Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+3 -3
View File
@@ -12,7 +12,7 @@ import { formPositiveBigInt } from "@/lib/form-data";
export async function createAd(formData: FormData): Promise<void> {
const staff = await requireStaff();
const image = String(formData.get("image") ?? "")
const image = String(formData.get("image") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!image) return;
@@ -39,10 +39,10 @@ export async function createAd(formData: FormData): Promise<void> {
export async function updateAd(formData: FormData): Promise<void> {
const staff = await requireStaff();
const raw = String(formData.get("id") ?? "");
const raw = String(formData.get("id") ?? "").normalize("NFC");
if (!/^\d+$/.test(raw)) return;
const id = BigInt(raw);
const image = String(formData.get("image") ?? "")
const image = String(formData.get("image") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!image) return;
+1 -1
View File
@@ -13,7 +13,7 @@ import { rcon } from "@/lib/services/rcon";
export async function sendHotelAlert(formData: FormData): Promise<void> {
await requireStaff();
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, 1000);
if (!message) return;
+8 -8
View File
@@ -19,10 +19,10 @@ async function uniqueSlug(title: string): Promise<string> {
export async function createArticle(formData: FormData): Promise<void> {
const staff = await requireStaff();
const title = String(formData.get("title") ?? "").trim();
const shortStory = String(formData.get("shortStory") ?? "").trim();
const fullStory = String(formData.get("fullStory") ?? "").trim();
const image = String(formData.get("image") ?? "").trim();
const title = String(formData.get("title") ?? "").normalize("NFC").trim();
const shortStory = String(formData.get("shortStory") ?? "").normalize("NFC").trim();
const fullStory = String(formData.get("fullStory") ?? "").normalize("NFC").trim();
const image = String(formData.get("image") ?? "").normalize("NFC").trim();
if (!title) return;
try {
@@ -53,14 +53,14 @@ export async function updateArticle(formData: FormData): Promise<void> {
await prisma.websiteArticles.update({
where: { id },
data: {
title: String(formData.get("title") ?? "")
title: String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
shortStory: String(formData.get("shortStory") ?? "")
shortStory: String(formData.get("shortStory") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
fullStory: String(formData.get("fullStory") ?? "").trim(),
image: String(formData.get("image") ?? "")
fullStory: String(formData.get("fullStory") ?? "").normalize("NFC").trim(),
image: String(formData.get("image") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
updatedAt: new Date(),
+1 -1
View File
@@ -27,7 +27,7 @@ export async function uploadBadge(formData: FormData): Promise<void> {
back("error", "Badge upload directory not configured");
}
const code = String(formData.get("code") ?? "").trim();
const code = String(formData.get("code") ?? "").normalize("NFC").trim();
if (!CODE_RE.test(code)) {
back("error", "Invalid badge code (use A-Z, 0-9, _ or -, max 64 chars)");
}
+1 -1
View File
@@ -9,7 +9,7 @@ export async function giveBadge(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const code = String(formData.get("code") ?? "")
const code = String(formData.get("code") ?? "").normalize("NFC")
.trim()
.slice(0, 32);
if (!(userId > 0) || code.length === 0) return;
+1 -1
View File
@@ -15,7 +15,7 @@ export async function createBan(formData: FormData): Promise<void> {
const staff = await requireStaff();
const userId = Number(formData.get("userId"));
const reason =
String(formData.get("reason") ?? "")
String(formData.get("reason") ?? "").normalize("NFC")
.trim()
.slice(0, 200) || "Banned";
const hours = Number(formData.get("hours"));
+8 -8
View File
@@ -7,14 +7,14 @@ import { formPositiveBigInt } from "@/lib/form-data";
export async function createEmailTemplate(formData: FormData): Promise<void> {
await requireStaff();
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const subject = String(formData.get("subject") ?? "")
const subject = String(formData.get("subject") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const body = String(formData.get("body") ?? "");
const variablesRaw = String(formData.get("variables") ?? "").trim();
const body = String(formData.get("body") ?? "").normalize("NFC");
const variablesRaw = String(formData.get("variables") ?? "").normalize("NFC").trim();
const isActive = formData.get("isActive") != null;
if (!name || !subject || !body) return;
@@ -32,7 +32,7 @@ export async function createEmailTemplate(formData: FormData): Promise<void> {
export async function updateEmailTemplate(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "");
const raw = String(formData.get("id") ?? "").normalize("NFC");
if (!raw) return;
let id: bigint;
try {
@@ -40,11 +40,11 @@ export async function updateEmailTemplate(formData: FormData): Promise<void> {
} catch {
return;
}
const subject = String(formData.get("subject") ?? "")
const subject = String(formData.get("subject") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const body = String(formData.get("body") ?? "");
const variablesRaw = String(formData.get("variables") ?? "").trim();
const body = String(formData.get("body") ?? "").normalize("NFC");
const variablesRaw = String(formData.get("variables") ?? "").normalize("NFC").trim();
const isActive = formData.get("isActive") != null;
if (!subject || !body) return;
+4 -4
View File
@@ -11,10 +11,10 @@ import { prisma } from "@/lib/prisma";
export async function updateEmulatorSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "")
const key = String(formData.get("key") ?? "").normalize("NFC")
.trim()
.slice(0, 100);
const value = String(formData.get("value") ?? "").slice(0, 512);
const value = String(formData.get("value") ?? "").normalize("NFC").slice(0, 512);
if (!key) return;
await prisma.emulatorSettings.upsert({
where: { key },
@@ -26,10 +26,10 @@ export async function updateEmulatorSetting(formData: FormData): Promise<void> {
export async function updateEmulatorText(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "")
const key = String(formData.get("key") ?? "").normalize("NFC")
.trim()
.slice(0, 100);
const value = String(formData.get("value") ?? "").slice(0, 4096);
const value = String(formData.get("value") ?? "").normalize("NFC").slice(0, 4096);
if (!key) return;
await prisma.emulatorTexts.upsert({
where: { key },
+14 -14
View File
@@ -17,27 +17,27 @@ function parsePosition(value: FormDataEntryValue | null): number {
export async function createHelpQuestion(formData: FormData): Promise<void> {
const staff = await requireStaff();
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const content = String(formData.get("content") ?? "").trim();
const content = String(formData.get("content") ?? "").normalize("NFC").trim();
if (!name || !content) return;
const imageUrl = String(formData.get("imageUrl") ?? "")
const imageUrl = String(formData.get("imageUrl") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonText = String(formData.get("buttonText") ?? "")
const buttonText = String(formData.get("buttonText") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonUrl = String(formData.get("buttonUrl") ?? "")
const buttonUrl = String(formData.get("buttonUrl") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonColor =
String(formData.get("buttonColor") ?? "")
String(formData.get("buttonColor") ?? "").normalize("NFC")
.trim()
.slice(0, 16) || "#eeb425";
const buttonBorderColor =
String(formData.get("buttonBorderColor") ?? "")
String(formData.get("buttonBorderColor") ?? "").normalize("NFC")
.trim()
.slice(0, 16) || "#facc15";
@@ -76,27 +76,27 @@ export async function updateHelpQuestion(formData: FormData): Promise<void> {
const id = formPositiveBigInt(formData, "id");
if (!id) return;
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const content = String(formData.get("content") ?? "").trim();
const content = String(formData.get("content") ?? "").normalize("NFC").trim();
if (!name || !content) return;
const imageUrl = String(formData.get("imageUrl") ?? "")
const imageUrl = String(formData.get("imageUrl") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonText = String(formData.get("buttonText") ?? "")
const buttonText = String(formData.get("buttonText") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonUrl = String(formData.get("buttonUrl") ?? "")
const buttonUrl = String(formData.get("buttonUrl") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const buttonColor =
String(formData.get("buttonColor") ?? "")
String(formData.get("buttonColor") ?? "").normalize("NFC")
.trim()
.slice(0, 16) || "#eeb425";
const buttonBorderColor =
String(formData.get("buttonBorderColor") ?? "")
String(formData.get("buttonBorderColor") ?? "").normalize("NFC")
.trim()
.slice(0, 16) || "#facc15";
+3 -3
View File
@@ -11,11 +11,11 @@ import { prisma } from "@/lib/prisma";
export async function upsertPermission(formData: FormData): Promise<void> {
await requireStaff();
const permission = String(formData.get("permission") ?? "")
const permission = String(formData.get("permission") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const minRank = Number(formData.get("minRank"));
const descriptionRaw = String(formData.get("description") ?? "")
const descriptionRaw = String(formData.get("description") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const description = descriptionRaw.length > 0 ? descriptionRaw : null;
@@ -38,7 +38,7 @@ export async function upsertPermission(formData: FormData): Promise<void> {
export async function deletePermission(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "");
const raw = String(formData.get("id") ?? "").normalize("NFC");
if (!raw) return;
try {
+4 -4
View File
@@ -5,13 +5,13 @@ import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
function parseIp(formData: FormData): string {
return String(formData.get("ipAddress") ?? "")
return String(formData.get("ipAddress") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
}
function parseAsn(formData: FormData): string | null {
const asn = String(formData.get("asn") ?? "")
const asn = String(formData.get("asn") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
return asn || null;
@@ -30,7 +30,7 @@ export async function addWhitelist(formData: FormData): Promise<void> {
export async function deleteWhitelist(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return;
await prisma.websiteIpWhitelist.delete({ where: { id: BigInt(raw) } });
revalidatePath("/admin/ip");
@@ -49,7 +49,7 @@ export async function addBlacklist(formData: FormData): Promise<void> {
export async function deleteBlacklist(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return;
await prisma.websiteIpBlacklist.delete({ where: { id: BigInt(raw) } });
revalidatePath("/admin/ip");
+2 -2
View File
@@ -39,11 +39,11 @@ export async function saveMaintenance(formData: FormData): Promise<void> {
// emulator/Laravel side expects.
const enabled = formData.get("enabled") != null ? "1" : "0";
const message = String(formData.get("message") ?? "");
const message = String(formData.get("message") ?? "").normalize("NFC");
// Coerce the rank to a non-negative integer; fall back to AtomCMS's default
// of 5 when the field is blank or garbage.
const rawRank = String(formData.get("min_rank") ?? "").trim();
const rawRank = String(formData.get("min_rank") ?? "").normalize("NFC").trim();
const parsedRank = Number.parseInt(rawRank, 10);
const minRank = Number.isFinite(parsedRank) && parsedRank >= 0 ? parsedRank : 5;
+6 -6
View File
@@ -14,17 +14,17 @@ import { logServerError } from "@/lib/server-log";
// created_at/updated_at are managed here.
function parseMinRank(formData: FormData): number {
const n = Number(String(formData.get("minRank") ?? "").trim());
const n = Number(String(formData.get("minRank") ?? "").normalize("NFC").trim());
return Number.isInteger(n) && n >= 0 ? n : 1;
}
export async function createPermission(formData: FormData): Promise<void> {
const staff = await requireStaff();
const permission = String(formData.get("permission") ?? "")
const permission = String(formData.get("permission") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const minRank = parseMinRank(formData);
const description = String(formData.get("description") ?? "").trim() || null;
const description = String(formData.get("description") ?? "").normalize("NFC").trim() || null;
if (!permission) return;
const now = new Date();
@@ -51,14 +51,14 @@ export async function createPermission(formData: FormData): Promise<void> {
export async function updatePermission(formData: FormData): Promise<void> {
const staff = await requireStaff();
const raw = String(formData.get("id") ?? "");
const raw = String(formData.get("id") ?? "").normalize("NFC");
if (!raw) return;
const id = BigInt(raw);
const permission = String(formData.get("permission") ?? "")
const permission = String(formData.get("permission") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const minRank = parseMinRank(formData);
const description = String(formData.get("description") ?? "").trim() || null;
const description = String(formData.get("description") ?? "").normalize("NFC").trim() || null;
if (!permission) return;
try {
+6 -6
View File
@@ -7,10 +7,10 @@ import { formPositiveBigInt } from "@/lib/form-data";
export async function createCategory(formData: FormData): Promise<void> {
await requireStaff();
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const badge = String(formData.get("badge") ?? "")
const badge = String(formData.get("badge") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const priorityRaw = Number(formData.get("priority"));
@@ -47,10 +47,10 @@ export async function createValue(formData: FormData): Promise<void> {
const categoryId = formPositiveBigInt(formData, "categoryId");
if (!categoryId) return;
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const furnitureIcon = String(formData.get("furnitureIcon") ?? "")
const furnitureIcon = String(formData.get("furnitureIcon") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!name || !furnitureIcon) return;
@@ -58,10 +58,10 @@ export async function createValue(formData: FormData): Promise<void> {
const itemIdRaw = Number(formData.get("itemId"));
const itemId = Number.isFinite(itemIdRaw) && itemIdRaw > 0 ? Math.floor(itemIdRaw) : null;
const creditValueRaw = String(formData.get("creditValue") ?? "")
const creditValueRaw = String(formData.get("creditValue") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const currencyValueRaw = String(formData.get("currencyValue") ?? "")
const currencyValueRaw = String(formData.get("currencyValue") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const currencyType =
+6 -6
View File
@@ -7,8 +7,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export async function updateSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "").trim();
const value = String(formData.get("value") ?? "");
const key = String(formData.get("key") ?? "").normalize("NFC").trim();
const value = String(formData.get("value") ?? "").normalize("NFC");
if (!key) return;
await prisma.websiteSetting.update({ where: { key }, data: { value } });
siteSettings.reload();
@@ -17,11 +17,11 @@ export async function updateSetting(formData: FormData): Promise<void> {
export async function createSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "")
const key = String(formData.get("key") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const value = String(formData.get("value") ?? "");
const comment = String(formData.get("comment") ?? "")
const value = String(formData.get("value") ?? "").normalize("NFC");
const comment = String(formData.get("comment") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!key) return;
@@ -36,7 +36,7 @@ export async function createSetting(formData: FormData): Promise<void> {
export async function deleteSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "").trim();
const key = String(formData.get("key") ?? "").normalize("NFC").trim();
if (!key) return;
await prisma.websiteSetting.delete({ where: { key } });
siteSettings.reload();
+11 -11
View File
@@ -14,7 +14,7 @@ import { logServerError } from "@/lib/server-log";
/** Parse an UnsignedInt form value, returning null when blank/invalid/negative. */
function optUInt(formData: FormData, key: string): number | null {
const raw = String(formData.get(key) ?? "").trim();
const raw = String(formData.get(key) ?? "").normalize("NFC").trim();
if (raw === "") return null;
const n = Number(raw);
if (!Number.isFinite(n) || n < 0) return null;
@@ -30,7 +30,7 @@ function reqUInt(formData: FormData, key: string): number {
export async function createShopArticle(formData: FormData): Promise<void> {
const staff = await requireStaff();
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!name) return;
@@ -40,13 +40,13 @@ export async function createShopArticle(formData: FormData): Promise<void> {
const created = await prisma.websiteShopArticles.create({
data: {
name,
info: String(formData.get("info") ?? "")
info: String(formData.get("info") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
iconUrl: String(formData.get("icon") ?? "")
iconUrl: String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
color: String(formData.get("color") ?? "")
color: String(formData.get("color") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
costs: reqUInt(formData, "costs"),
@@ -55,7 +55,7 @@ export async function createShopArticle(formData: FormData): Promise<void> {
duckets: optUInt(formData, "duckets"),
diamonds: optUInt(formData, "diamonds"),
badges:
String(formData.get("badges") ?? "")
String(formData.get("badges") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
position: reqUInt(formData, "position"),
@@ -85,7 +85,7 @@ export async function updateShopArticle(formData: FormData): Promise<void> {
const id = formPositiveBigInt(formData, "id");
if (!id) return;
const name = String(formData.get("name") ?? "")
const name = String(formData.get("name") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!name) return;
@@ -95,13 +95,13 @@ export async function updateShopArticle(formData: FormData): Promise<void> {
where: { id },
data: {
name,
info: String(formData.get("info") ?? "")
info: String(formData.get("info") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
iconUrl: String(formData.get("icon") ?? "")
iconUrl: String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
color: String(formData.get("color") ?? "")
color: String(formData.get("color") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
costs: reqUInt(formData, "costs"),
@@ -110,7 +110,7 @@ export async function updateShopArticle(formData: FormData): Promise<void> {
duckets: optUInt(formData, "duckets"),
diamonds: optUInt(formData, "diamonds"),
badges:
String(formData.get("badges") ?? "")
String(formData.get("badges") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
position: reqUInt(formData, "position"),
+4 -4
View File
@@ -7,12 +7,12 @@ import { prisma } from "@/lib/prisma";
export async function createTeam(formData: FormData): Promise<void> {
await requireStaff();
const rankName = String(formData.get("rankName") ?? "").trim();
const rankName = String(formData.get("rankName") ?? "").normalize("NFC").trim();
if (!rankName) return;
const badge = String(formData.get("badge") ?? "").trim();
const jobDescription = String(formData.get("jobDescription") ?? "").trim();
const staffColor = String(formData.get("staffColor") ?? "").trim() || "#327fa8";
const badge = String(formData.get("badge") ?? "").normalize("NFC").trim();
const jobDescription = String(formData.get("jobDescription") ?? "").normalize("NFC").trim();
const staffColor = String(formData.get("staffColor") ?? "").normalize("NFC").trim() || "#327fa8";
const hiddenRank = formData.get("hiddenRank") === "on";
const now = new Date();
+6 -6
View File
@@ -30,24 +30,24 @@ export async function saveTheme(formData: FormData): Promise<void> {
for (const mode of ["light", "dark"] as const) {
for (const key of THEME_COLOR_KEYS) {
const dbKey = settingKey(key, mode);
const raw = String(formData.get(dbKey) ?? "").trim();
const raw = String(formData.get(dbKey) ?? "").normalize("NFC").trim();
if (raw && COLOR_RE.test(raw)) await writeSetting(dbKey, raw);
}
}
const radius = String(formData.get("border_radius") ?? "").trim();
const radius = String(formData.get("border_radius") ?? "").normalize("NFC").trim();
if (/^\d{1,3}$/.test(radius)) await writeSetting("border_radius", radius);
// Typography
const font = String(formData.get("font_family") ?? "").trim();
const font = String(formData.get("font_family") ?? "").normalize("NFC").trim();
if (font in FONTS) await writeSetting("font_family", font);
for (const key of HEADING_KEYS) {
const v = String(formData.get(key) ?? "").trim();
const v = String(formData.get(key) ?? "").normalize("NFC").trim();
if (/^\d{1,3}$/.test(v)) await writeSetting(key, v);
}
// Raw custom CSS (staff-trusted; length-capped, ThemeVars injects it as-is).
if (formData.has("custom_css")) {
const cssRaw = String(formData.get("custom_css") ?? "").slice(0, CUSTOM_CSS_MAX);
const cssRaw = String(formData.get("custom_css") ?? "").normalize("NFC").slice(0, CUSTOM_CSS_MAX);
await writeSetting("custom_css", cssRaw);
}
@@ -66,7 +66,7 @@ export async function saveTheme(formData: FormData): Promise<void> {
export async function applyPreset(formData: FormData): Promise<void> {
const staff = await requireStaff();
const name = String(formData.get("preset") ?? "");
const name = String(formData.get("preset") ?? "").normalize("NFC");
// eslint-disable-next-line security/detect-object-injection -- guarded by null check below
const preset = PRESETS[name];
if (!preset) redirect("/admin/theme");
+3 -3
View File
@@ -41,9 +41,9 @@ export async function updateUser(formData: FormData): Promise<void> {
if (!existing) return;
// users row — only existing, safe columns.
const mailRaw = String(formData.get("mail") ?? "").trim();
const motto = String(formData.get("motto") ?? "").slice(0, 127);
const look = String(formData.get("look") ?? "").slice(0, 256);
const mailRaw = String(formData.get("mail") ?? "").normalize("NFC").trim();
const motto = String(formData.get("motto") ?? "").normalize("NFC").slice(0, 127);
const look = String(formData.get("look") ?? "").normalize("NFC").slice(0, 256);
const rank = toInt(formData.get("rank"), 1);
const credits = toInt(formData.get("credits"), 0);
const pixels = toInt(formData.get("pixels"), 0);
+3 -3
View File
@@ -30,7 +30,7 @@ export async function giveCurrency(formData: FormData): Promise<void> {
export async function setMotto(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const motto = String(formData.get("motto") ?? "").slice(0, 127);
const motto = String(formData.get("motto") ?? "").normalize("NFC").slice(0, 127);
if (userId > 0) {
await prisma.user.update({ where: { id: userId }, data: { motto } });
await rcon.setMotto(userId, motto);
@@ -59,13 +59,13 @@ export async function setRank(formData: FormData): Promise<void> {
export async function alertUser(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const message = String(formData.get("message") ?? "").trim();
const message = String(formData.get("message") ?? "").normalize("NFC").trim();
if (userId > 0 && message) await rcon.alertUser(userId, message);
}
export async function disconnectUser(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const username = String(formData.get("username") ?? "");
const username = String(formData.get("username") ?? "").normalize("NFC");
if (userId > 0) await rcon.disconnectUser(userId, username);
}
+2 -2
View File
@@ -9,7 +9,7 @@ import { logServerError } from "@/lib/server-log";
export async function createVoucher(formData: FormData): Promise<void> {
await requireStaff();
const code = String(formData.get("code") ?? "")
const code = String(formData.get("code") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const amount = Number(formData.get("amount"));
@@ -18,7 +18,7 @@ export async function createVoucher(formData: FormData): Promise<void> {
if (!code || !(amount > 0)) return;
const expiresRaw = String(formData.get("expiresAt") ?? "").trim();
const expiresRaw = String(formData.get("expiresAt") ?? "").normalize("NFC").trim();
let expiresAt: Date | null = null;
if (expiresRaw) {
const parsed = new Date(expiresRaw);
+4 -4
View File
@@ -27,17 +27,17 @@ export async function saveVpn(formData: FormData): Promise<void> {
const staff = await requireStaff();
// Toggle: an unchecked checkbox submits nothing, so absence === disabled.
const enabled = String(formData.get("vpn_block_enabled") ?? "").trim() !== "";
const enabled = String(formData.get("vpn_block_enabled") ?? "").normalize("NFC").trim() !== "";
const providerRaw = String(formData.get("vpn_provider") ?? "")
const providerRaw = String(formData.get("vpn_provider") ?? "").normalize("NFC")
.trim()
.toLowerCase();
const provider = ALLOWED_PROVIDERS.has(providerRaw) ? providerRaw : "none";
const apiKey = String(formData.get("vpn_api_key") ?? "")
const apiKey = String(formData.get("vpn_api_key") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const blockMessage = String(formData.get("vpn_block_message") ?? "")
const blockMessage = String(formData.get("vpn_block_message") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
+2 -2
View File
@@ -7,7 +7,7 @@ import { rcon } from "@/lib/services/rcon";
export async function addWord(formData: FormData): Promise<void> {
await requireStaff();
const word = String(formData.get("word") ?? "")
const word = String(formData.get("word") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!word) return;
@@ -23,7 +23,7 @@ export async function addWord(formData: FormData): Promise<void> {
export async function deleteWord(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "");
const raw = String(formData.get("id") ?? "").normalize("NFC");
if (!raw) return;
try {
+11 -11
View File
@@ -11,7 +11,7 @@ import { logStaffActivity } from "@/lib/services/staff-activity";
/** Parse a non-negative Int form value, falling back to 0. */
function reqInt(formData: FormData, key: string): number {
const raw = String(formData.get(key) ?? "").trim();
const raw = String(formData.get(key) ?? "").normalize("NFC").trim();
if (raw === "") return 0;
const n = Number(raw);
if (!Number.isFinite(n) || n < 0) return 0;
@@ -20,7 +20,7 @@ function reqInt(formData: FormData, key: string): number {
/** Parse the BigInt `id` form value, returning null when blank/invalid. */
function parseId(formData: FormData): bigint | null {
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return null;
try {
return BigInt(raw);
@@ -38,7 +38,7 @@ function revalidate(): void {
export async function createBox(formData: FormData): Promise<void> {
const staff = await requireStaff();
const title = String(formData.get("title") ?? "")
const title = String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!title) return;
@@ -49,12 +49,12 @@ export async function createBox(formData: FormData): Promise<void> {
data: {
title,
icon:
String(formData.get("icon") ?? "")
String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
content: String(formData.get("content") ?? ""),
content: String(formData.get("content") ?? "").normalize("NFC"),
position: reqInt(formData, "position"),
isActive: String(formData.get("isActive") ?? "") === "1",
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
createdAt: now,
updatedAt: now,
},
@@ -80,7 +80,7 @@ export async function updateBox(formData: FormData): Promise<void> {
const id = parseId(formData);
if (id == null) return;
const title = String(formData.get("title") ?? "")
const title = String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!title) return;
@@ -91,12 +91,12 @@ export async function updateBox(formData: FormData): Promise<void> {
data: {
title,
icon:
String(formData.get("icon") ?? "")
String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
content: String(formData.get("content") ?? ""),
content: String(formData.get("content") ?? "").normalize("NFC"),
position: reqInt(formData, "position"),
isActive: String(formData.get("isActive") ?? "") === "1",
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
updatedAt: new Date(),
},
});
@@ -143,7 +143,7 @@ export async function toggleBox(formData: FormData): Promise<void> {
if (id == null) return;
// `next` carries the desired state ("1" to activate, anything else to hide).
const next = String(formData.get("next") ?? "") === "1";
const next = String(formData.get("next") ?? "").normalize("NFC") === "1";
try {
await prisma.websiteWriteableBoxes.update({
+2 -2
View File
@@ -28,7 +28,7 @@ export async function applyStaff(formData: FormData): Promise<void> {
const rankId = Number(formData.get("rankId"));
if (!Number.isInteger(rankId) || rankId <= 0) return;
const content = String(formData.get("content") ?? "")
const content = String(formData.get("content") ?? "").normalize("NFC")
.trim()
.slice(0, CONTENT_MAX);
if (content.length < CONTENT_MIN) return;
@@ -72,7 +72,7 @@ export async function applyTeam(formData: FormData): Promise<void> {
const rankId = Number(formData.get("teamId"));
if (!Number.isInteger(rankId) || rankId <= 0) return;
const content = String(formData.get("content") ?? "")
const content = String(formData.get("content") ?? "").normalize("NFC")
.trim()
.slice(0, CONTENT_MAX);
if (content.length < CONTENT_MIN) return;
+2 -2
View File
@@ -21,7 +21,7 @@ export async function postComment(formData: FormData): Promise<void> {
const userId = Number(session.user.id);
if (!Number.isFinite(userId)) return;
const comment = String(formData.get("comment") ?? "")
const comment = String(formData.get("comment") ?? "").normalize("NFC")
.trim()
.slice(0, COMMENT_MAX);
if (!comment) return;
@@ -29,7 +29,7 @@ export async function postComment(formData: FormData): Promise<void> {
// Block filtered/AI-flagged content before it touches the DB (fail-open).
if (!(await isAllowed(comment)).ok) return;
const articleIdRaw = String(formData.get("articleId") ?? "").trim();
const articleIdRaw = String(formData.get("articleId") ?? "").normalize("NFC").trim();
if (!/^\d+$/.test(articleIdRaw)) return;
let articleId: bigint;
+2 -2
View File
@@ -31,12 +31,12 @@ export async function toggleReaction(formData: FormData): Promise<void> {
const userId = Number(session.user.id);
if (!Number.isFinite(userId)) return;
const reaction = String(formData.get("reaction") ?? "")
const reaction = String(formData.get("reaction") ?? "").normalize("NFC")
.trim()
.toLowerCase();
if (!ALLOWED_REACTIONS.has(reaction)) return;
const articleIdRaw = String(formData.get("articleId") ?? "").trim();
const articleIdRaw = String(formData.get("articleId") ?? "").normalize("NFC").trim();
if (!/^\d+$/.test(articleIdRaw)) return;
let articleId: bigint;
+1 -1
View File
@@ -12,7 +12,7 @@ export type PrecheckResult = "ok" | "invalid" | "twofactor";
* TOTP code is still required. Lets the login form do the two-step 2FA flow.
*/
export async function precheckLogin(username: string, password: string): Promise<PrecheckResult> {
const u = String(username ?? "").trim();
const u = String(username ?? "").normalize("NFC").trim();
const p = String(password ?? "");
if (!u || !p) return "invalid";
+6 -6
View File
@@ -42,7 +42,7 @@ export async function updateNavigator(): Promise<void> {
/** Broadcast a hotel-wide alert to every connected user (rcon: hotelalert). */
export async function hotelAlert(formData: FormData): Promise<void> {
await requireStaff();
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, 512);
if (!message) return;
@@ -58,7 +58,7 @@ export async function hotelAlert(formData: FormData): Promise<void> {
export async function disconnectUser(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const username = String(formData.get("username") ?? "").trim();
const username = String(formData.get("username") ?? "").normalize("NFC").trim();
if (!userId || !username) return;
try {
await rcon.disconnectUser(userId, username);
@@ -72,7 +72,7 @@ export async function disconnectUser(formData: FormData): Promise<void> {
export async function alertUser(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, 512);
if (!userId || !message) return;
@@ -144,7 +144,7 @@ export async function giveDiamonds(formData: FormData): Promise<void> {
export async function giveBadge(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const badge = String(formData.get("badge") ?? "").trim();
const badge = String(formData.get("badge") ?? "").normalize("NFC").trim();
if (!userId || !badge) return;
try {
await rcon.giveBadge(userId, badge);
@@ -158,7 +158,7 @@ export async function giveBadge(formData: FormData): Promise<void> {
export async function setMotto(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const motto = String(formData.get("motto") ?? "")
const motto = String(formData.get("motto") ?? "").normalize("NFC")
.trim()
.slice(0, 127);
if (!userId || !motto) return;
@@ -188,7 +188,7 @@ export async function setRank(formData: FormData): Promise<void> {
export async function executeCommand(formData: FormData): Promise<void> {
await requireStaff();
const userId = Number(formData.get("userId"));
const command = String(formData.get("command") ?? "").trim();
const command = String(formData.get("command") ?? "").normalize("NFC").trim();
if (!userId || !command) return;
try {
await rcon.executeCommand(userId, command);
+1 -1
View File
@@ -50,7 +50,7 @@ export async function buyBadge(formData: FormData): Promise<void> {
// The form posts the badge row id; everything else (price, code) is resolved
// server-side from trusted data — never from the client.
const rawId = String(formData.get("id") ?? "").trim();
const rawId = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!/^\d+$/.test(rawId)) redirect("/draw-badge?error=invalid");
let outcome: "bought" | "invalid" | "credits" | "fail";
+2 -2
View File
@@ -25,7 +25,7 @@ export async function postGuestbook(formData: FormData): Promise<void> {
const profileId = Number(formData.get("profileId"));
if (!Number.isInteger(profileId) || profileId <= 0) return;
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, MESSAGE_MAX);
if (!message) return;
@@ -34,7 +34,7 @@ export async function postGuestbook(formData: FormData): Promise<void> {
if (!(await isAllowed(message)).ok) return;
// Optional: used only to revalidate the correct profile route.
const username = String(formData.get("username") ?? "").trim();
const username = String(formData.get("username") ?? "").normalize("NFC").trim();
const now = new Date();
try {
+2 -2
View File
@@ -22,10 +22,10 @@ export async function createTicket(formData: FormData): Promise<void> {
if (!(await rateLimit(`ticket:${userId}`, 3, 60_000)).ok) return;
const raw = {
title: String(formData.get("title") ?? "")
title: String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
content: String(formData.get("content") ?? "")
content: String(formData.get("content") ?? "").normalize("NFC")
.trim()
.slice(0, 5000),
};
+4 -4
View File
@@ -15,7 +15,7 @@ function sha256(s: string): string {
}
export async function requestReset(formData: FormData): Promise<void> {
const email = String(formData.get("email") ?? "")
const email = String(formData.get("email") ?? "").normalize("NFC")
.trim()
.toLowerCase();
@@ -49,11 +49,11 @@ export async function requestReset(formData: FormData): Promise<void> {
}
export async function resetPassword(formData: FormData): Promise<void> {
const email = String(formData.get("email") ?? "")
const email = String(formData.get("email") ?? "").normalize("NFC")
.trim()
.toLowerCase();
const token = String(formData.get("token") ?? "").trim();
const password = String(formData.get("password") ?? "");
const token = String(formData.get("token") ?? "").normalize("NFC").trim();
const password = String(formData.get("password") ?? "").normalize("NFC");
// Throttle reset attempts per IP (5 per 15 min) to prevent token brute-force.
