Fix remaining security vulnerabilities
- H1: Add missing sanitize() to help center content rendering - H2: Tighten CSP by removing unsafe-inline/unsafe-eval from script-src; move theme init to external JS file with meta tag for defaultDark - M1: Add SSRF protection for radio API URLs (block private IPs) - M2: Add rate limiting to SSO ticket endpoint (5 req/30s per user) - M4: Document locale validation safety in i18n dynamic import - L1: Truncate stacktraces in admin commandocentrum to first 20 lines
This commit is contained in:
1 parent
5628e7d6b7
commit
10523e58ce
9 files changed
+52
-29
No files matched your search
@@ -423,8 +423,13 @@ export default async function CommandoCentrum() {
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{errors.map((e) => {
|
||||
{errors.map((e) => {
|
||||
const trace = decodeStacktrace(e.stacktrace);
|
||||
// Truncate stacktraces to first 20 lines to avoid info disclosure.
|
||||
const snippet = trace
|
||||
? trace.split("\n").slice(0, 20).join("\n") +
|
||||
(trace.split("\n").length > 20 ? "\n… (truncated)" : "")
|
||||
: "(empty)";
|
||||
return (
|
||||
<tr key={e.id}>
|
||||
<td className="text-sm text-gray-500 dark:text-gray-400 whitespace-nowrap">
|
||||
@@ -436,7 +441,7 @@ export default async function CommandoCentrum() {
|
||||
</td>
|
||||
<td>
|
||||
<pre className="text-xs p-2 bg-gray-50 dark:bg-black/20 rounded overflow-auto max-h-[160px]">
|
||||
{trace || "(empty)"}
|
||||
{snippet}
|
||||
</pre>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
Reference in new issue
Block a user