diff --git a/drizzle/migrations/0034_acl_midrank_revoke.sql b/drizzle/migrations/0034_acl_midrank_revoke.sql
new file mode 100644
index 00000000..324f65f0
--- /dev/null
+++ b/drizzle/migrations/0034_acl_midrank_revoke.sql
@@ -0,0 +1,25 @@
+-- Repair the escalation introduced by 0018's rule 1 ("has admin.dashboard gets
+-- ALL admin.*"). Migrating 0011 grants admin.dashboard to every rank >= 6 so
+-- that the sidebar opens, which meant rank 6 silently acquired
+-- admin.permissions.manage, admin.rcon.execute, admin.settings.edit,
+-- admin.users.edit, admin.users.reset_password, admin.room.delete, ...
+--
+-- Rule 1 is narrowed to `admin.%.view` (read-only, all the sidebar needs) in
+-- both the migration set and the runtime repair action. This migration undoes
+-- the over-grant on databases that already ran 0018: every role below the top
+-- rank keeps dashboard + *.view and loses every other admin.* grant. Ranks
+-- that legitimately hold tools keep them, because rule 3 only targets
+-- rank >= 7 and those roles are not touched here.
+
+DELETE `amp`
+FROM `acl_model_permissions` `amp`
+JOIN `acl_roles` `ar`
+ ON `ar`.`id` = `amp`.`model_id`
+ AND `ar`.`model_type` = 'Role'
+ AND `amp`.`model_type` = 'Role'
+JOIN `acl_permissions` `ap`
+ ON `ap`.`id` = `amp`.`permission_id`
+WHERE `ap`.`slug` LIKE 'admin.%'
+ AND `ap`.`slug` NOT LIKE '%.view'
+ AND `ar`.`slug` REGEXP '^rank_[0-9]+$'
+ AND CAST(SUBSTRING(`ar`.`slug`, 7) AS UNSIGNED) < 7;
diff --git a/src/actions/admin-media.ts b/src/actions/admin-media.ts
index 02962c26..a050100e 100644
--- a/src/actions/admin-media.ts
+++ b/src/actions/admin-media.ts
@@ -4,11 +4,32 @@ import { mkdir, writeFile } from "node:fs/promises";
import path from "node:path";
import { revalidatePath } from "next/cache";
import { requirePermission } from "@/lib/admin/guard";
+import { validateSiteImageUpload } from "@/lib/images/site-image-upload";
import { MEDIA_ROOT, resolveMediaPath } from "@/lib/media-storage";
import { PERMS } from "@/lib/permissions";
-const MAX_SIZE = 5 * 1024 * 1024; // 5MB
-const ALLOWED = ["image/png", "image/jpeg", "image/gif", "image/webp"];
+/**
+ * Store an uploaded media file under MEDIA_ROOT.
+ *
+ * The extension always comes from the *detected* format (magic bytes + a full
+ * sharp decode), never from `file.name` or the browser-supplied MIME type:
+ * trusting either lets arbitrary bytes land on disk with an attacker-chosen name
+ * that the media route would then serve.
+ */
+async function storeUploadedMedia(
+ file: File,
+): Promise<{ ok: true; name: string } | { ok: false; error: string }> {
+ const validated = await validateSiteImageUpload(file);
+ if (!validated.success) return { ok: false, error: validated.error };
+ const baseDir = MEDIA_ROOT;
+ await mkdir(baseDir, { recursive: true });
+ const name = `${Date.now()}-${Math.random().toString(36).slice(2, 8)}.${validated.extension}`;
+ const filePath = resolveMediaPath(name);
+ if (!filePath.startsWith(baseDir + path.sep))
+ return { ok: false, error: "Invalid path" };
+ await writeFile(filePath, validated.bytes);
+ return { ok: true, name };
+}
export async function uploadMedia(
formData: FormData,
@@ -16,25 +37,9 @@ export async function uploadMedia(
await requirePermission(PERMS.PAGES_EDIT);
const file = formData.get("file") as File | null;
if (!file || file.size === 0) return { ok: false, error: "No file provided" };
- if (file.size > MAX_SIZE)
- return { ok: false, error: "File too large (max 5MB)" };
- if (!ALLOWED.includes(file.type))
- return {
- ok: false,
- error: "Invalid file type. Allowed: PNG, JPEG, GIF, WebP",
- };
- const baseDir = MEDIA_ROOT;
- // eslint-disable-next-line security/detect-non-literal-fs-filename
- await mkdir(baseDir, { recursive: true });
-
- const ext = file.name.split(".").pop() ?? "png";
- const name = `${Date.now()}-${Math.random().toString(36).slice(2, 8)}.${ext}`;
- const bytes = await file.arrayBuffer();
- const filePath = resolveMediaPath(name);
- if (!filePath.startsWith(baseDir + path.sep)) throw new Error("Invalid path");
- // eslint-disable-next-line security/detect-non-literal-fs-filename
- await writeFile(filePath, Buffer.from(bytes));
+ const stored = await storeUploadedMedia(file);
+ if (!stored.ok) return { ok: false, error: stored.error };
revalidatePath("/api/media");
revalidatePath("/admin/media");
@@ -45,6 +50,8 @@ export async function deleteMedia(name: string): Promise {
await requirePermission(PERMS.PAGES_EDIT);
const { unlink } = await import("node:fs/promises");
const baseDir = MEDIA_ROOT;
+ // A name that is not a bare file name never reaches the unlink.
+ if (name.includes("/") || name.includes("\\") || name.includes("..")) return;
const filePath = resolveMediaPath(name);
if (!filePath.startsWith(baseDir + path.sep)) return;
try {
@@ -62,22 +69,11 @@ export async function uploadMediaAndReturn(
await requirePermission(PERMS.PAGES_EDIT);
const file = formData.get("file") as File | null;
if (!file || file.size === 0) return "";
- if (file.size > MAX_SIZE) return "";
- if (!ALLOWED.includes(file.type)) return "";
- const baseDir = MEDIA_ROOT;
- // eslint-disable-next-line security/detect-non-literal-fs-filename
- await mkdir(baseDir, { recursive: true });
-
- const ext = file.name.split(".").pop() ?? "png";
- const name = `${Date.now()}-${Math.random().toString(36).slice(2, 8)}.${ext}`;
- const bytes = await file.arrayBuffer();
- const filePath = resolveMediaPath(name);
- if (!filePath.startsWith(baseDir + path.sep)) return "";
- // eslint-disable-next-line security/detect-non-literal-fs-filename
- await writeFile(filePath, Buffer.from(bytes));
+ const stored = await storeUploadedMedia(file);
+ if (!stored.ok) return "";
revalidatePath("/api/media");
revalidatePath("/admin/media");
- return `/api/media/${name}`;
+ return `/api/media/${stored.name}`;
}
diff --git a/src/actions/admin-settings.ts b/src/actions/admin-settings.ts
index 27a5396c..745c7381 100644
--- a/src/actions/admin-settings.ts
+++ b/src/actions/admin-settings.ts
@@ -14,10 +14,19 @@ import {
import { PERMS } from "@/lib/permissions";
import { clearOfficialHabboFurnidataCache } from "@/lib/services/habbo-furnidata-cache";
import { clearBadgeCache } from "@/lib/services/habboassets";
+import {
+ isSecretSettingKey,
+ SECRET_PLACEHOLDER,
+} from "@/lib/services/setting-secrets";
import { siteSettings } from "@/lib/services/site-settings";
const managedKeySet = new Set(MANAGED_SETTING_KEYS);
+// Raw keys only the CMS core is allowed to own. Writing an arbitrary key from
+// the generic "advanced key/value" form previously meant a staff member could
+// overwrite `turnstile_secret`, `force_staff_2fa` or `min_staff_rank`.
+const RAW_SETTING_KEY_RE = /^[a-z0-9][a-z0-9_.-]{0,127}$/;
+
function normalizeSettingValue(key: string, value: string): string {
if (key === HABBO_GAMEDATA_HOTEL_SETTING_KEY) {
return normalizeHabboGamedataHotel(value);
@@ -71,11 +80,12 @@ export async function updateSetting(formData: FormData): Promise {
const key = String(formData.get("key") ?? "")
.normalize("NFC")
.trim();
- const value = normalizeSettingValue(
- key,
- String(formData.get("value") ?? "").normalize("NFC"),
- );
- if (!key) return;
+ const raw = String(formData.get("value") ?? "").normalize("NFC");
+ if (!key || !RAW_SETTING_KEY_RE.test(key)) return;
+ // Blank on a secret means "keep what is stored", so the UI can render a
+ // placeholder without the risk of wiping the credential.
+ if (isSecretSettingKey(key) && raw === SECRET_PLACEHOLDER) return;
+ const value = isSecretSettingKey(key) ? raw : normalizeSettingValue(key, raw);
await db
.insert(WebsiteSetting)
.values({ key, value })
@@ -90,7 +100,7 @@ export async function createSetting(formData: FormData): Promise {
const key = String(formData.get("key") ?? "")
.normalize("NFC")
.trim()
- .slice(0, 255);
+ .slice(0, 128);
const value = normalizeSettingValue(
key,
String(formData.get("value") ?? "").normalize("NFC"),
@@ -99,7 +109,17 @@ export async function createSetting(formData: FormData): Promise {
.normalize("NFC")
.trim()
.slice(0, 255);
- if (!key) return;
+ // Managed keys go through `saveManagedSettings`; anything else must be a
+ // clearly namespaced custom key, and lockout/security settings are never
+ // writable through the free-form form.
+ if (!key || !RAW_SETTING_KEY_RE.test(key)) return;
+ if (
+ key === "force_staff_2fa" ||
+ key === "min_staff_rank" ||
+ key === "maintenance_enabled"
+ ) {
+ return;
+ }
await db
.insert(WebsiteSetting)
.values({ key, value, comment: comment || null })
diff --git a/src/actions/bulk-users.test.ts b/src/actions/bulk-users.test.ts
index 22f2124b..25946767 100644
--- a/src/actions/bulk-users.test.ts
+++ b/src/actions/bulk-users.test.ts
@@ -41,7 +41,11 @@ const {
});
vi.mock("@/lib/admin/guard", () => ({ requirePermission: vi.fn() }));
-vi.mock("@/lib/permissions", () => ({ PERMS: { USERS_EDIT: "users.edit" } }));
+vi.mock("@/lib/permissions", () => ({
+ PERMS: { USERS_EDIT: "users.edit" },
+ // Staff (rank 7) may act on anyone below the hotel's top rank.
+ getHighestRank: vi.fn(() => Promise.resolve(10)),
+}));
vi.mock("@/lib/db", () => ({
db: {
delete: vi.fn(() => ({ where: deleteWhere })),
@@ -109,7 +113,10 @@ beforeEach(() => {
onDuplicateKeyUpdate.mockResolvedValue([{ affectedRows: 1 }]);
updateWhere.mockResolvedValue([{ affectedRows: 1 }]);
selectLimit.mockResolvedValue([]);
- selectWhereResolved.mockResolvedValue([]);
+ // Rank rows for the per-id rank guard: every target sits below staff rank 7.
+ selectWhereResolved.mockResolvedValue([{ rank: 1 }]);
+ // Max slot of existing badges (consumed by the badge loop, not the guard).
+ selectWhereResolved.mockResolvedValueOnce([{ rank: 1 }]);
});
describe("bulkUnban", () => {
diff --git a/src/actions/bulk-users.ts b/src/actions/bulk-users.ts
index 1bd037fa..8fda80e6 100644
--- a/src/actions/bulk-users.ts
+++ b/src/actions/bulk-users.ts
@@ -1,6 +1,7 @@
"use server";
import { and, eq, inArray, max, sql } from "drizzle-orm";
+import { isDynamicSuperAdmin } from "@/lib/admin/authorization-policy";
import { requirePermission } from "@/lib/admin/guard";
import {
Ban,
@@ -11,18 +12,69 @@ import {
UsersCurrency,
UsersSettings,
} from "@/lib/db";
-import { PERMS } from "@/lib/permissions";
+import { getHighestRank, PERMS } from "@/lib/permissions";
import type { ActionResult } from "@/lib/safe-action-shared";
import { rcon } from "@/lib/services/rcon";
import { logStaffActivity } from "@/lib/services/staff-activity";
+/**
+ * Bulk actions are plain server actions whose arguments come from the client,
+ * so every one of them validates the payload and the target ranks first. The
+ * helpers below are the whole "is this allowed" contract.
+ */
+const MAX_BULK_USERS = 200;
+
+function parseUserIds(raw: unknown): number[] {
+ if (!Array.isArray(raw)) return [];
+ const ids = raw
+ .map((v) => (typeof v === "number" ? v : Number(v)))
+ .filter((v) => Number.isInteger(v) && v > 0);
+ return [...new Set(ids)].slice(0, MAX_BULK_USERS);
+}
+
+function toPositiveInt(raw: unknown): number | null {
+ const n = typeof raw === "number" ? raw : Number(raw);
+ return Number.isInteger(n) && n > 0 ? n : null;
+}
+
+function parseAmount(raw: unknown, max = 1_000_000): number | null {
+ const n = typeof raw === "number" ? raw : Number(raw);
+ return Number.isInteger(n) && n > 0 && n <= max ? n : null;
+}
+
+function parseDuration(raw: unknown): number {
+ const n = typeof raw === "number" ? raw : Number(raw);
+ return Number.isInteger(n) && n > 0 ? Math.min(n, 60 * 60 * 24 * 365) : 0;
+}
+
+async function guardBulkTargets(
+ staff: { id: number; rank: number },
+ userIds: number[],
+): Promise {
+ const highestRank = await getHighestRank();
+ const superAdmin = isDynamicSuperAdmin(staff.rank, highestRank);
+ if (superAdmin || userIds.length === 0) return;
+ const rows = await db
+ .select({ rank: User.rank })
+ .from(User)
+ .where(inArray(User.id, userIds));
+ const blocked = rows.filter((r) => r.rank >= staff.rank);
+ if (blocked.length > 0) {
+ throw new Error(
+ "Cannot act on a user at or above your rank — those ids were skipped",
+ );
+ }
+}
+
export async function bulkUnban({
userIds,
}: {
userIds: number[];
}): Promise> {
const staff = await requirePermission(PERMS.USERS_EDIT);
- const result = await db.delete(Ban).where(inArray(Ban.userId, userIds));
+ const ids = parseUserIds(userIds);
+ await guardBulkTargets(staff, ids);
+ const result = await db.delete(Ban).where(inArray(Ban.userId, ids));
const unbanned = Number(result[0]?.affectedRows ?? 0);
await logStaffActivity({
staffId: staff.id,
@@ -30,10 +82,7 @@ export async function bulkUnban({
description: `Unbanned ${unbanned} user(s)`,
targetType: "user",
});
- return {
- ok: true as const,
- data: { unbanned, total: userIds.length },
- };
+ return { ok: true as const, data: { unbanned, total: ids.length } };
}
export async function bulkBan({
@@ -46,10 +95,14 @@ export async function bulkBan({
duration: number;
}): Promise> {
const staff = await requirePermission(PERMS.USERS_EDIT);
+ const ids = parseUserIds(userIds);
+ const seconds = parseDuration(duration);
+ const reasonText = typeof reason === "string" ? reason.slice(0, 255) : "";
+ await guardBulkTargets(staff, ids);
const now = Math.floor(Date.now() / 1000);
let banned = 0;
- for (const userId of userIds) {
+ for (const userId of ids) {
try {
await db.insert(Ban).values({
userId,
@@ -57,8 +110,8 @@ export async function bulkBan({
machineId: "",
userStaffId: staff.id,
timestamp: now,
- banExpire: duration > 0 ? now + duration : 0,
- banReason: reason,
+ banExpire: seconds > 0 ? now + seconds : 0,
+ banReason: reasonText,
type: "account",
});
banned++;
@@ -92,33 +145,37 @@ export async function bulkGiveCurrency({
}>
> {
const staff = await requirePermission(PERMS.USERS_EDIT);
+ const ids = parseUserIds(userIds);
+ const value = parseAmount(amount);
+ if (!value) throw new Error("Invalid amount");
+ await guardBulkTargets(staff, ids);
let given = 0;
const failedIds: Array<{ userId: number; reason: string }> = [];
- for (const userId of userIds) {
+ for (const userId of ids) {
try {
if (type === "credits") {
await db
.update(User)
- .set({ credits: sql`${User.credits} + ${amount}` })
+ .set({ credits: sql`${User.credits} + ${value}` })
.where(eq(User.id, userId));
- await rcon.giveCredits(userId, amount);
+ await rcon.giveCredits(userId, value);
} else if (type === "pixels") {
await db
.insert(UsersCurrency)
- .values({ userId, type: 0, amount })
+ .values({ userId, type: 0, amount: value })
.onDuplicateKeyUpdate({
- set: { amount: sql`${UsersCurrency.amount} + ${amount}` },
+ set: { amount: sql`${UsersCurrency.amount} + ${value}` },
});
- await rcon.giveDuckets(userId, amount);
+ await rcon.giveDuckets(userId, value);
} else if (type === "points") {
await db
.insert(UsersCurrency)
- .values({ userId, type: 101, amount })
+ .values({ userId, type: 101, amount: value })
.onDuplicateKeyUpdate({
- set: { amount: sql`${UsersCurrency.amount} + ${amount}` },
+ set: { amount: sql`${UsersCurrency.amount} + ${value}` },
});
- await rcon.givePointsGotw(userId, amount);
+ await rcon.givePointsGotw(userId, value);
}
given++;
} catch {
@@ -129,7 +186,7 @@ export async function bulkGiveCurrency({
await logStaffActivity({
staffId: staff.id,
action: "bulk_give_currency",
- description: `Gave ${amount} ${type} to ${given} user(s)`,
+ description: `Gave ${value} ${type} to ${given} user(s)`,
targetType: "user",
});
return {
@@ -152,19 +209,21 @@ export async function bulkGiveBadge({
}>
> {
const staff = await requirePermission(PERMS.USERS_EDIT);
+ const ids = parseUserIds(userIds);
+ const code =
+ typeof badgeCode === "string" ? badgeCode.trim().slice(0, 64) : "";
+ if (!code) throw new Error("Invalid badge code");
+ await guardBulkTargets(staff, ids);
let given = 0;
const failedIds: Array<{ userId: number; reason: string }> = [];
- for (const userId of userIds) {
+ for (const userId of ids) {
try {
const [existing] = await db
.select({ id: UsersBadges.id })
.from(UsersBadges)
.where(
- and(
- eq(UsersBadges.userId, userId),
- eq(UsersBadges.badgeCode, badgeCode),
- ),
+ and(eq(UsersBadges.userId, userId), eq(UsersBadges.badgeCode, code)),
)
.limit(1);
if (!existing) {
@@ -173,8 +232,10 @@ export async function bulkGiveBadge({
.from(UsersBadges)
.where(eq(UsersBadges.userId, userId));
const slotId = (agg?.maxSlot ?? 0) + 1;
- await db.insert(UsersBadges).values({ userId, slotId, badgeCode });
- await rcon.giveBadge(userId, badgeCode);
+ await db
+ .insert(UsersBadges)
+ .values({ userId, slotId, badgeCode: code });
+ await rcon.giveBadge(userId, code);
}
given++;
} catch {
@@ -211,12 +272,17 @@ export async function bulkAdjustCurrency({
}>
> {
const staff = await requirePermission(PERMS.USERS_EDIT);
+ const ids = parseUserIds(userIds);
if (!Number.isFinite(amount) || amount === 0) {
return { ok: false as const, error: "Amount must be a non-zero number" };
}
+ if (Math.abs(Math.trunc(amount)) > 1_000_000) {
+ return { ok: false as const, error: "Amount is too large" };
+ }
+ await guardBulkTargets(staff, ids);
if (amount > 0) {
- const given = await bulkGiveCurrency({ userIds, amount, type });
+ const given = await bulkGiveCurrency({ userIds: ids, amount, type });
if (!given.ok) return given;
if (!given.data) {
return { ok: false as const, error: "Currency adjustment failed" };
@@ -235,7 +301,7 @@ export async function bulkAdjustCurrency({
let adjusted = 0;
const failedIds: Array<{ userId: number; reason: string }> = [];
- for (const userId of userIds) {
+ for (const userId of ids) {
try {
if (type === "credits") {
const [user] = await db
@@ -299,8 +365,11 @@ export async function setTradeLock({
untilUnix: number;
}): Promise> {
const staff = await requirePermission(PERMS.USERS_EDIT);
- const until = Math.max(0, Math.trunc(untilUnix));
+ const id = toPositiveInt(userId);
+ if (!id) return { ok: false as const, error: "Invalid user" };
+ const until = Math.max(0, Math.min(Math.trunc(untilUnix), 2_000_000_000));
const locked = until > 0;
+ await guardBulkTargets(staff, [id]);
const [user] = await db
.select({
@@ -309,7 +378,7 @@ export async function setTradeLock({
online: User.online,
})
.from(User)
- .where(eq(User.id, userId))
+ .where(eq(User.id, id))
.limit(1);
if (!user) {
return { ok: false as const, error: "User not found" };
@@ -331,7 +400,7 @@ export async function setTradeLock({
.where(eq(Sanctions.id, existing.id));
} else {
await tx.insert(Sanctions).values({
- habboId: userId,
+ habboId: id,
tradeLockedUntil: until,
reason: locked ? "Trade lock (CMS)" : "",
});
@@ -369,5 +438,5 @@ export async function setTradeLock({
targetId: userId,
});
- return { ok: true as const, data: { userId, untilUnix: until } };
+ return { ok: true as const, data: { userId: id, untilUnix: until } };
}
diff --git a/src/actions/commandocentrum.ts b/src/actions/commandocentrum.ts
index 56b9680a..92d243ab 100644
--- a/src/actions/commandocentrum.ts
+++ b/src/actions/commandocentrum.ts
@@ -7,12 +7,30 @@ import { db, queryRows, User } from "@/lib/db";
import { PERMS } from "@/lib/permissions";
import { adminAction } from "@/lib/safe-action";
import { ActionError, actionOk } from "@/lib/safe-action-shared";
+import { logAudit } from "@/lib/services/audit";
import { rcon } from "@/lib/services/rcon";
const PATH = "/admin/commandocentrum";
const RCON_FAIL = "RCON command failed. Is the emulator running?";
+/** Currency amounts are capped: unbounded values break the hotel economy. */
+const MAX_CURRENCY = 1_000_000;
+
+/** Every mutation here gets an audit entry; rank changes and RCON most of all. */
+function auditAction(
+ userId: number,
+ action: string,
+ targetId: number,
+ after: Record,
+): void {
+ try {
+ logAudit({ userId, action, target: "User", targetId, after });
+ } catch {
+ /* auditing must never fail the command it describes */
+ }
+}
+
async function requireRconOk(ok: boolean): Promise {
if (!ok) throw new ActionError(RCON_FAIL);
}
@@ -120,9 +138,16 @@ const giveCreditsSchema = z.object({
export const giveCredits = adminAction(
{ permission: PERMS.RCON_EXECUTE, schema: giveCreditsSchema },
async (ctx) => {
+ if (ctx.data.credits > MAX_CURRENCY) {
+ throw new ActionError(`Amount is too large (max ${MAX_CURRENCY})`);
+ }
await requireRconOk(
await rcon.giveCredits(ctx.data.userId, ctx.data.credits),
);
+ auditAction(Number(ctx.session.user.id), "give_credits", ctx.data.userId, {
+ userId: ctx.data.userId,
+ amount: ctx.data.credits,
+ });
revalidatePath(PATH);
return actionOk();
},
@@ -137,9 +162,16 @@ const giveAmountSchema = z.object({
export const giveDuckets = adminAction(
{ permission: PERMS.RCON_EXECUTE, schema: giveAmountSchema },
async (ctx) => {
+ if (ctx.data.amount > MAX_CURRENCY) {
+ throw new ActionError(`Amount is too large (max ${MAX_CURRENCY})`);
+ }
await requireRconOk(
await rcon.giveDuckets(ctx.data.userId, ctx.data.amount),
);
+ auditAction(Number(ctx.session.user.id), "give_duckets", ctx.data.userId, {
+ userId: ctx.data.userId,
+ amount: ctx.data.amount,
+ });
revalidatePath(PATH);
return actionOk();
},
@@ -149,9 +181,16 @@ export const giveDuckets = adminAction(
export const giveDiamonds = adminAction(
{ permission: PERMS.RCON_EXECUTE, schema: giveAmountSchema },
async (ctx) => {
+ if (ctx.data.amount > MAX_CURRENCY) {
+ throw new ActionError(`Amount is too large (max ${MAX_CURRENCY})`);
+ }
await requireRconOk(
await rcon.giveDiamonds(ctx.data.userId, ctx.data.amount),
);
+ auditAction(Number(ctx.session.user.id), "give_diamonds", ctx.data.userId, {
+ userId: ctx.data.userId,
+ amount: ctx.data.amount,
+ });
revalidatePath(PATH);
return actionOk();
},
diff --git a/src/actions/messenger.test.ts b/src/actions/messenger.test.ts
index 1864afaf..ef682f02 100644
--- a/src/actions/messenger.test.ts
+++ b/src/actions/messenger.test.ts
@@ -10,8 +10,13 @@ const state = vi.hoisted(() => ({
deletes: [] as unknown[],
affectedDelete: 1,
emptyDeleteResult: false,
+ isAllowed: vi.fn(async () => ({ ok: true })),
}));
+// The real moderation module loads the word filter through the (mocked) db,
+// which would silently change the rows the offline-message assertions read.
+vi.mock("@/lib/services/moderation", () => ({ isAllowed: state.isAllowed }));
+
vi.mock("@/lib/db", async () => {
const schema = await import("@/db/schema");
const { createFakeDb } = await import("@/test/fake-db");
@@ -315,6 +320,18 @@ describe("sendOfflineMessage", () => {
expect(redirected()).toBe("/messages?send_error=invalid");
});
+ it("rejects content blocked by the word filter before storing it", async () => {
+ state.friendships = [{ id: 1 }];
+ state.isAllowed.mockResolvedValue({ ok: false, reason: "bad" });
+ await redirects(() =>
+ sendOfflineMessage(fakeForm({ friendId: "2", message: "rude words" })),
+ );
+ expect(state.isAllowed).toHaveBeenCalledWith("rude words");
+ expect(state.inserts).toHaveLength(0);
+ expect(redirected()).toBe("/messages?send_error=invalid");
+ state.isAllowed.mockResolvedValue({ ok: true });
+ });
+
it("stores an offline message for a friend", async () => {
state.friendships = [{ id: 1 }];
await redirects(() =>
diff --git a/src/actions/messenger.ts b/src/actions/messenger.ts
index a3c55009..9e6b4311 100644
--- a/src/actions/messenger.ts
+++ b/src/actions/messenger.ts
@@ -12,6 +12,7 @@ import {
User,
} from "@/lib/db";
import { clientIp, rateLimit } from "@/lib/rate-limit";
+import { isAllowed } from "@/lib/services/moderation";
type FriendOutcome =
| "accepted"
@@ -376,6 +377,8 @@ export async function sendOfflineMessage(formData: FormData): Promise {
.limit(1);
if (!recipient) {
outcome = "invalid";
+ } else if (!(await isAllowed(message)).ok) {
+ outcome = "invalid";
} else {
await db.insert(MessengerOffline).values({
userId: friendId,
diff --git a/src/actions/password-reset.test.ts b/src/actions/password-reset.test.ts
index 906398cd..713e4543 100644
--- a/src/actions/password-reset.test.ts
+++ b/src/actions/password-reset.test.ts
@@ -1,14 +1,14 @@
// @ts-nocheck
import { beforeEach, describe, expect, it, vi } from "vitest";
-const { selectLimit, insertOnDup, mockSendMail, mockRedirect } = vi.hoisted(
- () => ({
+const { selectLimit, selectWhere, insertOnDup, mockSendMail, mockRedirect } =
+ vi.hoisted(() => ({
selectLimit: vi.fn(),
insertOnDup: vi.fn().mockResolvedValue({}),
+ selectWhere: vi.fn(() => Promise.resolve([] as Array<{ id: number }>)),
mockSendMail: vi.fn(),
mockRedirect: vi.fn(),
- }),
-);
+ }));
vi.mock("next/navigation", () => ({
redirect: (...args: unknown[]) => {
@@ -24,6 +24,17 @@ vi.mock("@/lib/db", () => {
from: vi.fn(() => ({
where: vi.fn(() => ({
limit: selectLimit,
+ // Matches the deterministic `.orderBy(asc(User.id))` list
+ // reads used to resolve duplicate addresses.
+ orderBy: vi.fn(() => ({
+ // biome-ignore lint/suspicious/noThenProperty: Drizzle query thenable mock
+ then(
+ resolve: (v: unknown) => void,
+ reject: (e: unknown) => void,
+ ) {
+ return Promise.resolve(selectWhere()).then(resolve, reject);
+ },
+ })),
})),
})),
})),
@@ -70,13 +81,14 @@ beforeEach(() => {
describe("requestReset", () => {
it("sends a reset email when the user exists", async () => {
selectLimit.mockResolvedValue([{ id: 1 }]);
+ selectWhere.mockResolvedValue([{ id: 1 }]);
const fd = new FormData();
fd.set("email", "user@example.com");
await expect(requestReset(fd)).rejects.toThrow("redirect");
- expect(selectLimit).toHaveBeenCalled();
+ expect(selectWhere).toHaveBeenCalled();
expect(insertOnDup).toHaveBeenCalled();
expect(mockSendMail).toHaveBeenCalledWith(
"user@example.com",
@@ -87,6 +99,7 @@ describe("requestReset", () => {
it("does not send email when user is not found", async () => {
selectLimit.mockResolvedValue([]);
+ selectWhere.mockResolvedValue([]);
const fd = new FormData();
fd.set("email", "unknown@example.com");
diff --git a/src/actions/password-reset.ts b/src/actions/password-reset.ts
index 3e760333..93794de5 100644
--- a/src/actions/password-reset.ts
+++ b/src/actions/password-reset.ts
@@ -1,11 +1,14 @@
"use server";
import { createHash, randomBytes, timingSafeEqual } from "node:crypto";
-import { eq } from "drizzle-orm";
+import { asc, eq } from "drizzle-orm";
import { redirect } from "next/navigation";
import { env } from "@/env";
+import { invalidateLoginCache } from "@/lib/auth/login-core";
import { hashPassword } from "@/lib/auth/password";
+import { revokeUserCredentials } from "@/lib/auth/session-revocation";
import { db, PasswordReset, User } from "@/lib/db";
+import { logger } from "@/lib/logger";
import { clientIp, rateLimit } from "@/lib/rate-limit";
import { logServerError } from "@/lib/server-log";
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
@@ -17,6 +20,17 @@ function sha256(s: string): string {
return createHash("sha256").update(s).digest("hex");
}
+/**
+ * Back to the reset form with a *code*, never with the human-readable message:
+ * a raw `?error=` value would be rendered on our own domain, which is a
+ * perfect phishing skeleton. The page maps each code to a translation.
