Harden CMS security and theme contrast
This commit is contained in:
1 parent
2465ff2170
commit
4a1e1115b3
57 files changed
+1023
-231
No files matched your search
@@ -0,0 +1,8 @@
|
||||
export const USER_TOKENABLE_TYPE = "App\\Models\\User";
|
||||
|
||||
export function personalTokenScope(userId: number) {
|
||||
return {
|
||||
tokenableId: BigInt(userId),
|
||||
tokenableType: USER_TOKENABLE_TYPE,
|
||||
} as const;
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { databaseUserId, sessionUserId } from "@/lib/auth/session-user";
|
||||
|
||||
describe("sessionUserId", () => {
|
||||
it("returns a positive safe integer from a valid session id", () => {
|
||||
expect(sessionUserId("42")).toBe(42);
|
||||
});
|
||||
|
||||
it.each([undefined, null, "", "0", "-1", "1.5", "abc", Number.MAX_SAFE_INTEGER + 1])(
|
||||
"rejects invalid session id %s",
|
||||
(value) => {
|
||||
expect(sessionUserId(value)).toBeNull();
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
describe("databaseUserId", () => {
|
||||
it("converts a safe positive database id", () => {
|
||||
expect(databaseUserId(42n)).toBe(42);
|
||||
});
|
||||
|
||||
it.each([0n, -1n, BigInt(Number.MAX_SAFE_INTEGER) + 1n])(
|
||||
"rejects unsafe database id %s",
|
||||
(value) => {
|
||||
expect(databaseUserId(value)).toBeNull();
|
||||
},
|
||||
);
|
||||
});
|
||||
@@ -0,0 +1,9 @@
|
||||
export function sessionUserId(value: unknown): number | null {
|
||||
const id = typeof value === "string" && /^\d+$/.test(value) ? Number(value) : NaN;
|
||||
return Number.isSafeInteger(id) && id > 0 ? id : null;
|
||||
}
|
||||
|
||||
export function databaseUserId(value: bigint): number | null {
|
||||
const id = Number(value);
|
||||
return Number.isSafeInteger(id) && id > 0 ? id : null;
|
||||
}
|
||||
Reference in new issue
Block a user