Add NFC normalization to all FormData inputs across 41 server actions
Local Build and Deploy / deploy (push) Successful in 59s

All user-supplied string values from FormData now go through
String.prototype.normalize('NFC') to prevent Unicode homoglyph
attacks and canonicalization bypasses. NFC is idempotent for
already-normalized strings, so this is a pure security improvement
with zero behavioral change for legitimate users.
This commit is contained in:
openhands committed 2026-07-13 12:21:37 +02:00
1 parent e2fc7ea1a4
commit e5ae51bff7
41 files changed
+152 -152

No files matched your search

+3 -3
View File
@@ -61,7 +61,7 @@ export async function sendFriendRequest(formData: FormData): Promise<void> {
// Optional: revalidate the target profile if a username was supplied, purely
// to refresh any request-state UI rendered there.
const username = String(formData.get("username") ?? "").trim();
const username = String(formData.get("username") ?? "").normalize("NFC").trim();
if (username) revalidatePath(`/u/${username}`);
}
@@ -85,10 +85,10 @@ export async function postThread(formData: FormData): Promise<void> {
const guildId = Number(formData.get("guildId"));
if (!Number.isInteger(guildId) || guildId <= 0) return;
const subject = String(formData.get("subject") ?? "")
const subject = String(formData.get("subject") ?? "").normalize("NFC")
.trim()
.slice(0, SUBJECT_MAX);
const message = String(formData.get("message") ?? "")
const message = String(formData.get("message") ?? "").normalize("NFC")
.trim()
.slice(0, MESSAGE_MAX);
if (!subject || !message) return;