towerops/lib/towerops_web/plugs
Graham McIntie 1590f78bdc fix: input validation, SSRF, API hardening, and cookie security
- LIKE wildcard injection: sanitize %, _ in search queries (devices, sites, gaiia)
- Jason.decode! → Jason.decode with error handling for untrusted input
- inspect() leak: replace with generic error messages, log details server-side
- SSRF protection: URL validator blocks private IPs, localhost, non-HTTP schemes
- SSRF validation added to HTTP monitoring executor and integration credentials
- GraphQL complexity limits: always applied, not just in prod
- GraphQL introspection: also check GET query params, not just body
- Stripe webhook: explicit nil/empty checks for signature and body
- Cookie security: secure flag for session (prod), http_only+secure for remember_me
- Honeybadger API key: read from env var with fallback
- String.to_integer → Integer.parse with fallback for URL params
- String.to_atom → whitelist map for HTTP methods
- Gaiia webhook: remove secret_len and expected signature from log
- Admin API: add rate limiting pipeline
- to_atom_keys: per-key fallback instead of all-or-nothing rescue
2026-03-14 14:48:59 -05:00
..
api_auth.ex refactor: use API token auth for profile imports instead of session cookies 2026-01-18 09:30:21 -06:00
brute_force_protection.ex fix: input validation, SSRF, API hardening, and cookie security 2026-03-14 14:48:59 -05:00
capture_timezone.ex Use detected timezone from session in user registration 2026-02-01 12:18:33 -06:00
check_policy_consent.ex gdpr consent tracking 2026-01-29 11:12:35 -06:00
detect_eu_user.ex perf: disable Req retry for faster error tests 2026-03-10 16:19:31 -05:00
filter_noisy_logs.ex fix: properly disable Plug.Telemetry logging for health checks 2026-03-08 16:39:26 -05:00
graphql_introspection.ex Security fixes: mask credentials in logs/API, fix cookie/CSP/LIKE injection/webhooks 2026-02-15 09:09:04 -06:00
mobile_auth.ex Add comprehensive Dialyzer type specifications 2026-01-17 10:52:02 -06:00
rate_limit.ex perf: disable Req retry for faster error tests 2026-03-10 16:19:31 -05:00
remote_ip_logger.ex perf: disable Req retry for faster error tests 2026-03-10 16:19:31 -05:00
security_headers.ex fix: allow data URLs in CSP for dynamic favicon 2026-03-06 13:51:31 -06:00
update_session_activity.ex fix: netbox url field type, gaiia ipRange→block, remove unknown webhook log 2026-02-14 17:44:01 -06:00
webhook_auth.ex Add CI-triggered mass agent update webhook 2026-02-10 13:40:32 -06:00