Files
picpeak/backend/SQL_INJECTION_FIX_MIGRATION.md
T
paul e35ac6a41c
Test Gitea Actions / test (push) Successful in 20s
continuous-integration/drone/push Build is passing
feat: implement critical security fixes for SQL injection and authentication vulnerabilities
Security Enhancements:
- Fix SQL injection vulnerabilities by replacing whereRaw queries with parameterized queries
- Add LIKE pattern escaping to prevent SQL injection in search functionality
- Implement account lockout protection (5 failed attempts = 30 min lockout)
- Add comprehensive login attempt tracking and audit trail
- Enhance JWT tokens with issuer validation, IP tracking, and password change detection
- Add logout endpoint and session management
- Prevent user enumeration with generic error messages

Database Changes:
- Add login_attempts table for authentication tracking
- Add security columns to admin_users (password_changed_at, last_login_ip, two_factor_enabled)

New Security Features:
- Brute force protection with configurable lockout duration
- Automatic cleanup of old login attempts
- Enhanced authentication middleware with stricter validation
- Monitoring scripts for security health checks

All fixes are backward compatible and production-ready with rollback plans included.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-13 00:40:05 +02:00

158 lines
4.6 KiB
Markdown

# SQL Injection Fix Migration Guide
## Overview
This document describes the SQL injection vulnerability fixes applied to the PicPeak backend and the migration process for deploying these fixes to production.
## Vulnerabilities Fixed
### 1. WhereRaw Date Queries (High Risk)
**Location**: `adminDashboard.js`
- **Issue**: Direct string interpolation in SQL date calculations
- **Example**: `.whereRaw(\`timestamp >= datetime("now", "-${days} days")\`)`
- **Fix**: Replaced with parameterized queries using ISO date strings
### 2. LIKE Pattern Injection (Medium Risk)
**Locations**: `adminEvents.js`, `adminPhotos.js`
- **Issue**: Unescaped user input in LIKE queries
- **Example**: `.where('event_name', 'like', \`%${search}%\`)`
- **Fix**: Added proper escaping for LIKE special characters (%, _, \)
### 3. Dynamic Column/Order Injection (Low Risk)
**Locations**: Various sorting operations
- **Issue**: Unvalidated column names in ORDER BY
- **Fix**: Whitelist validation for sort columns and orders
## Files Changed
1. **Created**: `backend/src/utils/sqlSecurity.js`
- Central security utility functions
- `sanitizeDays()` - Validates numeric input
- `escapeLikePattern()` - Escapes LIKE wildcards
- `validateSortColumn()` - Whitelist validation
- `validateSortOrder()` - Ensures only 'asc' or 'desc'
2. **Modified**: `backend/src/routes/adminDashboard.js`
- Lines 21-24, 39-41, 45-47, 57-61, 65-68: Replaced whereRaw with parameterized queries
- Line 4: Added security utility imports
- Line 198: Added sanitizeDays for analytics
3. **Modified**: `backend/src/routes/adminEvents.js`
- Line 11: Added escapeLikePattern import
- Lines 156-161: Escaped search patterns in LIKE queries
4. **Modified**: `backend/src/routes/adminPhotos.js`
- Line 9: Added escapeLikePattern import
- Lines 477-478: Escaped search patterns in LIKE queries
## Migration Steps
### 1. Pre-Deployment Testing
```bash
# Run security utility tests
cd backend
node scripts/test-sql-security.js
# Run verification script
node scripts/verify-sql-fixes.js
```
### 2. Development Environment Testing
```bash
# Start development server
npm run dev
# Test key endpoints:
curl http://localhost:3001/api/admin/dashboard/stats -H "Authorization: Bearer YOUR_TOKEN"
curl http://localhost:3001/api/admin/events?search=test -H "Authorization: Bearer YOUR_TOKEN"
curl http://localhost:3001/api/admin/dashboard/analytics?days=7 -H "Authorization: Bearer YOUR_TOKEN"
```
### 3. Production Deployment
#### Option A: Docker Deployment
```bash
# Pull latest changes
git pull
# Rebuild and restart
docker-compose down
docker-compose up -d --build
```
#### Option B: PM2 Deployment
```bash
# Pull latest changes
git pull
# Install dependencies (if any)
cd backend
npm install
# Restart with PM2
pm2 restart picpeak-backend
```
### 4. Post-Deployment Verification
1. **Monitor Logs**:
```bash
# Docker
docker-compose logs -f backend
# PM2
pm2 logs picpeak-backend
```
2. **Test Critical Functions**:
- Admin dashboard loads correctly
- Event search works with special characters
- Analytics charts display properly
- Photo search functions normally
3. **Check Error Rates**:
- Monitor for any 500 errors
- Check database query logs for errors
## Testing Special Characters
After deployment, test these scenarios:
1. **Search with wildcards**: Search for "50%" or "user_name"
2. **Search with quotes**: Search for "O'Brien"
3. **Date range**: Change analytics to different day ranges
4. **Malicious input**: Try "'; DROP TABLE --" (should return no results)
## Rollback Instructions
If issues occur, see `SQL_INJECTION_FIX_ROLLBACK.md` for immediate rollback steps.
## Performance Impact
- Minimal performance impact expected
- Date calculations now use ISO strings instead of SQLite functions
- LIKE pattern escaping adds negligible overhead
- All changes maintain existing query optimization
## Security Improvements
1. **Eliminated SQL Injection Vectors**: No more direct string interpolation
2. **Input Validation**: All user inputs are validated/sanitized
3. **Parameterized Queries**: Using Knex's built-in parameterization
4. **Defense in Depth**: Multiple layers of protection
## Future Recommendations
1. Add request validation middleware
2. Implement rate limiting on search endpoints
3. Add SQL query logging for security auditing
4. Consider using prepared statements for complex queries
## Questions/Support
If you encounter any issues during migration:
1. Check the rollback plan first
2. Review error logs for specific issues
3. Test individual endpoints to isolate problems
4. Contact development team if needed