Skip to content

security: audit hardening wave 1 — IDOR binding, XFF spoof, SVG-XSS, unauth abuse - #248

Merged
kh0ra merged 1 commit into
mainfrom
security/audit-hardening
Jun 21, 2026
Merged

kh0ra merged 1 commit into
mainfrom
security/audit-hardening

Conversation

@kh0ra

@kh0ra kh0ra commented Jun 21, 2026

Copy link
Copy Markdown
Member

From an 8-lens multi-agent security audit (on-chain, authz, payments, injection/SSRF, crypto, DoS, business-logic, web-hardening). Full findings: docs/SECURITY_AUDIT.md (64 raw findings). This wave closes the confirmed high-severity, non-breaking issues; each was triaged by hand against the actual code.

Fixed

  • Systemic IDOR — requireAuth proved control of x-wallet but routes then acted on a body/path-supplied wallet without binding. New requireWalletMatch(auth, actingWallet) enforces signer == target; wired into avatar, stake, unstake, profile POST, profile PATCH. No-op while AUTH_ENFORCED is off, so it's correct the instant the flag flips.
  • Rate-limit bypass via X-Forwarded-For spoof — ipFromRequest used the attacker-controllable leftmost XFF. Now prefers Vercel's x-real-ip / x-vercel-forwarded-for, else the rightmost hop.
  • Avatar IDOR + stored-XSS — was unauthenticated; now auth-bound and rejects data:image/svg+xml (active content).
  • Unauthenticated + unthrottled expensive endpoints — generate/image (paid fal.ai), delivery/upload (Blob cost), a2a (job spam) now per-IP rate limited.
  • AUTH_ENFORCED — loud production warning when not true.

Deferred (tracked in docs/SECURITY_AUDIT.md)

SSRF TOCTOU/DNS-rebinding (agent register), x402 facilitator mint/recipient re-check, off-chain dispute griefing, wallet-signature replay nonce cache, reputation self-dealing, and the AUTH_ENFORCED=true production flip — that one needs the frontend + SDK to sign requests, a product step, not a code-only change.

Related: C-090/C-091/C-092/C-093 (M6 security).

…unauth abuse

From an 8-lens multi-agent security audit (full findings in
docs/SECURITY_AUDIT.md). This wave closes the confirmed, high-severity,
non-breaking issues; the systemic auth-enforcement flip is documented as
the one operator step that needs frontend signing.

- require-auth: add requireWalletMatch(auth, actingWallet) to bind the
  proven signer to the wallet a request mutates (closes the systemic IDOR
  where requireAuth proved control of x-wallet but routes acted on a
  body-supplied wallet). No-op while AUTH_ENFORCED is off, so the binding
  is correct the instant the flag flips. Added a loud production warning
  when AUTH_ENFORCED is not 'true'.
- rateLimit ipFromRequest: stop trusting the spoofable LEFTMOST
  X-Forwarded-For (an attacker rotated it to defeat per-IP limits). Prefer
  Vercel's x-real-ip / x-vercel-forwarded-for, else the rightmost XFF hop.
- profile avatar: add auth + requireWalletMatch (was unauthenticated IDOR);
  reject SVG/non-raster data URLs (stored-XSS via data:image/svg+xml).
- generate/image, delivery/upload, a2a: add per-IP rate limiting (were
  unauthenticated + unthrottled: fal.ai bill abuse, Blob cost abuse, job
  spam).
- agents/stake, agents/unstake, profile POST, profile/[wallet] PATCH:
  add requireAuth + requireWalletMatch (were spoofable / unauthenticated
  IDOR on stake/slash/identity).

Deferred to follow-up (tracked in docs/SECURITY_AUDIT.md): SSRF
TOCTOU/DNS-rebinding in agent register, x402 facilitator mint/recipient
re-check, off-chain dispute griefing, wallet-signature replay nonce cache,
reputation self-dealing, and the AUTH_ENFORCED=true production flip (needs
frontend/SDK request signing).
@changeset-bot

changeset-bot Bot commented Jun 21, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: da7f9fc

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@vercel

vercel Bot commented Jun 21, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
covenant Ready Ready Preview, Comment Jun 21, 2026 12:23am

@kh0ra
kh0ra merged commit 08d6637 into main Jun 21, 2026
10 of 12 checks passed
@kh0ra
kh0ra deleted the security/audit-hardening branch June 21, 2026 00:24

This branch was successfully deployed

1 active deployment
Preview — da7f9fc6 Deployed Jun 21, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant