LibreChat/api/server/services/Files/images/avatar.js
Danny Avila c7f38d9621
🛡️ fix: Validate Avatar URL Before Fetch (#12928)
`resizeAvatar` previously called `node-fetch` on any string input with
no validation. When OIDC providers surface a user-controllable
`picture` claim, this could be used to make blind SSRF requests to
internal services on every social login.

Wrap the URL fetch with:
- An allowlist on the URL protocol (http/https only).
- The shared `createSSRFSafeAgents` utility, which blocks resolution to
  private, loopback, and link-local IPs at TCP connect time
  (TOCTOU-safe; works equally for hostname targets that DNS-resolve
  privately and for IP-literal targets, since Node's `net.Socket`
  always dispatches through the agent's `lookup` hook).
- `redirect: 'error'` so a public-IP redirect target cannot be used to
  bypass the agent check on a subsequent hop.
- A 5-second total request budget (node-fetch v2's `timeout` covers
  request initiation through full body receipt, bounding slow-loris
  exposure rather than just the TCP connect).
- A 10 MB response cap (`size` option + `Content-Length` pre-check +
  post-read length assertion) so a hostile payload cannot exhaust
  memory before `sharp()` rejects it.

Fetch the canonicalized `parsed.href` rather than the raw input string
to eliminate any future parser-differential between `new URL()` and
the underlying fetch implementation.

Per-call agent construction is intentional: the avatar path runs once
per social login per user, so pooling adds complexity without a
measurable benefit. Documented inline.

Comprehensive test coverage in `avatar.spec.js`:
- Rejects malformed URLs, non-http(s) schemes (file://, data:,
  javascript:).
- Asserts the happy-path canonicalization (`fetch` is called with
  `parsed.href`) and the SSRF-safe agent factory routing
  (https→httpsAgent, http→httpAgent).
- Rejects non-2xx HTTP status.
- Rejects an oversized Content-Length before reading the body, and
  asserts `.buffer()` is never invoked in that case.
- Rejects an oversized body even when the server lies about / omits
  Content-Length.
- Surfaces ESSRF, redirect, and `size` overflow errors thrown by the
  fetch layer.
- Confirms Buffer inputs bypass the fetcher entirely.
2026-05-04 11:16:40 +09:00

147 lines
5.3 KiB
JavaScript

const sharp = require('sharp');
const fs = require('fs').promises;
const fetch = require('node-fetch');
const { logger } = require('@librechat/data-schemas');
const { EImageOutputType } = require('librechat-data-provider');
const { createSSRFSafeAgents } = require('@librechat/api');
const { resizeAndConvert } = require('./resize');
const ALLOWED_AVATAR_PROTOCOLS = new Set(['http:', 'https:']);
/**
* Cap response size to bound memory exposure if a malicious or compromised
* `picture` URL serves a multi-GB payload. Avatars are at most a few hundred
* KB in practice; 10 MB is well past any legitimate use.
*/
const MAX_AVATAR_BYTES = 10 * 1024 * 1024;
/**
* Fetches an image URL with SSRF protection: rejects non-http(s) schemes,
* blocks resolution to private/loopback/link-local IPs at TCP connect time,
* refuses to follow redirects to prevent post-validation rebinding, and caps
* the response body so a hostile payload cannot exhaust memory before
* `sharp()` rejects it.
*
* Per-call agent construction is intentional: avatar fetches are infrequent
* (once per social login per user) and pooling adds complexity without a
* measurable benefit on this path. If this ever becomes a hot path, hoist
* the agents to module scope.
*/
async function fetchAvatarBuffer(input) {
let parsed;
try {
parsed = new URL(input);
} catch {
throw new Error('Invalid avatar URL');
}
if (!ALLOWED_AVATAR_PROTOCOLS.has(parsed.protocol)) {
throw new Error(`Refusing to fetch avatar over ${parsed.protocol}`);
}
const { httpAgent, httpsAgent } = createSSRFSafeAgents();
/**
* `node-fetch` v2's `timeout` is the total request budget (request initiation
* through full body receipt), not a TCP-connect-only timeout. That is the
* stronger of the two for this path — bounds total slow-loris exposure.
*/
const response = await fetch(parsed.href, {
agent: (urlObj) => (urlObj.protocol === 'https:' ? httpsAgent : httpAgent),
redirect: 'error',
timeout: 5000,
size: MAX_AVATAR_BYTES,
});
if (!response.ok) {
throw new Error(`Failed to fetch image from URL. Status: ${response.status}`);
}
const contentLength = parseInt(response.headers.get('content-length') ?? '0', 10);
if (contentLength > MAX_AVATAR_BYTES) {
throw new Error(`Avatar response too large: ${contentLength} bytes`);
}
/**
* Re-check after read in case the server lied about Content-Length or
* omitted it. `node-fetch` v2 honors the `size` option above and throws on
* overflow, but Defense-in-depth: assert on the actual buffer length.
*/
const buffer = await response.buffer();
if (buffer.length > MAX_AVATAR_BYTES) {
throw new Error(`Avatar response too large: ${buffer.length} bytes`);
}
return buffer;
}
/**
* Uploads an avatar image for a user. This function can handle various types of input (URL, Buffer, or File object),
* processes the image to a square format, converts it to target format, and returns the resized buffer.
*
* @param {Object} params - The parameters object.
* @param {string} params.userId - The unique identifier of the user for whom the avatar is being uploaded.
* @param {string} options.desiredFormat - The desired output format of the image.
* @param {(string|Buffer|File)} params.input - The input representing the avatar image. Can be a URL (string),
* a Buffer, or a File object.
*
* @returns {Promise<any>}
* A promise that resolves to a resized buffer.
*
* @throws {Error} Throws an error if the user ID is undefined, the input type is invalid, the image fetching fails,
* or any other error occurs during the processing.
*/
async function resizeAvatar({ userId, input, desiredFormat = EImageOutputType.PNG }) {
try {
if (userId === undefined) {
throw new Error('User ID is undefined');
}
let imageBuffer;
if (typeof input === 'string') {
imageBuffer = await fetchAvatarBuffer(input);
} else if (input instanceof Buffer) {
imageBuffer = input;
} else if (typeof input === 'object' && input instanceof File) {
const fileContent = await fs.readFile(input.path);
imageBuffer = Buffer.from(fileContent);
} else {
throw new Error('Invalid input type. Expected URL, Buffer, or File.');
}
const metadata = await sharp(imageBuffer).metadata();
const { width, height } = metadata;
const minSize = Math.min(width, height);
if (metadata.format === 'gif') {
const resizedBuffer = await sharp(imageBuffer, { animated: true })
.extract({
left: Math.floor((width - minSize) / 2),
top: Math.floor((height - minSize) / 2),
width: minSize,
height: minSize,
})
.resize(250, 250)
.gif()
.toBuffer();
return resizedBuffer;
}
const squaredBuffer = await sharp(imageBuffer)
.extract({
left: Math.floor((width - minSize) / 2),
top: Math.floor((height - minSize) / 2),
width: minSize,
height: minSize,
})
.toBuffer();
const { buffer } = await resizeAndConvert({
inputBuffer: squaredBuffer,
desiredFormat,
});
return buffer;
} catch (error) {
logger.error('Error uploading the avatar:', error);
throw error;
}
}
module.exports = { resizeAvatar };