Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+5 -5
View File
@@ -31,12 +31,12 @@ const DEFAULT_LOOK = "hr-100-.hd-180-1.ch-255-66.lg-280-110.sh-305-62";
export async function register(prevState: string | null, formData: FormData): Promise<string | null> {
const raw = {
username: String(formData.get("username") ?? "").trim(),
mail: String(formData.get("mail") ?? "")
username: String(formData.get("username") ?? "").normalize("NFC").trim(),
mail: String(formData.get("mail") ?? "").normalize("NFC")
.trim()
.toLowerCase(),
password: String(formData.get("password") ?? ""),
look: String(formData.get("look") ?? "").trim() || DEFAULT_LOOK,
password: String(formData.get("password") ?? "").normalize("NFC"),
look: String(formData.get("look") ?? "").normalize("NFC").trim() || DEFAULT_LOOK,
};
const parsed = registerSchema.safeParse(raw);
@@ -56,7 +56,7 @@ export async function register(prevState: string | null, formData: FormData): Pr
// CAPTCHA (Turnstile / reCAPTCHA) — only enforced when configured in settings.
const cfg = await captchaConfig();
if (cfg.provider !== "none") {
const token = String(formData.get(cfg.field) ?? "");
const token = String(formData.get(cfg.field) ?? "").normalize("NFC");
if (!(await verifyCaptcha(token, ip))) return "Captcha verification failed. Please try again.";
}