Security fixes N4/H2/H1 + hide template editor for non-admins
This commit is contained in:
@@ -87,7 +87,8 @@ const allowedOrigins = validCorsOrigins.length > 0
|
||||
: ['http://localhost:5000', 'http://localhost:5173', 'http://127.0.0.1:5000', 'http://127.0.0.1:5173'];
|
||||
app.use(cors({ origin: allowedOrigins, credentials: true }));
|
||||
// Punkt 14: Body-Size-Limit to prevent DoS via large payloads
|
||||
app.use(express.json({ limit: process.env.BODY_LIMIT || '1mb' }));
|
||||
// N4: 10MB to accommodate file uploads (matches UPLOAD_MAX_MB)
|
||||
app.use(express.json({ limit: process.env.BODY_LIMIT || '10mb' }));
|
||||
// Punkt 8: Cookie-Parser für HttpOnly-Cookie Auth
|
||||
app.use(cookieParser());
|
||||
|
||||
|
||||
Reference in New Issue
Block a user