Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
@@ -39,11 +39,11 @@ export async function saveMaintenance(formData: FormData): Promise<void> {
|
||||
// emulator/Laravel side expects.
|
||||
const enabled = formData.get("enabled") != null ? "1" : "0";
|
||||
|
||||
const message = String(formData.get("message") ?? "");
|
||||
const message = String(formData.get("message") ?? "").normalize("NFC");
|
||||
|
||||
// Coerce the rank to a non-negative integer; fall back to AtomCMS's default
|
||||
// of 5 when the field is blank or garbage.
|
||||
const rawRank = String(formData.get("min_rank") ?? "").trim();
|
||||
const rawRank = String(formData.get("min_rank") ?? "").normalize("NFC").trim();
|
||||
const parsedRank = Number.parseInt(rawRank, 10);
|
||||
const minRank = Number.isFinite(parsedRank) && parsedRank >= 0 ? parsedRank : 5;
|
||||
|
||||
|
||||
Reference in new issue
Block a user