security: appliquer les findings de l'audit OWASP (H1→B3)

H1 — trusted_proxies RFC-1918 dans framework.yaml : rate limiting
     opérationnel derrière Traefik (IP client réelle, pas IP Traefik)

H2 — En-têtes HTTP dans Caddyfile : X-Frame-Options DENY,
     X-Content-Type-Options nosniff, Referrer-Policy, Permissions-Policy,
     suppression header Server

H3 — API Platform docs désactivés en when@prod (Swagger UI, ReDoc)

M1 — Rate limiter sur DELETE /api/push/subscribe (manquant)
M2 — Validation FILTER_VALIDATE_URL sur endpoint push avant stockage
M3 — APP_ENV=prod dans backend/.env (était dev — risque si .env.local absent)
M4 — Limite 4096 octets sur le body JSON (FeedbackController + PushController)
M5 — Service Worker : open redirect corrigé (targetUrl validé contre l'origine)

B1 — robots.txt créé (bloque /api/ et /bundles/)
B3 — --time-limit=3600 sur les workers Messenger (rotation + libération mémoire)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Gwadaking
2026-04-10 00:49:15 -04:00
parent 0d9c85e71b
commit cda9a7a8ff
9 changed files with 57 additions and 5 deletions

View File

@@ -0,0 +1,5 @@
User-agent: *
Disallow: /api/
Disallow: /bundles/
Allow: /

View File

@@ -25,7 +25,11 @@ self.addEventListener('push', (event) => {
self.addEventListener('notificationclick', (event) => {
event.notification.close();
const targetUrl = event.notification.data?.url ?? '/';
const rawUrl = event.notification.data?.url ?? '/';
// N'autoriser que les URLs relatives ou du même domaine (protection open redirect)
const targetUrl = (rawUrl.startsWith('/') || rawUrl.startsWith(self.location.origin))
? rawUrl
: '/';
event.waitUntil(
clients.matchAll({ type: 'window', includeUncontrolled: true }).then((windowClients) => {