more hardening
This commit is contained in:
parent
26a7dd821c
commit
fac130c49c
3 changed files with 21 additions and 9 deletions
8
crud.py
8
crud.py
|
|
@ -15,7 +15,7 @@ from .models import (
|
|||
GetNWC,
|
||||
NWCNewBudget
|
||||
)
|
||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_msats, assert_valid_positive_int
|
||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_expiration_seconds, assert_valid_msats, assert_valid_positive_int
|
||||
|
||||
db = Database("ext_nwcprovider")
|
||||
|
||||
|
|
@ -26,7 +26,7 @@ async def create_nwc(data: CreateNWCKey) -> NWCKey:
|
|||
assert_valid_pubkey(data.pubkey)
|
||||
assert_valid_wallet_id(data.wallet)
|
||||
assert_sane_string(data.description)
|
||||
assert_valid_timestamp_seconds(data.expires_at)
|
||||
assert_valid_expiration_seconds(data.expires_at)
|
||||
for permission in data.permissions:
|
||||
assert_sane_string(permission)
|
||||
|
||||
|
|
@ -77,7 +77,7 @@ async def get_wallet_nwcs(data: GetWalletNWC) -> List[NWCKey]:
|
|||
|
||||
# hardening #
|
||||
assert_valid_wallet_id(data.wallet)
|
||||
assert_valid_timestamp_seconds(expires)
|
||||
assert_valid_expiration_seconds(expires)
|
||||
# ## #
|
||||
|
||||
return await db.fetchall(
|
||||
|
|
@ -98,7 +98,7 @@ async def get_nwc(data: GetNWC) -> Optional[NWCKey]:
|
|||
|
||||
# hardening #
|
||||
assert_valid_pubkey(data.pubkey)
|
||||
assert_valid_timestamp_seconds(expires)
|
||||
assert_valid_expiration_seconds(expires)
|
||||
# ## #
|
||||
|
||||
# expires_at = 0 means it never expires
|
||||
|
|
|
|||
18
paranoia.py
18
paranoia.py
|
|
@ -80,12 +80,24 @@ def assert_valid_wallet_id(v:str):
|
|||
def assert_valid_timestamp_seconds(v:int):
|
||||
if not ENABLE_HARDENING:
|
||||
return
|
||||
assert_valid_int(v)
|
||||
if v < 0 and v != -1:
|
||||
panic("timestamp is negative")
|
||||
assert_valid_positive_int(v)
|
||||
if v > 2**31:
|
||||
panic("timestamp is too high")
|
||||
|
||||
|
||||
# Check if valid expiration in seconds
|
||||
def assert_valid_expiration_seconds(v: int):
|
||||
if not ENABLE_HARDENING:
|
||||
return
|
||||
assert_valid_int(v)
|
||||
if v == -1:
|
||||
return
|
||||
if v < 0:
|
||||
panic("expiration is invalid")
|
||||
if v > 2**31:
|
||||
panic("expiration is too high")
|
||||
|
||||
|
||||
# Check if string is within sane parameters
|
||||
def assert_sane_string(v:str):
|
||||
if not ENABLE_HARDENING:
|
||||
|
|
|
|||
4
tasks.py
4
tasks.py
|
|
@ -22,7 +22,7 @@ from .execution_queue import execution_queue
|
|||
from .models import NWCKey, TrackedSpendNWC, GetNWC
|
||||
from .nwcp import NWCServiceProvider
|
||||
from .permission import nwc_permissions
|
||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_msats, assert_valid_positive_int, assert_valid_bolt11, assert_valid_sha256
|
||||
from .paranoia import assert_valid_wallet_id, assert_valid_pubkey, assert_sane_string, assert_valid_timestamp_seconds, assert_valid_expiration_seconds, assert_valid_msats, assert_valid_positive_int, assert_valid_bolt11, assert_valid_sha256
|
||||
|
||||
|
||||
async def _check(nwc: Optional[NWCKey], method: str) -> Optional[Dict]:
|
||||
|
|
@ -257,7 +257,7 @@ async def _on_make_invoice(
|
|||
if description_hash:
|
||||
assert_valid_sha256(description_hash)
|
||||
if expiry:
|
||||
assert_valid_timestamp_seconds(expiry)
|
||||
assert_valid_expiration_seconds(expiry)
|
||||
# ## #
|
||||
|
||||
payment = await create_invoice(
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue