aprs.me/.kiro/steering/tech.md
Graham McIntire 94f3a62539
Add comprehensive input sanitization for coordinate parsing
Security improvements:
- Added sanitize_numeric_string to remove dangerous characters
- Limited input string length to prevent DoS attacks (20 chars for numbers)
- Added is_finite? checks to prevent infinity/NaN values
- Validate coordinate ranges (lat: -90 to 90, lng: -180 to 180)
- Added safe_parse_coordinate with proper validation
- Updated to_float in EncodingUtils with security validations
- Protected against integer overflow in coordinate conversions
- Added sanitize_path_string for APRS path validation

All coordinate inputs from users are now:
1. Sanitized to remove injection characters
2. Length-limited to prevent resource exhaustion
3. Validated for finite values (no infinity/NaN)
4. Checked against valid geographic ranges
5. Given safe fallback defaults

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-14 10:20:10 -05:00

100 lines
2.6 KiB
Markdown

# Technology Stack
## Core Technologies
- **Elixir**: ~> 1.17 - Primary programming language
- **Phoenix Framework**: ~> 1.8 - Web framework
- **Phoenix LiveView**: ~> 1.0.17 - Real-time web interfaces
- **PostgreSQL**: Database with PostGIS extension for geospatial data
- **Ecto**: Database wrapper and query generator
## Key Dependencies
### Web & UI
- **Bandit**: HTTP server (replaces Cowboy)
- **Phoenix LiveDashboard**: Development and monitoring dashboard
- **Tailwind CSS**: Utility-first CSS framework
- **Heroicons**: Icon library
- **ESBuild**: JavaScript bundler
### Data Processing
- **GenStage**: Stream processing for APRS packet pipeline
- **Oban**: Background job processing
- **Cachex**: In-memory caching
- **Geo/PostGIS**: Geospatial data handling
### External Integrations
- **HTTPoison/Req**: HTTP clients
- **Jason**: JSON encoding/decoding
- **Swoosh**: Email delivery
### Development Tools
- **Credo**: Static code analysis
- **Dialyxir**: Static type analysis
- **Styler**: Code formatting
- **ExVCR**: HTTP interaction recording for tests
- **Sobelow**: Security-focused static analysis
## Common Commands
### Development Setup
```bash
mix deps.get # Install dependencies
mix ecto.setup # Create and migrate database
mix phx.server # Start development server
iex -S mix phx.server # Start with interactive shell
```
### Database Operations
```bash
mix ecto.create # Create database
mix ecto.migrate # Run migrations
mix ecto.reset # Drop, create, and migrate database
mix ecto.gen.migration # Generate new migration
```
### Code Quality
```bash
mix credo # Run static analysis
mix dialyzer # Run type analysis
mix format # Format code
mix test # Run test suite
mix test.watch # Run tests in watch mode
```
### Asset Management
```bash
mix assets.deploy # Build and optimize assets for production
mix tailwind default # Compile Tailwind CSS
mix esbuild default # Compile JavaScript
```
### Production
```bash
mix release # Build production release
mix phx.digest # Generate asset digests
```
## Configuration
- **Development**: `config/dev.exs`
- **Production**: `config/prod.exs`
- **Runtime**: `config/runtime.exs`
- **Test**: `config/test.exs`
- **Base**: `config/config.exs`
## Code Style
- Uses **Styler** plugin for consistent formatting
- **Credo** enforces code quality with 120 character line limit
- **Dialyzer** for static type analysis
- Import dependencies: `:ecto`, `:ecto_sql`, `:phoenix`, `:stream_data`