fix(web): address auth review findings (open redirect, dead code, HMAC per-req)
Pre-merge review of the P0 branch: - Open redirect: login redirected to an unvalidated ?next param, so a crafted /login?next=https://evil (or //evil) bounced off-site after login. Now only same-origin relative paths are honored (else fall back to "/"). - Remove the unused useRouter import/binding in the login form. - Memoize expectedToken() keyed on (password, secret) so middleware stops recomputing an HMAC on every gated request. Deferred (low-value/latent, noted): Soulseek cover.jpg isn't retrieved into staging (UI still shows Cover Art Archive art); _retrieve's basename-keyed map could undercount same-named files but source_refs come from a single slskd dir; SignOut visibility rides a server-env read (cosmetic). web 138 tests green, tsc + build clean. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -1,12 +1,14 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { useRouter, useSearchParams } from "next/navigation";
|
||||
import { useSearchParams } from "next/navigation";
|
||||
|
||||
export function LoginForm() {
|
||||
const router = useRouter();
|
||||
const params = useSearchParams();
|
||||
const next = params.get("next") || "/";
|
||||
// Only allow same-origin relative paths, so a crafted ?next=https://evil or ?next=//evil
|
||||
// can't turn login into an open redirect.
|
||||
const raw = params.get("next") || "/";
|
||||
const next = raw.startsWith("/") && !raw.startsWith("//") ? raw : "/";
|
||||
const [password, setPassword] = useState("");
|
||||
const [error, setError] = useState("");
|
||||
const [busy, setBusy] = useState(false);
|
||||
|
||||
Reference in New Issue
Block a user