fix(security): authorize site uploads and harden tokens, media and request identity
This commit is contained in:
1 parent
52f6d1491f
commit
8abfe352ef
70 files changed
+1609
-204
No files matched your search
@@ -73,7 +73,7 @@ async function writeToFile(
|
||||
}
|
||||
}
|
||||
|
||||
/** Send an HTML email. Tries Resend → local sendmail → file fallback. Always returns true. */
|
||||
/** Send through configured transports; reject unsafe headers before any I/O. */
|
||||
export async function sendMail(
|
||||
to: string,
|
||||
subject: string,
|
||||
@@ -81,6 +81,20 @@ export async function sendMail(
|
||||
): Promise<boolean> {
|
||||
const from = env.SMTP_FROM ?? `no-reply@${env.HOTEL_NAME}`;
|
||||
|
||||
if (
|
||||
[to, subject, from].some(
|
||||
(value) =>
|
||||
typeof value !== "string" ||
|
||||
!value.trim() ||
|
||||
Array.from(value).some(
|
||||
(char) => char.charCodeAt(0) < 32 || char.charCodeAt(0) === 127,
|
||||
),
|
||||
)
|
||||
) {
|
||||
logger.warn("Email rejected: invalid header value", { module: "email" });
|
||||
return false;
|
||||
}
|
||||
|
||||
const r = getResend();
|
||||
if (r) {
|
||||
try {
|
||||
|
||||
Reference in new issue
Block a user