more hardening
This commit is contained in:
parent
26a7dd821c
commit
fac130c49c
3 changed files with 21 additions and 9 deletions
8
crud.py
8
crud.py
|
|
@ -15,7 +15,7 @@ from .models import (
|
||||||
GetNWC,
|
GetNWC,
|
||||||
NWCNewBudget
|
NWCNewBudget
|
||||||
)
|
)
|
||||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_msats, assert_valid_positive_int
|
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_expiration_seconds, assert_valid_msats, assert_valid_positive_int
|
||||||
|
|
||||||
db = Database("ext_nwcprovider")
|
db = Database("ext_nwcprovider")
|
||||||
|
|
||||||
|
|
@ -26,7 +26,7 @@ async def create_nwc(data: CreateNWCKey) -> NWCKey:
|
||||||
assert_valid_pubkey(data.pubkey)
|
assert_valid_pubkey(data.pubkey)
|
||||||
assert_valid_wallet_id(data.wallet)
|
assert_valid_wallet_id(data.wallet)
|
||||||
assert_sane_string(data.description)
|
assert_sane_string(data.description)
|
||||||
assert_valid_timestamp_seconds(data.expires_at)
|
assert_valid_expiration_seconds(data.expires_at)
|
||||||
for permission in data.permissions:
|
for permission in data.permissions:
|
||||||
assert_sane_string(permission)
|
assert_sane_string(permission)
|
||||||
|
|
||||||
|
|
@ -77,7 +77,7 @@ async def get_wallet_nwcs(data: GetWalletNWC) -> List[NWCKey]:
|
||||||
|
|
||||||
# hardening #
|
# hardening #
|
||||||
assert_valid_wallet_id(data.wallet)
|
assert_valid_wallet_id(data.wallet)
|
||||||
assert_valid_timestamp_seconds(expires)
|
assert_valid_expiration_seconds(expires)
|
||||||
# ## #
|
# ## #
|
||||||
|
|
||||||
return await db.fetchall(
|
return await db.fetchall(
|
||||||
|
|
@ -98,7 +98,7 @@ async def get_nwc(data: GetNWC) -> Optional[NWCKey]:
|
||||||
|
|
||||||
# hardening #
|
# hardening #
|
||||||
assert_valid_pubkey(data.pubkey)
|
assert_valid_pubkey(data.pubkey)
|
||||||
assert_valid_timestamp_seconds(expires)
|
assert_valid_expiration_seconds(expires)
|
||||||
# ## #
|
# ## #
|
||||||
|
|
||||||
# expires_at = 0 means it never expires
|
# expires_at = 0 means it never expires
|
||||||
|
|
|
||||||
18
paranoia.py
18
paranoia.py
|
|
@ -80,12 +80,24 @@ def assert_valid_wallet_id(v:str):
|
||||||
def assert_valid_timestamp_seconds(v:int):
|
def assert_valid_timestamp_seconds(v:int):
|
||||||
if not ENABLE_HARDENING:
|
if not ENABLE_HARDENING:
|
||||||
return
|
return
|
||||||
assert_valid_int(v)
|
assert_valid_positive_int(v)
|
||||||
if v < 0 and v != -1:
|
|
||||||
panic("timestamp is negative")
|
|
||||||
if v > 2**31:
|
if v > 2**31:
|
||||||
panic("timestamp is too high")
|
panic("timestamp is too high")
|
||||||
|
|
||||||
|
|
||||||
|
# Check if valid expiration in seconds
|
||||||
|
def assert_valid_expiration_seconds(v: int):
|
||||||
|
if not ENABLE_HARDENING:
|
||||||
|
return
|
||||||
|
assert_valid_int(v)
|
||||||
|
if v == -1:
|
||||||
|
return
|
||||||
|
if v < 0:
|
||||||
|
panic("expiration is invalid")
|
||||||
|
if v > 2**31:
|
||||||
|
panic("expiration is too high")
|
||||||
|
|
||||||
|
|
||||||
# Check if string is within sane parameters
|
# Check if string is within sane parameters
|
||||||
def assert_sane_string(v:str):
|
def assert_sane_string(v:str):
|
||||||
if not ENABLE_HARDENING:
|
if not ENABLE_HARDENING:
|
||||||
|
|
|
||||||
4
tasks.py
4
tasks.py
|
|
@ -22,7 +22,7 @@ from .execution_queue import execution_queue
|
||||||
from .models import NWCKey, TrackedSpendNWC, GetNWC
|
from .models import NWCKey, TrackedSpendNWC, GetNWC
|
||||||
from .nwcp import NWCServiceProvider
|
from .nwcp import NWCServiceProvider
|
||||||
from .permission import nwc_permissions
|
from .permission import nwc_permissions
|
||||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_msats, assert_valid_positive_int, assert_valid_bolt11, assert_valid_sha256
|
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_expiration_seconds, assert_valid_msats, assert_valid_positive_int, assert_valid_bolt11, assert_valid_sha256
|
||||||
|
|
||||||
|
|
||||||
async def _check(nwc: Optional[NWCKey], method: str) -> Optional[Dict]:
|
async def _check(nwc: Optional[NWCKey], method: str) -> Optional[Dict]:
|
||||||
|
|
@ -257,7 +257,7 @@ async def _on_make_invoice(
|
||||||
if description_hash:
|
if description_hash:
|
||||||
assert_valid_sha256(description_hash)
|
assert_valid_sha256(description_hash)
|
||||||
if expiry:
|
if expiry:
|
||||||
assert_valid_timestamp_seconds(expiry)
|
assert_valid_expiration_seconds(expiry)
|
||||||
# ## #
|
# ## #
|
||||||
|
|
||||||
payment = await create_invoice(
|
payment = await create_invoice(
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue