Micron Document
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
| SparkN0de-git | SparkN0de |
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

Node / ReticulumProjects / MeshChatX.git / files / meshchatx / src / backend / websocket_config_guard.py

Displaying Raw • Download


meshchatx/src/backend/websocket_config_guard.py eca1486f3c00aeb0b97d7199ccc03b929d9619f1 (eca1486f) Text, 962 B

T8b949e# SPDX-License-Identifier: 0BSD

T8b949e"""WebSocket config update guards.

Settings that change the HTTP security boundary must go through CSRF-protected
HTTP endpoints, not the unauthenticated ``config.set`` WebSocket message.
"""

Tff7b72from T7ee787__future__ Tff7b72import Te6edf3annotations

Tff7b72import T7ee787logging

Te6edf3logger Tff7b72= Te6edf3loggingTff7b72.Td2a8ffgetLoggerTb4b4b4(Tff7b72__name__Tb4b4b4)

Te6edf3WEBSOCKET_CONFIG_DENYLIST Tff7b72= Tffa657frozensetTb4b4b4(
Tb4b4b4{
Ta5d6ff"Ta5d6ffauth_enabledTa5d6ff"Tb4b4b4,
Ta5d6ff"Ta5d6ffauth_password_hashTa5d6ff"Tb4b4b4,
Tb4b4b4}Tb4b4b4,
Tb4b4b4)


Tff7b72def Td2a8ffsanitize_websocket_config_updateTb4b4b4(Te6edf3configTb4b4b4: Tffa657objectTb4b4b4) Tff7b72-Tff7b72> Tffa657dictTb4b4b4:
T8b949e"""Return a copy of *config* with security-sensitive keys removed."""
Tff7b72if Tff7b72not Tffa657isinstanceTb4b4b4(Te6edf3configTb4b4b4, Tffa657dictTb4b4b4)Tb4b4b4:
Tff7b72return Tb4b4b4{Tb4b4b4}

Te6edf3sanitized Tff7b72= Tffa657dictTb4b4b4(Te6edf3configTb4b4b4)
Te6edf3removed Tff7b72= Tb4b4b4[Te6edf3key Tff7b72for Te6edf3key Tff7b72in Te6edf3WEBSOCKET_CONFIG_DENYLIST Tff7b72if Te6edf3key Tff7b72in Te6edf3sanitizedTb4b4b4]
Tff7b72for Te6edf3key Tff7b72in Te6edf3removedTb4b4b4:
Tff7b72del Te6edf3sanitizedTb4b4b4[Te6edf3keyTb4b4b4]

Tff7b72if Te6edf3removedTb4b4b4:
Te6edf3loggerTff7b72.Td2a8ffwarningTb4b4b4(
Ta5d6ff"Ta5d6ffIgnored security-sensitive config keys over WebSocket: Tffd700%sTa5d6ff"Tb4b4b4,
Ta5d6ff"Ta5d6ff, Ta5d6ff"Tff7b72.Td2a8ffjoinTb4b4b4(Tffa657sortedTb4b4b4(Te6edf3removedTb4b4b4)Tb4b4b4)Tb4b4b4,
Tb4b4b4)

Tff7b72return Te6edf3sanitized


──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────