fix(security): 修复客户端认证与地图渲染漏洞 (#5)
## 安全修复 - 修复地图标记与悬浮卡片中的存储型 XSS - 限制登录后的重定向目标为当前站点 - 提前清除邮箱确认和密码重置 URL 中的令牌 - 将 Vite 升级到 8.0.16,修复已公开的高危漏洞 - 收紧 Referrer Policy 并增加 HSTS ## 验证 - `npm audit --audit-level=low`:0 个漏洞 - `npm run build` - 6 组正常与恶意重定向用例 - 危险 DOM API 残留检查Reviewed-on: #5
This commit was merged in pull request #5.
This commit is contained in:
@@ -13,9 +13,14 @@ const error = ref('')
|
||||
const state = ref<'checking' | 'ready' | 'invalid' | 'success'>('checking')
|
||||
const loading = ref(false)
|
||||
const countdown = ref(5)
|
||||
const resetToken = ref('')
|
||||
const initialResetToken = typeof route.query.token === 'string' ? route.query.token : ''
|
||||
const resetToken = ref(initialResetToken)
|
||||
let countdownTimer: ReturnType<typeof setInterval> | null = null
|
||||
|
||||
if (route.query.token !== undefined) {
|
||||
window.history.replaceState(window.history.state, '', window.location.pathname)
|
||||
}
|
||||
|
||||
const canSubmit = computed(() =>
|
||||
state.value === 'ready' && password.value.length >= 8 && password.value === confirmPassword.value,
|
||||
)
|
||||
@@ -49,13 +54,10 @@ function startCountdown() {
|
||||
}
|
||||
|
||||
async function initializeRecoverySession() {
|
||||
const token = typeof route.query.token === 'string' ? route.query.token : ''
|
||||
if (!token) {
|
||||
if (!resetToken.value) {
|
||||
showInvalidRecoveryLink()
|
||||
return
|
||||
}
|
||||
|
||||
resetToken.value = token
|
||||
state.value = 'ready'
|
||||
}
|
||||
|
||||
@@ -78,7 +80,6 @@ async function handleResetPassword() {
|
||||
auth: false,
|
||||
body: { token: resetToken.value, password: password.value },
|
||||
})
|
||||
window.history.replaceState(null, '', window.location.pathname)
|
||||
countdown.value = 5
|
||||
state.value = 'success'
|
||||
startCountdown()
|
||||
|
||||
Reference in New Issue
Block a user