diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..3c2e7c7 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2024-05-24 - [Protect Local Exports from Unauthorized Access] +**Vulnerability:** Saved requests were created in a directory with 0755 permissions, making them readable by any user on the system. +**Learning:** For a local developer tool that inspects and exports potentially sensitive HTTP requests (containing auth tokens, cookies, payloads), exporting them with world-readable permissions poses a local privilege escalation/information disclosure risk. +**Prevention:** Use stricter directory creation permissions (0o700) for paths handling sensitive user exports, ensuring only the owner has access. Redact `Set-Cookie` in exports in addition to `Cookie` and `Authorization` headers. diff --git a/internal/export/export.go b/internal/export/export.go index 7b0e25b..95b50a1 100644 --- a/internal/export/export.go +++ b/internal/export/export.go @@ -21,7 +21,7 @@ import ( const Redacted = "REDACTED" // DefaultRedactHeaders lists headers whose values are hidden on export. -var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key"} +var DefaultRedactHeaders = []string{"Authorization", "Cookie", "Proxy-Authorization", "X-Api-Key", "Set-Cookie"} // skippedInCurl are headers curl sets by itself. var skippedInCurl = map[string]bool{"host": true, "content-length": true, "transfer-encoding": true, "connection": true} @@ -89,7 +89,8 @@ func SaveRequest(dir string, ev events.Event, redact bool) (string, error) { if dir == "" { dir = "." } - if err := os.MkdirAll(dir, 0o755); err != nil { + // Create directory with 0o700 (owner only) to protect saved requests containing sensitive data. + if err := os.MkdirAll(dir, 0o700); err != nil { return "", err } method := cleanName(ev.Request.Method)