Fix security scanner findings

- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
This commit is contained in:
openhands committed 2026-07-10 23:08:15 +02:00
1 parent 942bc6fc8d
commit 1875a69b83
8 files changed
+46 -12

No files matched your search

+1 -1
View File
@@ -32,7 +32,7 @@ export function LanguageSwitcher() {
function switchLocale(code: string) {
if (code === locale) return;
document.cookie = `NEXT_LOCALE=${code};path=/;max-age=31536000;samesite=lax`;
document.cookie = `NEXT_LOCALE=${code};path=/;max-age=31536000;samesite=lax;secure`;
startTransition(() => router.refresh());
setOpen(false);
}