fix: allow bare filenames in avatar/banner validation, fix password min length
isValidAssetUrl() was rejecting bare filenames (e.g. "1234567890.webp") which is the established convention the frontend sends. Now accepts bare filenames while still blocking path traversal and unsafe schemes. Also updates client-side password validation to match server's 8-char minimum.
This commit is contained in:
@@ -214,8 +214,8 @@ export function AccountPanel() {
|
||||
setPasswordSuccess('');
|
||||
setPasswordResults(null);
|
||||
|
||||
if (newPassword.length < 6) {
|
||||
setPasswordError('New password must be at least 6 characters');
|
||||
if (newPassword.length < 8) {
|
||||
setPasswordError('New password must be at least 8 characters');
|
||||
return;
|
||||
}
|
||||
if (newPassword !== confirmNewPassword) {
|
||||
|
||||
Reference in New Issue
Block a user