fix(ci): align lint-safe security paths

This commit is contained in:
elky
2026-09-05 03:19:53 +08:00
parent f5e1420ee6
commit 33d5cd5993
45 changed files with 180 additions and 132 deletions
@@ -607,17 +607,15 @@ fn payment_order_payload(
// A gateway response is a live checkout capability, not durable order
// history. Once the order is paid, terminal, or expired, suppress URLs,
// form parameters, and provider metadata from the public payload.
let gateway_response = record
.status
.eq_ignore_ascii_case("pending")
.then(|| {
record
.expires_at_unix_secs
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
})
.unwrap_or(false)
.then(|| record.gateway_response.clone())
.flatten();
let gateway_response = if record.status.eq_ignore_ascii_case("pending")
&& record
.expires_at_unix_secs
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
{
record.gateway_response.clone()
} else {
None
};
json!({
"id": record.id,
"order_no": record.order_no,
@@ -383,8 +383,7 @@ fn forwarded_header_last(headers: &http::HeaderMap, name: &str) -> Option<String
.filter_map(|value| value.to_str().ok())
.flat_map(|value| value.split(','))
.map(str::trim)
.filter(|value| !value.is_empty())
.last()
.rfind(|value| !value.is_empty())
.map(ToOwned::to_owned)
}
@@ -1054,11 +1054,14 @@ fn redirect_to(target: &str, params: Option<RedirectParams>) -> Response<Body> {
fn build_redirect_location(target: &str, params: Option<RedirectParams>) -> String {
let relative_target =
url::Url::parse(target).is_err() && target.starts_with('/') && !target.starts_with("//");
let Ok(mut url) = url::Url::parse(target).or_else(|_| {
relative_target
.then(|| url::Url::parse("http://aether.invalid").and_then(|base| base.join(target)))
.unwrap_or_else(|| Err(url::ParseError::RelativeUrlWithoutBase))
}) else {
let parsed_target = url::Url::parse(target).or_else(|_| {
if relative_target {
url::Url::parse("http://aether.invalid").and_then(|base| base.join(target))
} else {
Err(url::ParseError::RelativeUrlWithoutBase)
}
});
let Ok(mut url) = parsed_target else {
return target.to_string();
};
match params {