Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .env.example
Original file line numberDiff line numberDiff line change
Expand Up@@ -64,6 +64,7 @@ PUBLIC_PLAY_STORE_EID_WALLET=""
NOTIFICATION_SHARED_SECRET=your-notification-secret-key

PUBLIC_ESIGNER_BASE_URL="http://localhost:3004"
PUBLIC_FILE_MANAGER_BASE_URL="http://localhost:3005"

DREAMSYNC_DATABASE_URL=postgresql://postgres:postgres@localhost:5432/dreamsync
VITE_DREAMSYNC_BASE_URL="http://localhost:8888"
Expand Down
1 change: 1 addition & 0 deletions platforms/esigner-api/src/controllers/FileController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -199,6 +199,7 @@ export class FileController {
res.json(signatures.map(sig => ({
id: sig.id,
userId: sig.userId,
fileSigneeId: sig.fileSigneeId || null,
user: sig.user ? {
id: sig.user.id,
name: sig.user.name,
Expand Down
166 changes: 166 additions & 0 deletions platforms/esigner-api/src/controllers/WebhookController.ts
Original file line numberDiff line numberDiff line change
Expand Up@@ -2,22 +2,30 @@ import { Request, Response } from "express";
import { UserService } from "../services/UserService";
import { GroupService } from "../services/GroupService";
import { MessageService } from "../services/MessageService";
import { FileService } from "../services/FileService";
import { Web3Adapter } from "web3-adapter";
import { User } from "../database/entities/User";
import { Group } from "../database/entities/Group";
import { Message } from "../database/entities/Message";
import { File } from "../database/entities/File";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { AppDataSource } from "../database/data-source";
import axios from "axios";

export class WebhookController {
userService: UserService;
groupService: GroupService;
messageService: MessageService;
fileService: FileService;
adapter: Web3Adapter;
fileRepository = AppDataSource.getRepository(File);
signatureRepository = AppDataSource.getRepository(SignatureContainer);

constructor(adapter: Web3Adapter) {
this.userService = new UserService();
this.groupService = new GroupService();
this.messageService = new MessageService();
this.fileService = new FileService();
this.adapter = adapter;
}

Expand DownExpand Up@@ -242,6 +250,164 @@ export class WebhookController {
});
console.log("Stored mapping for message:", message.id, "->", req.body.id);
}
} else if (mapping.tableName === "files") {
// Extract owner from the file data
// ownerId might be a global reference or local ID
let ownerId: string | null = null;
if (local.data.ownerId && typeof local.data.ownerId === "string") {
// Check if it's a reference format like "users(uuid)"
if (local.data.ownerId.includes("(")) {
ownerId = local.data.ownerId.split("(")[1].split(")")[0];
} else {
ownerId = local.data.ownerId;
}
}

// Resolve global ownerId to local ownerId if needed
if (ownerId) {
const localOwnerId = await this.adapter.mappingDb.getLocalId(ownerId);
ownerId = localOwnerId || ownerId;
}

const owner = ownerId ? await this.userService.getUserById(ownerId) : null;
if (!owner) {
console.error("Owner not found for file");
return res.status(500).send();
}

if (localId) {
// Update existing file
const file = await this.fileService.getFileById(localId);
if (!file) {
console.error("File not found for localId:", localId);
return res.status(500).send();
}

file.name = local.data.name as string;
file.displayName = local.data.displayName as string | null;
file.description = local.data.description as string | null;
file.mimeType = local.data.mimeType as string;
file.size = local.data.size as number;
file.md5Hash = local.data.md5Hash as string;
file.ownerId = owner.id;

