e35ac6a41c
Security Enhancements: - Fix SQL injection vulnerabilities by replacing whereRaw queries with parameterized queries - Add LIKE pattern escaping to prevent SQL injection in search functionality - Implement account lockout protection (5 failed attempts = 30 min lockout) - Add comprehensive login attempt tracking and audit trail - Enhance JWT tokens with issuer validation, IP tracking, and password change detection - Add logout endpoint and session management - Prevent user enumeration with generic error messages Database Changes: - Add login_attempts table for authentication tracking - Add security columns to admin_users (password_changed_at, last_login_ip, two_factor_enabled) New Security Features: - Brute force protection with configurable lockout duration - Automatic cleanup of old login attempts - Enhanced authentication middleware with stricter validation - Monitoring scripts for security health checks All fixes are backward compatible and production-ready with rollback plans included. 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
158 lines
4.6 KiB
Markdown
158 lines
4.6 KiB
Markdown
# SQL Injection Fix Migration Guide
|
|
|
|
## Overview
|
|
This document describes the SQL injection vulnerability fixes applied to the PicPeak backend and the migration process for deploying these fixes to production.
|
|
|
|
## Vulnerabilities Fixed
|
|
|
|
### 1. WhereRaw Date Queries (High Risk)
|
|
**Location**: `adminDashboard.js`
|
|
- **Issue**: Direct string interpolation in SQL date calculations
|
|
- **Example**: `.whereRaw(\`timestamp >= datetime("now", "-${days} days")\`)`
|
|
- **Fix**: Replaced with parameterized queries using ISO date strings
|
|
|
|
### 2. LIKE Pattern Injection (Medium Risk)
|
|
**Locations**: `adminEvents.js`, `adminPhotos.js`
|
|
- **Issue**: Unescaped user input in LIKE queries
|
|
- **Example**: `.where('event_name', 'like', \`%${search}%\`)`
|
|
- **Fix**: Added proper escaping for LIKE special characters (%, _, \)
|
|
|
|
### 3. Dynamic Column/Order Injection (Low Risk)
|
|
**Locations**: Various sorting operations
|
|
- **Issue**: Unvalidated column names in ORDER BY
|
|
- **Fix**: Whitelist validation for sort columns and orders
|
|
|
|
## Files Changed
|
|
|
|
1. **Created**: `backend/src/utils/sqlSecurity.js`
|
|
- Central security utility functions
|
|
- `sanitizeDays()` - Validates numeric input
|
|
- `escapeLikePattern()` - Escapes LIKE wildcards
|
|
- `validateSortColumn()` - Whitelist validation
|
|
- `validateSortOrder()` - Ensures only 'asc' or 'desc'
|
|
|
|
2. **Modified**: `backend/src/routes/adminDashboard.js`
|
|
- Lines 21-24, 39-41, 45-47, 57-61, 65-68: Replaced whereRaw with parameterized queries
|
|
- Line 4: Added security utility imports
|
|
- Line 198: Added sanitizeDays for analytics
|
|
|
|
3. **Modified**: `backend/src/routes/adminEvents.js`
|
|
- Line 11: Added escapeLikePattern import
|
|
- Lines 156-161: Escaped search patterns in LIKE queries
|
|
|
|
4. **Modified**: `backend/src/routes/adminPhotos.js`
|
|
- Line 9: Added escapeLikePattern import
|
|
- Lines 477-478: Escaped search patterns in LIKE queries
|
|
|
|
## Migration Steps
|
|
|
|
### 1. Pre-Deployment Testing
|
|
|
|
```bash
|
|
# Run security utility tests
|
|
cd backend
|
|
node scripts/test-sql-security.js
|
|
|
|
# Run verification script
|
|
node scripts/verify-sql-fixes.js
|
|
```
|
|
|
|
### 2. Development Environment Testing
|
|
|
|
```bash
|
|
# Start development server
|
|
npm run dev
|
|
|
|
# Test key endpoints:
|
|
curl http://localhost:3001/api/admin/dashboard/stats -H "Authorization: Bearer YOUR_TOKEN"
|
|
curl http://localhost:3001/api/admin/events?search=test -H "Authorization: Bearer YOUR_TOKEN"
|
|
curl http://localhost:3001/api/admin/dashboard/analytics?days=7 -H "Authorization: Bearer YOUR_TOKEN"
|
|
```
|
|
|
|
### 3. Production Deployment
|
|
|
|
#### Option A: Docker Deployment
|
|
```bash
|
|
# Pull latest changes
|
|
git pull
|
|
|
|
# Rebuild and restart
|
|
docker-compose down
|
|
docker-compose up -d --build
|
|
```
|
|
|
|
#### Option B: PM2 Deployment
|
|
```bash
|
|
# Pull latest changes
|
|
git pull
|
|
|
|
# Install dependencies (if any)
|
|
cd backend
|
|
npm install
|
|
|
|
# Restart with PM2
|
|
pm2 restart picpeak-backend
|
|
```
|
|
|
|
### 4. Post-Deployment Verification
|
|
|
|
1. **Monitor Logs**:
|
|
```bash
|
|
# Docker
|
|
docker-compose logs -f backend
|
|
|
|
# PM2
|
|
pm2 logs picpeak-backend
|
|
```
|
|
|
|
2. **Test Critical Functions**:
|
|
- Admin dashboard loads correctly
|
|
- Event search works with special characters
|
|
- Analytics charts display properly
|
|
- Photo search functions normally
|
|
|
|
3. **Check Error Rates**:
|
|
- Monitor for any 500 errors
|
|
- Check database query logs for errors
|
|
|
|
## Testing Special Characters
|
|
|
|
After deployment, test these scenarios:
|
|
|
|
1. **Search with wildcards**: Search for "50%" or "user_name"
|
|
2. **Search with quotes**: Search for "O'Brien"
|
|
3. **Date range**: Change analytics to different day ranges
|
|
4. **Malicious input**: Try "'; DROP TABLE --" (should return no results)
|
|
|
|
## Rollback Instructions
|
|
|
|
If issues occur, see `SQL_INJECTION_FIX_ROLLBACK.md` for immediate rollback steps.
|
|
|
|
## Performance Impact
|
|
|
|
- Minimal performance impact expected
|
|
- Date calculations now use ISO strings instead of SQLite functions
|
|
- LIKE pattern escaping adds negligible overhead
|
|
- All changes maintain existing query optimization
|
|
|
|
## Security Improvements
|
|
|
|
1. **Eliminated SQL Injection Vectors**: No more direct string interpolation
|
|
2. **Input Validation**: All user inputs are validated/sanitized
|
|
3. **Parameterized Queries**: Using Knex's built-in parameterization
|
|
4. **Defense in Depth**: Multiple layers of protection
|
|
|
|
## Future Recommendations
|
|
|
|
1. Add request validation middleware
|
|
2. Implement rate limiting on search endpoints
|
|
3. Add SQL query logging for security auditing
|
|
4. Consider using prepared statements for complex queries
|
|
|
|
## Questions/Support
|
|
|
|
If you encounter any issues during migration:
|
|
1. Check the rollback plan first
|
|
2. Review error logs for specific issues
|
|
3. Test individual endpoints to isolate problems
|
|
4. Contact development team if needed |