feat: HOST validated at the adapter boundary and controls the actual bind interface (E00-S04-T04)

The environment adapter now resolves HOST through resolveHost, validating it
at the adapter boundary as a hostname (RFC 1123) or IP address (IPv4/IPv6,
node:net isIP); an invalid HOST throws a field-specific ConfigStartupError
naming host, so arbitrary env content is never used for binding or echoed
verbatim into the startup log (issue acceptance criterion, resolving security
review finding SEC-3).

The server passes config.host to server.listen(config.port, config.host, ...),
so a configured HOST binds exactly that interface and the startup log never
claims a bind the process does not enforce (resolving SEC-2).
This commit is contained in:
implementer
2026-08-30 04:41:53 +00:00
parent 73a1ae88cd
commit 345ceccfad
5 changed files with 65 additions and 9 deletions
+5 -2
View File
@@ -23,8 +23,11 @@
* It maps the environment (`HOST`/`PORT`/`DATABASE_URL`/`EPPP_SESSION_SECRET`)
* onto the validated config shape and validates it with `assertValidConfig`
* at startup, so every setting flows through the adapter and no other module
* reads `process.env` directly. The `.env.example` template (E00-S04-T05)
* builds on this boundary in a later task.
* reads `process.env` directly. `HOST` is validated at the adapter boundary
* as a hostname or IP address before it is used for binding or logged, so
* arbitrary env content is never echoed verbatim into the startup log. The
* `.env.example` template (E00-S04-T05) builds on this boundary in a later
* task.
*/
export { configSchema } from './schema.js';