Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s

Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 19:38:42 +02:00
1 parent 6b884ad25a
commit 2de3696993
18 files changed
+218 -62

No files matched your search

+6 -2
View File
@@ -19,6 +19,7 @@ import {
} from "@/lib/services/paypal-topup";
import { rcon } from "@/lib/services/rcon";
import { sendCurrency } from "@/lib/services/send-currency";
import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
@@ -157,6 +158,9 @@ export async function POST(req: Request): Promise<Response> {
);
}
const hotelName =
(await siteSettings.get("hotel_name", env.HOTEL_NAME)) ?? env.HOTEL_NAME;
if (result.status !== "COMPLETED") {
// Record the non-completed attempt so support can trace it.
try {
@@ -164,7 +168,7 @@ export async function POST(req: Request): Promise<Response> {
where: { userId, transactionId: orderId, status: "CREATED" },
data: {
status: result.status,
description: `${env.HOTEL_NAME} top-up (not completed)`,
description: `${hotelName} top-up (not completed)`,
amount: result.amount,
currency: result.currency,
createdAt: new Date(),
@@ -189,7 +193,7 @@ export async function POST(req: Request): Promise<Response> {
where: { userId, transactionId: orderId, status: "CREATED" },
data: {
status: "CAPTURED_PENDING_CREDIT",
description: `${env.HOTEL_NAME} top-up: ${credits} credits`,
description: `${hotelName} top-up: ${credits} credits`,
amount: result.amount,
currency: result.currency,
createdAt: new Date(),
+4 -1
View File
@@ -11,6 +11,7 @@ import {
PAYPAL_CURRENCY,
} from "@/lib/services/paypal";
import { recordCreatedTopup } from "@/lib/services/paypal-topup";
import { siteSettings } from "@/lib/services/site-settings";
export const dynamic = "force-dynamic";
@@ -68,10 +69,12 @@ export async function POST(req: Request): Promise<Response> {
const credits = Math.floor(amount * creditsPerUnit());
const base = env.APP_URL.replace(/\/+$/, "");
const hotelName =
(await siteSettings.get("hotel_name", env.HOTEL_NAME)) ?? env.HOTEL_NAME;
try {
const order = await createOrder(amount, {
description: `${env.HOTEL_NAME} top-up: ${credits} credits`,
description: `${hotelName} top-up: ${credits} credits`,
returnUrl: `${base}/shop/topup?status=success`,
cancelUrl: `${base}/shop/topup?status=cancel`,
});