fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs, rate-limited guards and real error logging - Validate article status/date/id input and stop resetting publishedAt on every update - Validate guild updates (state, forum enums, non-empty name) behind rate-limited guard - Fix scheduled-article publishing (ignore NULL dates, set updatedAt, type-safe predicates) - Harden admin search API (LIKE escaping, query cap, per-user rate limit, round-robin result cap) and fix search dialog abort/res.ok/loading races - Lock down HTML sanitizer to an allowlist profile and add XSS tests - Improve mobile nav accessibility (unique id, dialog role, focus management, scroll lock, outside close) - Log swallowed server errors instead of silent catch blocks - Remove dead eslint config, drop unused dompurify deps, restore knip CI step, add Playwright config with smoke spec
This commit is contained in:
1 parent
61769e355b
commit
399c047515
20 files changed
+435
-147
No files matched your search
@@ -4,6 +4,7 @@ import { SearchIcon } from "lucide-react";
|
||||
import { useRouter } from "next/navigation";
|
||||
import { useTranslations } from "next-intl";
|
||||
import { useCallback, useEffect, useRef, useState } from "react";
|
||||
import type { AdminSearchResult } from "@/app/api/admin/search/route";
|
||||
import {
|
||||
Command,
|
||||
CommandEmpty,
|
||||
@@ -15,13 +16,7 @@ import {
|
||||
import { Dialog, DialogContent } from "@/components/ui/dialog";
|
||||
import { useDebounce } from "@/hooks/use-debounce";
|
||||
|
||||
type SearchResult = {
|
||||
type: string;
|
||||
id: number | string;
|
||||
title: string;
|
||||
subtitle: string;
|
||||
url: string;
|
||||
};
|
||||
type SearchResult = AdminSearchResult;
|
||||
|
||||
type SearchResponse = {
|
||||
ok: boolean;
|
||||
@@ -61,16 +56,26 @@ export function SearchDialog() {
|
||||
const res = await fetch(`/api/admin/search?q=${encodeURIComponent(q)}`, {
|
||||
signal: controller.signal,
|
||||
});
|
||||
if (!res.ok) return;
|
||||
const data: SearchResponse = await res.json();
|
||||
if (abortRef.current !== controller) return;
|
||||
if (data.ok) setResults(data.results);
|
||||
} catch {}
|
||||
setLoading(false);
|
||||
} catch (error) {
|
||||
if (error instanceof DOMException && error.name === "AbortError") return;
|
||||
if (abortRef.current === controller) setResults([]);
|
||||
} finally {
|
||||
if (abortRef.current === controller) setLoading(false);
|
||||
}
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
fetchResults(debouncedQuery);
|
||||
}, [debouncedQuery, fetchResults]);
|
||||
|
||||
useEffect(() => {
|
||||
return () => abortRef.current?.abort();
|
||||
}, []);
|
||||
|
||||
useEffect(() => {
|
||||
function handleKeyDown(e: KeyboardEvent) {
|
||||
if ((e.metaKey || e.ctrlKey) && e.key === "k") {
|
||||
|
||||
@@ -6,6 +6,7 @@ import {
|
||||
type ReactNode,
|
||||
useCallback,
|
||||
useEffect,
|
||||
useId,
|
||||
useRef,
|
||||
useState,
|
||||
} from "react";
|
||||
@@ -27,13 +28,15 @@ export function MobileNav({
|
||||
const [open, setOpen] = useState(false);
|
||||
const detailsRef = useRef<HTMLDivElement>(null);
|
||||
const menuRef = useRef<HTMLDivElement>(null);
|
||||
const MENU_ID = "mobile-nav-menu";
|
||||
const toggleRef = useRef<HTMLButtonElement>(null);
|
||||
const prevFocusRef = useRef<HTMLElement | null>(null);
|
||||
const menuId = useId();
|
||||
|
||||
const handleEscape = useCallback(
|
||||
(e: KeyboardEvent) => {
|
||||
if (e.key === "Escape" && open) {
|
||||
setOpen(false);
|
||||
detailsRef.current?.querySelector<HTMLButtonElement>("button")?.focus();
|
||||
(prevFocusRef.current ?? toggleRef.current)?.focus();
|
||||
}
|
||||
},
|
||||
[open],
|
||||
@@ -44,6 +47,38 @@ export function MobileNav({
|
||||
return () => document.removeEventListener("keydown", handleEscape);
|
||||
}, [handleEscape]);
|
||||
|
||||
// Initial focus, scroll-lock, click-outside close, focus restore.
