fix(security): python-jose CVE-2024-33663 durch pyjwt ersetzt, Deps gepinnt

- security.py/dependencies.py/auth.py: jose -> pyjwt (unmaintained,
  Algorithm-Confusion-CVE). API-kompatibel (jwt.encode/decode gleich).
- requirements.txt: alle Versionen gepinnt (waren >=, jetzt == anhand
  aktueller 137-Installation) fuer reproduzierbare Deploys.
- nginx.conf: /docs + /openapi.json nur noch aus LAN erreichbar (waren
  oeffentlich, API-Struktur-Leak).

fail2ban auf 137+164 installiert (sshd + nginx-badbots + timemaster-auth
Jails), Configs nicht im Repo (Server-only, /etc/fail2ban/).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LTxkZEUdfgMxZvHPiZJ8bV
This commit is contained in:
2026-08-05 19:10:28 +02:00
co-authored by Claude Sonnet 5
parent 7c24887ec1
commit 2046f6475b
6 changed files with 79 additions and 33 deletions
+10 -1
View File
@@ -30,8 +30,13 @@ server {
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none';" always;
}
# FastAPI Docs (nur in dev aktiv)
# FastAPI Docs nur aus internem LAN erreichbar (API-Struktur sonst für
# Angreifer sichtbar). LAN-Bereich ggf. an tatsächliches Subnetz anpassen.
location /docs {
allow 192.168.1.0/24;
allow 127.0.0.1;
deny all;
proxy_pass http://127.0.0.1:8000/docs;
# Security Headers
@@ -44,6 +49,10 @@ server {
}
location /openapi.json {
allow 192.168.1.0/24;
allow 127.0.0.1;
deny all;
proxy_pass http://127.0.0.1:8000/openapi.json;
# Security Headers