Only inbox_item_id survives the redirect to the list-page modal — the list page reads nothing else, and arbitrary caller params must not pollute its query string. Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
01dbef4015
commit
c7f0db00c8
@@ -9,16 +9,13 @@ export default async function NewExpenseRedirectPage({
|
||||
}) {
|
||||
const params = await searchParams
|
||||
const qs = new URLSearchParams()
|
||||
for (const [key, value] of Object.entries(params)) {
|
||||
if (value == null) continue
|
||||
if (Array.isArray(value)) {
|
||||
for (const v of value) qs.append(key, v)
|
||||
} else {
|
||||
qs.set(key, value)
|
||||
}
|
||||
}
|
||||
// Supplier invoice registration lives in a modal on the list page now
|
||||
// (?new=1) — go there directly instead of bouncing via /supplier-invoices/new.
|
||||
// Allowlist: forward only what the list page actually consumes.
|
||||
qs.set('new', '1')
|
||||
const inboxItemId = params.inbox_item_id
|
||||
if (typeof inboxItemId === 'string' && inboxItemId) {
|
||||
qs.set('inbox_item_id', inboxItemId)
|
||||
}
|
||||
redirect(`/supplier-invoices?${qs.toString()}`)
|
||||
}
|
||||
|
||||
@@ -15,13 +15,11 @@ export default async function NewSupplierInvoicePage({
|
||||
const params = await searchParams
|
||||
const qs = new URLSearchParams()
|
||||
qs.set('new', '1')
|
||||
for (const [key, value] of Object.entries(params)) {
|
||||
if (value == null) continue
|
||||
if (Array.isArray(value)) {
|
||||
for (const v of value) qs.append(key, v)
|
||||
} else {
|
||||
qs.set(key, value)
|
||||
}
|
||||
// Allowlist: forward only what the list page actually consumes — arbitrary
|
||||
// caller params must not pollute the destination query string.
|
||||
const inboxItemId = params.inbox_item_id
|
||||
if (typeof inboxItemId === 'string' && inboxItemId) {
|
||||
qs.set('inbox_item_id', inboxItemId)
|
||||
}
|
||||
redirect(`/supplier-invoices?${qs.toString()}`)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user