security(#197): constant-time API-key compare, clamp playout paging, baseline security headers
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 7s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 5m15s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 6m15s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / Docs update reminder (push) Has been skipped
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 8m13s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (push) Successful in 9m43s
Build ErsatzTV Image / Build & push image (amd64) (push) Has been cancelled
Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 7s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 5m15s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 6m15s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Build ErsatzTV Image / Docs update reminder (push) Has been skipped
Build ErsatzTV Image / Build & test (.NET) (push) Successful in 8m13s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (push) Successful in 9m43s
Build ErsatzTV Image / Build & push image (amd64) (push) Has been cancelled
Posture-independent safe hardening from the #197 cold API security review (the clear-cut fixes that don't depend on the fail-closed/CORS/versioning posture design, which is tracked separately): - ApiKeyAuthorizationFilter: compare X-Api-Key with CryptographicOperations.FixedTimeEquals instead of ordinal string.Equals (removes the response-timing oracle on the write key). [S10] - PlayoutController: clamp pageNum/pageSize on GET /api/playouts and /api/playouts/{id}/items to Math.Clamp(_, 1, 100), matching the documented api-conventions §1 convention every other paged endpoint already follows — these two were passing the raw value straight to EF Take(). [S8] - SecurityHeadersMiddleware: emit X-Content-Type-Options: nosniff, X-Frame-Options: DENY, Referrer-Policy: strict-origin-when-cross-origin on every response (nosniff backstops the artwork content-type MIME-sniffing risk). CSP/HSTS deferred to the #197 posture design (CSP needs SPA validation; HSTS is proxy/TLS-owned). [S10] Refs #197. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit was merged in pull request #279.
This commit is contained in:
@@ -45,6 +45,8 @@ public class PlayoutController(IMediator mediator, IEntityLocker entityLocker) :
|
||||
[FromQuery] int pageSize = 100,
|
||||
CancellationToken cancellationToken = default)
|
||||
{
|
||||
pageNum = Math.Max(0, pageNum);
|
||||
pageSize = Math.Clamp(pageSize, 1, MaxPageSize);
|
||||
PagedPlayoutsViewModel result =
|
||||
await mediator.Send(new GetPagedPlayouts(query, pageNum, pageSize), cancellationToken);
|
||||
return new PagedPlayoutsResponseModel(
|
||||
@@ -91,6 +93,8 @@ public class PlayoutController(IMediator mediator, IEntityLocker entityLocker) :
|
||||
return ApiResults.NotFoundProblem();
|
||||
}
|
||||
|
||||
pageNum = Math.Max(0, pageNum);
|
||||
pageSize = Math.Clamp(pageSize, 1, MaxPageSize);
|
||||
PagedPlayoutItemsViewModel result = await mediator.Send(
|
||||
new GetFuturePlayoutItemsById(id, showFiller, pageNum, pageSize),
|
||||
cancellationToken);
|
||||
|
||||
Reference in New Issue
Block a user