feb5380b28
Fixes critical pre-existing issues found during review: bulk_action.php had no auth check at all (unauthenticated download/delete of any qrcode) and built a table name from unwhitelisted user input (SQL injection); the QR generator classes wrote files from unvalidated filename/format, allowing path traversal and arbitrary file writes. Also pins chillerlan/php-qrcode to 5.0.5 since master now requires PHP 8.4, breaking the PHP 8.3 build. - CSRF tokens on all POST forms and the bulk_action.php JSON endpoint - Login rate limiting (5 attempts / 15 min) via new login_attempts table - Hardened sessions: httponly/samesite cookies, 30 min idle timeout, session regeneration on login - Forced password change for the default superadmin/superadmin account - Server-side validation in Users/DynamicQrcode/Qrcode classes - Audit log table for auth, user, and qrcode actions - Checked-in db schema (db/init.sql, migrations/) instead of relying on an opaque prebuilt db image - Production docker-compose with Nginx + php-fpm instead of the PHP dev server Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
60 lines
2.0 KiB
Docker
60 lines
2.0 KiB
Docker
FROM php:8.3-fpm
|
|
|
|
RUN if [ "$(grep '^VERSION_ID=' /etc/os-release | cut -d '=' -f 2 | tr -d '"')" -eq "9" ]; then \
|
|
sed -i -e 's/deb.debian.org/archive.debian.org/g' \
|
|
-e 's/security.debian.org/archive.debian.org/g' \
|
|
-e '/stretch-updates/d' /etc/apt/sources.list; \
|
|
fi
|
|
|
|
ADD https://github.com/mlocati/docker-php-extension-installer/releases/latest/download/install-php-extensions /usr/local/bin/
|
|
|
|
RUN chmod +x /usr/local/bin/install-php-extensions
|
|
|
|
RUN DEBIAN_FRONTEND=noninteractive apt-get update -q \
|
|
&& DEBIAN_FRONTEND=noninteractive apt-get install -qq -y \
|
|
curl \
|
|
libzip-dev \
|
|
libjpeg62-turbo-dev \
|
|
libpng-dev \
|
|
libfreetype6-dev \
|
|
zip unzip \
|
|
&& install-php-extensions \
|
|
gd \
|
|
gettext \
|
|
intl \
|
|
mysqli \
|
|
opcache \
|
|
pdo_mysql \
|
|
sockets \
|
|
zip
|
|
|
|
# Install Composer.
|
|
ENV PATH=$PATH:/root/composer/vendor/bin \
|
|
COMPOSER_ALLOW_SUPERUSER=1 \
|
|
COMPOSER_HOME=/root/composer
|
|
RUN cd /opt \
|
|
&& curl -sSL https://getcomposer.org/installer > composer-setup.php \
|
|
&& curl -sSL https://composer.github.io/installer.sha384sum > composer-setup.sha384sum \
|
|
&& sha384sum --check composer-setup.sha384sum \
|
|
&& php composer-setup.php --install-dir=/usr/local/bin --filename=composer --2 \
|
|
&& rm /opt/composer-setup.php /opt/composer-setup.sha384sum
|
|
|
|
RUN mkdir -p /opt && chmod 777 /opt
|
|
WORKDIR /opt
|
|
# Zie Dockerfile: vastgezet op 5.0.5, want 6.0.0+ vereist PHP >= 8.4.
|
|
RUN git clone --branch 5.0.5 --depth 1 https://github.com/chillerlan/php-qrcode.git \
|
|
&& chmod -R 777 ./php-qrcode
|
|
RUN cp ./php-qrcode/composer.json /var/www/html/composer.json
|
|
RUN cp -R ./php-qrcode/src /var/www/html/
|
|
|
|
WORKDIR /var/www/html
|
|
RUN composer update
|
|
COPY ./src ./
|
|
RUN chown -R www-data:www-data /var/www/html \
|
|
&& find /var/www/html -type f -exec chmod 644 {} \; \
|
|
&& find /var/www/html -type d -exec chmod 755 {} \; \
|
|
&& chmod -R 775 /var/www/html/saved_qrcode
|
|
|
|
EXPOSE 9000
|
|
CMD ["php-fpm"]
|