mirror of
https://github.com/Terncode/pixel.horse.git
synced 2026-09-24 21:55:52 +02:00
Security: Don't allow default secret/token config parameters (#80)
This commit is contained in:
@@ -181,6 +181,16 @@ Add `config.json` file in root directory with following content. You can use `co
|
||||
}
|
||||
```
|
||||
|
||||
### NOTE!
|
||||
|
||||
You **MUST** provide **unique**, **random** values for the `secret` and `token` fields of your config. It is **extremely dangerous** to leave these as default, as these values serve as authentication tokens for internal APIs and session cookies.
|
||||
|
||||
To generate new values for these parameters, you can use the following command:
|
||||
|
||||
```bash
|
||||
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
|
||||
```
|
||||
|
||||
## Running
|
||||
|
||||
### Your first build
|
||||
|
||||
@@ -7,8 +7,8 @@
|
||||
"host": "http://localhost:8090/",
|
||||
"local": "localhost:8090",
|
||||
"adminLocal": "localhost:8091",
|
||||
"secret": "gfhfdshtrdhgedryhe4t3y5uwjthr",
|
||||
"token": "sdlfgihsdor8ghor8dgdrgdegrdg",
|
||||
"secret": "<some_random_string_here>",
|
||||
"token": "<some_random_string_here>",
|
||||
"db": "mongodb://<username>:<password>@localhost:27017/<database_name>",
|
||||
"oauth": {
|
||||
"google": {
|
||||
|
||||
@@ -57,6 +57,36 @@ export const args = argv as AppArgs;
|
||||
export const { version, description }: AppPackage = require('../../../package.json');
|
||||
export const config: AppConfig = require('../../../config.json');
|
||||
|
||||
if (!DEVELOPMENT && !TESTS &&
|
||||
(!config.secret || !config.token
|
||||
|| config.secret.length < 16
|
||||
|| config.token.length < 16
|
||||
|| config.secret === config.token
|
||||
|| config.secret === 'gfhfdshtrdhgedryhe4t3y5uwjthr'
|
||||
|| config.token === 'sdlfgihsdor8ghor8dgdrgdegrdg'
|
||||
|| config.secret === '<some_random_string_here>'
|
||||
|| config.token === '<some_random_string_here>')) {
|
||||
console.error(
|
||||
`
|
||||
================================================================================
|
||||
WARNING! WARNING! WARNING!
|
||||
|
||||
Your config parameters token and secret appear to be insecure!
|
||||
This is **VERY** insecure, as these values serve as authentication tokens for
|
||||
internal APIs and session cookies. You **must** change these values in order to
|
||||
prevent potential exploits.
|
||||
|
||||
To generate new values for these parameters, you can use the following command:
|
||||
node -e "console.log(require('crypto').randomBytes(64).toString('base64'))"
|
||||
|
||||
Exiting here, as the security of your application cannot be guaranteed...
|
||||
================================================================================
|
||||
`
|
||||
);
|
||||
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
const loginServer: ServerConfig = { id: 'login', filter: false, port: config.port } as any;
|
||||
const adminServer: ServerConfig = { id: 'admin', filter: false, port: config.adminPort || config.port } as any;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user