clusev/app/Services
boban d7156ddc96 fix(security): harden the update path — signed sentinel, symlink-safe root writes, .env 0600
Security audit (12-angle adversarial workflow) findings on the container→host boundary:
- .env was created world-readable (cp of a 644 .env.example, never chmod'd) exposing the APP_KEY
  that decrypts the whole fleet's SSH vault. Now chown clusev + chmod 0600 before any secret write.
- The root updater followed attacker-planted symlinks in the container-writable ./run (update-phase.json,
  update.log) → arbitrary root file write. Status writes now go via a temp + rename(2) (never follow a
  link); the update transcript moved to the repo root (not the ./run bind mount).
- The generated UPDATE_HMAC_KEY was dead. The app now HMAC-signs the update-request marker
  (config/clusev.php update_hmac_key; DeploymentService) and watch.sh verifies it before running a
  root update, so a stray/limited write to ./run can't drive one (a full container compromise holds
  the key, so this is a bar-raise + integrity check; the standing guarantee is the marker only ever
  re-installs the trusted remote's code, never attacker code).
- force_kv/set_kv wrote unescaped values into a sed replacement — a & | or newline in an operator's
  domain/email/port could corrupt .env or inject a sed command. Values are now CR/LF-stripped and
  sed-escaped, and the HTTP port is validated numeric/in-range.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-04 10:25:10 +02:00
..
.gitkeep feat: scaffold — Dockerized Laravel 13 + Livewire 3 + Tailwind 4 + Reverb 2026-06-12 00:31:50 +02:00
BruteforceGuard.php harden(auth): fold IPv4-mapped IPv6, dedupe unbanAll, limit bans render, forged-token test 2026-06-20 18:53:52 +02:00
DeploymentService.php fix(security): harden the update path — signed sentinel, symlink-safe root writes, .env 0600 2026-07-04 10:25:10 +02:00
Fail2banService.php i18n: complete DE/EN localization (modals, shell, backend) + v0.3.0 2026-06-13 23:27:42 +02:00
FirewallService.php i18n: complete DE/EN localization (modals, shell, backend) + v0.3.0 2026-06-13 23:27:42 +02:00
FleetService.php fix(files): binary file content no longer breaks the Livewire snapshot (v0.9.54) 2026-06-22 05:49:05 +02:00
HardeningService.php fix(hardening): fail2ban — pin the sshd jail to the systemd backend 2026-06-25 01:14:06 +02:00
MaintenanceService.php feat(fail2ban): jail status, banned-IP list + unban, manual ban, whitelist 2026-06-13 20:27:55 +02:00
MetricHistory.php refactor(metrics): interactive history chart — smooth, area, tooltip, instant ranges 2026-06-25 01:51:24 +02:00
PipelineStatus.php refactor(release): drop the test-server step — pipeline is build readiness only 2026-06-23 02:46:17 +02:00
PromotionService.php feat(release): remove the no-op channel selector + dead beta→stable promotion (single stable channel) 2026-07-03 20:43:15 +02:00
ReleaseBridge.php feat(release): ReleaseBridge — write staging request, read host result 2026-06-22 23:14:34 +02:00
ReleaseChecker.php feat(release): collapse to a single stable channel 2026-07-03 20:00:50 +02:00
ReleasePlanner.php feat(release): ReleasePlanner — proposed beta targets from the current version 2026-06-22 23:07:41 +02:00
SessionService.php feat(sessions): database sessions + list/revoke (other devices, per-user, global) with remember-token rotation 2026-06-14 23:34:00 +02:00
SshKeyProvisioner.php fix(ssh): best-effort audit + exception-safe switch/verify and modal run(); lock serverId 2026-06-14 22:16:54 +02:00
WebauthnService.php fix(webauthn): add security-key hint so passkey managers defer 2026-06-19 21:30:52 +02:00
WgBridge.php feat(wg): configurable DNS + Server/Peers tabs + faster offline (v0.9.45) 2026-06-21 22:48:46 +02:00
WgStatus.php feat(wg): configurable DNS + Server/Peers tabs + faster offline (v0.9.45) 2026-06-21 22:48:46 +02:00
WgTraffic.php refactor(wireguard): remove dead code + DRY the WG surface (no behavior change) 2026-06-21 16:33:41 +02:00