Fix security scanner findings

- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
This commit is contained in:
openhands committed 2026-07-10 23:08:15 +02:00
1 parent 942bc6fc8d
commit 1875a69b83
8 files changed
+46 -12

No files matched your search

+10 -1
View File
@@ -5,6 +5,15 @@ import { uploadMediaAndReturn } from "@/actions/admin-media";
type MediaFile = { name: string; url: string };
function validImageUrl(url: string): string {
try {
const u = new URL(url, window.location.origin);
return u.protocol === "http:" || u.protocol === "https:" ? u.href : "";
} catch {
return "";
}
}
export function MediaPicker({
onSelect,
current,
@@ -109,7 +118,7 @@ export function MediaPicker({
>
{/* eslint-disable-next-line @next/next/no-img-element */}
<img
src={f.url}
src={validImageUrl(f.url)}
alt={f.name}
className="w-full h-[100px] object-cover block"
/>