Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s
Local Build and Deploy / deploy (push) Successful in 59s
All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
1 parent
e2fc7ea1a4
commit
e5ae51bff7
41 files changed
+152
-152
No files matched your search
@@ -42,7 +42,7 @@ export async function updateNavigator(): Promise<void> {
|
||||
/** Broadcast a hotel-wide alert to every connected user (rcon: hotelalert). */
|
||||
export async function hotelAlert(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const message = String(formData.get("message") ?? "")
|
||||
const message = String(formData.get("message") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 512);
|
||||
if (!message) return;
|
||||
@@ -58,7 +58,7 @@ export async function hotelAlert(formData: FormData): Promise<void> {
|
||||
export async function disconnectUser(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const username = String(formData.get("username") ?? "").trim();
|
||||
const username = String(formData.get("username") ?? "").normalize("NFC").trim();
|
||||
if (!userId || !username) return;
|
||||
try {
|
||||
await rcon.disconnectUser(userId, username);
|
||||
@@ -72,7 +72,7 @@ export async function disconnectUser(formData: FormData): Promise<void> {
|
||||
export async function alertUser(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const message = String(formData.get("message") ?? "")
|
||||
const message = String(formData.get("message") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 512);
|
||||
if (!userId || !message) return;
|
||||
@@ -144,7 +144,7 @@ export async function giveDiamonds(formData: FormData): Promise<void> {
|
||||
export async function giveBadge(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const badge = String(formData.get("badge") ?? "").trim();
|
||||
const badge = String(formData.get("badge") ?? "").normalize("NFC").trim();
|
||||
if (!userId || !badge) return;
|
||||
try {
|
||||
await rcon.giveBadge(userId, badge);
|
||||
@@ -158,7 +158,7 @@ export async function giveBadge(formData: FormData): Promise<void> {
|
||||
export async function setMotto(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const motto = String(formData.get("motto") ?? "")
|
||||
const motto = String(formData.get("motto") ?? "").normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 127);
|
||||
if (!userId || !motto) return;
|
||||
@@ -188,7 +188,7 @@ export async function setRank(formData: FormData): Promise<void> {
|
||||
export async function executeCommand(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const command = String(formData.get("command") ?? "").trim();
|
||||
const command = String(formData.get("command") ?? "").normalize("NFC").trim();
|
||||
if (!userId || !command) return;
|
||||
try {
|
||||
await rcon.executeCommand(userId, command);
|
||||
|
||||
Reference in new issue
Block a user