|
||||
useEffect(() => {
|
||||
if (!open) return;
|
||||
prevFocusRef.current =
|
||||
document.activeElement instanceof HTMLElement
|
||||
? document.activeElement
|
||||
: null;
|
||||
menuRef.current
|
||||
?.querySelector<HTMLElement>(
|
||||
'a[href], button:not([disabled]), [tabindex]:not([tabindex="-1"])',
|
||||
)
|
||||
?.focus();
|
||||
const prevOverflow = document.body.style.overflow;
|
||||
document.body.style.overflow = "hidden";
|
||||
|
||||
function handlePointerDown(e: PointerEvent) {
|
||||
if (
|
||||
menuRef.current &&
|
||||
!menuRef.current.contains(e.target as Node) &&
|
||||
!toggleRef.current?.contains(e.target as Node)
|
||||
) {
|
||||
setOpen(false);
|
||||
}
|
||||
}
|
||||
document.addEventListener("pointerdown", handlePointerDown);
|
||||
return () => {
|
||||
document.body.style.overflow = prevOverflow;
|
||||
document.removeEventListener("pointerdown", handlePointerDown);
|
||||
(prevFocusRef.current ?? toggleRef.current)?.focus();
|
||||
};
|
||||
}, [open]);
|
||||
|
||||
useEffect(() => {
|
||||
if (!open) return;
|
||||
const menu = menuRef.current;
|
||||
@@ -81,6 +116,7 @@ export function MobileNav({
|
||||
return (
|
||||
<div ref={detailsRef} className="group relative md:hidden">
|
||||
<button
|
||||
ref={toggleRef}
|
||||
type="button"
|
||||
onClick={() => setOpen((o) => !o)}
|
||||
className="list-none cursor-pointer flex items-center justify-center w-11 h-11 rounded-xl shrink-0
|
||||
@@ -90,8 +126,8 @@ export function MobileNav({
|
||||
focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-[var(--color-primary-readable,var(--color-primary))] focus-visible:ring-offset-2 focus-visible:ring-offset-[var(--color-navbar)]"
|
||||
aria-label={open ? closeLabel : menuLabel}
|
||||
aria-expanded={open}
|
||||
aria-haspopup="true"
|
||||
aria-controls={MENU_ID}
|
||||
aria-haspopup="dialog"
|
||||
aria-controls={menuId}
|
||||
>
|
||||
<motion.svg
|
||||
className="w-6 h-6"
|
||||
@@ -122,8 +158,9 @@ export function MobileNav({
|
||||
<AnimatePresence>
|
||||
{open && (
|
||||
<motion.div
|
||||
id={MENU_ID}
|
||||
role="menu"
|
||||
id={menuId}
|
||||
role="dialog"
|
||||
aria-modal="true"
|
||||
aria-label={brandLabel || "Navigation menu"}
|
||||
className="absolute left-0 top-full mt-2 w-[min(88vw,360px)] z-50 origin-top-left"
|
||||
style={{ backgroundColor: "transparent" }}
|
||||
|
||||
@@ -11,6 +11,7 @@ import { ThemeSwitcher } from "@/components/theme-switcher";
|
||||
import { db, MessengerFriendrequests, MessengerOffline } from "@/lib/db";
|
||||
import { resolveHotelName } from "@/lib/hotel-name";
|
||||
import { canAccess, getApiAdminContext, PERMS } from "@/lib/permissions";
|
||||
import { logServerError } from "@/lib/server-log";
|
||||
|
||||
export async function Navigation({ session }: { session: Session | null }) {
|
||||
const t = await getTranslations("nav");
|
||||
@@ -58,7 +59,11 @@ export async function Navigation({ session }: { session: Session | null }) {
|
||||
]);
|
||||
unreadMessages = unreadRows[0]?.total ?? 0;
|
||||
pendingFriendRequests = pendingRows[0]?.total ?? 0;
|
||||
} catch {}
|
||||
} catch (error) {
|
||||
logServerError("navigation.messenger_counts_failed", error, {
|
||||
userId: id,
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
return (
|
||||
|
||||
@@ -17,6 +17,7 @@ import {
|
||||
} from "@/lib/db";
|
||||
import { resolveHotelName } from "@/lib/hotel-name";
|
||||
import { canAccess, getApiAdminContext, PERMS } from "@/lib/permissions";
|
||||
import { logServerError } from "@/lib/server-log";
|
||||
|
||||
function Currency({
|
||||
icon,
|
||||
@@ -76,7 +77,9 @@ export async function TopHeader({ session }: { session: Session | null }) {
|
||||
if (c.type === 0) duckets = c.amount;
|
||||
if (c.type === 5) diamonds = c.amount;
|
||||
}
|
||||
} catch {}
|
||||
} catch (error) {
|
||||
logServerError("top-header.wallet_failed", error, { userId: id });
|
||||
}
|
||||
|
||||
let showAdmin = false;
|
||||
let showMod = false;
|
||||
@@ -111,7 +114,8 @@ export async function TopHeader({ session }: { session: Session | null }) {
|
||||
.where(eq(User.online, "1"));
|
||||
return row?.total ?? 0;
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("top-header.online_count_failed", error);
|
||||
online = 0;
|
||||
}
|
||||
|
||||
@@ -130,7 +134,9 @@ export async function TopHeader({ session }: { session: Session | null }) {
|
||||
]);
|
||||
unreadMessages = unreadRows[0]?.total ?? 0;
|
||||
pendingFriendRequests = pendingRows[0]?.total ?? 0;
|
||||
} catch {}
|
||||
} catch (error) {
|
||||
logServerError("top-header.messenger_counts_failed", error, { userId: id });
|
||||
}
|
||||
|
||||
const friendRequests = await db
|
||||
.select({ userFromId: MessengerFriendrequests.userFromId })
|
||||
|
||||
Reference in new issue
Block a user