Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
@@ -11,7 +11,7 @@ import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
|
||||
/** Parse a non-negative Int form value, falling back to 0. */
|
||||
function reqInt(formData: FormData, key: string): number {
|
||||
const raw = String(formData.get(key) ?? "").trim();
|
||||
const raw = String(formData.get(key) ?? "").normalize("NFC").trim();
|
||||
if (raw === "") return 0;
|
||||
const n = Number(raw);
|
||||
if (!Number.isFinite(n) || n < 0) return 0;
|
||||
@@ -20,7 +20,7 @@ function reqInt(formData: FormData, key: string): number {
|
||||
|
||||
/** Parse the BigInt `id` form value, returning null when blank/invalid. */
|
||||
function parseId(formData: FormData): bigint | null {
|
||||
const raw = String(formData.get("id") ?? "").trim();
|
||||
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
|
||||
if (!raw) return null;
|
||||
try {
|
||||
return BigInt(raw);
|
||||
@@ -38,7 +38,7 @@ function revalidate(): void {
|
||||
export async function createBox(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
|
||||
const title = String(formData.get("title") ?? "")
|
||||
const title = String(formData.get("title") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
if (!title) return;
|
||||
@@ -49,12 +49,12 @@ export async function createBox(formData: FormData): Promise<void> {
|
||||
data: {
|
||||
title,
|
||||
icon:
|
||||
String(formData.get("icon") ?? "")
|
||||
String(formData.get("icon") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255) || null,
|
||||
content: String(formData.get("content") ?? ""),
|
||||
content: String(formData.get("content") ?? "").normalize("NFC"),
|
||||
position: reqInt(formData, "position"),
|
||||
isActive: String(formData.get("isActive") ?? "") === "1",
|
||||
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
|
||||
createdAt: now,
|
||||
updatedAt: now,
|
||||
},
|
||||
@@ -80,7 +80,7 @@ export async function updateBox(formData: FormData): Promise<void> {
|
||||
const id = parseId(formData);
|
||||
if (id == null) return;
|
||||
|
||||
const title = String(formData.get("title") ?? "")
|
||||
const title = String(formData.get("title") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255);
|
||||
if (!title) return;
|
||||
@@ -91,12 +91,12 @@ export async function updateBox(formData: FormData): Promise<void> {
|
||||
data: {
|
||||
title,
|
||||
icon:
|
||||
String(formData.get("icon") ?? "")
|
||||
String(formData.get("icon") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 255) || null,
|
||||
content: String(formData.get("content") ?? ""),
|
||||
content: String(formData.get("content") ?? "").normalize("NFC"),
|
||||
position: reqInt(formData, "position"),
|
||||
isActive: String(formData.get("isActive") ?? "") === "1",
|
||||
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
|
||||
updatedAt: new Date(),
|
||||
},
|
||||
});
|
||||
@@ -143,7 +143,7 @@ export async function toggleBox(formData: FormData): Promise<void> {
|
||||
if (id == null) return;
|
||||
|
||||
// `next` carries the desired state ("1" to activate, anything else to hide).
|
||||
const next = String(formData.get("next") ?? "") === "1";
|
||||
const next = String(formData.get("next") ?? "").normalize("NFC") === "1";
|
||||
|
||||
try {
|
||||
await prisma.websiteWriteableBoxes.update({
|
||||
|
||||
Reference in new issue
Block a user