Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
+14
-14
@@ -17,27 +17,27 @@ function parsePosition(value: FormDataEntryValue | null): number {
|
||||
|
||||
export async function createHelpQuestion(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
const name = String(formData.get("name") ?? "")
|
||||
const name = String(formData.get("name") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const content = String(formData.get("content") ?? "").trim();
|
||||
const content = String(formData.get("content") ?? "").normalize("NFC").trim();
|
||||
if (!name || !content) return;
|
||||
|
||||
const imageUrl = String(formData.get("imageUrl") ?? "")
|
||||
const imageUrl = String(formData.get("imageUrl") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonText = String(formData.get("buttonText") ?? "")
|
||||
const buttonText = String(formData.get("buttonText") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonUrl = String(formData.get("buttonUrl") ?? "")
|
||||
const buttonUrl = String(formData.get("buttonUrl") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonColor =
|
||||
String(formData.get("buttonColor") ?? "")
|
||||
String(formData.get("buttonColor") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 16) || "#eeb425";
|
||||
const buttonBorderColor =
|
||||
String(formData.get("buttonBorderColor") ?? "")
|
||||
String(formData.get("buttonBorderColor") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 16) || "#facc15";
|
||||
|
||||
@@ -76,27 +76,27 @@ export async function updateHelpQuestion(formData: FormData): Promise<void> {
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
const name = String(formData.get("name") ?? "")
|
||||
const name = String(formData.get("name") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const content = String(formData.get("content") ?? "").trim();
|
||||
const content = String(formData.get("content") ?? "").normalize("NFC").trim();
|
||||
if (!name || !content) return;
|
||||
|
||||
const imageUrl = String(formData.get("imageUrl") ?? "")
|
||||
const imageUrl = String(formData.get("imageUrl") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonText = String(formData.get("buttonText") ?? "")
|
||||
const buttonText = String(formData.get("buttonText") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonUrl = String(formData.get("buttonUrl") ?? "")
|
||||
const buttonUrl = String(formData.get("buttonUrl") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
const buttonColor =
|
||||
String(formData.get("buttonColor") ?? "")
|
||||
String(formData.get("buttonColor") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 16) || "#eeb425";
|
||||
const buttonBorderColor =
|
||||
String(formData.get("buttonBorderColor") ?? "")
|
||||
String(formData.get("buttonBorderColor") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 16) || "#facc15";
|
||||
|
||||
|
||||
Reference in new issue
Block a user