Harden web root, secrets and realtime auth
- .htaccess: refuse .git, .env, docker, nodejs, sdlc*, scripts, archives and app internals; security headers, HSTS over TLS, optional HTTPS redirect - uploads served through app/file.php to signed-in users only - Apache/PHP hardening config for the container (ServerTokens, expose_php) - least-privilege DB account and APP_SECRET_KEY via docker/php/provision.php; SMTP passwords re-encrypted with a random IV (secret_box.php) - Socket.IO rooms from a PHP-signed token; /emit and cron refuse empty secrets - escape notification text; CLI guards on build scripts; no fixed demo password
This commit is contained in:
@@ -359,13 +359,19 @@ function _render_notif_list() {
|
||||
el.innerHTML = '<div class="text-center text-muted small py-4">No notifications</div>';
|
||||
return;
|
||||
}
|
||||
// Notification text arrives over the socket: escape it, never render it as markup.
|
||||
var esc = function (v) {
|
||||
return String(v).replace(/[&<>"']/g, function (c) {
|
||||
return { '&': '&', '<': '<', '>': '>', '"': '"', "'": ''' }[c];
|
||||
});
|
||||
};
|
||||
el.innerHTML = _notif_items.map(function(n) {
|
||||
var icon = _notif_icon_map[n.type] || _notif_icon_map.info;
|
||||
return '<div class="d-flex align-items-start gap-2 px-3 py-2 border-bottom">' +
|
||||
'<i class="ti ' + icon + ' fs-5 flex-shrink-0 mt-1"></i>' +
|
||||
'<div class="flex-grow-1 overflow-hidden">' +
|
||||
(n.title ? '<div class="fw-semibold small text-truncate">' + n.title + '</div>' : '') +
|
||||
(n.message ? '<div class="small text-muted text-truncate">' + n.message + '</div>' : '') +
|
||||
(n.title ? '<div class="fw-semibold small text-truncate">' + esc(n.title) + '</div>' : '') +
|
||||
(n.message ? '<div class="small text-muted text-truncate">' + esc(n.message) + '</div>' : '') +
|
||||
'<div class="small text-muted opacity-75 mt-1">' + n.time + '</div>' +
|
||||
'</div></div>';
|
||||
}).join('');
|
||||
|
||||
Reference in New Issue
Block a user