fix(security): patch 5 vulnerabilities from security audit

- mask API keys in usage stats/history responses (apiKeyMasked)
- validate proxy URL scheme + reject shell metachars before env write
- escape HTML in OAuth callback page to prevent XSS
- atomic O_EXCL lock file to prevent TOCTOU race in MITM startServer
- set mitmIsRestarting guard synchronously before any await

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
hamsa0x7
2026-06-26 11:04:51 +07:00
committed by decolua
co-authored by Cursor
parent 520f5049bf
commit d8c2298d07
5 changed files with 364 additions and 14 deletions
+22 -5
View File
@@ -3,6 +3,20 @@ function normalizeString(value) {
return String(value).trim();
}
const ALLOWED_PROXY_SCHEMES = ["http:", "https:", "socks5:", "socks4:", "socks5h:", "socks4a:"];
function validateProxyUrl(url) {
if (!url) return null;
if (/[\n\r`$]/.test(url)) return null;
try {
const parsed = new URL(url);
if (!ALLOWED_PROXY_SCHEMES.includes(parsed.protocol)) return null;
return parsed.href;
} catch {
return null;
}
}
export function applyOutboundProxyEnv(
{ outboundProxyEnabled, outboundProxyUrl, outboundNoProxy } = {}
) {
@@ -46,11 +60,14 @@ export function applyOutboundProxyEnv(
}
if (proxyUrl) {
process.env.HTTP_PROXY = proxyUrl;
process.env.HTTPS_PROXY = proxyUrl;
process.env.ALL_PROXY = proxyUrl;
process.env.NINE_ROUTER_PROXY_URL = proxyUrl;
managed = true;
const validated = validateProxyUrl(proxyUrl);
if (validated) {
process.env.HTTP_PROXY = validated;
process.env.HTTPS_PROXY = validated;
process.env.ALL_PROXY = validated;
process.env.NINE_ROUTER_PROXY_URL = validated;
managed = true;
}
}
if (noProxy) {