mirror of
https://github.com/BigBodyCobain/Shadowbroker.git
synced 2026-05-27 09:32:28 +02:00
e36d1fc79c
External security audit by @tg12 (May 17, 2026) filed issues #201–#214 in addition to the #189–#200 batch already closed by PRs #227/#232/#260. This PR closes all eight that are real security bugs (the other six in the 201–214 range are either design discussions or upstream-abuse/TOS concerns we're keeping intentional, see issue triage notes on each). The user-facing principle for this PR: fix the security gap WITHOUT introducing a single hostile error or behavior change for legitimate users. Every fix follows the same template — fail forward, not loud. When the secure path is harder than the insecure one, build a fallback chain that ends in graceful degradation, not in a scary modal or 422 response. #205 — OpenMHZ audio redirect SSRF (services/radio_intercept.py) Replaced requests.get(..., allow_redirects=True) with a manual redirect loop that re-validates each hop's host against _OPENMHZ_AUDIO_HOSTS. Same-host redirects (CDN edge selection) still work, so legitimate audio playback is unaffected. Cross-host redirects to disallowed hosts return a generic 502 which the browser audio element handles gracefully. Cap at 5 hops. #207 — infonet/status verify_signatures DoS (routers/mesh_public.py) Silently downgrade verify_signatures=true to False for unauthenticated callers. No error surfaced — the response shape is identical, just without the O(n_events) signature verification. Authenticated callers (scoped mesh.audit) still get the full path. The frontend never passes this param so legitimate UI is unaffected. #211 — thermal/verify expensive analysis (routers/sigint.py) Added Depends(require_local_operator). Frontend has no direct callers (verified by grep); Tauri/AI agents use scoped tokens that pass the auth check. Anonymous abusers blocked silently — the legitimate UI keeps working through the Next.js admin-key proxy. #213, #214 — OpenMHZ calls/audio upstream abuse (routers/radio.py) Added Depends(require_local_operator) to both. Browser users hit these through the Next.js proxy at src/app/api/[...path]/route.ts which injects X-Admin-Key, so the auth check passes transparently. Direct attackers can no longer rotate sys_names to hammer api.openmhz.com or relay arbitrary audio streams through the backend's bandwidth. #202 — overflights unbounded hours (routers/data.py) Silently clamp `hours` to OVERFLIGHTS_MAX_HOURS (default 72, configurable). NO 422 — clients asking for an absurd window get a shorter window back with `requested_hours` and `effective_hours` hint fields. Postel's law: liberal in what we accept, conservative in what we compute. #203 — Meshtastic callsign UA leak (services/fetchers/meshtastic_map.py) Added MESHTASTIC_SEND_CALLSIGN_HEADER opt-out env var. Default is TRUE — preserves existing operator behavior (callsign sent so meshtastic.org can rate-limit per-install). Privacy-conscious operators set it to false to suppress. #206 — KiwiSDR upstream is HTTP-only (services/kiwisdr_fetcher.py) Upstream rx.linkfanel.net doesn't speak HTTPS (verified — Apache 2.4.10 only on port 80). We can't fix the transport. Instead added three layers: 1. Content validation on fetched data — reject responses with <50 receivers or >5% malformed entries (likely MITM injection). 2. Existing disk cache fallback (already present). 3. NEW: bundled static directory at backend/data/kiwisdr_directory.json shipping 798 known-good receivers. Used as last resort so the KiwiSDR map layer always renders something useful. #208 — Merkle proof DoS via /api/mesh/infonet/sync (services/mesh/mesh_hashchain.py) The endpoint is part of the cross-node federation protocol — peers legitimately call it without local-operator auth, so we can't add Depends(). Instead made the underlying operation O(1) per proof via a cached Merkle level structure on the Infonet instance: - _merkle_levels_cache + _merkle_levels_for_event_count on each Infonet instance - _invalidate_merkle_cache() called from every chain mutation point (append, ingest_events, apply_fork, cleanup_expired) - _get_merkle_levels() does the lazy recompute on first read after invalidation, then serves from cache thereafter Effect: anonymous attackers hammering the proofs endpoint hit a cached structure; the rebuild happens at most once per real chain advance. Federation untouched. #201 — Tor bundle SHA-256 bypass (services/tor_hidden_service.py) Docker users were already covered — backend/Dockerfile installs Tor via apt-get at build time (signed by Debian's package system). No runtime download needed for the 80%-of-users case. For Tauri desktop, replaced the single .sha256sum check with a multi-source verification chain implemented in _verify_tor_bundle(): 1. Try upstream .sha256sum (current behavior — fast path) 2. Try baked-in digest list at backend/data/tor_bundle_digests.json (pinned per-version, maintainer-updated) 3. If neither source is REACHABLE: HTTPS-only fallback with a loud warning (avoids breaking first-run onboarding while the maintainer hasn't yet pinned a new Tor release) A mismatch from a source that DID respond is always fatal — only the "no source reachable" case falls back to HTTPS-only. This is the "have cake and eat it" pattern: real users see no new failure modes during torproject.org outages, but MITM/compromise attacks still fail because the downloaded digest can't match what BOTH the upstream and the baked-in list report. Currently the digest file ships with placeholder values for the current Tor URLs (those URLs are already stale on torproject.org too). A follow-up commit can populate real digests when a stable Tor release is selected; until then the HTTPS-only warning fires and onboarding still works. Tests (82 total, all passing): test_openmhz_redirect_ssrf.py (5 tests) — #205 test_infonet_status_verify_gate.py (2 tests) — #207 test_overflights_clamp.py (5 tests) — #202 test_meshtastic_callsign_optout.py (3 tests) — #203 test_kiwisdr_fallback.py (6 tests) — #206 test_merkle_cache.py (6 tests) — #208 test_tor_bundle_verification.py (6 tests) — #201 test_control_surface_auth.py (extended) — #211, #213, #214 + all previous security tests (CCTV redirect, GDELT https, sentinel cache, crowdthreat opt-in, third-party fetcher gates, control surface auth) continue to pass. Pre-existing test infrastructure issue with SHARED_EXECUTOR teardown in the broader sweep exists on main too (verified) — not introduced by this PR. Credit: @tg12 reported every one of these with accurate line citations and the recommended fixes that informed this implementation. Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
107 lines
4.6 KiB
Python
107 lines
4.6 KiB
Python
"""Regression coverage for operator-only control surfaces."""
|
|
|
|
import pytest
|
|
|
|
|
|
@pytest.mark.parametrize(
|
|
("method", "path", "payload"),
|
|
[
|
|
("get", "/api/wormhole/identity", None),
|
|
("post", "/api/wormhole/identity/bootstrap", {}),
|
|
("post", "/api/wormhole/gate/enter", {"gate_id": "general-talk"}),
|
|
("post", "/api/wormhole/gate/leave", {"gate_id": "general-talk"}),
|
|
("post", "/api/wormhole/sign", {"event_type": "gate_event", "payload": {"ok": True}}),
|
|
("post", "/api/wormhole/gate/key/rotate", {"gate_id": "general-talk", "reason": "test"}),
|
|
(
|
|
"post",
|
|
