From a648e676db87b7ee3e72db15df258ecbca501b6a Mon Sep 17 00:00:00 2001 From: Sergei Tsoganov Date: Thu, 25 Jan 2024 15:35:16 +0200 Subject: [PATCH] Fixed sanitizeUrl function --- server/utils/logger.js | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/server/utils/logger.js b/server/utils/logger.js index a5c685c..5d5814a 100644 --- a/server/utils/logger.js +++ b/server/utils/logger.js @@ -17,9 +17,9 @@ const logger = { ignoreRoute, meta: false, msg: (req, res) => { - return `${req.method} ${req.protocol}://${req.get('host')}${sanitizeUrl(req.originalUrl)} (${ - res.statusCode - }) ${Math.floor(res.responseTime / 1000)}, User-Agent: ${req.get( + return `${req.method} ${req.protocol}://${req.get('host')}${sanitizeUrl( + req.originalUrl + )} (${res.statusCode}) ${Math.floor(res.responseTime / 1000)}, User-Agent: ${req.get( 'User-Agent' )}, Referrer: ${sanitizeUrl(req.get('Referrer'))}, IP: ${ req.ip.indexOf(':') >= 0 ? req.ip.substring(req.ip.lastIndexOf(':') + 1) : req.i @@ -30,7 +30,11 @@ const logger = { function sanitizeUrl(url) { // Implement URL sanitization logic here // For example, removing or encoding certain characters - return url.replace(/[{}]/g, encodeURIComponent); + if (typeof url === 'string') { + return url.replace(/[{}]/g, match => encodeURIComponent(match)); + } else { + return ''; + } } export const accessLog = {