security: harden command exec, IPC, deep-link, cookies, and persistence #2
Reference in New Issue
Block a user
Delete Branch "security/audit-hardening"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Seven-tier security audit of the main process, each finding fixed with a
regression test. Typecheck (node + web) clean; unit tests 106 -> 140.
(blocks arbitrary-binary-install RCE); gate per-download extraArgs behind
the customCommandEnabled consent flag in main (blocks --exec RCE); resolve
taskkill/schtasks by absolute System32 path; validate per-download
outputDir; normalize the URL in assertHttpUrl and use it at every spawn.
('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the
untrusted id in entryUrl; catch reserved device names with extensions in
sanitizeDirSegment.
normalize deep-link URLs via assertHttpUrl.
URLs (recursively) and deny all web permissions on its session.
aerofetch:// scheme case-insensitively.
Bluetooth permissions on the app window.
youtube.com feed URLs (SSRF guard); complete isValidSource validation.
Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com
Seven-tier security audit of the main process, each finding fixed with a regression test. Typecheck (node + web) clean; unit tests 106 -> 140. - Tier 1 (command exec/argv): allowlist the yt-dlp --update-to channel (blocks arbitrary-binary-install RCE); gate per-download extraArgs behind the customCommandEnabled consent flag in main (blocks --exec RCE); resolve taskkill/schtasks by absolute System32 path; validate per-download outputDir; normalize the URL in assertHttpUrl and use it at every spawn. - Tier 2 (input validation): fix isSafeFilenameTemplate drive-relative ('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the untrusted id in entryUrl; catch reserved device names with extensions in sanitizeDirSegment. - Tier 3 (fs/backup): drop malformed template rows in importBackup; normalize deep-link URLs via assertHttpUrl. - Tier 4 (cookies): confine the sign-in window's navigations/popups to web URLs (recursively) and deny all web permissions on its session. - Tier 5 (deep-link/argv): bound the .url file read to 64 KB; match the aerofetch:// scheme case-insensitively. - Tier 6 (Electron window): deny camera/mic/geolocation/USB/HID/serial/ Bluetooth permissions on the app window. - Tier 7 (network/persistence): restrict the watched-source RSS fetch to youtube.com feed URLs (SSRF guard); complete isValidSource validation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>