Compare commits

..
4 changed files with 24 additions and 67 deletions
-2
View File
@@ -206,7 +206,6 @@ export default (app: Router) => {
}),
}),
async (req: Request, res: Response, next: NextFunction) => {
const logger: Logger = Container.get('logger');
try {
let { filename, content, path } = req.body as {
filename: string;
@@ -224,7 +223,6 @@ export default (app: Router) => {
await writeFileWithLock(filePath, content);
return res.send({ code: 200 });
} catch (e) {
logger.error('🔥 error saving script: %o', e);
return next(e);
}
},
+8
View File
@@ -22,6 +22,14 @@ export default ({ app }: { app: Application }) => {
app.use(rewrite(`${config.baseUrl}/*`, '/$1'));
}
// Normalize URL path to lowercase to prevent authentication bypass via mixed-case paths
// e.g. /API/system/command-run should not bypass JWT checks designed for /api/...
// The regex only matches the path portion (stops at ? or #), preserving query strings.
app.use((req: Request, res: Response, next: NextFunction) => {
req.url = req.url.replace(/^[^?#]*/, (p) => p.toLowerCase());
next();
});
app.get(`${config.api.prefix}/env.js`, serveEnv);
app.use(`${config.api.prefix}/static`, express.static(config.uploadPath));
-11
View File
@@ -16,17 +16,6 @@ export class HttpServerService {
metricsService.record('http_service_start', 1, {
port: port.toString(),
});
// Set server timeouts to prevent premature connection drops
if (this.server) {
// Timeout for receiving the entire request (including body) - 5 minutes
this.server.requestTimeout = 300000;
// Timeout for headers - 2 minutes
this.server.headersTimeout = 120000;
// Keep-alive timeout - 65 seconds (slightly more than typical load balancer timeout)
this.server.keepAliveTimeout = 65000;
}
resolve(this.server);
});
+16 -54
View File
@@ -1,9 +1,8 @@
import { lock } from 'proper-lockfile';
import os from 'os';
import path from 'path';
import { writeFile, open, chmod, FileHandle } from 'fs/promises';
import { writeFile, open, chmod } from 'fs/promises';
import { fileExist } from '../config/util';
import Logger from '../loaders/logger';
function getUniqueLockPath(filePath: string) {
const sanitizedPath = filePath
@@ -20,61 +19,24 @@ export async function writeFileWithLock(
if (typeof options === 'string') {
options = { encoding: options };
}
// Ensure file exists before locking
if (!(await fileExist(filePath))) {
let fileHandle: FileHandle | undefined;
try {
fileHandle = await open(filePath, 'w');
} catch (error) {
const errorMessage = error instanceof Error ? error.message : String(error);
throw new Error(`Failed to create file ${filePath}: ${errorMessage}`);
} finally {
if (fileHandle !== undefined) {
try {
await fileHandle.close();
} catch (closeError) {
// Log close error but don't throw to avoid masking the original error
Logger.error(`Failed to close file handle for ${filePath}:`, closeError);
}
}
}
const fileHandle = await open(filePath, 'w');
fileHandle.close();
}
const lockfilePath = getUniqueLockPath(filePath);
let release: (() => Promise<void>) | undefined;
try {
release = await lock(filePath, {
retries: {
retries: 10,
factor: 2,
minTimeout: 100,
maxTimeout: 3000,
},
lockfilePath,
});
} catch (error) {
const errorMessage = error instanceof Error ? error.message : String(error);
throw new Error(`Failed to acquire lock for ${filePath}: ${errorMessage}`);
}
try {
await writeFile(filePath, content, { encoding: 'utf8', ...options });
if (options?.mode) {
await chmod(filePath, options.mode);
}
} catch (error) {
const errorMessage = error instanceof Error ? error.message : String(error);
throw new Error(`Failed to write to file ${filePath}: ${errorMessage}`);
} finally {
if (release) {
try {
await release();
} catch (error) {
// Log but don't throw on release failure
Logger.error(`Failed to release lock for ${filePath}:`, error);
}
}
const release = await lock(filePath, {
retries: {
retries: 10,
factor: 2,
minTimeout: 100,
maxTimeout: 3000,
},
lockfilePath,
});
await writeFile(filePath, content, { encoding: 'utf8', ...options });
if (options?.mode) {
await chmod(filePath, options.mode);
}
await release();
}