6b9c7cf4aed23ab7df8fea9c24e8d0be99ddb9a9
- Add ValidateFileName (allowlist regex, rejects .. and separators) and apply it to every route that concatenates a raw path segment into a filesystem or remote FTP path: /show/lvgmc-forecast, /show/grib, /grib/binary-chunk, and /debug/file. Previously an unauthenticated caller could read arbitrary files, including /proc/self/environ (leaks LVGMC_PASSWORD/POSTGRES_PASSWORD). - Harden ValidateInt to reject negative integers. - Gate /api/fetch/lvgmc/stations behind ENABLE_LVGMC_FTP_JOBS so it can no longer trigger a real, unauthenticated FTP login regardless of the flag; stop leaking error.getMessage in its response. - Add an explicit /api/* catch-all (NotFound) so an unmatched API route can never fall through to the SPA fallback and be served index.html as a 200. - Cap binary-chunk read length at 64MB to prevent an unbounded allocation.
Weather Tool
Tool for downloading historical and real-time data from weather stations in Latvia. It aggregates and displays data for different time periods, cities, and weather parameters.
Setup
Rename .env-sample to .env and fill in credentials
Environment boundary
- Windows: source editing, review, and Git operations only. Do not compile, build, run containers, install project dependencies, or test the application here.
- Rocky Linux: the only development runtime; compile, build, run, seed, and test WeatherTool here.
- Ubuntu VPS: deployment target only. It receives the reviewed release artifact built and verified on Rocky; it is not a development or build host.
Run
docker-compose up --build --no-cache --force-recreate
Web
nginx proxy config
server {
listen 80;
server_name laikazinas.lsm.lv;
location / {
proxy_pass http://localhost:9090; # Forward requests to the Scala app
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection 'upgrade';
proxy_set_header Host $host;
proxy_cache_bypass $http_upgrade;
}
}
Rocky development runtime
// 1st terminal
podman-compose up postgres
// 2nd terminal
sbt run
// 3rd terminal
cd web/
npm run dev
Run one file
sbt "runMain grib.GribParserTest"
Backend Tech:
- scala: cats-effects, http4s, fs2, circe, scalatest
- postgres
Frontend Tech:
- SolidJS
- Vite
Fly commands
// suspend instance
fly scale count 0
// check display
fly ssh console
df -h
fly scale memory 512
Description
Languages
TypeScript
60.1%
Scala
33.3%
CSS
5.7%
HTML
0.4%
Dockerfile
0.4%
Other
0.1%