Files
ResolveSpec/pkg/common/hardening.go
T
Hein ca89cb8a73 fix(common): harden CORS, sort, raw-SQL WHERE and x-custom-sql-or
Add a `hardening` config section (RESOLVESPEC_HARDENING_*) so each
fix can be switched off to restore the previous behaviour:

- cors_strict_origins: only reflect origins listed in
  cors.allowed_origins / server URLs, with credentials; `*` never
  sends credentials; fix shared-slice append of expose headers.
- sort_strict: join aliases must match `alias.identifier` (empty alias
  no longer matches everything); sort expressions reject dangerous
  functions/catalogs; cql* columns must be identifier-safe.
- sql_strict: client raw-SQL fragments must have balanced parens and
  quotes, no comments/`;`/`$$`, DML keywords, dangerous functions or
  system catalogs; a rejected fragment now fails closed ("(1=0)")
  instead of dropping the filter. Subqueries stay allowed unless
  sql_block_subqueries is set.
- x-custom-sql-or is grouped together with the client's own
  conditions (new optional WhereGrouper, implemented for bun and gorm)
  so it can no longer OR past server-side filters.
2026-10-01 13:46:01 +02:00

17 lines
622 B
Go

package common
import "github.com/bitechdev/ResolveSpec/pkg/config"
// hardeningProvider returns the active hardening switches. Tests may replace it.
var hardeningProvider = func() config.HardeningConfig {
cfg, err := config.GetConfigManager().GetConfig()
if err != nil || cfg == nil {
// Fail secure: hardening on when config is unavailable.
return config.HardeningConfig{CORSStrictOrigins: true, SortStrict: true, SQLStrict: true}
}
return cfg.Hardening
}
// Hardening returns the security hardening toggles (config section "hardening").
func Hardening() config.HardeningConfig { return hardeningProvider() }