aboutsummaryrefslogtreecommitdiff
path: root/src/lib/Data/AniList/schedule.ts
diff options
context:
space:
mode:
authorFuwn <[email protected]>2026-04-18 08:55:09 +0000
committerFuwn <[email protected]>2026-04-18 08:55:09 +0000
commitd7d7a5f00be218540b98e4a923606cf57bbd23e9 (patch)
tree3088bb7b6fd844e3ba5b139b91090506af057132 /src/lib/Data/AniList/schedule.ts
parentfix(utility): treat .localhost subdomains as private in appOrigin (diff)
downloaddue.moe-d7d7a5f00be218540b98e4a923606cf57bbd23e9.tar.xz
due.moe-d7d7a5f00be218540b98e4a923606cf57bbd23e9.zip
fix(api): encode subsplease timezone to prevent query-param injection
The `tz` query value was interpolated raw into the upstream URL, letting callers append arbitrary query segments (e.g. `tz=foo&f=hax`). Wrap the value in encodeURIComponent and rename the local variable away from the banned `tz` abbreviation.
Diffstat (limited to 'src/lib/Data/AniList/schedule.ts')
0 files changed, 0 insertions, 0 deletions