mirror of
https://github.com/gethomepage/homepage.git
synced 2026-09-29 23:41:16 -07:00
Security: narrow settings props for signin page
This commit is contained in:
@@ -60,9 +60,22 @@ describe("pages/auth/signin", () => {
|
|||||||
expect(screen.getByRole("button", { name: /login via oidc/i })).toBeInTheDocument();
|
expect(screen.getByRole("button", { name: /login via oidc/i })).toBeInTheDocument();
|
||||||
});
|
});
|
||||||
|
|
||||||
it("getServerSideProps returns providers and settings", async () => {
|
it("getServerSideProps returns providers and only public sign-in settings", async () => {
|
||||||
getProviders.mockResolvedValueOnce({ foo: { id: "foo", name: "Foo" } });
|
getProviders.mockResolvedValueOnce({ foo: { id: "foo", name: "Foo" } });
|
||||||
getSettingsMock.mockReturnValueOnce({ theme: "dark" });
|
getSettingsMock.mockReturnValueOnce({
|
||||||
|
theme: "dark",
|
||||||
|
color: "slate",
|
||||||
|
title: "Homepage",
|
||||||
|
background: { image: "background.jpg", opacity: 20 },
|
||||||
|
backgroundOpacity: 10,
|
||||||
|
providers: {
|
||||||
|
longhorn: {
|
||||||
|
username: "admin",
|
||||||
|
password: "secret",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
layout: { Internal: { style: "row" } },
|
||||||
|
});
|
||||||
|
|
||||||
const res = await getServerSideProps({});
|
const res = await getServerSideProps({});
|
||||||
|
|
||||||
@@ -71,8 +84,16 @@ describe("pages/auth/signin", () => {
|
|||||||
expect(res).toEqual({
|
expect(res).toEqual({
|
||||||
props: {
|
props: {
|
||||||
providers: { foo: { id: "foo", name: "Foo" } },
|
providers: { foo: { id: "foo", name: "Foo" } },
|
||||||
settings: { theme: "dark" },
|
settings: {
|
||||||
|
theme: "dark",
|
||||||
|
color: "slate",
|
||||||
|
title: "Homepage",
|
||||||
|
background: { image: "background.jpg", opacity: 20 },
|
||||||
|
backgroundOpacity: 10,
|
||||||
|
},
|
||||||
},
|
},
|
||||||
});
|
});
|
||||||
|
expect(res.props.settings).not.toHaveProperty("providers");
|
||||||
|
expect(res.props.settings).not.toHaveProperty("layout");
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -6,6 +6,8 @@ import { BiShieldQuarter } from "react-icons/bi";
|
|||||||
|
|
||||||
import { getSettings } from "utils/config/config";
|
import { getSettings } from "utils/config/config";
|
||||||
|
|
||||||
|
const PUBLIC_SIGN_IN_SETTINGS = ["theme", "color", "title", "background", "backgroundOpacity"];
|
||||||
|
|
||||||
export default function SignIn({ providers, settings }) {
|
export default function SignIn({ providers, settings }) {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
const [password, setPassword] = useState("");
|
const [password, setPassword] = useState("");
|
||||||
@@ -201,7 +203,13 @@ export default function SignIn({ providers, settings }) {
|
|||||||
|
|
||||||
export async function getServerSideProps(context) {
|
export async function getServerSideProps(context) {
|
||||||
const providers = await getProviders();
|
const providers = await getProviders();
|
||||||
const settings = getSettings();
|
const homepageSettings = getSettings();
|
||||||
|
const settings = Object.fromEntries(
|
||||||
|
PUBLIC_SIGN_IN_SETTINGS.filter((key) => Object.prototype.hasOwnProperty.call(homepageSettings, key)).map((key) => [
|
||||||
|
key,
|
||||||
|
homepageSettings[key],
|
||||||
|
]),
|
||||||
|
);
|
||||||
return {
|
return {
|
||||||
props: { providers, settings },
|
props: { providers, settings },
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user