mirror of
https://github.com/PegaProx/project-pegaprox.git
synced 2026-08-12 15:27:47 +08:00
Security - Full-DB SQLCipher encryption (AES-256-CBC + HMAC-SHA512, format v4) on Linux x86_64. Auto-migrates plain DBs on first boot post-update (copy → sqlcipher_export → per-table row-count verify → atomic rename; timestamped .plain.bak retained). Graceful fallback to plain SQLite + Fernet field-encryption where the sqlcipher3-binary wheel isn't available (ARM/macOS/Windows). - Multi-tier master-key loader: PEGAPROX_DB_KEY env → systemd LoadCredentialEncrypted → PEGAPROX_KEY_FILE → /etc/pegaprox/secret.key → ~/.config/pegaprox/secret.key → legacy CONFIG_DIR. Loose-perm files are skipped, never silently used. deploy.sh Step 5 generates the key outside config/ for fresh installs. - Dependency floor bumps to clear pip-audit / Snyk findings: flask 3.0.3 (werkzeug 3 RCE fix transit), flask-cors 6.0.0 (CWE-178 + 2 mediums), gevent 25.4.1 (CVSS 9.3 + 8.3 + 6.9), urllib3 2.5.0, paramiko 4.0.0, cryptography 46.0.7, h11 0.16.0, pyasn1 0.6.3, setuptools 78.1.1, zipp 3.19.1. - 42-site reflected-content sanitizer (parse_pve_error html.escape) on Proxmox passthrough error paths across datacenter/vms/storage/static_files. Features - LXC dedicated text terminal — pct enter via PVE built-in termproxy API, wrapped through the existing SSH-WS transport. Server-side ticket mint, no shell exec on PegaProx side. vm.console permission gated, audit-logged. - Cluster-scoped syslog viewer (#387, PR #399, contributed by @gyptazy, sponsored by credativ GmbH). Settings → Syslog Server tab with toggle; filters log rows by cluster's hostnames/nodes. i18n DE/EN/FR/ES/PT/KO. - Corporate-layout enhancements across dashboard / VM modals / config tabs (~1.4k lines of new UI sources). Operations - Docker HEALTHCHECK start_period 15s→120s, retries 3→5 to give the in-process DB migration room on upgrade boot. Subsequent boots short-circuit. - README: Aikido security audit badge. - docs/SECURITY.md: new operator guide covering keystore tiers, migration tool, recovery story, and systemd LoadCredentialEncrypted (TPM2-bound) setup.
0 lines
0 B
Python
0 lines
0 B
Python
The file is empty.