mirror of
https://github.com/danny-avila/LibreChat.git
synced 2026-08-04 14:57:42 +00:00
`resizeAvatar` previously called `node-fetch` on any string input with no validation. When OIDC providers surface a user-controllable `picture` claim, this could be used to make blind SSRF requests to internal services on every social login. Wrap the URL fetch with: - An allowlist on the URL protocol (http/https only). - The shared `createSSRFSafeAgents` utility, which blocks resolution to private, loopback, and link-local IPs at TCP connect time (TOCTOU-safe; works equally for hostname targets that DNS-resolve privately and for IP-literal targets, since Node's `net.Socket` always dispatches through the agent's `lookup` hook). - `redirect: 'error'` so a public-IP redirect target cannot be used to bypass the agent check on a subsequent hop. - A 5-second total request budget (node-fetch v2's `timeout` covers request initiation through full body receipt, bounding slow-loris exposure rather than just the TCP connect). - A 10 MB response cap (`size` option + `Content-Length` pre-check + post-read length assertion) so a hostile payload cannot exhaust memory before `sharp()` rejects it. Fetch the canonicalized `parsed.href` rather than the raw input string to eliminate any future parser-differential between `new URL()` and the underlying fetch implementation. Per-call agent construction is intentional: the avatar path runs once per social login per user, so pooling adds complexity without a measurable benefit. Documented inline. Comprehensive test coverage in `avatar.spec.js`: - Rejects malformed URLs, non-http(s) schemes (file://, data:, javascript:). - Asserts the happy-path canonicalization (`fetch` is called with `parsed.href`) and the SSRF-safe agent factory routing (https→httpsAgent, http→httpAgent). - Rejects non-2xx HTTP status. - Rejects an oversized Content-Length before reading the body, and asserts `.buffer()` is never invoked in that case. - Rejects an oversized body even when the server lies about / omits Content-Length. - Surfaces ESSRF, redirect, and `size` overflow errors thrown by the fetch layer. - Confirms Buffer inputs bypass the fetcher entirely.
147 lines
5.3 KiB
JavaScript
147 lines
5.3 KiB
JavaScript
const sharp = require('sharp');
|
|
const fs = require('fs').promises;
|
|
const fetch = require('node-fetch');
|
|
const { logger } = require('@librechat/data-schemas');
|
|
const { EImageOutputType } = require('librechat-data-provider');
|
|
const { createSSRFSafeAgents } = require('@librechat/api');
|
|
const { resizeAndConvert } = require('./resize');
|
|
|
|
const ALLOWED_AVATAR_PROTOCOLS = new Set(['http:', 'https:']);
|
|
/**
|
|
* Cap response size to bound memory exposure if a malicious or compromised
|
|
* `picture` URL serves a multi-GB payload. Avatars are at most a few hundred
|
|
* KB in practice; 10 MB is well past any legitimate use.
|
|
*/
|
|
const MAX_AVATAR_BYTES = 10 * 1024 * 1024;
|
|
|
|
/**
|
|
* Fetches an image URL with SSRF protection: rejects non-http(s) schemes,
|
|
* blocks resolution to private/loopback/link-local IPs at TCP connect time,
|
|
* refuses to follow redirects to prevent post-validation rebinding, and caps
|
|
* the response body so a hostile payload cannot exhaust memory before
|
|
* `sharp()` rejects it.
|
|
*
|
|
* Per-call agent construction is intentional: avatar fetches are infrequent
|
|
* (once per social login per user) and pooling adds complexity without a
|
|
* measurable benefit on this path. If this ever becomes a hot path, hoist
|
|
* the agents to module scope.
|
|
*/
|
|
async function fetchAvatarBuffer(input) {
|
|
let parsed;
|
|
try {
|
|
parsed = new URL(input);
|
|
} catch {
|
|
throw new Error('Invalid avatar URL');
|
|
}
|
|
if (!ALLOWED_AVATAR_PROTOCOLS.has(parsed.protocol)) {
|
|
throw new Error(`Refusing to fetch avatar over ${parsed.protocol}`);
|
|
}
|
|
|
|
const { httpAgent, httpsAgent } = createSSRFSafeAgents();
|
|
/**
|
|
* `node-fetch` v2's `timeout` is the total request budget (request initiation
|
|
* through full body receipt), not a TCP-connect-only timeout. That is the
|
|
* stronger of the two for this path — bounds total slow-loris exposure.
