Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking - Add DB backups to .gitignore - Replace all console.log/console.error with structured logger module - Translate Dutch error messages to English (link-discord.ts) - Remove dead code blocks (register-form.tsx false && pattern) - Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins - Add Prettier config - Add eslint-plugin-security for security-aware linting - Fix all 119+ ESLint warnings across the codebase: - Resolve security/detect-object-injection with safe access patterns - Resolve security/detect-non-literal-fs-filename with path traversal validation - Replace <img> with next/image <Image> component - Remove unused variables and imports - Replace non-null assertions with proper type guards - Replace <a> with <Link> for internal navigation - Use next/script Script component for external scripts - Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher) - Add lint and format scripts to package.json All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
This commit is contained in:
1 parent
7f8c9afc0f
commit
942bc6fc8d
93 files changed
+2676
-379115
No files matched your search
@@ -101,6 +101,7 @@ async function loadSettingsRows(
|
||||
.map((t) => {
|
||||
const u = byId.get(t.userId as number);
|
||||
if (!u) return null;
|
||||
// eslint-disable-next-line security/detect-object-injection -- field is union of known keys
|
||||
return { username: u.username, look: u.look, value: Number(t[field] ?? 0) };
|
||||
})
|
||||
.filter((r): r is Row => r !== null);
|
||||
@@ -123,13 +124,14 @@ export default async function LeaderboardPage({
|
||||
const t = await getTranslations("pages.leaderboard");
|
||||
const { type } = await searchParams;
|
||||
const active: TabKey = TABS.some((t) => t.key === type) ? (type as TabKey) : "credits";
|
||||
const activeTab = TABS.find((t) => t.key === active)!;
|
||||
const activeTab = TABS.find((t) => t.key === active) ?? TABS[0];
|
||||
|
||||
const [rows, imagerBase] = await Promise.all([
|
||||
active === "credits"
|
||||
? loadCreditsRows()
|
||||
: active === "diamonds" || active === "duckets"
|
||||
? loadCurrencyRows(CURRENCY_TYPE[active])
|
||||
// eslint-disable-next-line security/detect-object-injection -- active validated as "diamonds"|"duckets" in this branch
|
||||
? loadCurrencyRows(CURRENCY_TYPE[active])
|
||||
: loadSettingsRows(SETTINGS_FIELD[active as keyof typeof SETTINGS_FIELD]),
|
||||
siteSettings.get("habbo_imaging_url", "https://www.habbo.com/habbo-imaging/avatarimage"),
|
||||
]);
|
||||
|
||||
Reference in new issue
Block a user