Security hardening: 12 improvements across the stack

1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
This commit is contained in:
openhands committed 2026-07-04 18:52:00 +02:00
1 parent a1950e5b65
commit 5628e7d6b7
19 files changed
+370 -220

No files matched your search

+12
View File
@@ -2,6 +2,7 @@ import { redirect } from "next/navigation";
import { isStaff } from "@/lib/admin/is-staff";
import { auth } from "@/lib/auth";
import { siteSettings } from "@/lib/services/site-settings";
import { clientIp, rateLimit } from "@/lib/rate-limit";
export { isStaff };
@@ -31,3 +32,14 @@ export async function requireStaff(): Promise<StaffUser> {
username: session.user.name ?? "",
};
}
/**
* Like requireStaff but also rate-limits the action per staff user (30 requests
* per minute). Use on sensitive admin actions (ban, rank-change, settings edit).
*/
export async function requireStaffRateLimited(): Promise<StaffUser> {
const staff = await requireStaff();
const ip = await clientIp();
if (!rateLimit(`admin:${staff.id}:${ip}`, 30, 60_000).ok) redirect("/admin?error=ratelimit");
return staff;
}