• Stefy Lanza (nextime / spora )'s avatar
    admin: sanitize model-upload paths + atomic auth.json read-modify-write · f97459fc
    Stefy Lanza (nextime / spora ) authored
    The model-upload endpoint joined a client-supplied filename straight onto
    the cache dir, so an admin-authenticated request with a traversal filename
    (or upload_id) could write outside it. Reduce both to a safe basename,
    reject separators/.., and add a commonpath containment check before
    committing the upload.
    
    SessionManager only locked the write half of each load->mutate->save, so
    concurrent writers could clobber each other's changes (lost sessions or
    tokens). Add update_auth_data(mutator), which holds the lock across the
    whole read-modify-write and persists only when the mutator asks to; route
    every mutating method (and the token create/delete endpoints) through it.
    Read-only callers keep the lock-free load since writes are atomic via
    os.replace. While migrating the token endpoints, switch IDs to max+1 (no
    reuse after deletion) and to timezone-aware timestamps.
    Co-Authored-By: 's avatarClaude Opus 4.8 <noreply@anthropic.com>
    f97459fc
Name
Last commit
Last update
codai Loading commit data...
docs Loading commit data...
packaging Loading commit data...
samples Loading commit data...
tests Loading commit data...
tools Loading commit data...
.dockerignore Loading commit data...
.gitignore Loading commit data...
AI.PROMPT Loading commit data...
CODERAI_API_DOCUMENTATION.md Loading commit data...
CoderAI.gif Loading commit data...
DISTRIBUTION.md Loading commit data...
LICENSE.md Loading commit data...
MULTIMODAL_CAPABILITIES.md Loading commit data...
MULTIMODAL_UI_EXAMPLES.md Loading commit data...
README.md Loading commit data...
build-oci.sh Loading commit data...
build.ps1 Loading commit data...
build.sh Loading commit data...
coderai Loading commit data...
coderai-broker-implementation-reference.md Loading commit data...
coderai-integration.md Loading commit data...
commands Loading commit data...
osxbuild.sh Loading commit data...
package-oci.sh Loading commit data...
package-tarball.sh Loading commit data...
requirements-nvidia.txt Loading commit data...
requirements-vulkan.txt Loading commit data...
requirements.txt Loading commit data...
run-oci.sh Loading commit data...
smoke-test-oci.sh Loading commit data...
todo.md Loading commit data...
video_editor.config.json Loading commit data...