fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s

- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
This commit is contained in:
openhands committed 2026-09-04 13:04:08 +02:00
1 parent 61769e355b
commit 399c047515
20 files changed
+435 -147

No files matched your search

+43 -6
View File
@@ -6,6 +6,7 @@ import {
type ReactNode,
useCallback,
useEffect,
useId,
useRef,
useState,
} from "react";
@@ -27,13 +28,15 @@ export function MobileNav({
const [open, setOpen] = useState(false);
const detailsRef = useRef<HTMLDivElement>(null);
const menuRef = useRef<HTMLDivElement>(null);
const MENU_ID = "mobile-nav-menu";
const toggleRef = useRef<HTMLButtonElement>(null);
const prevFocusRef = useRef<HTMLElement | null>(null);
const menuId = useId();
const handleEscape = useCallback(
(e: KeyboardEvent) => {
if (e.key === "Escape" && open) {
setOpen(false);
detailsRef.current?.querySelector<HTMLButtonElement>("button")?.focus();
(prevFocusRef.current ?? toggleRef.current)?.focus();
}
},
[open],
@@ -44,6 +47,38 @@ export function MobileNav({
return () => document.removeEventListener("keydown", handleEscape);
}, [handleEscape]);
// Initial focus, scroll-lock, click-outside close, focus restore.
useEffect(() => {
if (!open) return;
prevFocusRef.current =
document.activeElement instanceof HTMLElement
? document.activeElement
: null;
menuRef.current
?.querySelector<HTMLElement>(
'a[href], button:not([disabled]), [tabindex]:not([tabindex="-1"])',
)
?.focus();
const prevOverflow = document.body.style.overflow;
document.body.style.overflow = "hidden";
function handlePointerDown(e: PointerEvent) {
if (
menuRef.current &&
!menuRef.current.contains(e.target as Node) &&
!toggleRef.current?.contains(e.target as Node)
) {
setOpen(false);
}
}
document.addEventListener("pointerdown", handlePointerDown);
return () => {
document.body.style.overflow = prevOverflow;
document.removeEventListener("pointerdown", handlePointerDown);
(prevFocusRef.current ?? toggleRef.current)?.focus();
};
}, [open]);
useEffect(() => {
if (!open) return;
const menu = menuRef.current;
@@ -81,6 +116,7 @@ export function MobileNav({
return (
<div ref={detailsRef} className="group relative md:hidden">
<button
ref={toggleRef}
type="button"
onClick={() => setOpen((o) => !o)}
className="list-none cursor-pointer flex items-center justify-center w-11 h-11 rounded-xl shrink-0
@@ -90,8 +126,8 @@ export function MobileNav({
focus-visible:outline-none focus-visible:ring-2 focus-visible:ring-[var(--color-primary-readable,var(--color-primary))] focus-visible:ring-offset-2 focus-visible:ring-offset-[var(--color-navbar)]"
aria-label={open ? closeLabel : menuLabel}
aria-expanded={open}
aria-haspopup="true"
aria-controls={MENU_ID}
aria-haspopup="dialog"
aria-controls={menuId}
>
<motion.svg
className="w-6 h-6"
@@ -122,8 +158,9 @@ export function MobileNav({
<AnimatePresence>
{open && (
<motion.div
id={MENU_ID}
role="menu"
id={menuId}
role="dialog"
aria-modal="true"
aria-label={brandLabel || "Navigation menu"}
className="absolute left-0 top-full mt-2 w-[min(88vw,360px)] z-50 origin-top-left"
style={{ backgroundColor: "transparent" }}