Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
@@ -7,14 +7,14 @@ import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
export async function createEmailTemplate(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const name = String(formData.get("name") ?? "")
|
||||
const name = String(formData.get("name") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const subject = String(formData.get("subject") ?? "")
|
||||
const subject = String(formData.get("subject") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const body = String(formData.get("body") ?? "");
|
||||
const variablesRaw = String(formData.get("variables") ?? "").trim();
|
||||
const body = String(formData.get("body") ?? "").normalize("NFC");
|
||||
const variablesRaw = String(formData.get("variables") ?? "").normalize("NFC").trim();
|
||||
const isActive = formData.get("isActive") != null;
|
||||
if (!name || !subject || !body) return;
|
||||
|
||||
@@ -32,7 +32,7 @@ export async function createEmailTemplate(formData: FormData): Promise<void> {
|
||||
|
||||
export async function updateEmailTemplate(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
const raw = String(formData.get("id") ?? "").normalize("NFC");
|
||||
if (!raw) return;
|
||||
let id: bigint;
|
||||
try {
|
||||
@@ -40,11 +40,11 @@ export async function updateEmailTemplate(formData: FormData): Promise<void> {
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const subject = String(formData.get("subject") ?? "")
|
||||
const subject = String(formData.get("subject") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const body = String(formData.get("body") ?? "");
|
||||
const variablesRaw = String(formData.get("variables") ?? "").trim();
|
||||
const body = String(formData.get("body") ?? "").normalize("NFC");
|
||||
const variablesRaw = String(formData.get("variables") ?? "").normalize("NFC").trim();
|
||||
const isActive = formData.get("isActive") != null;
|
||||
if (!subject || !body) return;
|
||||
|
||||
|
||||
Reference in new issue
Block a user