security: backend validation for all inputs
- router.param('id'): all :id path params must be positive ints
(tickets/features/polls/auth/users; external/bans/notifications already
had parseInt - now consistent)
- notifications: type enum + webhook URL format + SSRF (isPrivateUrl
exported) + events whitelist + active boolean check on PUT
- bans: type enum + player_name length
- external: all-tickets type/status enums, bans status/type enums,
page/limit floor protection, ticket field length caps, clients active
boolean + id validation
- verified: 28 checks (syntax + validation coverage)
This commit is contained in:
@@ -24,6 +24,12 @@ const { authenticate, requireRole } = require('../middleware/auth');
|
||||
|
||||
const router = express.Router();
|
||||
|
||||
// 统一校验 :id 路径参数(必须是正整数)
|
||||
router.param('id', (req, res, next, id) => {
|
||||
if (!/^\d+$/.test(id)) return res.status(400).json({ error: '无效的ID' });
|
||||
next();
|
||||
});
|
||||
|
||||
router.get('/', authenticate, requireRole('owner','admin'), async (req, res) => {
|
||||
const rows = await query(`SELECT u.id, u.username, u.email, u.game_name, u.game_uid, u.source, u.role, u.active, u.email_verified, u.created_at,
|
||||
(SELECT COUNT(*) FROM user_identities ui WHERE ui.user_id = u.id) as identity_count
|
||||
|
||||
Reference in New Issue
Block a user