Feat/bound unpaginated audit queries - #1118
Open
ajulaybeeb wants to merge 2 commits into
Open
Conversation
…uard - Refactored the file size guard in main.ts to enforce stream-level byte counting. - Missing or unparseable Content-Length requests without chunked encoding are now rejected with 411 Length Required. - Added a counting stream guard that destroys the request if actual payload bytes exceed the limit. - Updated multer config in upload-validation.util.ts to dynamically read FILE_UPLOAD_MAX_BYTES. - Added e2e tests for chunked upload bypassing and understated Content-Length scenarios. Closes rinafcode#989
- Added explicit skip/take pagination with a hard server-side max of 1000 items to all six AuditQueryService find methods. - Enforced a default 30-day time window for all temporal queries to protect against massive history scans. - Added a streamAll cursor-based method for bulk exports to prevent memory exhaustion. - Optimized the entity index for entityType/entityId to include timestamp. - Added tests asserting pagination ceiling clamp and the default time window. Closes rinafcode#1019
|
@ajulaybeeb Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
Contributor
|
Well done on the job done so far! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1019
**: Bounds unpaginated repository reads in
AuditQueryServiceto prevent OOM / memory exhaustion vulnerabilities during compliance and incident investigations. Audit logs are append-only and the fastest-growing table in the system; this PR guarantees that all queries are safely bounded by pagination and temporal limits.Security Mitigations & Enhancements
find*methods (findAll,findByUser,findByAction,findByEntity,findByIpAddress,findByDateRange) to enforce a hard server-side pagination ceiling (take: Math.min(limit, 1000)).startDate/endDate) if none is explicitly provided, neutralizing unbound historical full-table scans.streamAll(filters)method utilizing TypeORM'sstream()capabilities for safe bulk exporting, allowing unbounded cursor traversal without materializing result sets into memory.['entityType', 'entityId']to includetimestamp, allowing queries filtering by entity targets to utilize the index for theirORDER BY timestamp DESCclauses.audit-query.service.spec.ts) strictly asserting that pagination parameters are clamped to the1000hard limit ceiling and that the 30-day bounds are applied automatically.