Files
CloddsBot/docker-compose.yml
T
alsk1992andClaude Opus 4.5 c1a1072fc6 Security hardening: fix all audit findings
- Replace Math.random() IDs with crypto.randomBytes (21 files)
- Disable sandbox and canvas eval by default
- Fix task runner shell injection (execFile + validation)
- Add HTML escaping to canvas components (XSS fix)
- Fix CORS credentials with wildcard origin
- Add IP rate limiting (100 req/min default)
- Add security headers (HSTS, X-Frame-Options, etc)
- Add WebSocket message validation + size limits
- Fix Dockerfile (Node 22, remove Python deps, add healthcheck)
- Update security docs and changelog

New env vars:
- CLODDS_IP_RATE_LIMIT
- CLODDS_FORCE_HTTPS
- CLODDS_HSTS_ENABLED
- CANVAS_ALLOW_JS_EVAL
- ALLOW_UNSAFE_SANDBOX

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-02-02 12:39:50 +00:00

18 lines
316 B
YAML

services:
clodds:
build: .
ports:
- "18789:18789"
env_file:
- .env
environment:
CLODDS_STATE_DIR: /data
CLODDS_WORKSPACE: /data/workspace
CLODDS_CONFIG_PATH: /data/clodds.json
volumes:
- clodds_data:/data
restart: unless-stopped
volumes:
clodds_data: