fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s

- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
This commit is contained in:
openhands committed 2026-09-04 13:04:08 +02:00
1 parent 61769e355b
commit 399c047515
20 files changed
+435 -147

No files matched your search

+14 -9
View File
@@ -4,6 +4,7 @@ import { SearchIcon } from "lucide-react";
import { useRouter } from "next/navigation";
import { useTranslations } from "next-intl";
import { useCallback, useEffect, useRef, useState } from "react";
import type { AdminSearchResult } from "@/app/api/admin/search/route";
import {
Command,
CommandEmpty,
@@ -15,13 +16,7 @@ import {
import { Dialog, DialogContent } from "@/components/ui/dialog";
import { useDebounce } from "@/hooks/use-debounce";
type SearchResult = {
type: string;
id: number | string;
title: string;
subtitle: string;
url: string;
};
type SearchResult = AdminSearchResult;
type SearchResponse = {
ok: boolean;
@@ -61,16 +56,26 @@ export function SearchDialog() {
const res = await fetch(`/api/admin/search?q=${encodeURIComponent(q)}`, {
signal: controller.signal,
});
if (!res.ok) return;
const data: SearchResponse = await res.json();
if (abortRef.current !== controller) return;
if (data.ok) setResults(data.results);
} catch {}
setLoading(false);
} catch (error) {
if (error instanceof DOMException && error.name === "AbortError") return;
if (abortRef.current === controller) setResults([]);
} finally {
if (abortRef.current === controller) setLoading(false);
}
}, []);
useEffect(() => {
fetchResults(debouncedQuery);
}, [debouncedQuery, fetchResults]);
useEffect(() => {
return () => abortRef.current?.abort();
}, []);
useEffect(() => {
function handleKeyDown(e: KeyboardEvent) {
if ((e.metaKey || e.ctrlKey) && e.key === "k") {