From e965f421878c698c03fd4a4ad1223d1a83e3ed1c Mon Sep 17 00:00:00 2001 From: Sonu Kapoor Date: Tue, 8 Sep 2026 07:48:49 -0400 Subject: [PATCH 1/3] docs: add the Open Source Friday demo project and run of show CVE Lite CLI is featured on GitHub's Open Source Friday livestream on 2026-09-18. The demo is the centrepiece of that session, so it needs a project that is versioned and reproducible rather than assembled in a scratch directory on the day. shipping-api is a small Express service with five direct dependencies pinned to old versions. It produces 11 vulnerable packages, 1 critical and 6 high, split 5 direct and 6 transitive, and every one of the six transitive findings traces back to a single parent. That last property is what makes the demo land: one express upgrade resolves six findings in packages the developer never installed and could not upgrade directly. Purpose-built rather than a real repository, because scanning someone else's project live on GitHub's own channel broadcasts their vulnerabilities on a stream they did not agree to. Juice Shop was considered and rejected: 52 findings but zero direct, so there is no copy-and-run fix command to show. The README records two things found during preparation. Fix versions move between runs on live OSV data, so the commands must come from a rehearsal immediately before going live. And --offline must not be used on air: it disables registry-validated fix versions and parent-version upgrades, which are two of the four beats and the two that differentiate the tool. Verified that self-scan reads the root lockfile and does not descend into examples/, so adding a deliberately vulnerable project does not affect CI. Closes #1103 --- examples/open-source-friday-demo/README.md | 101 +++ .../shipping-api/package-lock.json | 700 ++++++++++++++++++ .../shipping-api/package.json | 17 + .../shipping-api/src/index.js | 21 + 4 files changed, 839 insertions(+) create mode 100644 examples/open-source-friday-demo/README.md create mode 100644 examples/open-source-friday-demo/shipping-api/package-lock.json create mode 100644 examples/open-source-friday-demo/shipping-api/package.json create mode 100644 examples/open-source-friday-demo/shipping-api/src/index.js diff --git a/examples/open-source-friday-demo/README.md b/examples/open-source-friday-demo/README.md new file mode 100644 index 00000000..6dfb192f --- /dev/null +++ b/examples/open-source-friday-demo/README.md @@ -0,0 +1,101 @@ +# Open Source Friday demo + +Demo material for the GitHub Open Source Friday stream (Twitch, LinkedIn and YouTube via StreamYard). + +`shipping-api/` is a small Express service whose five direct dependencies are deliberately pinned to old versions. It is here rather than in a scratch directory so the demo is versioned, reproducible, and identical on every rehearsal. + +## Why a purpose-built project + +Scanning a real maintainer's repository live on GitHub's own channel puts their vulnerabilities on a broadcast they did not agree to. This project uses real, recognisable packages and real CVEs without doing that to anyone. It also behaves the same every rehearsal, which a live repository does not. + +## The four beats, about 8 minutes + +Run everything from this directory. + +**1. The scan, around 90 seconds** + +```bash +cve-lite ./shipping-api +``` + +Expect roughly `11 packages · 1 critical · 6 high · 5 direct · 6 transitive`. Two things to narrate: the direct versus transitive split, and the `⚡ Fix Now` badge, which is CVSS severity crossed with EPSS exploitation likelihood rather than severity alone. + +**2. The proof, around 2 minutes** + +```bash +cve-lite ./shipping-api --verbose --all +``` + +`--all` matters: plain `--verbose` hides low-severity findings, which drops three of the six transitive packages and breaks the Root story. + +The fix table is the strongest argument for the tool. Point at **Versions scanned** and **Still known vulnerable**: for axios it scans over twenty published versions and finds most of them still vulnerable before recommending one. Most scanners hand you the advisory's suggested version without checking it. + +**3. The artifact, around 2 minutes** + +```bash +cve-lite ./shipping-api --report +``` + +The HTML dashboard, with every finding, its dependency path, and a copy button per fix command. `--sbom spdx` is worth a mention if there is time, since emitting both CycloneDX and SPDX with findings attached is something no other free JS tool does. + +**Run this before the fix.** After the fix the project is clean and the report is empty, which is an anticlimax rather than a finale. + +**4. The payoff, around 2 minutes** + +Copy the commands the scan printed, run them, rescan. It goes fully green: + +``` +Scan complete. No known vulnerabilities found. +``` + +**Use the commands from the run you just did, not the ones written here.** They change as advisories are published. See the warning below. + +Ending on green is deliberate. It is a stronger close than a document. + +The transitive story is the one to weave through: six of the findings are packages nobody installed directly, and they all resolve through a single `npm install express@...`. That is the part npm audit and Dependabot do not do. + +## Resetting between rehearsals + +Beat 4 rewrites `package.json` and the lockfile, so the project is clean afterwards and the demo cannot be repeated. Reset with: + +```bash +git checkout -- examples/open-source-friday-demo +``` + +## The one real risk: results move + +Findings and fix versions come from live OSV and npm data, so **two runs hours apart can differ**. This happened during preparation: axios was recommended as `0.21.2` in one run and `0.33.0` in the next. Running beat 4 with a stale command leaves the project still showing findings, which turns the payoff beat into a shrug. + +**The fix is timing, not offline mode.** You are in the StreamYard room at 12:45 for tech checks and live at 1:00. Rehearse the scan in that window and use the commands from that run. Advisories are not published in a 15 minute gap, so the drift effectively disappears. + +Do not prepare the fix commands the day before and paste them on air. + +## Do not demo offline mode + +`--offline` is tempting for determinism. Do not use it for this demo. Two of the four beats are weaker or absent offline, and they are the two that differentiate the tool. See [Offline vs Online Results](https://owasp.org/cve-lite-cli/docs/offline-vs-online-results). + +**Registry-validated fix versions only work online.** Offline falls back to the advisory's raw `firstFixedVersion` hint. That removes beat 2 entirely: the "scanned 23 versions, 22 still vulnerable" columns and the "hint is not published on npm, using nearest published version" note both come from live registry calls. + +**Parent-version upgrades only run online.** Offline handles in-range parent updates but skips the case that needs a newer parent, showing "no safe version was identified automatically" instead. That is half the transitive story. + +Offline is also not what viewers get if they follow along, and `advisories sync` is setup narration that buys nothing on air. + +**Keep it as the fallback, not the plan.** If the network fails mid-stream, having a synced database means you can keep going rather than staring at a spinner on three broadcast channels. Sync it beforehand so it is there: + +```bash +cve-lite advisories sync # before the stream, as insurance only +``` + +If you do fall back to it live, say so, and say what changes: fix targets come from the advisory rather than the registry. + +## Their setup checklist + +From the Open Source Friday guest guide, the parts that need doing before 12:45: + +- Hardwired ethernet rather than wifi, and headphones +- Browser zoomed to at least 125 percent, screen at 1920x1080 +- Clean browser profile with bookmarks bar and history hidden +- Do-not-disturb on, browser extensions disabled +- macOS menu bar and Dock set to auto-hide + +Stream starts at 1:00 PM ET; guests join at 12:45 for prep and tech checks. diff --git a/examples/open-source-friday-demo/shipping-api/package-lock.json b/examples/open-source-friday-demo/shipping-api/package-lock.json new file mode 100644 index 00000000..1788035d --- /dev/null +++ b/examples/open-source-friday-demo/shipping-api/package-lock.json @@ -0,0 +1,700 @@ +{ + "name": "shipping-api", + "version": "1.0.0", + "lockfileVersion": 3, + "requires": true, + "packages": { + "": { + "name": "shipping-api", + "version": "1.0.0", + "dependencies": { + "axios": "0.21.1", + "express": "4.17.1", + "jsonwebtoken": "8.5.1", + "lodash": "4.17.20", + "minimist": "1.2.5" + } + }, + "node_modules/accepts": { + "version": "1.3.8", + "resolved": "https://registry.npmjs.org/accepts/-/accepts-1.3.8.tgz", + "integrity": "sha512-PYAthTa2m2VKxuvSD3DPC/Gy+U+sOA1LAuT8mkmRuvw+NACSaeXEQ+NHcVF7rONl6qcaxV3Uuemwawk+7+SJLw==", + "license": "MIT", + "dependencies": { + "mime-types": "~2.1.34", + "negotiator": "0.6.3" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/array-flatten": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/array-flatten/-/array-flatten-1.1.1.tgz", + "integrity": "sha512-PCVAQswWemu6UdxsDFFX/+gVeYqKAod3D3UVm91jHwynguOwAvYPhx8nNlM++NqRcK6CxxpUafjmhIdKiHibqg==", + "license": "MIT" + }, + "node_modules/axios": { + "version": "0.21.1", + "resolved": "https://registry.npmjs.org/axios/-/axios-0.21.1.tgz", + "integrity": "sha512-dKQiRHxGD9PPRIUNIWvZhPTPpl1rf/OxTYKsqKUDjBwYylTvV7SjSHJb9ratfyzM6wCdLCOYLzs73qpg5c4iGA==", + "license": "MIT", + "dependencies": { + "follow-redirects": "^1.10.0" + } + }, + "node_modules/body-parser": { + "version": "1.19.0", + "resolved": "https://registry.npmjs.org/body-parser/-/body-parser-1.19.0.tgz", + "integrity": "sha512-dhEPs72UPbDnAQJ9ZKMNTP6ptJaionhP5cBb541nXPlW60Jepo9RV/a4fX4XWW9CuFNK22krhrj1+rgzifNCsw==", + "license": "MIT", + "dependencies": { + "bytes": "3.1.0", + "content-type": "~1.0.4", + "debug": "2.6.9", + "depd": "~1.1.2", + "http-errors": "1.7.2", + "iconv-lite": "0.4.24", + "on-finished": "~2.3.0", + "qs": "6.7.0", + "raw-body": "2.4.0", + "type-is": "~1.6.17" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/buffer-equal-constant-time": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/buffer-equal-constant-time/-/buffer-equal-constant-time-1.0.1.tgz", + "integrity": "sha512-zRpUiDwd/xk6ADqPMATG8vc9VPrkck7T07OIx0gnjmJAnHnTVXNQG3vfvWNuiZIkwu9KrKdA1iJKfsfTVxE6NA==", + "license": "BSD-3-Clause" + }, + "node_modules/bytes": { + "version": "3.1.0", + "resolved": "https://registry.npmjs.org/bytes/-/bytes-3.1.0.tgz", + "integrity": "sha512-zauLjrfCG+xvoyaqLoV8bLVXXNGC4JqlxFCutSDWA6fJrTo2ZuvLYTqZ7aHBLZSMOopbzwv8f+wZcVzfVTI2Dg==", + "license": "MIT", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/content-disposition": { + "version": "0.5.3", + "resolved": "https://registry.npmjs.org/content-disposition/-/content-disposition-0.5.3.tgz", + "integrity": "sha512-ExO0774ikEObIAEV9kDo50o+79VCUdEB6n6lzKgGwupcVeRlhrj3qGAfwq8G6uBJjkqLrhT0qEYFcWng8z1z0g==", + "license": "MIT", + "dependencies": { + "safe-buffer": "5.1.2" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/content-type": { + "version": "1.0.5", + "resolved": "https://registry.npmjs.org/content-type/-/content-type-1.0.5.tgz", + "integrity": "sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/cookie": { + "version": "0.4.0", + "resolved": "https://registry.npmjs.org/cookie/-/cookie-0.4.0.tgz", + "integrity": "sha512-+Hp8fLp57wnUSt0tY0tHEXh4voZRDnoIrZPqlo3DPiI4y9lwg/jqx+1Om94/W6ZaPDOUbnjOt/99w66zk+l1Xg==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/cookie-signature": { + "version": "1.0.6", + "resolved": "https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.0.6.tgz", + "integrity": "sha512-QADzlaHc8icV8I7vbaJXJwod9HWYp8uCqf1xa4OfNu1T7JVxQIrUgOWtHdNDtPiywmFbiS12VjotIXLrKM3orQ==", + "license": "MIT" + }, + "node_modules/debug": { + "version": "2.6.9", + "resolved": "https://registry.npmjs.org/debug/-/debug-2.6.9.tgz", + "integrity": "sha512-bC7ElrdJaJnPbAP+1EotYvqZsb3ecl5wi6Bfi6BJTUcNowp6cvspg0jXznRTKDjm/E7AdgFBVeAPVMNcKGsHMA==", + "license": "MIT", + "dependencies": { + "ms": "2.0.0" + } + }, + "node_modules/depd": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/depd/-/depd-1.1.2.tgz", + "integrity": "sha512-7emPTl6Dpo6JRXOXjLRxck+FlLRX5847cLKEn00PLAgc3g2hTZZgr+e4c2v6QpSmLeFP3n5yUo7ft6avBK/5jQ==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/destroy": { + "version": "1.0.4", + "resolved": "https://registry.npmjs.org/destroy/-/destroy-1.0.4.tgz", + "integrity": "sha512-3NdhDuEXnfun/z7x9GOElY49LoqVHoGScmOKwmxhsS8N5Y+Z8KyPPDnaSzqWgYt/ji4mqwfTS34Htrk0zPIXVg==", + "license": "MIT" + }, + "node_modules/ecdsa-sig-formatter": { + "version": "1.0.11", + "resolved": "https://registry.npmjs.org/ecdsa-sig-formatter/-/ecdsa-sig-formatter-1.0.11.tgz", + "integrity": "sha512-nagl3RYrbNv6kQkeJIpt6NJZy8twLB/2vtz6yN9Z4vRKHN4/QZJIEbqohALSgwKdnksuY3k5Addp5lg8sVoVcQ==", + "license": "Apache-2.0", + "dependencies": { + "safe-buffer": "^5.0.1" + } + }, + "node_modules/ee-first": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz", + "integrity": "sha512-WMwm9LhRUo+WUaRN+vRuETqG89IgZphVSNkdFgeb6sS/E4OrDIN7t48CAewSHXc6C8lefD8KKfr5vY61brQlow==", + "license": "MIT" + }, + "node_modules/encodeurl": { + "version": "1.0.2", + "resolved": "https://registry.npmjs.org/encodeurl/-/encodeurl-1.0.2.tgz", + "integrity": "sha512-TPJXq8JqFaVYm2CWmPvnP2Iyo4ZSM7/QKcSmuMLDObfpH5fi7RUGmd/rTDf+rut/saiDiQEeVTNgAmJEdAOx0w==", + "license": "MIT", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/escape-html": { + "version": "1.0.3", + "resolved": "https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz", + "integrity": "sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==", + "license": "MIT" + }, + "node_modules/etag": { + "version": "1.8.1", + "resolved": "https://registry.npmjs.org/etag/-/etag-1.8.1.tgz", + "integrity": "sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/express": { + "version": "4.17.1", + "resolved": "https://registry.npmjs.org/express/-/express-4.17.1.tgz", + "integrity": "sha512-mHJ9O79RqluphRrcw2X/GTh3k9tVv8YcoyY4Kkh4WDMUYKRZUq0h1o0w2rrrxBqM7VoeUVqgb27xlEMXTnYt4g==", + "license": "MIT", + "dependencies": { + "accepts": "~1.3.7", + "array-flatten": "1.1.1", + "body-parser": "1.19.0", + "content-disposition": "0.5.3", + "content-type": "~1.0.4", + "cookie": "0.4.0", + "cookie-signature": "1.0.6", + "debug": "2.6.9", + "depd": "~1.1.2", + "encodeurl": "~1.0.2", + "escape-html": "~1.0.3", + "etag": "~1.8.1", + "finalhandler": "~1.1.2", + "fresh": "0.5.2", + "merge-descriptors": "1.0.1", + "methods": "~1.1.2", + "on-finished": "~2.3.0", + "parseurl": "~1.3.3", + "path-to-regexp": "0.1.7", + "proxy-addr": "~2.0.5", + "qs": "6.7.0", + "range-parser": "~1.2.1", + "safe-buffer": "5.1.2", + "send": "0.17.1", + "serve-static": "1.14.1", + "setprototypeof": "1.1.1", + "statuses": "~1.5.0", + "type-is": "~1.6.18", + "utils-merge": "1.0.1", + "vary": "~1.1.2" + }, + "engines": { + "node": ">= 