Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
@@ -7,12 +7,12 @@ import { prisma } from "@/lib/prisma";
|
||||
export async function createTeam(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
|
||||
const rankName = String(formData.get("rankName") ?? "").trim();
|
||||
const rankName = String(formData.get("rankName") ?? "").normalize("NFC").trim();
|
||||
if (!rankName) return;
|
||||
|
||||
const badge = String(formData.get("badge") ?? "").trim();
|
||||
const jobDescription = String(formData.get("jobDescription") ?? "").trim();
|
||||
const staffColor = String(formData.get("staffColor") ?? "").trim() || "#327fa8";
|
||||
const badge = String(formData.get("badge") ?? "").normalize("NFC").trim();
|
||||
const jobDescription = String(formData.get("jobDescription") ?? "").normalize("NFC").trim();
|
||||
const staffColor = String(formData.get("staffColor") ?? "").normalize("NFC").trim() || "#327fa8";
|
||||
const hiddenRank = formData.get("hiddenRank") === "on";
|
||||
|
||||
const now = new Date();
|
||||
|
||||
Reference in new issue
Block a user