Security: - Disable SSL verification only in development (lib/req.js) - Wrap all JSON.parse(cookie) calls in try-catch via safeJsonParse utility - Sanitize dangerouslySetInnerHTML in blog/clinic with sanitizeHtml utility - Fix open redirect in payment page — validate URL origin before redirect - Fix cookie cleanup on 401 — use js-cookie with correct domain scope Performance: - Wrap ItemDoctor with React.memo to prevent unnecessary re-renders - Replace <img> with Next.js <Image> in blog Caption component Functionality: - Fix memory leak in Recode.js — store intervals in refs, cleanup on unmount - Add null guard on retryIcon.current before classList manipulation - Fix getParsedUserInfo in helper to handle malformed cookie gracefully Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
19 lines
458 B
JavaScript
19 lines
458 B
JavaScript
import axios from "axios";
|
|
import https from "https";
|
|
|
|
const axiosInstance = axios.create({
|
|
...(process.env.NODE_ENV === "development" && {
|
|
httpsAgent: new https.Agent({ rejectUnauthorized: false }),
|
|
}),
|
|
});
|
|
|
|
export const fetchReq = async (url, headers) => {
|
|
try {
|
|
const response = await axiosInstance.get(url, headers);
|
|
return response.data;
|
|
} catch (error) {
|
|
console.error("fetchReq error:", error.message);
|
|
return null;
|
|
}
|
|
};
|