security(main): dialog-grant admission for local paths, explicit webPreferences

New localPathGrants.ts: an in-memory registry of paths the user picked in a
native dialog. Every check resolves realpath + stat at grant and use time;
Windows case folding; missing files, directories-as-files, devices and
symlinked parents can never pass. SFTP upload/download and zmodem send/
receive now refuse renderer-supplied local paths that were never granted,
returning the resolved path so callers never re-traverse a symlink. keyPath
is validated as a regular file <= 1MB before reading (a device node would
have blocked the UI thread forever). Tests inject a stub policy via
setLocalPathPolicy; production always defaults to the real registry.

Also: webPreferences now explicitly pins contextIsolation/nodeIntegration/
webSecurity instead of relying on defaults.

New offline test tests/local-path-grants.mjs (37 assertions incl. symlink
escape); offline suite grows to 13. i18n: 6 main.sftp/main.key error keys
in 4 languages.
This commit is contained in:
Bill committed 2026-10-07 22:06:45 +08:00
1 parent 9c75cdc7d4
commit d22923aedd
14 files changed
+612 -18

No files matched your search

+17
View File
@@ -83,6 +83,23 @@ if (!existsSync(bundlePath)) {
const zmodem = require_('zmodem.js')
const engine = require_(bundlePath)
/**
* Local-path admission for the engine. In the app the default policy only
* accepts paths the user granted through a native dialog (localPathGrants.ts),
* and this harness has no dialog to grant from — so the scenarios supply their
* own double. It is deliberately permissive (and deliberately NOT a re-export
* of the real policy, which is what keeps these scenarios about transfer
* mechanics rather than admission rules).
*/
engine.setLocalPathPolicy({
readSource: (p) => (typeof p === 'string' ? p : null),
readDirectory: (d) => (typeof d === 'string' && d !== '' ? d : null),
writeTarget: (dir, name) =>
typeof dir === 'string' && dir !== '' && typeof name === 'string' && name !== ''
? join(dir, name)
: null
})
const sleep = (ms) => new Promise((r) => setTimeout(r, ms))
/**