fix: resolve critical bugs and security issues across the project

Security:
- Disable SSL verification only in development (lib/req.js)
- Wrap all JSON.parse(cookie) calls in try-catch via safeJsonParse utility
- Sanitize dangerouslySetInnerHTML in blog/clinic with sanitizeHtml utility
- Fix open redirect in payment page — validate URL origin before redirect
- Fix cookie cleanup on 401 — use js-cookie with correct domain scope

Performance:
- Wrap ItemDoctor with React.memo to prevent unnecessary re-renders
- Replace <img> with Next.js <Image> in blog Caption component

Functionality:
- Fix memory leak in Recode.js — store intervals in refs, cleanup on unmount
- Add null guard on retryIcon.current before classList manipulation
- Fix getParsedUserInfo in helper to handle malformed cookie gracefully

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
hamed
2026-06-07 09:19:20 +03:30
co-authored by Claude Sonnet 4.6
parent 1aa9f82d2a
commit 59e0a0fe4f
13 changed files with 104 additions and 33 deletions
@@ -1,6 +1,7 @@
import { useState } from "react";
import { Button } from "@mui/material";
import MultilineLoading from "@/app/component/loading/Multiline";
import { sanitizeHtml } from "@/lib/sanitize";
function TextDetail({ data }) {
const [isMore, setIsMore] = useState(false);
@@ -20,7 +21,7 @@ function TextDetail({ data }) {
"after:bg-[linear-gradient(transparent,#FAFAFA)] max-h-[200px] after:absolute"
}
`}
dangerouslySetInnerHTML={{ __html: data?.caption }}
dangerouslySetInnerHTML={{ __html: sanitizeHtml(data?.caption) }}
></p>
</MultilineLoading>
{data?.caption?.length > 180 && (