// Decode base64 data if provided
if (local.data.data && typeof local.data.data === "string") {
file.data = Buffer.from(local.data.data, "base64");
}

this.adapter.addToLockedIds(localId);
await this.fileRepository.save(file);
} else {
// Create new file with binary data
// Decode base64 data if provided
let fileData: Buffer = Buffer.alloc(0);
if (local.data.data && typeof local.data.data === "string") {
fileData = Buffer.from(local.data.data, "base64");
}

const file = this.fileRepository.create({
name: local.data.name as string,
displayName: local.data.displayName as string | null,
description: local.data.description as string | null,
mimeType: local.data.mimeType as string,
size: local.data.size as number,
md5Hash: local.data.md5Hash as string,
ownerId: owner.id,
data: fileData,
});

this.adapter.addToLockedIds(file.id);
await this.fileRepository.save(file);
await this.adapter.mappingDb.storeMapping({
localId: file.id,
globalId: req.body.id,
});
localId = file.id;
}
} else if (mapping.tableName === "signature_containers") {
// Extract file and user from the signature data
let file: File | null = null;
let user: User | null = null;

// Resolve fileId - might be global reference
let fileId: string | null = null;
if (local.data.fileId && typeof local.data.fileId === "string") {
if (local.data.fileId.includes("(")) {
const fileGlobalId = local.data.fileId.split("(")[1].split(")")[0];
const fileLocalId = await this.adapter.mappingDb.getLocalId(fileGlobalId);
fileId = fileLocalId || fileGlobalId;
} else {
fileId = local.data.fileId;
}
}

// Resolve userId - might be global reference
let userId: string | null = null;
if (local.data.userId && typeof local.data.userId === "string") {
if (local.data.userId.includes("(")) {
userId = local.data.userId.split("(")[1].split(")")[0];
} else {
userId = local.data.userId;
}
}

// Resolve global IDs to local IDs
if (fileId) {
const localFileId = await this.adapter.mappingDb.getLocalId(fileId);
fileId = localFileId || fileId;
}
if (userId) {
const localUserId = await this.adapter.mappingDb.getLocalId(userId);
userId = localUserId || userId;
}

file = fileId ? await this.fileRepository.findOne({ where: { id: fileId } }) : null;
user = userId ? await this.userService.getUserById(userId) : null;

if (!file || !user) {
console.error("File or user not found for signature");
return res.status(500).send();
}

if (localId) {
// Update existing signature
const signature = await this.signatureRepository.findOne({
where: { id: localId },
});
if (!signature) {
console.error("Signature not found for localId:", localId);
return res.status(500).send();
}

signature.fileId = file.id;
signature.userId = user.id;
signature.md5Hash = local.data.md5Hash as string;
signature.signature = local.data.signature as string;
signature.publicKey = local.data.publicKey as string;
signature.message = local.data.message as string;

this.adapter.addToLockedIds(localId);
await this.signatureRepository.save(signature);
} else {
// Create new signature
const signature = this.signatureRepository.create({
fileId: file.id,
userId: user.id,
md5Hash: local.data.md5Hash as string,
signature: local.data.signature as string,
publicKey: local.data.publicKey as string,
message: local.data.message as string,
});

this.adapter.addToLockedIds(signature.id);
await this.signatureRepository.save(signature);
await this.adapter.mappingDb.storeMapping({
localId: signature.id,
globalId: req.body.id,
});
localId = signature.id;
}
}

res.status(200).json({ success: true });
Expand Down
11 changes: 11 additions & 0 deletions platforms/esigner-api/src/services/InvitationService.ts
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,15 @@
import { AppDataSource } from "../database/data-source";
import { File } from "../database/entities/File";
import { FileSignee } from "../database/entities/FileSignee";
import { SignatureContainer } from "../database/entities/SignatureContainer";
import { User } from "../database/entities/User";
import { In } from "typeorm";
import { NotificationService } from "./NotificationService";

export class InvitationService {
private fileRepository = AppDataSource.getRepository(File);
private fileSigneeRepository = AppDataSource.getRepository(FileSignee);
private signatureRepository = AppDataSource.getRepository(SignatureContainer);
private userRepository = AppDataSource.getRepository(User);
private notificationService = new NotificationService();

Expand All@@ -25,6 +27,15 @@ export class InvitationService {
throw new Error("File not found or user is not the owner");
}

// Check if file already has signatures (single-use enforcement)
const existingSignatures = await this.signatureRepository.find({
where: { fileId },
});

if (existingSignatures.length > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
Comment on lines +30 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

Critical: Race condition (TOCTOU) in single-use enforcement.

