Security hardening: CSRF, rate limiting, session/password policy, audit log
Fixes critical pre-existing issues found during review: bulk_action.php had no auth check at all (unauthenticated download/delete of any qrcode) and built a table name from unwhitelisted user input (SQL injection); the QR generator classes wrote files from unvalidated filename/format, allowing path traversal and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since master now requires PHP 8.4, breaking the PHP 8.3 build. - CSRF tokens on all POST forms and the bulk_action.php JSON endpoint - Login rate limiting (5 attempts / 15 min) via new login_attempts table - Hardened sessions: httponly/samesite cookies, 30 min idle timeout, session regeneration on login - Forced password change for the default superadmin/superadmin account - Server-side validation in Users/DynamicQrcode/Qrcode classes - Audit log table for auth, user, and qrcode actions - Checked-in db schema (db/init.sql, migrations/) instead of relying on an opaque prebuilt db image - Production docker-compose with Nginx + php-fpm instead of the PHP dev server
This commit is contained in:
@@ -0,0 +1,59 @@
|
||||
FROM php:8.3-fpm
|
||||
|
||||
RUN if [ "$(grep '^VERSION_ID=' /etc/os-release | cut -d '=' -f 2 | tr -d '"')" -eq "9" ]; then \
|
||||
sed -i -e 's/deb.debian.org/archive.debian.org/g' \
|
||||
-e 's/security.debian.org/archive.debian.org/g' \
|
||||
-e '/stretch-updates/d' /etc/apt/sources.list; \
|
||||
fi
|
||||
|
||||
ADD https://github.com/mlocati/docker-php-extension-installer/releases/latest/download/install-php-extensions /usr/local/bin/
|
||||
|
||||
RUN chmod +x /usr/local/bin/install-php-extensions
|
||||
|
||||
RUN DEBIAN_FRONTEND=noninteractive apt-get update -q \
|
||||
&& DEBIAN_FRONTEND=noninteractive apt-get install -qq -y \
|
||||
curl \
|
||||
libzip-dev \
|
||||
libjpeg62-turbo-dev \
|
||||
libpng-dev \
|
||||
libfreetype6-dev \
|
||||
zip unzip \
|
||||
&& install-php-extensions \
|
||||
gd \
|
||||
gettext \
|
||||
intl \
|
||||
mysqli \
|
||||
opcache \
|
||||
pdo_mysql \
|
||||
sockets \
|
||||
zip
|
||||
|
||||
# Install Composer.
|
||||
ENV PATH=$PATH:/root/composer/vendor/bin \
|
||||
COMPOSER_ALLOW_SUPERUSER=1 \
|
||||
COMPOSER_HOME=/root/composer
|
||||
RUN cd /opt \
|
||||
&& curl -sSL https://getcomposer.org/installer > composer-setup.php \
|
||||
&& curl -sSL https://composer.github.io/installer.sha384sum > composer-setup.sha384sum \
|
||||
&& sha384sum --check composer-setup.sha384sum \
|
||||
&& php composer-setup.php --install-dir=/usr/local/bin --filename=composer --2 \
|
||||
&& rm /opt/composer-setup.php /opt/composer-setup.sha384sum
|
||||
|
||||
RUN mkdir -p /opt && chmod 777 /opt
|
||||
WORKDIR /opt
|
||||
# Zie Dockerfile: vastgezet op 5.0.5, want 6.0.0+ vereist PHP >= 8.4.
|
||||
RUN git clone --branch 5.0.5 --depth 1 https://github.com/chillerlan/php-qrcode.git \
|
||||
&& chmod -R 777 ./php-qrcode
|
||||
RUN cp ./php-qrcode/composer.json /var/www/html/composer.json
|
||||
RUN cp -R ./php-qrcode/src /var/www/html/
|
||||
|
||||
WORKDIR /var/www/html
|
||||
RUN composer update
|
||||
COPY ./src ./
|
||||
RUN chown -R www-data:www-data /var/www/html \
|
||||
&& find /var/www/html -type f -exec chmod 644 {} \; \
|
||||
&& find /var/www/html -type d -exec chmod 755 {} \; \
|
||||
&& chmod -R 775 /var/www/html/saved_qrcode
|
||||
|
||||
EXPOSE 9000
|
||||
CMD ["php-fpm"]
|
||||
Reference in New Issue
Block a user