diff --git a/SECURITY.md b/SECURITY.md new file mode 100644 index 000000000..75100dbf0 --- /dev/null +++ b/SECURITY.md @@ -0,0 +1,25 @@ + + +# Security Policy + +## Supported Versions + +Considering the amount of resources necessary to backport security or bug fixes to previous, unsupported CryptPad versions, it's not something we do. +However, we quickly release new minor versions in case of need. + +Please keep up with the latest release published here: https://github.com/cryptpad/cryptpad/releases + +Note that every GitHub release page has an RSS compatible feed that you can subscribe on to be informed of every new release. + +We do also communicate about this topic on: +- [Our blog](https://blog.cryptpad.org) +- [Our Matrix public space](https://matrix.to/#/#cryptpad:matrix.xwiki.com) +- [Our Mastodon account](https://fosstodon.org/@cryptpad) + +## Reporting a Vulnerability + +Vulnerabilities can be reported using the GitHub Security interface. You can also send us an email at security@cryptpad.org diff --git a/config/config.example.js b/config/config.example.js index 3e0be47c0..4e4ddd46e 100644 --- a/config/config.example.js +++ b/config/config.example.js @@ -74,12 +74,12 @@ module.exports = { // httpSafeOrigin: "https://some-other-domain.xyz", /* httpAddress specifies the address on which the nodejs server - * should be accessible. By default it will listen on 127.0.0.1 - * (IPv4 localhost on most systems). If you want it to listen on - * all addresses, including IPv6, set this to '::'. + * should be accessible. By default it will listen on localhost + * (IPv4 & IPv6 if enabled). If you want it to listen on + * a specific address, specify it here. e.g '192.168.0.1' * */ - //httpAddress: '::', + //httpAddress: 'localhost', /* httpPort specifies on which port the nodejs server should listen. * By default it will serve content over port 3000, which is suitable diff --git a/customize.dist/pages.js b/customize.dist/pages.js index da85e72db..fcb63bb11 100644 --- a/customize.dist/pages.js +++ b/customize.dist/pages.js @@ -98,7 +98,7 @@ define([ return h('a', attrs, [icon, text]); }; - Pages.versionString = "5.5.0"; + Pages.versionString = "5.6.0"; var customURLs = Pages.customURLs = {}; (function () { diff --git a/docs/cryptpad.service b/docs/cryptpad.service index efd06e488..8565e1f8e 100644 --- a/docs/cryptpad.service +++ b/docs/cryptpad.service @@ -14,6 +14,10 @@ Restart=always # Restart service after 10 seconds if node service crashes RestartSec=2 +# Proper logging to journald +StandardOutput=journal +StandardError=journal+console + User=cryptpad Group=cryptpad # modify to match your working directory diff --git a/docs/example.httpd.conf b/docs/example.httpd.conf new file mode 100644 index 000000000..f98b505f2 --- /dev/null +++ b/docs/example.httpd.conf @@ -0,0 +1,39 @@ +# SPDX-FileCopyrightText: 2023 XWiki CryptPad Team and contributors +# +# SPDX-License-Identifier: AGPL-3.0-or-later + +# This file is included strictly as an example of how Apache httpd can be +# configured to work with CryptPad. If you are using CryptPad in production +# and require professional support please contact sales@cryptpad.fr + +# This configuration requires mod_ssl, mod_socache_shmcb, mod_proxy, +# mod_proxy_http and mod_headers + +Listen 443 + +SSLCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 +SSLProxyCipherSuite ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384 +SSLHonorCipherOrder off +SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 +SSLProxyProtocol all -SSLv3 -TLSv1 -TLSv1.1 +SSLSessionCache "shmcb:logs/ssl_scache(512000)" +SSLSessionCacheTimeout 86400 +SSLSessionTickets off +SSLUseStapling on +SSLStaplingCache "shmcb:logs/ssl_stapling(32768)" + + + ServerName cryptpad.your-domain.com + ServerAlias sandbox.your-domain.com + Header always set Strict-Transport-Security "max-age=63072000; includeSubDomains" + SSLEngine on + SSLCertificateFile /etc/letsencrypt/live/your-domain.com/cert.pem + SSLCertificateKeyFile /etc/letsencrypt/live/your-domain.com/privkey.pem + BrowserMatch "MSIE [2-5]" \ + nokeepalive ssl-unclean-shutdown \ + downgrade-1.0 force-response-1.0 + Protocols h2 http/1.1 + LimitRequestBody 157286400 + ProxyPass / http://localhost:3000/ upgrade=websocket + ProxyPassReverse / http://localhost:3000/ + diff --git a/lib/http-worker.js b/lib/http-worker.js index 5788b63a5..185ae748e 100644 --- a/lib/http-worker.js +++ b/lib/http-worker.js @@ -194,7 +194,8 @@ app.head(/^\/common\/feedback\.html/, function (req, res, next) { const { createProxyMiddleware } = require("http-proxy-middleware"); -var proxyTarget = new URL('', `ws:${Env.httpAddress}`); +var httpAddress = Env.httpAddress === '::' ? 'localhost' : Env.httpAddress; +var proxyTarget = new URL('', `ws:${httpAddress}`); proxyTarget.port = Env.websocketPort; const wsProxy = createProxyMiddleware({ diff --git a/lib/load-config.js b/lib/load-config.js index 6fc7534ec..2ba9771d0 100644 --- a/lib/load-config.js +++ b/lib/load-config.js @@ -50,7 +50,7 @@ config.sso = {}; try { config.sso = require("../config/sso"); } catch (e) { - console.log("SSO config not found"); + //console.log("SSO config not found"); } module.exports = config; diff --git a/lib/plugins/README.md b/lib/plugins/README.md index 70e448011..dd2d15af2 100644 --- a/lib/plugins/README.md +++ b/lib/plugins/README.md @@ -1 +1,7 @@ + + # CryptPad's plugins directory diff --git a/package-lock.json b/package-lock.json index 8b0b3081c..34e3156bd 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "cryptpad", - "version": "5.5.0", + "version": "5.6.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "cryptpad", - "version": "5.5.0", + "version": "5.6.0", "license": "AGPL-3.0+", "dependencies": { "@mcrowe/minibloom": "^0.2.0", diff --git a/package.json b/package.json index 3eea3fdbf..0c1cb79e1 100644 --- a/package.json +++ b/package.json @@ -1,7 +1,7 @@ { "name": "cryptpad", "description": "realtime collaborative visual editor with zero knowlege server", - "version": "5.5.0", + "version": "5.6.0", "license": "AGPL-3.0+", "repository": { "type": "git",