security+feat: v1.3.0 — pentest remediation, container reliability, UI overhaul
Security (33 pentest findings addressed): - CRITICAL: backend binds 127.0.0.1, path traversal in tor.rs/dwn fixed - HIGH: federation requires signatures, XSS login redirect, RBAC viewer restricted - HIGH: tar slip prevention, S3 SSRF validation, backup ID validation - MEDIUM: remember-me random secret, TOTP session rotation, password re-auth - LOW: CSP unsafe-inline removed, CORS dev-only, onion/webhook validation Container reliability: - Memory limits on all 37 containers (OOM prevention) - Exited vs stopped state distinction with health-aware status badges - Crash recovery coordination (no more restart cascade) - User-stopped tracking survives reboots - Tiered boot recovery (databases → core → services → apps) UI: - Wallet TransactionsModal, health-aware app status badges - Restart button on containers, exited/crashed red state - Mesh view overhaul, glass button updates, BaseModal/ToggleSwitch - Apps sticky header removed, dev faucet, mutable mock wallet Infrastructure: - LND REST port 8080 exposed over Tor (LND Connect fix) - Nginx cookie_session fix, deploy script Tor config updated - Dev environment: podman auto-start, boot mode simulation Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
d1b48388fb
commit
1a74a930f7
@@ -7,6 +7,87 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [1.3.0] - 2026-03-19
|
||||
|
||||
### Security
|
||||
|
||||
#### Pentest Remediation (33 findings, all addressed)
|
||||
- **Critical**: Backend now binds to 127.0.0.1 only — no more direct LAN access to port 5678
|
||||
- **Critical**: Fixed path traversal in Tor service management that could allow `sudo rm -rf` on arbitrary directories
|
||||
- **Critical**: Fixed unauthenticated file read/delete via DWN recordId path traversal
|
||||
- **High**: Federation peers now require cryptographic signature — unsigned peers rejected
|
||||
- **High**: Login redirect XSS vulnerability fixed with proper URL validation
|
||||
- **High**: Viewer role restricted to read-only node methods (was granting sign/export access)
|
||||
- **High**: Backup restore/verify now validates IDs against path traversal
|
||||
- **High**: Tar archive extraction validates every entry path (prevents tar slip attacks)
|
||||
- **High**: S3 backup endpoints require HTTPS and reject private IP ranges
|
||||
- **Medium**: Remember-me token secret now uses cryptographic random (not machine-id)
|
||||
- **Medium**: Destructive operations (factory reset, onboarding reset) now require password re-verification
|
||||
- **Medium**: Session token rotated after TOTP verification (prevents interception reuse)
|
||||
- **Medium**: Webhook URL validation hardened against IPv6 bypass, DNS rebinding, redirect chains
|
||||
- **Low**: CORS localhost:8100 only included in dev mode
|
||||
- **Low**: CSP `unsafe-inline` removed from `script-src`
|
||||
- **Low**: Content filenames validated against path separators and hidden file prefixes
|
||||
- **Low**: Nostr relay URLs restricted to `wss://` with private IP rejection
|
||||
- **Low**: Onion address validation enforces v3 format (56 base32 chars)
|
||||
- **Low**: Router detection restricted to private IP ranges only
|
||||
|
||||
#### Nginx Authentication
|
||||
- Fixed session cookie name mismatch (`session_id` → `session`) across all nginx auth checks
|
||||
- LND Connect info endpoint now properly authenticated
|
||||
|
||||
### Container Reliability
|
||||
|
||||
#### Memory Limits (prevents OOM crashes)
|
||||
- All 37 containers in `first-boot-containers.sh` now have `--memory=` limits
|
||||
- Automatic RAM tier detection — reduced limits on 8GB machines
|
||||
- Prevents a single runaway container from crashing the entire system
|
||||
|
||||
#### Smart Container States
|
||||
- New `exited` state distinguishes crashed containers from intentionally stopped ones
|
||||
- Crashed containers show red "crashed" badge with restart button
|
||||
- Health-aware status: "healthy" (green), "starting up" (yellow spinner), "unhealthy" (orange pulse)
|
||||
- Restart button added next to Stop on running containers
|
||||
|
||||
#### Crash Recovery Improvements
|
||||
- Boot recovery and health monitor now coordinate via shared flag (no more restart cascade)
|
||||
- User-stopped containers tracked in `user-stopped.json` — survive reboots without auto-restart
|
||||
- Boot recovery uses tiered ordering: databases → core → services → apps → UIs
|
||||
- Health monitor waits for boot recovery to complete before starting checks
|
||||
|
||||
### UI Improvements
|
||||
|
||||
#### Home Dashboard
|
||||
- Wallet card now matches Web5 wallet display
|
||||
- New Transactions modal with full history (incoming/outgoing, amounts, confirmations)
|
||||
- Transactions button in header — switches to "Incoming" badge when pending transactions exist
|
||||
- Dev faucet button (dev mode only) with mutable wallet state
|
||||
- Fixed system stats crash (`cpu_usage_percent` field name mismatch)
|
||||
|
||||
#### Apps & App Details
|
||||
- Container restart button (icon) next to Stop on all running apps
|
||||
- Exited/crashed containers show "Restart" instead of "Start" with red styling
|
||||
- Removed broken sticky header from Apps page
|
||||
- Health-aware status badges throughout
|
||||
|
||||
#### Mesh, Cloud, Settings & More
|
||||
- Mesh view overhaul with improved layout
|
||||
- Glass button styling updates across components
|
||||
- New BaseModal and ToggleSwitch components
|
||||
- Updated translations (English + Spanish)
|
||||
- Spotlight search improvements
|
||||
|
||||
### Infrastructure
|
||||
|
||||
#### LND Connect
|
||||
- Tor hidden service now exposes LND REST port (8080) for remote wallet connections
|
||||
- Fixed in ISO build script, deploy script, and live servers
|
||||
|
||||
#### Dev Environment
|
||||
- Mock backend has mutable wallet state (faucet/send/receive actually change balances)
|
||||
- Testnet stack option auto-starts Podman machine on macOS
|
||||
- Boot mode simulation for testing startup screens
|
||||
|
||||
## [1.2.0] - 2026-03-14
|
||||
|
||||
### Fixed
|
||||
|
||||
Reference in New Issue
Block a user