Files
J621/backend/config/settings.py
T
JakeBreath f86eccf9a3 Security fixes: SSRF, staff role escalation, SPA-only gating, throttling, encrypted keys
Findings from the audit (50-check harness across guest/user/uploader/staff/
admin) and their fixes:

- SSRF: 'Download to Library' and the staged-upload resolve path fetched
  any http(s) URL. services.validate_remote_url now enforces the e621
  media allowlist and open_remote re-validates every redirect hop; the
  download-task create endpoint and the guest proxy use them, so internal
  addresses (127.0.0.1, LAN, metadata) are rejected with 400.
- Privilege escalation: staff could promote users to staff and demote
  other staff. Role changes across the staff boundary now require an
  admin, matching the account-deletion rules; the Users page hides what
  the backend would refuse.
- SPA-only gating: /api/storage/ and /api/duplicates/* were readable by
  any authenticated account (absolute paths, duplicate groups) while the
  SPA only shows them to uploaders. They now require CanUpload.
- Throttling (REST_FRAMEWORK, env-overridable, counted in Redis):
  anon 120/min, user 600/min, login 5/min, register 20/hour, guest e621
  proxy 60/hour. Login now goes through a throttled view.
- e621 API keys are encrypted at rest with a Fernet key derived from
  SECRET_KEY (apps/accounts/crypto.py); a data migration encrypts existing
  rows and the column widens first. Reads decrypt transparently, legacy
  plaintext still works, and a changed SECRET_KEY reads as 'not
  configured' instead of leaking. Rotating SECRET_KEY now invalidates
  stored keys as well as signed media URLs.
- Hardening: the server refuses to start with DEBUG=False while SECRET_KEY
  is still the development default.

Verified: corrected harness 50/50 (guest visibility, IDOR, signed-URL
tamper/expiry, staged-upload/similarity privacy, role matrix, SSRF),
login throttles at the 6th attempt with 429, anon polling unaffected, the
guest proxy still reaches allowlisted hosts, live e621 auth works with the
decrypted key, and DB rows hold only ciphertext.
2026-09-18 00:21:14 -05:00

313 lines
9.7 KiB
Python

"""
Django settings for the J621 backend.
"""
import os
import subprocess
from pathlib import Path
from django.core.exceptions import ImproperlyConfigured
from dotenv import load_dotenv
BASE_DIR = Path(__file__).resolve().parent.parent
load_dotenv(BASE_DIR / ".env")
SECRET_KEY = os.getenv("SECRET_KEY", "django-insecure-dev-only-change-me")
DEBUG = os.getenv("DEBUG", "True").lower() == "true"
if not DEBUG and SECRET_KEY == "django-insecure-dev-only-change-me":
raise ImproperlyConfigured(
"SECRET_KEY is still the development default. Set a long random value "
"in backend/.env before running with DEBUG=False — it signs the media "
"URLs and encrypts stored e621 keys."
)
ALLOWED_HOSTS = [
host.strip()
for host in os.getenv("ALLOWED_HOSTS", "localhost,127.0.0.1,0.0.0.0").split(",")
if host.strip()
]
# Same-origin access always works; list extra frontend origins in
# CORS_ALLOWED_ORIGINS (comma separated, e.g. https://j621.example.com).
CORS_ALLOWED_ORIGINS = [
origin.strip().rstrip("/")
for origin in os.getenv("CORS_ALLOWED_ORIGINS", "").split(",")
if origin.strip()
]
# Escape hatch for local experiments; never enable against a public server.
CORS_ALLOW_ALL_ORIGINS = (
os.getenv("CORS_ALLOW_ALL_ORIGINS", "false").lower() == "true"
)
# The SPA authenticates with an Authorization: Token header, not cookies, so
# cross-origin requests do not need credentials. Enable this only if a
# cross-origin client really relies on cookies (e.g. the Django admin).
CORS_ALLOW_CREDENTIALS = (
os.getenv("CORS_ALLOW_CREDENTIALS", "false").lower() == "true"
)
# Same list, for session/CSRF-protected endpoints (Django admin) reached from
# another origin.
CSRF_TRUSTED_ORIGINS = [
origin.strip().rstrip("/")
for origin in os.getenv("CSRF_TRUSTED_ORIGINS", "").split(",")
if origin.strip()
]
# Behind a TLS-terminating proxy the backend sees plain http; trust the
# proxy's X-Forwarded-Proto/Host so absolute media URLs keep https and the
# public hostname.
if os.getenv("TRUST_PROXY_HEADERS", "false").lower() == "true":
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
USE_X_FORWARDED_HOST = True
def _git_commit_hash():
"""Short git hash of the running build, mirroring the original app."""
