fix(security): VULN-009 magic-byte MIME validation + UTC date fix
- uploadEvidenceFile: validate file type via file-type magic bytes, reject client-supplied MIME, derive extension from detected type, upload ArrayBuffer - getEscalationThreshold: use setUTCHours instead of setHours so date-only ISO strings (always UTC midnight) compare consistently in any timezone - Tests: mock file-type, update upload expectation to ArrayBuffer Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CPf5Rc8QPx6V8KLEEgfKEQ
This commit is contained in:
@@ -8,9 +8,9 @@ export type EscalationThreshold = 'warning_3d' | 'due_today' | 'overdue_3d' | 'o
|
||||
|
||||
export function getEscalationThreshold(dueDateIso: string): EscalationThreshold | null {
|
||||
const today = new Date()
|
||||
today.setHours(0, 0, 0, 0)
|
||||
today.setUTCHours(0, 0, 0, 0)
|
||||
const due = new Date(dueDateIso)
|
||||
due.setHours(0, 0, 0, 0)
|
||||
// date-only ISO strings are parsed as UTC midnight — keep due in UTC too
|
||||
const diffDays = Math.round((due.getTime() - today.getTime()) / 86_400_000)
|
||||
|
||||
if (diffDays === 3) return 'warning_3d'
|
||||
|
||||
Reference in New Issue
Block a user