fix: security hardening, validation, cache and analytics fixes
Build & Push Docker Image / build (push) Successful in 4m32s
Build & Push Docker Image / build (push) Successful in 4m32s
Backend security: - Admin-gate /admin/redundancy (GET+POST) with zod validation and tool existence checks - Restrict CORS to same-origin (plus CORS_ORIGIN allowlist) and SameSite=Lax cookie - Validate returnTo to prevent open redirect in the OIDC flow - Validate/coerce relations body, reject self-relations and non-admin 'recommended' - Add central JSON error middleware (no more Express HTML 500s) - Fail fast at startup when SESSION_SECRET/VOTER_SECRET missing in production Backend correctness: - Stop leaking voterToken in the create-rating response - Allow clearing websiteUrl/iconUrl (nullable in UpdateToolBody, frontend sends null) - Regenerate session after login/callback (session fixation) and add OIDC state check - Block self-demotion and last-admin demotion in user PATCH - Set created_by to NULL on user delete (FK-safe) - Validate cost create/update bodies with zod - Unique index (tool_id, voter_token) + 409 on race duplicate ratings - Clamp audit limit, escape ilike wildcards in search, O(N) analytics queries Frontend: - tools-browse reads and syncs URL query params (fixes home 'View all' links) - Invalidate analytics/top-tools/categories/features caches after mutations - Sync category combobox input when the value changes externally - Hide Write a Review for anonymous users, drop unreachable rating guard
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
import { useState } from "react";
|
||||
import { useState, useEffect } from "react";
|
||||
import {
|
||||
useListTools,
|
||||
useListCategories,
|
||||
@@ -11,13 +11,35 @@ import { Button } from "@/components/ui/button";
|
||||
import { Select, SelectContent, SelectItem, SelectTrigger, SelectValue } from "@/components/ui/select";
|
||||
import { Skeleton } from "@/components/ui/skeleton";
|
||||
import { Search, Wrench, SlidersHorizontal, X } from "lucide-react";
|
||||
import { Link } from "wouter";
|
||||
import { Link, useLocation, useSearch } from "wouter";
|
||||
|
||||
const SORT_VALUES = new Set<string>([ListToolsSort.newest, ListToolsSort.top_rated, ListToolsSort.most_reviewed]);
|
||||
|
||||
export default function ToolsBrowse() {
|
||||
const [search, setSearch] = useState("");
|
||||
const [searchInput, setSearchInput] = useState("");
|
||||
const [category, setCategory] = useState<string>("all");
|
||||
const [sort, setSort] = useState<ListToolsSort>(ListToolsSort.newest);
|
||||
const [, navigate] = useLocation();
|
||||
const urlSearch = useSearch();
|
||||
|
||||
const initialParams = new URLSearchParams(urlSearch);
|
||||
const initialSearch = initialParams.get("search") ?? "";
|
||||
const initialCategory = initialParams.get("category") ?? "all";
|
||||
const initialSortParam = initialParams.get("sort") ?? "";
|
||||
const initialSort = SORT_VALUES.has(initialSortParam)
|
||||
? (initialSortParam as ListToolsSort)
|
||||
: ListToolsSort.newest;
|
||||
|
||||
const [search, setSearch] = useState(initialSearch);
|
||||
const [searchInput, setSearchInput] = useState(initialSearch);
|
||||
const [category, setCategory] = useState<string>(initialCategory);
|
||||
const [sort, setSort] = useState<ListToolsSort>(initialSort);
|
||||
|
||||
useEffect(() => {
|
||||
const p = new URLSearchParams();
|
||||
if (search) p.set("search", search);
|
||||
if (category && category !== "all") p.set("category", category);
|
||||
if (sort && sort !== ListToolsSort.newest) p.set("sort", sort);
|
||||
const qs = p.toString();
|
||||
navigate(qs ? `/tools?${qs}` : "/tools", { replace: true });
|
||||
}, [search, category, sort]);
|
||||
|
||||
const { data: categories, isLoading: loadingCategories } = useListCategories();
|
||||
|
||||
|
||||
Reference in New Issue
Block a user