Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression
This commit is contained in:
1 parent
d782b7c4c2
commit
259c0c96ab
3 files changed
+10
-6
No files matched your search
@@ -6,9 +6,10 @@ import { uploadMedia } from "@/actions/admin-media";
|
|||||||
type MediaFile = { name: string; url: string };
|
type MediaFile = { name: string; url: string };
|
||||||
|
|
||||||
function validImageUrl(url: string): string {
|
function validImageUrl(url: string): string {
|
||||||
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
|
if (!url.startsWith("/")) return "";
|
||||||
if (url.startsWith("/")) return url;
|
if (/[<>"']/.test(url)) return "";
|
||||||
return "";
|
if (/(data|javascript|vbscript|file):/i.test(url)) return "";
|
||||||
|
return url;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function AdminMediaGrid() {
|
export function AdminMediaGrid() {
|
||||||
|
|||||||
@@ -6,9 +6,10 @@ import { uploadMediaAndReturn } from "@/actions/admin-media";
|
|||||||
type MediaFile = { name: string; url: string };
|
type MediaFile = { name: string; url: string };
|
||||||
|
|
||||||
function validImageUrl(url: string): string {
|
function validImageUrl(url: string): string {
|
||||||
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
|
if (!url.startsWith("/")) return "";
|
||||||
if (url.startsWith("/")) return url;
|
if (/[<>"']/.test(url)) return "";
|
||||||
return "";
|
if (/(data|javascript|vbscript|file):/i.test(url)) return "";
|
||||||
|
return url;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function MediaPicker({
|
export function MediaPicker({
|
||||||
|
|||||||
@@ -30,6 +30,7 @@ export class LaravelEncrypter {
|
|||||||
encrypt(value: string, serialize = true): string {
|
encrypt(value: string, serialize = true): string {
|
||||||
const iv = randomBytes(16);
|
const iv = randomBytes(16);
|
||||||
const data = serialize ? phpSerializeString(value) : value;
|
const data = serialize ? phpSerializeString(value) : value;
|
||||||
|
// snyk:ignore:javascript/CipherWithNoIntegrity
|
||||||
// AES-256-CBC is required for Laravel compatibility. Integrity is provided
|
// AES-256-CBC is required for Laravel compatibility. Integrity is provided
|
||||||
// by the HMAC-SHA256 MAC (verified by decrypt before any output is returned),
|
// by the HMAC-SHA256 MAC (verified by decrypt before any output is returned),
|
||||||
// not by the cipher mode itself. Switching to GCM would break existing
|
// not by the cipher mode itself. Switching to GCM would break existing
|
||||||
@@ -55,6 +56,7 @@ export class LaravelEncrypter {
|
|||||||
throw new Error("The MAC is invalid.");
|
throw new Error("The MAC is invalid.");
|
||||||
}
|
}
|
||||||
const iv = Buffer.from(json.iv, "base64");
|
const iv = Buffer.from(json.iv, "base64");
|
||||||
|
// snyk:ignore:javascript/CipherWithNoIntegrity
|
||||||
// AES-256-CBC required for Laravel compatibility; MAC already verified
|
// AES-256-CBC required for Laravel compatibility; MAC already verified
|
||||||
// above so padding-oracle / tampering is not a risk.
|
// above so padding-oracle / tampering is not a risk.
|
||||||
const decipher = createDecipheriv("aes-256-cbc", this.key, iv);
|
const decipher = createDecipheriv("aes-256-cbc", this.key, iv);
|
||||||
|
|||||||
Reference in new issue
Block a user