Files
upaas/TODO.md
T
clawbot f1dfd382a4 Reject path traversal in deploy log download handler (closes #177)
The deploy-log download handler passed a request-derived path to
http.ServeFile, which gosec flags as G703 (path traversal via taint).
The handler now opens the log through an os.Root confined to the deploy
log directory, so any escaping path is rejected at runtime (404) and the
file is streamed with http.ServeContent. A regression test plants a
sentinel outside the log dir and asserts the traversal is refused and its
contents never served; removing the guard makes that test fail. No
//nolint used.

Model: opus-4-8
2026-09-22 11:01:07 +02:00

2.5 KiB

Workflow

  • branch (from main)
  • do the work in Next Step
  • move Next Step to the top of Completed Steps
  • move the top item of Future Steps into Next Step
  • commit (TODO.md changes in the same commit as the work)
  • merge to main if the branch is not protected, otherwise open a PR
  • push

Status

1.0+. Tagged 1.0.0 on 2026-02-26; 8 commits on main since. make check is green as of the golangci-lint v2.12.2 update.

Next Step

Confirm .gitea/workflows/check.yml gates merges on make check so main cannot regress.

Completed Steps

  • 2026-09-22: Added .prettierignore so make fmt no longer rewrites the vendored static/js/alpine.min.js bundle (#185).
  • 2026-09-22: Fixed the gosec G703 path-traversal finding in the deploy log download handler by verifying the resolved path stays within the deploy log directory before serving, returning 404 on escape (#177).
  • 2026-09-09: Fixed four deployability blockers found by QA: CSRF origin check over plain HTTP (UPAAS_PLAINTEXT_HTTP, #189), pulling the git image when absent (#190), the env-var editor CSRF token lookup (#191), and the port-mapping delete form's CSRF field (#192).
  • 2026-08-07: Updated golangci-lint to v2.12.2 (canonical .golangci.yml, Dockerfile lint stage pin, script/bootstrap release-archive pins) and fixed all resulting lint findings (noctx, gosec, goconst, lll, dupl, nolintlint); make check green.
  • 2026-07-07 Adopted scripts-to-rule-them-all: script/ entrypoints, Makefile shims, README Entrypoints section
  • 2026-03-11: Monolithic env var editing with bulk save (#158).
  • 2026-03-10: Webhook event history UI page (#164); added missing Makefile docker and hooks targets plus test timeout (#159); notification settings passed from create form (#160).
  • 2026-03-03: REPO_POLICIES compliance file set added (#155).
  • 2026-03-01: Module path changed to sneak.berlin/go/upaas (#143); Dockerfile split into lint and build stages with forced lint execution (#152, #154).
  • 2026-02-26: 1.0.0 tagged; dashboard CSRFField crash fixed (#146).
  • 1.0 audit bug fixes (#120-#125): deferred rollback on commit error, deployment log size cap, error path rendering, docker-compose bind mount, domain type refactor.
  • CI simplified to docker build only (#130).
  • 2025-12-29 onward: core PaaS built out: deploys with real-time build log streaming, container start/stop/restart and logs, TCP/UDP port mapping, Alpine.js UI, Slack notifications, ULID app IDs, session handling.

Future Steps

  • Resume feature work only after main is green.