towerops/lib/towerops_web/controllers
Graham McIntire 1d928d4356
security: implement comprehensive security audit fixes
Critical Fixes:
- Remove /health/time endpoint exposing system time information
  * Prevents attackers from detecting time sync issues for TOTP attacks
  * Removed route and controller function, updated tests
- Add email confirmation check to account data export
  * GDPR export now requires confirmed email address
  * Prevents unconfirmed accounts from accessing data export
- Add path traversal validation for MIB archive uploads
  * Extract to temp directory, validate all paths, then copy if safe
  * Prevents malicious tar/zip files from writing outside target directory
  * Added validate_extracted_paths/1 helper function

High Priority Fixes:
- Add comprehensive input validation for mobile auth
  * Length limits: device_name (255), device_os (100), app_version (50), push_token (512)
  * Prevents database corruption and storage exhaustion
- Add heartbeat rate limiting to agent channel
  * Limit database updates to once per 30 seconds (max ~2/min per agent)
  * Prevents malicious agents from exhausting database connections
- Sanitize 500 error responses
  * Return generic error messages to clients
  * Log full details server-side with request_id for support
  * Prevents leaking stack traces and module names
- Add message size limits to agent channel
  * 10MB maximum for all protobuf messages (result, heartbeat, error)
  * Prevents DoS attacks via oversized payloads

Medium Priority Fixes:
- Add GraphQL query depth limits (max_depth: 10)
  * Prevents DoS from deeply nested queries
  * Complements existing complexity limits

Code Quality:
- Refactor agent channel handlers to reduce nesting depth
  * Extract message processing into separate private functions
  * Fixes Credo warnings about excessive nesting
  * Improves code readability and maintainability

Files changed:
- lib/towerops_web/controllers/health_controller.ex
- lib/towerops_web/controllers/api/account_data_controller.ex
- lib/towerops_web/controllers/api/v1/mib_controller.ex
- lib/towerops/mobile_sessions/mobile_session.ex
- lib/towerops_web/channels/agent_channel.ex
- lib/towerops_web/controllers/error_json.ex
- lib/towerops_web/router.ex
- CHANGELOG.txt
- priv/static/changelog.txt
- test/towerops_web/controllers/health_controller_test.exs
- test/towerops_web/controllers/error_json_test.exs

All 7,424 tests passing.
2026-03-05 13:08:10 -06:00
..
api security: implement comprehensive security audit fixes 2026-03-05 13:08:10 -06:00
api_docs_html fix: resolve compilation errors, test failures, and credo issues 2026-02-14 12:23:10 -06:00
error_html Add onboarding flow for new organizations 2026-02-16 10:14:45 -06:00
graphql_docs_html fix: resolve compilation errors, test failures, and credo issues 2026-02-14 12:23:10 -06:00
page_html fix: add dark mode support to marketing site 2026-03-04 13:57:12 -06:00
user_confirmation_html i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_registration_html ui: polish auth pages, core components, and visual consistency 2026-02-14 21:11:33 -06:00
user_reset_password_html purge more passkey and gettext updates 2026-02-02 10:20:59 -06:00
user_session_html ui: polish auth pages, core components, and visual consistency 2026-02-14 21:11:33 -06:00
user_settings_html fix: netbox url field type, gaiia ipRange→block, remove unknown webhook log 2026-02-14 17:44:01 -06:00
user_sudo_html fix: netbox url field type, gaiia ipRange→block, remove unknown webhook log 2026-02-14 17:44:01 -06:00
admin_controller.ex Skip SNMP check execution in CheckExecutorWorker for agent-polled devices 2026-02-17 07:47:15 -06:00
api_docs_controller.ex updates 2026-01-17 17:49:53 -06:00
api_docs_html.ex updates 2026-01-17 17:49:53 -06:00
debug_controller.ex add headers debug in prod 2026-02-01 10:54:13 -06:00
error_html.ex add error pages 2026-01-06 14:37:48 -06:00
error_json.ex security: implement comprehensive security audit fixes 2026-03-05 13:08:10 -06:00
graphql_docs_controller.ex feat: add GraphQL API with Absinthe, full schema, resolvers, and documentation 2026-02-14 11:28:57 -06:00
graphql_docs_html.ex feat: add GraphQL API with Absinthe, full schema, resolvers, and documentation 2026-02-14 11:28:57 -06:00
health_controller.ex security: implement comprehensive security audit fixes 2026-03-05 13:08:10 -06:00
invitation_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
page_controller.ex Fix mobile Gaiia entity mapping + redirect / to /dashboard 2026-02-15 15:05:20 -06:00
page_html.ex init 2025-12-21 11:10:43 -06:00
user_confirmation_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_confirmation_html.ex feat: require email verification before first login 2026-02-14 11:28:57 -06:00
user_registration_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_registration_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_reset_password_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_reset_password_html.ex forgot password flow 2026-01-31 17:03:22 -06:00
user_session_controller.ex fix: org switching now correctly updates session 2026-03-04 17:04:49 -06:00
user_session_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_settings_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_settings_html.ex credo cleanup 2026-01-17 15:00:52 -06:00
user_sudo_controller.ex i18n: wrap all user-facing strings in gettext() 2026-02-14 17:44:01 -06:00
user_sudo_html.ex feat: implement sudo mode MFA-only verification controller 2026-02-01 14:34:17 -06:00