chore(release): public-release readiness and security fixes for 1.1.16
Security: - Escape user-supplied values in LDAP filters and DNs (group_ldap.js, user_ldap.js) - Replace Math.random() token/UUID/OTP generation with crypto.randomUUID / crypto.randomInt - Refuse startup when oauth.jwtSecret is missing or placeholder Fixes: - Correct from-address template rendering in email.js Packaging: - Remove private flag and bump version to 1.1.16 Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
@@ -1,7 +1,8 @@
|
||||
'use strict';
|
||||
|
||||
const Table = require('.');
|
||||
const UUID = function b(a){return a?(a^Math.random()*16>>a/4).toString(16):([1e7]+-1e3+-4e3+-8e3+-1e11).replace(/[018]/g,b)};
|
||||
const crypto = require('crypto');
|
||||
const UUID = () => crypto.randomUUID();
|
||||
|
||||
|
||||
class Token extends Table{
|
||||
@@ -110,7 +111,7 @@ class OtpToken extends Token {
|
||||
for (const t of existing) {
|
||||
if (t.is_valid) await t.update({is_valid: false});
|
||||
}
|
||||
const code = String(Math.floor(100000 + Math.random() * 900000));
|
||||
const code = String(crypto.randomInt(100000, 1000000));
|
||||
return this.create({uid, code, method, created_by: uid});
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user