+ */
+function errorRedirect(email: string, token: string, code: string): never {
+ return redirect(
+ `/reset?email=${encodeURIComponent(email)}&token=${encodeURIComponent(token)}&error=${code}`,
+ );
+}
+
export async function requestReset(formData: FormData): Promise {
const email = String(formData.get("email") ?? "")
.normalize("NFC")
@@ -40,12 +54,23 @@ export async function requestReset(formData: FormData): Promise {
// Always respond the same way so we don't reveal which emails exist.
if (allowed && /^[^@\s]+@[^@\s]+\.[^@\s]+$/.test(email)) {
try {
- const [user] = await db
+ const matches = await db
.select({ id: User.id })
.from(User)
.where(eq(User.mail, email))
- .limit(1);
+ .orderBy(asc(User.id));
+ if (matches.length > 1) {
+ logger.warn("Password reset address is not unique", {
+ email,
+ accountCount: matches.length,
+ using: matches[0]?.id,
+ });
+ }
+ const user = matches[0];
if (user) {
+ // Duplicate addresses exist on legacy databases; resetting the
+ // *oldest* account keeps the choice deterministic instead of
+ // "whatever row the engine returns first".
const token = randomBytes(32).toString("hex");
const hashed = sha256(token);
const createdAt = new Date();
@@ -80,13 +105,11 @@ export async function resetPassword(formData: FormData): Promise {
// Throttle reset attempts per IP (5 per 15 min) to prevent token brute-force.
if (!(await rateLimit(`resetpwd:${await clientIp()}`, 5, 15 * 60_000)).ok) {
- redirect(
- `/reset?email=${encodeURIComponent(email)}&token=${encodeURIComponent(token)}&error=${encodeURIComponent("Too many attempts — try again later")}`,
- );
+ redirect(errorRedirect(email, token, "ratelimit"));
}
- let error: string | null = null;
- if (password.length < 12) error = "Password must be at least 12 characters";
+ let error: "password" | "invalid" | "failed" | null = null;
+ if (password.length < 12) error = "password";
if (!error) {
try {
@@ -107,20 +130,29 @@ export async function resetPassword(formData: FormData): Promise {
row != null && a.length === b.length && timingSafeEqual(a, b);
if (!row || !fresh || !match) {
- error = "This reset link is invalid or has expired";
+ error = "invalid";
} else {
- const [user] = await db
+ const matches = await db
.select({ id: User.id })
.from(User)
.where(eq(User.mail, email))
- .limit(1);
+ .orderBy(asc(User.id));
+ const user = matches[0];
if (!user) {
- error = "Account not found";
+ error = "invalid";
} else {
- await db
- .update(User)
- .set({ password: await hashPassword(password) })
- .where(eq(User.id, user.id));
+ const newHash = await hashPassword(password);
+ // A password change has to end every existing session: the
+ // popular reason for resetting is a compromised account, and a
+ // stolen cookie/API token must not outlive the reset.
+ await Promise.all([
+ db
+ .update(User)
+ .set({ password: newHash })
+ .where(eq(User.id, user.id)),
+ revokeUserCredentials(user.id),
+ ]);
+ await invalidateLoginCache(email);
await db
.delete(PasswordReset)
.where(eq(PasswordReset.email, email))
@@ -132,14 +164,12 @@ export async function resetPassword(formData: FormData): Promise {
}
}
} catch {
- error = "Could not reset the password — try again";
+ error = "failed";
}
}
if (error) {
- redirect(
- `/reset?email=${encodeURIComponent(email)}&token=${encodeURIComponent(token)}&error=${encodeURIComponent(error)}`,
- );
+ redirect(errorRedirect(email, token, error));
}
redirect("/login?reset=1");
}
diff --git a/src/actions/permissions.ts b/src/actions/permissions.ts
index d75fe7e4..b9e996d1 100644
--- a/src/actions/permissions.ts
+++ b/src/actions/permissions.ts
@@ -175,8 +175,10 @@ export const setCmsPermissions = adminAction(
);
/**
- * Re-apply the same grant repair as migration 0018:
- * - ranks with admin.dashboard get all admin.*
+ * Re-apply the grant repair from migration 0018/0034:
+ * - ranks with admin.dashboard get all admin.*.view (read-only: the sidebar
+ * needs to open, nothing more — a blanket `admin.%` grant here is what
+ * promoted rank 6 to full admin)
* - ranks >= 6 get admin.*.view + dashboard
* - ranks >= 7 get edit/manage/execute tools used by the sidebar
*/
@@ -187,7 +189,9 @@ export const repairAdminNavAclGrants = adminAction(
INSERT INTO \`acl_model_permissions\` (\`model_type\`, \`model_id\`, \`permission_id\`)
SELECT 'Role', ar.id, ap.id
FROM \`acl_roles\` ar
- JOIN \`acl_permissions\` ap ON ap.slug LIKE 'admin.%'
+ -- View slugs only: widening this to all admin.* turned "can open the
+ -- panel" into "is a full admin" for every mid rank (see 0034).
+ JOIN \`acl_permissions\` ap ON ap.slug LIKE 'admin.%' AND ap.slug LIKE '%.view'
WHERE EXISTS (
SELECT 1
FROM \`acl_model_permissions\` amp
diff --git a/src/actions/rooms.test.ts b/src/actions/rooms.test.ts
index a10ce18a..8aa38669 100644
--- a/src/actions/rooms.test.ts
+++ b/src/actions/rooms.test.ts
@@ -76,14 +76,17 @@ describe("rooms actions", () => {
});
state.del.mockResolvedValue([{ affectedRows: 1 }]);
state.update.mockResolvedValue([{ affectedRows: 1 }]);
+ // The item/room ownership lookups must find their row.
+ state.roomRows = [{ name: "Lobby" }, { id: 4 }];
});
it("requires the ROOMS_EDIT permission for updateRoomItem", async () => {
- await updateRoomItem({ roomId: 9, itemId: 4, custom: "x" });
+ // `custom` is not an allow-listed column, so it must never reach `.set()`.
+ await updateRoomItem({ roomId: 9, itemId: 4, rot: 4, custom: "x" });
expect(state.requirePermission).toHaveBeenCalledWith("admin.room.edit");
expect(state.update).toHaveBeenCalledWith(
Items,
- { custom: "x" },
+ { rot: 4 },
expect.anything(),
);
expect(state.logStaffActivity).toHaveBeenCalledWith(
diff --git a/src/actions/rooms.ts b/src/actions/rooms.ts
index 6b14181b..51513834 100644
--- a/src/actions/rooms.ts
+++ b/src/actions/rooms.ts
@@ -9,16 +9,63 @@ import { rcon } from "@/lib/services/rcon";
import { logStaffActivity } from "@/lib/services/staff-activity";
import { notify } from "@/lib/services/webhook";
+// Only these columns may be patched from the client. Spreading the whole payload
+// into `.set()` let a caller rewrite roomId/userId/extraData of any row, which
+// is mass assignment and IDOR in one.
+const ROOM_ITEM_FIELDS = [
+ "wallPos",
+ "x",
+ "y",
+ "z",
+ "rot",
+ "extraData",
+ "wiredData",
+ "limitedData",
+ "guildId",
+] as const;
+
+const ROOM_FIELDS = ["name", "description", "state", "usersMax"] as const;
+
+function pickAllowed(
+ fields: Record,
+ allowed: readonly string[],
+): Record {
+ const out: Record = {};
+ for (const key of allowed) {
+ if (Object.hasOwn(fields, key) && fields[key] !== undefined) {
+ out[key] = fields[key];
+ }
+ }
+ return out;
+}
+
+function toPositiveInt(value: unknown): number | null {
+ const n = typeof value === "number" ? value : Number(value);
+ return Number.isInteger(n) && n > 0 ? n : null;
+}
+
export async function updateRoomItem(payload: Record) {
const staff = await requirePermission(PERMS.ROOMS_EDIT);
- const { roomId, itemId, ...data } = payload as {
- roomId: number;
- itemId: number;
- [key: string]: unknown;
- };
+ const roomId = toPositiveInt(payload.roomId);
+ const itemId = toPositiveInt(payload.itemId);
+ if (!roomId || !itemId) {
+ throw new Error("Invalid room or item id");
+ }
+ // The item must belong to the room the staff member is editing.
+ const [item] = await db
+ .select({ id: Items.id })
+ .from(Items)
+ .where(and(eq(Items.id, itemId), eq(Items.roomId, roomId)))
+ .limit(1);
+ if (!item) throw new Error("Item not found in this room");
+
await db
.update(Items)
- .set(data as Partial)
+ .set(
+ pickAllowed(payload, ROOM_ITEM_FIELDS) as Partial<
+ typeof Items.$inferInsert
+ >,
+ )
.where(eq(Items.id, itemId));
await logStaffActivity({
staffId: staff.id,
@@ -117,24 +164,20 @@ export async function deleteRoom({ id }: { id: number }) {
revalidatePath("/admin/rooms");
}
-export async function updateRoom({
- id,
- ...data
-}: {
- id: number;
- name?: string;
- description?: string;
- state?: string;
- usersMax?: number;
-}) {
+export async function updateRoom({ id, ...data }: Record) {
const staff = await requirePermission(PERMS.ROOMS_EDIT);
- await db.update(Rooms).set(data).where(eq(Rooms.id, id));
+ const roomId = toPositiveInt(id);
+ if (!roomId) throw new Error("Invalid room id");
+ await db
+ .update(Rooms)
+ .set(pickAllowed(data, ROOM_FIELDS) as Partial)
+ .where(eq(Rooms.id, roomId));
await logStaffActivity({
staffId: staff.id,
action: "room_update",
- description: `Updated room #${id}`,
+ description: `Updated room #${roomId}`,
targetType: "room",
- targetId: id,
+ targetId: roomId,
});
- revalidatePath(`/admin/rooms/${id}`);
+ revalidatePath(`/admin/rooms/${roomId}`);
}
diff --git a/src/actions/social.test.ts b/src/actions/social.test.ts
index 44e97de4..6d10a23b 100644
--- a/src/actions/social.test.ts
+++ b/src/actions/social.test.ts
@@ -14,8 +14,13 @@ const state = vi.hoisted(() => ({
selectQueue: [] as Queue,
rows: [] as Array>,
failInsert: false,
+ isAllowed: vi.fn(async () => ({ ok: true })),
}));
+// The real moderation module loads the word filter through the (mocked) db
+// select queue, which would shift the rows the forum assertions rely on.
+vi.mock("@/lib/services/moderation", () => ({ isAllowed: state.isAllowed }));
+
vi.mock("next/cache", () => ({ revalidatePath: state.revalidatePath }));
vi.mock("next/navigation", () => ({
redirect: (path: string) => {
@@ -210,6 +215,7 @@ describe("postThread", () => {
state.failInsert = false;
state.selectQueue = [];
state.rows = [];
+ state.isAllowed.mockResolvedValue({ ok: true });
state.transaction.mockImplementation(
async (fn: (tx: unknown) => Promise, txDb: unknown) => fn(txDb),
);
@@ -283,6 +289,18 @@ describe("postThread", () => {
expect(state.insert).not.toHaveBeenCalled();
});
+ it("rejects content blocked by the word filter before hitting the db", async () => {
+ state.isAllowed.mockResolvedValue({ ok: false, reason: "bad" });
+ state.selectQueue = [[{ id: 10 }]];
+ await expect(postThread(threadForm())).rejects.toThrow(
+ "/guilds/10/forum/new?error=invalid",
+ );
+ expect(state.isAllowed).toHaveBeenCalledWith(
+ "Welcome thread Hello from the community",
+ );
+ expect(state.insert).not.toHaveBeenCalled();
+ });
+
it("reports not_found when the guild does not exist", async () => {
state.selectQueue = [[]];
await expect(postThread(threadForm())).rejects.toThrow(
@@ -324,6 +342,7 @@ describe("replyToThread", () => {
state.failInsert = false;
state.selectQueue = [];
state.rows = [];
+ state.isAllowed.mockResolvedValue({ ok: true });
state.transaction.mockImplementation(
async (fn: (tx: unknown) => Promise, txDb: unknown) => fn(txDb),
);
@@ -361,6 +380,16 @@ describe("replyToThread", () => {
expect(state.update.mock.calls[0][1]).toMatchObject({ postsCount: 1 });
});
+ it("rejects a reply blocked by the word filter before hitting the db", async () => {
+ state.isAllowed.mockResolvedValue({ ok: false, reason: "bad" });
+ state.selectQueue = [[{ id: 20, locked: 0, postsCount: 3 }]];
+ await expect(replyToThread(replyForm())).rejects.toThrow(
+ "/guilds/10/forum/20?error=invalid",
+ );
+ expect(state.isAllowed).toHaveBeenCalledWith("A thoughtful reply");
+ expect(state.insert).not.toHaveBeenCalled();
+ });
+
it("rejects missing or non-positive ids by redirecting to /guilds", async () => {
await expect(replyToThread(replyForm({ guildId: "abc" }))).rejects.toThrow(
"/guilds",
diff --git a/src/actions/social.ts b/src/actions/social.ts
index 9dde1c08..98357a72 100644
--- a/src/actions/social.ts
+++ b/src/actions/social.ts
@@ -13,6 +13,7 @@ import {
MessengerFriendships,
} from "@/lib/db";
import { clientIp, rateLimit } from "@/lib/rate-limit";
+import { isAllowed } from "@/lib/services/moderation";
// Guild forum subjects are VARCHAR(255); the comment/message body lives in
// guilds_forums_comments.message which is TEXT. Keep the first post's message
@@ -235,6 +236,8 @@ export async function postThread(formData: FormData): Promise {
.slice(0, MESSAGE_MAX);
if (!subject || !message) {
outcome = "invalid";
+ } else if (!(await isAllowed(`${subject} ${message}`)).ok) {
+ outcome = "invalid";
} else {
const now = Math.floor(Date.now() / 1000);
@@ -326,6 +329,8 @@ export async function replyToThread(formData: FormData): Promise {
.slice(0, MESSAGE_MAX);
if (!message) {
outcome = "invalid";
+ } else if (!(await isAllowed(message)).ok) {
+ outcome = "invalid";
} else {
const now = Math.floor(Date.now() / 1000);
diff --git a/src/actions/twofactor.ts b/src/actions/twofactor.ts
index ab96bb36..40b1e1fb 100644
--- a/src/actions/twofactor.ts
+++ b/src/actions/twofactor.ts
@@ -78,6 +78,22 @@ async function verifyTwoFactorCode(
export async function beginTwoFactor(): Promise {
const id = await sessionUserId();
if (!env.APP_KEY) redirect("/settings/2fa?error=noappkey");
+
+ if (!(await rateLimit(`2fa-begin:${id}`, 5, 30_000)).ok)
+ redirect("/settings/2fa?error=ratelimit");
+
+ // Re-running this action while 2FA is confirmed would be a silent *downgrade*
+ // (the new secret is stored unconfirmed, and unconfirmed means "login gate
+ // off"), so the existing setup has to be disabled through the proper flow
+ // first: a valid code, not just an authenticated session.