if (!(await rateLimit(`resetpwd:${await clientIp()}`, 5, 15 * 60_000)).ok) {
+1 -1
View File
@@ -11,7 +11,7 @@ const TEXT_MAX = 5000;
const STYLE_MAX = 5000;
function str(form: FormData, key: string, max: number): string {
return String(form.get(key) ?? "")
return String(form.get(key) ?? "").normalize("NFC")
.trim()
.slice(0, max);
}
+2 -2
View File
@@ -12,10 +12,10 @@ export async function submitRequest(formData: FormData): Promise<void> {
const userId = Number(session?.user?.id);
if (!Number.isInteger(userId) || userId <= 0) return;
const songTitle = String(formData.get("songTitle") ?? "")
const songTitle = String(formData.get("songTitle") ?? "").normalize("NFC")
.trim()
.slice(0, SONG_MAX);
const artist = String(formData.get("artist") ?? "")
const artist = String(formData.get("artist") ?? "").normalize("NFC")
.trim()
.slice(0, ARTIST_MAX);
if (!songTitle && !artist) return;
+1 -1
View File
@@ -28,7 +28,7 @@ export async function postShout(formData: FormData): Promise<void> {
if (!(await rateLimit(`shout:${userId}`, 5, 30_000)).ok) return;
const raw = {
message: String(formData.get("message") ?? "")
message: String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, 255),
};
+5 -5
View File
@@ -31,12 +31,12 @@ const DEFAULT_LOOK = "hr-100-.hd-180-1.ch-255-66.lg-280-110.sh-305-62";
export async function register(prevState: string | null, formData: FormData): Promise<string | null> {
const raw = {
username: String(formData.get("username") ?? "").trim(),
mail: String(formData.get("mail") ?? "")
username: String(formData.get("username") ?? "").normalize("NFC").trim(),
mail: String(formData.get("mail") ?? "").normalize("NFC")
.trim()
.toLowerCase(),
password: String(formData.get("password") ?? ""),
look: String(formData.get("look") ?? "").trim() || DEFAULT_LOOK,
password: String(formData.get("password") ?? "").normalize("NFC"),
look: String(formData.get("look") ?? "").normalize("NFC").trim() || DEFAULT_LOOK,
};
const parsed = registerSchema.safeParse(raw);
@@ -56,7 +56,7 @@ export async function register(prevState: string | null, formData: FormData): Pr
// CAPTCHA (Turnstile / reCAPTCHA) — only enforced when configured in settings.
const cfg = await captchaConfig();
if (cfg.provider !== "none") {
const token = String(formData.get(cfg.field) ?? "");
const token = String(formData.get(cfg.field) ?? "").normalize("NFC");
if (!(await verifyCaptcha(token, ip))) return "Captcha verification failed. Please try again.";
}
+3 -3
View File
@@ -61,7 +61,7 @@ export async function sendFriendRequest(formData: FormData): Promise<void> {
// Optional: revalidate the target profile if a username was supplied, purely
// to refresh any request-state UI rendered there.
const username = String(formData.get("username") ?? "").trim();
const username = String(formData.get("username") ?? "").normalize("NFC").trim();
if (username) revalidatePath(`/u/${username}`);
}
@@ -85,10 +85,10 @@ export async function postThread(formData: FormData): Promise<void> {
const guildId = Number(formData.get("guildId"));
if (!Number.isInteger(guildId) || guildId <= 0) return;
const subject = String(formData.get("subject") ?? "")
const subject = String(formData.get("subject") ?? "").normalize("NFC")
.trim()
.slice(0, SUBJECT_MAX);
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, MESSAGE_MAX);
if (!subject || !message) return;
+2 -2
View File
@@ -92,7 +92,7 @@ export async function confirmTwoFactor(formData: FormData): Promise<void> {
if (!(await rateLimit(`2fa-confirm:${id}`, 5, 30_000)).ok) redirect("/settings/2fa?error=ratelimit");
const code = String(formData.get("code") ?? "").trim();
const code = String(formData.get("code") ?? "").normalize("NFC").trim();
const { ok } = await verifyTwoFactorCode(id, code);
if (!ok) redirect("/settings/2fa?error=badcode");
@@ -107,7 +107,7 @@ export async function disableTwoFactor(formData: FormData): Promise<void> {
if (!(await rateLimit(`2fa-disable:${id}`, 5, 30_000)).ok) redirect("/settings/2fa?error=ratelimit");
const code = String(formData.get("code") ?? "").trim();
const code = String(formData.get("code") ?? "").normalize("NFC").trim();
const { ok } = await verifyTwoFactorCode(id, code);
if (!ok) redirect("/settings/2fa?error=badcode");
+1 -1
View File
@@ -34,7 +34,7 @@ const updateMottoAction = authAction(
);
export async function updateMotto(formData: FormData): Promise<void> {
const motto = String(formData.get("motto") ?? "").slice(0, MOTTO_MAX);
const motto = String(formData.get("motto") ?? "").normalize("NFC").slice(0, MOTTO_MAX);
await updateMottoAction({ motto });
}
+1 -1
View File
@@ -34,7 +34,7 @@ export async function redeem(_prev: RedeemState, formData: FormData): Promise<Re
return { ok: false, message: "Your session is invalid. Please sign in again." };
}
const code = String(formData.get("code") ?? "").trim();
const code = String(formData.get("code") ?? "").normalize("NFC").trim();
if (!code) {
return { ok: false, message: "Please enter a voucher code." };
}