fix: remove env var leaking to child processes

- Remove dotenv dependency and .env file loading from server.js
- Whitelist env vars passed to child process in plugin.ts (was spreading all of process.env)
- Same fix in tests/helpers/startServer.js
- Remove dotenv from package.json dependencies
- Add CONTRIBUTING.md with env security rules
This commit is contained in:
Pradeep Elankumaran
2026-02-11 15:31:52 -08:00
parent 84a894845f
commit 5c4c79da44
5 changed files with 50 additions and 4 deletions
+43
View File
@@ -0,0 +1,43 @@
# Contributing to camofox-browser
## Environment Variable Security
**Do not pass the host environment to child processes.** This is a hard rule.
When spawning child processes (e.g., the server from the plugin), only pass an explicit whitelist of environment variables. Never use `...process.env` or equivalent spreads.
```typescript
// WRONG — leaks all host secrets to the child process
spawn("node", [serverPath], {
env: { ...process.env, CAMOFOX_PORT: "9377" },
});
// RIGHT — only what the child actually needs
spawn("node", [serverPath], {
env: {
PATH: process.env.PATH,
HOME: process.env.HOME,
NODE_ENV: process.env.NODE_ENV,
CAMOFOX_PORT: "9377",
},
});
```
If the child process needs a new env var, add it to the whitelist explicitly in both `plugin.ts` and `tests/helpers/startServer.js`.
**Do not use `dotenv` or load `.env` files.** The server reads its configuration from explicitly passed environment variables only. Users running camofox alongside other tools may have `.env` files with secrets that should never be loaded into this process.
## Testing
```bash
npm test # e2e tests
npm run test:live # live site tests (requires RUN_LIVE_TESTS=1)
npm run test:debug # with server output (DEBUG_SERVER=1)
```
## Code Style
- No comments explaining what the code does — keep it readable without them
- Use `const` by default, `let` only when reassignment is needed
- Error responses: `{ error: "message" }` with appropriate HTTP status codes
- All tab operations require `userId` for session isolation
-1
View File
@@ -56,7 +56,6 @@
},
"dependencies": {
"camoufox-js": "^0.8.5",
"dotenv": "^17.2.3",
"express": "^4.18.2",
"playwright": "^1.50.0",
"playwright-core": "^1.58.0",
+6 -1
View File
@@ -108,7 +108,12 @@ async function startServer(
const serverPath = join(pluginDir, "server.js");
const proc = spawn("node", [serverPath], {
cwd: pluginDir,
env: { ...process.env, CAMOFOX_PORT: String(port) },
env: {
PATH: process.env.PATH,
HOME: process.env.HOME,
NODE_ENV: process.env.NODE_ENV,
CAMOFOX_PORT: String(port),
},
stdio: ["ignore", "pipe", "pipe"],
detached: false,
});
-1
View File
@@ -1,4 +1,3 @@
require('dotenv').config();
const { Camoufox, launchOptions } = require('camoufox-js');
const { firefox } = require('playwright-core');
const express = require('express');
+1 -1
View File
@@ -25,7 +25,7 @@ async function startServer(port = 0) {
const serverPath = path.join(__dirname, '../../server.js');
serverProcess = spawn('node', [serverPath], {
env: { ...process.env, CAMOFOX_PORT: usePort.toString(), DEBUG_RESPONSES: 'false' },
env: { PATH: process.env.PATH, HOME: process.env.HOME, NODE_ENV: process.env.NODE_ENV, CAMOFOX_PORT: usePort.toString(), DEBUG_RESPONSES: 'false' },
stdio: ['ignore', 'pipe', 'pipe'],
detached: false
});