fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs, rate-limited guards and real error logging - Validate article status/date/id input and stop resetting publishedAt on every update - Validate guild updates (state, forum enums, non-empty name) behind rate-limited guard - Fix scheduled-article publishing (ignore NULL dates, set updatedAt, type-safe predicates) - Harden admin search API (LIKE escaping, query cap, per-user rate limit, round-robin result cap) and fix search dialog abort/res.ok/loading races - Lock down HTML sanitizer to an allowlist profile and add XSS tests - Improve mobile nav accessibility (unique id, dialog role, focus management, scroll lock, outside close) - Log swallowed server errors instead of silent catch blocks - Remove dead eslint config, drop unused dompurify deps, restore knip CI step, add Playwright config with smoke spec
This commit is contained in:
1 parent
61769e355b
commit
399c047515
20 files changed
+435
-147
No files matched your search
+11
-9
@@ -1,6 +1,6 @@
|
||||
import "./load-env";
|
||||
import { Cron } from "croner";
|
||||
import { and, lt, or, sql } from "drizzle-orm";
|
||||
import { and, eq, lt, lte, sql } from "drizzle-orm";
|
||||
import { env } from "../src/env";
|
||||
import {
|
||||
db,
|
||||
@@ -237,19 +237,21 @@ async function publishScheduledArticles(): Promise<void> {
|
||||
.set({
|
||||
status: "published",
|
||||
publishedAt: now,
|
||||
updatedAt: now,
|
||||
})
|
||||
.where(
|
||||
and(
|
||||
sql`${WebsiteArticles.status} = 'scheduled'`,
|
||||
or(
|
||||
sql`${WebsiteArticles.publishAt} IS NULL`,
|
||||
sql`${WebsiteArticles.publishAt} <= ${now}`,
|
||||
),
|
||||
eq(WebsiteArticles.status, "scheduled"),
|
||||
lte(WebsiteArticles.publishAt, now),
|
||||
),
|
||||
);
|
||||
const info = result as unknown as { affectedRows?: number };
|
||||
if (info.affectedRows && info.affectedRows > 0) {
|
||||
logger.info(`Published ${info.affectedRows} scheduled article(s)`, {
|
||||
const info = result as unknown as {
|
||||
affectedRows?: number;
|
||||
rowsAffected?: number;
|
||||
};
|
||||
const published = info.affectedRows ?? info.rowsAffected ?? 0;
|
||||
if (published > 0) {
|
||||
logger.info(`Published ${published} scheduled article(s)`, {
|
||||
module: "jobs",
|
||||
});
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user