Research-Stack/5-Applications
devin-ai-integration[bot] 85506530f2 fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard (#76)
* fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard

- run_import_workflow.py, run_multi_import.py: replace hardcoded budget
  password with BUDGET_PASSWORD env-var (fail-fast if unset)
- server.js /ingest: replace shell-interpolated exec() with execFile()
  so user-controlled title/body cannot inject shell commands
- authentik-values.yaml: blank out bootstrap_password and bootstrap_token
  so they must be supplied at deploy time via --set or sealed-secret
- cluster-dashboard main.py: restrict CORS from allow_origins=["*"] to
  env-configurable whitelist (default: dashboard.researchstack.info),
  methods to GET, headers to Authorization+Content-Type
- neo4j_obsidian_connector_router.js (both copies): replace permissive
  prefix-only readOnly regex with a deny-list that blocks
  CREATE/MERGE/DELETE/DETACH/SET/REMOVE/DROP anywhere in the query, and
  route readOnly queries through session.readTransaction()

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>

* fix(security): add CALL procedure allowlist for Cypher readOnly, add OPTIONS to CORS

- Cypher guard: restore positive allowlist for CALL targets (only db.* and
  apoc.meta.* allowed in readOnly mode). Extract cypherReadOnlyViolation()
  helper for clarity. Both copies updated.
- CORS: add OPTIONS to allow_methods so preflight requests succeed.

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>

* fix(security): use negative lookahead for CALL allowlist, remove dead CALL\s*\{ branch

- Replace two-regex CALL check with single negative-lookahead
  CYPHER_CALL_DISALLOWED_RE = /\bCALL\s+(?!db\.|apoc\.meta\.)/i
  This correctly blocks queries containing ANY disallowed CALL target,
  even when bundled alongside an allowed CALL db.* or CALL apoc.meta.*.
- Remove dead CALL\s*\{ alternative from CYPHER_WRITE_RE — the trailing
  \b never matched because { is a non-word character.
- Both copies updated identically.

Co-Authored-By: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>

---------

Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-authored-by: Allaun Silverfox <bigdataiscoming+9i37y6j2@protonmail.com>
2026-06-14 20:42:14 -05:00
..
AppFlowy-Cloud Add EC2 recovery backup: NixOS config, AppFlowy compose/env template, credential server bootstrap, recovery guide 2026-05-18 10:44:23 -05:00
audio-dsp Track remaining source and documentation inventory 2026-05-11 22:18:31 -05:00
audit initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
caddy-edge feat(infra): WebRTC bridge + Caddy edge config + Tailscale Funnel 2026-05-28 13:11:53 -05:00
cff Track remaining source and documentation inventory 2026-05-11 22:18:31 -05:00
cluster-dashboard fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard (#76) 2026-06-14 20:42:14 -05:00
compression-core Track remaining source and documentation inventory 2026-05-11 22:18:31 -05:00
dashboard fix(adversarial-review): resolve 35 critical coding bugs across 8 subsystems 2026-05-31 23:38:03 -05:00
hutter_prize initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
linear-native-tauri Bump the linear-tauri-cargo-minor-patch group 2026-05-20 23:03:27 -05:00
nodupe fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard (#76) 2026-06-14 20:42:14 -05:00
notion-native-tauri Bump the notion-tauri-cargo-minor-patch group 2026-05-20 23:03:27 -05:00
out/verilog feat: 12 math enhancements — Q16 LUT, braid VCN encoder, FPGA Verilog, FFT, crypto 2026-05-28 14:49:26 -05:00
parquet_compressor Bump dashmap 2026-05-20 23:03:27 -05:00
pist-scripts initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
plugins/substack-connector Track remaining source and documentation inventory 2026-05-11 22:18:31 -05:00
scripts fix(security): remove hardcoded secrets, patch command injection, tighten CORS and Cypher guard (#76) 2026-06-14 20:42:14 -05:00
teleport-kanban fix(adversarial-review): resolve 35 critical coding bugs across 8 subsystems 2026-05-31 23:38:03 -05:00
tests initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
text-to-cad docs(agents): project-wide AGENTS.md audit — cross-refs, baseline, contracts 2026-05-26 22:34:46 -05:00
tools-scripts test(coverage): add 138 unit tests for least-covered modules (#78) 2026-06-14 19:31:16 -05:00
webrtc-bridge feat(infra): WebRTC bridge + Caddy edge config + Tailscale Funnel 2026-05-28 13:11:53 -05:00
finance_manager.py chore: preserve working tree before secure wipe 2026-05-13 17:36:02 -05:00
README.md initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
requirements_swarm_api.txt initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00
visualizer_service.py initial: sovereign research stack (consolidated, weightless, and lfs-optimized) 2026-05-04 18:11:36 -05:00

5-Applications

Purpose: End-to-end pipelines, integration tests, automation scripts, benchmarks, audit.

Depends on: 0 through 4

Contents (Target)

Source Destination
5-Applications/scripts/ 5-Applications/scripts/
5-Applications/tests/ 5-Applications/tests/
5-Applications/out/ 5-Applications/out/
5-Applications/audit/ 5-Applications/audit/

Scripts

  • build_manifold_graphml.py
  • export_manifold_to_obsidian.py
  • hot_swap_daemon.py
  • hot_swap_manager.py

Pipeline

  1. Generate provably hard question (Builder: ADD clock)
  2. Route via OmnidirectionalInterface (Lean)
  3. Execute via DomainModelIntegration (Lean → Python shim)
  4. Store in Google Drive topological storage (Warden: SUBTRACT clock)
  5. Hardware triumvirate integration (Judge: PAUSE clock)