Between checking for existing signature containers (lines 31-33) and creating invitations (lines 52-96), concurrent requests can both pass the validation and proceed, violating the single-use constraint. This is a classic time-of-check to time-of-use vulnerability.

🔎 Recommended fix: Wrap in transaction with appropriate isolation
 async inviteSignees(
fileId: string,
userIds: string[],
invitedBy: string
): Promise<FileSignee[]> {
+ return await AppDataSource.transaction(async (transactionalEntityManager) => {+ const signatureRepository = transactionalEntityManager.getRepository(SignatureContainer);+ const fileRepository = transactionalEntityManager.getRepository(File);+ const fileSigneeRepository = transactionalEntityManager.getRepository(FileSignee);+ const userRepository = transactionalEntityManager.getRepository(User);+
// Verify file exists and user is owner
- const file = await this.fileRepository.findOne({+ const file = await fileRepository.findOne({
where: { id: fileId, ownerId: invitedBy },
+ lock: { mode: "pessimistic_write" },
});
if (!file) {
throw new Error("File not found or user is not the owner");
}
// Check if file already has signatures (single-use enforcement)
- const existingSignatures = await this.signatureRepository.find({+ const existingSignatureCount = await signatureRepository.count({
where: { fileId },
});
- if (existingSignatures.length > 0) {+ if (existingSignatureCount > 0) {
throw new Error("This file has already been used in a signature container and cannot be reused");
}
// ... rest of the method using transactionalEntityManager repositories
+ });
}

This approach:

  • Uses a transaction to ensure atomicity
  • Applies pessimistic write lock on the file to prevent concurrent modifications
  • Improves performance by using count() instead of find()

Committable suggestion skipped: line range outside the PR's diff.

🤖 Prompt for AI Agents
In @platforms/esigner-api/src/services/InvitationService.ts around lines 30-37,
The single-use check in InvitationService (the existingSignatures lookup via
this.signatureRepository.find with fileId) is vulnerable to a TOCTOU race; wrap
the check-and-create logic that spans the validation and invitation creation
(the block that precedes and includes the create-invitation flow) in a database
transaction, acquire a pessimistic write/row lock on the target file record (or
an appropriate row representing the file) inside that transaction, replace the
find(...) call with a count(...) query for existence, and perform the invitation
creation only within the same transaction so concurrent requests are serialized
and cannot both pass the check.


// Filter out the owner from userIds (they can't invite themselves)
const filteredUserIds = userIds.filter(userId => userId !== invitedBy);

Expand Down
18 changes: 18 additions & 0 deletions platforms/esigner-api/src/web3adapter/mappings/file.mapping.json
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
{
"tableName": "files",
"schemaId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"ownerEnamePath": "users(owner.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"name": "name",
"displayName": "displayName",
"description": "description",
"mimeType": "mimeType",
"size": "size",
"md5Hash": "md5Hash",
"data": "data",
"ownerId": "users(owner.id),ownerId",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
{
"tableName": "signature_containers",
"schemaId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"ownerEnamePath": "users(user.ename)",
"ownedJunctionTables": [],
"localToUniversalMap": {
"fileId": "files(file.id),fileId",
"userId": "users(user.id),userId",
"md5Hash": "md5Hash",
"signature": "signature",
"publicKey": "publicKey",
"message": "message",
"createdAt": "__date(createdAt)",
"updatedAt": "__date(updatedAt)"
}
}
Comment on lines +1 to +16

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

CRITICAL: This mapping file is identical to the one in file-manager-api.

Both platforms/file-manager-api/src/web3adapter/mappings/signature.mapping.json and this file share:

  • Identical schemaId: "b2c3d4e5-f6a7-8901-bcde-f12345678901"
  • Identical tableName, ownerEnamePath, and field mappings

This raises several concerns:

  1. If schemaIds must be globally unique: This is a data integrity violation that could cause collisions in distributed systems.
  2. If this is intentional synchronization: The duplication creates a maintenance burden—updates must be kept in sync manually.
  3. Configuration management: Consider whether this shared configuration should live in a common location.

Verify the intended architecture and either:

  • Generate unique schemaIds if required, or
  • Extract to a shared configuration module if both platforms truly share the same schema

Loading