Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+11 -11
View File
@@ -11,7 +11,7 @@ import { logStaffActivity } from "@/lib/services/staff-activity";
/** Parse a non-negative Int form value, falling back to 0. */
function reqInt(formData: FormData, key: string): number {
const raw = String(formData.get(key) ?? "").trim();
const raw = String(formData.get(key) ?? "").normalize("NFC").trim();
if (raw === "") return 0;
const n = Number(raw);
if (!Number.isFinite(n) || n < 0) return 0;
@@ -20,7 +20,7 @@ function reqInt(formData: FormData, key: string): number {
/** Parse the BigInt `id` form value, returning null when blank/invalid. */
function parseId(formData: FormData): bigint | null {
const raw = String(formData.get("id") ?? "").trim();
const raw = String(formData.get("id") ?? "").normalize("NFC").trim();
if (!raw) return null;
try {
return BigInt(raw);
@@ -38,7 +38,7 @@ function revalidate(): void {
export async function createBox(formData: FormData): Promise<void> {
const staff = await requireStaff();
const title = String(formData.get("title") ?? "")
const title = String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!title) return;
@@ -49,12 +49,12 @@ export async function createBox(formData: FormData): Promise<void> {
data: {
title,
icon:
String(formData.get("icon") ?? "")
String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
content: String(formData.get("content") ?? ""),
content: String(formData.get("content") ?? "").normalize("NFC"),
position: reqInt(formData, "position"),
isActive: String(formData.get("isActive") ?? "") === "1",
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
createdAt: now,
updatedAt: now,
},
@@ -80,7 +80,7 @@ export async function updateBox(formData: FormData): Promise<void> {
const id = parseId(formData);
if (id == null) return;
const title = String(formData.get("title") ?? "")
const title = String(formData.get("title") ?? "").normalize("NFC")
.trim()
.slice(0, 255);
if (!title) return;
@@ -91,12 +91,12 @@ export async function updateBox(formData: FormData): Promise<void> {
data: {
title,
icon:
String(formData.get("icon") ?? "")
String(formData.get("icon") ?? "").normalize("NFC")
.trim()
.slice(0, 255) || null,
content: String(formData.get("content") ?? ""),
content: String(formData.get("content") ?? "").normalize("NFC"),
position: reqInt(formData, "position"),
isActive: String(formData.get("isActive") ?? "") === "1",
isActive: String(formData.get("isActive") ?? "").normalize("NFC") === "1",
updatedAt: new Date(),
},
});
@@ -143,7 +143,7 @@ export async function toggleBox(formData: FormData): Promise<void> {
if (id == null) return;
// `next` carries the desired state ("1" to activate, anything else to hide).
const next = String(formData.get("next") ?? "") === "1";
const next = String(formData.get("next") ?? "").normalize("NFC") === "1";
try {
await prisma.websiteWriteableBoxes.update({