Security checks

This commit is contained in:
2026-02-08 12:50:21 +01:00
parent a79b653b05
commit 6f418661c4
+92 -4
View File
@@ -1,6 +1,9 @@
import * as vscode from "vscode"; import * as vscode from "vscode";
import { currentRun, startRun, stopRun } from "./run"; import { currentRun, startRun, stopRun } from "./run";
import { startServer, stopServer } from "./server"; import { startServer, stopServer } from "./server";
import os from "os";
import { exec } from "child_process";
import net from "net";
export function activate(context: vscode.ExtensionContext) { export function activate(context: vscode.ExtensionContext) {
const config = vscode.workspace.getConfiguration("devrun"); const config = vscode.workspace.getConfiguration("devrun");
@@ -50,14 +53,99 @@ export function activate(context: vscode.ExtensionContext) {
); );
console.log("dev-run Activated"); console.log("dev-run Activated");
// Security check - Make sure there aren't any malicious servers currently running
const autoStart = config.get<boolean>("autoStartServer"); const autoStart = config.get<boolean>("autoStartServer");
if (autoStart) { canConnect(63780)
startServer(statusBarItem); .then((canConnect) => {
console.log("dev-run server auto started!"); if (canConnect) {
} console.error(
"Unable to start due to another process listening on port 63780",
);
console.error("Possible malicious dev-run instance running");
vscode.window
.showErrorMessage(
"Possible malicious dev-run instance running",
"Kill the process listening on port 63780",
)
.then(async (response) => {
if (!response) return;
if (response === "Kill the process listening on port 63780") {
await killProcessOnPort(63780);
if (autoStart) {
startServer(statusBarItem);
console.log("dev-run server auto started!");
}
}
});
return;
}
if (autoStart) {
startServer(statusBarItem);
console.log("dev-run server auto started!");
}
})
.catch(() => {});
} }
export function deactivate() { export function deactivate() {
stopRun(); stopRun();
} }
export function canConnect(
port: number,
host = "127.0.0.1",
timeout = 1000,
): Promise<boolean> {
return new Promise((resolve) => {
const socket = new net.Socket();
socket.setTimeout(timeout);
socket.once("connect", () => {
socket.destroy();
resolve(true);
});
socket.once("timeout", () => {
socket.destroy();
resolve(false);
});
socket.once("error", () => {
resolve(false);
});
socket.connect(port, host);
});
}
export function killProcessOnPort(port: number): Promise<void> {
return new Promise((resolve, reject) => {
const platform = os.platform();
let cmd: string;
if (platform === "win32") {
// Windows
cmd = `for /f "tokens=5" %a in ('netstat -ano ^| findstr :${port}') do taskkill /PID %a /F`;
} else {
// macOS / Linux
cmd = `lsof -ti tcp:${port} | xargs kill -9`;
}
exec(cmd, (error) => {
if (error) {
resolve();
} else {
resolve();
}
});
});
}