Enforce admin CSRF, harden catalog translate, use CMS hotel name for PayPal.
Local Build and Deploy / deploy (push) Successful in 1m38s

Mutating withAdmin routes now require a double-submit CSRF token; translate is capped at 500 items with audit logging; PayPal descriptions prefer siteSettings hotel_name.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-18 19:38:42 +02:00
1 parent 6b884ad25a
commit 2de3696993
18 files changed
+218 -62

No files matched your search

+18 -9
View File
@@ -5,9 +5,15 @@ import { env } from "@/env";
import type { IpAddress } from "./types";
const CSRF_BYTES = 32;
const CSRF_COOKIE = "__Host-csrf-token";
const CSRF_COOKIE_MAX_AGE = 86400; // 24h
/** `__Host-` requires Secure; use a plain name on non-HTTPS local dev. */
function csrfCookieName(): string {
return process.env.NODE_ENV === "production"
? "__Host-csrf-token"
: "csrf-token";
}
const ALLOWED_HOSTS: ReadonlySet<string> = new Set(
[
env.APP_URL ? new URL(env.APP_URL).host : "",
@@ -58,7 +64,7 @@ export function redirectSafe(
redirect(safeRedirect(destination, fallback));
}
function csrfCookieOpts(): {
function csrfCookieOpts(value: string): {
name: string;
value: string;
httpOnly: boolean;
@@ -67,11 +73,12 @@ function csrfCookieOpts(): {
path: string;
maxAge: number;
} {
const isProd = process.env.NODE_ENV === "production";
return {
name: CSRF_COOKIE,
value: crypto.randomBytes(CSRF_BYTES).toString("hex"),
name: csrfCookieName(),
value,
httpOnly: true,
secure: true,
secure: isProd,
sameSite: "lax" as const,
path: "/",
maxAge: CSRF_COOKIE_MAX_AGE,
@@ -80,19 +87,21 @@ function csrfCookieOpts(): {
export async function setCsrfCookie(): Promise<string> {
const c = await cookies();
const existing = c.get(CSRF_COOKIE);
const name = csrfCookieName();
const existing = c.get(name);
if (existing?.value && existing.value.length === CSRF_BYTES * 2)
return existing.value;
const opts = csrfCookieOpts();
const value = crypto.randomBytes(CSRF_BYTES).toString("hex");
const opts = csrfCookieOpts(value);
c.set(opts.name, opts.value, opts);
return opts.value;
return value;
}
export async function validateCsrfToken(token: string): Promise<boolean> {
if (!token || token.length !== CSRF_BYTES * 2) return false;
try {
const c = await cookies();
const stored = c.get(CSRF_COOKIE)?.value;
const stored = c.get(csrfCookieName())?.value;
if (!stored || stored.length !== CSRF_BYTES * 2) return false;
return crypto.timingSafeEqual(Buffer.from(token), Buffer.from(stored));
} catch {