Echo Document Manager is a multi-tenant Cloudflare Worker (Hono, D1 + KV + R2) storing actual tenant document content (in R2) plus Stripe billing metadata.
- The auth middleware exempted every GET request unconditionally, not just the intended
public ones. The repo already has a correctly-designed, token-gated
/shared/:tokenmechanism for deliberate public sharing -- but the blanketc.req.method === 'GET'exemption meant every other GET route was reachable with zero credentials too, given only a guessable id. This is more severe than a metadata-only exposure:/files/:id/downloadserved real file bytes from R2, not just a database row. Also exposed:/tenants/:id,/folders,/files,/files/:id/versions,/files/:id/comments,/shares,/trash,/activity,/analytics/overview,/plans/:tenant_id. Narrowed the exemption to the routes actually meant to be public:/health,/status,/shared/*(its own token gate),/webhooks/stripe(its own HMAC signature check). - Timing side-channel in the credential check. The API key comparison used raw
key !== c.env.ECHO_API_KEY. Replaced with a constant-timetimingSafeEqual. (The existing Stripe webhook signature check,verifyStripeSignature, was already constant-time -- an XOR-accumulator loop -- and was left unchanged.)
The repo had no tsconfig.json and no typescript devDependency at all -- it could not
be typechecked as it stood. Added both, matching the same Hono + D1 + KV(+ R2) shape used by
sibling repos in this consolidation campaign.
npm audit reports 8 vulnerabilities (undici, ws) via wrangler/miniflare's dependency
tree -- local dev-server/build tooling, never shipped in the deployed Worker bundle. Fixing
requires an unverified major wrangler bump. Same disposition as the identical finding on
echo-compliance-auditor and echo-lms earlier in this consolidation campaign.
Security fixes target the current main branch. Historical commits are retained for evidence
and are not patched in place.
Do not open a public issue for a suspected vulnerability. Send a private report to
security@echo-op.com with:
- affected endpoint and exact revision;
- reproduction steps and expected impact (this service stores real tenant document content
and Stripe billing metadata -- treat any auth-boundary issue as high severity, especially
anything touching
/files/*or/shared/*); - safe contact details for follow-up.
Never include a live ECHO_API_KEY, STRIPE_SECRET_KEY, or STRIPE_WEBHOOK_SECRET in a
report.