fix(invoices): allowlist forwarded params on the /new redirects (#861 review) (#864)

Only inbox_item_id survives the redirect to the list-page modal — the list
page reads nothing else, and arbitrary caller params must not pollute its
query string.

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Jakob Wennberg
2026-07-02 15:30:21 +02:00
committed by GitHub
co-authored by Claude Fable 5
parent 01dbef4015
commit c7f0db00c8
2 changed files with 10 additions and 15 deletions
+5 -8
View File
@@ -9,16 +9,13 @@ export default async function NewExpenseRedirectPage({
}) {
const params = await searchParams
const qs = new URLSearchParams()
for (const [key, value] of Object.entries(params)) {
if (value == null) continue
if (Array.isArray(value)) {
for (const v of value) qs.append(key, v)
} else {
qs.set(key, value)
}
}
// Supplier invoice registration lives in a modal on the list page now
// (?new=1) — go there directly instead of bouncing via /supplier-invoices/new.
// Allowlist: forward only what the list page actually consumes.
qs.set('new', '1')
const inboxItemId = params.inbox_item_id
if (typeof inboxItemId === 'string' && inboxItemId) {
qs.set('inbox_item_id', inboxItemId)
}
redirect(`/supplier-invoices?${qs.toString()}`)
}
@@ -15,13 +15,11 @@ export default async function NewSupplierInvoicePage({
const params = await searchParams
const qs = new URLSearchParams()
qs.set('new', '1')
for (const [key, value] of Object.entries(params)) {
if (value == null) continue
if (Array.isArray(value)) {
for (const v of value) qs.append(key, v)
} else {
qs.set(key, value)
}
// Allowlist: forward only what the list page actually consumes — arbitrary
// caller params must not pollute the destination query string.
const inboxItemId = params.inbox_item_id
if (typeof inboxItemId === 'string' && inboxItemId) {
qs.set('inbox_item_id', inboxItemId)
}
redirect(`/supplier-invoices?${qs.toString()}`)
}