fix(security): patch 5 vulnerabilities from security audit
- mask API keys in usage stats/history responses (apiKeyMasked) - validate proxy URL scheme + reject shell metachars before env write - escape HTML in OAuth callback page to prevent XSS - atomic O_EXCL lock file to prevent TOCTOU race in MITM startServer - set mitmIsRestarting guard synchronously before any await Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
committed by
decolua
co-authored by
Cursor
parent
520f5049bf
commit
d8c2298d07
@@ -3,6 +3,20 @@ function normalizeString(value) {
|
||||
return String(value).trim();
|
||||
}
|
||||
|
||||
const ALLOWED_PROXY_SCHEMES = ["http:", "https:", "socks5:", "socks4:", "socks5h:", "socks4a:"];
|
||||
|
||||
function validateProxyUrl(url) {
|
||||
if (!url) return null;
|
||||
if (/[\n\r`$]/.test(url)) return null;
|
||||
try {
|
||||
const parsed = new URL(url);
|
||||
if (!ALLOWED_PROXY_SCHEMES.includes(parsed.protocol)) return null;
|
||||
return parsed.href;
|
||||
} catch {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
export function applyOutboundProxyEnv(
|
||||
{ outboundProxyEnabled, outboundProxyUrl, outboundNoProxy } = {}
|
||||
) {
|
||||
@@ -46,11 +60,14 @@ export function applyOutboundProxyEnv(
|
||||
}
|
||||
|
||||
if (proxyUrl) {
|
||||
process.env.HTTP_PROXY = proxyUrl;
|
||||
process.env.HTTPS_PROXY = proxyUrl;
|
||||
process.env.ALL_PROXY = proxyUrl;
|
||||
process.env.NINE_ROUTER_PROXY_URL = proxyUrl;
|
||||
managed = true;
|
||||
const validated = validateProxyUrl(proxyUrl);
|
||||
if (validated) {
|
||||
process.env.HTTP_PROXY = validated;
|
||||
process.env.HTTPS_PROXY = validated;
|
||||
process.env.ALL_PROXY = validated;
|
||||
process.env.NINE_ROUTER_PROXY_URL = validated;
|
||||
managed = true;
|
||||
}
|
||||
}
|
||||
|
||||
if (noProxy) {
|
||||
|
||||
Reference in New Issue
Block a user