|
|
*/
|
|
const response = await fetch(parsed.href, {
|
|
agent: (urlObj) => (urlObj.protocol === 'https:' ? httpsAgent : httpAgent),
|
|
redirect: 'error',
|
|
timeout: 5000,
|
|
size: MAX_AVATAR_BYTES,
|
|
});
|
|
|
|
if (!response.ok) {
|
|
throw new Error(`Failed to fetch image from URL. Status: ${response.status}`);
|
|
}
|
|
|
|
const contentLength = parseInt(response.headers.get('content-length') ?? '0', 10);
|
|
if (contentLength > MAX_AVATAR_BYTES) {
|
|
throw new Error(`Avatar response too large: ${contentLength} bytes`);
|
|
}
|
|
|
|
/**
|
|
* Re-check after read in case the server lied about Content-Length or
|
|
* omitted it. `node-fetch` v2 honors the `size` option above and throws on
|
|
* overflow, but Defense-in-depth: assert on the actual buffer length.
|
|
*/
|
|
const buffer = await response.buffer();
|
|
if (buffer.length > MAX_AVATAR_BYTES) {
|
|
throw new Error(`Avatar response too large: ${buffer.length} bytes`);
|
|
}
|
|
return buffer;
|
|
}
|
|
|
|
/**
|
|
* Uploads an avatar image for a user. This function can handle various types of input (URL, Buffer, or File object),
|
|
* processes the image to a square format, converts it to target format, and returns the resized buffer.
|
|
*
|
|
* @param {Object} params - The parameters object.
|
|
* @param {string} params.userId - The unique identifier of the user for whom the avatar is being uploaded.
|
|
* @param {string} options.desiredFormat - The desired output format of the image.
|
|
* @param {(string|Buffer|File)} params.input - The input representing the avatar image. Can be a URL (string),
|
|
* a Buffer, or a File object.
|
|
*
|
|
* @returns {Promise<any>}
|
|
* A promise that resolves to a resized buffer.
|
|
*
|
|
* @throws {Error} Throws an error if the user ID is undefined, the input type is invalid, the image fetching fails,
|
|
* or any other error occurs during the processing.
|
|
*/
|
|
async function resizeAvatar({ userId, input, desiredFormat = EImageOutputType.PNG }) {
|
|
try {
|
|
if (userId === undefined) {
|
|
throw new Error('User ID is undefined');
|
|
}
|
|
|
|
let imageBuffer;
|
|
if (typeof input === 'string') {
|
|
imageBuffer = await fetchAvatarBuffer(input);
|
|
} else if (input instanceof Buffer) {
|
|
imageBuffer = input;
|
|
} else if (typeof input === 'object' && input instanceof File) {
|
|
const fileContent = await fs.readFile(input.path);
|
|
imageBuffer = Buffer.from(fileContent);
|
|
} else {
|
|
throw new Error('Invalid input type. Expected URL, Buffer, or File.');
|
|
}
|
|
|
|
const metadata = await sharp(imageBuffer).metadata();
|
|
const { width, height } = metadata;
|
|
const minSize = Math.min(width, height);
|
|
|
|
if (metadata.format === 'gif') {
|
|
const resizedBuffer = await sharp(imageBuffer, { animated: true })
|
|
.extract({
|
|
left: Math.floor((width - minSize) / 2),
|
|
top: Math.floor((height - minSize) / 2),
|
|
width: minSize,
|
|
height: minSize,
|
|
})
|
|
.resize(250, 250)
|
|
.gif()
|
|
.toBuffer();
|
|
|
|
return resizedBuffer;
|
|
}
|
|
|
|
const squaredBuffer = await sharp(imageBuffer)
|
|
.extract({
|
|
left: Math.floor((width - minSize) / 2),
|
|
top: Math.floor((height - minSize) / 2),
|
|
width: minSize,
|
|
height: minSize,
|
|
})
|
|
.toBuffer();
|
|
|
|
const { buffer } = await resizeAndConvert({
|
|
inputBuffer: squaredBuffer,
|
|
desiredFormat,
|
|
});
|
|
return buffer;
|
|
} catch (error) {
|
|
logger.error('Error uploading the avatar:', error);
|
|
throw error;
|
|
}
|
|
}
|
|
|
|
module.exports = { resizeAvatar };
|