fix(auth): centralize session recovery and sanitize SVG uploads - #1419
Conversation
Add proactive expiry checks and centralized 401 refresh/logout handling, safely rasterize static SVG uploads, and clarify sanitizer module boundaries. Closes CodeGirlsInc#1309 Closes CodeGirlsInc#1310 Closes CodeGirlsInc#1311 Closes CodeGirlsInc#1312
|
@Maryermarh is attempting to deploy a commit to the Mftee's projects Team on Vercel. A member of the Team first needs to authorize it. |
|
@Maryermarh Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
# Conflicts: # backend/src/auth/auth.controller.ts # backend/src/dispute/dispute.service.ts # backend/src/documents/documents.controller.ts # backend/src/documents/pipes/file-validation.pipe.ts # backend/src/documents/pipes/mime-type-validation.pipe.ts # frontend/app/[locale]/(protected)/admin/providers/page.tsx # frontend/app/[locale]/(protected)/admin/users/page.tsx # frontend/app/[locale]/(protected)/disputes/[id]/page.tsx # frontend/app/[locale]/(protected)/disputes/page.tsx # frontend/app/[locale]/(protected)/documents/upload/page.tsx # frontend/app/[locale]/(protected)/layout.tsx # frontend/app/[locale]/(protected)/settings/data/page.tsx # frontend/app/[locale]/(protected)/settings/security/page.tsx # frontend/app/[locale]/2fa/setup/page.tsx # frontend/app/[locale]/2fa/verify/page.tsx # frontend/app/[locale]/forgot-password/page.tsx # frontend/app/[locale]/login/LoginForm.tsx # frontend/app/[locale]/reset-password/page.tsx # frontend/app/[locale]/verify-email/page.tsx # frontend/components/LanguageSwitcher.tsx # frontend/components/disputes/FileDisputeModal.tsx # frontend/components/layout/NotificationBell.tsx # frontend/lib/__tests__/session-expiry.test.ts # frontend/lib/api-client.ts # frontend/lib/auth-session.ts # frontend/lib/session-expiry-warning.ts # frontend/test-utils/LoginForm.test.tsx # frontend/test-utils/api-client.test.ts # frontend/test-utils/language-switcher.test.tsx # frontend/test-utils/mocks/handlers.ts
mftee
left a comment
There was a problem hiding this comment.
Reviewed and resolved a large conflict against main, similar in scope to #1420: PR #1415/#1420 had already landed a competing auth-cookie scheme covering most of this PR's plumbing changes. Kept main's already-deployed session/auth code and backported this PR's real contribution — the extensive SVG upload-security work (allow/deny element lists, URL-attribute checks, dimension/element-count limits) into file-validation.pipe.ts, added image/svg+xml to the shared documentUpload contract so it isn't rejected before reaching that sanitizer, wired the browser-side sanitizeSvg pre-check into the upload page for early feedback, and kept the 403-vs-401 (ForbiddenException) correction in dispute.service.ts's ownership check. Dropped the now-superseded auth-cookie/session-bootstrap plumbing and the disputes.ts/SessionBootstrap files that duplicated what main already has. Good, thorough SVG-sanitization allowlist.
Summary
Issues
Validation
Closes #1309
Closes #1310
Closes #1311
Closes #1312