Harden CMS security and theme contrast

This commit is contained in:
Simo committed 2026-07-11 20:27:20 +02:00
1 parent 2465ff2170
commit 4a1e1115b3
57 files changed
+1023 -231

No files matched your search

+7 -9
View File
@@ -3,6 +3,7 @@
import { revalidatePath } from "next/cache";
import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
import { formPositiveBigInt } from "@/lib/form-data";
export async function createCategory(formData: FormData): Promise<void> {
await requireStaff();
@@ -28,9 +29,8 @@ export async function createCategory(formData: FormData): Promise<void> {
export async function deleteCategory(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "");
if (!/^\d+$/.test(raw)) return;
const id = BigInt(raw);
const id = formPositiveBigInt(formData, "id");
if (!id) return;
try {
// Remove the category's values first to avoid orphaned rows.
@@ -44,9 +44,8 @@ export async function deleteCategory(formData: FormData): Promise<void> {
export async function createValue(formData: FormData): Promise<void> {
await requireStaff();
const categoryRaw = String(formData.get("categoryId") ?? "");
if (!/^\d+$/.test(categoryRaw)) return;
const categoryId = BigInt(categoryRaw);
const categoryId = formPositiveBigInt(formData, "categoryId");
if (!categoryId) return;
const name = String(formData.get("name") ?? "")
.trim()
@@ -90,9 +89,8 @@ export async function createValue(formData: FormData): Promise<void> {
export async function deleteValue(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "");
if (!/^\d+$/.test(raw)) return;
const id = BigInt(raw);
const id = formPositiveBigInt(formData, "id");
if (!id) return;
try {
await prisma.websiteRareValues.delete({ where: { id } });