fix: harden admin actions, search, sanitization and repo hygiene
- Split approve/dismiss application workflows with distinct audit logs, rate-limited guards and real error logging - Validate article status/date/id input and stop resetting publishedAt on every update - Validate guild updates (state, forum enums, non-empty name) behind rate-limited guard - Fix scheduled-article publishing (ignore NULL dates, set updatedAt, type-safe predicates) - Harden admin search API (LIKE escaping, query cap, per-user rate limit, round-robin result cap) and fix search dialog abort/res.ok/loading races - Lock down HTML sanitizer to an allowlist profile and add XSS tests - Improve mobile nav accessibility (unique id, dialog role, focus management, scroll lock, outside close) - Log swallowed server errors instead of silent catch blocks - Remove dead eslint config, drop unused dompurify deps, restore knip CI step, add Playwright config with smoke spec
This commit is contained in:
1 parent
61769e355b
commit
399c047515
20 files changed
+435
-147
No files matched your search
@@ -45,6 +45,7 @@ describe("deploy job", () => {
|
||||
|
||||
it("runs container with production env and volumes", () => {
|
||||
expect(deployJob).toContain(". /var/www/atom-nexst/.env");
|
||||
// biome-ignore lint/suspicious/noTemplateCurlyInString: intentional literal shell snippet
|
||||
expect(deployJob).toContain('"${ENV_ARGS[@]}"');
|
||||
expect(deployJob).toContain("/var/www/Gamedata:/var/www/Gamedata");
|
||||
expect(deployJob).toContain("/app/storage");
|
||||
|
||||
@@ -0,0 +1,37 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { sanitize } from "./sanitize";
|
||||
|
||||
describe("sanitize", () => {
|
||||
it("returns empty string for nullish input", () => {
|
||||
expect(sanitize(null)).toBe("");
|
||||
expect(sanitize(undefined)).toBe("");
|
||||
expect(sanitize("")).toBe("");
|
||||
});
|
||||
|
||||
it("keeps safe formatting tags", () => {
|
||||
const out = sanitize("<p>Hello <strong>world</strong></p>");
|
||||
expect(out).toContain("<strong>world</strong>");
|
||||
});
|
||||
|
||||
it("strips event handlers", () => {
|
||||
const out = sanitize('<img src="x.gif" onerror="alert(1)">');
|
||||
expect(out).not.toContain("onerror");
|
||||
});
|
||||
|
||||
it("strips javascript: URLs", () => {
|
||||
const out = sanitize('<a href="javascript:alert(1)">click</a>');
|
||||
expect(out).not.toContain("javascript:");
|
||||
});
|
||||
|
||||
it("strips svg onload vectors", () => {
|
||||
const out = sanitize('<svg onload="alert(1)"><circle r="10"/></svg>');
|
||||
expect(out).not.toContain("onload");
|
||||
expect(out).not.toContain("<svg");
|
||||
});
|
||||
|
||||
it("strips script tags", () => {
|
||||
const out = sanitize("<p>hi</p><script>alert(1)</script>");
|
||||
expect(out).not.toContain("<script");
|
||||
expect(out).toContain("hi");
|
||||
});
|
||||
});
|
||||
+47
-1
@@ -1,6 +1,52 @@
|
||||
import DOMPurify from "isomorphic-dompurify";
|
||||
|
||||
const ALLOWED_TAGS = [
|
||||
"a",
|
||||
"b",
|
||||
"blockquote",
|
||||
"br",
|
||||
"code",
|
||||
"em",
|
||||
"h1",
|
||||
"h2",
|
||||
"h3",
|
||||
"h4",
|
||||
"hr",
|
||||
"i",
|
||||
"img",
|
||||
"li",
|
||||
"ol",
|
||||
"p",
|
||||
"pre",
|
||||
"strong",
|
||||
"table",
|
||||
"tbody",
|
||||
"td",
|
||||
"th",
|
||||
"thead",
|
||||
"tr",
|
||||
"u",
|
||||
"ul",
|
||||
];
|
||||
|
||||
const ALLOWED_ATTR = [
|
||||
"href",
|
||||
"src",
|
||||
"alt",
|
||||
"title",
|
||||
"target",
|
||||
"rel",
|
||||
"colspan",
|
||||
"rowspan",
|
||||
];
|
||||
|
||||
export function sanitize(html: string | null | undefined): string {
|
||||
if (!html) return "";
|
||||
return DOMPurify.sanitize(html);
|
||||
return DOMPurify.sanitize(html, {
|
||||
ALLOWED_TAGS,
|
||||
ALLOWED_ATTR,
|
||||
ALLOW_DATA_ATTR: false,
|
||||
FORBID_TAGS: ["style", "script", "svg", "math", "form", "input", "button"],
|
||||
USE_PROFILES: { html: true },
|
||||
});
|
||||
}
|
||||
Reference in new issue
Block a user