security: backend validation for all inputs

- router.param('id'): all :id path params must be positive ints
  (tickets/features/polls/auth/users; external/bans/notifications already
  had parseInt - now consistent)
- notifications: type enum + webhook URL format + SSRF (isPrivateUrl
  exported) + events whitelist + active boolean check on PUT
- bans: type enum + player_name length
- external: all-tickets type/status enums, bans status/type enums,
  page/limit floor protection, ticket field length caps, clients active
  boolean + id validation
- verified: 28 checks (syntax + validation coverage)
This commit is contained in:
2026-08-21 20:10:05 +08:00
parent 8c5ce78fd0
commit e1cdff2b4a
9 changed files with 108 additions and 21 deletions

View File

@@ -28,6 +28,12 @@ const { validateLengths } = require('../middleware/security');
const router = express.Router();
// 统一校验 :id 路径参数(必须是正整数)
router.param('id', (req, res, next, id) => {
if (!/^\d+$/.test(id)) return res.status(400).json({ error: '无效的ID' });
next();
});
async function getSiteUrl() {
const row = await getRow("SELECT v FROM settings WHERE k = 'site_url'");
return row?.v || 'http://localhost:3100';