fix(security): VULN-009 magic-byte MIME validation + UTC date fix

- uploadEvidenceFile: validate file type via file-type magic bytes, reject
  client-supplied MIME, derive extension from detected type, upload ArrayBuffer
- getEscalationThreshold: use setUTCHours instead of setHours so date-only ISO
  strings (always UTC midnight) compare consistently in any timezone
- Tests: mock file-type, update upload expectation to ArrayBuffer

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
This commit is contained in:
2026-07-13 06:37:59 +08:00
co-authored by Claude Sonnet 4.6
parent 3776bc20b3
commit 614c792225
5 changed files with 150 additions and 12 deletions
+2 -2
View File
@@ -8,9 +8,9 @@ export type EscalationThreshold = 'warning_3d' | 'due_today' | 'overdue_3d' | 'o
export function getEscalationThreshold(dueDateIso: string): EscalationThreshold | null {
const today = new Date()
today.setHours(0, 0, 0, 0)
today.setUTCHours(0, 0, 0, 0)
const due = new Date(dueDateIso)
due.setHours(0, 0, 0, 0)
// date-only ISO strings are parsed as UTC midnight — keep due in UTC too
const diffDays = Math.round((due.getTime() - today.getTime()) / 86_400_000)
if (diffDays === 3) return 'warning_3d'