Threat Model for resolve (module path resolution library)
-
<h3>Threat Model for resolve (module path resolution library)</h3>
<h4>1. Library Overview</h4>
<ul>
<li><strong>Library Name:</strong> resolve</li>
<li><strong>Brief Description:</strong> Implements Node.js <code>require.resolve()</code> algorithm for synchronous and asynchronous file path resolution. Used to locate modules and files in Node.js projects.</li>
<li><strong>Key Public APIs/Functions:</strong> <code>resolve.sync()</code> / <code>resolve/sync</code>, <code>resolve()</code> / <code>resolve/async</code></li>
</ul><h4>2. Define Scope</h4>
<p>This threat model focuses on the core path resolution algorithm, including filesystem interaction, option handling, and cache management.</p>
<h4>3. Conceptual System Diagram</h4>
<pre><code>
Caller Application → resolve(id, options) → Resolution Algorithm → File System
│
└→ Options Handling
└→ Cache System
</code></pre><p><strong>Trust Boundaries:</strong></p>
<ul>
<li><strong>Input module IDs:</strong> May come from untrusted sources (user input, configuration)</li>
<li><strong>Filesystem access:</strong> The library interacts with the filesystem to resolve paths</li>
<li><strong>Options:</strong> Provided by the caller</li>
<li><strong>Cache:</strong> Used to improve performance, but could be a vector for tampering or information disclosure if not handled securely</li>
</ul><h4>4. Identify Assets</h4>
<ul>
<li><strong>Integrity of resolution output:</strong> Ensure correct and safe file path matching.</li>
<li><strong>Confidentiality of configuration:</strong> Prevent sensitive path information from being leaked.</li>
<li><strong>Availability/performance for host application:</strong> Prevent crashes or resource exhaustion.</li>
<li><strong>Security of host application:</strong> Prevent path traversal or unintended filesystem access.</li>
<li><strong>Reputation of library:</strong> Maintain trust by avoiding supply chain attacks and vulnerabilities[1][3][4].</li>
</ul><h4>5. Identify Threats</h4>
<table>
<tr><td>Component / API / Interaction</td><td>S</td><td>T</td><td>R</td><td>I</td><td>D</td><td>E</td></tr>
<tr><td>Public API Call (resolve/async,resolve/sync)</td><td>✓</td><td>✓</td><td>–</td><td>✓</td><td>–</td><td>–</td></tr>
<tr><td>Filesystem Access</td><td>–</td><td>✓</td><td>–</td><td>✓</td><td>✓</td><td>–</td></tr>
<tr><td>Options Handling</td><td>✓</td><td>✓</td><td>–</td><td>✓</td><td>–</td><td>–</td></tr>
<tr><td>Cache System</td><td>–</td><td>✓</td><td>–</td><td>✓</td><td>–</td><td>–</td></tr>
</table><p><strong>Key Threats:</strong></p>
<ul>
<li><strong>Spoofing:</strong> Malicious module IDs mimicking legitimate packages, or spoofing configuration options[1].</li>
<li><strong>Tampering:</strong> Caller-provided paths altering resolution order, or cache tampering leading to incorrect results[1][4].</li>
<li><strong>Information Disclosure:</strong> Error messages revealing filesystem structure or sensitive paths[1].</li>
<li><strong>Denial of Service:</strong> Recursive or excessive resolution exhausting filesystem handles or causing application crashes[1].</li>
<li><strong>Path Traversal:</strong> Malicious input allowing access to files outside the intended directory[4].</li>
</ul><h4>6. Mitigation/Countermeasures</h4>
<table>
<tr><td>Threat Identified</td><td>Proposed Mitigation</td></tr>
<tr><td>Spoofing (malicious module IDs/config)</td><td>Sanitize input IDs; validate against known patterns; restrictbasedirto app-controlled paths[1][4].</td></tr>
<tr><td>Tampering (path traversal, cache)</td><td>Validate input IDs for directory escapes; secure cache reads/writes; restrict cache to trusted sources[1][4].</td></tr>
<tr><td>Information Disclosure (error messages)</td><td>Generic "not found" errors without internal paths; avoid exposing sensitive configuration in errors[1].</td></tr>
</table>
<p>| Denial of Service (resource exhaustion) | Limit recursive resolution depth; implement timeout; monitor</p><hr>
<p>有没有同行遇到过同样的问题?分享一下经验。</p>