lotus(security): harden denoise base, audio-inject, decorations
CI / Build embedded bundle (push) Successful in 1m8s
CI / Publish to Gitea npm registry (push) Has been skipped

Holistic security audit findings:
- C1 (CRITICAL): force lotusDenoiseBase to same-origin before it reaches
  audioWorklet.addModule()/fetch — a crafted call-link param could
  otherwise load attacker JS/WASM as a worklet processing the live mic.
  Non-same-origin/malformed values fall back to bundled ./denoise/.
- H1 (HIGH): gate audio-inject behind explicit lotusAudioInject=1 (still
  acks the action so no transport hang) — it publishes under the local
  user's identity, so it must not be silently armed for every call.
- M1 (MED): cap the decoration roster at 512 entries.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Lotus CI
2026-06-30 00:00:40 -04:00
co-authored by Claude Opus 4.8
parent 39b57db3b2
commit b8543c3fe1
3 changed files with 30 additions and 2 deletions
+5 -1
View File
@@ -70,7 +70,11 @@ export function startLotusDecorations(): () => void {
| undefined;
const next: Record<string, string> = {};
if (data?.decorations && typeof data.decorations === "object") {
for (const [userId, url] of Object.entries(data.decorations)) {
// Cap the roster so a pathological map can't spawn unbounded overlays.
for (const [userId, url] of Object.entries(data.decorations).slice(
0,
512,
)) {
const safe = safeImageUrl(url);
if (safe) next[userId] = safe;
}