Skip to content

LOTTO v1.24.1 — Security patch

Choose a tag to compare

@MattGeiger MattGeiger released this 25 Aug 06:46
· 80 commits to main since this release

LOTTO v1.24.1 is a security patch. It closes the two exploitable Auth.js weaknesses in LOTTO's own code rather than waiting on an upstream upgrade, and removes a development-only tool from the production dependency tree.

Production advisories: 16 → 9 (3 critical / 11 high / 2 moderate → 3 critical / 6 high)

Security

  • Authorization gate no longer fails open. src/proxy.ts is the single authorization check in front of every gated API prefix, and it tested session truthiness alone. Auth.js can resolve auth() to an error-carrying object rather than null when the configuration factory throws, so that check could treat a failed configuration as an authenticated session. The gate now requires a populated session.user. (GHSA-8fpg-xm3f-6cx3)
  • Admin email authorization resists Unicode confusables. Non-ASCII characters are screened on the raw address before normalization, and NFKC normalization now runs before validation rather than after. Confusables such as U+FF20 FULLWIDTH COMMERCIAL AT collapse into a plain @, so a check applied after normalization cannot see the characters it exists to reject. (GHSA-7rqj-j65f-68wh)
  • react-email moved to devDependencies. It is a preview CLI that no source file or script imports; the shipped runtime library is @react-email/components. This removed socket.io, engine.io, ws, minimatch, ajv, and fast-uri from the production tree, clearing 7 advisories with no runtime change.

Compatibility

No client-side code changed. Of the 48 built client chunks, 47 are byte-identical to v1.24.0; the sole difference is the inlined package.json metadata. Hydration was verified against the deployed build on a simulated iPad mini 4 running iOS 15.4, matching the declared support floor in docs/BROWSER_SUPPORT.md.

Deferred

next, next-auth, nodemailer, and sharp upgrades are held for a separate release. Each ships code into the client bundle or conflicts with a declared peer range, and requires device verification against the iOS 15 support floor. See CHANGELOG.md for the reasoning on each.

Full changelog: v1.24.0...v1.24.1