security: fix vulnerabilities 1-7 from security audit
- Fix #1: Share handler IDOR - enforce owner check on share operations - Fix #2: list_files_query IDOR - bind folder queries to authenticated user - Fix #3: Dedup handler IDOR - restrict dedup operations to file owner - Fix #4: Trash handler OptionalAuthUser - require full AuthUser - Fix #5: Error info leakage - sanitize 500 error responses - Fix #6: Chunked upload IDOR - bind upload sessions to user_id, add verify_session_owner() check on all session operations - Fix #7: CSP unsafe-inline removal - migrate all inline scripts, styles and event handlers to external files, tighten CSP to script-src 'self'; style-src 'self' New files: - static/js/core/theme-init.js (render-blocking theme init) - static/js/core/sw-register.js (service worker registration) - static/css/views/device-verify.css (extracted inline styles) - static/js/views/device-verify/device-verify.js (extracted inline script)
This commit is contained in:
@@ -74,7 +74,7 @@ impl SearchHandler {
|
||||
error!("Search error: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "error": format!("Search error: {}", err) })),
|
||||
Json(json!({ "error": "Search error" })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -115,7 +115,7 @@ impl SearchHandler {
|
||||
error!("Search error: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "error": format!("Search error: {}", err) })),
|
||||
Json(json!({ "error": "Search error" })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -159,7 +159,7 @@ impl SearchHandler {
|
||||
error!("Suggestions error: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "error": format!("Suggestions error: {}", err) })),
|
||||
Json(json!({ "error": "Suggestions error" })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
@@ -195,7 +195,7 @@ impl SearchHandler {
|
||||
error!("Error clearing search cache: {}", err);
|
||||
(
|
||||
StatusCode::INTERNAL_SERVER_ERROR,
|
||||
Json(json!({ "error": format!("Error clearing search cache: {}", err) })),
|
||||
Json(json!({ "error": "Error clearing search cache" })),
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user