Stricter URL widget validation

This commit is contained in:
Kalle
2026-09-06 11:49:33 +03:00
parent 0461374771
commit 99f2de3bee
2 changed files with 43 additions and 7 deletions

View File

@@ -40,6 +40,18 @@ import type {
TrophyOption,
} from "./types";
const httpUrlSchema = v.pipe(
v.string(),
v.url(),
v.check((value) => {
try {
return ["http:", "https:"].includes(new URL(value).protocol);
} catch {
return false;
}
}, "Only http(s) URLs are allowed."),
);
export const formRegistry = new WeakMap<object, FormField>();
/** Clones the schema first so shared instances (e.g. `id`, `stageId`) each get their own registry entry. */
@@ -155,12 +167,7 @@ export function textFieldOptional(
): v.GenericSchema<string | null, string | null> {
// validated as a plain string, so unlike other optional text fields it has no null fallback and its key stays required
if (args.validate === "url") {
return registerTextField(
v.pipe(v.string(), v.url()),
args,
false,
false,
) as never;
return registerTextField(httpUrlSchema, args, false, false) as never;
}
return registerTextField(
@@ -174,7 +181,7 @@ export function textFieldOptional(
export function textField(args: TextFieldArgs): v.GenericSchema<string> {
const schema =
args.validate === "url"
? v.pipe(v.string(), v.url())
? httpUrlSchema
: safeStringSchema({ min: args.minLength, max: args.maxLength });
return registerTextField(schema, args, true, false) as never;