<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Threat Model for resolve (module path resolution library)]]></title><description><![CDATA[<p dir="auto">&lt;h3&gt;Threat Model for resolve (module path resolution library)&lt;/h3&gt;</p>
<p dir="auto">&lt;h4&gt;1. Library Overview&lt;/h4&gt;</p>
<p dir="auto">&lt;ul&gt;<br />
&lt;li&gt;&lt;strong&gt;Library Name:&lt;/strong&gt; resolve&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Brief Description:&lt;/strong&gt; Implements Node.js &lt;code&gt;require.resolve()&lt;/code&gt; algorithm for synchronous and asynchronous file path resolution. Used to locate modules and files in Node.js projects.&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Key Public APIs/Functions:&lt;/strong&gt; &lt;code&gt;resolve.sync()&lt;/code&gt; / &lt;code&gt;resolve/sync&lt;/code&gt;, &lt;code&gt;resolve()&lt;/code&gt; / &lt;code&gt;resolve/async&lt;/code&gt;&lt;/li&gt;<br />
&lt;/ul&gt;</p>
<p dir="auto">&lt;h4&gt;2. Define Scope&lt;/h4&gt;</p>
<p dir="auto">&lt;p&gt;This threat model focuses on the core path resolution algorithm, including filesystem interaction, option handling, and cache management.&lt;/p&gt;</p>
<p dir="auto">&lt;h4&gt;3. Conceptual System Diagram&lt;/h4&gt;</p>
<p dir="auto">&lt;pre&gt;&lt;code&gt;<br />
Caller Application → resolve(id, options) → Resolution Algorithm → File System<br />
│<br />
└→ Options Handling<br />
└→ Cache System<br />
&lt;/code&gt;&lt;/pre&gt;</p>
<p dir="auto">&lt;p&gt;&lt;strong&gt;Trust Boundaries:&lt;/strong&gt;&lt;/p&gt;<br />
&lt;ul&gt;<br />
&lt;li&gt;&lt;strong&gt;Input module IDs:&lt;/strong&gt; May come from untrusted sources (user input, configuration)&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Filesystem access:&lt;/strong&gt; The library interacts with the filesystem to resolve paths&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Options:&lt;/strong&gt; Provided by the caller&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Cache:&lt;/strong&gt; Used to improve performance, but could be a vector for tampering or information disclosure if not handled securely&lt;/li&gt;<br />
&lt;/ul&gt;</p>
<p dir="auto">&lt;h4&gt;4. Identify Assets&lt;/h4&gt;</p>
<p dir="auto">&lt;ul&gt;<br />
&lt;li&gt;&lt;strong&gt;Integrity of resolution output:&lt;/strong&gt; Ensure correct and safe file path matching.&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Confidentiality of configuration:&lt;/strong&gt; Prevent sensitive path information from being leaked.&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Availability/performance for host application:&lt;/strong&gt; Prevent crashes or resource exhaustion.&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Security of host application:&lt;/strong&gt; Prevent path traversal or unintended filesystem access.&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Reputation of library:&lt;/strong&gt; Maintain trust by avoiding supply chain attacks and vulnerabilities[1][3][4].&lt;/li&gt;<br />
&lt;/ul&gt;</p>
<p dir="auto">&lt;h4&gt;5. Identify Threats&lt;/h4&gt;</p>
<p dir="auto">&lt;table&gt;<br />
&lt;tr&gt;&lt;td&gt;Component / API / Interaction&lt;/td&gt;&lt;td&gt;S&lt;/td&gt;&lt;td&gt;T&lt;/td&gt;&lt;td&gt;R&lt;/td&gt;&lt;td&gt;I&lt;/td&gt;&lt;td&gt;D&lt;/td&gt;&lt;td&gt;E&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Public API Call (<code>resolve/async</code>, <code>resolve/sync</code>)&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Filesystem Access&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Options Handling&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Cache System&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;✓&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;td&gt;–&lt;/td&gt;&lt;/tr&gt;<br />
&lt;/table&gt;</p>
<p dir="auto">&lt;p&gt;&lt;strong&gt;Key Threats:&lt;/strong&gt;&lt;/p&gt;<br />
&lt;ul&gt;<br />
&lt;li&gt;&lt;strong&gt;Spoofing:&lt;/strong&gt; Malicious module IDs mimicking legitimate packages, or spoofing configuration options[1].&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Tampering:&lt;/strong&gt; Caller-provided paths altering resolution order, or cache tampering leading to incorrect results[1][4].&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Information Disclosure:&lt;/strong&gt; Error messages revealing filesystem structure or sensitive paths[1].&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Denial of Service:&lt;/strong&gt; Recursive or excessive resolution exhausting filesystem handles or causing application crashes[1].&lt;/li&gt;<br />
&lt;li&gt;&lt;strong&gt;Path Traversal:&lt;/strong&gt; Malicious input allowing access to files outside the intended directory[4].&lt;/li&gt;<br />
&lt;/ul&gt;</p>
<p dir="auto">&lt;h4&gt;6. Mitigation/Countermeasures&lt;/h4&gt;</p>
<p dir="auto">&lt;table&gt;<br />
&lt;tr&gt;&lt;td&gt;Threat Identified&lt;/td&gt;&lt;td&gt;Proposed Mitigation&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Spoofing (malicious module IDs/config)&lt;/td&gt;&lt;td&gt;Sanitize input IDs; validate against known patterns; restrict <code>basedir</code> to app-controlled paths[1][4].&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Tampering (path traversal, cache)&lt;/td&gt;&lt;td&gt;Validate input IDs for directory escapes; secure cache reads/writes; restrict cache to trusted sources[1][4].&lt;/td&gt;&lt;/tr&gt;<br />
&lt;tr&gt;&lt;td&gt;Information Disclosure (error messages)&lt;/td&gt;&lt;td&gt;Generic "not found" errors without internal paths; avoid exposing sensitive configuration in errors[1].&lt;/td&gt;&lt;/tr&gt;<br />
&lt;/table&gt;<br />
&lt;p&gt;| Denial of Service (resource exhaustion)    | Limit recursive resolution depth; implement timeout; monitor&lt;/p&gt;</p>
<p dir="auto">&lt;hr&gt;<br />
&lt;p&gt;有没有同行遇到过同样的问题？分享一下经验。&lt;/p&gt;</p>
]]></description><link>https://forum.mj7.cn/topic/7239/threat-model-for-resolve-module-path-resolution-library</link><generator>RSS for Node</generator><lastBuildDate>Fri, 02 Oct 2026 08:12:38 GMT</lastBuildDate><atom:link href="https://forum.mj7.cn/topic/7239.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 19 Apr 2026 22:08:58 GMT</pubDate><ttl>60</ttl></channel></rss>