Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
- Remove .prettierrc (dead config, Biome replaces Prettier) - Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat - Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit - Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts - Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars - Replace barrel export src/types/index.ts with direct @/types/common imports - Make trustHost conditional (development only) in auth.ts - Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations - Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
This commit is contained in:
1 parent
b922f6d49f
commit
17847545dd
292 files changed
+69195
-67915
No files matched your search
@@ -2,6 +2,7 @@ import crypto from "node:crypto";
|
||||
import { cookies, headers } from "next/headers";
|
||||
import { redirect } from "next/navigation";
|
||||
import { env } from "@/env";
|
||||
import { logger } from "@/lib/logger";
|
||||
import type { IpAddress } from "./types";
|
||||
|
||||
const CSRF_BYTES = 32;
|
||||
@@ -23,12 +24,14 @@ async function isRequestSecure(): Promise<boolean> {
|
||||
if (proto === "https") return true;
|
||||
if (proto === "http") return false;
|
||||
} catch {
|
||||
// headers unavailable during static analysis
|
||||
logger.warn(
|
||||
"Headers unavailable during static analysis in isRequestSecure",
|
||||
);
|
||||
}
|
||||
try {
|
||||
if (env.APP_URL) return new URL(env.APP_URL).protocol === "https:";
|
||||
} catch {
|
||||
// ignore malformed APP_URL
|
||||
logger.warn("Malformed APP_URL in isRequestSecure");
|
||||
}
|
||||
return process.env.NODE_ENV === "production";
|
||||
}
|
||||
@@ -86,6 +89,7 @@ export function safeRedirect(
|
||||
if (url.host === "localhost" || url.host === "127.0.0.1")
|
||||
return destination;
|
||||
} catch {
|
||||
logger.warn("Failed to parse redirect URL", { destination });
|
||||
if (isSafePath(destination)) return destination;
|
||||
}
|
||||
return fallback;
|
||||
@@ -130,6 +134,7 @@ function trySetCsrfCookie(
|
||||
c.set(opts.name, opts.value, opts);
|
||||
return true;
|
||||
} catch {
|
||||
logger.warn("Failed to set CSRF cookie", { name: opts.name });
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -155,6 +160,7 @@ export async function setCsrfCookie(): Promise<string> {
|
||||
|
||||
return "";
|
||||
} catch {
|
||||
logger.warn("Failed to set CSRF cookie (outer)");
|
||||
return "";
|
||||
}
|
||||
}
|
||||
@@ -174,6 +180,7 @@ export async function validateCsrfToken(token: string): Promise<boolean> {
|
||||
if (!stored) return false;
|
||||
return crypto.timingSafeEqual(Buffer.from(token), Buffer.from(stored));
|
||||
} catch {
|
||||
logger.warn("CSRF token validation failed");
|
||||
return false;
|
||||
}
|
||||
}
|
||||
@@ -244,6 +251,7 @@ export async function extractClientIpAsync(): Promise<IpAddress> {
|
||||
h.get("x-real-ip") ??
|
||||
"0.0.0.0") as IpAddress;
|
||||
} catch {
|
||||
logger.warn("Failed to get client IP from headers");
|
||||
return "0.0.0.0" as IpAddress;
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user