Security fixes N4/H2/H1 + hide template editor for non-admins

This commit is contained in:
Kühn
2026-08-28 10:15:31 +02:00
parent a35721abec
commit 03d20b0e09
19 changed files with 31 additions and 56 deletions

View File

@@ -87,7 +87,8 @@ const allowedOrigins = validCorsOrigins.length > 0
: ['http://localhost:5000', 'http://localhost:5173', 'http://127.0.0.1:5000', 'http://127.0.0.1:5173'];
app.use(cors({ origin: allowedOrigins, credentials: true }));
// Punkt 14: Body-Size-Limit to prevent DoS via large payloads
app.use(express.json({ limit: process.env.BODY_LIMIT || '1mb' }));
// N4: 10MB to accommodate file uploads (matches UPLOAD_MAX_MB)
app.use(express.json({ limit: process.env.BODY_LIMIT || '10mb' }));
// Punkt 8: Cookie-Parser für HttpOnly-Cookie Auth
app.use(cookieParser());