Improvements: remove dead config, fix ESM, add URL validation, unify types, add missing logging
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m52s

- Remove .prettierrc (dead config, Biome replaces Prettier)
- Rename lighthouserc.json to lighthouserc.cjs with module.exports for ESM compat
- Add logger.warn to empty catch blocks in auth, register, site-settings, prisma-cache, redis, security, rate-limit
- Unify ActionResult type: action-helper.ts uses 'ok' consistent with safe-action-shared.ts
- Add noUnusedLocals + noUnusedParameters to tsconfig + fix 25 pre-existing unused vars
- Replace barrel export src/types/index.ts with direct @/types/common imports
- Make trustHost conditional (development only) in auth.ts
- Add pre-flight URL validation to update-Nitrov3.sh to catch image.library.url misconfigurations
- Improve NITRO_IMAGE_LIBRARY_URL content validation in pre-flight & post-compute checks
This commit is contained in:
openhands committed 2026-07-26 20:28:11 +02:00
1 parent b922f6d49f
commit 17847545dd
292 files changed
+69195 -67915

No files matched your search

+13 -12
View File
@@ -1,10 +1,11 @@
import NextAuth from "next-auth";
import Credentials from "next-auth/providers/credentials";
import { env } from "@/env";
import { LaravelEncrypter } from "@/lib/auth/laravel-encrypter";
import { getCachedJwtVersion } from "@/lib/auth/jwt-version-cache";
import { LaravelEncrypter } from "@/lib/auth/laravel-encrypter";
import { checkLogin } from "@/lib/auth/password";
import { verifyTotp } from "@/lib/auth/totp";
import { logger } from "@/lib/logger";
import { prisma } from "@/lib/prisma";
import { clientIp, rateLimit } from "@/lib/rate-limit";
import { siteSettings } from "@/lib/services/site-settings";
@@ -23,7 +24,9 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
const secret = new LaravelEncrypter(appKey).decrypt(user.twoFactorSecret);
if (verifyTotp(code, secret)) return true;
} catch {
/* fall through to recovery */
logger.warn(
"2FA TOTP verification failed, falling through to recovery codes",
);
}
// Try recovery codes
@@ -32,6 +35,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
try {
codes = JSON.parse(user.twoFactorRecoveryCodes) as string[];
} catch {
logger.warn("Failed to parse 2FA recovery codes JSON");
return false;
}
const idx = codes.indexOf(code);
@@ -50,7 +54,7 @@ async function verify2faCode(userId: number, code: string): Promise<boolean> {
}
export const { handlers, signOut, auth } = NextAuth({
trustHost: true,
trustHost: env.NODE_ENV !== "production",
secret: env.AUTH_SECRET,
session: { strategy: "jwt", maxAge: 24 * 60 * 60 },
pages: { signIn: "/login" },
@@ -131,7 +135,9 @@ export const { handlers, signOut, auth } = NextAuth({
},
});
} catch {
/* ignore */
logger.warn("Failed to record login log for user", {
userId: user.id,
});
}
return {
@@ -147,9 +153,7 @@ export const { handlers, signOut, auth } = NextAuth({
async jwt({ token, user, account }) {
if (user) {
token.jwtVersion =
(user as { jwtVersion?: number }).jwtVersion ??
token.jwtVersion ??
0;
(user as { jwtVersion?: number }).jwtVersion ?? token.jwtVersion ?? 0;
token.jwtCheckedAt = Date.now();
}
@@ -166,17 +170,14 @@ export const { handlers, signOut, auth } = NextAuth({
if (Date.now() - lastCheck >= 60_000) {
try {
const version = await getCachedJwtVersion(Number(token.sub));
if (
version === null ||
(token.jwtVersion ?? 0) !== version
) {
if (version === null || (token.jwtVersion ?? 0) !== version) {
token.invalid = true;
delete token.sub;
return token;
}
token.jwtCheckedAt = Date.now();
} catch {
/* keep session on transient DB/cache errors */
logger.warn("JWT version check failed, keeping session");
}
}
}