fix(security): authorize site uploads and harden tokens, media and request identity
CI / check (push) Successful in 3m15s
CI / deploy (push) Successful in 1m19s
CI / publish-container (push) Successful in 48s

This commit is contained in:
Simo committed 2026-09-13 19:24:43 +02:00
1 parent 52f6d1491f
commit 8abfe352ef
70 files changed
+1609 -204

No files matched your search

+15 -1
View File
@@ -73,7 +73,7 @@ async function writeToFile(
}
}
/** Send an HTML email. Tries Resend → local sendmail → file fallback. Always returns true. */
/** Send through configured transports; reject unsafe headers before any I/O. */
export async function sendMail(
to: string,
subject: string,
@@ -81,6 +81,20 @@ export async function sendMail(
): Promise<boolean> {
const from = env.SMTP_FROM ?? `no-reply@${env.HOTEL_NAME}`;
if (
[to, subject, from].some(
(value) =>
typeof value !== "string" ||
!value.trim() ||
Array.from(value).some(
(char) => char.charCodeAt(0) < 32 || char.charCodeAt(0) === 127,
),
)
) {
logger.warn("Email rejected: invalid header value", { module: "email" });
return false;
}
const r = getResend();
if (r) {
try {