mirror of
https://github.com/Sendouc/sendou.ink.git
synced 2026-10-01 07:37:55 -05:00
Stricter URL widget validation
This commit is contained in:
@@ -40,6 +40,18 @@ import type {
|
||||
TrophyOption,
|
||||
} from "./types";
|
||||
|
||||
const httpUrlSchema = v.pipe(
|
||||
v.string(),
|
||||
v.url(),
|
||||
v.check((value) => {
|
||||
try {
|
||||
return ["http:", "https:"].includes(new URL(value).protocol);
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}, "Only http(s) URLs are allowed."),
|
||||
);
|
||||
|
||||
export const formRegistry = new WeakMap<object, FormField>();
|
||||
|
||||
/** Clones the schema first so shared instances (e.g. `id`, `stageId`) each get their own registry entry. */
|
||||
@@ -155,12 +167,7 @@ export function textFieldOptional(
|
||||
): v.GenericSchema<string | null, string | null> {
|
||||
// validated as a plain string, so unlike other optional text fields it has no null fallback and its key stays required
|
||||
if (args.validate === "url") {
|
||||
return registerTextField(
|
||||
v.pipe(v.string(), v.url()),
|
||||
args,
|
||||
false,
|
||||
false,
|
||||
) as never;
|
||||
return registerTextField(httpUrlSchema, args, false, false) as never;
|
||||
}
|
||||
|
||||
return registerTextField(
|
||||
@@ -174,7 +181,7 @@ export function textFieldOptional(
|
||||
export function textField(args: TextFieldArgs): v.GenericSchema<string> {
|
||||
const schema =
|
||||
args.validate === "url"
|
||||
? v.pipe(v.string(), v.url())
|
||||
? httpUrlSchema
|
||||
: safeStringSchema({ min: args.minLength, max: args.maxLength });
|
||||
|
||||
return registerTextField(schema, args, true, false) as never;
|
||||
|
||||
Reference in New Issue
Block a user