feat(auth): implement all 16 homepage/login/register review items
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m30s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 2m56s
Gitea Actions Runner Test / test-job (push) Successful in 1s
CI / check (push) Successful in 33s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Successful in 1m47s
CI / tests-ui (push) Successful in 2m30s
CI / preflight (push) Skipped
CI / deploy (push) Failing after 2m56s
- add countArticles() (published-only, mirrors news-list) and warm total_articles - localize homepage metadata; bind articleCount to both stats; unique photo alts - drop duplicate news date and the mascot preload priorities - extract shared AuthPageFrame/AuthUsersCards used by /login and /register - login: localized noindex metadata, session redirect via safeRedirectPath, ?from passthrough from proxy, unified auth roster cache keys, registered notice - register: localized metadata, session redirect to /me, unified cache keys - add resend-verification flow on /verify with rate-limited non-enumerable action - add safeRedirectPath() with unit tests - register form: live requirements checklist + password mismatch guard - login form: unverified state with resend-link CTA - honour prefers-reduced-motion in TypewriterText - add 6 translations across all 25 locales
This commit is contained in:
1 parent
8561c3f85e
commit
3933214953
43 files changed
+1037
-490
No files matched your search
@@ -0,0 +1,30 @@
|
||||
import { describe, expect, it } from "vitest";
|
||||
import { safeRedirectPath } from "./safe-redirect";
|
||||
|
||||
describe("safeRedirectPath", () => {
|
||||
it("keeps same-site destinations", () => {
|
||||
expect(safeRedirectPath("/admin/users")).toBe("/admin/users");
|
||||
expect(safeRedirectPath("/me")).toBe("/me");
|
||||
expect(safeRedirectPath("/login?from=%2Fadmin")).toBe(
|
||||
"/login?from=%2Fadmin",
|
||||
);
|
||||
expect(safeRedirectPath("/news/welcome#comments")).toBe(
|
||||
"/news/welcome#comments",
|
||||
);
|
||||
});
|
||||
|
||||
it("refuses cross-origin and non-path destinations", () => {
|
||||
expect(safeRedirectPath("//evil.example")).toBe("/me");
|
||||
expect(safeRedirectPath("/\\evil.example")).toBe("/me");
|
||||
expect(safeRedirectPath("https://evil.example")).toBe("/me");
|
||||
expect(safeRedirectPath("javascript:alert(1)")).toBe("/me");
|
||||
expect(safeRedirectPath("admin")).toBe("/me");
|
||||
});
|
||||
|
||||
it("treats a missing value as the fallback", () => {
|
||||
expect(safeRedirectPath(undefined)).toBe("/me");
|
||||
expect(safeRedirectPath(null)).toBe("/me");
|
||||
expect(safeRedirectPath("")).toBe("/me");
|
||||
expect(safeRedirectPath(undefined, "/admin")).toBe("/admin");
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,17 @@
|
||||
/**
|
||||
* Validate a post-login destination taken from the query string.
|
||||
*
|
||||
* The value ends up in `window.location.href`, so an unvalidated one turns the
|
||||
* sign-in form into an open redirect. Only same-site absolute paths pass:
|
||||
* `//host` and `/\host` are cross-origin in every browser, and anything without
|
||||
* a leading slash is not a path at all.
|
||||
*/
|
||||
export function safeRedirectPath(
|
||||
raw: string | null | undefined,
|
||||
fallback = "/me",
|
||||
): string {
|
||||
if (!raw) return fallback;
|
||||
if (!raw.startsWith("/")) return fallback;
|
||||
if (raw.startsWith("//") || raw.startsWith("/\\")) return fallback;
|
||||
return raw;
|
||||
}
|
||||
@@ -7,6 +7,7 @@ import { logger } from "@/lib/logger";
|
||||
import { apiCacheKey, redisCache } from "@/lib/redis-cache";
|
||||
import { cacheNews } from "@/lib/services/news-cache";
|
||||
import {
|
||||
countArticles,
|
||||
countOnline,
|
||||
countPhotos,
|
||||
countRooms,
|
||||
@@ -65,6 +66,11 @@ export async function warmPublicCaches(): Promise<void> {
|
||||
staleMs: COUNTER_TTL_MS,
|
||||
}),
|
||||
);
|
||||
await warm("total_articles", () =>
|
||||
cached("total_articles", COUNTER_TTL_MS, countArticles, {
|
||||
staleMs: COUNTER_TTL_MS,
|
||||
}),
|
||||
);
|
||||
await warm("online_users", () =>
|
||||
cached("online_users", ONLINE_TTL_MS, listOnlineUsers, {
|
||||
staleMs: 15_000,
|
||||
|
||||
@@ -14,6 +14,7 @@ const tables = vi.hoisted(() => ({
|
||||
User: { name: "users" },
|
||||
Rooms: { name: "rooms" },
|
||||
CameraWeb: { name: "camera_web" },
|
||||
WebsiteArticles: { name: "website_articles" },
|
||||
}));
|
||||
|
||||
vi.mock("@/lib/db", () => {
|
||||
@@ -48,6 +49,7 @@ vi.mock("@/lib/db", () => {
|
||||
});
|
||||
|
||||
import {
|
||||
countArticles,
|
||||
countOnline,
|
||||
countPhotos,
|
||||
countRooms,
|
||||
@@ -98,3 +100,11 @@ it("keeps the online count exact", async () => {
|
||||
state.exact = 12;
|
||||
expect(await countOnline()).toBe(12);
|
||||
});
|
||||
|
||||
it("counts the articles table, not the news preview it renders from", async () => {
|
||||
// The homepage shows a total article count while the news panel beside it
|
||||
// only ever receives the four latest rows — the two must not be conflated.
|
||||
state.perTable = { website_articles: 42, users: 7 };
|
||||
expect(await countArticles()).toBe(42);
|
||||
expect(await countUsers()).toBe(7);
|
||||
});
|
||||
@@ -1,7 +1,7 @@
|
||||
import "server-only";
|
||||
|
||||
import { count, eq } from "drizzle-orm";
|
||||
import { CameraWeb, db, Rooms, User } from "@/lib/db";
|
||||
import { and, count, eq, or, sql } from "drizzle-orm";
|
||||
import { CameraWeb, db, Rooms, User, WebsiteArticles } from "@/lib/db";
|
||||
|
||||
/**
|
||||
* Row counters for the public homepage.
|
||||
@@ -40,6 +40,27 @@ export async function countPhotos(): Promise<number> {
|
||||
return row?.total ?? 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Published articles only — the same filter `getNewsList` renders from, so the
|
||||
* "Articles" figure on the homepage can never disagree with the news section
|
||||
* that sits next to it.
|
||||
*/
|
||||
export async function countArticles(): Promise<number> {
|
||||
const [row] = await db
|
||||
.select({ total: count() })
|
||||
.from(WebsiteArticles)
|
||||
.where(
|
||||
and(
|
||||
eq(WebsiteArticles.status, "published"),
|
||||
or(
|
||||
sql`${WebsiteArticles.publishAt} IS NULL`,
|
||||
sql`${WebsiteArticles.publishAt} <= NOW()`,
|
||||
),
|
||||
),
|
||||
);
|
||||
return row?.total ?? 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* Online users is deliberately *not* estimated: it is read from an index over a
|
||||
* small subset of rows, it is the one counter people watch closely, and being a
|
||||
|
||||
Reference in new issue
Block a user