fix(security): 修复客户端认证与地图渲染漏洞 (#5)
## 安全修复 - 修复地图标记与悬浮卡片中的存储型 XSS - 限制登录后的重定向目标为当前站点 - 提前清除邮箱确认和密码重置 URL 中的令牌 - 将 Vite 升级到 8.0.16,修复已公开的高危漏洞 - 收紧 Referrer Policy 并增加 HSTS ## 验证 - `npm audit --audit-level=low`:0 个漏洞 - `npm run build` - 6 组正常与恶意重定向用例 - 危险 DOM API 残留检查Reviewed-on: #5
This commit was merged in pull request #5.
This commit is contained in:
@@ -13,13 +13,25 @@ const password = ref('')
|
||||
const error = ref('')
|
||||
const loading = ref(false)
|
||||
|
||||
function getSafeRedirect(value: unknown) {
|
||||
if (typeof value !== 'string' || !value.startsWith('/')) return '/'
|
||||
|
||||
try {
|
||||
const target = new URL(value, window.location.origin)
|
||||
return target.origin === window.location.origin
|
||||
? `${target.pathname}${target.search}${target.hash}`
|
||||
: '/'
|
||||
} catch {
|
||||
return '/'
|
||||
}
|
||||
}
|
||||
|
||||
async function handleLogin() {
|
||||
error.value = ''
|
||||
loading.value = true
|
||||
try {
|
||||
await authStore.login(email.value, password.value)
|
||||
const redirect = (route.query.redirect as string) || '/'
|
||||
router.push(redirect)
|
||||
void router.push(getSafeRedirect(route.query.redirect))
|
||||
} catch (e: unknown) {
|
||||
error.value = e instanceof Error ? e.message : '登录失败,请稍后重试'
|
||||
} finally {
|
||||
|
||||
Reference in New Issue
Block a user