fix: allow bare filenames in avatar/banner validation, fix password min length

isValidAssetUrl() was rejecting bare filenames (e.g. "1234567890.webp") which
is the established convention the frontend sends. Now accepts bare filenames
while still blocking path traversal and unsafe schemes.

Also updates client-side password validation to match server's 8-char minimum.
This commit is contained in:
Jannis Braun
2026-03-15 00:11:10 +01:00
parent 7c544c1ff4
commit 3a266e07ed
2 changed files with 5 additions and 3 deletions
+3 -1
View File
@@ -10,12 +10,14 @@ import { deleteUploadFile } from '../utils/fileCleanup.js';
import { tombstoneUser } from '../utils/userDeletion.js';
import { generateSnowflake } from '../utils/snowflake.js';
/** Validates that a URL is a safe asset URL (relative upload path or http/https) */
/** Validates that a URL is a safe asset URL (relative upload path, bare filename, or http/https) */
function isValidAssetUrl(url: string | null | undefined): boolean {
if (!url || url.trim().length === 0) return true; // empty/null = clearing
const trimmed = url.trim();
if (trimmed.startsWith('/api/uploads/')) return true;
if (trimmed.startsWith('https://') || trimmed.startsWith('http://')) return true;
// Accept bare filenames (the existing convention) — no slashes, no traversal
if (!trimmed.includes('/') && !trimmed.includes('\\') && !trimmed.includes('..')) return true;
return false;
}