Repository navigation
Harden draft publishing surface: secure rendering, PIN flow, lifecycle controls, and abuse limits - #3
Conversation
|
@copilot please address the following before merge: Spec gaps (issue #2):
Architecture: Minor cleanup: Please push fixes to this PR branch. |
Addressed in commit Implemented the requested fixes:
|
|
@copilot good progress — all 6 points from the last review are fixed (early size check, tightened CSP, correct IP precedence, bundled PIN fields, dropped unused param, separated rate-limit store). One new, more serious issue found by checking the CSP against this repo's own flagship template: CSP breaks the product's core use case.
So the hardening fix, as written, renders every published draft that uses CDN-loaded CSS/JS (which is the expected case for "AI-generated HTML plans/mockups" per the README) completely unstyled and non-interactive. XSS protection at the cost of breaking the product's stated purpose isn't a fix, it's a tradeoff that needs a decision, not a silent default. Options to reconcile:
Please pick one and implement it — silently shipping a CSP that breaks the example template isn't acceptable to merge as-is. Also: |
…binding The prior script-src/style-src 'none' policy blocked the repo's own templates/plan-template.html, which loads Tailwind, Font Awesome, and Lucide from CDN — every published draft using it rendered unstyled and non-interactive. Inline <script> (the actual XSS vector) stays blocked; a fixed CDN allowlist (jsdelivr, cdnjs, unpkg) covers legitimate assets. Also documents the UPLOAD_RATE_LIMITS KV binding in wrangler.toml.example so rate-limit counters land in their own namespace instead of silently falling back to HTML_DRAFTS on a fresh deploy.
|
Copilot's last push (71aac47) fixed all 6 points from the first review round: early size-check before JSON parse, Two blockers remained from the second round — fixed directly in 4567c75:
All 8 findings from issue #2 are now addressed and verified against the repo's own template. Merging. |
FreeFlow’s worker/CLI publish path had multiple security and robustness gaps: draft HTML was served with weak browser protections, PINs leaked via URL/plaintext storage, and uploads lacked lifecycle/abuse controls. This change tightens draft access semantics and adds bounded, authenticated operations for safer self-hosted publishing.
Worker response hardening
Content-Security-Policy(default-src 'none',script-src 'none',frame-ancestors 'none', etc.)X-Frame-Options: DENYX-Content-Type-Options: nosniffReferrer-Policy: no-referrerPIN flow + secret handling
?key=...query parameter.POST /d/:idform submission andx-draft-pinheader.pinHash+pinSalt) instead of plaintext.Draft lifecycle controls
ttlSeconds) with bounds validation and KVexpirationTtl.DELETE /d/:idendpoint (same bearer auth as upload) to remove drafts on demand.Abuse/robustness controls
413response on overflow./uploadrate limiting (configurable viaUPLOAD_RATE_LIMIT_PER_MINUTE, default 30/min).CLI guardrail