File transfer server sessions never expire — unbounded memory growth and stale auth risk
Severity: Medium
File: feature/file-transfer/src/main/java/com/wanbaohe/file_transfer/server/FileTransferServer.kt:52
Authenticated sessions are stored in a plain mutable set with no TTL, no max-size cap, and no eviction policy:
private val authenticatedSessions = mutableSetOf<String>()
Every successful /api/auth call adds a new UUID to this set (line 374), but sessions are never removed. Over a long-running file-transfer session (the server runs as a foreground service), this set grows without bound.
Why it matters
If the server runs for hours (common for file transfer use cases), each browser tab or reconnect creates a new session ID that is never cleaned up, causing gradual memory growth. More critically, an old session ID remains valid indefinitely — even if the operator changes the server password via updateConfig(), all previously-issued session cookies continue to work because isAuthenticated() only checks set membership, not the current password. Sessions should expire after a timeout (e.g. 30 minutes of inactivity) and be invalidated when the password changes.
File transfer server sessions never expire — unbounded memory growth and stale auth risk
Severity: Medium
File:
feature/file-transfer/src/main/java/com/wanbaohe/file_transfer/server/FileTransferServer.kt:52Authenticated sessions are stored in a plain mutable set with no TTL, no max-size cap, and no eviction policy:
Every successful
/api/authcall adds a new UUID to this set (line 374), but sessions are never removed. Over a long-running file-transfer session (the server runs as a foreground service), this set grows without bound.Why it matters
If the server runs for hours (common for file transfer use cases), each browser tab or reconnect creates a new session ID that is never cleaned up, causing gradual memory growth. More critically, an old session ID remains valid indefinitely — even if the operator changes the server password via
updateConfig(), all previously-issued session cookies continue to work becauseisAuthenticated()only checks set membership, not the current password. Sessions should expire after a timeout (e.g. 30 minutes of inactivity) and be invalidated when the password changes.