Require secrets via headers only: drop ?key= and ?password= query fallbacks (#137, #141)
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped

Query strings leak into Traefik access logs, browser history, and Referer
headers. Admin key is now accepted only via X-Admin-Key; paste and can
passwords only via X-Paste-Password (or the POST unlock form). Tests
updated; new negative cases assert 401 for the query paths.
This commit is contained in:
fen
2026-09-09 23:23:10 -05:00
parent 98222e762f
commit d013f3965f
8 changed files with 29 additions and 29 deletions
+4 -5
View File
@@ -160,13 +160,12 @@ func HandleResetAdminKey(dbPath string) {
}
// adminKeyOK reports whether the request carries the correct admin key via
// X-Admin-Key header or ?key=. Constant-time compare; failures and successes
// are both logged (#40).
// the X-Admin-Key header only. The ?key= query fallback was removed (#137):
// query strings land in access logs, browser history, and Referer headers,
// so accepting the key there leaked the admin secret. Constant-time compare;
// failures and successes are both logged (#40).
func (a *apiServer) adminKeyOK(r *http.Request, key string) bool {
given := r.Header.Get("X-Admin-Key")
if given == "" {
given = r.URL.Query().Get("key")
}
return subtle.ConstantTimeCompare([]byte(given), []byte(key)) == 1
}