KamoCRM

No anonymous write to the session Redis, and no session id in the sign-out log

Fixkamo-login
Dikirim
25 September 2026 pukul 10.17 UTC
Penulis
Kamo
Commit
b826b5a

POST /api/session stored any JSON under any KS= key, with a caller-chosen TTL and no authentication, through a Redis client pair of its own. The session Redis runs maxmemory 2gb with allkeys-lru, so a flood of those keys evicts every *** and OTK and signs the whole platform out; the Redis ACL cannot stop it because the route writes as kamo_app. Nothing read a KS= key and nothing called the route (the page uses /api/session/select), so it is deleted, and app/lib/redis.ts is now the only Redis client. Sign-out logged the whole session key twice, and on a Redis failure it printed the ioredis error, which carries the failed command's arguments (the key again). It now logs neither. tests/session-redis.test.mjs (node --test tests/*.test.mjs) pins both: only app/lib/redis.ts opens Redis, no route writes to it except sign-out deleting the caller's own session, and no sign-out log line carries the id, on success or on a Redis failure. KamoAI SP00 final review I-2 and P3.

Semua perubahan

Seperti apa yang Anda lihat pengiriman?

Semua itu tiba di ruang kerjamu sendiri. Mulailah dengan rencana gratis dan baca halaman ini lagi dalam sebulan.

Mulai Bebas SelamanyaTampilkan Harga