fix(security): python-jose CVE-2024-33663 durch pyjwt ersetzt, Deps gepinnt
Security Audit / Python Dependency Audit (push) Has been cancelled
Security Audit / Node.js Dependency Audit (push) Has been cancelled

- security.py/dependencies.py/auth.py: jose -> pyjwt (unmaintained,
  Algorithm-Confusion-CVE). API-kompatibel (jwt.encode/decode gleich).
- requirements.txt: alle Versionen gepinnt (waren >=, jetzt == anhand
  aktueller 137-Installation) fuer reproduzierbare Deploys.
- nginx.conf: /docs + /openapi.json nur noch aus LAN erreichbar (waren
  oeffentlich, API-Struktur-Leak).

fail2ban auf 137+164 installiert (sshd + nginx-badbots + timemaster-auth
Jails), Configs nicht im Repo (Server-only, /etc/fail2ban/).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LTxkZEUdfgMxZvHPiZJ8bV
This commit is contained in:
2026-08-05 19:10:28 +02:00
co-authored by Claude Sonnet 5
parent 803e888638
commit edb727e09a
6 changed files with 79 additions and 33 deletions
+36
View File
@@ -2686,3 +2686,39 @@ Keine Commits in dieser Session.
- frontend/src/types/hoursPayout.ts | 7 ++ - frontend/src/types/hoursPayout.ts | 7 ++
--- ---
## 2026-08-05 18:56 18:57 (0m)
**Beschreibung:** Claude Code Session
**Projekt:** timemaster
### Commits
- 803e888 fix(hours_payouts): RLS-Bypass-Falle bei mid-request commit
### Geänderte Dateien
- DEVLOG.md | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++
- backend/app/routers/hours_payouts.py | 22 ++++++++++++----------
---
## 2026-08-05 18:57 18:57 (0m)
**Beschreibung:** Claude Code Session
**Projekt:** timemaster
### Commits
Keine Commits in dieser Session.
### Geänderte Dateien
- DEVLOG.md | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++
- backend/app/routers/hours_payouts.py | 22 ++++++++++++----------
---
## 2026-08-05 18:58 18:58 (0m)
**Beschreibung:** Claude Code Session
**Projekt:** timemaster
### Commits
Keine Commits in dieser Session.
### Geänderte Dateien
- DEVLOG.md | 50 ++++++++++++++++++++++++++++++++++++++++++++++++++
- backend/app/routers/hours_payouts.py | 22 ++++++++++++----------
---
+1 -1
View File
@@ -4,7 +4,7 @@ from uuid import UUID
from fastapi import Depends, HTTPException, Request, status from fastapi import Depends, HTTPException, Request, status
from fastapi.security import HTTPAuthorizationCredentials, HTTPBearer from fastapi.security import HTTPAuthorizationCredentials, HTTPBearer
from jose import JWTError from jwt import PyJWTError as JWTError
from sqlalchemy import text from sqlalchemy import text
from sqlalchemy.ext.asyncio import AsyncSession from sqlalchemy.ext.asyncio import AsyncSession
+2 -1
View File
@@ -4,7 +4,8 @@ import secrets
import hashlib import hashlib
import bcrypt import bcrypt
from jose import JWTError, jwt import jwt
from jwt import PyJWTError as JWTError
from app.core.config import settings from app.core.config import settings
+1 -1
View File
@@ -306,7 +306,7 @@ async def totp_login(
from app.core.config import settings from app.core.config import settings
from app.core.security import decode_partial_token from app.core.security import decode_partial_token
from app.models.user import User from app.models.user import User
from jose import JWTError from jwt import PyJWTError as JWTError
try: try:
user_id = decode_partial_token(data.partial_token) user_id = decode_partial_token(data.partial_token)
+29 -29
View File
@@ -1,29 +1,29 @@
fastapi>=0.110.0 fastapi==0.135.2
uvicorn[standard]>=0.27.0 uvicorn[standard]==0.42.0
sqlalchemy[asyncio]>=2.0.0 sqlalchemy[asyncio]==2.0.48
asyncpg>=0.29.0 asyncpg==0.31.0
alembic>=1.13.0 alembic==1.18.4
pydantic[email]>=2.6.0 pydantic[email]==2.12.5
pydantic-settings>=2.2.0 pydantic-settings==2.13.1
python-jose[cryptography]>=3.3.0 pyjwt[crypto]==2.10.1
bcrypt>=4.0.0 bcrypt==5.0.0
openpyxl>=3.1.0 openpyxl==3.1.5
ldap3>=2.9.0 ldap3==2.9.1
cryptography>=42.0.0 cryptography==46.0.6
python-multipart>=0.0.9 python-multipart==0.0.22
slowapi>=0.1.9 slowapi==0.1.9
limits>=3.6.0 limits==5.8.0
redis>=5.0.0 redis==7.4.0
resend>=0.7.0 resend==2.26.0
python-dateutil>=2.9.0 python-dateutil==2.9.0.post0
pyotp>=2.9.0 pyotp==2.9.0
httpx>=0.27.0 httpx==0.28.1
icalendar>=5.0.0 icalendar==7.0.3
pytest>=8.0.0 pytest==9.0.2
pytest-asyncio>=0.23.0 pytest-asyncio==1.3.0
pytest-httpx>=0.30.0 pytest-httpx==0.36.0
aiosqlite>=0.20.0 aiosqlite==0.22.1
weasyprint>=61.0 weasyprint==68.1
typer>=0.12.0 typer==0.25.1
rich>=13.7.0 rich==15.0.0
apscheduler>=3.10.0 apscheduler==3.11.2
+10 -1
View File
@@ -30,8 +30,13 @@ server {
add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none';" always; add_header Content-Security-Policy "default-src 'self'; script-src 'self' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; img-src 'self' data: blob:; font-src 'self' data:; connect-src 'self'; frame-ancestors 'none';" always;
} }
# FastAPI Docs (nur in dev aktiv) # FastAPI Docs nur aus internem LAN erreichbar (API-Struktur sonst für
# Angreifer sichtbar). LAN-Bereich ggf. an tatsächliches Subnetz anpassen.
location /docs { location /docs {
allow 192.168.1.0/24;
allow 127.0.0.1;
deny all;
proxy_pass http://127.0.0.1:8000/docs; proxy_pass http://127.0.0.1:8000/docs;
# Security Headers # Security Headers
@@ -44,6 +49,10 @@ server {
} }
location /openapi.json { location /openapi.json {
allow 192.168.1.0/24;
allow 127.0.0.1;
deny all;
proxy_pass http://127.0.0.1:8000/openapi.json; proxy_pass http://127.0.0.1:8000/openapi.json;
# Security Headers # Security Headers