Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression

This commit is contained in:
openhands committed 2026-07-10 23:40:11 +02:00
1 parent d782b7c4c2
commit 259c0c96ab
3 files changed
+10 -6

No files matched your search

+4 -3
View File
@@ -6,9 +6,10 @@ import { uploadMedia } from "@/actions/admin-media";
type MediaFile = { name: string; url: string }; type MediaFile = { name: string; url: string };
function validImageUrl(url: string): string { function validImageUrl(url: string): string {
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs. if (!url.startsWith("/")) return "";
if (url.startsWith("/")) return url; if (/[<>"']/.test(url)) return "";
return ""; if (/(data|javascript|vbscript|file):/i.test(url)) return "";
return url;
} }
export function AdminMediaGrid() { export function AdminMediaGrid() {
+4 -3
View File
@@ -6,9 +6,10 @@ import { uploadMediaAndReturn } from "@/actions/admin-media";
type MediaFile = { name: string; url: string }; type MediaFile = { name: string; url: string };
function validImageUrl(url: string): string { function validImageUrl(url: string): string {
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs. if (!url.startsWith("/")) return "";
if (url.startsWith("/")) return url; if (/[<>"']/.test(url)) return "";
return ""; if (/(data|javascript|vbscript|file):/i.test(url)) return "";
return url;
} }
export function MediaPicker({ export function MediaPicker({
+2
View File
@@ -30,6 +30,7 @@ export class LaravelEncrypter {
encrypt(value: string, serialize = true): string { encrypt(value: string, serialize = true): string {
const iv = randomBytes(16); const iv = randomBytes(16);
const data = serialize ? phpSerializeString(value) : value; const data = serialize ? phpSerializeString(value) : value;
// snyk:ignore:javascript/CipherWithNoIntegrity
// AES-256-CBC is required for Laravel compatibility. Integrity is provided // AES-256-CBC is required for Laravel compatibility. Integrity is provided
// by the HMAC-SHA256 MAC (verified by decrypt before any output is returned), // by the HMAC-SHA256 MAC (verified by decrypt before any output is returned),
// not by the cipher mode itself. Switching to GCM would break existing // not by the cipher mode itself. Switching to GCM would break existing
@@ -55,6 +56,7 @@ export class LaravelEncrypter {
throw new Error("The MAC is invalid."); throw new Error("The MAC is invalid.");
} }
const iv = Buffer.from(json.iv, "base64"); const iv = Buffer.from(json.iv, "base64");
// snyk:ignore:javascript/CipherWithNoIntegrity
// AES-256-CBC required for Laravel compatibility; MAC already verified // AES-256-CBC required for Laravel compatibility; MAC already verified
// above so padding-oracle / tampering is not a risk. // above so padding-oracle / tampering is not a risk.
const decipher = createDecipheriv("aes-256-cbc", this.key, iv); const decipher = createDecipheriv("aes-256-cbc", this.key, iv);