +54,10 @@ export function FriendsPage() {
}
};
const handleOpenDm = async (friendId: string, instanceOrigin: string) => {
const handleOpenDm = async (friendId: string, instanceOrigin: string, homeUserId?: string) => {
try {
// Check if a DM already exists with this user (on any instance)
const existing = useSpaceStore.getState().findExistingDmForUser({ id: friendId });
const existing = useSpaceStore.getState().findExistingDmForUser({ id: friendId, homeUserId: homeUserId ?? undefined });
if (existing) {
useUIStore.getState().setShowDms(true);
navigate(`/channels/@me/${existing.dm.id}`);
@@ -99,7 +99,7 @@ export function FriendsPage() {
</div>
) : (
onlineFriends.map(friend => (
<FriendItem key={`${friend.id}:${friend._instanceOrigin}`} friend={friend} onRemove={() => removeFriend(friend.id)} onDm={() => handleOpenDm(friend.id, friend._instanceOrigin)} />
<FriendItem key={`${friend.id}:${friend._instanceOrigin}`} friend={friend} onRemove={() => removeFriend(friend.id)} onDm={() => handleOpenDm(friend.id, friend._instanceOrigin, friend.homeUserId ?? undefined)} />
))
)}
</div>
@@ -116,7 +116,7 @@ export function FriendsPage() {
</div>
) : (
friends.map(friend => (
<FriendItem key={`${friend.id}:${friend._instanceOrigin}`} friend={friend} onRemove={() => removeFriend(friend.id)} onDm={() => handleOpenDm(friend.id, friend._instanceOrigin)} />
<FriendItem key={`${friend.id}:${friend._instanceOrigin}`} friend={friend} onRemove={() => removeFriend(friend.id)} onDm={() => handleOpenDm(friend.id, friend._instanceOrigin, friend.homeUserId ?? undefined)} />
))
)}
</div>
@@ -227,7 +227,7 @@ function AddFriendTab({
addStatus: { type: 'success' | 'error'; message: string } | null;
isLoading: boolean;
onSubmit: (e: React.FormEvent) => void;
onOpenDm: (userId: string, origin: string) => void;
onOpenDm: (userId: string, origin: string, homeUserId?: string) => void;
}) {
const discoverUsers = useDiscoverStore((s) => s.users);
const discoverLoading = useDiscoverStore((s) => s.isLoading);
@@ -354,7 +354,7 @@ function UserDiscoverCard({
onOpenDm,
}: {
user: TaggedDiscoverUser;
onOpenDm: (userId: string, origin: string) => void;
onOpenDm: (userId: string, origin: string, homeUserId?: string) => void;
}) {
const sendFriendRequest = useSocialStore((s) => s.sendFriendRequest);
const updateFriendRequest = useSocialStore((s) => s.updateFriendRequest);
@@ -443,7 +443,7 @@ function UserDiscoverCard({
};
const handleMessage = () => {
onOpenDm(user.id, user._instanceOrigin);
onOpenDm(user.id, user._instanceOrigin, user.homeUserId ?? undefined);
};
return (