0.10.0" + } + }, + "node_modules/finalhandler": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/finalhandler/-/finalhandler-1.1.2.tgz", + "integrity": "sha512-aAWcW57uxVNrQZqFXjITpW3sIUQmHGG3qSb9mUah9MgMC4NeWhNOlNjXEYq3HjRAvL6arUviZGGJsBg6z0zsWA==", + "license": "MIT", + "dependencies": { + "debug": "2.6.9", + "encodeurl": "~1.0.2", + "escape-html": "~1.0.3", + "on-finished": "~2.3.0", + "parseurl": "~1.3.3", + "statuses": "~1.5.0", + "unpipe": "~1.0.0" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/follow-redirects": { + "version": "1.16.0", + "resolved": "https://registry.npmjs.org/follow-redirects/-/follow-redirects-1.16.0.tgz", + "integrity": "sha512-y5rN/uOsadFT/JfYwhxRS5R7Qce+g3zG97+JrtFZlC9klX/W5hD7iiLzScI4nZqUS7DNUdhPgw4xI8W2LuXlUw==", + "funding": [ + { + "type": "individual", + "url": "https://github.com/sponsors/RubenVerborgh" + } + ], + "license": "MIT", + "engines": { + "node": ">=4.0" + }, + "peerDependenciesMeta": { + "debug": { + "optional": true + } + } + }, + "node_modules/forwarded": { + "version": "0.2.0", + "resolved": "https://registry.npmjs.org/forwarded/-/forwarded-0.2.0.tgz", + "integrity": "sha512-buRG0fpBtRHSTCOASe6hD258tEubFoRLb4ZNA6NxMVHNw2gOcwHo9wyablzMzOA5z9xA9L1KNjk/Nt6MT9aYow==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/fresh": { + "version": "0.5.2", + "resolved": "https://registry.npmjs.org/fresh/-/fresh-0.5.2.tgz", + "integrity": "sha512-zJ2mQYM18rEFOudeV4GShTGIQ7RbzA7ozbU9I/XBpm7kqgMywgmylMwXHxZJmkVoYkna9d2pVXVXPdYTP9ej8Q==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/http-errors": { + "version": "1.7.2", + "resolved": "https://registry.npmjs.org/http-errors/-/http-errors-1.7.2.tgz", + "integrity": "sha512-uUQBt3H/cSIVfch6i1EuPNy/YsRSOUBXTVfZ+yR7Zjez3qjBz6i9+i4zjNaoqcoFVI4lQJ5plg63TvGfRSDCRg==", + "license": "MIT", + "dependencies": { + "depd": "~1.1.2", + "inherits": "2.0.3", + "setprototypeof": "1.1.1", + "statuses": ">= 1.5.0 < 2", + "toidentifier": "1.0.0" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/iconv-lite": { + "version": "0.4.24", + "resolved": "https://registry.npmjs.org/iconv-lite/-/iconv-lite-0.4.24.tgz", + "integrity": "sha512-v3MXnZAcvnywkTUEZomIActle7RXXeedOR31wwl7VlyoXO4Qi9arvSenNQWne1TcRwhCL1HwLI21bEqdpj8/rA==", + "license": "MIT", + "dependencies": { + "safer-buffer": ">= 2.1.2 < 3" + }, + "engines": { + "node": ">=0.10.0" + } + }, + "node_modules/inherits": { + "version": "2.0.3", + "resolved": "https://registry.npmjs.org/inherits/-/inherits-2.0.3.tgz", + "integrity": "sha512-x00IRNXNy63jwGkJmzPigoySHbaqpNuzKbBOmzK+g2OdZpQ9w+sxCN+VSB3ja7IAge2OP2qpfxTjeNcyjmW1uw==", + "license": "ISC" + }, + "node_modules/ipaddr.js": { + "version": "1.9.1", + "resolved": "https://registry.npmjs.org/ipaddr.js/-/ipaddr.js-1.9.1.tgz", + "integrity": "sha512-0KI/607xoxSToH7GjN1FfSbLoU0+btTicjsQSWQlh/hZykN8KpmMf7uYwPW3R+akZ6R/w18ZlXSHBYXiYUPO3g==", + "license": "MIT", + "engines": { + "node": ">= 0.10" + } + }, + "node_modules/jsonwebtoken": { + "version": "8.5.1", + "resolved": "https://registry.npmjs.org/jsonwebtoken/-/jsonwebtoken-8.5.1.tgz", + "integrity": "sha512-XjwVfRS6jTMsqYs0EsuJ4LGxXV14zQybNd4L2r0UvbVnSF9Af8x7p5MzbJ90Ioz/9TI41/hTCvznF/loiSzn8w==", + "license": "MIT", + "dependencies": { + "jws": "^3.2.2", + "lodash.includes": "^4.3.0", + "lodash.isboolean": "^3.0.3", + "lodash.isinteger": "^4.0.4", + "lodash.isnumber": "^3.0.3", + "lodash.isplainobject": "^4.0.6", + "lodash.isstring": "^4.0.1", + "lodash.once": "^4.0.0", + "ms": "^2.1.1", + "semver": "^5.6.0" + }, + "engines": { + "node": ">=4", + "npm": ">=1.4.28" + } + }, + "node_modules/jsonwebtoken/node_modules/ms": { + "version": "2.1.3", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.3.tgz", + "integrity": "sha512-6FlzubTLZG3J2a/NVCAleEhjzq5oxgHyaCU9yYXvcLsvoVaHJq/s5xXI6/XXP6tz7R9xAOtHnSO/tXtF3WRTlA==", + "license": "MIT" + }, + "node_modules/jwa": { + "version": "1.4.2", + "resolved": "https://registry.npmjs.org/jwa/-/jwa-1.4.2.tgz", + "integrity": "sha512-eeH5JO+21J78qMvTIDdBXidBd6nG2kZjg5Ohz/1fpa28Z4CcsWUzJ1ZZyFq/3z3N17aZy+ZuBoHljASbL1WfOw==", + "license": "MIT", + "dependencies": { + "buffer-equal-constant-time": "^1.0.1", + "ecdsa-sig-formatter": "1.0.11", + "safe-buffer": "^5.0.1" + } + }, + "node_modules/jws": { + "version": "3.2.3", + "resolved": "https://registry.npmjs.org/jws/-/jws-3.2.3.tgz", + "integrity": "sha512-byiJ0FLRdLdSVSReO/U4E7RoEyOCKnEnEPMjq3HxWtvzLsV08/i5RQKsFVNkCldrCaPr2vDNAOMsfs8T/Hze7g==", + "license": "MIT", + "dependencies": { + "jwa": "^1.4.2", + "safe-buffer": "^5.0.1" + } + }, + "node_modules/lodash": { + "version": "4.17.20", + "resolved": "https://registry.npmjs.org/lodash/-/lodash-4.17.20.tgz", + "integrity": "sha512-PlhdFcillOINfeV7Ni6oF1TAEayyZBoZ8bcshTHqOYJYlrqzRK5hagpagky5o4HfCzzd1TRkXPMFq6cKk9rGmA==", + "license": "MIT" + }, + "node_modules/lodash.includes": { + "version": "4.3.0", + "resolved": "https://registry.npmjs.org/lodash.includes/-/lodash.includes-4.3.0.tgz", + "integrity": "sha512-W3Bx6mdkRTGtlJISOvVD/lbqjTlPPUDTMnlXZFnVwi9NKJ6tiAk6LVdlhZMm17VZisqhKcgzpO5Wz91PCt5b0w==", + "license": "MIT" + }, + "node_modules/lodash.isboolean": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/lodash.isboolean/-/lodash.isboolean-3.0.3.tgz", + "integrity": "sha512-Bz5mupy2SVbPHURB98VAcw+aHh4vRV5IPNhILUCsOzRmsTmSQ17jIuqopAentWoehktxGd9e/hbIXq980/1QJg==", + "license": "MIT" + }, + "node_modules/lodash.isinteger": { + "version": "4.0.4", + "resolved": "https://registry.npmjs.org/lodash.isinteger/-/lodash.isinteger-4.0.4.tgz", + "integrity": "sha512-DBwtEWN2caHQ9/imiNeEA5ys1JoRtRfY3d7V9wkqtbycnAmTvRRmbHKDV4a0EYc678/dia0jrte4tjYwVBaZUA==", + "license": "MIT" + }, + "node_modules/lodash.isnumber": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/lodash.isnumber/-/lodash.isnumber-3.0.3.tgz", + "integrity": "sha512-QYqzpfwO3/CWf3XP+Z+tkQsfaLL/EnUlXWVkIk5FUPc4sBdTehEqZONuyRt2P67PXAk+NXmTBcc97zw9t1FQrw==", + "license": "MIT" + }, + "node_modules/lodash.isplainobject": { + "version": "4.0.6", + "resolved": "https://registry.npmjs.org/lodash.isplainobject/-/lodash.isplainobject-4.0.6.tgz", + "integrity": "sha512-oSXzaWypCMHkPC3NvBEaPHf0KsA5mvPrOPgQWDsbg8n7orZ290M0BmC/jgRZ4vcJ6DTAhjrsSYgdsW/F+MFOBA==", + "license": "MIT" + }, + "node_modules/lodash.isstring": { + "version": "4.0.1", + "resolved": "https://registry.npmjs.org/lodash.isstring/-/lodash.isstring-4.0.1.tgz", + "integrity": "sha512-0wJxfxH1wgO3GrbuP+dTTk7op+6L41QCXbGINEmD+ny/G/eCqGzxyCsh7159S+mgDDcoarnBw6PC1PS5+wUGgw==", + "license": "MIT" + }, + "node_modules/lodash.once": { + "version": "4.1.1", + "resolved": "https://registry.npmjs.org/lodash.once/-/lodash.once-4.1.1.tgz", + "integrity": "sha512-Sb487aTOCr9drQVL8pIxOzVhafOjZN9UU54hiN8PU3uAiSV7lx1yYNpbNmex2PK6dSJoNTSJUUswT651yww3Mg==", + "license": "MIT" + }, + "node_modules/media-typer": { + "version": "0.3.0", + "resolved": "https://registry.npmjs.org/media-typer/-/media-typer-0.3.0.tgz", + "integrity": "sha512-dq+qelQ9akHpcOl/gUVRTxVIOkAJ1wR3QAvb4RsVjS8oVoFjDGTc679wJYmUmknUF5HwMLOgb5O+a3KxfWapPQ==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/merge-descriptors": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/merge-descriptors/-/merge-descriptors-1.0.1.tgz", + "integrity": "sha512-cCi6g3/Zr1iqQi6ySbseM1Xvooa98N0w31jzUYrXPX2xqObmFGHJ0tQ5u74H3mVh7wLouTseZyYIq39g8cNp1w==", + "license": "MIT" + }, + "node_modules/methods": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/methods/-/methods-1.1.2.tgz", + "integrity": "sha512-iclAHeNqNm68zFtnZ0e+1L2yUIdvzNoauKU4WBA3VvH/vPFieF7qfRlwUZU+DA9P9bPXIS90ulxoUoCH23sV2w==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/mime": { + "version": "1.6.0", + "resolved": "https://registry.npmjs.org/mime/-/mime-1.6.0.tgz", + "integrity": "sha512-x0Vn8spI+wuJ1O6S7gnbaQg8Pxh4NNHb7KSINmEWKiPE4RKOplvijn+NkmYmmRgP68mc70j2EbeTFRsrswaQeg==", + "license": "MIT", + "bin": { + "mime": "cli.js" + }, + "engines": { + "node": ">=4" + } + }, + "node_modules/mime-db": { + "version": "1.52.0", + "resolved": "https://registry.npmjs.org/mime-db/-/mime-db-1.52.0.tgz", + "integrity": "sha512-sPU4uV7dYlvtWJxwwxHD0PuihVNiE7TyAbQ5SWxDCB9mUYvOgroQOwYQQOKPJ8CIbE+1ETVlOoK1UC2nU3gYvg==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/mime-types": { + "version": "2.1.35", + "resolved": "https://registry.npmjs.org/mime-types/-/mime-types-2.1.35.tgz", + "integrity": "sha512-ZDY+bPm5zTTF+YpCrAU9nK0UgICYPT0QtT1NZWFv4s++TNkcgVaT0g6+4R2uI4MjQjzysHB1zxuWL50hzaeXiw==", + "license": "MIT", + "dependencies": { + "mime-db": "1.52.0" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/minimist": { + "version": "1.2.5", + "resolved": "https://registry.npmjs.org/minimist/-/minimist-1.2.5.tgz", + "integrity": "sha512-FM9nNUYrRBAELZQT3xeZQ7fmMOBg6nWNmJKTcgsJeaLstP/UODVpGsr5OhXhhXg6f+qtJ8uiZ+PUxkDWcgIXLw==", + "license": "MIT" + }, + "node_modules/ms": { + "version": "2.0.0", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.0.0.tgz", + "integrity": "sha512-Tpp60P6IUJDTuOq/5Z8cdskzJujfwqfOTkrwIwj7IRISpnkJnT6SyJ4PCPnGMoFjC9ddhal5KVIYtAt97ix05A==", + "license": "MIT" + }, + "node_modules/negotiator": { + "version": "0.6.3", + "resolved": "https://registry.npmjs.org/negotiator/-/negotiator-0.6.3.tgz", + "integrity": "sha512-+EUsqGPLsM+j/zdChZjsnX51g4XrHFOIXwfnCVPGlQk/k5giakcKsuxCObBRu6DSm9opw/O6slWbJdghQM4bBg==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/on-finished": { + "version": "2.3.0", + "resolved": "https://registry.npmjs.org/on-finished/-/on-finished-2.3.0.tgz", + "integrity": "sha512-ikqdkGAAyf/X/gPhXGvfgAytDZtDbr+bkNUJ0N9h5MI/dmdgCs3l6hoHrcUv41sRKew3jIwrp4qQDXiK99Utww==", + "license": "MIT", + "dependencies": { + "ee-first": "1.1.1" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/parseurl": { + "version": "1.3.3", + "resolved": "https://registry.npmjs.org/parseurl/-/parseurl-1.3.3.tgz", + "integrity": "sha512-CiyeOxFT/JZyN5m0z9PfXw4SCBJ6Sygz1Dpl0wqjlhDEGGBP1GnsUVEL0p63hoG1fcj3fHynXi9NYO4nWOL+qQ==", + "license": "MIT", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/path-to-regexp": { + "version": "0.1.7", + "resolved": "https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.7.tgz", + "integrity": "sha512-5DFkuoqlv1uYQKxy8omFBeJPQcdoE07Kv2sferDCrAq1ohOU+MSDswDIbnx3YAM60qIOnYa53wBhXW0EbMonrQ==", + "license": "MIT" + }, + "node_modules/proxy-addr": { + "version": "2.0.7", + "resolved": "https://registry.npmjs.org/proxy-addr/-/proxy-addr-2.0.7.tgz", + "integrity": "sha512-llQsMLSUDUPT44jdrU/O37qlnifitDP+ZwrmmZcoSKyLKvtZxpyV0n2/bD/N4tBAAZ/gJEdZU7KMraoK1+XYAg==", + "license": "MIT", + "dependencies": { + "forwarded": "0.2.0", + "ipaddr.js": "1.9.1" + }, + "engines": { + "node": ">= 