From the whole-codebase re-audit (deferred MEDIUM findings, Codex-reviewed): - poller: CredentialVault enforces a credential's disabled_at lock only at connect(), but PollMetrics reuses one long-lived SSH connection per server, so a credential disabled mid-run kept streaming metrics over the already-open session. Add Server::withActiveCredential() (whereHas credential whereNull disabled_at); the poller selects via it and prunes any cached client whose server left the active set, so a revocation drops the server on the next tick and closes its session promptly. - prod compose: add security_opt no-new-privileges:true to every service + a generous pids_limit (fork-bomb backstop). cap_drop/read_only are deliberately left out — they need a per-service prod smoke test (nginx :80 bind, entrypoint chown) before enabling; documented inline. - Caddyfile + compose: strengthen the TRUSTED_PROXY_CIDR guidance — an over-broad value in external-TLS mode lets any client forge X-Forwarded-For and defeat the IP-keyed throttles + ban. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| AuditEvent.php | ||
| BannedIp.php | ||
| HostCredential.php | ||
| MetricSample.php | ||
| Server.php | ||
| Setting.php | ||
| SshCredential.php | ||
| TerminalSession.php | ||
| User.php | ||
| WebauthnCredential.php | ||
| WgTrafficSample.php | ||