From 47a9ac07fb4f6ea0c4649828b4bea556384dee7b Mon Sep 17 00:00:00 2001 From: MichalC <103170279+wSBMichalee@users.noreply.github.com> Date: Sat, 1 Aug 2026 13:24:41 +0200 Subject: [PATCH] feat: security audit, rate limiting, server-side pricing, html escaping and security headers --- .env.example | 6 ++ .gitignore | 1 + app/blog/[slug]/page.tsx | 13 +-- app/cennik-montazu/page.tsx | 3 +- app/klimatyzacja-do-biura/page.tsx | 3 +- app/klimatyzacja-do-domu/page.tsx | 3 +- app/klimatyzacja/[miasto]/page.tsx | 6 +- app/klimatyzacja/page.tsx | 3 +- app/klimatyzacja/wroclaw/[dzielnica]/page.tsx | 6 +- app/kontakt/actions.ts | 4 +- app/montaz-klimatyzacji/page.tsx | 3 +- app/pompy-ciepla/page.tsx | 3 +- app/serwis-daikin/page.tsx | 3 +- app/serwis-klimatyzacji/page.tsx | 3 +- app/serwis-lg/page.tsx | 3 +- app/serwis-mitsubishi/page.tsx | 3 +- app/serwis-samsung/page.tsx | 3 +- app/zamowienie/actions.ts | 89 +++++++++++++----- app/zapytanie-multisplit/actions.ts | 94 ++++++++----------- app/zgloszenie-awarii/actions.ts | 94 +++++++++++-------- components/ui/JsonLd.tsx | 2 +- lib/mail.ts | 17 ++++ lib/security.ts | 60 ++++++++++++ next.config.ts | 18 ++++ 24 files changed, 292 insertions(+), 151 deletions(-) create mode 100644 .env.example create mode 100644 lib/mail.ts create mode 100644 lib/security.ts diff --git a/.env.example b/.env.example new file mode 100644 index 0000000..64ebdaa --- /dev/null +++ b/.env.example @@ -0,0 +1,6 @@ +RESEND_API_KEY= +RESEND_FROM_EMAIL= +RESEND_TO_EMAIL= +NEXT_PUBLIC_RECAPTCHA_SITE_KEY= +RECAPTCHA_SECRET_KEY= +NEXT_PUBLIC_BASE_URL= diff --git a/.gitignore b/.gitignore index 4bb68e0..5355dde 100644 --- a/.gitignore +++ b/.gitignore @@ -32,6 +32,7 @@ yarn-error.log* # env files (can opt-in for committing if needed) .env* +!.env.example # vercel .vercel diff --git a/app/blog/[slug]/page.tsx b/app/blog/[slug]/page.tsx index d811660..5a11f3a 100644 --- a/app/blog/[slug]/page.tsx +++ b/app/blog/[slug]/page.tsx @@ -3,6 +3,7 @@ import Image from 'next/image'; import Link from 'next/link'; import { notFound } from 'next/navigation'; import { getPosts, getPostBySlug, getRelatedPosts } from '@/content/posts'; +import { JsonLd } from '@/components/ui/JsonLd'; import { CtaBanner } from '@/components/sections/CtaBanner'; import { Calendar, User, ArrowLeft, ArrowRight } from 'lucide-react'; import { companyDetails } from '@/content/company'; @@ -139,14 +140,8 @@ export default async function BlogPostPage({ params }: BlogPostPageProps) { return (
{/* Skrypty JSON-LD dla SEO */} -