H3-Fix: TRUST_PROXY konfigurierbar (H3: Rate-Limit-Bypass hinter Proxy geloest)
This commit is contained in:
@@ -48,8 +48,18 @@ const { startLDAPSync, isLDAPConfigured } = require('./ldapSync');
|
|||||||
const app = express();
|
const app = express();
|
||||||
const PORT = process.env.PORT || 5000;
|
const PORT = process.env.PORT || 5000;
|
||||||
|
|
||||||
// Trust proxy for correct IP in rate limiting (Docker/Reverse Proxy)
|
// H3-Fix: Trust proxy konfigurierbar — hinter TLS-terminierendem Proxy (HAProxy)
|
||||||
app.set('trust proxy', 1);
|
// MUSS trust proxy aktiv sein, damit Express die echte Client-IP aus
|
||||||
|
// X-Forwarded-For liest (Rate-Limiting, Audit-Log). Bei direktem Port-Zugriff
|
||||||
|
// (ohne Proxy) muss es deaktiviert sein, sonst ist X-Forwarded-For spoofbar
|
||||||
|
// und das Rate-Limiting umgehbar.
|
||||||
|
// TRUST_PROXY=true → 1 Hop vertrauen (HAProxy/Nginx davor) ← Produktion
|
||||||
|
// TRUST_PROXY=false → keine Proxy-Header vertrauen ← direkter Zugriff
|
||||||
|
// unset → true in Produktion (Docker-Stack läuft hinter HAProxy)
|
||||||
|
const TRUST_PROXY = process.env.TRUST_PROXY !== undefined
|
||||||
|
? process.env.TRUST_PROXY === 'true'
|
||||||
|
: process.env.NODE_ENV === 'production';
|
||||||
|
app.set('trust proxy', TRUST_PROXY ? 1 : false);
|
||||||
|
|
||||||
// ============ Security Middleware ============
|
// ============ Security Middleware ============
|
||||||
// P14: Validate CORS_ORIGIN - filter empty/invalid entries before using in CSP
|
// P14: Validate CORS_ORIGIN - filter empty/invalid entries before using in CSP
|
||||||
|
|||||||
@@ -37,6 +37,8 @@ services:
|
|||||||
- UPLOAD_MAX_MB=${UPLOAD_MAX_MB:-10}
|
- UPLOAD_MAX_MB=${UPLOAD_MAX_MB:-10}
|
||||||
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:3900}
|
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:3900}
|
||||||
- NODE_ENV=${NODE_ENV:-production}
|
- NODE_ENV=${NODE_ENV:-production}
|
||||||
|
# H3: Proxy-Header vertrauen (true hinter HAProxy/Nginx, false bei direktem Zugriff)
|
||||||
|
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||||
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
|
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
|
||||||
- SESSION_MAX_PER_USER=${SESSION_MAX_PER_USER:-5}
|
- SESSION_MAX_PER_USER=${SESSION_MAX_PER_USER:-5}
|
||||||
- SESSION_TTL_HOURS=${SESSION_TTL_HOURS:-168}
|
- SESSION_TTL_HOURS=${SESSION_TTL_HOURS:-168}
|
||||||
|
|||||||
@@ -24,6 +24,8 @@ services:
|
|||||||
- SESSION_SECRET=${SESSION_SECRET:-}
|
- SESSION_SECRET=${SESSION_SECRET:-}
|
||||||
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:5000}
|
- CORS_ORIGIN=${CORS_ORIGIN:-http://localhost:5000}
|
||||||
- NODE_ENV=${NODE_ENV:-production}
|
- NODE_ENV=${NODE_ENV:-production}
|
||||||
|
# H3: Proxy-Header vertrauen (true hinter HAProxy/Nginx, false bei direktem Zugriff)
|
||||||
|
- TRUST_PROXY=${TRUST_PROXY:-true}
|
||||||
# Punkt 4: PostgreSQL (auto-started)
|
# Punkt 4: PostgreSQL (auto-started)
|
||||||
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
|
- DATABASE_URL=postgresql://${POSTGRES_USER:-workflow}:${POSTGRES_PASSWORD:-workflow}@db:5432/${POSTGRES_DB:-workflow}
|
||||||
# Punkt 9: Session-Limitierung
|
# Punkt 9: Session-Limitierung
|
||||||
|
|||||||
Reference in New Issue
Block a user