Fix HIGH findings from 2026-09-24 maintenance review
- nginx: resolve real client IP through Cloudflare -> NPM so rate limits are per client instead of shared across all users - Bump vulnerable Python deps (PyJWT auth bypass, anyio, starlette via fastapi 0.141.1, cryptography, python-multipart, Mako); pin PyMySQL 1.1.2 since 1.2.x breaks SQLAlchemy 2.0.35's aiomysql ping - Backend: python 3.12.14-slim, apt-get upgrade, drop unneeded build deps - Frontend: nginx 1.30.5-alpine (stable) + apk upgrade - MySQL 8.0.40 (EOL) -> 8.4.11 LTS; add healthcheck start_period so slow startups (e.g. data upgrades) don't abort dependent services - Add maintenance review report Co-Authored-By: Claude Opus 5.5 <[email protected]>
This commit is contained in:
1 parent
8e92ae6073
commit
3170c7f4eb
6 files changed
+260
-10
No files matched your search
+3
-1
@@ -10,7 +10,9 @@ COPY . .
|
||||
RUN npm run build
|
||||
|
||||
# Stage 2: Serve with nginx
|
||||
FROM nginx:1.29.6-alpine
|
||||
FROM nginx:1.30.5-alpine
|
||||
|
||||
RUN apk upgrade --no-cache
|
||||
|
||||
COPY --from=builder /app/dist /usr/share/nginx/html
|
||||
COPY nginx.conf /etc/nginx/conf.d/default.conf
|
||||
|
||||
@@ -1,3 +1,33 @@
|
||||
# Real client IP — traffic arrives via Cloudflare → NPM (172.16.22.21), so
|
||||
# $remote_addr would otherwise be NPM for every request and rate limits would
|
||||
# be shared by all clients. Walk X-Forwarded-For right-to-left past trusted hops.
|
||||
# Cloudflare ranges: https://www.cloudflare.com/ips/
|
||||
set_real_ip_from 172.16.22.21;
|
||||
set_real_ip_from 173.245.48.0/20;
|
||||
set_real_ip_from 103.21.244.0/22;
|
||||
set_real_ip_from 103.22.200.0/22;
|
||||
set_real_ip_from 103.31.4.0/22;
|
||||
set_real_ip_from 141.101.64.0/18;
|
||||
set_real_ip_from 108.162.192.0/18;
|
||||
set_real_ip_from 190.93.240.0/20;
|
||||
set_real_ip_from 188.114.96.0/20;
|
||||
set_real_ip_from 197.234.240.0/22;
|
||||
set_real_ip_from 198.41.128.0/17;
|
||||
set_real_ip_from 162.158.0.0/15;
|
||||
set_real_ip_from 104.16.0.0/13;
|
||||
set_real_ip_from 104.24.0.0/14;
|
||||
set_real_ip_from 172.64.0.0/13;
|
||||
set_real_ip_from 131.0.72.0/22;
|
||||
set_real_ip_from 2400:cb00::/32;
|
||||
set_real_ip_from 2606:4700::/32;
|
||||
set_real_ip_from 2803:f800::/32;
|
||||
set_real_ip_from 2405:b500::/32;
|
||||
set_real_ip_from 2405:8100::/32;
|
||||
set_real_ip_from 2a06:98c0::/29;
|
||||
set_real_ip_from 2c0f:f248::/32;
|
||||
real_ip_header X-Forwarded-For;
|
||||
real_ip_recursive on;
|
||||
|
||||
# Rate limiting zones — included inside http{} block
|
||||
limit_req_zone $binary_remote_addr zone=auth_limit:10m rate=5r/m;
|
||||
limit_req_zone $binary_remote_addr zone=tv_limit:10m rate=10r/m;
|
||||
|
||||
Reference in new issue
Block a user