fix: harden admin actions, search, sanitization and repo hygiene
CI / check (push) Successful in 1m21s
CI / deploy (push) Successful in 1m25s

- Split approve/dismiss application workflows with distinct audit logs,
  rate-limited guards and real error logging
- Validate article status/date/id input and stop resetting publishedAt
  on every update
- Validate guild updates (state, forum enums, non-empty name) behind
  rate-limited guard
- Fix scheduled-article publishing (ignore NULL dates, set updatedAt,
  type-safe predicates)
- Harden admin search API (LIKE escaping, query cap, per-user
  rate limit, round-robin result cap) and fix search dialog
  abort/res.ok/loading races
- Lock down HTML sanitizer to an allowlist profile and add XSS tests
- Improve mobile nav accessibility (unique id, dialog role, focus
  management, scroll lock, outside close)
- Log swallowed server errors instead of silent catch blocks
- Remove dead eslint config, drop unused dompurify deps, restore knip
  CI step, add Playwright config with smoke spec
This commit is contained in:
openhands committed 2026-09-04 13:04:08 +02:00
1 parent 61769e355b
commit 399c047515
20 files changed
+435 -147

No files matched your search

+9 -3
View File
@@ -17,6 +17,7 @@ import {
} from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
import { canAccess, getApiAdminContext, PERMS } from "@/lib/permissions";
import { logServerError } from "@/lib/server-log";
function Currency({
icon,
@@ -76,7 +77,9 @@ export async function TopHeader({ session }: { session: Session | null }) {
if (c.type === 0) duckets = c.amount;
if (c.type === 5) diamonds = c.amount;
}
} catch {}
} catch (error) {
logServerError("top-header.wallet_failed", error, { userId: id });
}
let showAdmin = false;
let showMod = false;
@@ -111,7 +114,8 @@ export async function TopHeader({ session }: { session: Session | null }) {
.where(eq(User.online, "1"));
return row?.total ?? 0;
});
} catch {
} catch (error) {
logServerError("top-header.online_count_failed", error);
online = 0;
}
@@ -130,7 +134,9 @@ export async function TopHeader({ session }: { session: Session | null }) {
]);
unreadMessages = unreadRows[0]?.total ?? 0;
pendingFriendRequests = pendingRows[0]?.total ?? 0;
} catch {}
} catch (error) {
logServerError("top-header.messenger_counts_failed", error, { userId: id });
}
const friendRequests = await db
.select({ userFromId: MessengerFriendrequests.userFromId })