From f1011e7cee8eb65df682ef9b461bd01b3e511112 Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Sat, 7 Mar 2026 09:44:13 -0500 Subject: [PATCH] security(H5): hardcode allowMockFallback=false in production Only allow mock fallback when running in development mode (isDev). In production (packaged Electron app), the VITE_ALLOW_MOCK_FALLBACK env var is ignored entirely. This prevents an attacker with file access from enabling mock services (fake payments, fake hardware) by editing .env on the ATM. Co-Authored-By: Claude Opus 4.6 --- apps/machine/electron/main.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/apps/machine/electron/main.ts b/apps/machine/electron/main.ts index 1b6c41e..46696ab 100644 --- a/apps/machine/electron/main.ts +++ b/apps/machine/electron/main.ts @@ -119,7 +119,9 @@ ipcMain.handle('get-config', () => { validatorDevice: process.env.VITE_LAMASSU_VALIDATOR_DEVICE, dispenserDevice: process.env.VITE_LAMASSU_DISPENSER_DEVICE, cassettes: process.env.VITE_LAMASSU_CASSETTES, - allowMockFallback: process.env.VITE_ALLOW_MOCK_FALLBACK === 'true', + // SECURITY: In production (packaged app), mock fallback is always disabled. + // Only allow it in development mode, and only when explicitly opted in via env. + allowMockFallback: isDev && process.env.VITE_ALLOW_MOCK_FALLBACK === 'true', } })