Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression

This commit is contained in:
openhands committed 2026-07-10 23:40:11 +02:00
1 parent d782b7c4c2
commit 259c0c96ab
3 files changed
+10 -6

No files matched your search

+4 -3
View File
@@ -6,9 +6,10 @@ import { uploadMedia } from "@/actions/admin-media";
type MediaFile = { name: string; url: string };
function validImageUrl(url: string): string {
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
if (url.startsWith("/")) return url;
return "";
if (!url.startsWith("/")) return "";
if (/[<>"']/.test(url)) return "";
if (/(data|javascript|vbscript|file):/i.test(url)) return "";
return url;
}
export function AdminMediaGrid() {
+4 -3
View File
@@ -6,9 +6,10 @@ import { uploadMediaAndReturn } from "@/actions/admin-media";
type MediaFile = { name: string; url: string };
function validImageUrl(url: string): string {
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
if (url.startsWith("/")) return url;
return "";
if (!url.startsWith("/")) return "";
if (/[<>"']/.test(url)) return "";
if (/(data|javascript|vbscript|file):/i.test(url)) return "";
return url;
}
export function MediaPicker({