From c7f0db00c81c8c497eb5730b231781f2333c930f Mon Sep 17 00:00:00 2001 From: Jakob Wennberg <149234542+jakobwennberg@users.noreply.github.com> Date: Thu, 2 Jul 2026 15:30:21 +0200 Subject: [PATCH] fix(invoices): allowlist forwarded params on the /new redirects (#861 review) (#864) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Only inbox_item_id survives the redirect to the list-page modal — the list page reads nothing else, and arbitrary caller params must not pollute its query string. Co-authored-by: Claude Fable 5 --- app/(dashboard)/expenses/new/page.tsx | 13 +++++-------- app/(dashboard)/supplier-invoices/new/page.tsx | 12 +++++------- 2 files changed, 10 insertions(+), 15 deletions(-) diff --git a/app/(dashboard)/expenses/new/page.tsx b/app/(dashboard)/expenses/new/page.tsx index ceff4666..72632288 100644 --- a/app/(dashboard)/expenses/new/page.tsx +++ b/app/(dashboard)/expenses/new/page.tsx @@ -9,16 +9,13 @@ export default async function NewExpenseRedirectPage({ }) { const params = await searchParams const qs = new URLSearchParams() - for (const [key, value] of Object.entries(params)) { - if (value == null) continue - if (Array.isArray(value)) { - for (const v of value) qs.append(key, v) - } else { - qs.set(key, value) - } - } // Supplier invoice registration lives in a modal on the list page now // (?new=1) — go there directly instead of bouncing via /supplier-invoices/new. + // Allowlist: forward only what the list page actually consumes. qs.set('new', '1') + const inboxItemId = params.inbox_item_id + if (typeof inboxItemId === 'string' && inboxItemId) { + qs.set('inbox_item_id', inboxItemId) + } redirect(`/supplier-invoices?${qs.toString()}`) } diff --git a/app/(dashboard)/supplier-invoices/new/page.tsx b/app/(dashboard)/supplier-invoices/new/page.tsx index 6403538b..2ceea4a9 100644 --- a/app/(dashboard)/supplier-invoices/new/page.tsx +++ b/app/(dashboard)/supplier-invoices/new/page.tsx @@ -15,13 +15,11 @@ export default async function NewSupplierInvoicePage({ const params = await searchParams const qs = new URLSearchParams() qs.set('new', '1') - for (const [key, value] of Object.entries(params)) { - if (value == null) continue - if (Array.isArray(value)) { - for (const v of value) qs.append(key, v) - } else { - qs.set(key, value) - } + // Allowlist: forward only what the list page actually consumes — arbitrary + // caller params must not pollute the destination query string. + const inboxItemId = params.inbox_item_id + if (typeof inboxItemId === 'string' && inboxItemId) { + qs.set('inbox_item_id', inboxItemId) } redirect(`/supplier-invoices?${qs.toString()}`) }