Use secrets.token_hex for SECRET_KEY (no hardcoded default). Add CSRF tokens to forms and cookie. Rate limit uploads: 10 per 60s per IP. Add security headers: CSP, X-Frame-Options, X-Content-Type-Options, HSTS, Referrer-Policy. Block SVG uploads (executable JS risk). Validate image content via magic bytes. Atomic file creation with O_EXCL (fixes TOCTOU race). Increase paste ID from 8→16 hex chars. Run cleanup_expired every 5min in background thread. Delete .txt files on paste deletion. Fix file upload tab (missing name attribute). Docker: add non-root user, pin dependency versions.
4 lines
46 B
Plaintext
4 lines
46 B
Plaintext
flask==3.1.0
|
|
gunicorn==23.0.0
|
|
werkzeug==3.1.3
|