Commit 5b33b58
security: add authentication and origin validation to WebSocket (#414)
* security: add authentication and origin validation to WebSocket
Add session authentication and origin header validation to the
WebSocket endpoint to prevent unauthorized access.
- Add checkWebSocketOrigin() for origin header validation
- Add AuthenticatedWebSocketHandler() requiring valid session
- Update main.go to use authenticated handler
- Support ALLOWED_ORIGIN and FRONTEND_ORIGIN_DEV env vars
- Allow localhost in development mode
- Log rejected connections for security monitoring
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
* Fix origin comparison security issue and improve ENV handling
Addresses review feedback:
1. Security fix: Replace insecure substring check with proper hostname
comparison. Previously `strings.Contains(origin, host)` could be
bypassed by an attacker using "malicious-example.com" to match
"example.com". Now parses the origin URL and compares hostnames
exactly.
2. Add getEnv() helper that returns "development" by default, making
the environment check clearer and more maintainable.
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>1 parent dbeffcf commit 5b33b58
2 files changed
Lines changed: 51 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
11 | 12 | | |
12 | 13 | | |
13 | 14 | | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
14 | 24 | | |
15 | 25 | | |
16 | 26 | | |
| |||
21 | 31 | | |
22 | 32 | | |
23 | 33 | | |
24 | | - | |
| 34 | + | |
25 | 35 | | |
26 | 36 | | |
27 | 37 | | |
| |||
73 | 83 | | |
74 | 84 | | |
75 | 85 | | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
76 | 125 | | |
77 | 126 | | |
78 | 127 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
| 130 | + | |
131 | 131 | | |
132 | 132 | | |
133 | 133 | | |
| |||
0 commit comments