Security Audit Fixes: Session fixation prevention, SameSite cookies, audit log redaction, backup integrity, Docker hardening, error sanitization, rate limiting, trusted proxies, and config hardening

This commit is contained in:
backup 2026-09-03 23:55:25 -05:00
commit b587fb87a9
18 changed files with 987 additions and 87 deletions

View file

@ -72,24 +72,22 @@ func (h *TraefikAPIHandler) cached(c *gin.Context, path string, fn func() (inter
data, err := fn()
if err != nil {
if traefik.IsNotFound(err) {
c.JSON(http.StatusNotFound, gin.H{"error": "not found", "detail": err.Error()})
c.JSON(http.StatusNotFound, gin.H{"error": "resource not found"})
return
}
if traefik.IsUnauthorized(err) {
// 401 from Traefik is upstream problem, not caller's auth failure -> 502
c.JSON(http.StatusBadGateway, gin.H{"error": "traefik API unauthorized - check if Traefik API is enabled or on a private entrypoint", "detail": err.Error()})
c.JSON(http.StatusBadGateway, gin.H{"error": "traefik API unauthorized - check if Traefik API is enabled or on a private entrypoint"})
return
}
if apiErr, ok := err.(*traefik.APIError); ok {
// Preserve upstream status for 5xx, else 502
status := apiErr.StatusCode
if status < 400 || status >= 600 {
status = http.StatusBadGateway
}
c.JSON(status, gin.H{"error": apiErr.Message, "detail": apiErr.Body})
c.JSON(status, gin.H{"error": apiErr.Message})
return
}
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
c.JSON(http.StatusInternalServerError, gin.H{"error": "upstream API error"})
return
}