+ const [current] = await db
+ .select({ twoFactorConfirmedAt: User.twoFactorConfirmedAt })
+ .from(User)
+ .where(eq(User.id, id))
+ .limit(1);
+ if (current?.twoFactorConfirmedAt)
+ redirect("/settings/2fa?error=alreadyenabled");
+
const secret = generateTotpSecret();
const encrypted = new LaravelEncrypter(env.APP_KEY).encrypt(secret);
const codes = generateRecoveryCodes();
@@ -104,12 +120,19 @@ export async function confirmTwoFactor(formData: FormData): Promise {
.normalize("NFC")
.trim();
- const { ok } = await verifyTwoFactorCode(id, code);
+ const { ok, updatedRecoveryCodes } = await verifyTwoFactorCode(id, code);
if (!ok) redirect("/settings/2fa?error=badcode");
+ // A recovery code spends itself on use, so persist the remainder together
+ // with the confirmation instead of dropping the caller's own update.
await db
.update(User)
- .set({ twoFactorConfirmedAt: new Date() })
+ .set({
+ twoFactorConfirmedAt: new Date(),
+ ...(updatedRecoveryCodes !== undefined
+ ? { twoFactorRecoveryCodes: updatedRecoveryCodes }
+ : {}),
+ })
.where(eq(User.id, id));
redirect("/settings/2fa?enabled=1");
}
diff --git a/src/actions/user-settings.test.ts b/src/actions/user-settings.test.ts
index 267f9572..a84cccc4 100644
--- a/src/actions/user-settings.test.ts
+++ b/src/actions/user-settings.test.ts
@@ -8,6 +8,7 @@ const state = vi.hoisted(() => ({
updateCall: undefined as unknown,
rconSetMotto: vi.fn(),
failDbUpdate: false,
+ isAllowed: vi.fn(async () => ({ ok: true })),
}));
const databaseErrorClass = vi.hoisted(
@@ -63,6 +64,10 @@ vi.mock("@/lib/services/rcon", () => ({
rcon: { setMotto: state.rconSetMotto },
}));
+vi.mock("@/lib/services/moderation", () => ({
+ isAllowed: state.isAllowed,
+}));
+
const mockRevalidatePath = vi.hoisted(() => vi.fn());
vi.mock("next/cache", () => ({ revalidatePath: mockRevalidatePath }));
@@ -98,6 +103,7 @@ beforeEach(() => {
state.updateCall = undefined;
state.rconSetMotto.mockResolvedValue(true);
state.failDbUpdate = false;
+ state.isAllowed.mockResolvedValue({ ok: true });
});
describe("updateMotto", () => {
@@ -141,6 +147,18 @@ describe("updateMotto", () => {
});
});
+describe("updateMotto word filter", () => {
+ it("rejects a motto blocked by the word filter before persisting", async () => {
+ state.isAllowed.mockResolvedValue({ ok: false, reason: "bad" });
+ await expect(updateMotto(mockingForm("bad motto"))).rejects.toThrow(
+ databaseErrorClass,
+ );
+ expect(state.isAllowed).toHaveBeenCalledWith("bad motto");
+ expect(state.updateCall).toBeUndefined();
+ expect(state.rconSetMotto).not.toHaveBeenCalled();
+ });
+});
+
describe("updateMottoAction", () => {
it("denies unauthenticated callers", async () => {
state.auth.mockResolvedValue(null);
diff --git a/src/actions/user-settings.ts b/src/actions/user-settings.ts
index 6174e95f..3d666ee4 100644
--- a/src/actions/user-settings.ts
+++ b/src/actions/user-settings.ts
@@ -6,6 +6,7 @@ import { z } from "zod";
import { db, User } from "@/lib/db";
import { actionOk, authAction } from "@/lib/foundation/action";
import { DatabaseError } from "@/lib/foundation/errors";
+import { isAllowed } from "@/lib/services/moderation";
import { rcon } from "@/lib/services/rcon";
const MOTTO_MAX = 127;
@@ -16,7 +17,14 @@ const mottoSchema = z.object({
.max(MOTTO_MAX, `Motto must be at most ${MOTTO_MAX} characters`),
});
+async function assertMottoAllowed(motto: string): Promise {
+ if (!(await isAllowed(motto)).ok) {
+ throw new DatabaseError("Motto not allowed");
+ }
+}
+
const updateMottoAction = authAction({ schema: mottoSchema }, async (ctx) => {
+ await assertMottoAllowed(ctx.data.motto);
try {
await db
.update(User)
diff --git a/src/actions/users.test.ts b/src/actions/users.test.ts
index 81047451..e53d5dbd 100644
--- a/src/actions/users.test.ts
+++ b/src/actions/users.test.ts
@@ -62,6 +62,9 @@ vi.mock("@/lib/permissions", () => ({
USERS_BAN: "users.ban",
USERS_RESET_PASSWORD: "users.reset_password",
},
+ // Staff in the fixtures is rank 7 and the hotel's top rank is 10, so rank
+ // guards act as "below-your-own-rank only".
+ getHighestRank: vi.fn(() => Promise.resolve(10)),
}));
vi.mock("@/lib/safe-action", () => ({
@@ -77,6 +80,10 @@ vi.mock("@/lib/services/audit", () => ({
logAudit: vi.fn(),
}));
+vi.mock("@/lib/auth/session-revocation", () => ({
+ revokeUserCredentials: vi.fn(() => Promise.resolve()),
+}));
+
vi.mock("@/lib/services/webhook", () => ({
notify: vi.fn(),
}));
diff --git a/src/actions/users.ts b/src/actions/users.ts
index d4526acc..c3b76875 100644
--- a/src/actions/users.ts
+++ b/src/actions/users.ts
@@ -3,8 +3,10 @@
import crypto from "node:crypto";
import { and, eq } from "drizzle-orm";
import { z } from "zod";
+import { isDynamicSuperAdmin } from "@/lib/admin/authorization-policy";
import { invalidateLoginCache } from "@/lib/auth";
import { hashPassword } from "@/lib/auth/password";
+import { revokeUserCredentials } from "@/lib/auth/session-revocation";
import {
Ban,
db,
@@ -13,7 +15,7 @@ import {
UsersCurrency,
UsersSettings,
} from "@/lib/db";
-import { PERMS } from "@/lib/permissions";
+import { getHighestRank, PERMS } from "@/lib/permissions";
import { adminAction } from "@/lib/safe-action";
import { ActionError, actionOk } from "@/lib/safe-action-shared";
import { logAudit } from "@/lib/services/audit";
@@ -54,8 +56,9 @@ export const createUser = adminAction(
{ permission: PERMS.USERS_EDIT, schema: createUserSchema },
async (ctx) => {
const { username, mail, password, rank, motto } = ctx.data;
-
- if (rank >= ctx.session.user.rank && ctx.session.user.rank < 7) {
+ const actorRank = ctx.session.user.rank;
+ const highestRank = await getHighestRank();
+ if (rank >= actorRank && !isDynamicSuperAdmin(actorRank, highestRank)) {
throw new ActionError("Cannot assign rank equal or higher than your own");
}
@@ -130,7 +133,7 @@ export const updateUser = adminAction(
if (
userData.rank !== undefined &&
userData.rank >= ctx.session.user.rank &&
- ctx.session.user.rank < 7
+ !isDynamicSuperAdmin(ctx.session.user.rank, await getHighestRank())
) {
throw new ActionError("Cannot assign rank equal or higher than your own");
}
@@ -144,7 +147,15 @@ export const updateUser = adminAction(
motto: string;
credits: number;
pixels: number;
+ mailVerified?: string;
}>;
+ // A changed address has to prove itself again: leaving mail_verified
+ // set would keep every mail send (resets, notifications) pointed at an
+ // inbox nobody confirmed, and would silently bypass the "verified
+ // accounts only" gate.
+ if (patch.mail !== undefined && patch.mail !== targetUser.mail) {
+ patch.mailVerified = "0";
+ }
if (Object.keys(patch).length > 0) {
await db.update(User).set(patch).where(eq(User.id, id));
}
@@ -331,7 +342,14 @@ async function guardRank(targetUserId: number, sessionRank: number) {
.where(eq(User.id, targetUserId))
.limit(1);
if (!target) throw new ActionError("User not found");
- if (target.rank >= sessionRank && sessionRank < 7) {
+ // The owner is whoever holds the hotel's highest rank *today*. The old
+ // `sessionRank < 7` shortcut handed every rank-7 account owner powers on
+ // any hotel whose top rank is 8+, which makes it a plain escalation.
+ const highestRank = await getHighestRank();
+ if (
+ target.rank >= sessionRank &&
+ !isDynamicSuperAdmin(sessionRank, highestRank)
+ ) {
throw new ActionError("Cannot modify user with equal or higher rank");
}
return target;
@@ -358,6 +376,9 @@ export const resetPassword = adminAction(
.update(User)
.set({ password: hashed })
.where(eq(User.id, ctx.data.userId));
+ // A staff-issued password must also end the user's live sessions: this
+ // action exists precisely for "account compromised" situations.
+ await revokeUserCredentials(ctx.data.userId);
invalidateLoginCache(target.username);
logAudit({
@@ -419,9 +440,19 @@ const alertUserSchema = z.object({
export const alertUser = adminAction(
{ permission: PERMS.USERS_EDIT, schema: alertUserSchema },
async (ctx) => {
+ const target = await guardRank(ctx.data.userId, ctx.session.user.rank);
const success = await rcon.alertUser(ctx.data.userId, ctx.data.message);
if (!success)
throw new ActionError("Failed to send alert. Is the emulator running?");
+
+ logAudit({
+ userId: ctx.session.user.id,
+ action: "user_alert",
+ target: "User",
+ targetId: ctx.data.userId,
+ after: { message: ctx.data.message, username: target.username },
+ });
+
return actionOk();
},
);
diff --git a/src/actions/verify.ts b/src/actions/verify.ts
index a950034e..7737f20a 100644
--- a/src/actions/verify.ts
+++ b/src/actions/verify.ts
@@ -36,6 +36,11 @@ export async function resendVerification(
if (!(await rateLimit(`verify:resend:${ip}`, 3, 10 * 60_000)).ok) {
return { ok: false, error: "rateLimited" };
}
+ // Same cooldown keyed on the address, so rotating IPs cannot be used to
+ // mail-bomb an arbitrary inbox with "verify your email".
+ if (!(await rateLimit(`verify:resend:email:${email}`, 3, 10 * 60_000)).ok) {
+ return { ok: false, error: "rateLimited" };
+ }
try {
const [user] = await db
diff --git a/src/app/(site)/apply/staff/page.tsx b/src/app/(site)/apply/staff/page.tsx
index cebae932..7aa7df45 100644
--- a/src/app/(site)/apply/staff/page.tsx
+++ b/src/app/(site)/apply/staff/page.tsx
@@ -110,7 +110,7 @@ export default async function ApplyStaffPage({
const appliedRankIds = new Set(myApps.map((a) => a.rankId));
return (
-
+
{submitted === "1" ? (
{t("success.submitted")}
@@ -233,6 +233,6 @@ export default async function ApplyStaffPage({
})}
)}
-
+
);
}
diff --git a/src/app/(site)/apply/team/page.tsx b/src/app/(site)/apply/team/page.tsx
index fad2aa3f..64d33ca2 100644
--- a/src/app/(site)/apply/team/page.tsx
+++ b/src/app/(site)/apply/team/page.tsx
@@ -89,7 +89,7 @@ export default async function ApplyTeamPage({
const appliedTeamIds = new Set(myApps.map((a) => a.rankId));
return (
-
+
{submitted === "1" ? (
{t("success.submitted")}
@@ -199,6 +199,6 @@ export default async function ApplyTeamPage({
})}
)}
-
+
);
}
diff --git a/src/app/(site)/badges/page.tsx b/src/app/(site)/badges/page.tsx
index 7c05d3b5..378014c4 100644
--- a/src/app/(site)/badges/page.tsx
+++ b/src/app/(site)/badges/page.tsx
@@ -30,7 +30,7 @@ export default async function BadgesPage() {
.catch(() => []);
return (
-
+
@@ -76,6 +76,6 @@ export default async function BadgesPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/banned/page.tsx b/src/app/(site)/banned/page.tsx
index 4df2bfa3..defad995 100644
--- a/src/app/(site)/banned/page.tsx
+++ b/src/app/(site)/banned/page.tsx
@@ -52,7 +52,7 @@ export default async function BannedPage() {
});
return (
-
+
{t("body")}
{reason ? (
@@ -65,6 +65,6 @@ export default async function BannedPage() {
{t("contactStaff")}
-
+
);
}
diff --git a/src/app/(site)/community/page.tsx b/src/app/(site)/community/page.tsx
index 63576e72..5c34743f 100644
--- a/src/app/(site)/community/page.tsx
+++ b/src/app/(site)/community/page.tsx
@@ -54,7 +54,7 @@ export default function CommunityPage() {
const t = useTranslations("pages.community");
return (
-
+
@@ -84,6 +84,6 @@ export default function CommunityPage() {
))}
-
+
);
}
diff --git a/src/app/(site)/developers/page.tsx b/src/app/(site)/developers/page.tsx
index b07f7565..29860ae6 100644
--- a/src/app/(site)/developers/page.tsx
+++ b/src/app/(site)/developers/page.tsx
@@ -398,7 +398,7 @@ export default function DevelopersPage() {
const totalEndpoints = GROUPS.reduce((n, g) => n + g.endpoints.length, 0);
return (
-
+
+
);
}
diff --git a/src/app/(site)/draw-badge/page.tsx b/src/app/(site)/draw-badge/page.tsx
index e1588657..798b7736 100644
--- a/src/app/(site)/draw-badge/page.tsx
+++ b/src/app/(site)/draw-badge/page.tsx
@@ -102,7 +102,7 @@ export default async function DrawBadgePage({
}
return (
-
+
+
);
}
diff --git a/src/app/(site)/events/[slugOrId]/page.tsx b/src/app/(site)/events/[slugOrId]/page.tsx
index 742942c8..74ca78dc 100644
--- a/src/app/(site)/events/[slugOrId]/page.tsx
+++ b/src/app/(site)/events/[slugOrId]/page.tsx
@@ -142,7 +142,7 @@ export default async function EventDetailPage({
else if (isFull) disabledReason = t("eventFull");
return (
-
+
{t("back")}
@@ -259,6 +259,6 @@ export default async function EventDetailPage({
) : null}
-
+
);
}
diff --git a/src/app/(site)/events/page.tsx b/src/app/(site)/events/page.tsx
index 42775135..f9ca1cb3 100644
--- a/src/app/(site)/events/page.tsx
+++ b/src/app/(site)/events/page.tsx
@@ -69,7 +69,7 @@ async function EventsPage({
const href = (page: number) =>
`/events?${new URLSearchParams({ status: result?.status ?? "all", week: result?.week ?? "", mine: params.mine ?? "", page: String(page) })}`;
return (
-
+
@@ -272,7 +272,7 @@ async function EventsPage({
)}
-
+
);
}
diff --git a/src/app/(site)/forgot/page.tsx b/src/app/(site)/forgot/page.tsx
index c32dfe64..a5f49250 100644
--- a/src/app/(site)/forgot/page.tsx
+++ b/src/app/(site)/forgot/page.tsx
@@ -1,3 +1,4 @@
+import type { Metadata } from "next";
import { headers } from "next/headers";
import { getTranslations } from "next-intl/server";
import { requestReset } from "@/actions/password-reset";
@@ -6,6 +7,15 @@ import Link from "@/components/link";
import { ContentCard } from "@/components/public/ui";
import { captchaConfig } from "@/lib/services/captcha";
+export async function generateMetadata(): Promise {
+ const t = await getTranslations("pages.forgot");
+ return {
+ title: t("title"),
+ description: t("subtitle"),
+ robots: { index: false, follow: false },
+ };
+}
+
export default async function ForgotPage({
searchParams,
}: {
@@ -17,12 +27,39 @@ export default async function ForgotPage({
const nonce = (await headers()).get("x-nonce") ?? undefined;
return (
-
+
{sent ? (
-
- {t("sentNotice")}
-
+ <>
+
+ {t("sentNotice")}
+
+ {/* A mail that never arrived must be retryable from here,
+ otherwise the visitor is stuck on a dead end. */}
+
+ >
) : (
-
+
);
}
diff --git a/src/app/(site)/friends/page.tsx b/src/app/(site)/friends/page.tsx
index 946b7241..fe686c53 100644
--- a/src/app/(site)/friends/page.tsx
+++ b/src/app/(site)/friends/page.tsx
@@ -102,7 +102,7 @@ export default async function FriendsPage({
: null;
return (
-
+
{removed === "1" ? (
{t("success.removed")}
@@ -180,6 +180,6 @@ export default async function FriendsPage({
)}
-
+
);
}
diff --git a/src/app/(site)/guilds/[id]/forum/[threadId]/page.tsx b/src/app/(site)/guilds/[id]/forum/[threadId]/page.tsx
index f5dc495a..ec41537b 100644
--- a/src/app/(site)/guilds/[id]/forum/[threadId]/page.tsx
+++ b/src/app/(site)/guilds/[id]/forum/[threadId]/page.tsx
@@ -103,11 +103,11 @@ export default async function GuildForumThreadPage({
} catch (error) {
publicReadFailure("guild.thread")(error);
return (
-
+
+
);
}
@@ -173,7 +173,7 @@ export default async function GuildForumThreadPage({
: null;
return (
-
+
{replied === "1" ? (
{t("success.replied")}
@@ -317,6 +317,6 @@ export default async function GuildForumThreadPage({
{t("loginToReply")}
{t("loginLink")}
)}
-
+
);
}
diff --git a/src/app/(site)/guilds/[id]/forum/new/page.tsx b/src/app/(site)/guilds/[id]/forum/new/page.tsx
index 452d4bba..1fae630a 100644
--- a/src/app/(site)/guilds/[id]/forum/new/page.tsx
+++ b/src/app/(site)/guilds/[id]/forum/new/page.tsx
@@ -70,7 +70,7 @@ export default async function NewThreadPage({
: null;
return (
-
+
{errorMessage ? (
{errorMessage}
@@ -132,6 +132,6 @@ export default async function NewThreadPage({
-
+
);
}
diff --git a/src/app/(site)/guilds/[id]/forum/page.tsx b/src/app/(site)/guilds/[id]/forum/page.tsx
index 106bf6d5..672824da 100644
--- a/src/app/(site)/guilds/[id]/forum/page.tsx
+++ b/src/app/(site)/guilds/[id]/forum/page.tsx
@@ -67,11 +67,11 @@ export default async function GuildForumPage({
} catch (error) {
publicReadFailure("guild.forum")(error);
return (
-
+
+
);
}
@@ -135,7 +135,7 @@ export default async function GuildForumPage({
const usernameById = new Map(users.map((u) => [u.id, u.username]));
return (
-
+
{posted === "1" ? (
{t("success.posted")}
@@ -240,6 +240,6 @@ export default async function GuildForumPage({
)}
-
+
);
}
diff --git a/src/app/(site)/guilds/[id]/page.tsx b/src/app/(site)/guilds/[id]/page.tsx
index 281b3f8c..bd15eba7 100644
--- a/src/app/(site)/guilds/[id]/page.tsx
+++ b/src/app/(site)/guilds/[id]/page.tsx
@@ -55,11 +55,11 @@ export default async function GuildPage({
} catch (error) {
publicReadFailure("guild.detail")(error);
return (
-
+
+
);
}
@@ -139,7 +139,7 @@ export default async function GuildPage({
const created = formatDate(new Date(guild.dateCreated * 1000), "date");
return (
-
+
{t("allGuilds")}
@@ -251,6 +251,6 @@ export default async function GuildPage({
)}
-
+
);
}
diff --git a/src/app/(site)/guilds/page.tsx b/src/app/(site)/guilds/page.tsx
index f700f58a..67330571 100644
--- a/src/app/(site)/guilds/page.tsx
+++ b/src/app/(site)/guilds/page.tsx
@@ -50,7 +50,7 @@ export default async function GuildsPage() {
const guilds = await getGuilds();
return (
-
+
@@ -98,6 +98,6 @@ export default async function GuildsPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/help/[category]/page.tsx b/src/app/(site)/help/[category]/page.tsx
index 0114203c..5ef771f5 100644
--- a/src/app/(site)/help/[category]/page.tsx
+++ b/src/app/(site)/help/[category]/page.tsx
@@ -103,7 +103,7 @@ export default async function HelpCategoryPage({
const hasButton = Boolean(cat.buttonText && cat.buttonText.trim() !== "");
return (
-
+
{t("back")}
@@ -162,6 +162,6 @@ export default async function HelpCategoryPage({
) : null}
-
+
);
}
diff --git a/src/app/(site)/help/page.tsx b/src/app/(site)/help/page.tsx
index 077b8bd3..06f4d42e 100644
--- a/src/app/(site)/help/page.tsx
+++ b/src/app/(site)/help/page.tsx
@@ -127,7 +127,7 @@ export default async function HelpCenterPage() {
}
return (
-
+
+
);
}
diff --git a/src/app/(site)/help/tickets/[id]/page.tsx b/src/app/(site)/help/tickets/[id]/page.tsx
index fe95b7db..59c2a1e3 100644
--- a/src/app/(site)/help/tickets/[id]/page.tsx
+++ b/src/app/(site)/help/tickets/[id]/page.tsx
@@ -157,7 +157,7 @@ export default async function HelpTicketDetailPage({
];
return (
-
+
{replied === "1" ? (
{t("success.replied")}
@@ -302,6 +302,6 @@ export default async function HelpTicketDetailPage({
{t("closedHint")}
)}
-
+
);
}
diff --git a/src/app/(site)/help/tickets/page.tsx b/src/app/(site)/help/tickets/page.tsx
index 17f0667a..44307317 100644
--- a/src/app/(site)/help/tickets/page.tsx
+++ b/src/app/(site)/help/tickets/page.tsx
@@ -67,7 +67,7 @@ export default async function HelpTicketsPage({
: null;
return (
-
+
{created === "1" ? (
{t("success.created")}
@@ -167,6 +167,6 @@ export default async function HelpTicketsPage({
)}
-
+
);
}
diff --git a/src/app/(site)/layout.tsx b/src/app/(site)/layout.tsx
index 4aa4b4ae..ab8bbfa9 100644
--- a/src/app/(site)/layout.tsx
+++ b/src/app/(site)/layout.tsx
@@ -31,19 +31,18 @@ export default async function SiteLayout({
return (
<>
- {session?.user?.id ? (
- <>
-
-
-
-
-
-
-
-
-
- >
- ) : null}
+ {/* Site chrome is public: hiding it all for anonymous visitors used to
+ strand them — from /news, /leaderboard or /shop there was no way to
+ reach any other page at all. */}
+
+
+
+
+
+
+
+
+
{
const t = await getTranslations("pages.leaderboard");
@@ -52,7 +53,17 @@ function formatValue(key: TabKey, value: number): string {
return value.toLocaleString();
}
-type Row = { username: string; look: string; value: number };
+type Row = { userId: number; username: string; look: string; value: number };
+
+/**
+ * Users who hid their wallet must not appear in the currency tabs: the profile
+ * page already honours that, and a leaderboard that ignores it makes the
+ * setting meaningless.
+ */
+async function withoutHiddenWallets(rows: Row[]): Promise
{
+ const privacy = await loadProfilePrivacyMap(rows.map((r) => r.userId));
+ return rows.filter((r) => privacy.get(r.userId)?.wallet !== false);
+}
async function loadCreditsRows(): Promise {
try {
@@ -62,6 +73,7 @@ async function loadCreditsRows(): Promise {
() =>
db
.select({
+ id: User.id,
username: User.username,
look: User.look,
credits: User.credits,
@@ -71,11 +83,14 @@ async function loadCreditsRows(): Promise {
.limit(20),
{ staleMs: 120000 },
);
- return users.map((u) => ({
- username: u.username,
- look: u.look,
- value: u.credits,
- }));
+ return await withoutHiddenWallets(
+ users.map((u) => ({
+ userId: u.id,
+ username: u.username,
+ look: u.look,
+ value: u.credits,
+ })),
+ );
} catch {
return [];
}
@@ -89,6 +104,7 @@ async function loadCurrencyRows(type: number): Promise {
() =>
db
.select({
+ userId: User.id,
username: User.username,
look: User.look,
value: UsersCurrency.amount,
@@ -99,7 +115,7 @@ async function loadCurrencyRows(type: number): Promise {
.orderBy(desc(UsersCurrency.amount))
.limit(20),
{ staleMs: 120000 },
- );
+ ).then(withoutHiddenWallets);
} catch {
return [];
}
@@ -116,6 +132,7 @@ async function loadSettingsRows(
() =>
db
.select({
+ userId: User.id,
username: User.username,
look: User.look,
value: column,
@@ -166,7 +183,7 @@ export default async function LeaderboardPage({
: null;
return (
-
+
+
);
}
diff --git a/src/app/(site)/login/page.tsx b/src/app/(site)/login/page.tsx
index 063ba05e..95b61337 100644
--- a/src/app/(site)/login/page.tsx
+++ b/src/app/(site)/login/page.tsx
@@ -1,4 +1,4 @@
-import { count, desc, eq } from "drizzle-orm";
+import { desc, eq } from "drizzle-orm";
import type { Metadata } from "next";
import { headers } from "next/headers";
import Image from "next/image";
@@ -13,9 +13,11 @@ import { SurfaceCard } from "@/components/surface-card";
import { auth } from "@/lib/auth";
import { safeRedirectPath } from "@/lib/auth/safe-redirect";
import { cached } from "@/lib/cache";
+
import { db, User } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
import { captchaConfig } from "@/lib/services/captcha";
+import { cachedOnlineCount } from "@/lib/services/public-counters";
import { siteSettings } from "@/lib/services/site-settings";
export async function generateMetadata(): Promise {
@@ -34,7 +36,11 @@ export async function generateMetadata(): Promise {
export default async function LoginPage({
searchParams,
}: {
- searchParams: Promise<{ from?: string; registered?: string }>;
+ searchParams: Promise<{
+ from?: string;
+ registered?: string;
+ reset?: string;
+ }>;
}) {
const t = await getTranslations("pages.login");
const [hotelName, cfg, logo] = await Promise.all([
@@ -53,19 +59,13 @@ export default async function LoginPage({
if (session?.user?.id) redirect(redirectTo);
const [online, recentUsers, latestUsers] = await Promise.all([
- cached("online_count", 10_000, () =>
- db
- .select({ total: count() })
- .from(User)
- .where(eq(User.online, "1"))
- .then((rows) => rows[0]?.total ?? 0),
- ).catch(() => 0),
+ cachedOnlineCount().catch(() => 0),
cached(
"auth_online_users",
10_000,
() =>
db
- .select({ username: User.username, look: User.look })
+ .select({ id: User.id, username: User.username, look: User.look })
.from(User)
.where(eq(User.online, "1"))
.limit(8),
@@ -76,7 +76,7 @@ export default async function LoginPage({
30_000,
() =>
db
- .select({ username: User.username, look: User.look })
+ .select({ id: User.id, username: User.username, look: User.look })
.from(User)
.orderBy(desc(User.accountCreated))
.limit(8),
@@ -96,6 +96,16 @@ export default async function LoginPage({
>
{t("registeredSuccess")}
+ ) : sp.reset === "1" ? (
+ // `?reset=1` comes from a successful password reset; saying so matters
+ // because the visitor just changed their password and a silent form
+ // reads like the reset failed.
