Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s
Local Build and Deploy / deploy (push) Successful in 1m38s
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
6b884ad25a
commit
2de3696993
18 files changed
+218
-62
No files matched your search
@@ -19,6 +19,7 @@ import {
|
||||
} from "@/lib/services/paypal-topup";
|
||||
import { rcon } from "@/lib/services/rcon";
|
||||
import { sendCurrency } from "@/lib/services/send-currency";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -157,6 +158,9 @@ export async function POST(req: Request): Promise<Response> {
|
||||
);
|
||||
}
|
||||
|
||||
const hotelName =
|
||||
(await siteSettings.get("hotel_name", env.HOTEL_NAME)) ?? env.HOTEL_NAME;
|
||||
|
||||
if (result.status !== "COMPLETED") {
|
||||
// Record the non-completed attempt so support can trace it.
|
||||
try {
|
||||
@@ -164,7 +168,7 @@ export async function POST(req: Request): Promise<Response> {
|
||||
where: { userId, transactionId: orderId, status: "CREATED" },
|
||||
data: {
|
||||
status: result.status,
|
||||
description: `${env.HOTEL_NAME} top-up (not completed)`,
|
||||
description: `${hotelName} top-up (not completed)`,
|
||||
amount: result.amount,
|
||||
currency: result.currency,
|
||||
createdAt: new Date(),
|
||||
@@ -189,7 +193,7 @@ export async function POST(req: Request): Promise<Response> {
|
||||
where: { userId, transactionId: orderId, status: "CREATED" },
|
||||
data: {
|
||||
status: "CAPTURED_PENDING_CREDIT",
|
||||
description: `${env.HOTEL_NAME} top-up: ${credits} credits`,
|
||||
description: `${hotelName} top-up: ${credits} credits`,
|
||||
amount: result.amount,
|
||||
currency: result.currency,
|
||||
createdAt: new Date(),
|
||||
|
||||
@@ -11,6 +11,7 @@ import {
|
||||
PAYPAL_CURRENCY,
|
||||
} from "@/lib/services/paypal";
|
||||
import { recordCreatedTopup } from "@/lib/services/paypal-topup";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -68,10 +69,12 @@ export async function POST(req: Request): Promise<Response> {
|
||||
|
||||
const credits = Math.floor(amount * creditsPerUnit());
|
||||
const base = env.APP_URL.replace(/\/+$/, "");
|
||||
const hotelName =
|
||||
(await siteSettings.get("hotel_name", env.HOTEL_NAME)) ?? env.HOTEL_NAME;
|
||||
|
||||
try {
|
||||
const order = await createOrder(amount, {
|
||||
description: `${env.HOTEL_NAME} top-up: ${credits} credits`,
|
||||
description: `${hotelName} top-up: ${credits} credits`,
|
||||
returnUrl: `${base}/shop/topup?status=success`,
|
||||
cancelUrl: `${base}/shop/topup?status=cancel`,
|
||||
});
|
||||
|
||||
Reference in new issue
Block a user