Skip to content

Harden upload and logging boundaries and make extraction workers recoverable - #271

Merged
nonprofittechy merged 4 commits into
mainfrom
security/high-priority-hardening
Sep 30, 2026
Merged

nonprofittechy merged 4 commits into
mainfrom
security/high-priority-hardening

Conversation

@nonprofittechy

Copy link
Copy Markdown
Member

Public legacy upload routes allowed anonymous S3 writes, application logs could contain credentials and filing contents, and obsolete extraction workers could overwrite newer analysis. This PR closes those routes and logging paths, updates vulnerable dependencies, and makes extraction attempts bounded and recoverable. YAML remains the authoring format with the existing in-memory cache.

Changes

  • Remove legacy upload, mock upload, bucket diagnostic, and session-debug routes. Remove sensitive submission and API logging; default application logging to INFO.
  • Upgrade Django to 5.2.17 and update vulnerable resolved dependencies. Add a CI dependency audit using the lockfile.
  • Restrict jurisdiction lookup to installed canonical identifiers. Preserve base configuration when no jurisdiction is selected and tolerate invalid identifiers during template/error-page rendering.
  • Fence extraction attempts with claim tokens and renewable leases; add retry backoff and recovery of exhausted interrupted jobs. Run each attempt in a supervised child with time and memory limits. Preference changes discard obsolete results and refund superseded attempts without erasing earlier real failures.
  • Disable persistent ASGI database connections, configure manifest static storage through STORAGES, and remove S3 bucket probes from ordinary operations.

Validation

  • Full backend suite and JavaScript unit tests passed the final pre-push checks. Separately, 108 focused regression tests passed, with a further extraction rerun passing all 15 checks.
  • Focused end-to-end run: 39 checks passed, including complete filing flows for Illinois, Massachusetts, and Vermont with court calls stubbed.
  • Live Chromium checks against an isolated local database: removed routes, configuration fallback, invalid-jurisdiction rendering, authenticated preference changes, status polling, and review rendering passed.
  • A real spawned extraction worker processed a seven-page synthetic PDF from local test storage in keyword mode. No live court submission or AI service was used.
  • Formatting, Ruff, ty, Bandit, and migration consistency checks passed. Dependency audit reports no known vulnerabilities in audited packages; the two unpublished GitHub court-directory packages are outside its coverage.
  • Docker image rebuilt; hashed static URLs, gzip encoding, and immutable cache headers verified.

Rollout and scope

Stop old extraction workers before applying migration 0028_extraction_claim_leases and starting the new web/worker image. Old workers do not honor claim tokens. Defaults are 600 seconds and 768 MiB of virtual address space per extraction child; validate against representative documents before increasing worker capacity.

Review historical logs and rotate/revoke credentials confirmed to have been recorded. No production deployment or load test was performed. Upload quotas/cleanup, browser CSRF restoration, session-polling writes, and configuration compilation remain follow-up work. See docs/developer-notes/security-hardening.md for details.

@nonprofittechy
nonprofittechy merged commit ce92201 into main Sep 30, 2026
8 checks passed
@nonprofittechy
nonprofittechy deleted the security/high-priority-hardening branch September 30, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant