← back to Hospitalitywallpaper
fix: safeImg allow same-origin /img/ proxy urls (vendor-neutral image proxy 2026-06-03) — product cards were falling back to hero-bg (images all wrong)
56ed2de46ec9aaf91c01880b65f6235ca6907b73 · 2026-06-18 09:04:26 -0700 · Steve Abrams
Files touched
M public/index.htmlM server.js
Diff
commit 56ed2de46ec9aaf91c01880b65f6235ca6907b73
Author: Steve Abrams <steve@designerwallcoverings.com>
Date: Thu Jun 18 09:04:26 2026 -0700
fix: safeImg allow same-origin /img/ proxy urls (vendor-neutral image proxy 2026-06-03) — product cards were falling back to hero-bg (images all wrong)
---
public/index.html | 6 ++++--
server.js | 55 ++++++++++++++++++++++++++++++++++++++++++++++++-------
2 files changed, 52 insertions(+), 9 deletions(-)
diff --git a/public/index.html b/public/index.html
index 3390716..c78cef8 100644
--- a/public/index.html
+++ b/public/index.html
@@ -574,8 +574,10 @@ function cleanSku(s){
var V=/(?:^|-)(versace|kravet|fentucci|sandberg|harlequin|blithfield|westport|thibaut|koroseal|schumacher|scalamandre|fromental|dedar|carnegie|marburg|fabricut|coordonne|nina-campbell|lee-jofa(?:-modern)?|clarke(?:-and)?-clarke|clarke|brunschwig(?:-and)?(?:-fils)?|designers-guild|graham-(?:and-)?brown|andrew-martin|candice-olson|ronald-redding|jeffrey-stevens|sister-parish|arte-international|wolf-gordon|phillip-jeffries|cole-(?:and-)?son|maya-romanoff|g-p-j-baker|les-ensembliers|breegan(?:-jane)?)(?:-\\d+)?(?=-|$)/gi;
return String(s||'').replace(V,'').replace(/--+/g,'-').replace(/^-+|-+$/g,'');
}
-// Image-URL allowlist: only DW Shopify CDN + designerwallcoverings.com (defends against XSS via crafted products.json)
-function safeImg(u) { return /^https:\/\/(?:cdn\.shopify\.com|designerwallcoverings\.com)\//.test(u || '') ? u : '/hero-bg.jpg'; }
+// Image-URL allowlist: same-origin proxied /img/ (vendor-neutral image proxy, 2026-06-03) +
+// DW Shopify CDN + designerwallcoverings.com (defends against XSS via crafted products.json).
+// /img/ is server-controlled same-origin (not protocol-relative, not a javascript: URI) so it's safe.
+function safeImg(u) { u = u || ''; return (/^\/img\//.test(u) || /^https:\/\/(?:cdn\.shopify\.com|designerwallcoverings\.com)\//.test(u)) ? u : '/hero-bg.jpg'; }
function cardHTML(p) {
const eager = state.page === 1;
return '<img loading="' + (eager ? 'eager' : 'lazy') + '"' + (eager ? ' fetchpriority="high"' : '') + ' src="' + escAttr(safeImg(p.image_url)) + '" alt="' + escAttr(p.title) + '">'
diff --git a/server.js b/server.js
index b407431..2a0445b 100644
--- a/server.js
+++ b/server.js
@@ -24,6 +24,51 @@ const siteCfg = JSON.parse(fs.readFileSync(path.join(__dirname, 'site.config.jso
const SITE_SLUG = siteCfg.slug || __SITE;
const SITE_RAILS = Array.isArray(siteCfg.rails) ? siteCfg.rails : [];
+// Read-time rail membership: a product belongs to a rail if its `aesthetic` OR
+// any `tag` equals the rail key (or a declared synonym). Sister-site catalogs
+// have a degenerate `aesthetic` (here: "all"), so naive
+// `p.aesthetic === key` matching collapses every rail to empty — the richer
+// signal lives in `tags`. Prefer the shared matcher on dev; fall back to a
+// self-contained copy on prod where the _shared/ tree isn't deployed.
