Compare commits

...

6 Commits

Author SHA1 Message Date
Constantin Graf
0c58896b00 Run OSS Scanner image on Octane/FrankenPHP and bundle Gotenberg
Production runs as long-lived Octane workers in FrankenPHP worker mode, so state leaking between requests
(static properties, singletons, ...) is a real risk that php artisan serve cannot reproduce. Base the scanner image
on the production FrankenPHP image, add start-octane.sh (single worker, production Caddyfile) and describe this
class of issue in the threat model.

Bundle Gotenberg (Chromium only) so the PDF export tests pass offline and PDF rendering can be exercised.
2026-10-09 18:10:44 +02:00
Constantin Graf
6301b0f4a1 Clarify that super admins are trusted in OSS Scanner threat model 2026-10-09 18:10:44 +02:00
Constantin Graf
4c993c8eb2 Add OSS Scanner build environment and threat model 2026-10-09 18:10:44 +02:00
Constantin Graf
ae6937d012 Updated auditing extension to v0.0.5 2026-10-09 15:09:41 +02:00
Constantin Graf
1256fa61bd Updated invoicing extension to v0.0.10 2026-10-09 14:42:41 +02:00
Constantin Graf
d6f80e23fb Run core PHPUnit tests with extensions enabled in CI 2026-10-09 14:42:41 +02:00
8 changed files with 293 additions and 4 deletions

View File

@@ -5,7 +5,7 @@ permissions:
jobs: jobs:
phpunit-extensions: phpunit-extensions:
runs-on: ubuntu-latest runs-on: ubuntu-latest
timeout-minutes: 15 timeout-minutes: 25
strategy: strategy:
matrix: matrix:
postgres_version: [ 15, 16, 17 ] postgres_version: [ 15, 16, 17 ]
@@ -132,5 +132,8 @@ jobs:
php artisan key:generate php artisan key:generate
php artisan passport:keys php artisan passport:keys
- name: "Run PHPUnit" - name: "Run PHPUnit (extensions)"
run: php artisan test extensions/Billing/tests extensions/Services/tests extensions/Invoicing/tests --stop-on-failure run: php artisan test extensions/Billing/tests extensions/Services/tests extensions/Invoicing/tests --stop-on-failure
- name: "Run PHPUnit (core)"
run: php artisan test --testsuite=Unit,Feature --stop-on-failure

86
.oss-scanner/Dockerfile Normal file
View File

@@ -0,0 +1,86 @@
# Build environment for Anthropic's OSS Scanner (https://github.com/anthropics/oss-scanner).
# The scanner builds this image with the repository root as the build context and then audits it without network
# access, so everything needed to run the app and its test suite (PHP + Composer deps, Node deps + built frontend,
# a local PostgreSQL and a local Gotenberg for PDF rendering) is installed here.
#
# The base image is the FrankenPHP image the production image (docker/prod/Dockerfile) is built on: in production the
# app runs as long-lived Laravel Octane workers in FrankenPHP worker mode, not as one PHP process per request.
#
# Inside the finished image:
# .oss-scanner/start-postgres.sh start the local PostgreSQL server (required for tests and the app)
# .oss-scanner/start-gotenberg.sh start the local Gotenberg server (required for PDF exports)
# php artisan test run the PHPUnit suite (needs PostgreSQL and Gotenberg running)
# .oss-scanner/start-octane.sh run the app like production on http://127.0.0.1:8000 (starts everything above)
ARG FRANKENPHP_VERSION=1.11
ARG PHP_VERSION=8.3
FROM node:20-trixie-slim AS node
FROM gotenberg/gotenberg:8 AS gotenberg
FROM dunglas/frankenphp:${FRANKENPHP_VERSION}-php${PHP_VERSION}
ENV DEBIAN_FRONTEND=noninteractive \
COMPOSER_ALLOW_SUPERUSER=1 \
COMPOSER_NO_INTERACTION=1 \
OCTANE_SERVER=frankenphp \
TZ=UTC
COPY --from=composer:2 /usr/bin/composer /usr/local/bin/composer
COPY --from=node /usr/local/bin/node /usr/local/bin/node
COPY --from=node /usr/local/lib/node_modules /usr/local/lib/node_modules
RUN ln -s ../lib/node_modules/npm/bin/npm-cli.js /usr/local/bin/npm \
&& ln -s ../lib/node_modules/npm/bin/npx-cli.js /usr/local/bin/npx
# PostgreSQL 17 (Debian trixie default) is one of the versions solidtime is tested against in CI.
# chromium, qpdf and exiftool are what Gotenberg needs for HTML to PDF rendering.
RUN apt-get update \
&& apt-get install -y --no-install-recommends git unzip curl ca-certificates postgresql postgresql-client \
chromium fonts-liberation qpdf libimage-exiftool-perl \
&& install-php-extensions pdo_pgsql pgsql intl gd zip bcmath exif pcntl sockets soap apcu \
&& rm -rf /var/lib/apt/lists/* \
&& echo "memory_limit=2G" > "$PHP_INI_DIR/conf.d/99-oss-scanner.ini"
# Gotenberg 8 (the PDF renderer, same image as in CI). solidtime only uses its Chromium HTML to PDF route, so LibreOffice
# and pdftk are not installed: Gotenberg only checks at startup that their binaries exist, start-gotenberg.sh disables
# the LibreOffice routes and the Chromium route does not use pdftk.
COPY --from=gotenberg /usr/bin/gotenberg /usr/local/bin/gotenberg
COPY --from=gotenberg /usr/bin/pdfcpu /usr/local/bin/pdfcpu
COPY --from=gotenberg /opt/gotenberg /opt/gotenberg
ENV CHROMIUM_BIN_PATH=/usr/bin/chromium \
CHROMIUM_HYPHEN_DATA_DIR_PATH=/opt/gotenberg/chromium-hyphen-data \
GOTENBERG_VERSIONS_DIR_PATH=/opt/gotenberg/versions \
QPDF_BIN_PATH=/usr/bin/qpdf \
EXIFTOOL_BIN_PATH=/usr/bin/exiftool \
PDFCPU_BIN_PATH=/usr/local/bin/pdfcpu \
LIBREOFFICE_BIN_PATH=/bin/false \
UNOCONVERTER_BIN_PATH=/bin/false \
PDFTK_BIN_PATH=/bin/false
# Database matching .env.ci: user root / password root, database laravel.
RUN pg_ctlcluster 17 main start \
&& runuser -u postgres -- psql -c "CREATE ROLE root WITH LOGIN SUPERUSER PASSWORD 'root';" \
&& runuser -u postgres -- createdb -O root laravel \
&& pg_ctlcluster 17 main stop
# scanner contract: the checkout lives inside the image, at /src
COPY . /src
WORKDIR /src
RUN composer install --prefer-dist \
&& npm ci \
&& npm run build
RUN cp .env.ci .env \
&& php artisan key:generate \
&& php artisan passport:keys --force \
&& php artisan octane:install --server=frankenphp --no-interaction \
&& chmod +x .oss-scanner/*.sh
# Run the test suite so the image is known to work, but do not fail the build on test failures.
RUN .oss-scanner/start-postgres.sh \
&& .oss-scanner/start-gotenberg.sh \
&& (php artisan test || echo "WARNING: PHPUnit reported failures") \
&& kill "$(cat /tmp/gotenberg.pid)" \
&& pg_ctlcluster 17 main stop

View File

@@ -0,0 +1,18 @@
# Used instead of the root .dockerignore when building .oss-scanner/Dockerfile. The root one is tailored to the
# production image and excludes tests, phpunit.xml etc., which the scanner needs.
node_modules
extensions/*/node_modules
vendor
.env
public/build
public/hot
storage/*.key
storage/logs/*
coverage
test-results
playwright-report
.phpunit.cache
.phpunit.result.cache
auth.json
.DS_Store
.idea

16
.oss-scanner/start-gotenberg.sh Executable file
View File

@@ -0,0 +1,16 @@
#!/usr/bin/env bash
# Start the local Gotenberg server (PDF rendering) on 127.0.0.1:3000, matching GOTENBERG_URL in .env.ci.
# Only the Chromium routes are needed by solidtime, see .oss-scanner/Dockerfile. Stop: kill "$(cat /tmp/gotenberg.pid)"
set -euo pipefail
if ! curl -fs http://127.0.0.1:3000/health >/dev/null; then
nohup gotenberg \
--api-port=3000 \
--libreoffice-disable-routes \
--libreoffice-auto-start=false \
--log-level=warn \
>/tmp/gotenberg.log 2>&1 &
echo $! >/tmp/gotenberg.pid
until curl -fs http://127.0.0.1:3000/health >/dev/null; do sleep 0.5; done
fi
echo "Gotenberg is running on http://127.0.0.1:3000 (log: /tmp/gotenberg.log)"

37
.oss-scanner/start-octane.sh Executable file
View File

@@ -0,0 +1,37 @@
#!/usr/bin/env bash
# Run the app the way production does: Laravel Octane on FrankenPHP in worker mode, with the production Caddyfile.
# A worker boots the app once and then serves many requests, so state kept in memory (static properties, singletons,
# changed config, ...) survives from one request to the next. With a single worker, consecutive requests always hit the
# same worker, so such leaks between requests (e.g. between users of different organizations) reproduce reliably.
#
# Usage: .oss-scanner/start-octane.sh (OCTANE_WORKERS and OCTANE_MAX_REQUESTS can be overridden)
# Stop: php artisan octane:stop
# After changing PHP code, run `php artisan octane:reload`: workers keep the code they booted with.
set -euo pipefail
cd "$(dirname "$0")/.."
.oss-scanner/start-postgres.sh
.oss-scanner/start-gotenberg.sh
php artisan migrate --force
if [ "$(PGPASSWORD=root psql -h 127.0.0.1 -U root -d laravel -tAc 'SELECT count(*) FROM users')" = "0" ]; then
php artisan db:seed --force
fi
php artisan optimize:clear >/dev/null
nohup php artisan octane:frankenphp \
--host=127.0.0.1 \
--port=8000 \
--workers="${OCTANE_WORKERS:-1}" \
--max-requests="${OCTANE_MAX_REQUESTS:-10000}" \
--caddyfile=docker/prod/deployment/octane/FrankenPHP/Caddyfile \
>/tmp/octane.log 2>&1 &
until curl -fs -o /dev/null http://127.0.0.1:8000/login; do
if ! kill -0 $! 2>/dev/null; then
cat /tmp/octane.log
exit 1
fi
sleep 0.5
done
echo "solidtime is running on http://127.0.0.1:8000 with Octane/FrankenPHP (log: /tmp/octane.log)"

7
.oss-scanner/start-postgres.sh Executable file
View File

@@ -0,0 +1,7 @@
#!/usr/bin/env bash
# Start the local PostgreSQL server used by the test suite and the app (see .oss-scanner/Dockerfile).
set -euo pipefail
pg_ctlcluster 17 main start 2>/dev/null || true
until pg_isready -h 127.0.0.1 -p 5432 -q; do sleep 0.5; done
echo "PostgreSQL is running on 127.0.0.1:5432 (user root, password root, database laravel)"

View File

@@ -0,0 +1,122 @@
# Threat model
## What this project does
solidtime is an open-source, multi-tenant time tracking web application (Laravel backend, Vue 3 + Inertia frontend,
PostgreSQL). It runs as a hosted SaaS (solidtime.io) and is self-hosted by many organisations. Users belong to one or
more **organizations**; inside an organization each member has a role: `owner`, `admin`, `manager`, `employee` or
`placeholder` (an imported, non-login member). What each role may do is defined in `app/Service/PermissionStore.php`.
The most important security property is **isolation**: a user must never read or modify data of an organization they
are not a member of, and within an organization a member must not exceed the permissions of their role (e.g. an
employee must not see other members' time entries, billable rates, or manage members, unless the organization settings
explicitly allow it).
## Trust boundaries
- **Super admins are fully trusted.** They are the instance operators, configured via the `SUPER_ADMINS` env
variable, and have access to the Filament admin panel (`app/Filament`), which can view and change data of every
organization and impersonate users. Anything a super admin can do through the panel (including XSS, SQL injection,
SSRF or file access that is only reachable from the panel) is not a vulnerability.
- What **is** in scope: a user who is not a super admin reaching the admin panel, or any of its actions, at all.
- Operators of a self-hosted instance (shell, database, environment, filesystem access) are trusted.
- Everyone else, including organization owners and admins when acting outside their own organization, is untrusted.
## Runtime: long-lived Octane workers
In production (the hosted SaaS and the official Docker image, `docker/prod/`) the app does **not** run as one PHP
process per request. It runs on Laravel Octane with FrankenPHP in worker mode: each worker boots the application once
and then serves many requests from different users and organizations. Anything kept in memory survives from one request
to the next unless Octane resets it (`config/octane.php` lists what is reset). This includes static properties and
static caches, container bindings registered with `singleton()` instead of `scoped()` (see
`app/Providers/AppServiceProvider.php`), objects captured by those singletons, runtime `config()` / locale / timezone
changes, macros and event listeners registered during a request, and state in third-party packages.
Request A leaving state behind that request B (another user, possibly of another organization) then sees or is
affected by is in scope, rated by its impact like any other issue (see severity below). The PHPUnit suite cannot
show this class of bug, because it boots a fresh application for every test. It has to be reproduced over HTTP against
the Octane server, see "How to exercise it".
## Where untrusted input enters
All authenticated users, including employees of any organization and anyone who self-registers (registration is open
by default), are untrusted.
- **JSON API** `routes/api.php` (`/api/v1/...`), authenticated via Passport (session cookie or personal access token).
Most routes are scoped by `{organization}` and authorised in the controllers / form requests.
- **Public, unauthenticated** endpoints: `GET /api/v1/public/reports` (shared reports, accessed by a secret), login,
registration, password reset, email verification, organization invitation acceptance (`routes/web.php`).
- **Web / Inertia routes** `routes/web.php` and Fortify/Jetstream actions in `app/Actions`.
- **Imports** (`app/Service/Import/Importers`): user-uploaded CSV and ZIP files from Toggl, Clockify, Harvest,
generic CSV and solidtime's own export format. ZIP handling is in `ZipImportHelper.php`.
- **Exports / reports** (`app/Service/Export`, `app/Service/ReportExport`): CSV/XLSX/ODS and PDF. PDFs are rendered by
sending HTML to a Gotenberg (headless Chromium) service, so user-controlled content in that HTML matters.
- **OAuth** (Passport) authorization and token endpoints.
- **Filament admin panel** (`app/Filament`): only its access control is in scope (see Trust boundaries).
## Components that matter most / least
Most important: organization scoping and role checks in the API controllers, form requests (`app/Http/Requests`),
`PermissionStore`, public report sharing, invitations and member management (role changes, ownership transfer, member
merge), authentication flows (Fortify, 2FA, email change, API tokens), import parsing.
Less important / out of scope:
- `extensions/` is empty in this repository (proprietary modules are not part of the open-source code).
- `docker/`, `k8s/`, `e2e/`, `playwright/`, `docs/` and developer tooling.
- Third-party dependencies in `vendor/` and `node_modules/`, unless solidtime uses them in an unsafe way.
## How to exercise it
- `.oss-scanner/start-postgres.sh` starts the local PostgreSQL server (user `root`, password `root`, db `laravel`).
- `.oss-scanner/start-gotenberg.sh` starts the local Gotenberg server (PDF rendering via headless Chromium) on
http://127.0.0.1:3000, so the PDF export code path, including what Chromium does with the rendered HTML, can be
exercised.
- `php artisan test` runs the PHPUnit suite (start PostgreSQL and Gotenberg first); all tests are expected to pass. Endpoint tests in `tests/Unit/Endpoint/Api/V1/` show how to create users,
organizations and members with factories and call the API with a given role; they are the quickest way to write a
reproducer. Example: `php artisan test --filter=TimeEntryEndpointTest`.
- To run the app like production: `.oss-scanner/start-octane.sh` (http://127.0.0.1:8000). It starts PostgreSQL and
Gotenberg, migrates (and seeds an empty database, see `database/seeders/DatabaseSeeder.php` for the users) and runs
Octane/FrankenPHP with the production Caddyfile and a **single worker**, so consecutive requests always hit the same
worker and leaks between requests reproduce reliably. Workers keep the code they booted with: after changing PHP
code run `php artisan octane:reload`. Stop it with `php artisan octane:stop`. Note that the test suite and the app
share the same database, so `php artisan test` wipes the app's data.
- A reproducer for a leak between requests is a script that sends request A (e.g. as a member of organization X) and
then request B (as a user of organization Y) to the running Octane server and shows that B observes A's state. API
requests can be authenticated with a personal access token, e.g. created with
`php artisan tinker --execute="echo App\Models\User::where('email', '...')->first()->createToken('t')->accessToken;"`.
- There is no network: mail delivery is not available (mail uses the `array` driver in tests), and remote resources
referenced by PDF templates (e.g. fonts from fonts.bunny.net) fail to load, so PDFs fall back to local fonts.
## How we rate severity
- **Critical**: unauthenticated access to other users' data or accounts; authentication bypass; remote code execution;
SQL injection reachable by any registered user; reading or writing data of an organization the attacker is not a
member of, including through state leaking between requests in an Octane worker.
- **High**: privilege escalation within an organization (e.g. employee to admin/owner, or performing admin-only
actions); access to data the role must not see (other members' time entries, billable rates, member emails) when
the organization settings do not allow it; stored XSS that executes in another user's session; SSRF via PDF
rendering or imports; account takeover requiring user interaction.
- **Medium**: information disclosure with limited impact, CSRF on state-changing endpoints, issues requiring an
unusual but realistic configuration, denial of service by a single authenticated request (e.g. pathological
import file).
- **Low**: everything else with real security impact.
## Anything to leave alone
Please do not report (see also `SECURITY.md`):
- Theoretical findings without a working reproducer.
- Missing or weak security headers in isolation; TLS / mail DNS configuration.
- Self-XSS; CSRF on non-state-changing endpoints (logout, theme).
- CSV / spreadsheet formula injection in exports.
- Owners or admins acting destructively within their own organization.
- Anything requiring direct DB, shell or filesystem access on a self-hosted instance.
- Anything that requires being a super admin, including issues inside the Filament admin panel.
- Missing OAuth scope enforcement (not implemented yet).
- Rate-limit tuning and generic DoS through volume of requests.
## Reports and patches
Please include the affected endpoint or code path, the attacker's role and the victim, a PHPUnit test (in the style of
`tests/Unit/Endpoint/Api/V1/`) that reproduces the issue (for leaks between requests: a script against
`.oss-scanner/start-octane.sh` instead), and a minimal patch that follows the existing patterns
(authorisation in form requests/controllers via `PermissionStore`).

View File

@@ -9,10 +9,10 @@
}, },
"Invoicing": { "Invoicing": {
"repository": "solidtime-io/extension-invoicing", "repository": "solidtime-io/extension-invoicing",
"ref": "v0.0.9" "ref": "v0.0.10"
}, },
"Auditing": { "Auditing": {
"repository": "solidtime-io/extension-auditing", "repository": "solidtime-io/extension-auditing",
"ref": "v0.0.4" "ref": "v0.0.5"
} }
} }