security(H5): hardcode allowMockFallback=false in production

Only allow mock fallback when running in development mode (isDev).
In production (packaged Electron app), the VITE_ALLOW_MOCK_FALLBACK
env var is ignored entirely. This prevents an attacker with file
access from enabling mock services (fake payments, fake hardware)
by editing .env on the ATM.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-07 09:44:13 -05:00
commit f1011e7cee

View file

@ -119,7 +119,9 @@ ipcMain.handle('get-config', () => {
validatorDevice: process.env.VITE_LAMASSU_VALIDATOR_DEVICE, validatorDevice: process.env.VITE_LAMASSU_VALIDATOR_DEVICE,
dispenserDevice: process.env.VITE_LAMASSU_DISPENSER_DEVICE, dispenserDevice: process.env.VITE_LAMASSU_DISPENSER_DEVICE,
cassettes: process.env.VITE_LAMASSU_CASSETTES, cassettes: process.env.VITE_LAMASSU_CASSETTES,
allowMockFallback: process.env.VITE_ALLOW_MOCK_FALLBACK === 'true', // SECURITY: In production (packaged app), mock fallback is always disabled.
// Only allow it in development mode, and only when explicitly opted in via env.
allowMockFallback: isDev && process.env.VITE_ALLOW_MOCK_FALLBACK === 'true',
} }
}) })