Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,4 @@
## 2025-02-20 - Insecure Random Number Generation for Coupon Codes
**Vulnerability:** Found `Math.random()` being used to generate coupon codes and store credit codes in `app/api/bargain/route.ts` and `lib/actions/admin.ts`. `Math.random()` is not cryptographically secure and its outputs can be predicted.
**Learning:** For any code that generates sensitive tokens like coupon codes, authentication tokens, or store credits, we need to ensure the source of randomness is cryptographically secure. The use of `Math.random()` in Next.js backend actions can expose financial endpoints to brute-force attacks if code generation becomes predictable.
**Prevention:** Use the Web Crypto API (`crypto.getRandomValues()`) or the Node.js `crypto` module (`crypto.randomBytes()`) for generation. Created a `generateSecureCode(prefix, length)` utility in `lib/utils.ts` to be used for all code generation.
8 changes: 2 additions & 6 deletions app/api/bargain/route.ts
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ import { db, user, coupons, bargainSessions, products, combos } from "@/lib/db";
import { and, eq, inArray } from "drizzle-orm";
import { headers } from "next/headers";
import { auth } from "@/lib/auth";
import { generateSecureCode } from "@/lib/utils";

export const maxDuration = 30;
const MAX_NEGOTIATION_ROUNDS = 10;
Expand All @@ -20,12 +21,7 @@ type BargainCartItem = {

// Generate unique coupon code
function generateCouponCode(): string {
const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
let code = "BRG-";
for (let i = 0; i < 6; i++) {
code += chars.charAt(Math.floor(Math.random() * chars.length));
}
return code;
return generateSecureCode("BRG-", 6);
}

function calculateCartRuleCap(cartTotal: number, isFirstTimeUser: boolean): number {
Expand Down
7 changes: 2 additions & 5 deletions lib/actions/admin.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import { products, productVariants, coupons, orders, orderItems } from "@/lib/db
import { requireAdmin } from "@/lib/auth-server";
import { eq, desc, sql, and, gte } from "drizzle-orm";
import { revalidatePath } from "next/cache";
import { generateSecureCode } from "@/lib/utils";

// ============================================
// PRODUCT ACTIONS
Expand Down Expand Up @@ -567,11 +568,7 @@ export async function issueStoreCredit(data: IssueStoreCreditInput) {
const creditAmount = Math.round(data.refundAmount * bonusMultiplier);

// Generate unique store credit code
const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
let code = "CREDIT-";
for (let i = 0; i < 8; i++) {
code += chars.charAt(Math.floor(Math.random() * chars.length));
}
const code = generateSecureCode("CREDIT-", 8);

// Set validity (30-60 days)
const validityDays = Math.min(Math.max(data.validityDays || 30, 30), 60);
Expand Down
11 changes: 11 additions & 0 deletions lib/utils.ts
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,14 @@ import { twMerge } from "tailwind-merge"
export function cn(...inputs: ClassValue[]) {
return twMerge(clsx(inputs))
}

export function generateSecureCode(prefix: string, length: number): string {
const chars = "ABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789";
const array = new Uint32Array(length);
crypto.getRandomValues(array);
let code = prefix;
for (let i = 0; i < length; i++) {
code += chars[array[i] % chars.length];
}
return code;
}