Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement
This commit is contained in:
1 parent
1875a69b83
commit
d782b7c4c2
9 files changed
+39
-41
No files matched your search
@@ -6,12 +6,9 @@ import { uploadMedia } from "@/actions/admin-media";
|
||||
type MediaFile = { name: string; url: string };
|
||||
|
||||
function validImageUrl(url: string): string {
|
||||
try {
|
||||
const u = new URL(url, window.location.origin);
|
||||
return u.protocol === "http:" || u.protocol === "https:" ? u.href : "";
|
||||
} catch {
|
||||
return "";
|
||||
}
|
||||
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
|
||||
if (url.startsWith("/")) return url;
|
||||
return "";
|
||||
}
|
||||
|
||||
export function AdminMediaGrid() {
|
||||
|
||||
@@ -6,12 +6,9 @@ import { uploadMediaAndReturn } from "@/actions/admin-media";
|
||||
type MediaFile = { name: string; url: string };
|
||||
|
||||
function validImageUrl(url: string): string {
|
||||
try {
|
||||
const u = new URL(url, window.location.origin);
|
||||
return u.protocol === "http:" || u.protocol === "https:" ? u.href : "";
|
||||
} catch {
|
||||
return "";
|
||||
}
|
||||
// Only allow relative URLs (starting with /) to prevent XSS via absolute URLs.
|
||||
if (url.startsWith("/")) return url;
|
||||
return "";
|
||||
}
|
||||
|
||||
export function MediaPicker({
|
||||
|
||||
Reference in new issue
Block a user