A08: add an integrity seal to backup archives #22

Closed
opened 2026-08-13 09:35:05 +00:00 by nalum · 0 comments
Owner

Export/import archives (ADR-0022/0023) are plain gzip+JSON with no integrity seal. A doctored backup restored by a well-meaning admin imports attacker password hashes, API keys, and a known jwt_secret. Restore semantics make this inherent and the flow is consent-gated, but the UI has no way to warn on tampering.

Fix: HMAC the archive with an install-keyed secret (or attach a signed manifest) at export, verify at import, and warn — not block — when the seal is missing or wrong, so cross-install restores still work.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

Export/import archives (ADR-0022/0023) are plain gzip+JSON with no integrity seal. A doctored backup restored by a well-meaning admin imports attacker password hashes, API keys, and a known `jwt_secret`. Restore semantics make this inherent and the flow is consent-gated, but the UI has no way to warn on tampering. **Fix**: HMAC the archive with an install-keyed secret (or attach a signed manifest) at export, verify at import, and warn — not block — when the seal is missing or wrong, so cross-install restores still work. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:37 +00:00
nalum closed this issue 2026-08-13 11:41:12 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#22
No description provided.