Skip to content

fix(security): patch 5 vulnerabilities from security audit - #2007

Closed
hamsa0x7 wants to merge 2 commits into
decolua:masterfrom
hamsa0x7:fix/security-audit-001-018
Closed

hamsa0x7 wants to merge 2 commits into
decolua:masterfrom
hamsa0x7:fix/security-audit-001-018

Conversation

@hamsa0x7

@hamsa0x7 hamsa0x7 commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Security Audit Fixes

This PR patches 5 vulnerabilities identified during a comprehensive security audit of the 9router codebase.

Fixes

#1962 - API key leak in usage stats (AUDIT-002)

  • Added maskApiKey helper to strip raw API keys from getUsageStats and getUsageHistory responses
  • All apiKey fields replaced with apiKeyMasked in broadcast payloads to prevent exposure to dashboard clients
  • File: src/lib/db/repos/usageRepo.js

#1961 - Command injection via proxy URL (AUDIT-003)

  • Added validateProxyUrl with allowlist of safe proxy schemes (http, https, socks4/5 variants)
  • Rejects URLs containing shell metacharacters (newline, backtick, dollar sign)
  • Only validated URLs are written to HTTP_PROXY/HTTPS_PROXY/ALL_PROXY env vars
  • File: src/lib/network/outboundProxy.js

#1963 - TOCTOU race in MITM server startup (AUDIT-004)

  • Added atomic lock file creation using O_EXCL flag (fs.writeFileSync with flag wx)
  • Lock is cleaned up on success, failure, server exit, and stopServer
  • Prevents concurrent startServer calls from racing on PID file checks
  • File: src/mitm/manager.js

#1965 - Race condition in retry tracking (AUDIT-001)

  • Moved mitmIsRestarting guard to immediately after the check, before any await
  • Moved mitmRestartCount increment before the await setTimeout delay
  • Added mitmIsRestarting reset to the max-restarts early return path
  • File: src/mitm/manager.js

#1972 - XSS in OAuth callback page (AUDIT-018)

  • Added escapeHtml function to escape ampersand, angle brackets, quotes
  • Applied to message parameter in renderCodexResultPage before HTML interpolation
  • Prevents script injection via error_description query parameter in OAuth callbacks
  • File: src/lib/oauth/utils/server.js

Test Results

All 21 tests pass (vitest):

\
Tests 21 passed (21)
Duration 277ms
\\

Test Status
AUDIT-002: maskApiKey function exists PASS
AUDIT-002: getUsageHistory returns apiKeyMasked PASS
AUDIT-002: getUsageStats uses apiKeyMasked in byApiKey PASS
AUDIT-002: byApiKey keys use masked key PASS
AUDIT-003: validateProxyUrl function exists PASS
AUDIT-003: accepts valid http proxy PASS
AUDIT-003: accepts valid https proxy PASS
AUDIT-003: accepts valid socks5 proxy PASS
AUDIT-003: rejects newline injection PASS
AUDIT-003: rejects backtick injection PASS
AUDIT-003: rejects dollar injection PASS
AUDIT-003: rejects file:// scheme PASS
AUDIT-003: rejects javascript: scheme PASS
AUDIT-018: escapeHtml function exists PASS
AUDIT-018: escapes all HTML entities PASS
AUDIT-018: uses safeMessage in HTML PASS
AUDIT-004: LOCK_FILE constant defined PASS
AUDIT-004: uses O_EXCL (wx) flag PASS
AUDIT-004: cleans up lock on all exit paths PASS
AUDIT-001: guard set before first await PASS
AUDIT-001: guard reset on max-restarts return PASS

Test plan

  • Verify usage stats/history responses no longer contain raw API keys
  • Verify proxy URL with shell metacharacters is rejected
  • Verify concurrent MITM server starts are serialized by lock file
  • Verify MITM restart guard prevents duplicate restart attempts
  • Verify OAuth callback page escapes HTML in error messages

hamsa0x7 added 2 commits June 23, 2026 10:11
- decolua#1962: mask API keys in usage stats and history responses
- decolua#1961: validate proxy URL scheme before writing to env vars
- decolua#1963: use atomic O_EXCL lock file to prevent TOCTOU race in startServer
- decolua#1965: set mitmIsRestarting guard synchronously before any await
- decolua#1972: escape HTML in OAuth callback result page to prevent XSS
21 tests covering:
- AUDIT-002: API key masking in usage stats and history
- AUDIT-003: Proxy URL scheme validation and shell metacharacter rejection
- AUDIT-004: Atomic O_EXCL lock file for MITM startup
- AUDIT-001: Synchronous restart guard before any await
- AUDIT-018: HTML escaping in OAuth callback page
@hamsa0x7
hamsa0x7 force-pushed the fix/security-audit-001-018 branch from 6809eb7 to 8deded7 Compare June 23, 2026 04:41
ozkancan-apk added a commit to ozkancan-apk/9routerFullFree that referenced this pull request Jun 24, 2026
…it), decolua#2020 (cascade delete + token limits), decolua#2018 (dynamic model fetch)

PR decolua#2046: SSE non-JSON satir + duplicate [DONE] fix. Stream kararlilik.
PR decolua#2007: 5 guvenlik yamasi (API key leak, proxy URL validation, XSS, MITM race, lock file).
PR decolua#2020: Provider silinince model alias cascade delete + custom model token limit.
PR decolua#2018: Custom provider'dan model listesi dinamik cekme.

+ onceki: betterSqliteAdapter transaction fix (createProviderConnection undefined hatasi).
@hamsa0x7 hamsa0x7 closed this Jun 25, 2026
@hamsa0x7
hamsa0x7 deleted the fix/security-audit-001-018 branch June 25, 2026 14:33
@hamsa0x7
hamsa0x7 restored the fix/security-audit-001-018 branch June 25, 2026 14:37
@hamsa0x7 hamsa0x7 reopened this Jun 25, 2026
@decolua

decolua commented Jun 26, 2026

Copy link
Copy Markdown
Owner

Thanks @hamsa0x7! Reviewed all 5 security fixes — API key masking, proxy URL validation, OAuth XSS escaping, and the two MITM race/lock fixes. Verified no impact on existing UI or user data. Merged into master. Appreciate the thorough audit + tests.

@decolua decolua closed this Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants