meshai/work/dashboard-frontend/node_modules/resolve/.github/THREAT_MODEL.md
malice 2c46c9104d
feat(region-routing): unified per-family routing cards + region-scoped family→channel routing (#87)
* feat(region-routing): P1 tagging + region_routes primitive + read/write API + preview launcher

- config.py: add Coverage.region_tagging (bool=False); add RegionRouteMatrix
  dataclass (enabled, cells) above NotificationsConfig; add region_routes field
  to NotificationsConfig; add explicit hydration branch for region_routes in
  _dict_to_dataclass mirroring destinations pattern.

- coverage_area.py: add MonitoringArea.name (str|None=None, frozen); update
  areas_from_config to preserve name; refactor inline geom extraction from
  classify_event_areas into shared _event_geom_json helper; add
  matching_area_names(geom_json, areas)->list[str] (additive, all named
  matches, config-order, deduped; gate unchanged); add event_region_names
  convenience wrapper.

- coverage_filter.py: add region_tagging ctor kwarg; stamp event.region/
  regions before the gate when region_tagging=True and areas non-empty and
  not event.regions (never clobbers satpass preset).

- pipeline/__init__.py: wire region_tagging into CoverageFilter construction.

- notification_routes.py: add GET /notifications/regions (named coverage area
  names, config-order, deduped); GET /notifications/region-routing (matrix as
  JSON); POST /notifications/region-routing (explicit RMW — only region_routes
  changes, toggles/rules/destinations survive).

- scripts/preview_dashboard.py: mesh-free launcher — dashboard API only, no
  mesh connector, no broadcast loop; vite runs separately.

All 87 coverage tests pass; 300 total pass; 6 pre-existing failures unchanged
(adapter config count mismatch + MeshCore EventType.NEW_CONTACT).

* feat(region-routing): manual region x family matrix editor page

Adds RegionRoutingMatrix.tsx — a plain editor over the region_routes
config primitive. Rows = families (via useFamilies()), cols = regions
(from GET /api/notifications/regions). Each cell exposes MT channel
(ChannelPicker single + includeDisabled), MC channel name (text input),
min_severity select (routine/priority/critical/immediate), and an enabled
checkbox. Only cells where MT or MC is set are included in the sparse
POST payload. Master enable toggle maps to top-level enabled. MT budget
guard warns when more than 7 distinct MT indices are in use. Sticky
family column; horizontal scroll for wide region sets.

Registers route /region-routing in App.tsx and adds "Region Routing"
nav entry (Map icon) under the Meshtastic section in Layout.tsx,
immediately after Routing.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(region-routing): regions endpoint reads saved (disk) coverage so routing columns are dynamic without a bot restart; preview reloads config after writes

* feat(routing): unify MT/MC routing into per-family cards; region routing as an in-card expand; remove rules/destinations UI + standalone page

* refactor(routing): move Meshtastic Routing from /notifications to /meshtastic/routing (mirror /meshcore/routing); redirect legacy path

* feat(region-routing): dispatcher honors region_routes matrix (authoritative-on-match, per-region cooldown, per-channel dedup); non-matrix path unchanged

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(region-routing): matrix dedup key must match boot-restore 2-tuple form (prevents restart re-broadcast flood); regression test

---------

Co-authored-by: Matt Johnson <mj@k7zvx.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-07-07 16:52:03 -06:00

4.1 KiB
Raw Blame History

Threat Model for resolve (module path resolution library)

1. Library Overview

  • Library Name: resolve
  • Brief Description: Implements Node.js require.resolve() algorithm for synchronous and asynchronous file path resolution. Used to locate modules and files in Node.js projects.
  • Key Public APIs/Functions: resolve.sync() / resolve/sync, resolve() / resolve/async

2. Define Scope

This threat model focuses on the core path resolution algorithm, including filesystem interaction, option handling, and cache management.

3. Conceptual System Diagram

Caller Application → resolve(id, options) → Resolution Algorithm → File System
                           │
                           └→ Options Handling
                           └→ Cache System

Trust Boundaries:

  • Input module IDs: May come from untrusted sources (user input, configuration)
  • Filesystem access: The library interacts with the filesystem to resolve paths
  • Options: Provided by the caller
  • Cache: Used to improve performance, but could be a vector for tampering or information disclosure if not handled securely

4. Identify Assets

  • Integrity of resolution output: Ensure correct and safe file path matching.
  • Confidentiality of configuration: Prevent sensitive path information from being leaked.
  • Availability/performance for host application: Prevent crashes or resource exhaustion.
  • Security of host application: Prevent path traversal or unintended filesystem access.
  • Reputation of library: Maintain trust by avoiding supply chain attacks and vulnerabilities[1][3][4].

5. Identify Threats

Component / API / Interaction S T R I D E
Public API Call (resolve/async, resolve/sync)
Filesystem Access
Options Handling
Cache System

Key Threats:

  • Spoofing: Malicious module IDs mimicking legitimate packages, or spoofing configuration options[1].
  • Tampering: Caller-provided paths altering resolution order, or cache tampering leading to incorrect results[1][4].
  • Information Disclosure: Error messages revealing filesystem structure or sensitive paths[1].
  • Denial of Service: Recursive or excessive resolution exhausting filesystem handles or causing application crashes[1].
  • Path Traversal: Malicious input allowing access to files outside the intended directory[4].

6. Mitigation/Countermeasures

Threat Identified Proposed Mitigation
Spoofing (malicious module IDs/config) Sanitize input IDs; validate against known patterns; restrict basedir to app-controlled paths[1][4].
Tampering (path traversal, cache) Validate input IDs for directory escapes; secure cache reads/writes; restrict cache to trusted sources[1][4].
Information Disclosure (error messages) Generic "not found" errors without internal paths; avoid exposing sensitive configuration in errors[1].
Denial of Service (resource exhaustion) Limit recursive resolution depth; implement timeout; monitor for excessive filesystem operations[1].

7. Risk Ranking

  • High: Path traversal via malicious IDs (if not properly mitigated)
  • Medium: Cache tampering or spoofing (if cache is not secured)
  • Low: Information disclosure in errors (if error handling is generic)

8. Next Steps & Review

  1. Implement input sanitization for module IDs and configuration.
  2. Add resolution depth limiting and timeout.
  3. Audit cache handling for race conditions and tampering.
  4. Regularly review dependencies for vulnerabilities.
  5. Keep documentation and threat model up to date.
  6. Monitor for new threats as the ecosystem and library evolve[1][3].