aprs.me/.kiro/steering/tech.md
Graham McIntire 94f3a62539
Add comprehensive input sanitization for coordinate parsing
Security improvements:
- Added sanitize_numeric_string to remove dangerous characters
- Limited input string length to prevent DoS attacks (20 chars for numbers)
- Added is_finite? checks to prevent infinity/NaN values
- Validate coordinate ranges (lat: -90 to 90, lng: -180 to 180)
- Added safe_parse_coordinate with proper validation
- Updated to_float in EncodingUtils with security validations
- Protected against integer overflow in coordinate conversions
- Added sanitize_path_string for APRS path validation

All coordinate inputs from users are now:
1. Sanitized to remove injection characters
2. Length-limited to prevent resource exhaustion
3. Validated for finite values (no infinity/NaN)
4. Checked against valid geographic ranges
5. Given safe fallback defaults

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-14 10:20:10 -05:00

2.6 KiB

Technology Stack

Core Technologies

  • Elixir: ~> 1.17 - Primary programming language
  • Phoenix Framework: ~> 1.8 - Web framework
  • Phoenix LiveView: ~> 1.0.17 - Real-time web interfaces
  • PostgreSQL: Database with PostGIS extension for geospatial data
  • Ecto: Database wrapper and query generator

Key Dependencies

Web & UI

  • Bandit: HTTP server (replaces Cowboy)
  • Phoenix LiveDashboard: Development and monitoring dashboard
  • Tailwind CSS: Utility-first CSS framework
  • Heroicons: Icon library
  • ESBuild: JavaScript bundler

Data Processing

  • GenStage: Stream processing for APRS packet pipeline
  • Oban: Background job processing
  • Cachex: In-memory caching
  • Geo/PostGIS: Geospatial data handling

External Integrations

  • HTTPoison/Req: HTTP clients
  • Jason: JSON encoding/decoding
  • Swoosh: Email delivery

Development Tools

  • Credo: Static code analysis
  • Dialyxir: Static type analysis
  • Styler: Code formatting
  • ExVCR: HTTP interaction recording for tests
  • Sobelow: Security-focused static analysis

Common Commands

Development Setup

mix deps.get              # Install dependencies
mix ecto.setup            # Create and migrate database
mix phx.server            # Start development server
iex -S mix phx.server     # Start with interactive shell

Database Operations

mix ecto.create           # Create database
mix ecto.migrate          # Run migrations
mix ecto.reset            # Drop, create, and migrate database
mix ecto.gen.migration    # Generate new migration

Code Quality

mix credo                 # Run static analysis
mix dialyzer              # Run type analysis
mix format                # Format code
mix test                  # Run test suite
mix test.watch            # Run tests in watch mode

Asset Management

mix assets.deploy         # Build and optimize assets for production
mix tailwind default      # Compile Tailwind CSS
mix esbuild default       # Compile JavaScript

Production

mix release               # Build production release
mix phx.digest            # Generate asset digests

Configuration

  • Development: config/dev.exs
  • Production: config/prod.exs
  • Runtime: config/runtime.exs
  • Test: config/test.exs
  • Base: config/config.exs

Code Style

  • Uses Styler plugin for consistent formatting
  • Credo enforces code quality with 120 character line limit
  • Dialyzer for static type analysis
  • Import dependencies: :ecto, :ecto_sql, :phoenix, :stream_data