Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s

- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
This commit is contained in:
openhands committed 2026-07-26 20:28:11 +02:00
1 parent b922f6d49f
commit 17847545dd
292 files changed
+69195 -67915

No files matched your search

+10 -2
View File
@@ -2,6 +2,7 @@ import crypto from "node:crypto";
import { cookies, headers } from "next/headers";
import { redirect } from "next/navigation";
import { env } from "@/env";
import { logger } from "@/lib/logger";
import type { IpAddress } from "./types";
const CSRF_BYTES = 32;
@@ -23,12 +24,14 @@ async function isRequestSecure(): Promise<boolean> {
if (proto === "https") return true;
if (proto === "http") return false;
} catch {
// headers unavailable during static analysis
logger.warn(
"Headers unavailable during static analysis in isRequestSecure",
);
}
try {
if (env.APP_URL) return new URL(env.APP_URL).protocol === "https:";
} catch {
// ignore malformed APP_URL
logger.warn("Malformed APP_URL in isRequestSecure");
}
return process.env.NODE_ENV === "production";
}
@@ -86,6 +89,7 @@ export function safeRedirect(
if (url.host === "localhost" || url.host === "127.0.0.1")
return destination;
} catch {
logger.warn("Failed to parse redirect URL", { destination });
if (isSafePath(destination)) return destination;
}
return fallback;
@@ -130,6 +134,7 @@ function trySetCsrfCookie(
c.set(opts.name, opts.value, opts);
return true;
} catch {
logger.warn("Failed to set CSRF cookie", { name: opts.name });
return false;
}
}
@@ -155,6 +160,7 @@ export async function setCsrfCookie(): Promise<string> {
return "";
} catch {
logger.warn("Failed to set CSRF cookie (outer)");
return "";
}
}
@@ -174,6 +180,7 @@ export async function validateCsrfToken(token: string): Promise<boolean> {
if (!stored) return false;
return crypto.timingSafeEqual(Buffer.from(token), Buffer.from(stored));
} catch {
logger.warn("CSRF token validation failed");
return false;
}
}
@@ -244,6 +251,7 @@ export async function extractClientIpAsync(): Promise<IpAddress> {
h.get("x-real-ip") ??
"0.0.0.0") as IpAddress;
} catch {
logger.warn("Failed to get client IP from headers");
return "0.0.0.0" as IpAddress;
}
}