Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement
This commit is contained in:
1 parent
1875a69b83
commit
d782b7c4c2
9 files changed
+39
-41
No files matched your search
@@ -46,6 +46,9 @@ export default function TopUpForm({
|
||||
if (redirectUrl.protocol !== "https:") {
|
||||
throw new Error("Invalid redirect URL: must be HTTPS");
|
||||
}
|
||||
if (!redirectUrl.hostname.endsWith(".paypal.com") && redirectUrl.hostname !== "paypal.com") {
|
||||
throw new Error("Invalid redirect URL: must be a PayPal domain");
|
||||
}
|
||||
window.location.href = redirectUrl.href;
|
||||
} catch {
|
||||
setError("Network error — please try again.");
|
||||
|
||||
Reference in new issue
Block a user