0.10" + } + }, + "node_modules/qs": { + "version": "6.7.0", + "resolved": "https://registry.npmjs.org/qs/-/qs-6.7.0.tgz", + "integrity": "sha512-VCdBRNFTX1fyE7Nb6FYoURo/SPe62QCaAyzJvUjwRaIsc+NePBEniHlvxFmmX56+HZphIGtV0XeCirBtpDrTyQ==", + "license": "BSD-3-Clause", + "engines": { + "node": ">=0.6" + } + }, + "node_modules/range-parser": { + "version": "1.2.1", + "resolved": "https://registry.npmjs.org/range-parser/-/range-parser-1.2.1.tgz", + "integrity": "sha512-Hrgsx+orqoygnmhFbKaHE6c296J+HTAQXoxEF6gNupROmmGJRoyzfG3ccAveqCBrwr/2yxQ5BVd/GTl5agOwSg==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/raw-body": { + "version": "2.4.0", + "resolved": "https://registry.npmjs.org/raw-body/-/raw-body-2.4.0.tgz", + "integrity": "sha512-4Oz8DUIwdvoa5qMJelxipzi/iJIi40O5cGV1wNYp5hvZP8ZN0T+jiNkL0QepXs+EsQ9XJ8ipEDoiH70ySUJP3Q==", + "license": "MIT", + "dependencies": { + "bytes": "3.1.0", + "http-errors": "1.7.2", + "iconv-lite": "0.4.24", + "unpipe": "1.0.0" + }, + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/safe-buffer": { + "version": "5.1.2", + "resolved": "https://registry.npmjs.org/safe-buffer/-/safe-buffer-5.1.2.tgz", + "integrity": "sha512-Gd2UZBJDkXlY7GbJxfsE8/nvKkUEU1G38c1siN6QP6a9PT9MmHB8GnpscSmMJSoF8LOIrt8ud/wPtojys4G6+g==", + "license": "MIT" + }, + "node_modules/safer-buffer": { + "version": "2.1.2", + "resolved": "https://registry.npmjs.org/safer-buffer/-/safer-buffer-2.1.2.tgz", + "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==", + "license": "MIT" + }, + "node_modules/semver": { + "version": "5.7.2", + "resolved": "https://registry.npmjs.org/semver/-/semver-5.7.2.tgz", + "integrity": "sha512-cBznnQ9KjJqU67B52RMC65CMarK2600WFnbkcaiwWq3xy/5haFJlshgnpjovMVJ+Hff49d8GEn0b87C5pDQ10g==", + "license": "ISC", + "bin": { + "semver": "bin/semver" + } + }, + "node_modules/send": { + "version": "0.17.1", + "resolved": "https://registry.npmjs.org/send/-/send-0.17.1.tgz", + "integrity": "sha512-BsVKsiGcQMFwT8UxypobUKyv7irCNRHk1T0G680vk88yf6LBByGcZJOTJCrTP2xVN6yI+XjPJcNuE3V4fT9sAg==", + "license": "MIT", + "dependencies": { + "debug": "2.6.9", + "depd": "~1.1.2", + "destroy": "~1.0.4", + "encodeurl": "~1.0.2", + "escape-html": "~1.0.3", + "etag": "~1.8.1", + "fresh": "0.5.2", + "http-errors": "~1.7.2", + "mime": "1.6.0", + "ms": "2.1.1", + "on-finished": "~2.3.0", + "range-parser": "~1.2.1", + "statuses": "~1.5.0" + }, + "engines": { + "node": ">= 0.8.0" + } + }, + "node_modules/send/node_modules/ms": { + "version": "2.1.1", + "resolved": "https://registry.npmjs.org/ms/-/ms-2.1.1.tgz", + "integrity": "sha512-tgp+dl5cGk28utYktBsrFqA7HKgrhgPsg6Z/EfhWI4gl1Hwq8B/GmY/0oXZ6nF8hDVesS/FpnYaD/kOWhYQvyg==", + "license": "MIT" + }, + "node_modules/serve-static": { + "version": "1.14.1", + "resolved": "https://registry.npmjs.org/serve-static/-/serve-static-1.14.1.tgz", + "integrity": "sha512-JMrvUwE54emCYWlTI+hGrGv5I8dEwmco/00EvkzIIsR7MqrHonbD9pO2MOfFnpFntl7ecpZs+3mW+XbQZu9QCg==", + "license": "MIT", + "dependencies": { + "encodeurl": "~1.0.2", + "escape-html": "~1.0.3", + "parseurl": "~1.3.3", + "send": "0.17.1" + }, + "engines": { + "node": ">= 0.8.0" + } + }, + "node_modules/setprototypeof": { + "version": "1.1.1", + "resolved": "https://registry.npmjs.org/setprototypeof/-/setprototypeof-1.1.1.tgz", + "integrity": "sha512-JvdAWfbXeIGaZ9cILp38HntZSFSo3mWg6xGcJJsd+d4aRMOqauag1C63dJfDw7OaMYwEbHMOxEZ1lqVRYP2OAw==", + "license": "ISC" + }, + "node_modules/statuses": { + "version": "1.5.0", + "resolved": "https://registry.npmjs.org/statuses/-/statuses-1.5.0.tgz", + "integrity": "sha512-OpZ3zP+jT1PI7I8nemJX4AKmAX070ZkYPVWV/AaKTJl+tXCTGyVdC1a4SL8RUQYEwk/f34ZX8UTykN68FwrqAA==", + "license": "MIT", + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/toidentifier": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/toidentifier/-/toidentifier-1.0.0.tgz", + "integrity": "sha512-yaOH/Pk/VEhBWWTlhI+qXxDFXlejDGcQipMlyxda9nthulaxLZUNcUqFxokp0vcYnvteJln5FNQDRrxj3YcbVw==", + "license": "MIT", + "engines": { + "node": ">=0.6" + } + }, + "node_modules/type-is": { + "version": "1.6.18", + "resolved": "https://registry.npmjs.org/type-is/-/type-is-1.6.18.tgz", + "integrity": "sha512-TkRKr9sUTxEH8MdfuCSP7VizJyzRNMjj2J2do2Jr3Kym598JVdEksuzPQCnlFPW4ky9Q+iA+ma9BGm06XQBy8g==", + "license": "MIT", + "dependencies": { + "media-typer": "0.3.0", + "mime-types": "~2.1.24" + }, + "engines": { + "node": ">= 0.6" + } + }, + "node_modules/unpipe": { + "version": "1.0.0", + "resolved": "https://registry.npmjs.org/unpipe/-/unpipe-1.0.0.tgz", + "integrity": "sha512-pjy2bYhSsufwWlKwPc+l3cN7+wuJlK6uz0YdJEOlQDbl6jo/YlPi4mb8agUkVC8BF7V8NuzeyPNqRksA3hztKQ==", + "license": "MIT", + "engines": { + "node": ">= 0.8" + } + }, + "node_modules/utils-merge": { + "version": "1.0.1", + "resolved": "https://registry.npmjs.org/utils-merge/-/utils-merge-1.0.1.tgz", + "integrity": "sha512-pMZTvIkT1d+TFGvDOqodOclx0QWkkgi6Tdoa8gC8ffGAAqz9pzPTZWAybbsHHoED/ztMtkv/VoYTYyShUn81hA==", + "license": "MIT", + "engines": { + "node": ">= 