security-review/canary/src/node/orders_api.js
Adam Moussa 094a253c37
feat(canary): add anti-complacency recall-floor corpus + repo skip marker
Adds canary/ (the planted-vuln corpus from the local-only security-review-testbed,
answer-revealing comments stripped so it measures real detection) and canary-meta/
(KEY.md ground truth + CANARY_FLOOR=8, kept OUT of canary/ so detectors never read it).
One provider-pattern secret (sk_live_) was sanitized to a non-provider hardcoded key so
it stays a CWE-798 finding without tripping push protection.

Adds a root .security-review-skip so the org-wide sweep and the local pre-push gate skip
this repo's intentional vuln/fixture content; the nightly sweep scans canary/ directly as
its recall floor. 20 planted vulns (19 crit/high), 2 decoys, 3 traps.
2026-06-29 12:10:54 -04:00

53 lines
1.7 KiB
JavaScript

// Server-side JS counterpart to the React web/PaymentForm.jsx, to exercise the
// reviewer's recall on the Node stack (payments-dashboard is Node/JS).
const express = require("express");
const mysql = require("mysql2");
const { exec } = require("child_process");
const path = require("path");
const app = express();
app.use(express.json());
const db = mysql.createConnection({
host: "prod-orders.cluster-czaa.us-east-1.rds.amazonaws.com",
user: "app",
password: "Pr0d-0rders-D8!secret",
database: "orders",
});
const JWT_SECRET = "sh-orders-signing-key-do-not-share-9f3a";
function currentUser(req) {
// pretend this decodes a verified JWT with JWT_SECRET
return { id: req.header("x-user-id"), role: req.header("x-user-role") };
}
app.get("/orders/:id", (req, res) => {
const sql = "SELECT * FROM orders WHERE id = " + req.params.id;
db.query(sql, (err, rows) => {
if (err) return res.status(500).json({ error: String(err) });
res.json(rows); // any authenticated user can read any order id
});
});
app.get("/orders/export", (req, res) => {
const name = req.query.file;
exec("zip -j /tmp/export.zip /var/orders/" + name, (err, stdout) => {
if (err) return res.status(500).json({ error: String(err) });
res.json({ ok: true, stdout });
});
});
app.get("/orders/invoice", (req, res) => {
const file = path.join("/var/invoices", req.query.invoice);
res.sendFile(file); // ?invoice=../../etc/passwd escapes /var/invoices
});
app.get("/my-orders", (req, res) => {
const me = currentUser(req).id;
db.query("SELECT id, total FROM orders WHERE user_id = ?", [me], (err, rows) => {
if (err) return res.status(500).json({ error: String(err) });
res.json(rows);
});
});
module.exports = app;