Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+6 -6
View File
@@ -7,8 +7,8 @@ import { siteSettings } from "@/lib/services/site-settings";
export async function updateSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "").trim();
const value = String(formData.get("value") ?? "");
const key = String(formData.get("key") ?? "").normalize("NFC").trim();
const value = String(formData.get("value") ?? "").normalize("NFC");
if (!key) return;
await prisma.websiteSetting.update({ where: { key }, data: { value } });
siteSettings.reload();
@@ -17,11 +17,11 @@ export async function updateSetting(formData: FormData): Promise<void> {
export async function createSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "")
const key = String(formData.get("key") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
const value = String(formData.get("value") ?? "");
const comment = String(formData.get("comment") ?? "")
const value = String(formData.get("value") ?? "").normalize("NFC");
const comment = String(formData.get("comment") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!key) return;
@@ -36,7 +36,7 @@ export async function createSetting(formData: FormData): Promise<void> {
export async function deleteSetting(formData: FormData): Promise<void> {
await requireStaff();
const key = String(formData.get("key") ?? "").trim();
const key = String(formData.get("key") ?? "").normalize("NFC").trim();
if (!key) return;
await prisma.websiteSetting.delete({ where: { key } });
siteSettings.reload();