[DC-026] routes/auth/sso-gate.js — fix sessionDuration='never' bypass Both /auth/gate/:serviceId and /auth/app-token/:serviceId had a session check gated on `sessionDuration !== 'never'`. An admin setting TOTP to never-expire accidentally created an authentication-free path to credential injection (Basic Auth, X-Api-Key, Plex/Prowlarr tokens). Patched: session required whenever TOTP is enabled, period. Added 8 regression tests. [DC-027] src/utilities/middleware.js — rate limit /auth/* New authLimiter (20 req / 15 min) on /auth/keys, /auth/jwt, /auth/gate, /auth/app-token. These endpoints expose credentials and were unmetered. Without this, an attacker with a guessed session cookie could burn through every credential-touching endpoint. Added 5 tests. [DC-028] src/security/audit-logger.js — log credential exposures /auth/gate and /auth/app-token were in SKIP_PATHS, silently dropping every credential-exposure event from the audit log. Combined with the GET-skip rule, NONE of these events were being recorded. Now logged with named actions: auth.credential-injection, auth.app-token-issue, auth.api-key-generate, auth.api-key-revoke, auth.jwt-mint. Added 9 tests. [start.sh] Disable in-container self-updater DASHCADDY_UPDATE_ENABLED=false. Without this, the container kept writing trigger.json every 30 min and clobbered my in-progress host edits. The path unit on the host is still active for manual triggers, but the container won't auto-update itself — only when an admin clicks the update button or a new release is manually published. [package.json] Bump to 1.14.7 Test results: 1066/1066 passing across 39 suites (added 22 new tests).
50 lines
1.6 KiB
JSON
50 lines
1.6 KiB
JSON
{
|
|
"name": "dashcaddy-api",
|
|
"version": "1.14.7",
|
|
"description": "DashCaddy API server - Dashboard backend for Docker, Caddy & DNS management",
|
|
"main": "server.js",
|
|
"scripts": {
|
|
"start": "node server.js",
|
|
"test": "jest",
|
|
"test:watch": "jest --watch",
|
|
"test:coverage": "jest --coverage",
|
|
"test:ci": "jest --ci --coverage --maxWorkers=2 --forceExit",
|
|
"test:unit": "jest --testPathPattern=__tests__/(?!routes|integration) --no-coverage",
|
|
"test:routes": "jest --testPathPattern=__tests__/routes --no-coverage",
|
|
"test:security": "jest --testPathPattern=(crypto-utils|credential-manager|csrf-protection|auth-manager|input-validator|backup-manager) --no-coverage",
|
|
"test:changed": "jest --onlyChanged --no-coverage",
|
|
"test:debug": "node --inspect-brk node_modules/jest/bin/jest.js --runInBand --no-coverage",
|
|
"lint": "eslint .",
|
|
"lint:fix": "eslint . --fix",
|
|
"format": "prettier --write '**/*.{js,json,md}'"
|
|
},
|
|
"dependencies": {
|
|
"compression": "^1.8.1",
|
|
"cors": "^2.8.6",
|
|
"dockerode": "^4.0.9",
|
|
"dropbox": "^10.34.0",
|
|
"express": "^4.22.1",
|
|
"express-rate-limit": "^7.5.1",
|
|
"helmet": "^8.1.0",
|
|
"js-yaml": "^4.1.1",
|
|
"jsonwebtoken": "^9.0.2",
|
|
"lru-cache": "^10.4.3",
|
|
"nodemailer": "^8.0.4",
|
|
"otplib": "^12.0.1",
|
|
"png-to-ico": "^2.1.8",
|
|
"proper-lockfile": "^4.1.2",
|
|
"qrcode": "^1.5.3",
|
|
"sharp": "^0.33.5",
|
|
"ssh2-sftp-client": "^11.0.0",
|
|
"validator": "^13.11.0",
|
|
"webdav": "^5.7.1",
|
|
"ws": "^8.20.0"
|
|
},
|
|
"devDependencies": {
|
|
"eslint": "^8.57.1",
|
|
"jest": "^29.7.0",
|
|
"prettier": "^3.8.1",
|
|
"supertest": "^6.3.4"
|
|
}
|
|
}
|