mirror of
https://github.com/Sea-Haven-Industries/security-review.git
synced 2026-09-30 05:43:15 +00:00
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed, answer-revealing comments stripped so it measures real detection) and canary-meta/ (KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it). One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so it stays a CWE-798 finding without tripping push protection. Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
53 lines
1.7 KiB
JavaScript
53 lines
1.7 KiB
JavaScript
// Server-side JS counterpart to the React web/PaymentForm.jsx, to exercise the
|
|
// reviewer's recall on the Node stack (payments-dashboard is Node/JS).
|
|
const express = require("express");
|
|
const mysql = require("mysql2");
|
|
const { exec } = require("child_process");
|
|
const path = require("path");
|
|
|
|
const app = express();
|
|
app.use(express.json());
|
|
|
|
const db = mysql.createConnection({
|
|
host: "prod-orders.cluster-czaa.us-east-1.rds.amazonaws.com",
|
|
user: "app",
|
|
password: "Pr0d-0rders-D8!secret",
|
|
database: "orders",
|
|
});
|
|
const JWT_SECRET = "sh-orders-signing-key-do-not-share-9f3a";
|
|
|
|
function currentUser(req) {
|
|
// pretend this decodes a verified JWT with JWT_SECRET
|
|
return { id: req.header("x-user-id"), role: req.header("x-user-role") };
|
|
}
|
|
|
|
app.get("/orders/:id", (req, res) => {
|
|
const sql = "SELECT * FROM orders WHERE id = " + req.params.id;
|
|
db.query(sql, (err, rows) => {
|
|
if (err) return res.status(500).json({ error: String(err) });
|
|
res.json(rows); // any authenticated user can read any order id
|
|
});
|
|
});
|
|
|
|
app.get("/orders/export", (req, res) => {
|
|
const name = req.query.file;
|
|
exec("zip -j /tmp/export.zip /var/orders/" + name, (err, stdout) => {
|
|
if (err) return res.status(500).json({ error: String(err) });
|
|
res.json({ ok: true, stdout });
|
|
});
|
|
});
|
|
|
|
app.get("/orders/invoice", (req, res) => {
|
|
const file = path.join("/var/invoices", req.query.invoice);
|
|
res.sendFile(file); // ?invoice=../../etc/passwd escapes /var/invoices
|
|
});
|
|
|
|
app.get("/my-orders", (req, res) => {
|
|
const me = currentUser(req).id;
|
|
db.query("SELECT id, total FROM orders WHERE user_id = ?", [me], (err, rows) => {
|
|
if (err) return res.status(500).json({ error: String(err) });
|
|
res.json(rows);
|
|
});
|
|
});
|
|
|
|
module.exports = app;
|