mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-11 03:39:49 +08:00
fix(ci): align lint-safe security paths
This commit is contained in:
@@ -607,17 +607,15 @@ fn payment_order_payload(
|
||||
// A gateway response is a live checkout capability, not durable order
|
||||
// history. Once the order is paid, terminal, or expired, suppress URLs,
|
||||
// form parameters, and provider metadata from the public payload.
|
||||
let gateway_response = record
|
||||
.status
|
||||
.eq_ignore_ascii_case("pending")
|
||||
.then(|| {
|
||||
record
|
||||
.expires_at_unix_secs
|
||||
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
|
||||
})
|
||||
.unwrap_or(false)
|
||||
.then(|| record.gateway_response.clone())
|
||||
.flatten();
|
||||
let gateway_response = if record.status.eq_ignore_ascii_case("pending")
|
||||
&& record
|
||||
.expires_at_unix_secs
|
||||
.is_some_and(|expires_at| expires_at > Utc::now().timestamp().max(0) as u64)
|
||||
{
|
||||
record.gateway_response.clone()
|
||||
} else {
|
||||
None
|
||||
};
|
||||
json!({
|
||||
"id": record.id,
|
||||
"order_no": record.order_no,
|
||||
|
||||
@@ -383,8 +383,7 @@ fn forwarded_header_last(headers: &http::HeaderMap, name: &str) -> Option<String
|
||||
.filter_map(|value| value.to_str().ok())
|
||||
.flat_map(|value| value.split(','))
|
||||
.map(str::trim)
|
||||
.filter(|value| !value.is_empty())
|
||||
.last()
|
||||
.rfind(|value| !value.is_empty())
|
||||
.map(ToOwned::to_owned)
|
||||
}
|
||||
|
||||
|
||||
@@ -1054,11 +1054,14 @@ fn redirect_to(target: &str, params: Option<RedirectParams>) -> Response<Body> {
|
||||
fn build_redirect_location(target: &str, params: Option<RedirectParams>) -> String {
|
||||
let relative_target =
|
||||
url::Url::parse(target).is_err() && target.starts_with('/') && !target.starts_with("//");
|
||||
let Ok(mut url) = url::Url::parse(target).or_else(|_| {
|
||||
relative_target
|
||||
.then(|| url::Url::parse("http://aether.invalid").and_then(|base| base.join(target)))
|
||||
.unwrap_or_else(|| Err(url::ParseError::RelativeUrlWithoutBase))
|
||||
}) else {
|
||||
let parsed_target = url::Url::parse(target).or_else(|_| {
|
||||
if relative_target {
|
||||
url::Url::parse("http://aether.invalid").and_then(|base| base.join(target))
|
||||
} else {
|
||||
Err(url::ParseError::RelativeUrlWithoutBase)
|
||||
}
|
||||
});
|
||||
let Ok(mut url) = parsed_target else {
|
||||
return target.to_string();
|
||||
};
|
||||
match params {
|
||||
|
||||
Reference in New Issue
Block a user