security: harden command exec, IPC, deep-link, cookies, and persistence #2

Merged
debont80 merged 1 commits from security/audit-hardening into main 2026-06-24 08:06:55 -04:00
Owner

Seven-tier security audit of the main process, each finding fixed with a
regression test. Typecheck (node + web) clean; unit tests 106 -> 140.

  • Tier 1 (command exec/argv): allowlist the yt-dlp --update-to channel
    (blocks arbitrary-binary-install RCE); gate per-download extraArgs behind
    the customCommandEnabled consent flag in main (blocks --exec RCE); resolve
    taskkill/schtasks by absolute System32 path; validate per-download
    outputDir; normalize the URL in assertHttpUrl and use it at every spawn.
  • Tier 2 (input validation): fix isSafeFilenameTemplate drive-relative
    ('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the
    untrusted id in entryUrl; catch reserved device names with extensions in
    sanitizeDirSegment.
  • Tier 3 (fs/backup): drop malformed template rows in importBackup;
    normalize deep-link URLs via assertHttpUrl.
  • Tier 4 (cookies): confine the sign-in window's navigations/popups to web
    URLs (recursively) and deny all web permissions on its session.
  • Tier 5 (deep-link/argv): bound the .url file read to 64 KB; match the
    aerofetch:// scheme case-insensitively.
  • Tier 6 (Electron window): deny camera/mic/geolocation/USB/HID/serial/
    Bluetooth permissions on the app window.
  • Tier 7 (network/persistence): restrict the watched-source RSS fetch to
    youtube.com feed URLs (SSRF guard); complete isValidSource validation.

Co-Authored-By: Claude Opus 4.8 noreply@anthropic.com

Seven-tier security audit of the main process, each finding fixed with a regression test. Typecheck (node + web) clean; unit tests 106 -> 140. - Tier 1 (command exec/argv): allowlist the yt-dlp --update-to channel (blocks arbitrary-binary-install RCE); gate per-download extraArgs behind the customCommandEnabled consent flag in main (blocks --exec RCE); resolve taskkill/schtasks by absolute System32 path; validate per-download outputDir; normalize the URL in assertHttpUrl and use it at every spawn. - Tier 2 (input validation): fix isSafeFilenameTemplate drive-relative ('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the untrusted id in entryUrl; catch reserved device names with extensions in sanitizeDirSegment. - Tier 3 (fs/backup): drop malformed template rows in importBackup; normalize deep-link URLs via assertHttpUrl. - Tier 4 (cookies): confine the sign-in window's navigations/popups to web URLs (recursively) and deny all web permissions on its session. - Tier 5 (deep-link/argv): bound the .url file read to 64 KB; match the aerofetch:// scheme case-insensitively. - Tier 6 (Electron window): deny camera/mic/geolocation/USB/HID/serial/ Bluetooth permissions on the app window. - Tier 7 (network/persistence): restrict the watched-source RSS fetch to youtube.com feed URLs (SSRF guard); complete isValidSource validation. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
debont80 added 1 commit 2026-06-24 08:06:45 -04:00
Seven-tier security audit of the main process, each finding fixed with a
regression test. Typecheck (node + web) clean; unit tests 106 -> 140.

- Tier 1 (command exec/argv): allowlist the yt-dlp --update-to channel
  (blocks arbitrary-binary-install RCE); gate per-download extraArgs behind
  the customCommandEnabled consent flag in main (blocks --exec RCE); resolve
  taskkill/schtasks by absolute System32 path; validate per-download
  outputDir; normalize the URL in assertHttpUrl and use it at every spawn.
- Tier 2 (input validation): fix isSafeFilenameTemplate drive-relative
  ('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the
  untrusted id in entryUrl; catch reserved device names with extensions in
  sanitizeDirSegment.
- Tier 3 (fs/backup): drop malformed template rows in importBackup;
  normalize deep-link URLs via assertHttpUrl.
- Tier 4 (cookies): confine the sign-in window's navigations/popups to web
  URLs (recursively) and deny all web permissions on its session.
- Tier 5 (deep-link/argv): bound the .url file read to 64 KB; match the
  aerofetch:// scheme case-insensitively.
- Tier 6 (Electron window): deny camera/mic/geolocation/USB/HID/serial/
  Bluetooth permissions on the app window.
- Tier 7 (network/persistence): restrict the watched-source RSS fetch to
  youtube.com feed URLs (SSRF guard); complete isValidSource validation.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
debont80 merged commit 76098c6928 into main 2026-06-24 08:06:55 -04:00
Sign in to join this conversation.
No Reviewers
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: debont80/AeroFetch#2