fix(security): python-jose CVE-2024-33663 durch pyjwt ersetzt, Deps gepinnt
- security.py/dependencies.py/auth.py: jose -> pyjwt (unmaintained, Algorithm-Confusion-CVE). API-kompatibel (jwt.encode/decode gleich). - requirements.txt: alle Versionen gepinnt (waren >=, jetzt == anhand aktueller 137-Installation) fuer reproduzierbare Deploys. - nginx.conf: /docs + /openapi.json nur noch aus LAN erreichbar (waren oeffentlich, API-Struktur-Leak). fail2ban auf 137+164 installiert (sshd + nginx-badbots + timemaster-auth Jails), Configs nicht im Repo (Server-only, /etc/fail2ban/). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LTxkZEUdfgMxZvHPiZJ8bV
This commit is contained in:
+10
-1
@@ -30,8 +30,13 @@ server {
|
||||
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none';" always;
|
||||
}
|
||||
|
||||
# FastAPI Docs (nur in dev aktiv)
|
||||
# FastAPI Docs – nur aus internem LAN erreichbar (API-Struktur sonst für
|
||||
# Angreifer sichtbar). LAN-Bereich ggf. an tatsächliches Subnetz anpassen.
|
||||
location /docs {
|
||||
allow 192.168.1.0/24;
|
||||
allow 127.0.0.1;
|
||||
deny all;
|
||||
|
||||
proxy_pass http://127.0.0.1:8000/docs;
|
||||
|
||||
# Security Headers
|
||||
@@ -44,6 +49,10 @@ server {
|
||||
}
|
||||
|
||||
location /openapi.json {
|
||||
allow 192.168.1.0/24;
|
||||
allow 127.0.0.1;
|
||||
deny all;
|
||||
|
||||
proxy_pass http://127.0.0.1:8000/openapi.json;
|
||||
|
||||
# Security Headers
|
||||
|
||||
Reference in New Issue
Block a user