Skip to content

Secure QR public asset pages and hide production error details - #3

Draft
ardacetin wants to merge 1 commit into
mainfrom
cursor/secure-qr-public-view-5f25
Draft

ardacetin wants to merge 1 commit into
mainfrom
cursor/secure-qr-public-view-5f25

Conversation

@ardacetin

Copy link
Copy Markdown
Owner

Summary

Closes two security gaps: production error leakage from public/index.php, and unauthenticated enumeration of sensitive asset fields via sequential /assets/view/{id} URLs.

Error display

  • display_errors / fatal detail output now honor APP_ENV=production and DISPLAY_ERROR_DETAILS
  • Production fatals are logged and show a generic message only

QR / public asset page

  • Replaces /assets/view/{id} with opaque 64-char tokens (/assets/view/{token})
  • Tokens are revocable/regenerable from the asset detail modal
  • Settings → General: access mode (public / authenticated / network) + CIDR allowlist + visible fields
  • Serial number and MAC addresses are hidden by default
  • Legacy numeric IDs no longer resolve to assets

Test plan

  • With APP_ENV=production, trigger/simulate a fatal and confirm no file/line details in the browser
  • Open an asset detail QR; confirm the encoded URL uses a long token, not a numeric id
  • Visiting /assets/view/1 (or any short/numeric path) returns 404
  • Disable serial/MAC in settings and confirm they do not appear on the public page
  • Set access mode to authenticated and confirm redirect to login when logged out
  • Set access mode to network with a CIDR and confirm allow/deny behavior
  • Regenerate and revoke QR links; confirm old tokens stop working
Open in Web Open in Cursor 

Hide fatal/error details in production, replace enumerable /assets/view/{id}
links with revocable opaque tokens, and let admins control QR field
visibility and access (public, authenticated, or corporate network).

Co-authored-by: Arda Çetin <acetin@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants