mirror of
https://github.com/jo-inc/camofox-browser.git
synced 2026-10-02 04:14:41 +08:00
fix: remove env var leaking to child processes
- Remove dotenv dependency and .env file loading from server.js - Whitelist env vars passed to child process in plugin.ts (was spreading all of process.env) - Same fix in tests/helpers/startServer.js - Remove dotenv from package.json dependencies - Add CONTRIBUTING.md with env security rules
This commit is contained in:
@@ -0,0 +1,43 @@
|
|||||||
|
# Contributing to camofox-browser
|
||||||
|
|
||||||
|
## Environment Variable Security
|
||||||
|
|
||||||
|
**Do not pass the host environment to child processes.** This is a hard rule.
|
||||||
|
|
||||||
|
When spawning child processes (e.g., the server from the plugin), only pass an explicit whitelist of environment variables. Never use `...process.env` or equivalent spreads.
|
||||||
|
|
||||||
|
```typescript
|
||||||
|
// WRONG — leaks all host secrets to the child process
|
||||||
|
spawn("node", [serverPath], {
|
||||||
|
env: { ...process.env, CAMOFOX_PORT: "9377" },
|
||||||
|
});
|
||||||
|
|
||||||
|
// RIGHT — only what the child actually needs
|
||||||
|
spawn("node", [serverPath], {
|
||||||
|
env: {
|
||||||
|
PATH: process.env.PATH,
|
||||||
|
HOME: process.env.HOME,
|
||||||
|
NODE_ENV: process.env.NODE_ENV,
|
||||||
|
CAMOFOX_PORT: "9377",
|
||||||
|
},
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
If the child process needs a new env var, add it to the whitelist explicitly in both `plugin.ts` and `tests/helpers/startServer.js`.
|
||||||
|
|
||||||
|
**Do not use `dotenv` or load `.env` files.** The server reads its configuration from explicitly passed environment variables only. Users running camofox alongside other tools may have `.env` files with secrets that should never be loaded into this process.
|
||||||
|
|
||||||
|
## Testing
|
||||||
|
|
||||||
|
```bash
|
||||||
|
npm test # e2e tests
|
||||||
|
npm run test:live # live site tests (requires RUN_LIVE_TESTS=1)
|
||||||
|
npm run test:debug # with server output (DEBUG_SERVER=1)
|
||||||
|
```
|
||||||
|
|
||||||
|
## Code Style
|
||||||
|
|
||||||
|
- No comments explaining what the code does — keep it readable without them
|
||||||
|
- Use `const` by default, `let` only when reassignment is needed
|
||||||
|
- Error responses: `{ error: "message" }` with appropriate HTTP status codes
|
||||||
|
- All tab operations require `userId` for session isolation
|
||||||
@@ -56,7 +56,6 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"camoufox-js": "^0.8.5",
|
"camoufox-js": "^0.8.5",
|
||||||
"dotenv": "^17.2.3",
|
|
||||||
"express": "^4.18.2",
|
"express": "^4.18.2",
|
||||||
"playwright": "^1.50.0",
|
"playwright": "^1.50.0",
|
||||||
"playwright-core": "^1.58.0",
|
"playwright-core": "^1.58.0",
|
||||||
|
|||||||
@@ -108,7 +108,12 @@ async function startServer(
|
|||||||
const serverPath = join(pluginDir, "server.js");
|
const serverPath = join(pluginDir, "server.js");
|
||||||
const proc = spawn("node", [serverPath], {
|
const proc = spawn("node", [serverPath], {
|
||||||
cwd: pluginDir,
|
cwd: pluginDir,
|
||||||
env: { ...process.env, CAMOFOX_PORT: String(port) },
|
env: {
|
||||||
|
PATH: process.env.PATH,
|
||||||
|
HOME: process.env.HOME,
|
||||||
|
NODE_ENV: process.env.NODE_ENV,
|
||||||
|
CAMOFOX_PORT: String(port),
|
||||||
|
},
|
||||||
stdio: ["ignore", "pipe", "pipe"],
|
stdio: ["ignore", "pipe", "pipe"],
|
||||||
detached: false,
|
detached: false,
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
require('dotenv').config();
|
|
||||||
const { Camoufox, launchOptions } = require('camoufox-js');
|
const { Camoufox, launchOptions } = require('camoufox-js');
|
||||||
const { firefox } = require('playwright-core');
|
const { firefox } = require('playwright-core');
|
||||||
const express = require('express');
|
const express = require('express');
|
||||||
|
|||||||
@@ -25,7 +25,7 @@ async function startServer(port = 0) {
|
|||||||
const serverPath = path.join(__dirname, '../../server.js');
|
const serverPath = path.join(__dirname, '../../server.js');
|
||||||
|
|
||||||
serverProcess = spawn('node', [serverPath], {
|
serverProcess = spawn('node', [serverPath], {
|
||||||
env: { ...process.env, CAMOFOX_PORT: usePort.toString(), DEBUG_RESPONSES: 'false' },
|
env: { PATH: process.env.PATH, HOME: process.env.HOME, NODE_ENV: process.env.NODE_ENV, CAMOFOX_PORT: usePort.toString(), DEBUG_RESPONSES: 'false' },
|
||||||
stdio: ['ignore', 'pipe', 'pipe'],
|
stdio: ['ignore', 'pipe', 'pipe'],
|
||||||
detached: false
|
detached: false
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user