Security & UX Release v7
Security: - H1: Stored-XSS-Fix — Upload-Pfad-Whitelist (Server + Frontend-Guard safeFileUrl) - H2: Transaktionen repariert — txDb-Contract in db.js (PG + SQLite), Rollback funktioniert - H3-Vorbereitung: SESSION_SECRET wird in Compose durchgereicht (Fix M3) - registerLimiter exportiert (Crash-Bug: Route.post ohne Callback) - LDAP-Sync: PG-Transaktionsabbruch bei UNIQUE-Verstoß behoben (Precheck-Selects) - LDAP-Filter: nur echte Benutzerkonten (keine Computer/Service-Accounts, Bit 512) - Rollen app-seitig: Sync ändert nie role/status, neue User immer user+inaktiv - DB-Cleanup: 82 Computer-/Service-Accounts aus lokaler User-Tabelle entfernt UX: - Dashboard: Vorlagen als Table-Liste + Column-Chart (Top 5 in %), 2 gleich große Spalten - Table-Listen (Dashboard/Vorlageneditor/Aufgaben) scrollbar bis Seitenende - Pagination 10/Seite im Dashboard, Sidebar-Label Dashboard
This commit is contained in:
@@ -60,6 +60,15 @@ const validCorsOrigins = rawCorsOrigin
|
||||
.filter(o => o && /^https?:\/\/.+/.test(o));
|
||||
const cspConnectSrc = ["'self'", ...validCorsOrigins];
|
||||
|
||||
// M1: HSTS only makes sense over HTTPS. When serving plain HTTP (e.g. without
|
||||
// a TLS-terminating proxy), HSTS is ignored by browsers and can even cause
|
||||
// issues. Allow disabling it via HSTS_ENABLED=false (default: enabled in prod
|
||||
// when COOKIE_SECURE is true, i.e. when TLS is expected).
|
||||
const { COOKIE_SECURE } = require('./middleware/auth');
|
||||
const hstsEnabled = process.env.HSTS_ENABLED !== undefined
|
||||
? process.env.HSTS_ENABLED === 'true'
|
||||
: COOKIE_SECURE;
|
||||
|
||||
app.use(helmet({
|
||||
contentSecurityPolicy: {
|
||||
directives: {
|
||||
@@ -71,12 +80,12 @@ app.use(helmet({
|
||||
fontSrc: ["'self'", "data:"],
|
||||
},
|
||||
},
|
||||
// P18: HSTS - enforce HTTPS in production
|
||||
hsts: {
|
||||
// P18: HSTS - enforce HTTPS in production (only effective over HTTPS)
|
||||
hsts: hstsEnabled ? {
|
||||
maxAge: 31536000,
|
||||
includeSubDomains: true,
|
||||
preload: true,
|
||||
},
|
||||
} : false,
|
||||
crossOriginEmbedderPolicy: false,
|
||||
}));
|
||||
|
||||
|
||||
Reference in New Issue
Block a user