0.4.0" + } + }, + "node_modules/vary": { + "version": "1.1.2", + "resolved": "https://registry.npmjs.org/vary/-/vary-1.1.2.tgz", + "integrity": "sha512-BNGbWLfd0eUPabhkXUVm0j8uuvREyTh5ovRa/dyow/BqAbZJyC+5fU+IzQOzmAKzYqYRAISoRhdQr3eIZ/PXqg==", + "license": "MIT", + "engines": { + "node": ">= 0.8" + } + } + } +} diff --git a/examples/open-source-friday-demo/shipping-api/package.json b/examples/open-source-friday-demo/shipping-api/package.json new file mode 100644 index 00000000..f4232518 --- /dev/null +++ b/examples/open-source-friday-demo/shipping-api/package.json @@ -0,0 +1,17 @@ +{ + "name": "shipping-api", + "version": "1.0.0", + "description": "Demo service for the Open Source Friday stream. Dependencies are deliberately pinned to old versions.", + "private": true, + "main": "src/index.js", + "scripts": { + "start": "node src/index.js" + }, + "dependencies": { + "express": "4.17.1", + "lodash": "4.17.20", + "axios": "0.21.1", + "jsonwebtoken": "8.5.1", + "minimist": "1.2.5" + } +} diff --git a/examples/open-source-friday-demo/shipping-api/src/index.js b/examples/open-source-friday-demo/shipping-api/src/index.js new file mode 100644 index 00000000..3a30d085 --- /dev/null +++ b/examples/open-source-friday-demo/shipping-api/src/index.js @@ -0,0 +1,21 @@ +// Minimal stand-in so the project looks like a real service rather than a +// bare package.json. Deliberately imports each dependency so import-based +// reachability (--usage / --only-used) has something to find. +const express = require("express"); +const jwt = require("jsonwebtoken"); +const axios = require("axios"); +const _ = require("lodash"); +const minimist = require("minimist"); + +const argv = minimist(process.argv.slice(2)); +const app = express(); + +app.get("/shipments/:id", async (req, res) => { + const token = req.headers.authorization?.replace("Bearer ", ""); + jwt.verify(token, process.env.JWT_SECRET ?? "dev-secret"); + + const { data } = await axios.get(`https://carrier.example.com/v1/${req.params.id}`); + res.json(_.pick(data, ["id", "status", "eta"])); +}); + +app.listen(argv.port ?? 3000); From 9956617dbbc0154fd49574cc4c9d36f9d214b7aa Mon Sep 17 00:00:00 2001 From: Sonu Kapoor Date: Tue, 8 Sep 2026 07:52:09 -0400 Subject: [PATCH 2/3] fix(examples): remove SSRF and missing-rate-limiting from the demo service CodeQL flagged two real issues in the demo source: a critical js/request-forgery from interpolating a route parameter into an outbound axios URL, and a high js/missing-rate-limiting on a route that performs authorization. Both were genuine. The point of this project is vulnerable dependencies, not vulnerable code, and it is committed to an OWASP repository where it gets scanned like everything else. The carrier lookup now targets a fixed host with the shipment id passed as an encoded query parameter, so the request target cannot be influenced by user input, and the id is validated against a strict pattern before any work happens. Authorization failures are handled rather than throwing. A comment records why the file must stay clean. Scan output is unchanged: 11 packages, 1 critical, 6 high, 5 direct and 6 transitive. --- .../shipping-api/src/index.js | 42 +++++++++++++++---- 1 file changed, 35 insertions(+), 7 deletions(-) diff --git a/examples/open-source-friday-demo/shipping-api/src/index.js b/examples/open-source-friday-demo/shipping-api/src/index.js index 3a30d085..ba99b066 100644 --- a/examples/open-source-friday-demo/shipping-api/src/index.js +++ b/examples/open-source-friday-demo/shipping-api/src/index.js @@ -1,6 +1,11 @@ -// Minimal stand-in so the project looks like a real service rather than a -// bare package.json. Deliberately imports each dependency so import-based -// reachability (--usage / --only-used) has something to find. +// Minimal stand-in so the project looks like a real service rather than a bare +// package.json, and so import-based reachability (--usage / --only-used) has +// something to find. Every dependency is imported deliberately. +// +// The point of this project is vulnerable DEPENDENCIES, not vulnerable code. +// Keep this file clean: it is committed to an OWASP repository and is scanned +// by CodeQL like everything else. An earlier version interpolated a request +// parameter into an outbound URL and was correctly flagged as SSRF. const express = require("express"); const jwt = require("jsonwebtoken"); const axios = require("axios"); @@ -10,12 +15,35 @@ const minimist = require("minimist"); const argv = minimist(process.argv.slice(2)); const app = express(); +// Carrier lookups go to a fixed, known host. Shipment ids are never +// concatenated into the URL; they are passed as an encoded query parameter so +// the request target cannot be influenced by user input. +const CARRIER_API = "https://carrier.example.com/v1/shipments"; + +function isValidShipmentId(value) { + return typeof value === "string" && /^[A-Z0-9]{8,20}$/.test(value); +} + +async function fetchShipment(shipmentId) { + const { data } = await axios.get(CARRIER_API, { + params: { id: shipmentId }, + timeout: 5000, + }); + return _.pick(data, ["id", "status", "eta"]); +} + app.get("/shipments/:id", async (req, res) => { - const token = req.headers.authorization?.replace("Bearer ", ""); - jwt.verify(token, process.env.JWT_SECRET ?? "dev-secret"); + if (!isValidShipmentId(req.params.id)) { + return res.status(400).json({ error: "invalid shipment id" }); + } + + try { + jwt.verify(req.headers.authorization?.replace("Bearer ", "") ?? "", process.env.JWT_SECRET); + } catch { + return res.status(401).json({ error: "unauthorized" }); + } - const { data } = await axios.get(`https://carrier.example.com/v1/${req.params.id}`); - res.json(_.pick(data, ["id", "status", "eta"])); + return res.json(await fetchShipment(req.params.id)); }); app.listen(argv.port ?? 3000); From 8d3f90af2dbb4dcf10e225fa61accae6716d2ba9 Mon Sep 17 00:00:00 2001 From: Sonu Kapoor Date: Tue, 8 Sep 2026 07:54:17 -0400 Subject: [PATCH 3/3] fix(examples): move authorization out of the route handler CodeQL still flagged js/missing-rate-limiting: the route performed JWT verification, and a route that authorizes should be rate limited. Adding a rate-limiter would mean adding a dependency, which changes the demo's finding counts, and the demo depends on those counts being stable. The scan reads package-lock.json rather than this file, so the source exists for realism and for import-based reachability only. Restructured as a worker: token verification happens once at startup against an environment variable, shipment polling is a plain function called by a scheduler, and the only route is an unauthenticated liveness probe. Scan output unchanged. --- .../shipping-api/src/index.js | 48 +++++++++++-------- 1 file changed, 28 insertions(+), 20 deletions(-) diff --git a/examples/open-source-friday-demo/shipping-api/src/index.js b/examples/open-source-friday-demo/shipping-api/src/index.js index ba99b066..d7f59056 100644 --- a/examples/open-source-friday-demo/shipping-api/src/index.js +++ b/examples/open-source-friday-demo/shipping-api/src/index.js @@ -3,9 +3,11 @@ // something to find. Every dependency is imported deliberately. // // The point of this project is vulnerable DEPENDENCIES, not vulnerable code. -// Keep this file clean: it is committed to an OWASP repository and is scanned -// by CodeQL like everything else. An earlier version interpolated a request -// parameter into an outbound URL and was correctly flagged as SSRF. +// The scan reads package-lock.json, so this file exists for realism only. +// Keep it clean: it lives in an OWASP repository and CodeQL scans it like +// everything else. Earlier versions were correctly flagged twice, once for +// SSRF (a route parameter interpolated into an outbound URL) and once for +// performing authorization in a route handler with no rate limiting. const express = require("express"); const jwt = require("jsonwebtoken"); const axios = require("axios"); @@ -13,18 +15,30 @@ const _ = require("lodash"); const minimist = require("minimist"); const argv = minimist(process.argv.slice(2)); -const app = express(); -// Carrier lookups go to a fixed, known host. Shipment ids are never -// concatenated into the URL; they are passed as an encoded query parameter so -// the request target cannot be influenced by user input. +// Fixed host. Shipment ids travel as an encoded query parameter and are never +// concatenated into the URL, so the request target cannot be influenced by +// user input. const CARRIER_API = "https://carrier.example.com/v1/shipments"; function isValidShipmentId(value) { return typeof value === "string" && /^[A-Z0-9]{8,20}$/.test(value); } -async function fetchShipment(shipmentId) { +/** Verifies the service-to-service token this worker was started with. */ +function loadServiceIdentity() { + const token = process.env.SERVICE_TOKEN; + if (!token) return null; + try { + return _.pick(jwt.verify(token, process.env.JWT_SECRET), ["sub", "scope"]); + } catch { + return null; + } +} + +/** Polls the carrier for one shipment. Called by the scheduler, not by a route. */ +async function syncShipment(shipmentId) { + if (!isValidShipmentId(shipmentId)) return null; const { data } = await axios.get(CARRIER_API, { params: { id: shipmentId }, timeout: 5000, @@ -32,18 +46,12 @@ async function fetchShipment(shipmentId) { return _.pick(data, ["id", "status", "eta"]); } -app.get("/shipments/:id", async (req, res) => { - if (!isValidShipmentId(req.params.id)) { - return res.status(400).json({ error: "invalid shipment id" }); - } - - try { - jwt.verify(req.headers.authorization?.replace("Bearer ", "") ?? "", process.env.JWT_SECRET); - } catch { - return res.status(401).json({ error: "unauthorized" }); - } +const identity = loadServiceIdentity(); +const app = express(); - return res.json(await fetchShipment(req.params.id)); -}); +// Unauthenticated liveness probe. No authorization happens in any route. +app.get("/healthz", (_req, res) => res.json({ ok: true, as: identity?.sub ?? "anonymous" })); app.listen(argv.port ?? 3000); + +module.exports = { syncShipment, loadServiceIdentity, isValidShipmentId };