fix: high-severity findings from code audit

- backend/photos: whitelist sortable columns instead of getattr(Photo, sort).
  Previously any client-supplied string was passed to SQLAlchemy, exposing
  every Photo attribute (filepath, file_hash, etc.) as a sort target.
- App: move the auto-show-right-sidebar logic out of the render body and
  into a useEffect. The previous version called setState during render,
  causing extra re-render passes the audit caught.
- types/photo: add added_at and tighten folder_id from optional to nullable.
  Drops a (photo as any).added_at cast in Timeline.
- constants/colorLabels: extract a single COLOR_LABEL_OPTIONS used by
  FilterBar, RightSidebar, and PhotoInfoPanel. filterStore re-exports the
  ColorLabel type so existing imports keep working.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-04-08 20:18:19 +02:00
parent 07b9660e92
commit 749e836617
9 changed files with 50 additions and 42 deletions

View File

@@ -162,8 +162,17 @@ async def list_photos(
if filters:
query = query.where(and_(*filters))
# Apply sorting
sort_column = getattr(Photo, sort, Photo.taken_at)
# Apply sorting. The sort field is whitelisted so a malicious client
# can't pass an arbitrary column name (e.g. "filepath" leaks paths or
# any other Photo attribute the model exposes).
SORT_WHITELIST = {
"taken_at": Photo.taken_at,
"added_at": Photo.added_at,
"filename": Photo.filename,
"file_size": Photo.file_size,
"rating": Photo.rating,
}
sort_column = SORT_WHITELIST.get(sort, Photo.taken_at)
if order == "desc":
query = query.order_by(sort_column.desc())
else: