Harden server: drain connections on stop, validate proxy URL scheme, add fetch timeout

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-04-26 09:41:44 -07:00
co-authored by Claude Sonnet 4.6
parent 3445ef89f0
commit 03128cbe6b
+15 -3
View File
@@ -35,8 +35,16 @@ function startServer({ port, overlayDir }) {
app.get('/api/image-proxy', async (req, res) => {
const url = req.query.url;
if (!url) return res.status(400).send('Missing url parameter');
let parsed;
try { parsed = new URL(url); }
catch { return res.status(400).send('Invalid url'); }
if (parsed.protocol !== 'http:' && parsed.protocol !== 'https:') {
return res.status(400).send('Only http/https URLs are allowed');
}
try {
const response = await fetch(url);
const response = await fetch(url, { signal: AbortSignal.timeout(10_000) });
if (!response.ok) return res.status(response.status).send('Upstream error');
res.set('Content-Type', response.headers.get('content-type') || 'image/jpeg');
res.set('Cache-Control', 'public, max-age=3600');
@@ -52,6 +60,7 @@ function startServer({ port, overlayDir }) {
}
wss.on('connection', (ws) => {
ws.on('error', () => {});
ws.send(JSON.stringify(currentState));
});
@@ -59,14 +68,17 @@ function startServer({ port, overlayDir }) {
currentState = mergeState(currentState, update || {});
const message = JSON.stringify(currentState);
wss.clients.forEach((client) => {
if (client.readyState === 1) client.send(message);
if (client.readyState === 1) client.send(message); // 1 === WebSocket.OPEN
});
return currentState;
}
function stop() {
return new Promise((resolve) => {
wss.close(() => server.close(() => resolve()));
wss.close(() => {
server.closeAllConnections();
server.close(() => resolve());
});
});
}