Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s
Local Build and Deploy / deploy (push) Successful in 1m38s
Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
6b884ad25a
commit
2de3696993
18 files changed
+218
-62
No files matched your search
@@ -0,0 +1,31 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { readFileSync } from "node:fs";
|
||||
import { resolve } from "node:path";
|
||||
|
||||
describe("admin CSRF wiring", () => {
|
||||
it("defaults CSRF on for mutating withAdmin handlers", () => {
|
||||
const source = readFileSync(
|
||||
resolve(process.cwd(), "src/lib/api-handler.ts"),
|
||||
"utf8",
|
||||
);
|
||||
expect(source).toContain("options.requireCsrf !== false");
|
||||
});
|
||||
|
||||
it("issues a csrf meta tag from the admin layout", () => {
|
||||
const source = readFileSync(
|
||||
resolve(process.cwd(), "src/app/admin/layout.tsx"),
|
||||
"utf8",
|
||||
);
|
||||
expect(source).toContain("setCsrfCookie");
|
||||
expect(source).toContain('meta name="csrf-token"');
|
||||
});
|
||||
|
||||
it("provides adminFetch helper that sets x-csrf-token", () => {
|
||||
const source = readFileSync(
|
||||
resolve(process.cwd(), "src/lib/admin-fetch.ts"),
|
||||
"utf8",
|
||||
);
|
||||
expect(source).toContain("x-csrf-token");
|
||||
expect(source).toContain("getCsrfToken");
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user