Skip to content

File transfer server sessions never expire — unbounded memory growth and stale auth risk #22

Description

@kohfact

File transfer server sessions never expire — unbounded memory growth and stale auth risk

Severity: Medium
File: feature/file-transfer/src/main/java/com/wanbaohe/file_transfer/server/FileTransferServer.kt:52

Authenticated sessions are stored in a plain mutable set with no TTL, no max-size cap, and no eviction policy:

private val authenticatedSessions = mutableSetOf<String>()

Every successful /api/auth call adds a new UUID to this set (line 374), but sessions are never removed. Over a long-running file-transfer session (the server runs as a foreground service), this set grows without bound.

Why it matters

If the server runs for hours (common for file transfer use cases), each browser tab or reconnect creates a new session ID that is never cleaned up, causing gradual memory growth. More critically, an old session ID remains valid indefinitely — even if the operator changes the server password via updateConfig(), all previously-issued session cookies continue to work because isAuthenticated() only checks set membership, not the current password. Sessions should expire after a timeout (e.g. 30 minutes of inactivity) and be invalidated when the password changes.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions