fix: harden Omarseafile for marketplace security review - #1
Merged
Merged
Conversation
This commit addresses all 7 security-review blockers from omarchy-plugin-marketplace #4145: 1. HTTPS enforcement for auth (UrlPolicy) 2. Bounded API transport (HttpTransport with curl, no XHR) 3. Secure secret temp files (SafePath, XDG_RUNTIME_DIR, O_EXCL|O_NOFOLLOW, 0600) 4. Safe transfer paths (sanitizeBasename, secureJoin, traversal prevention) 5. Transfer limits/timeouts (curl --max-filesize, --connect-timeout, --max-time, --speed-limit, process group kill) 6. Helper process hardening (ProcessWithTimeout, timeout, bounded output, process group kill) 7. QML AutoText fixes (textFormat: Text.PlainText on all dynamic content) New modules: - js/UrlPolicy.qml - js/SafePath.qml - js/HttpTransport.qml - js/ProcessWithTimeout.qml Open Local bug fix (da77af3) preserved and verified working.
- Fix factory reference names in all new modules - Remove Authorization from curl argv (use header file via stdin) - Replace ALL authenticated XHR with HttpTransport (curl via stdin auth) - Enforce collection/string limits in HttpTransport and SeafileAPI - Fix XDG_RUNTIME_DIR mode validation (verify 0700, ownership) - Fix TOCTOU in temp file creation (mktemp + atomic write via stdin) - Fix process group creation/kill (pgid tracking, kill -TERM -pgid) - Use SafePath on ALL transfer paths (sanitizeBasename, secureJoin) - Implement producer-side response limits (curl --max-filesize, StdioCollector maxBytes) - Add security regression test helpers - Open Local bug fix preserved and verified All 7 security findings from marketplace #4145 addressed.
- Revert circular import pattern: js/ singletons must NOT import
'roddy.seafile 1.0' from within the module (causes 'module not
installed' at runtime)
- Remove broken Qt6 directory imports: 'import "./Foo.qml"' is a
directory import in Qt6, not a file import; remove cross-singleton
file imports since qmldir singletons are auto-visible within the module
- Fix TransferService.qml scheduleRetry(): restore Component factory
pattern (security code used invalid Qt.createComponent('dummy') with
JS block statement as signal handler)
- Restore truncated TransferService.qml: ~105 missing lines from
handleOpenDownloadExited through logoutCleanup (security commits cut
the file at line 1030)
- Remove non-existent StdioCollector { maxBytes: } property from
Auth.qml, HttpTransport.qml, ProcessWithTimeout.qml, TransferService.qml
- Remove conflicting root qmldir (conflicted with js/qmldir module
declaration)
- Remove redundant explicit singleton imports from Panel.qml
TransferManager: fix Clear/Clear Done button overflow in section headers. Root cause: spacer Item width didn't account for the section label's implicit width, causing the Row children to exceed parent.width by ~50px. Fix: subtract label.width from spacer calculation. TransferService: strengthen Open Local handoff lifecycle. - Guard late process exit against overwriting terminal states - Ensure reservation release on all cancellation paths - Add openCachedFile process guard for null/failed creation Tests: add Open Local lifecycle test (test_open_lifecycle.qml) that proves cancellation during Opening phase, active cache protection, late exit safety, and cache release. Add deploy scope test.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This branch addresses the marketplace security review.
Exact independently reviewed candidate SHA:
08c4bb015ea33c9efa4632bd3f88082bc8e425cdIndependent exact-SHA review findings:
GitHub CI has not yet been claimed as passed; this PR is created to trigger the pull_request workflow.