3536626a8a
Seven-tier security audit of the main process, each finding fixed with a
regression test. Typecheck (node + web) clean; unit tests 106 -> 140.
- Tier 1 (command exec/argv): allowlist the yt-dlp --update-to channel
(blocks arbitrary-binary-install RCE); gate per-download extraArgs behind
the customCommandEnabled consent flag in main (blocks --exec RCE); resolve
taskkill/schtasks by absolute System32 path; validate per-download
outputDir; normalize the URL in assertHttpUrl and use it at every spawn.
- Tier 2 (input validation): fix isSafeFilenameTemplate drive-relative
('C:foo') and Windows dotted-'..' traversal bypasses; percent-encode the
untrusted id in entryUrl; catch reserved device names with extensions in
sanitizeDirSegment.
- Tier 3 (fs/backup): drop malformed template rows in importBackup;
normalize deep-link URLs via assertHttpUrl.
- Tier 4 (cookies): confine the sign-in window's navigations/popups to web
URLs (recursively) and deny all web permissions on its session.
- Tier 5 (deep-link/argv): bound the .url file read to 64 KB; match the
aerofetch:// scheme case-insensitively.
- Tier 6 (Electron window): deny camera/mic/geolocation/USB/HID/serial/
Bluetooth permissions on the app window.
- Tier 7 (network/persistence): restrict the watched-source RSS fetch to
youtube.com feed URLs (SSRF guard); complete isValidSource validation.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
71 lines
2.7 KiB
TypeScript
71 lines
2.7 KiB
TypeScript
/**
|
|
* Windows Task Scheduler integration for the daily watched-source sync
|
|
* (ROADMAP-PINCHFLAT.md Phase J). Registers a task that launches AeroFetch with
|
|
* `--sync` once a day; the app then runs its startup sync of watched sources.
|
|
*
|
|
* NOTE: this is OS-level wiring and cannot be exercised in the Vite UI preview or
|
|
* the unit tests — like the `aerofetch://` protocol registration, it needs a real
|
|
* install + manual smoke test. `schtasks` is invoked via execFile (no shell), and
|
|
* the only interpolated value is the trusted `process.execPath`.
|
|
*/
|
|
|
|
import { execFile } from 'child_process'
|
|
import { getSystem32Path } from './binaries'
|
|
import type { ScheduledSyncStatus } from '@shared/ipc'
|
|
|
|
const TASK_NAME = 'AeroFetchDailySync'
|
|
/** The argv flag the scheduled task passes so startup knows it's a sync launch. */
|
|
export const SYNC_FLAG = '--sync'
|
|
|
|
function schtasks(args: string[]): Promise<{ code: number; stdout: string; stderr: string }> {
|
|
return new Promise((resolve) => {
|
|
// Resolve schtasks from System32 by absolute path, not the bare name, so a
|
|
// planted schtasks.exe on PATH / in the CWD can't be invoked instead. (audit F3)
|
|
execFile(getSystem32Path('schtasks.exe'), args, { windowsHide: true }, (err, stdout, stderr) => {
|
|
const code = err ? ((err as { code?: number }).code ?? 1) : 0
|
|
resolve({ code, stdout: String(stdout), stderr: String(stderr) })
|
|
})
|
|
})
|
|
}
|
|
|
|
/** True when this launch came from the scheduled task (argv carries --sync). */
|
|
export function isSyncLaunch(argv: string[]): boolean {
|
|
return argv.includes(SYNC_FLAG)
|
|
}
|
|
|
|
/** Whether the daily-sync scheduled task is currently registered. */
|
|
export async function getScheduledSync(): Promise<ScheduledSyncStatus> {
|
|
const r = await schtasks(['/Query', '/TN', TASK_NAME])
|
|
return { enabled: r.code === 0 }
|
|
}
|
|
|
|
/**
|
|
* Register or remove the daily-sync scheduled task. Creating runs AeroFetch with
|
|
* `--sync` every day at 09:00 (overwriting any prior task of the same name).
|
|
*/
|
|
export async function setScheduledSync(enabled: boolean): Promise<ScheduledSyncStatus> {
|
|
if (enabled) {
|
|
const tr = `"${process.execPath}" ${SYNC_FLAG}`
|
|
const r = await schtasks([
|
|
'/Create',
|
|
'/F',
|
|
'/SC',
|
|
'DAILY',
|
|
'/ST',
|
|
'09:00',
|
|
'/TN',
|
|
TASK_NAME,
|
|
'/TR',
|
|
tr
|
|
])
|
|
return {
|
|
enabled: r.code === 0,
|
|
error: r.code === 0 ? undefined : r.stderr.trim() || 'Could not create the scheduled task.'
|
|
}
|
|
}
|
|
const r = await schtasks(['/Delete', '/F', '/TN', TASK_NAME])
|
|
// A missing task ("cannot find") is success for our purposes — it's already gone.
|
|
const gone = r.code === 0 || /cannot find|does not exist/i.test(r.stderr)
|
|
return { enabled: gone ? false : true, error: gone ? undefined : r.stderr.trim() }
|
|
}
|