fix(security): resolve audit findings — logging, endpoints, contact details #3

Merged
sathish merged 1 commits from fix/security-audit into main 2026-08-04 13:18:56 +00:00
10 changed files with 27 additions and 31 deletions
Showing only changes of commit fc932dbc7e - Show all commits

View File

@@ -7,18 +7,11 @@ const nextConfig: NextConfig = {
// Image optimization
images: {
remotePatterns: [
{
protocol: "https",
hostname: "**",
},
{
protocol: "http",
hostname: "localhost",
},
{
protocol: "http",
hostname: "127.0.0.1",
},
{ protocol: "https", hostname: "*.contabostorage.com" },
{ protocol: "https", hostname: "*.amazonaws.com" },
{ protocol: "https", hostname: "*.digitaloceanspaces.com" },
{ protocol: "http", hostname: "localhost" },
{ protocol: "http", hostname: "127.0.0.1" },
],
// Don't proxy external images through Next.js server
// Avoids SSL cert issues with Contabo S3 (sin1.contabostorage.com)

View File

@@ -3,8 +3,8 @@
import { SettingsSidebar, PasswordSecurityForm } from '@/components/settings';
export default function PasswordSecurityPage() {
const handleSave = (data: { currentPassword: string; newPassword: string }) => {
console.log('Updating agent password:', data);
const handleSave = (_data: { currentPassword: string; newPassword: string }) => {
// TODO: call the change-password API. Do not log password payloads.
};
return (

View File

@@ -3,8 +3,8 @@
import { SettingsSidebar, PasswordSecurityForm } from '@/components/settings';
export default function UserPasswordSecurityPage() {
const handleSave = (data: { currentPassword: string; newPassword: string }) => {
console.log('Updating user password:', data);
const handleSave = (_data: { currentPassword: string; newPassword: string }) => {
// TODO: call the change-password API. Do not log password payloads.
};
return (

View File

@@ -31,7 +31,7 @@ interface ContactCta {
const defaultContactDetails: ContactDetails = {
title: 'Get In Touch',
description: 'Have a question about a property or need assistance? Fill out the form below and our team will get back to you shortly.',
email: '123support@gmail.com',
email: 'support@re-quest.com',
phone: '1234567890',
phoneHours: 'Mon-Fri 9am-6pm',
officeAddress: '123 Market Street',

View File

@@ -262,7 +262,7 @@ export default function FAQPage() {
Start Live Chat
</Link>
<a
href="mailto:support@requesn.com"
href="mailto:support@re-quest.com"
className="flex items-center justify-center gap-2 w-[174px] h-[51px] border border-[#00293d] rounded-[7px] font-fractul text-[16px] text-[#00293d] hover:bg-gray-50 transition-colors"
>
<Image

View File

@@ -158,12 +158,15 @@ export default function RootLayout({
<NotificationProvider />
{children}
</SessionProvider>
{/* Umami analytics — loaded after page becomes interactive */}
{/* Umami analytics — set NEXT_PUBLIC_UMAMI_URL and NEXT_PUBLIC_UMAMI_WEBSITE_ID to enable */}
{process.env.NEXT_PUBLIC_UMAMI_URL &&
process.env.NEXT_PUBLIC_UMAMI_WEBSITE_ID && (
<Script
src="https://analytics.superlabs.co/script.js"
data-website-id="00e1ce31-e174-4519-8b59-63e8d4556b01"
src={process.env.NEXT_PUBLIC_UMAMI_URL}
data-website-id={process.env.NEXT_PUBLIC_UMAMI_WEBSITE_ID}
strategy="afterInteractive"
/>
)}
{/* Microsoft Clarity */}
{process.env.NEXT_PUBLIC_CLARITY_ID && (
<Script id="ms-clarity" strategy="afterInteractive">

View File

@@ -477,10 +477,10 @@ export default function PrivacyPolicyPage() {
<p className="mb-1">
Email:{' '}
<a
href="mailto:request.sha@gmail.com"
href="mailto:support@re-quest.com"
className="text-[#e58625] underline hover:opacity-80"
>
request.sha@gmail.com
support@re-quest.com
</a>
</p>
<p>Address: 1975 Peralta Point, Colorado Springs, CO 80910</p>

View File

@@ -163,7 +163,7 @@ export default function TermsOfServicePage() {
<p className="font-serif text-[15px] leading-[24px] text-[#00293d] mb-4">
If you experience any threatening, abusive, or suspicious behavior from another user, please report the
interaction immediately using the in-app reporting feature or by contacting us at
officialteam.request@gmail.com. RE-Quest will investigate reported incidents and take appropriate action,
support@re-quest.com. RE-Quest will investigate reported incidents and take appropriate action,
which may include account suspension or referral to law enforcement.
</p>
@@ -464,7 +464,7 @@ export default function TermsOfServicePage() {
If you have any questions or concerns about these Terms, please contact us:
</p>
<p className="font-serif text-[15px] leading-[24px] text-[#00293d] mb-1">
<span className="font-bold">Email:</span> officialteam.request@gmail.com
<span className="font-bold">Email:</span> support@re-quest.com
</p>
<p className="font-serif text-[15px] leading-[24px] text-[#00293d]">
<span className="font-bold">Address:</span> 1975 Peralta Point, Colorado Springs, CO 80910

View File

@@ -270,10 +270,10 @@ export function SubscriptionForm() {
{/* Support Email */}
<Link
href="mailto:support@example.com"
href="mailto:support@re-quest.com"
className="font-serif font-bold text-[14px] text-[#e58625] underline hover:text-[#d47920] transition-colors"
>
support@example.com
support@re-quest.com
</Link>
</div>

View File

@@ -59,7 +59,7 @@ class SocketService {
}
// Extract base URL without /api/v1 path for Socket.io connection
const apiUrl = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:4000';
const apiUrl = process.env.NEXT_PUBLIC_API_URL || 'http://localhost:3001/api/v1';
const baseUrl = apiUrl.replace(/\/api\/v1\/?$/, '');
this.socket = io(baseUrl, {