try:
return subprocess.check_output(
["git", "rev-parse", "--short", "HEAD"],
cwd=BASE_DIR,
text=True,
stderr=subprocess.DEVNULL,
).strip()
except (subprocess.SubprocessError, OSError):
return "unknown"
GIT_COMMIT_HASH = _git_commit_hash()
APP_ENV = "dev" if DEBUG else "prod"
APP_VERSION = f"{APP_ENV} @ {GIT_COMMIT_HASH}"
# Application definition
INSTALLED_APPS = [
"django.contrib.admin",
"django.contrib.auth",
"django.contrib.contenttypes",
"django.contrib.sessions",
"django.contrib.messages",
"django.contrib.staticfiles",
"rest_framework",
"rest_framework.authtoken",
"django_filters",
"corsheaders",
"apps.accounts",
"apps.library",
"apps.follows",
"apps.core",
]
MIDDLEWARE = [
"django.middleware.security.SecurityMiddleware",
# Must sit above CommonMiddleware so preflights are answered early.
"corsheaders.middleware.CorsMiddleware",
"django.contrib.sessions.middleware.SessionMiddleware",
"django.middleware.common.CommonMiddleware",
"django.middleware.csrf.CsrfViewMiddleware",
"django.contrib.auth.middleware.AuthenticationMiddleware",
"django.contrib.messages.middleware.MessageMiddleware",
"django.middleware.clickjacking.XFrameOptionsMiddleware",
"apps.core.middleware.TimingMiddleware",
]
ROOT_URLCONF = "config.urls"
TEMPLATES = [
{
"BACKEND": "django.template.backends.django.DjangoTemplates",
"DIRS": [],
"APP_DIRS": True,
"OPTIONS": {
"context_processors": [
"django.template.context_processors.request",
"django.contrib.auth.context_processors.auth",
"django.contrib.messages.context_processors.messages",
],
},
},
]
WSGI_APPLICATION = "config.wsgi.application"
# Database (MariaDB, run via docker compose at the repo root)
DATABASES = {
"default": {
"ENGINE": "django.db.backends.mysql",
"NAME": os.getenv("DB_NAME", "j621"),
"USER": os.getenv("DB_USER", "j621"),
"PASSWORD": os.getenv("DB_PASSWORD", "j621"),
"HOST": os.getenv("DB_HOST", "127.0.0.1"),
"PORT": os.getenv("DB_PORT", "3307"),
"OPTIONS": {"charset": "utf8mb4"},
}
}
# Authentication
AUTH_USER_MODEL = "accounts.User"
AUTH_PASSWORD_VALIDATORS = [
{
"NAME": "django.contrib.auth.password_validation.UserAttributeSimilarityValidator",
},
{
"NAME": "django.contrib.auth.password_validation.MinimumLengthValidator",
},
{
"NAME": "django.contrib.auth.password_validation.CommonPasswordValidator",
},
{
"NAME": "django.contrib.auth.password_validation.NumericPasswordValidator",
},
]
# Internationalization
LANGUAGE_CODE = "en-us"
TIME_ZONE = os.getenv("TIME_ZONE", "America/Bogota")
USE_I18N = True
USE_TZ = True
# Static and media files
STATIC_URL = "static/"
STATIC_ROOT = BASE_DIR / "staticfiles"
MEDIA_URL = "/media/"
MEDIA_ROOT = BASE_DIR / "media"
# Watched folder that gets indexed into the library.
_watched = os.getenv("WATCHED_FOLDER", "").strip()
WATCHED_FOLDER = Path(_watched) if _watched else MEDIA_ROOT / "library"
if not WATCHED_FOLDER.is_absolute():
WATCHED_FOLDER = BASE_DIR / WATCHED_FOLDER
WATCHED_FOLDER = str(WATCHED_FOLDER)
# e621 integration
E621_BASE_URL = os.getenv("E621_BASE_URL", "https://e621.net").rstrip("/")
USER_AGENT = os.getenv("USER_AGENT", "J621/0.1 (by J621 on e621)")
