Repository navigation
security: audit hardening wave 1 — IDOR binding, XFF spoof, SVG-XSS, unauth abuse - #248
Merged
Merged
Conversation
…unauth abuse From an 8-lens multi-agent security audit (full findings in docs/SECURITY_AUDIT.md). This wave closes the confirmed, high-severity, non-breaking issues; the systemic auth-enforcement flip is documented as the one operator step that needs frontend signing. - require-auth: add requireWalletMatch(auth, actingWallet) to bind the proven signer to the wallet a request mutates (closes the systemic IDOR where requireAuth proved control of x-wallet but routes acted on a body-supplied wallet). No-op while AUTH_ENFORCED is off, so the binding is correct the instant the flag flips. Added a loud production warning when AUTH_ENFORCED is not 'true'. - rateLimit ipFromRequest: stop trusting the spoofable LEFTMOST X-Forwarded-For (an attacker rotated it to defeat per-IP limits). Prefer Vercel's x-real-ip / x-vercel-forwarded-for, else the rightmost XFF hop. - profile avatar: add auth + requireWalletMatch (was unauthenticated IDOR); reject SVG/non-raster data URLs (stored-XSS via data:image/svg+xml). - generate/image, delivery/upload, a2a: add per-IP rate limiting (were unauthenticated + unthrottled: fal.ai bill abuse, Blob cost abuse, job spam). - agents/stake, agents/unstake, profile POST, profile/[wallet] PATCH: add requireAuth + requireWalletMatch (were spoofable / unauthenticated IDOR on stake/slash/identity). Deferred to follow-up (tracked in docs/SECURITY_AUDIT.md): SSRF TOCTOU/DNS-rebinding in agent register, x402 facilitator mint/recipient re-check, off-chain dispute griefing, wallet-signature replay nonce cache, reputation self-dealing, and the AUTH_ENFORCED=true production flip (needs frontend/SDK request signing).
|
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
7 tasks
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
From an 8-lens multi-agent security audit (on-chain, authz, payments, injection/SSRF, crypto, DoS, business-logic, web-hardening). Full findings:
docs/SECURITY_AUDIT.md(64 raw findings). This wave closes the confirmed high-severity, non-breaking issues; each was triaged by hand against the actual code.Fixed
requireAuthproved control ofx-walletbut routes then acted on a body/path-supplied wallet without binding. NewrequireWalletMatch(auth, actingWallet)enforces signer == target; wired into avatar, stake, unstake, profile POST, profile PATCH. No-op whileAUTH_ENFORCEDis off, so it's correct the instant the flag flips.ipFromRequestused the attacker-controllable leftmost XFF. Now prefers Vercel'sx-real-ip/x-vercel-forwarded-for, else the rightmost hop.data:image/svg+xml(active content).generate/image(paid fal.ai),delivery/upload(Blob cost),a2a(job spam) now per-IP rate limited.true.Deferred (tracked in
docs/SECURITY_AUDIT.md)SSRF TOCTOU/DNS-rebinding (agent register), x402 facilitator mint/recipient re-check, off-chain dispute griefing, wallet-signature replay nonce cache, reputation self-dealing, and the AUTH_ENFORCED=true production flip — that one needs the frontend + SDK to sign requests, a product step, not a code-only change.
Related: C-090/C-091/C-092/C-093 (M6 security).