+let railMatch;
+try {
+ railMatch = require('../_shared/rail-match');
+} catch (e) {
+ const norm = s => String(s == null ? '' : s).trim().toLowerCase();
+ const productInRail = (p, key, syn) => {
+ const vals = [norm(key)].concat((syn && Array.isArray(syn[key]) ? syn[key] : []).map(norm));
+ if (vals.includes(norm(p && p.aesthetic))) return true;
+ const tags = p && Array.isArray(p.tags) ? p.tags : [];
+ return tags.some(t => vals.includes(norm(t)));
+ };
+ railMatch = {
+ productInRail,
+ buildRails(products, railKeys, opts) {
+ opts = opts || {}; const syn = opts.synonyms || null;
+ const minShare = opts.minShare != null ? opts.minShare : 0.08;
+ const minItems = opts.minItems != null ? opts.minItems : 4;
+ const perRail = opts.perRail != null ? opts.perRail : 12;
+ const maxShare = opts.maxShare != null ? opts.maxShare : 0.99;
+ const list = Array.isArray(products) ? products : []; const N = list.length || 1; const out = [];
+ for (const key of (railKeys || [])) {
+ const m = list.filter(p => productInRail(p, key, syn)); const c = m.length;
+ if (c >= minItems && c / N >= minShare && c / N <= maxShare) out.push({ key, aesthetic: key, count: c, items: m.slice(0, perRail) });
+ }
+ return out;
+ },
+ railFacets(products, railKeys, syn) {
+ const list = Array.isArray(products) ? products : []; const f = {};
+ for (const key of (railKeys || [])) f[key] = list.filter(p => productInRail(p, key, syn || null)).length;
+ return f;
+ }
+ };
+}
+const { productInRail, buildRails, railFacets } = railMatch;
+// Synonyms come from the site's own config (prod-safe); the shared default map
+// is a dev-only convenience when _shared/ is present.
+let RAIL_SYN = siteCfg.railSynonyms || {};
+if (!siteCfg.railSynonyms) { try { RAIL_SYN = require('../_shared/rail-synonyms.json'); } catch (e) {} }
+
function isJunk(p) {
if (!p.image_url || !p.image_url.trim()) return true;
if (!p.handle && !p.sku) return true;
@@ -183,7 +228,7 @@ function filterProducts({ q, aesthetic, vendor } = {}, skip = null) {
const needle = String(q).toLowerCase();
list = list.filter(p => (p.title || '').toLowerCase().includes(needle) || (p.tags || []).some(t => t.toLowerCase().includes(needle)));
}
- if (skip !== 'aesthetic' && aesthetic && aesthetic !== 'all') list = list.filter(p => p.aesthetic === aesthetic);
+ if (skip !== 'aesthetic' && aesthetic && aesthetic !== 'all') list = list.filter(p => productInRail(p, aesthetic, RAIL_SYN));
if (skip !== 'vendor' && vendor && vendor !== 'all') list = list.filter(p => p.vendor === vendor);
return list;
}
@@ -201,12 +246,8 @@ app.get('/api/products', (req, res) => {
});
app.get('/api/sliders', (req, res) => {
- const out = [];
- for (const a of SITE_RAILS) {
- const items = PRODUCTS_NICHE.filter(p => p.aesthetic === a).slice(0, 12);
- if (items.length >= 4) out.push({ aesthetic: a, items });
- }
- res.json({ rails: out });
+ const rails = buildRails(PRODUCTS_NICHE, SITE_RAILS, { synonyms: RAIL_SYN });
+ res.json({ rails: rails.map(r => ({ aesthetic: r.aesthetic, items: r.items })) });
});
app.get('/api/facets', (req, res) => {
← 2b71a34 step2 vendor-leak fix: dual-key /sample resolver + handle_di
·
back to Hospitalitywallpaper
·
Mount new-arrivals promo strip (Tier B): require ../_shared/ fce81cd →