+
+ {t("passwordChanged")}
+
) : undefined;
return (
diff --git a/src/app/(site)/logo/page.tsx b/src/app/(site)/logo/page.tsx
index dd38b84d..72aafa2c 100644
--- a/src/app/(site)/logo/page.tsx
+++ b/src/app/(site)/logo/page.tsx
@@ -30,7 +30,7 @@ export default async function LogoPage() {
),
);
return (
-
-
+
);
}
diff --git a/src/app/(site)/maintenance/page.tsx b/src/app/(site)/maintenance/page.tsx
index eecfe2be..ca3f4de1 100644
--- a/src/app/(site)/maintenance/page.tsx
+++ b/src/app/(site)/maintenance/page.tsx
@@ -14,7 +14,7 @@ export default async function MaintenancePage() {
]);
return (
-
+
+
);
}
diff --git a/src/app/(site)/marketplace/page.tsx b/src/app/(site)/marketplace/page.tsx
index 853ada5a..7ca2f601 100644
--- a/src/app/(site)/marketplace/page.tsx
+++ b/src/app/(site)/marketplace/page.tsx
@@ -82,7 +82,7 @@ export default async function MarketplacePage() {
const total = offers.reduce((sum, o) => sum + o.price, 0);
return (
-
+
)}
-
+
);
}
diff --git a/src/app/(site)/me/page.tsx b/src/app/(site)/me/page.tsx
index 8b27221a..5018ddf1 100644
--- a/src/app/(site)/me/page.tsx
+++ b/src/app/(site)/me/page.tsx
@@ -47,14 +47,14 @@ async function MePage({
data = await loadUserDashboard(userId);
} catch {
return (
-
+
{t("loadError")}
{t("retry")}
-
+
);
}
// Daily reward state (settings + schedule + the user's last claim). Never
@@ -63,14 +63,14 @@ async function MePage({
const user = data.userRows[0];
if (!user)
return (
-
+
{t("loadError")}
{t("login")}
-
+
);
const {
hotelName,
@@ -145,7 +145,7 @@ async function MePage({
? error
: "error";
return (
-
+
{claimed && (
{t("claimed")}
@@ -181,6 +181,8 @@ async function MePage({
width={100}
height={140}
className={styles.avatar}
+ loading="eager"
+ fetchPriority="high"
/>
{t("welcome", { hotel: hotelName })}
@@ -469,7 +471,7 @@ async function MePage({
-
+
);
}
diff --git a/src/app/(site)/messages/page.tsx b/src/app/(site)/messages/page.tsx
index d29f8334..0995a702 100644
--- a/src/app/(site)/messages/page.tsx
+++ b/src/app/(site)/messages/page.tsx
@@ -177,7 +177,7 @@ export default async function MessagesPage({
: null;
return (
-
+
{accepted === "1" ? (
{t("success.accepted")}
@@ -391,6 +391,6 @@ export default async function MessagesPage({
)}
-
+
);
}
diff --git a/src/app/(site)/news/[...slug]/page.tsx b/src/app/(site)/news/[...slug]/page.tsx
index 396da102..f0d6a743 100644
--- a/src/app/(site)/news/[...slug]/page.tsx
+++ b/src/app/(site)/news/[...slug]/page.tsx
@@ -94,7 +94,7 @@ async function ArticlePage({
} catch {
logger.error("Public article lookup failed", { module: "news" });
return (
-
+
+
);
}
if (!article) notFound();
@@ -159,7 +159,7 @@ async function ArticlePage({
: null;
return (
-
+
{comment === "posted" ? (
{t("success.posted")}
@@ -196,7 +196,16 @@ async function ArticlePage({
src={article.image}
alt=""
decoding="async"
- style={{ width: "100%", borderRadius: 10, margin: "0 0 1rem" }}
+ loading="eager"
+ // Reserve the box: an unbounded hero image shifts the whole
+ // article down once the bitmap decodes.
+ style={{
+ width: "100%",
+ aspectRatio: "16 / 9",
+ objectFit: "cover",
+ borderRadius: 10,
+ margin: "0 0 1rem",
+ }}
/>
) : null}
{/* Article body is rich HTML (atom uses TinyMCE) — sanitised server-side. */}
@@ -414,7 +423,7 @@ async function ArticlePage({
)}
-
+
);
}
diff --git a/src/app/(site)/news/page.tsx b/src/app/(site)/news/page.tsx
index d8b506b4..3e8d85e4 100644
--- a/src/app/(site)/news/page.tsx
+++ b/src/app/(site)/news/page.tsx
@@ -31,7 +31,7 @@ async function NewsPage({
`/news?${new URLSearchParams({ q: result?.search ?? params.q ?? "", order: result?.order ?? "newest", page: String(page) })}`;
return (
-
+
@@ -186,7 +186,7 @@ async function NewsPage({
)}
-
+
);
}
diff --git a/src/app/(site)/page.tsx b/src/app/(site)/page.tsx
index 548101ce..640d195a 100644
--- a/src/app/(site)/page.tsx
+++ b/src/app/(site)/page.tsx
@@ -1,4 +1,4 @@
-import { count, desc, eq } from "drizzle-orm";
+import { desc, eq } from "drizzle-orm";
import { ArrowRight, ChevronDown } from "lucide-react";
import type { Metadata } from "next";
import { headers } from "next/headers";
@@ -25,7 +25,9 @@ import { formatDate } from "@/lib/format-date";
import { resolveHotelName } from "@/lib/hotel-name";
import { captchaConfig } from "@/lib/services/captcha";
import { getNewsList } from "@/lib/services/news-list";
+import { loadProfilePrivacyMap } from "@/lib/services/profile-privacy";
import {
+ cachedOnlineCount,
countArticles,
countPhotos,
countRooms,
@@ -183,13 +185,7 @@ async function getHotelData() {
recentUsers,
recentPhotos,
] = await Promise.all([
- cached("online_count", 10_000, () =>
- db
- .select({ total: count() })
- .from(User)
- .where(eq(User.online, "1"))
- .then((rows) => rows[0]?.total ?? 0),
- ).catch(publicReadFailure("home.online")),
+ cachedOnlineCount().catch(publicReadFailure("home.online")),
cached("total_users", 300_000, countUsers, { staleMs: 300000 }).catch(
publicReadFailure("home.users"),
),
@@ -210,7 +206,7 @@ async function getHotelData() {
15_000,
() =>
db
- .select({ username: User.username, look: User.look })
+ .select({ id: User.id, username: User.username, look: User.look })
.from(User)
.where(eq(User.online, "1"))
.limit(12),
@@ -259,11 +255,22 @@ export default async function Home() {
totalPhotos,
articleCount,
articles,
- recentUsers,
+ recentUsers: rawRecentUsers,
recentPhotos,
logo,
} = await getHotelData();
+ // Users who hide their online state must not surface in the "who is online"
+ // rails on the homepage either.
+ const recentUserPrivacy = await loadProfilePrivacyMap(
+ (rawRecentUsers ?? []).map((u) => u.id),
+ );
+ const recentUsers =
+ rawRecentUsers === null
+ ? null
+ : rawRecentUsers.filter(
+ (u) => recentUserPrivacy.get(u.id)?.online !== false,
+ );
const captcha = await captchaConfig();
const nonce = (await headers()).get("x-nonce") ?? undefined;
diff --git a/src/app/(site)/photos/page.tsx b/src/app/(site)/photos/page.tsx
index 581a2a8d..8dd10b18 100644
--- a/src/app/(site)/photos/page.tsx
+++ b/src/app/(site)/photos/page.tsx
@@ -10,6 +10,7 @@ import { ContentCard, EmptyState } from "@/components/public/ui";
import { cached } from "@/lib/cache";
import { CameraWeb, db } from "@/lib/db";
import { formatDate } from "@/lib/format-date";
+import { loadProfilePrivacyMap } from "@/lib/services/profile-privacy";
import { publicReadFailure } from "@/lib/services/public-read";
export async function generateMetadata(): Promise
{
@@ -53,9 +54,16 @@ export default async function PhotosPage() {
photos = publicReadFailure("photos")(error);
}
+ // Users can hide their photos everywhere, not only on their profile.
+ const photoOwners = [...new Set((photos ?? []).map((p) => p.userId))];
+ const photoPrivacy = await loadProfilePrivacyMap(photoOwners);
+ const visiblePhotos = (photos ?? []).filter(
+ (p) => photoPrivacy.get(p.userId)?.photos !== false,
+ );
+
// Pre-shape for the client lightbox: translate captions server-side so the
// client component stays free of i18n/db dependencies.
- const items: LightboxPhoto[] = (photos ?? []).map((p) => ({
+ const items: LightboxPhoto[] = visiblePhotos.map((p) => ({
id: String(p.id),
url: p.url,
alt: t("photoAlt", { id: p.userId }),
@@ -64,7 +72,7 @@ export default async function PhotosPage() {
}));
return (
-
+
@@ -76,6 +84,6 @@ export default async function PhotosPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/polls/[id]/page.tsx b/src/app/(site)/polls/[id]/page.tsx
index 3c92de01..c23c894b 100644
--- a/src/app/(site)/polls/[id]/page.tsx
+++ b/src/app/(site)/polls/[id]/page.tsx
@@ -96,7 +96,7 @@ export default async function PollDetailPage({
}
return (
-
+
{t("back")}
@@ -248,6 +248,6 @@ export default async function PollDetailPage({
) : null}
-
+
);
}
diff --git a/src/app/(site)/polls/page.tsx b/src/app/(site)/polls/page.tsx
index be741d5d..88b10ee1 100644
--- a/src/app/(site)/polls/page.tsx
+++ b/src/app/(site)/polls/page.tsx
@@ -60,7 +60,7 @@ export default async function PollsPage() {
}));
return (
-
+
@@ -122,6 +122,6 @@ export default async function PollsPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/radio/apply/page.tsx b/src/app/(site)/radio/apply/page.tsx
index 8a9fae1b..11e77a42 100644
--- a/src/app/(site)/radio/apply/page.tsx
+++ b/src/app/(site)/radio/apply/page.tsx
@@ -65,7 +65,7 @@ export default async function RadioApplyPage({
: null;
return (
-
+
{submitted === "1" ? (
{t("success.submitted")}
@@ -199,6 +199,6 @@ export default async function RadioApplyPage({
-
+
);
}
diff --git a/src/app/(site)/radio/contests/[id]/page.tsx b/src/app/(site)/radio/contests/[id]/page.tsx
index 1a69893c..2da5705a 100644
--- a/src/app/(site)/radio/contests/[id]/page.tsx
+++ b/src/app/(site)/radio/contests/[id]/page.tsx
@@ -33,7 +33,7 @@ export default async function RadioContestDetailPage({
const active = contest.isActive ? "Active" : "Ended";
return (
-
+
← Back to contests
@@ -90,6 +90,6 @@ export default async function RadioContestDetailPage({
-
+
);
}
diff --git a/src/app/(site)/radio/contests/page.tsx b/src/app/(site)/radio/contests/page.tsx
index bdbfb02e..fcf9918e 100644
--- a/src/app/(site)/radio/contests/page.tsx
+++ b/src/app/(site)/radio/contests/page.tsx
@@ -23,7 +23,7 @@ export default async function RadioContestsPage() {
.catch(() => []);
return (
-
+
@@ -71,6 +71,6 @@ export default async function RadioContestsPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/radio/giveaways/[id]/page.tsx b/src/app/(site)/radio/giveaways/[id]/page.tsx
index 42cda4a7..8da0e570 100644
--- a/src/app/(site)/radio/giveaways/[id]/page.tsx
+++ b/src/app/(site)/radio/giveaways/[id]/page.tsx
@@ -38,7 +38,7 @@ export default async function RadioGiveawayDetailPage({
: null);
return (
-
+
← Back to giveaways
@@ -95,6 +95,6 @@ export default async function RadioGiveawayDetailPage({
-
+
);
}
diff --git a/src/app/(site)/radio/giveaways/page.tsx b/src/app/(site)/radio/giveaways/page.tsx
index e41dab47..e588f451 100644
--- a/src/app/(site)/radio/giveaways/page.tsx
+++ b/src/app/(site)/radio/giveaways/page.tsx
@@ -25,7 +25,7 @@ export default async function RadioGiveawaysPage() {
.catch(() => []);
return (
-
+
@@ -78,6 +78,6 @@ export default async function RadioGiveawaysPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/radio/leaderboard/page.tsx b/src/app/(site)/radio/leaderboard/page.tsx
index 2ecc2444..3ca9d8dd 100644
--- a/src/app/(site)/radio/leaderboard/page.tsx
+++ b/src/app/(site)/radio/leaderboard/page.tsx
@@ -38,7 +38,7 @@ export default async function RadioLeaderboardPage() {
const rows = await loadRows();
return (
-
+
@@ -85,6 +85,6 @@ export default async function RadioLeaderboardPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/radio/page.tsx b/src/app/(site)/radio/page.tsx
index 1aa6511b..8a3f8cc5 100644
--- a/src/app/(site)/radio/page.tsx
+++ b/src/app/(site)/radio/page.tsx
@@ -120,7 +120,7 @@ export default async function RadioPage() {
const isLive = Boolean(streamUrl);
return (
-
+
{/* ── Header: live stream + now playing ─────────────────────── */}
)}
-
+
);
}
diff --git a/src/app/(site)/radio/schedule/page.tsx b/src/app/(site)/radio/schedule/page.tsx
index c349c04a..417d0456 100644
--- a/src/app/(site)/radio/schedule/page.tsx
+++ b/src/app/(site)/radio/schedule/page.tsx
@@ -74,7 +74,7 @@ export default async function RadioSchedulePage() {
const hasAny = schedules.length > 0;
return (
-
+
@@ -126,6 +126,6 @@ export default async function RadioSchedulePage() {
)}
-
+
);
}
diff --git a/src/app/(site)/radio/shouts/page.tsx b/src/app/(site)/radio/shouts/page.tsx
index 92b6b573..4e591951 100644
--- a/src/app/(site)/radio/shouts/page.tsx
+++ b/src/app/(site)/radio/shouts/page.tsx
@@ -73,7 +73,7 @@ export default async function RadioShoutsPage({
: null;
return (
-
+
{posted === "1" ? (
{t("success.posted")}
@@ -166,6 +166,6 @@ export default async function RadioShoutsPage({
)}
-
+
);
}
diff --git a/src/app/(site)/rankings/page.tsx b/src/app/(site)/rankings/page.tsx
index 4982befb..5eadaffb 100644
--- a/src/app/(site)/rankings/page.tsx
+++ b/src/app/(site)/rankings/page.tsx
@@ -62,7 +62,7 @@ export default async function RankingsPage() {
}
return (
-
+
@@ -104,6 +104,6 @@ export default async function RankingsPage() {
)}
-
+
);
}
diff --git a/src/app/(site)/rares/[category]/page.tsx b/src/app/(site)/rares/[category]/page.tsx
index b06b65b3..16bc2f9e 100644
--- a/src/app/(site)/rares/[category]/page.tsx
+++ b/src/app/(site)/rares/[category]/page.tsx
@@ -96,7 +96,7 @@ export default async function RareCategoryPage({
badgeBase && cat.badge ? `${badgeBase}/${cat.badge}.gif` : "";
return (
-
+
+
);
}
diff --git a/src/app/(site)/rares/page.tsx b/src/app/(site)/rares/page.tsx
index 747b470b..f3bf3a3a 100644
--- a/src/app/(site)/rares/page.tsx
+++ b/src/app/(site)/rares/page.tsx
@@ -65,7 +65,7 @@ export default async function RareValuesPage() {
}
return (
-
+
{categories.length === 0 ? (
@@ -116,6 +116,6 @@ export default async function RareValuesPage() {
})}
)}
-
+
);
}
diff --git a/src/app/(site)/redeem/page.tsx b/src/app/(site)/redeem/page.tsx
index 1780a8f2..2fff790e 100644
--- a/src/app/(site)/redeem/page.tsx
+++ b/src/app/(site)/redeem/page.tsx
@@ -29,7 +29,7 @@ export default async function RedeemPage() {
if (!user) redirect("/login");
return (
-
+
@@ -63,6 +63,6 @@ export default async function RedeemPage() {
-
+
);
}
diff --git a/src/app/(site)/register/page.tsx b/src/app/(site)/register/page.tsx
index 3986735e..f23b753f 100644
--- a/src/app/(site)/register/page.tsx
+++ b/src/app/(site)/register/page.tsx
@@ -1,4 +1,4 @@
-import { count, desc, eq } from "drizzle-orm";
+import { desc, eq } from "drizzle-orm";
import type { Metadata } from "next";
import { headers } from "next/headers";
import Image from "next/image";
@@ -12,9 +12,11 @@ import { RegisterForm } from "@/components/auth/register-form";
import { SurfaceCard } from "@/components/surface-card";
import { auth } from "@/lib/auth";
import { cached } from "@/lib/cache";
+
import { db, User } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
import { captchaConfig } from "@/lib/services/captcha";
+import { cachedOnlineCount } from "@/lib/services/public-counters";
import { siteSettings } from "@/lib/services/site-settings";
export async function generateMetadata(): Promise {
@@ -42,19 +44,13 @@ export default async function RegisterPage() {
if (session?.user?.id) redirect("/me");
const [online, recentUsers, latestUsers] = await Promise.all([
- cached("online_count", 10_000, () =>
- db
- .select({ total: count() })
- .from(User)
- .where(eq(User.online, "1"))
- .then((rows) => rows[0]?.total ?? 0),
- ).catch(() => 0),
+ cachedOnlineCount().catch(() => 0),
cached(
"auth_online_users",
10_000,
() =>
db
- .select({ username: User.username, look: User.look })
+ .select({ id: User.id, username: User.username, look: User.look })
.from(User)
.where(eq(User.online, "1"))
.limit(8),
@@ -65,7 +61,7 @@ export default async function RegisterPage() {
30_000,
() =>
db
- .select({ username: User.username, look: User.look })
+ .select({ id: User.id, username: User.username, look: User.look })
.from(User)
.orderBy(desc(User.accountCreated))
.limit(8),
diff --git a/src/app/(site)/reset/page.tsx b/src/app/(site)/reset/page.tsx
index 54ac2a5a..d4e7c9a0 100644
--- a/src/app/(site)/reset/page.tsx
+++ b/src/app/(site)/reset/page.tsx
@@ -1,8 +1,26 @@
+import type { Metadata } from "next";
import { getTranslations } from "next-intl/server";
import { resetPassword } from "@/actions/password-reset";
import Link from "@/components/link";
import { ContentCard } from "@/components/public/ui";
+export async function generateMetadata(): Promise {
+ const t = await getTranslations("pages.reset");
+ return {
+ title: t("title"),
+ description: t("subtitle"),
+ // Single-use links: never indexable.
