Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s

Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 19:38:42 +02:00
1 parent 6b884ad25a
commit 2de3696993
18 files changed
+218 -62

No files matched your search

+6 -5
View File
@@ -52,6 +52,7 @@ import {
} from "@/components/ui/tooltip";
import { translateCaption } from "@/lib/catalog-translations";
import { cn } from "@/lib/utils";
import { adminFetch } from "@/lib/admin-fetch";
/* ─── Types ──────────────────────────────────────────────── */
@@ -211,7 +212,7 @@ export function CatalogTree({
setSearching(true);
try {
const catParam = catalogType === "bc" ? "&catalog=bc" : "";
const res = await fetch(
const res = await adminFetch(
`/api/admin/catalog/tree?search=${encodeURIComponent(searchQuery.trim())}${catParam}`,
);
if (res.ok) {
@@ -237,7 +238,7 @@ export function CatalogTree({
const handleToggleEnabled = useCallback(
async (node: TreeNode) => {
try {
const res = await fetch("/api/admin/catalog/tree", {
const res = await adminFetch("/api/admin/catalog/tree", {
method: "PATCH",
headers: { "Content-Type": "application/json" },
body: `{"pageId":${node.id},"toggleField":"toggleEnabled"${catBody}}`,
@@ -257,7 +258,7 @@ export function CatalogTree({
const handleToggleVisible = useCallback(
async (node: TreeNode) => {
try {
const res = await fetch("/api/admin/catalog/tree", {
const res = await adminFetch("/api/admin/catalog/tree", {
method: "PATCH",
headers: { "Content-Type": "application/json" },
body: `{"pageId":${node.id},"toggleField":"toggleVisible"${catBody}}`,
@@ -290,7 +291,7 @@ export function CatalogTree({
if (!ok) return;
try {
const res = await fetch(
const res = await adminFetch(
`/api/admin/catalog/tree?pageId=${node.id}&mode=reparent${catParam}`,
{
method: "DELETE",
@@ -571,7 +572,7 @@ function TreeItem({
setLoading(true);
try {
const catParam = catalogType === "bc" ? "&catalog=bc" : "";
const res = await fetch(
const res = await adminFetch(
`/api/admin/catalog/tree?parentId=${node.id}${catParam}`,
);
if (res.ok) {