feat: security hardening, DB indexes, token revocation, and input validation
- SSRF protection: DNS resolution + private IP blocking on metadata fetcher - Upload security: CSP/X-Frame-Options headers, SVG forced download, nosniff - Auth hardening: JWT secret min length, password min 8 chars, token revocation via password_changed_at - Attachment ownership verification before linking to messages - Message length limit (4000 chars) enforced on client and server - Asset URL validation on avatar/banner updates - Federation instance validation (domain regex, origin scheme, length limits) - DB indexes on all FK columns for query performance - Migrations: nullable moderator columns, dm_messages reply_to FK constraint - File cleanup on avatar/banner replacement and space deletion - Fastify trustProxy, AbortController on fetches, typing map size cap
This commit is contained in:
@@ -595,14 +595,16 @@ export const useChatStore = create<ChatState>((set, get) => ({
|
||||
});
|
||||
},
|
||||
|
||||
updateUserInMessages: (user: { id: string; [key: string]: any }) => {
|
||||
updateUserInMessages: (user: { id: string; homeUserId?: string | null; [key: string]: any }) => {
|
||||
set((state) => {
|
||||
const newMessages = new Map(state.messages);
|
||||
let changed = false;
|
||||
for (const [channelId, msgs] of newMessages) {
|
||||
let channelChanged = false;
|
||||
const updated = msgs.map(m => {
|
||||
if (m.userId === user.id) {
|
||||
const matches = m.userId === user.id ||
|
||||
(user.homeUserId && m.user?.homeUserId && m.user.homeUserId === user.homeUserId);
|
||||
if (matches) {
|
||||
channelChanged = true;
|
||||
return { ...m, user: { ...m.user, ...user } };
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user