+ robots: { index: false, follow: false },
+ };
+}
+
+const ERROR_KEYS: Record = {
+ password: "passwordMinLength",
+ ratelimit: "tooManyAttempts",
+ invalid: "invalidLink",
+ failed: "failed",
+};
+
export default async function ResetPage({
searchParams,
}: {
@@ -10,9 +28,12 @@ export default async function ResetPage({
}) {
const t = await getTranslations("pages.reset");
const { email = "", token = "", error } = await searchParams;
+ // Only codes the action can produce are mapped — anything else stays silent
+ // instead of being echoed back onto our own domain.
+ const errorKey = error ? (ERROR_KEYS[error] ?? null) : null;
return (
-
+
- {error ? (
+ {errorKey ? (
- {error}
+ {t(errorKey)}
) : null}
{t("backToLogin")}
-
+
);
}
diff --git a/src/app/(site)/room/[id]/page.tsx b/src/app/(site)/room/[id]/page.tsx
index 995e1ad4..42cfe66c 100644
--- a/src/app/(site)/room/[id]/page.tsx
+++ b/src/app/(site)/room/[id]/page.tsx
@@ -101,7 +101,7 @@ export default async function RoomPage({
.filter(Boolean);
return (
-
+
← Back to the hotel
@@ -166,6 +166,6 @@ export default async function RoomPage({
Enter the hotel to visit {room.name || `room #${room.id}`} in 3D.
-
+
);
}
diff --git a/src/app/(site)/search/page.tsx b/src/app/(site)/search/page.tsx
index 808d7f08..8422c51f 100644
--- a/src/app/(site)/search/page.tsx
+++ b/src/app/(site)/search/page.tsx
@@ -5,6 +5,7 @@ import { LocalEventTime } from "@/components/public/local-event-time";
import { ContentCard, EmptyState } from "@/components/public/ui";
import { UserAvatarThumbnail } from "@/components/shared/user-avatar-thumbnail";
import { withPublicPagePerformance } from "@/lib/public-page-performance";
+import { loadProfilePrivacyMap } from "@/lib/services/profile-privacy";
import { loadPublicSearch } from "@/lib/services/public-search";
export async function generateMetadata(): Promise {
@@ -29,6 +30,11 @@ async function SearchPage({ searchParams }: { searchParams: Promise }) {
eventsPage: Number(params.eventsPage ?? 1),
});
const query = result?.query ?? "";
+ // Users who hide their online state must not have it surfaced here either —
+ // the listing, not just the profile, is what makes it enumerable.
+ const userRows =
+ result?.users.status === "fulfilled" ? result.users.value.rows : [];
+ const userPrivacy = await loadProfilePrivacyMap(userRows.map((u) => u.id));
const pagination = (
kind: "users" | "rooms" | "news" | "events",
data: { page: number; lastPage: number; total: number },
@@ -65,7 +71,7 @@ async function SearchPage({ searchParams }: { searchParams: Promise }) {
);
};
return (
-
+
>
)}
-
+
);
}
diff --git a/src/app/(site)/settings/2fa/page.tsx b/src/app/(site)/settings/2fa/page.tsx
index 3a3acbb5..39e3052f 100644
--- a/src/app/(site)/settings/2fa/page.tsx
+++ b/src/app/(site)/settings/2fa/page.tsx
@@ -73,7 +73,7 @@ export default async function TwoFactorPage({
}
return (
-
) : null}
+ {sp.error === "alreadyenabled" ? (
+
+ {t("alreadyEnabled")}
+
+ ) : null}
{!hasAppKey ? (
@@ -217,6 +222,6 @@ export default async function TwoFactorPage({
>
)}
-
+
);
}
diff --git a/src/app/(site)/settings/sessions/page.tsx b/src/app/(site)/settings/sessions/page.tsx
index 4d77c294..d025ff4e 100644
--- a/src/app/(site)/settings/sessions/page.tsx
+++ b/src/app/(site)/settings/sessions/page.tsx
@@ -78,7 +78,7 @@ export default async function SessionsPage({
}
return (
-
+
{signedOutAll === "1" ? (
) : null}
-
+
);
}
diff --git a/src/app/(site)/shop/page.tsx b/src/app/(site)/shop/page.tsx
index 36ab4053..1caa8884 100644
--- a/src/app/(site)/shop/page.tsx
+++ b/src/app/(site)/shop/page.tsx
@@ -154,7 +154,7 @@ export default async function ShopPage({
: undefined;
return (
-
+
{boughtMessage ? (
{boughtMessage}
@@ -340,6 +340,6 @@ export default async function ShopPage({
)}
-
+
);
}
diff --git a/src/app/(site)/shop/topup/page.tsx b/src/app/(site)/shop/topup/page.tsx
index b7904b9f..69d855ef 100644
--- a/src/app/(site)/shop/topup/page.tsx
+++ b/src/app/(site)/shop/topup/page.tsx
@@ -41,7 +41,7 @@ export default async function TopUpPage({
const rate = creditsPerUnit();
return (
-
+
{sp.status === "cancel" ? (
@@ -92,6 +92,6 @@ export default async function TopUpPage({
-
+
);
}
diff --git a/src/app/(site)/staff/page.tsx b/src/app/(site)/staff/page.tsx
index e6426b71..f80e6258 100644
--- a/src/app/(site)/staff/page.tsx
+++ b/src/app/(site)/staff/page.tsx
@@ -59,7 +59,7 @@ export default async function StaffPage() {
]);
return (
-
+
{t("title")}
@@ -151,6 +151,6 @@ export default async function StaffPage() {
)
)}
-
+
);
}
diff --git a/src/app/(site)/u/[username]/page.tsx b/src/app/(site)/u/[username]/page.tsx
index 07d5b619..883f24d9 100644
--- a/src/app/(site)/u/[username]/page.tsx
+++ b/src/app/(site)/u/[username]/page.tsx
@@ -338,7 +338,7 @@ async function ProfilePage({
const badgeByCode = new Map(badgeDetails.map((b) => [b.badgeKey, b]));
return (
-
+
{friend === "sent" ? (
{t("success.sent")}
@@ -373,6 +373,8 @@ async function ProfilePage({
width={100}
height={150}
className={styles.avatar}
+ loading="eager"
+ fetchPriority="high"
/>
{user.username}
@@ -692,7 +694,7 @@ async function ProfilePage({
-
+
);
}
diff --git a/src/app/(site)/verify/page.tsx b/src/app/(site)/verify/page.tsx
index 8023c2e0..87f9e74e 100644
--- a/src/app/(site)/verify/page.tsx
+++ b/src/app/(site)/verify/page.tsx
@@ -1,5 +1,6 @@
-import { eq } from "drizzle-orm";
+import { asc, eq } from "drizzle-orm";
import { CheckCircle2, Clock, MailX } from "lucide-react";
+import type { Metadata } from "next";
import { getTranslations } from "next-intl/server";
import { ResendVerificationForm } from "@/components/auth/resend-verification-form";
import Link from "@/components/link";
@@ -7,6 +8,16 @@ import { SurfaceCard } from "@/components/surface-card";
import { isValidVerificationToken } from "@/lib/auth/email-verification";
import { db, User } from "@/lib/db";
+export async function generateMetadata(): Promise
{
+ const t = await getTranslations("pages.verify");
+ return {
+ title: t("verifiedTitle"),
+ description: t("invalidSubtitle"),
+ // Token links are single-use; the page itself has nothing to index.
+ robots: { index: false, follow: false },
+ };
+}
+
type Status = "verified" | "already" | "invalid" | "unavailable";
function StatusCard({
@@ -31,7 +42,7 @@ function StatusCard({
const tint = tintMap[color] ?? tintMap.blue;
return (
-
+
-
+
);
}
@@ -98,11 +109,14 @@ export default async function VerifyPage({
const ok = await isValidVerificationToken(normalisedEmail, token);
if (ok) {
try {
- const [user] = await db
+ // Legacy databases allow duplicate addresses; always resolve the
+ // oldest account so the link cannot verify a different one.
+ const matches = await db
.select({ id: User.id, mailVerified: User.mailVerified })
.from(User)
.where(eq(User.mail, normalisedEmail))
- .limit(1);
+ .orderBy(asc(User.id));
+ const user = matches[0];
if (!user) {
status = "invalid";
} else if (user.mailVerified === "1") {
@@ -173,6 +187,21 @@ export default async function VerifyPage({
{t("unavailableBody")}
+ {/* Transient failure: offer both the retry path and the way out
+ instead of leaving the visitor stranded on this card. */}
+
+
+ {t("backToLogin")}
+
)}
diff --git a/src/app/admin-next/hotel/nitro-cleanup/page.tsx b/src/app/admin-next/hotel/nitro-cleanup/page.tsx
index 676d1da4..1458582c 100644
--- a/src/app/admin-next/hotel/nitro-cleanup/page.tsx
+++ b/src/app/admin-next/hotel/nitro-cleanup/page.tsx
@@ -1,5 +1,11 @@
+import { AdminToaster } from "@/components/admin/admin-toaster";
import { NitroCleanupPanel } from "@/components/admin/studio/nitro-cleanup-panel";
export default function HousekeepingHotelNitroCleanupPage() {
- return
;
+ return (
+ <>
+
+
+ >
+ );
}
diff --git a/src/app/admin/layout.tsx b/src/app/admin/layout.tsx
index 992cce7b..6c101c82 100644
--- a/src/app/admin/layout.tsx
+++ b/src/app/admin/layout.tsx
@@ -6,6 +6,7 @@ import type { ReactNode } from "react";
import { AdminHubChrome } from "@/components/admin/admin-hub-chrome";
import { AdminMobileWrapper } from "@/components/admin/admin-mobile-wrapper";
import { AdminSidebarNav } from "@/components/admin/admin-sidebar-nav";
+import { AdminToaster } from "@/components/admin/admin-toaster";
import { AdminTopbar } from "@/components/admin/admin-topbar";
import { LanguageSwitcher } from "@/components/language-switcher";
import Link from "@/components/link";
@@ -54,6 +55,7 @@ export default async function AdminLayout({
+
>
);
}
diff --git a/src/app/admin/logs/_lib/load-ignored-logs.ts b/src/app/admin/logs/_lib/load-ignored-logs.ts
index 5476b236..d4586ce3 100644
--- a/src/app/admin/logs/_lib/load-ignored-logs.ts
+++ b/src/app/admin/logs/_lib/load-ignored-logs.ts
@@ -32,7 +32,8 @@ function parsePageParams(
) {
const sp = new URLSearchParams(rawParams);
const parsed = parseListParams(sp);
- const perPage = Number(rawParams.perPage) || defaultPerPage;
+ // parseListParams clamps perPage to 1..100 — use it instead of the raw value.
+ const perPage = parsed.perPage || defaultPerPage;
return { search: parsed.search.trim(), page: parsed.page, perPage };
}
@@ -63,8 +64,10 @@ async function loadLogList(
rawParams,
input.defaultPerPage ?? 50,
);
- const offset = (page - 1) * perPage;
- const like = `%${search}%`;
+ // Cap the offset: `?page=1000000` otherwise builds a multi-hundred-million
+ // row scan before returning an empty page.