# Hosts the client-download proxy is allowed to stream from.
E621_MEDIA_HOSTS = [
host.strip()
for host in os.getenv(
"E621_MEDIA_HOSTS",
"static1.e621.net,static2.e621.net,static3.e621.net",
).split(",")
if host.strip()
]
# Guest visibility: e621's anonymous default blacklist is mirrored into the
# cache by `manage.py refresh_guest_blacklist`. This fallback is used until
# that command runs or when e621 is unreachable.
GUEST_BLACKLIST_FALLBACK = [
tag.strip()
for tag in os.getenv(
"GUEST_BLACKLIST_FALLBACK", "young,cub,shota,loli,child,underage"
).split(",")
if tag.strip()
]
GUEST_BLACKLIST_TTL = int(os.getenv("GUEST_BLACKLIST_TTL", "3600"))
# Similarity threshold for flagging staged uploads that match library items.
VISUAL_MATCH_THRESHOLD = float(os.getenv("VISUAL_MATCH_THRESHOLD", "0.9"))
# Ephemeral similarity-check uploads are deleted after this many minutes
# (and always on startup).
SIMILARITY_TTL_MINUTES = int(os.getenv("SIMILARITY_TTL_MINUTES", "30"))
# Redis cache (run via docker compose at the repo root), shared by web
# workers and management commands (e.g. the mirrored guest blacklist).
CACHES = {
"default": {
"BACKEND": "django.core.cache.backends.redis.RedisCache",
"LOCATION": os.getenv("REDIS_URL", "redis://127.0.0.1:6380/1"),
}
}
# Django REST Framework
REST_FRAMEWORK = {
"DEFAULT_AUTHENTICATION_CLASSES": [
"rest_framework.authentication.TokenAuthentication",
],
"DEFAULT_PERMISSION_CLASSES": [
"rest_framework.permissions.IsAuthenticatedOrReadOnly",
],
"DEFAULT_FILTER_BACKENDS": [
"django_filters.rest_framework.DjangoFilterBackend",
"rest_framework.filters.SearchFilter",
"rest_framework.filters.OrderingFilter",
],
"DEFAULT_PAGINATION_CLASS": "config.pagination.StandardPagination",
"PAGE_SIZE": 48,
# Per-IP/per-user rate limits (counted in the shared Redis cache).
"DEFAULT_THROTTLE_CLASSES": [
"rest_framework.throttling.AnonRateThrottle",
"rest_framework.throttling.UserRateThrottle",
],
"DEFAULT_THROTTLE_RATES": {
# Generous enough for the shell polling (status every 5s, stats every 2s).
"anon": os.getenv("THROTTLE_ANON", "120/min"),
"user": os.getenv("THROTTLE_USER", "600/min"),
# Credential stuffing / spam guards.
"login": os.getenv("THROTTLE_LOGIN", "5/min"),
"register": os.getenv("THROTTLE_REGISTER", "20/hour"),
# The guest e621 download proxy streams whole files.
"e621_proxy": os.getenv("THROTTLE_E621_PROXY", "60/hour"),
},
}
DEFAULT_AUTO_FIELD = "django.db.models.BigAutoField"
LOGS_DIR = BASE_DIR / "logs"
LOG_FILE = LOGS_DIR / "j621.log"
try:
LOGS_DIR.mkdir(parents=True, exist_ok=True)
except OSError: # read-only checkout: keep console logging only
pass
_log_handlers = {
"console": {
"class": "logging.StreamHandler",
"formatter": "simple",
},
}
_root_handlers = ["console"]
if LOGS_DIR.exists():
_log_handlers["file"] = {
"class": "logging.handlers.RotatingFileHandler",
"filename": str(LOG_FILE),
"maxBytes": 5 * 1024 * 1024,
"backupCount": 3,
"encoding": "utf-8",
"formatter": "simple",
}
_root_handlers.append("file")
LOGGING = {
"version": 1,
"disable_existing_loggers": False,
"formatters": {
"simple": {
"format": "{levelname} {asctime} {name} {message}",
"style": "{",
},
},
"handlers": _log_handlers,
"loggers": {
# Scanners on the network probe things like /health and /v1/models;
# their 404s are noise in the log file. Real server errors (5xx) still
# log, and the dev server keeps printing every request to the console.
"django.request": {
"handlers": _root_handlers,
"level": "ERROR",
"propagate": False,
},
},
"root": {
"handlers": _root_handlers,
"level": "INFO",
},
}