Repository navigation
release: v5.0.3 security fixes and verified deployment - #800
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
🟡 Changes recommended
A shipped configuration remains insecure, and the archive traversal regression depends on mutable static configuration initialization order.
2 open findings
What changed in this PR
Releases v5.0.3 with security hardening, regression coverage, documentation, and verified Windows deployment behavior.
Changes:
- Hardens preview sources, uploads, FTP commands, archives, and monitoring exposure.
- Adds security regression and deployment tests.
- Updates release metadata, Docker paths, and deployment rollback logic.
| File | Description |
|---|---|
PreviewSourceSecurityTests.java |
Tests preview-source validation. |
UploadPathSecurityTests.java |
Tests upload path confinement. |
PreviewParameterSecurityTests.java |
Tests safe preview parameters. |
ArchiveDirectorySecurityTests.java |
Tests archive-tree confinement. |
FtpCommandSecurityTests.java |
Tests FTP argument validation. |
ArchiveTraversalSecurityTests.java |
Tests ZIP traversal rejection. |
ActuatorExposureSecurityTests.java |
Tests monitoring exposure defaults. |
record.ftl |
Adds v5.0.3 release details. |
compress.ftl |
Uses server-generated archive trees. |
TrustHostFilter.java |
Validates every source host. |
TrustDirFilter.java |
Validates every source path. |
OnlinePreviewController.java |
Normalizes page and agent parameters. |
FileController.java |
Confines uploads and removes /directory. |
WebUtils.java |
Collects and validates all source URLs. |
RarUtils.java |
Safely traverses archive directories. |
FtpUtils.java |
Rejects FTP control characters. |
CompressFilePreviewImpl.java |
Generates validated archive-tree JSON. |
application.properties |
Restricts default actuator exposure. |
server/pom.xml |
Bumps server version to 5.0.3. |
README.md |
Documents the security release. |
README.cn.md |
Adds Chinese release documentation. |
pom.xml |
Bumps parent version to 5.0.3. |
Dockerfile |
Updates packaged runtime paths. |
maven.yml |
Adds security and deployment checks. |
master-auto-deploy.yml |
Passes revision and hardening options. |
test_windows_deploy.ps1 |
Tests deployment configuration migration. |
remote_windows_deploy.ps1 |
Adds verified deployment and rollback. |
deploy_windows_winrm.py |
Forwards deployment controls over WinRM. |
🧠 Review effort: Balanced
Give feedback about Copilot approvals in this survey to enter a drawing for a $150 gift card.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3c73d8e0e1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| $HealthEndpoint = [System.Uri]::new([System.Uri]$Url, 'actuator/health').AbsoluteUri | ||
| $MetricsEndpoint = [System.Uri]::new([System.Uri]$Url, 'actuator/metrics').AbsoluteUri |
There was a problem hiding this comment.
Preserve the context path when constructing actuator URLs
When KK_DEPLOY_HEALTH_URL names an application context without a trailing slash, such as http://host/kkfileview, the relative System.Uri construction replaces kkfileview and probes http://host/actuator/... instead. The ordinary health check can succeed at the configured URL, but a harden_actuator deployment then fails verification and rolls back despite correctly securing the application; normalize the base URL as a directory or construct these endpoints from its context path explicitly.
Useful? React with 👍 / 👎.
|
@klboke I'm the reporter of GHSA-2459-998h-g664. The fix is in v5.0.3 (PR #800). Could you please request a CVE for this advisory? Thanks! |


Release v5.0.3 with fixes for FTP command argument validation, upload and folder path confinement, preview source validation, preview parameter handling, archive directory disclosure, and default monitoring exposure. Update both READMEs, the release page, and Docker paths.
The Windows deployment now builds the exact triggering commit. An explicit
harden_actuatordispatch migrates only the two monitoring defaults in the configuration actually used by the running application, backs up that file and the JAR, verifies the HTTP behavior, and rolls both back if verification fails. Normal automatic deployments preserve external configuration.Validation: 85 local regression cases and the CI packaging command passed for the security changes; each private patch was independently verified. This PR additionally runs Linux security regressions, Windows deployment parsing/configuration tests, all three OS builds, and preview E2E.
Compatibility:
/directoryis removed while built-in archive browsing remains supported. Existing external configurations must adopt the documented monitoring settings. Uploads remain disabled by default.