Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions boot.tests/SecurityHardeningTests.cs
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
namespace boot.tests;

[TestClass]
[DoNotParallelize]
public sealed class SecurityHardeningTests
{
private const string MainnetPayoutAddress = "bc1qd9m04z95mglaxd9e9accmhyjdlmkfmzjprkq4p";
Expand Down Expand Up @@ -48,6 +49,26 @@ public void PrivateDashboardDiagnosticsRequireExplicitApplianceOptInOrAdminAuth(
Assert.IsTrue(DashboardController.CanViewOperatorDiagnostics(config, adminAuthorized: false));
}

[TestMethod]
public void PrivateDashboardEnvironmentOverrideSupportsPackageUpgrades()
{
const string variable = "GRIDPOOL_TRUSTED_PRIVATE_DASHBOARD_ENABLED";
string? previous = Environment.GetEnvironmentVariable(variable);
try
{
var config = ValidConfig();
Environment.SetEnvironmentVariable(variable, "true");

Program.ApplyPoolConfigEnvironmentOverrides(config);

Assert.IsTrue(config.TrustedPrivateDashboardEnabled);
}
finally
{
Environment.SetEnvironmentVariable(variable, previous);
}
}

[TestMethod]
public void StoredMinerLabelIsBoundedAndMarkupFree()
{
Expand Down
12 changes: 12 additions & 0 deletions boot_portal/Program.cs
Original file line number Diff line number Diff line change
Expand Up @@ -658,6 +658,7 @@
if (config != null)
{
ApplyPoolConfigDefaults(config);
ApplyPoolConfigEnvironmentOverrides(config);
PoolConfigValidator.ValidateOrThrow(config);
Console.WriteLine(
string.IsNullOrWhiteSpace(localConfigPath) || !File.Exists(localConfigPath)
Expand All @@ -674,6 +675,7 @@
Console.WriteLine($"🔧 Using default pool config");
var fallbackConfig = new PoolConfig();
ApplyPoolConfigDefaults(fallbackConfig);
ApplyPoolConfigEnvironmentOverrides(fallbackConfig);
PoolConfigValidator.ValidateOrThrow(fallbackConfig);
return fallbackConfig;
}
Expand Down Expand Up @@ -785,6 +787,16 @@
}
}

internal static void ApplyPoolConfigEnvironmentOverrides(PoolConfig config)
{
string? trustedPrivateDashboard =
Environment.GetEnvironmentVariable("GRIDPOOL_TRUSTED_PRIVATE_DASHBOARD_ENABLED");
if (bool.TryParse(trustedPrivateDashboard, out bool enabled))
{
config.TrustedPrivateDashboardEnabled = enabled;
}
}

private static RateLimitPartition<string> CreateRateLimitPartition(HttpContext context, PoolConfig poolConfig, string policyName, int permitLimit)
{
return RateLimitPartition.GetFixedWindowLimiter(
Expand Down Expand Up @@ -1844,7 +1856,7 @@
// Truncate input to actual length
var cipherText = encryptedBody.AsSpan(0, bytesRead).ToArray();
byte[] combinedCiphertext = new byte[bytesRead + LibSodium.CryptoBox.NonceLen];
Array.Copy(_sessionNonceReceiver, 0, combinedCiphertext, 0, LibSodium.CryptoBox.NonceLen);

Check warning on line 1859 in boot_portal/Program.cs

View workflow job for this annotation

GitHub Actions / dotnet

Possible null reference argument for parameter 'sourceArray' in 'void Array.Copy(Array sourceArray, int sourceIndex, Array destinationArray, int destinationIndex, int length)'.

Check warning on line 1859 in boot_portal/Program.cs

View workflow job for this annotation

GitHub Actions / dotnet

Possible null reference argument for parameter 'sourceArray' in 'void Array.Copy(Array sourceArray, int sourceIndex, Array destinationArray, int destinationIndex, int length)'.
Array.Copy(encryptedBody, 0, combinedCiphertext, LibSodium.CryptoBox.NonceLen, bytesRead);


Expand Down
Loading