feat(security): harden canvas server with auth, rate-limiting, and validation

- Add security.ts: helmet, CORS allowlist, timing-safe API key auth, prototype
  pollution guard, Mermaid input limits, rate limiting (general/destructive/burst)
- WS auth challenge-response with 5 s timeout and close code 4001
- Fix sync crash: array check before logger access (500 → 400)
- Fix sync/v2: validate element type before write (invalid → 400)
- Upgrade zod 3.22.4 → 3.25.5 (fixes ERR_PACKAGE_PATH_NOT_EXPORTED on startup)
- Extract ElementSharedFieldsSchema; move VALID_ELEMENT_TYPES to module level
- Docker: resource limits, .dockerignore hardening
- Add .project-hooks/pre-commit; expand test coverage (369 tests)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
newblacc
2026-03-29 16:06:04 +02:00
co-authored by Claude Sonnet 4.6
parent a1977d86f9
commit 5539235004
29 changed files with 1287 additions and 664 deletions
+6 -1
View File
@@ -137,11 +137,16 @@ interface SyncResponse {
}
function canvasHeaders(extra?: Record<string, string>): Record<string, string> {
return {
const headers: Record<string, string> = {
'Content-Type': 'application/json',
'X-Tenant-Id': dbGetActiveTenantId(),
...extra
};
// Forward API key to canvas when auth is enabled — required for two-service
// Docker deployments where canvas runs with EXCALIDRAW_API_KEY set.
const apiKey = process.env.EXCALIDRAW_API_KEY;
if (apiKey) headers['X-API-Key'] = apiKey;
return headers;
}
// Helper functions to sync with Express server (canvas)