Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+4 -4
View File
@@ -5,13 +5,13 @@ import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
function parseIp(formData: FormData): string {
return String(formData.get("ipAddress") ?? "")
return String(formData.get("ipAddress") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
}
function parseAsn(formData: FormData): string | null {
const asn = String(formData.get("asn") ?? "")
const asn = String(formData.get("asn") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
return asn || null;
@@ -30,7 +30,7 @@ export async function addWhitelist(formData: FormData): Promise<void> {
export async function deleteWhitelist(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return;
await prisma.websiteIpWhitelist.delete({ where: { id: BigInt(raw) } });
revalidatePath("/admin/ip");
@@ -49,7 +49,7 @@ export async function addBlacklist(formData: FormData): Promise<void> {
export async function deleteBlacklist(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return;
await prisma.websiteIpBlacklist.delete({ where: { id: BigInt(raw) } });
revalidatePath("/admin/ip");