Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s

Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 19:38:42 +02:00
1 parent 6b884ad25a
commit 2de3696993
18 files changed
+218 -62

No files matched your search

+4 -1
View File
@@ -25,7 +25,10 @@ export function withAdmin(
handler: AdminHandler,
) {
return async (request: NextRequest, routeContext: RouteContext = {}) => {
if (options.requireCsrf === true && MUTATING_METHODS.has(request.method)) {
// CSRF required for mutating admin APIs unless explicitly opted out.
const csrfRequired =
options.requireCsrf !== false && MUTATING_METHODS.has(request.method);
if (csrfRequired) {
const csrfToken =
request.headers.get("x-csrf-token") ??
request.headers.get("csrf-token") ??