fix(web): address auth review findings (open redirect, dead code, HMAC per-req)

Pre-merge review of the P0 branch:
- Open redirect: login redirected to an unvalidated ?next param, so a crafted
  /login?next=https://evil (or //evil) bounced off-site after login. Now only
  same-origin relative paths are honored (else fall back to "/").
- Remove the unused useRouter import/binding in the login form.
- Memoize expectedToken() keyed on (password, secret) so middleware stops
  recomputing an HMAC on every gated request.

Deferred (low-value/latent, noted): Soulseek cover.jpg isn't retrieved into
staging (UI still shows Cover Art Archive art); _retrieve's basename-keyed map
could undercount same-named files but source_refs come from a single slskd dir;
SignOut visibility rides a server-env read (cosmetic).

web 138 tests green, tsc + build clean.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jonathan
2026-07-14 10:25:37 +02:00
parent 8cd5392ec3
commit 446a4bc2d2
2 changed files with 13 additions and 4 deletions
+5 -3
View File
@@ -1,12 +1,14 @@
"use client";
import { useState } from "react";
import { useRouter, useSearchParams } from "next/navigation";
import { useSearchParams } from "next/navigation";
export function LoginForm() {
const router = useRouter();
const params = useSearchParams();
const next = params.get("next") || "/";
// Only allow same-origin relative paths, so a crafted ?next=https://evil or ?next=//evil
// can't turn login into an open redirect.
const raw = params.get("next") || "/";
const next = raw.startsWith("/") && !raw.startsWith("//") ? raw : "/";
const [password, setPassword] = useState("");
const [error, setError] = useState("");
const [busy, setBusy] = useState(false);