Skip to content

Close out review findings: path traversal, redirects, secrets, timeouts, DB reconnect, and doc accuracy - #73

Merged
michielbdejong merged 1 commit into
mainfrom
claude/serene-thompson-lj59qa
Sep 16, 2026
Merged

michielbdejong merged 1 commit into
mainfrom
claude/serene-thompson-lj59qa

Conversation

@michielbdejong

Copy link
Copy Markdown
Contributor

Summary

Works through the 20 open review-finding issues (#48–#66, #72). All P1 and P2 issues with a real code or doc fix are addressed below; #59 and #72 are closed as already resolved on main (no code change needed — see notes).

P1 (security)

P2 (code)

P2 (docs)

Also fixes 3 pre-existing clippy::nonminimal_bool findings (identity.rs, providers.rs) surfaced by the current toolchain — needed to keep cargo clippy --all-targets --all-features -- -D warnings green for this PR's CI run.

Test plan

  • cargo fmt --all -- --check
  • cargo clippy --all-targets --all-features -- -D warnings
  • cargo test (91 passed)
  • cargo test -- --include-ignored against a local PostgreSQL instance and live network (111 passed), including the new reconnect, e2e forwarding, and default-catalog-pin tests
  • CI will additionally run the ignored PostgreSQL tests automatically

Fixes #48, #49, #50, #51, #52, #53, #54, #55, #56, #57, #58, #59, #60, #61, #62, #63, #64, #65, #66, #72

🤖 Generated with Claude Code

https://claude.ai/code/session_013UCidwbyQwtBvFwHyreivf


Generated by Claude Code

…ts, DB reconnect, and doc accuracy

P1 security fixes:
- Reject `.`/`..` path segments before catalog validation so a traversal
  path cannot normalize to a different upstream path than the one
  authorized (#48).
- Disable automatic redirects and add connect/read timeouts on the shared
  HTTP client, so a redirect can't escape catalog validation and a slow
  upstream can't hold a request open indefinitely (#49, #51).
- Reject empty required config values (SERVER_SECRET, DATABASE_URL, etc.)
  instead of accepting them, and treat an empty SESSION_SECRET as unset
  rather than hashing it into a reproducible key (#50).
- Stream and bound the upstream response body incrementally instead of
  buffering the whole thing before checking the size limit (#51).

P2 fixes:
- Add a bounded OpenAPI request validator (required query parameters,
  enum values, request body presence/content-type) wired into the proxy
  forwarding path (#52).
- Give `Security` a self-healing PostgreSQL connection: a dropped
  connection is retried with backoff and the shared client is swapped in
  automatically, with a new `/healthz` readiness endpoint (#53).
- Opportunistically clean up expired `oauth_states` and `connection_codes`
  rows (matching the existing pattern for other tables), plus supporting
  indexes (#54).
- Forward `ETag`, `X-Total-Count`, and `X-Next-Page` response headers to
  match what CORS already exposes (#55).
- Add end-to-end coverage of `forward()`: credential refresh, upstream
  call, header forwarding, and connection-code rotation (#56).
- Add regression coverage of the OAuth profiles catalog against the
  application's actual default `CATALOG_PATH` pin, not just a separately
  identified revision (#57).
- Correct README/SECURITY.md/.env.example inaccuracies: the no-database
  framing, the removed "token storage unimplemented" claim, browser
  handoff vs. legacy proxy credentials, the nonexistent GitHub pagination
  rewrite, .env auto-loading, missing DATABASE_URL/ENCRYPTION_KEY example
  values, the Spotify client auth method, and the stale five-minute proxy
  credential expiry (#58, #60, #61, #62, #63, #64, #65).
- Replace hardcoded "Atomic Data Hub" consent wording with generic
  destination wording, and drop the obsolete two-provider description now
  that OAuth is fully catalog-driven (#66).

Also fixes 3 pre-existing clippy findings (identity.rs, providers.rs)
surfaced by the current toolchain, needed to keep `-D warnings` green.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_013UCidwbyQwtBvFwHyreivf
@michielbdejong
michielbdejong merged commit 6f42f7e into main Sep 16, 2026
1 check passed
This was referenced Sep 16, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[P1] Normalize proxy paths before checking the catalog allowlist

2 participants