fix: resolve all remaining audit failures across rust, svelte, and java
This commit is contained in:
1 parent
bc12a25a01
commit
590178e41a
35 files changed
+958
-300
No files matched your search
@@ -60,6 +60,7 @@ fn clip(s: &str, max: usize) -> String {
|
||||
|
||||
#[derive(Debug, Clone, sqlx::FromRow, Serialize)]
|
||||
pub struct ServerRow {
|
||||
pub instance_id: String,
|
||||
pub id: i64,
|
||||
pub name: String,
|
||||
#[serde(skip)]
|
||||
@@ -232,43 +233,9 @@ fn canonical_ip(ip: std::net::IpAddr) -> std::net::IpAddr {
|
||||
}
|
||||
}
|
||||
|
||||
fn is_private_or_local(ip: &std::net::IpAddr) -> bool {
|
||||
match canonical_ip(*ip) {
|
||||
std::net::IpAddr::V4(v4) => v4.is_loopback() || v4.is_private() || v4.is_link_local(),
|
||||
std::net::IpAddr::V6(v6) => v6.is_loopback(),
|
||||
}
|
||||
}
|
||||
|
||||
pub fn ips_match(sess_str: &str, req_str: &str) -> bool {
|
||||
let s = sess_str.trim();
|
||||
let r = req_str.trim();
|
||||
if s.eq_ignore_ascii_case(r) {
|
||||
return true;
|
||||
}
|
||||
let (Ok(ip_a), Ok(ip_b)) = (s.parse::<std::net::IpAddr>(), r.parse::<std::net::IpAddr>()) else {
|
||||
return false;
|
||||
};
|
||||
let a = canonical_ip(ip_a);
|
||||
let b = canonical_ip(ip_b);
|
||||
if a == b {
|
||||
return true;
|
||||
}
|
||||
if a.is_loopback() && b.is_loopback() {
|
||||
return true;
|
||||
}
|
||||
if is_private_or_local(&a) && is_private_or_local(&b) {
|
||||
return true;
|
||||
}
|
||||
if is_private_or_local(&a) {
|
||||
return true;
|
||||
}
|
||||
match (a, b) {
|
||||
(std::net::IpAddr::V4(v4_a), std::net::IpAddr::V4(v4_b)) => {
|
||||
v4_a.octets()[0..3] == v4_b.octets()[0..3]
|
||||
}
|
||||
(std::net::IpAddr::V6(v6_a), std::net::IpAddr::V6(v6_b)) => {
|
||||
v6_a.segments()[0..4] == v6_b.segments()[0..4]
|
||||
}
|
||||
match (sess_str.trim().parse::<std::net::IpAddr>(), req_str.trim().parse::<std::net::IpAddr>()) {
|
||||
(Ok(a), Ok(b)) => canonical_ip(a) == canonical_ip(b),
|
||||
_ => false,
|
||||
}
|
||||
}
|
||||
@@ -553,6 +520,10 @@ pub async fn sync(GameServer(server): GameServer, State(state): State<AppState>,
|
||||
}
|
||||
}
|
||||
}
|
||||
let mut rewarded = std::collections::HashSet::new();
|
||||
for d in &s.stats { if let Some(uuid) = dashed(&d.uuid) { rewarded.insert(uuid); } }
|
||||
for e in &s.events { if let Some(uuid) = e.uuid.as_deref().and_then(dashed) { rewarded.insert(uuid); } }
|
||||
for uuid in rewarded { crate::routes::leveling::grant_rewards(&mut tx, &uuid, &at_now).await?; }
|
||||
tx.commit().await?;
|
||||
|
||||
// Occasional housekeeping.
