Reports/Export builder (CSV/XLSX), plus a security fix pass
Adds the Berichte export pipeline (/api/export/{report,events,employees})
with shared CSV/XLSX writers in lib/export.ts and lib/reports-data.ts.
Security pass alongside it: sanitize .or() search terms against PostgREST
filter injection, sanitize spreadsheet cells against CSV/Excel formula
injection, stop leaking raw DB error messages to clients, harden the
service-role client with server-only, add baseline security headers, and
bump the vulnerable nested postcss via an override.
This commit is contained in:
9
lib/supabase/query.ts
Normal file
9
lib/supabase/query.ts
Normal file
@@ -0,0 +1,9 @@
|
||||
// PostgREST's .or() filter syntax treats "," "(" and ")" as structural
|
||||
// delimiters between conditions. A raw user-supplied search term containing
|
||||
// them (e.g. from a search box or ?q= param) can break out of the intended
|
||||
// column conditions and append arbitrary extra filters to the query. Strip
|
||||
// them before interpolating — harmless for real name/title searches, which
|
||||
// never legitimately contain them.
|
||||
export function sanitizeIlikeTerm(term: string): string {
|
||||
return term.replace(/[,()]/g, "");
|
||||
}
|
||||
Reference in New Issue
Block a user