Require secrets via headers only: drop ?key= and ?password= query fallbacks (#137, #141)
CI / test (pull_request) Successful in 28s
CI / docker (pull_request) Skipped

Query strings leak into Traefik access logs, browser history, and Referer
headers. Admin key is now accepted only via X-Admin-Key; paste and can
passwords only via X-Paste-Password (or the POST unlock form). Tests
updated; new negative cases assert 401 for the query paths.
This commit is contained in:
fen
2026-09-09 23:23:10 -05:00
parent 98222e762f
commit d013f3965f
8 changed files with 29 additions and 29 deletions
+5 -6
View File
@@ -267,18 +267,17 @@ func (a *apiServer) handleGetPaste(w http.ResponseWriter, r *http.Request) {
return
}
if row.PasswordHash.Valid {
// #81: every password verification (header, query param, or empty)
// goes through the same per-IP+paste unlock limiter as the POST form
// path, so brute-force via GET ?password= or X-Paste-Password gets 429.
// #81/#141: every password verification (header or empty) goes
// through the same per-IP+paste unlock limiter as the POST form
// path, so brute-force via X-Paste-Password gets 429. The
// ?password= query fallback was removed (#141): query strings
// leak into access logs, browser history, and Referer headers.
if !rateLimitUnlock(row.ID, r) {
writeRateLimited(w, 60)
return
}
// require password via header or query
pw := r.Header.Get("X-Paste-Password")
if pw == "" {
pw = r.URL.Query().Get("password")
}
if pw == "" || !store.CheckPassword(row.PasswordHash.String, pw) {
writeErr(w, 401, "password required")
return