Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement

This commit is contained in:
openhands committed 2026-07-10 23:34:57 +02:00
1 parent 1875a69b83
commit d782b7c4c2
9 files changed
+39 -41

No files matched your search

+3
View File
@@ -46,6 +46,9 @@ export default function TopUpForm({
if (redirectUrl.protocol !== "https:") {
throw new Error("Invalid redirect URL: must be HTTPS");
}
if (!redirectUrl.hostname.endsWith(".paypal.com") && redirectUrl.hostname !== "paypal.com") {
throw new Error("Invalid redirect URL: must be a PayPal domain");
}
window.location.href = redirectUrl.href;
} catch {
setError("Network error — please try again.");