Refuse host entries that are not a host name or an IP address
check / check (push) Failing after 3s

An entry of allowlist_hosts or referer_blocklist that is neither a host
name (letters, digits, hyphens and dots, with at most one leading dot)
nor an IP address now aborts startup naming the setting and the entry,
so a `*.` wildcard or a port no longer loads and silently matches
nothing. README.md, configs/config.example.yml and the TODO.md entry now
say the Referer check comes before the signature, the cache and the
upstream fetch, since maintenance mode answers first; the example config
says the list does not cover the login and generator pages.

Model: opus-5-5
This commit is contained in:
2026-10-04 19:09:02 +00:00
parent e1737f497c
commit a2effe1e27
4 changed files with 51 additions and 42 deletions
+12 -10
View File
@@ -31,6 +31,18 @@ P2: security: per-IP rate limiting on the image routes
# Completed Steps
- 2026-10-04 referer blocklist (closes #90): `referer_blocklist`
(`PIXA_REFERER_BLOCKLIST`) lists hosts, written and matched as for
`allowlist_hosts` with the same matcher; an entry of either list that is
neither a host name (letters, digits, hyphens and dots, with at most one
leading dot) nor an IP address, such as one with a port or a `*.` wildcard,
aborts startup naming the setting and the entry. Both image routes refuse a
request whose `Referer` names a listed host with 403 and a JSON error before
the signature, the cache and the upstream fetch, so it fetches nothing and is
refused whether or not the image is cached. A request with no `Referer`, or
one that does not parse as a URL with a host, is served, so the list is easily
got around; `README.md` and `configs/config.example.yml` say so. It does not
apply to the login and generator pages.
- 2026-10-04 fewer files in the repository root (closes #97):
`config.example.yml` moved unchanged to `configs/config.example.yml`, and
`README.md`, the comments in `internal/config/config.go` and the startup error
@@ -47,16 +59,6 @@ P2: security: per-IP rate limiting on the image routes
for it, and the default `db_url` turns on WAL mode with
`_pragma=journal_mode(WAL)`. The old default's `_journal_mode=WAL` is not a
parameter the driver reads, so the database was never in WAL mode.
- 2026-10-04 referer blocklist (closes #90): `referer_blocklist`
(`PIXA_REFERER_BLOCKLIST`) lists hosts, written and matched as for
`allowlist_hosts` with the same matcher; an entry that is not a bare host
aborts startup naming the setting and the entry. Both image routes refuse a
request whose `Referer` names a listed host with 403 and a JSON error before
anything else is done for it, so it fetches nothing and is refused whether or
not the image is cached. A request with no `Referer`, or one that does not
parse as a URL with a host, is served, so the list is easily got around;
`README.md` and `config.example.yml` say so. It does not apply to the login
and generator pages.
- 2026-10-04 `TestPeriodicReconciliationAdoptsFileThatAppearsAfterStartup`
only passes through a periodic pass (closes #189): it slept for three
eviction intervals before writing its file, and a startup pass still running