Skip to content

release: v5.0.3 security fixes and verified deployment - #800

Merged
klboke merged 9 commits into
masterfrom
release/5.0.3
Oct 8, 2026
Merged

klboke merged 9 commits into
masterfrom
release/5.0.3

Conversation

@klboke

@klboke klboke commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Release v5.0.3 with fixes for FTP command argument validation, upload and folder path confinement, preview source validation, preview parameter handling, archive directory disclosure, and default monitoring exposure. Update both READMEs, the release page, and Docker paths.

The Windows deployment now builds the exact triggering commit. An explicit harden_actuator dispatch migrates only the two monitoring defaults in the configuration actually used by the running application, backs up that file and the JAR, verifies the HTTP behavior, and rolls both back if verification fails. Normal automatic deployments preserve external configuration.

Validation: 85 local regression cases and the CI packaging command passed for the security changes; each private patch was independently verified. This PR additionally runs Linux security regressions, Windows deployment parsing/configuration tests, all three OS builds, and preview E2E.

Compatibility: /directory is removed while built-in archive browsing remains supported. Existing external configurations must adopt the documented monitoring settings. Uploads remain disabled by default.

Copilot AI balanced review requested due to automatic review settings October 8, 2026 07:39
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T07:52:32.803004Z 3c73d8e New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

A shipped configuration remains insecure, and the archive traversal regression depends on mutable static configuration initialization order.

2 open findings
What changed in this PR

Releases v5.0.3 with security hardening, regression coverage, documentation, and verified Windows deployment behavior.

Changes:

  • Hardens preview sources, uploads, FTP commands, archives, and monitoring exposure.
  • Adds security regression and deployment tests.
  • Updates release metadata, Docker paths, and deployment rollback logic.
File Description
PreviewSourceSecurityTests.java Tests preview-source validation.
UploadPathSecurityTests.java Tests upload path confinement.
PreviewParameterSecurityTests.java Tests safe preview parameters.
ArchiveDirectorySecurityTests.java Tests archive-tree confinement.
FtpCommandSecurityTests.java Tests FTP argument validation.
ArchiveTraversalSecurityTests.java Tests ZIP traversal rejection.
ActuatorExposureSecurityTests.java Tests monitoring exposure defaults.
record.ftl Adds v5.0.3 release details.
compress.ftl Uses server-generated archive trees.
TrustHostFilter.java Validates every source host.
TrustDirFilter.java Validates every source path.
OnlinePreviewController.java Normalizes page and agent parameters.
FileController.java Confines uploads and removes /directory.
WebUtils.java Collects and validates all source URLs.
RarUtils.java Safely traverses archive directories.
FtpUtils.java Rejects FTP control characters.
CompressFilePreviewImpl.java Generates validated archive-tree JSON.
application.properties Restricts default actuator exposure.
server/​pom.xml Bumps server version to 5.0.3.
README.md Documents the security release.
README.cn.md Adds Chinese release documentation.
pom.xml Bumps parent version to 5.0.3.
Dockerfile Updates packaged runtime paths.
maven.yml Adds security and deployment checks.
master-auto-deploy.yml Passes revision and hardening options.
test_windows_deploy.ps1 Tests deployment configuration migration.
remote_windows_deploy.ps1 Adds verified deployment and rollback.
deploy_windows_winrm.py Forwards deployment controls over WinRM.

🧠 Review effort: Balanced


Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.

Comment thread server/src/main/config/application.properties
Comment thread server/src/test/java/cn/keking/service/ArchiveTraversalSecurityTests.java Outdated
@klboke
klboke merged commit 3b82689 into master Oct 8, 2026
4 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3c73d8e0e1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +361 to +362
$HealthEndpoint = [System.Uri]::new([System.Uri]$Url, 'actuator/health').AbsoluteUri
$MetricsEndpoint = [System.Uri]::new([System.Uri]$Url, 'actuator/metrics').AbsoluteUri

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve the context path when constructing actuator URLs

When KK_DEPLOY_HEALTH_URL names an application context without a trailing slash, such as http://host/kkfileview, the relative System.Uri construction replaces kkfileview and probes http://host/actuator/... instead. The ordinary health check can succeed at the configured URL, but a harden_actuator deployment then fails verification and rolls back despite correctly securing the application; normalize the base URL as a directory or construct these endpoints from its context path explicitly.

Useful? React with 👍 / 👎.

@jsksk-C

jsksk-C commented Oct 9, 2026

Copy link
Copy Markdown

@klboke I'm the reporter of GHSA-2459-998h-g664. The fix is in v5.0.3 (PR #800). Could you please request a CVE for this advisory? Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants