fix: high-severity findings from code audit
- backend/photos: whitelist sortable columns instead of getattr(Photo, sort). Previously any client-supplied string was passed to SQLAlchemy, exposing every Photo attribute (filepath, file_hash, etc.) as a sort target. - App: move the auto-show-right-sidebar logic out of the render body and into a useEffect. The previous version called setState during render, causing extra re-render passes the audit caught. - types/photo: add added_at and tighten folder_id from optional to nullable. Drops a (photo as any).added_at cast in Timeline. - constants/colorLabels: extract a single COLOR_LABEL_OPTIONS used by FilterBar, RightSidebar, and PhotoInfoPanel. filterStore re-exports the ColorLabel type so existing imports keep working. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -162,8 +162,17 @@ async def list_photos(
|
||||
if filters:
|
||||
query = query.where(and_(*filters))
|
||||
|
||||
# Apply sorting
|
||||
sort_column = getattr(Photo, sort, Photo.taken_at)
|
||||
# Apply sorting. The sort field is whitelisted so a malicious client
|
||||
# can't pass an arbitrary column name (e.g. "filepath" leaks paths or
|
||||
# any other Photo attribute the model exposes).
|
||||
SORT_WHITELIST = {
|
||||
"taken_at": Photo.taken_at,
|
||||
"added_at": Photo.added_at,
|
||||
"filename": Photo.filename,
|
||||
"file_size": Photo.file_size,
|
||||
"rating": Photo.rating,
|
||||
}
|
||||
sort_column = SORT_WHITELIST.get(sort, Photo.taken_at)
|
||||
if order == "desc":
|
||||
query = query.order_by(sort_column.desc())
|
||||
else:
|
||||
|
||||
Reference in New Issue
Block a user