Commit 8b2c14c
authored
security: fix MEDIUM findings (M2, M5, M10) and H5 (#5601)
* security: fix MEDIUM findings (M2, M5, M10) and HIGH H5
M2: Validate table name and where field in buildDynamicUpdateQuery()
against safe identifier regex to prevent SQL injection.
M5: Add URL protocol validation in hypothesisRunner to prevent SSRF.
Only allows http: and https: protocols.
M10: Replace Math.random() with crypto.randomBytes() for prompt ID
generation in PromptManager.
H5: Replace eval() with direct function call in requests.tsx.
The Google Translate compatibility fix was using eval() on a
hardcoded string — converted to a proper function.
* revert: undo M10 crypto.randomBytes change in PromptManager
Math.random() is fine for prompt IDs — they're not security tokens.1 parent 4c20bb7 commit 8b2c14c
File tree
3 files changed
+32
-21
lines changed- valhalla/jawn/src/lib/experiment
- web
- lib/api/db
- pages
3 files changed
+32
-21
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
33 | 33 | | |
34 | 34 | | |
35 | 35 | | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
36 | 41 | | |
37 | 42 | | |
38 | 43 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
149 | 149 | | |
150 | 150 | | |
151 | 151 | | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
152 | 161 | | |
153 | 162 | | |
154 | 163 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
16 | 15 | | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
| 16 | + | |
| 17 | + | |
21 | 18 | | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
27 | 26 | | |
28 | | - | |
29 | | - | |
30 | | - | |
| 27 | + | |
| 28 | + | |
31 | 29 | | |
32 | 30 | | |
33 | | - | |
34 | 31 | | |
35 | 32 | | |
36 | 33 | | |
| |||
49 | 46 | | |
50 | 47 | | |
51 | 48 | | |
52 | | - | |
| 49 | + | |
53 | 50 | | |
54 | 51 | | |
55 | 52 | | |
| |||
0 commit comments