{{ $update->description }}
diff --git a/app/Http/Controllers/UpdateController.php b/app/Http/Controllers/UpdateController.php index 7a7f248..795292e 100644 --- a/app/Http/Controllers/UpdateController.php +++ b/app/Http/Controllers/UpdateController.php @@ -44,8 +44,8 @@ public function store(Request $request): RedirectResponse $this->authorize('manage-updates'); $request->validate([ - 'description' => 'required|string', - 'link' => 'nullable|url', + 'description' => ['required', 'string', 'max:5000'], + 'link' => ['nullable', 'url:http,https', 'max:255'], ]); Update::create($request->only('description', 'link')); diff --git a/app/Models/Update.php b/app/Models/Update.php index 5b33f8d..df821a7 100644 --- a/app/Models/Update.php +++ b/app/Models/Update.php @@ -23,4 +23,17 @@ class Update extends Model 'description', 'link', ]; + + /** + * Return only browser-safe external links, including for legacy records. + */ + public function safeExternalLink(): ?string + { + $link = trim((string) $this->link); + $scheme = strtolower((string) parse_url($link, PHP_URL_SCHEME)); + + return $link !== '' && in_array($scheme, ['http', 'https'], true) + ? $link + : null; + } } diff --git a/resources/views/dashboard.blade.php b/resources/views/dashboard.blade.php index 81524f7..517d74a 100644 --- a/resources/views/dashboard.blade.php +++ b/resources/views/dashboard.blade.php @@ -182,6 +182,7 @@ @if ($updates->isNotEmpty())
{{ $update->description }}