DEV1.0: Initial commit - Workflow Portal with security fixes

- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration
- Frontend: React 18 + Vite + TailwindCSS/DaisyUI
- Security fixes applied (2026-07 + 2026-08):
  - LDAP injection prevention, CSRF protection, HttpOnly cookies
  - Session hashing (SHA-256), account lockout, rate limiting
  - Input validation (zod), file upload security, CSP/HSTS headers
  - V3: express-rate-limit updated (ip-address SSRF fix)
  - V4: postcss updated (nanoid DoS fix)
  - V5: Rate-limit on /health endpoint
  - V6: Session rotation on login (session fixation prevention)
  - V9: Task values array limit (DoS prevention)
  - V10: Frontend XSS audit completed
- Docker: Multi-stage build, non-root user, PostgreSQL + backup service
This commit is contained in:
Kühn
2026-08-24 09:45:28 +02:00
commit 6be1791c62
103 changed files with 12253 additions and 0 deletions

View File

@@ -0,0 +1,90 @@
import React, { createContext, useContext, useState, useCallback, useEffect } from 'react';
import { API_BASE, setCSRFToken, getCSRFToken } from '../utils/api';
const AuthContext = createContext(null);
export function AuthProvider({ children }) {
const [user, setUser] = useState(() => {
try {
const saved = localStorage.getItem('workflow_user');
if (saved) return JSON.parse(saved);
} catch (e) { /* ignore */ }
return null;
});
const [loading, setLoading] = useState(true);
// Verify session on mount - P5: cookie-only auth (no token in localStorage)
useEffect(() => {
fetch(`${API_BASE}/auth/me`, { credentials: 'include' })
.then(res => res.ok ? res.json() : Promise.reject())
.then(data => { setUser(data); localStorage.setItem('workflow_user', JSON.stringify(data)); })
.catch(() => {
setUser(null);
localStorage.removeItem('workflow_user');
setCSRFToken(null);
})
.finally(() => setLoading(false));
}, []);
const login = useCallback(async (email, password) => {
const res = await fetch(`${API_BASE}/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ email, password }),
credentials: 'include', // P5: HttpOnly-Cookie only
});
const data = await res.json();
if (!res.ok) throw new Error(data.error || 'Anmeldung fehlgeschlagen');
setUser(data);
localStorage.setItem('workflow_user', JSON.stringify(data));
// P4: Store CSRF token in memory (returned from login response)
if (data.csrfToken) setCSRFToken(data.csrfToken);
return data;
}, []);
const register = useCallback(async (email, password, name = '') => {
const res = await fetch(`${API_BASE}/auth/register`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ email, password, name, role: 'user' }),
credentials: 'include', // P5: HttpOnly-Cookie only
});
const data = await res.json();
if (!res.ok) throw new Error(data.error || 'Registrierung fehlgeschlagen');
setUser(data);
localStorage.setItem('workflow_user', JSON.stringify(data));
// P4: Store CSRF token in memory (returned from register response)
if (data.csrfToken) setCSRFToken(data.csrfToken);
return data;
}, []);
const logout = useCallback(async () => {
try {
// Bug 2/4: Send CSRF token with logout request
const csrf = getCSRFToken();
await fetch(`${API_BASE}/auth/logout`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
...(csrf ? { 'x-csrf-token': csrf } : {}),
},
credentials: 'include',
});
} catch (e) { /* ignore */ }
setUser(null);
localStorage.removeItem('workflow_user');
setCSRFToken(null);
}, []);
return (
<AuthContext.Provider value={{ user, login, register, logout, loading }}>
{children}
</AuthContext.Provider>
);
}
export function useAuth() {
const ctx = useContext(AuthContext);
if (!ctx) throw new Error('useAuth must be used within AuthProvider');
return ctx;
}