Compare commits

..
4 changed files with 24 additions and 67 deletions
-2
View File
@@ -206,7 +206,6 @@ export default (app: Router) => {
}), }),
}), }),
async (req: Request, res: Response, next: NextFunction) => { async (req: Request, res: Response, next: NextFunction) => {
const logger: Logger = Container.get('logger');
try { try {
let { filename, content, path } = req.body as { let { filename, content, path } = req.body as {
filename: string; filename: string;
@@ -224,7 +223,6 @@ export default (app: Router) => {
await writeFileWithLock(filePath, content); await writeFileWithLock(filePath, content);
return res.send({ code: 200 }); return res.send({ code: 200 });
} catch (e) { } catch (e) {
logger.error('🔥 error saving script: %o', e);
return next(e); return next(e);
} }
}, },
+8
View File
@@ -22,6 +22,14 @@ export default ({ app }: { app: Application }) => {
app.use(rewrite(`${config.baseUrl}/*`, '/$1')); app.use(rewrite(`${config.baseUrl}/*`, '/$1'));
} }
// Normalize URL path to lowercase to prevent authentication bypass via mixed-case paths
// e.g. /API/system/command-run should not bypass JWT checks designed for /api/...
// The regex only matches the path portion (stops at ? or #), preserving query strings.
app.use((req: Request, res: Response, next: NextFunction) => {
req.url = req.url.replace(/^[^?#]*/, (p) => p.toLowerCase());
next();
});
app.get(`${config.api.prefix}/env.js`, serveEnv); app.get(`${config.api.prefix}/env.js`, serveEnv);
app.use(`${config.api.prefix}/static`, express.static(config.uploadPath)); app.use(`${config.api.prefix}/static`, express.static(config.uploadPath));
-11
View File
@@ -16,17 +16,6 @@ export class HttpServerService {
metricsService.record('http_service_start', 1, { metricsService.record('http_service_start', 1, {
port: port.toString(), port: port.toString(),
}); });
// Set server timeouts to prevent premature connection drops
if (this.server) {
// Timeout for receiving the entire request (including body) - 5 minutes
this.server.requestTimeout = 300000;
// Timeout for headers - 2 minutes
this.server.headersTimeout = 120000;
// Keep-alive timeout - 65 seconds (slightly more than typical load balancer timeout)
this.server.keepAliveTimeout = 65000;
}
resolve(this.server); resolve(this.server);
}); });
+16 -54
View File
@@ -1,9 +1,8 @@
import { lock } from 'proper-lockfile'; import { lock } from 'proper-lockfile';
import os from 'os'; import os from 'os';
import path from 'path'; import path from 'path';
import { writeFile, open, chmod, FileHandle } from 'fs/promises'; import { writeFile, open, chmod } from 'fs/promises';
import { fileExist } from '../config/util'; import { fileExist } from '../config/util';
import Logger from '../loaders/logger';
function getUniqueLockPath(filePath: string) { function getUniqueLockPath(filePath: string) {
const sanitizedPath = filePath const sanitizedPath = filePath
@@ -20,61 +19,24 @@ export async function writeFileWithLock(
if (typeof options === 'string') { if (typeof options === 'string') {
options = { encoding: options }; options = { encoding: options };
} }
// Ensure file exists before locking
if (!(await fileExist(filePath))) { if (!(await fileExist(filePath))) {
let fileHandle: FileHandle | undefined; const fileHandle = await open(filePath, 'w');
try { fileHandle.close();
fileHandle = await open(filePath, 'w');
} catch (error) {
const errorMessage = error instanceof Error ? error.message : String(error);
throw new Error(`Failed to create file ${filePath}: ${errorMessage}`);
} finally {
if (fileHandle !== undefined) {
try {
await fileHandle.close();
} catch (closeError) {
// Log close error but don't throw to avoid masking the original error
Logger.error(`Failed to close file handle for ${filePath}:`, closeError);
}
}
}
} }
const lockfilePath = getUniqueLockPath(filePath); const lockfilePath = getUniqueLockPath(filePath);
let release: (() => Promise<void>) | undefined;
try { const release = await lock(filePath, {
release = await lock(filePath, { retries: {
retries: { retries: 10,
retries: 10, factor: 2,
factor: 2, minTimeout: 100,
minTimeout: 100, maxTimeout: 3000,
maxTimeout: 3000, },
}, lockfilePath,
lockfilePath, });
}); await writeFile(filePath, content, { encoding: 'utf8', ...options });
} catch (error) { if (options?.mode) {
const errorMessage = error instanceof Error ? error.message : String(error); await chmod(filePath, options.mode);
throw new Error(`Failed to acquire lock for ${filePath}: ${errorMessage}`);
}
try {
await writeFile(filePath, content, { encoding: 'utf8', ...options });
if (options?.mode) {
await chmod(filePath, options.mode);
}
} catch (error) {
const errorMessage = error instanceof Error ? error.message : String(error);
throw new Error(`Failed to write to file ${filePath}: ${errorMessage}`);
} finally {
if (release) {
try {
await release();
} catch (error) {
// Log but don't throw on release failure
Logger.error(`Failed to release lock for ${filePath}:`, error);
}
}
} }
await release();
} }