|
||||
@@ -786,7 +757,7 @@ async fn update_progression_for_delta(
|
||||
.fetch_optional(&mut **tx)
|
||||
.await?;
|
||||
|
||||
if let Some(lvl) = global_level {
|
||||
if let Some(lvl) = global_level.filter(|_| achievements_on) {
|
||||
let lvl_ach: Vec<String> = sqlx::query_scalar(
|
||||
"SELECT id FROM achievements WHERE requirement_type = 'level' AND requirement_value <= ?",
|
||||
)
|
||||
@@ -820,6 +791,8 @@ pub async fn list(_: AdminUser, State(state): State<AppState>) -> AppResult<Json
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct ServerInput {
|
||||
#[serde(default)]
|
||||
instance_id: String,
|
||||
name: String,
|
||||
#[serde(default = "default_access")]
|
||||
access: String,
|
||||
@@ -860,7 +833,7 @@ pub async fn create(_: AdminUser, State(state): State<AppState>, Json(input): Js
|
||||
input.validate()?;
|
||||
let token = new_token();
|
||||
let id: i64 = sqlx::query_scalar(
|
||||
"INSERT INTO game_servers (name, token_hash, token_hint, access, allowed_groups, require_launcher, created_at) VALUES (?, ?, ?, ?, ?, ?, ?) RETURNING id",
|
||||
"INSERT INTO game_servers (name, token_hash, token_hint, access, allowed_groups, require_launcher, created_at, instance_id) VALUES (?, ?, ?, ?, ?, ?, ?, ?) RETURNING id",
|
||||
)
|
||||
.bind(input.name.trim())
|
||||
.bind(hash_token(&token))
|
||||
@@ -869,6 +842,7 @@ pub async fn create(_: AdminUser, State(state): State<AppState>, Json(input): Js
|
||||
.bind(serde_json::to_string(&input.allowed_groups).unwrap_or_else(|_| "[]".into()))
|
||||
.bind(input.require_launcher)
|
||||
.bind(now())
|
||||
.bind(&input.instance_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
let server = get_server(&state, id).await?;
|
||||
@@ -883,11 +857,12 @@ pub async fn update(
|
||||
) -> AppResult<Json<ServerView>> {
|
||||
input.validate()?;
|
||||
get_server(&state, id).await?;
|
||||
sqlx::query("UPDATE game_servers SET name = ?, access = ?, allowed_groups = ?, require_launcher = ? WHERE id = ?")
|
||||
sqlx::query("UPDATE game_servers SET name = ?, access = ?, allowed_groups = ?, require_launcher = ?, instance_id = ? WHERE id = ?")
|
||||
.bind(input.name.trim())
|
||||
.bind(&input.access)
|
||||
.bind(serde_json::to_string(&input.allowed_groups).unwrap_or_else(|_| "[]".into()))
|
||||
.bind(input.require_launcher)
|
||||
.bind(&input.instance_id)
|
||||
.bind(id)
|
||||
.execute(&state.db)
|
||||
.await?;
|
||||
@@ -1070,6 +1045,7 @@ pub async fn public_servers(State(state): State<AppState>) -> AppResult<Json<Val
|
||||
json!({
|
||||
"id": s.id,
|
||||
"name": s.name,
|
||||
"instance_id": s.instance_id,
|
||||
"online": is_online,
|
||||
"players_online": if is_online { s.online_count } else { 0 },
|
||||
"players_max": s.max_players,
|
||||
@@ -1225,8 +1201,8 @@ mod tests {
|
||||
assert!(ips_match("203.0.113.9", "203.0.113.9"));
|
||||
|
||||
// Loopback IPv4 & IPv6
|
||||
assert!(ips_match("127.0.0.1", "::1"));
|
||||
assert!(ips_match("::1", "127.0.0.1"));
|
||||
assert!(!ips_match("127.0.0.1", "::1"));
|
||||
assert!(!ips_match("::1", "127.0.0.1"));
|
||||
assert!(ips_match("127.0.0.1", "127.0.0.1"));
|
||||
|
||||
// IPv4-mapped IPv6
|
||||
@@ -1234,11 +1210,11 @@ mod tests {
|
||||
assert!(ips_match("192.168.1.10", "::ffff:192.168.1.10"));
|
||||
|
||||
// Docker bridge / private gateway recorded
|
||||
assert!(ips_match("172.18.0.1", "192.168.1.50"));
|
||||
assert!(ips_match("10.0.0.1", "10.0.0.2"));
|
||||
assert!(!ips_match("172.18.0.1", "192.168.1.50"));
|
||||
assert!(!ips_match("10.0.0.1", "10.0.0.2"));
|
||||
|
||||
// Subnet /24 match
|
||||
assert!(ips_match("203.0.113.5", "203.0.113.9"));
|
||||
assert!(!ips_match("203.0.113.5", "203.0.113.9"));
|
||||
|
||||
// Different public networks do not match
|
||||
assert!(!ips_match("198.51.100.1", "203.0.113.9"));
|
||||
|
||||
Reference in new issue
Block a user