T05 · Unauthorized Access and Privilege Escalation
- Location
server.py:23- Finding
Unauthenticated HTTP Interface Exposes Private Manuscript Data and Modification Operations
- Content
View full analysis
- Remediation
View remediation
` header for every endpoint other than a minimal health check. 3. Compare credentials using a constant-time comparison function. 4. Store the token in a file readable only by the owning user, such as mode `0600`. 5. Validate browser `Origin` headers against an explicit allowlist and reject unexpected origins. 6. Require `Content-Type: application/json` for JSON endpoints. 7. Separate read, write, delete, and export permissions where practical. 8. Return generic errors that do not expose private content or internal paths. 9. Prefer a Unix-domain socket with restrictive filesystem permissions if the service is intended exclusively for local clients. 10. Add automated tests confirming that unauthenticated requests cannot list, read, modify, delete, or export content. ]]>
