fix(security): python-jose CVE-2024-33663 durch pyjwt ersetzt, Deps gepinnt
- security.py/dependencies.py/auth.py: jose -> pyjwt (unmaintained, Algorithm-Confusion-CVE). API-kompatibel (jwt.encode/decode gleich). - requirements.txt: alle Versionen gepinnt (waren >=, jetzt == anhand aktueller 137-Installation) fuer reproduzierbare Deploys. - nginx.conf: /docs + /openapi.json nur noch aus LAN erreichbar (waren oeffentlich, API-Struktur-Leak). fail2ban auf 137+164 installiert (sshd + nginx-badbots + timemaster-auth Jails), Configs nicht im Repo (Server-only, /etc/fail2ban/). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LTxkZEUdfgMxZvHPiZJ8bV
This commit is contained in:
@@ -4,7 +4,8 @@ import secrets
|
||||
import hashlib
|
||||
|
||||
import bcrypt
|
||||
from jose import JWTError, jwt
|
||||
import jwt
|
||||
from jwt import PyJWTError as JWTError
|
||||
|
||||
from app.core.config import settings
|
||||
|
||||
|
||||
Reference in New Issue
Block a user