"/api/wormhole/gate/key/grant",
|
|
{
|
|
"gate_id": "general-talk",
|
|
"recipient_node_id": "node-test",
|
|
"recipient_dh_pub": "dh-test",
|
|
},
|
|
),
|
|
("post", "/api/wormhole/gate/persona/create", {"gate_id": "general-talk", "label": "test"}),
|
|
(
|
|
"post",
|
|
"/api/wormhole/gate/persona/activate",
|
|
{"gate_id": "general-talk", "persona_id": "persona-test"},
|
|
),
|
|
("post", "/api/wormhole/gate/persona/clear", {"gate_id": "general-talk"}),
|
|
(
|
|
"post",
|
|
"/api/wormhole/gate/persona/retire",
|
|
{"gate_id": "general-talk", "persona_id": "persona-test"},
|
|
),
|
|
(
|
|
"post",
|
|
"/api/wormhole/gate/message/sign-encrypted",
|
|
{
|
|
"gate_id": "general-talk",
|
|
"epoch": 1,
|
|
"ciphertext": "ciphertext",
|
|
"nonce": "nonce",
|
|
"format": "mls1",
|
|
"envelope_hash": "hash",
|
|
},
|
|
),
|
|
("post", "/api/wormhole/gate/message/compose", {"gate_id": "general-talk", "plaintext": "hello"}),
|
|
("post", "/api/wormhole/sign-raw", {"message": "raw"}),
|
|
("post", "/api/wormhole/gate/state/export", {"gate_id": "general-talk"}),
|
|
("post", "/api/wormhole/gate/proof", {"gate_id": "general-talk"}),
|
|
("post", "/api/wormhole/connect", {}),
|
|
("post", "/api/layers", {"layers": {"viirs_nightlights": True}}),
|
|
("post", "/api/ais/feed", {"msgs": []}),
|
|
# Added in post-#227 gap audit:
|
|
# /api/wormhole/join also calls bootstrap_wormhole_identity() — same
|
|
# identity-takeover surface as /identity/bootstrap. PR #227 hardened
|
|
# the latter but missed the former.
|
|
("post", "/api/wormhole/join", {}),
|
|
# /api/sigint/transmit relays APRS-IS packets over radio using
|
|
# operator-supplied credentials. Any caller who reaches this endpoint
|
|
# could transmit on the operator's authority. Must be local-only.
|
|
(
|
|
"post",
|
|
"/api/sigint/transmit",
|
|
{
|
|
"callsign": "N0CALL",
|
|
"passcode": "12345",
|
|
"target": "NOCALL",
|
|
"message": "test",
|
|
},
|
|
),
|
|
# Issue #198 (tg12, May 17): three gate introspection GETs leak the
|
|
# operator's active persona, persona inventory, and key status for
|
|
# any gate_id an anonymous caller knows. Defeats the unlinkability
|
|
# property documented in the privacy threat model.
|
|
("get", "/api/wormhole/gate/general-talk/identity", None),
|
|
("get", "/api/wormhole/gate/general-talk/personas", None),
|
|
("get", "/api/wormhole/gate/general-talk/key", None),
|
|
# Issue #211 (tg12): /api/thermal/verify fans out into an expensive
|
|
# STAC search + remote SWIR raster reads. Unauthenticated abuse
|
|
# could burn Sentinel-Hub quota and outbound bandwidth.
|
|
("get", "/api/thermal/verify?lat=0&lng=0&radius_km=10", None),
|
|
# Issue #213 (tg12): /api/radio/openmhz/calls/{sys_name} — rotating
|
|
# sys_name bypasses the 20s cache and hammers OpenMHZ. Risks an
|
|
# IP-ban for the project.
|
|
("get", "/api/radio/openmhz/calls/abc", None),
|
|
# Issue #214 (tg12): /api/radio/openmhz/audio — anonymous bandwidth
|
|
# relay through the backend. 60/minute rate limit is not enough on
|
|
# a streaming endpoint.
|
|
("get", "/api/radio/openmhz/audio?url=https%3A%2F%2Fmedia.openmhz.com%2Faudio%2Fabc.mp3", None),
|
|
],
|
|
)
|
|
def test_remote_control_surface_rejects_without_local_operator_or_admin(
|
|
remote_client, method, path, payload
|
|
):
|
|
request = getattr(remote_client, method)
|
|
response = request(path, json=payload) if payload is not None else request(path)
|
|
|
|
assert response.status_code == 403
|
|
|
|
|
|
def test_remote_agent_actions_poll_rejects_without_local_operator_or_admin(remote_client):
|
|
response = remote_client.get("/api/ai/agent-actions")
|
|
|
|
assert response.status_code == 403
|