Security: Don't allow default secret/token config parameters (#80)

This commit is contained in:
Eliot Partridge
2019-09-07 01:59:42 -05:00
committed by GitHub
parent b9d50c2665
commit cba4e94da2
3 changed files with 42 additions and 2 deletions
+10
View File
@@ -181,6 +181,16 @@ Add `config.json` file in root directory with following content. You can use `co
} }
``` ```
### NOTE!
You **MUST** provide **unique**, **random** values for the `secret` and `token` fields of your config. It is **extremely dangerous** to leave these as default, as these values serve as authentication tokens for internal APIs and session cookies.
To generate new values for these parameters, you can use the following command:
```bash
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
```
## Running ## Running
### Your first build ### Your first build
+2 -2
View File
@@ -7,8 +7,8 @@
"host": "http://localhost:8090/", "host": "http://localhost:8090/",
"local": "localhost:8090", "local": "localhost:8090",
"adminLocal": "localhost:8091", "adminLocal": "localhost:8091",
"secret": "gfhfdshtrdhgedryhe4t3y5uwjthr", "secret": "<some_random_string_here>",
"token": "sdlfgihsdor8ghor8dgdrgdegrdg", "token": "<some_random_string_here>",
"db": "mongodb://<username>:<password>@localhost:27017/<database_name>", "db": "mongodb://<username>:<password>@localhost:27017/<database_name>",
"oauth": { "oauth": {
"google": { "google": {
+30
View File
@@ -57,6 +57,36 @@ export const args = argv as AppArgs;
export const { version, description }: AppPackage = require('../../../package.json'); export const { version, description }: AppPackage = require('../../../package.json');
export const config: AppConfig = require('../../../config.json'); export const config: AppConfig = require('../../../config.json');
if (!DEVELOPMENT && !TESTS &&
(!config.secret || !config.token
|| config.secret.length < 16
|| config.token.length < 16
|| config.secret === config.token
|| config.secret === 'gfhfdshtrdhgedryhe4t3y5uwjthr'
|| config.token === 'sdlfgihsdor8ghor8dgdrgdegrdg'
|| config.secret === '<some_random_string_here>'
|| config.token === '<some_random_string_here>')) {
console.error(
`
================================================================================
WARNING! WARNING! WARNING!
Your config parameters token and secret appear to be insecure!
This is **VERY** insecure, as these values serve as authentication tokens for
internal APIs and session cookies. You **must** change these values in order to
prevent potential exploits.
To generate new values for these parameters, you can use the following command:
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
Exiting here, as the security of your application cannot be guaranteed...
================================================================================
`
);
process.exit(1);
}
const loginServer: ServerConfig = { id: 'login', filter: false, port: config.port } as any; const loginServer: ServerConfig = { id: 'login', filter: false, port: config.port } as any;
const adminServer: ServerConfig = { id: 'admin', filter: false, port: config.adminPort || config.port } as any; const adminServer: ServerConfig = { id: 'admin', filter: false, port: config.adminPort || config.port } as any;