0xMiden / 0xMiden/note-transport-service

No TLS on the gRPC server; missing HTTP/2 connection hardening

Abierto
#120 1 comentario 0 reacciones 0 asignados Ver en GitHub
enhancement production-readiness
Lenguaje dominante
Rust
Estrellas
3
Forks
10
Merge medio
2 h 23 min
PR fusionados (30 d)
4

Descripción

Severity: high.

### Summary

The server is plaintext-only. `tonic` is built without any `tls-*` feature (`Cargo.toml:126`) and `serve()` sets no TLS config (`crates/node/src/node/grpc/mod.rs:117-126`). Note *contents* are encrypted, but tags, cursors, and note headers travel in cleartext and traffic can be MITM'd/tampered.

Separately, no HTTP/2 hardening is configured: no `max_concurrent_streams`, `http2_keepalive_interval`/`timeout`, `tcp_keepalive`, or header-read timeout. `accept_http1(true)` also enables grpc-web (HTTP/1.1), where slow-header/body trickle applies. The 4 s `TimeoutLayer` only covers a request *after* dispatch.

### Recommendation

- Either add tonic TLS config, or document a hard requirement for a TLS-terminating proxy and bind only to localhost/private interfaces by default.
- Set `max_concurrent_streams`, keepalive, and `tcp_keepalive` on the builder.

---
Part of #114.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.