v2.5.1: Admin theme refactor, Navigation plugin, user roles, guide restructure
- Reorganize admin into admin/theme/default/ (views + assets) - Rename GuideNav to Navigation plugin (essential, protected) - Plugin assets support (SCSS/CSS) loaded after theme CSS - User roles: Admin, Content Manager, BI Manager, Site Admin - Role-based access control (RBAC) for admin routes and sidebar - Guide restructure: sub-topics in separate folders with sidebar nav - Dynamic breadcrumb for homepage and subdirectories - Fix theme path traversal (../../ -> ../) in admin.php - Fix CodeMirror mode load order (xml -> css -> js -> htmlmixed -> php) - Fix editor-toolbar.js null checks for plugin edit pages - Layout select from theme.json with live frontmatter update - Footer sticky at bottom of viewport (min-height: 100vh) - Breadcrumb color fix (var(--nav-font) -> var(--header-bg)) - Remove language switcher from guide pages - Update README.md and README.en.md - Bump version to 2.5.1
This commit is contained in:
@@ -0,0 +1,34 @@
|
||||
# Security
|
||||
|
||||
## XSS prevention
|
||||
|
||||
```php
|
||||
// Always escape
|
||||
echo htmlspecialchars($userInput, ENT_QUOTES, 'UTF-8');
|
||||
|
||||
// In Twig (automatic)
|
||||
{{ userVariable }}
|
||||
```
|
||||
|
||||
## CSRF tokens
|
||||
|
||||
```php
|
||||
// Generate
|
||||
$csrf = $auth->getCsrfToken();
|
||||
|
||||
// Verify
|
||||
if (!$auth->verifyCsrf($_POST['csrf_token'])) {
|
||||
die('Invalid CSRF token');
|
||||
}
|
||||
```
|
||||
|
||||
## Path traversal prevention
|
||||
|
||||
```php
|
||||
// Use realpath() and check prefix
|
||||
$realPath = realpath($filePath);
|
||||
$realContentDir = realpath($contentDir);
|
||||
if (strpos($realPath, $realContentDir) !== 0) {
|
||||
die('Invalid path');
|
||||
}
|
||||
```
|
||||
Reference in New Issue
Block a user