+ const offset = Math.min((page - 1) * perPage, 100_000);
+ const like = `%${search.slice(0, 100)}%`;
const where = search ? sql`WHERE ${spec.searchWhere(like)}` : sql``;
const [rawRowsResult, countRows] = await Promise.all([
diff --git a/src/app/admin/radio/settings/page.tsx b/src/app/admin/radio/settings/page.tsx
index c8e80d76..30f2ff48 100644
--- a/src/app/admin/radio/settings/page.tsx
+++ b/src/app/admin/radio/settings/page.tsx
@@ -7,7 +7,7 @@ import { StatusCard } from "@/components/admin/dashboard";
import { Button } from "@/components/ui/button";
import { db, WebsiteSetting } from "@/lib/db";
-type Field = { key: string; comment: string };
+type Field = { key: string; comment: string; secret?: boolean };
type Group = { title: string; fields: Field[] };
const GROUPS: Group[] = [
@@ -19,7 +19,11 @@ const GROUPS: Group[] = [
{ key: "radio_stream_backup_url", comment: "Backup stream URL" },
{ key: "radio_azurecast_base_url", comment: "AzureCast base URL" },
{ key: "radio_azurecast_station_id", comment: "AzureCast station ID" },
- { key: "radio_azurecast_api_key", comment: "AzureCast API key" },
+ {
+ key: "radio_azurecast_api_key",
+ comment: "AzureCast API key",
+ secret: true,
+ },
{ key: "radio_azurecast_port", comment: "AzureCast stream port" },
{
key: "radio_azurecast_protocol",
@@ -41,9 +45,14 @@ const GROUPS: Group[] = [
{
key: "radio_sambroadcaster_password",
comment: "Sambroadcaster password",
+ secret: true,
},
{ key: "radio_virtual_dj_url", comment: "Virtual DJ URL" },
- { key: "radio_virtual_dj_password", comment: "Virtual DJ password" },
+ {
+ key: "radio_virtual_dj_password",
+ comment: "Virtual DJ password",
+ secret: true,
+ },
{ key: "radio_djs_api_url", comment: "DJs API URL" },
],
},
@@ -331,7 +340,11 @@ const GROUPS: Group[] = [
{
title: "Discord webhook & custom code",
fields: [
- { key: "radio_discord_webhook_url", comment: "Discord webhook URL" },
+ {
+ key: "radio_discord_webhook_url",
+ comment: "Discord webhook URL",
+ secret: true,
+ },
{
key: "radio_discord_enabled",
comment: "Enable Discord notifications (0=no, 1=yes)",
@@ -467,7 +480,15 @@ export default async function AdminRadioSettingsPage() {
{field.comment ? (
diff --git a/src/app/admin/settings/advanced-settings-panel.tsx b/src/app/admin/settings/advanced-settings-panel.tsx
index 38116dbf..d732f5d8 100644
--- a/src/app/admin/settings/advanced-settings-panel.tsx
+++ b/src/app/admin/settings/advanced-settings-panel.tsx
@@ -14,8 +14,10 @@ import { MANAGED_SETTING_KEYS } from "./cms-settings-config";
interface SettingRow {
key: string;
+ /** Masked for secrets — the real value never reaches the client. */
value: string;
comment: string | null;
+ secret?: boolean;
}
export function AdvancedSettingsPanel({
@@ -126,7 +128,7 @@ export function AdvancedSettingsPanel({
>
) : (
- {s.value}
+ {s.secret ? "•• hidden ••" : s.value}
)}
diff --git a/src/app/admin/settings/page.tsx b/src/app/admin/settings/page.tsx
index 16c6a795..4d8b00f3 100644
--- a/src/app/admin/settings/page.tsx
+++ b/src/app/admin/settings/page.tsx
@@ -5,6 +5,10 @@ import { getTranslations } from "next-intl/server";
import { AdminPageShell } from "@/components/admin/admin-page-shell";
import { db, WebsiteSetting } from "@/lib/db";
import { canAccess, getAdminContext, PERMS } from "@/lib/permissions";
+import {
+ isSecretSettingKey,
+ SECRET_PLACEHOLDER,
+} from "@/lib/services/setting-secrets";
import { AdvancedSettingsPanel } from "./advanced-settings-panel";
import { FIELD_DEFAULTS, MANAGED_SETTING_KEYS } from "./cms-settings-config";
import { CmsSettingsForm } from "./cms-settings-form";
@@ -61,10 +65,14 @@ export default async function AdminSettings() {
({
key: s.key,
- value: s.value,
+ value: isSecretSettingKey(s.key) ? SECRET_PLACEHOLDER : s.value,
comment: s.comment,
+ secret: isSecretSettingKey(s.key),
}))}
canEdit={canEdit}
/>
diff --git a/src/app/api/admin/import/furni/route.ts b/src/app/api/admin/import/furni/route.ts
index d13f785d..332acc83 100644
--- a/src/app/api/admin/import/furni/route.ts
+++ b/src/app/api/admin/import/furni/route.ts
@@ -5,7 +5,7 @@ import { invalidateCatalogTotals } from "@/features/catalog/server/catalog-total
import { apiError, apiOk } from "@/lib/api";
import { withAdmin } from "@/lib/api-handler";
import { db, ItemsBase, queryRows } from "@/lib/db";
-import { normalizeClassname } from "@/lib/furni/classname";
+import { isSafeAssetName, normalizeClassname } from "@/lib/furni/classname";
import { localFurnitureStatus } from "@/lib/furni/local-presence";
import { PERMS } from "@/lib/permissions";
import { logAudit } from "@/lib/services/audit";
@@ -709,9 +709,20 @@ export const PATCH = withAdmin(
[];
for (const item of items) {
- const starIdx = item.classname.indexOf("*");
+ const normalised = item.classname.trim();
+ // The classname is joined straight into a `.nitro` file path, so a
+ // separator/looking payload must never get that far.
+ if (!isSafeAssetName(normalised)) {
+ results.push({
+ classname: item.classname,
+ ok: false,
+ warning: "Invalid classname",
+ });
+ continue;
+ }
+ const starIdx = normalised.indexOf("*");
const baseClassname =
- starIdx !== -1 ? item.classname.substring(0, starIdx) : item.classname;
+ starIdx !== -1 ? normalised.substring(0, starIdx) : normalised;
const nitroPath = path.join(
/*turbopackIgnore: true*/ nitroDir,
`${baseClassname}.nitro`,
diff --git a/src/app/api/admin/users/actions/route.ts b/src/app/api/admin/users/actions/route.ts
index 551aed09..1256ae33 100644
--- a/src/app/api/admin/users/actions/route.ts
+++ b/src/app/api/admin/users/actions/route.ts
@@ -6,11 +6,20 @@ import { PERMS } from "@/lib/permissions";
import { rcon } from "@/lib/services/rcon";
import { logStaffActivity } from "@/lib/services/staff-activity";
+/** Currency grants are capped: an unbounded `amount` minted an economy-breaking
+ * balance with a single request. */
+function positiveAmount(amount: number): boolean {
+ return Number.isInteger(amount) && amount > 0 && amount <= MAX_CURRENCY_GRANT;
+}
+
+const MAX_CURRENCY_GRANT = 1_000_000;
+
export const POST = withAdmin(
{ permission: PERMS.USERS_EDIT },
async (request, context) => {
const staffId = context.session.user.id;
const staffRank = context.session.user.rank;
+ const isSuper = context.permissions.isSuperAdmin;
const formData = await request.formData();
const userId = Number(formData.get("userId"));
const username = String(formData.get("username") || "");
@@ -23,6 +32,33 @@ export const POST = withAdmin(
);
}
+ // Every branch below acts on a live account, so the rank guard that the
+ // set_rank branch already applies belongs to all of them: staff may not
+ // act on users at or above their own rank unless they are the hotel's
+ // dynamic owner.
+ if (action !== "set_rank") {
+ const [target] = await db
+ .select({ rank: User.rank })
+ .from(User)
+ .where(eq(User.id, userId))
+ .limit(1);
+ if (!target) {
+ return NextResponse.json(
+ { success: false, message: "User not found" },
+ { status: 404 },
+ );
+ }
+ if (!isSuper && target.rank >= staffRank) {
+ return NextResponse.json(
+ {
+ success: false,
+ message: "Cannot act on a user at or above your rank",
+ },
+ { status: 403 },
+ );
+ }
+ }
+
if (action === "set_rank") {
const rank = Number(formData.get("rank") || "0");
if (!Number.isInteger(rank) || rank < 1) {
@@ -141,7 +177,7 @@ export const POST = withAdmin(
if (action === "give_credits") {
const credits = Number(formData.get("credits") || "0");
- if (!credits || credits <= 0) {
+ if (!positiveAmount(credits)) {
return NextResponse.json(
{ success: false, message: "Invalid credit amount" },
{ status: 400 },
@@ -166,7 +202,7 @@ export const POST = withAdmin(
if (action === "give_duckets") {
const amount = Number(formData.get("amount") || "0");
- if (!amount || amount <= 0) {
+ if (!positiveAmount(amount)) {
return NextResponse.json(
{ success: false, message: "Invalid duckets amount" },
{ status: 400 },
@@ -188,7 +224,7 @@ export const POST = withAdmin(
if (action === "give_diamonds") {
const amount = Number(formData.get("amount") || "0");
- if (!amount || amount <= 0) {
+ if (!positiveAmount(amount)) {
return NextResponse.json(
{ success: false, message: "Invalid diamonds amount" },
{ status: 400 },
@@ -213,7 +249,7 @@ export const POST = withAdmin(
if (action === "give_points") {
const amount = Number(formData.get("amount") || "0");
- if (!amount || amount <= 0) {
+ if (!positiveAmount(amount)) {
return NextResponse.json(
{ success: false, message: "Invalid points amount" },
{ status: 400 },
diff --git a/src/app/api/diagnostics/errors/route.ts b/src/app/api/diagnostics/errors/route.ts
index f14eb07b..f00b2867 100644
--- a/src/app/api/diagnostics/errors/route.ts
+++ b/src/app/api/diagnostics/errors/route.ts
@@ -23,6 +23,12 @@ export async function POST(request: Request) {
!request.headers.get("content-type")?.startsWith("application/json")
)
return new Response(null, { status: 403 });
+ // The IP bucket is rotatable, so also require the browser's own fetch
+ // metadata: a script hammering this endpoint from another site is
+ // `cross-site`, while a real in-page reporter is never.
+ const fetchSite = request.headers.get("sec-fetch-site");
+ if (fetchSite && fetchSite !== "same-origin" && fetchSite !== "none")
+ return new Response(null, { status: 403 });
const limit = await rateLimit(`cms-error:${await clientIp()}`, 20, 60000);
if (!limit.ok) return new Response(null, { status: 429 });
const reader = request.body?.getReader();
diff --git a/src/app/api/home/route.ts b/src/app/api/home/route.ts
index ec2ea91d..c9c6aa06 100644
--- a/src/app/api/home/route.ts
+++ b/src/app/api/home/route.ts
@@ -1,11 +1,7 @@
-import { and, count, desc, eq, or, sql } from "drizzle-orm";
import { env } from "@/env";
import { apiJson } from "@/lib/api";
-import { db, User, WebsiteArticles } from "@/lib/db";
-import { resolveHotelName } from "@/lib/hotel-name";
import { logger } from "@/lib/logger";
-import { apiCacheKey, cacheSafe } from "@/lib/redis-cache";
-import { cacheNews } from "@/lib/services/news-cache";
+import { cachedHomePayload } from "@/lib/services/home-payload";
/**
* GET /api/home — combined landing payload: the latest 4 website_articles and
@@ -14,39 +10,7 @@ import { cacheNews } from "@/lib/services/news-cache";
*/
export async function GET(_req: Request) {
try {
- const data = await cacheNews(apiCacheKey("home"), 15_000, async () => {
- const [articles, onlineRows, hotelName] = await Promise.all([
- db
- .select({
- id: WebsiteArticles.id,
- title: WebsiteArticles.title,
- slug: WebsiteArticles.slug,
- shortStory: WebsiteArticles.shortStory,
- image: WebsiteArticles.image,
- createdAt: WebsiteArticles.createdAt,
- })
- .from(WebsiteArticles)
- .where(
- and(
- eq(WebsiteArticles.status, "published"),
- or(
- sql`${WebsiteArticles.publishAt} IS NULL`,
- sql`${WebsiteArticles.publishAt} <= NOW()`,
- ),
- ),
- )
- .orderBy(desc(WebsiteArticles.createdAt))
- .limit(4),
- db.select({ total: count() }).from(User).where(eq(User.online, "1")),
- resolveHotelName(),
- ]);
- return cacheSafe({
- articles,
- online: onlineRows[0]?.total ?? 0,
- hotelName,
- });
- });
- return apiJson(data);
+ return apiJson(await cachedHomePayload());
} catch (error) {
logger.error("Public news query failed", { module: "news", error });
return apiJson(
diff --git a/src/app/api/leaderboard/route.ts b/src/app/api/leaderboard/route.ts
index 74db9aa2..ab579ab1 100644
--- a/src/app/api/leaderboard/route.ts
+++ b/src/app/api/leaderboard/route.ts
@@ -14,11 +14,29 @@ const CURRENCY_TYPE: Record, number> = {
duckets: 0,
};
-type Row = { rank: number; username: string; look: string; value: number };
+type Row = {
+ rank: number;
+ userId: number;
+ username: string;
+ look: string;
+ value: number;
+};
+
+/** Hidden-wallet users must not be listed, exactly like on the page. */
+async function withoutHiddenWallets(
+ rows: T[],
+): Promise {
+ const { loadProfilePrivacyMap } = await import(
+ "@/lib/services/profile-privacy"
+ );
+ const privacy = await loadProfilePrivacyMap(rows.map((r) => r.userId));
+ return rows.filter((r) => privacy.get(r.userId)?.wallet !== false);
+}
async function loadCreditsRows(): Promise {
const users = await db
.select({
+ userId: User.id,
username: User.username,
look: User.look,
credits: User.credits,
@@ -26,8 +44,9 @@ async function loadCreditsRows(): Promise {
.from(User)
.orderBy(desc(User.credits))
.limit(20);
- return users.map((u, i) => ({
+ return (await withoutHiddenWallets(users)).map((u, i) => ({
rank: i + 1,
+ userId: u.userId,
username: u.username,
look: u.look,
value: u.credits,
@@ -55,15 +74,24 @@ async function loadCurrencyRows(type: number): Promise {
top.map((t) => t.userId),
),
);
- const byId = new Map(users.map((u) => [u.id, u]));
+ const allowed = await withoutHiddenWallets(top);
+ const allowedIds = new Set(allowed.map((t) => t.userId));
+ const byId = new Map(
+ users.filter((u) => allowedIds.has(u.id)).map((u) => [u.id, u]),
+ );
- return top
+ return allowed
.map((t) => {
const u = byId.get(t.userId);
if (!u) return null;
- return { username: u.username, look: u.look, value: t.amount };
+ return {
+ userId: u.id,
+ username: u.username,
+ look: u.look,
+ value: t.amount,
+ };
})
- .filter((r): r is Omit => r !== null)
+ .filter((r) => r !== null)
.map((r, i) => ({ rank: i + 1, ...r }));
}
diff --git a/src/app/api/media/route.ts b/src/app/api/media/route.ts
index 1b1c0419..fe1fae3f 100644
--- a/src/app/api/media/route.ts
+++ b/src/app/api/media/route.ts
@@ -1,13 +1,20 @@
import { existsSync, readdirSync, statSync } from "node:fs";
import { resolve } from "node:path";
-import { NextResponse } from "next/server";
+import { apiOk } from "@/lib/api";
+import { withAdmin } from "@/lib/api-handler";
import { MEDIA_ROOT } from "@/lib/media-storage";
+import { PERMS } from "@/lib/permissions";
-export async function GET() {
+/**
+ * Directory listing for the admin media picker. It used to be world-readable and
+ * unrated, which handed every visitor a complete inventory of uploaded media
+ * (logo/favicon paths included) plus their timestamps.
+ */
+export const GET = withAdmin({ permission: PERMS.PAGES_EDIT }, async () => {
const dir = MEDIA_ROOT;
// eslint-disable-next-line security/detect-non-literal-fs-filename
if (!existsSync(dir)) {
- return NextResponse.json({ files: [] });
+ return apiOk({ files: [] });
}
// eslint-disable-next-line security/detect-non-literal-fs-filename
const files = readdirSync(dir)
@@ -23,5 +30,5 @@ export async function GET() {
})
.sort((a, b) => b.uploaded - a.uploaded);
- return NextResponse.json({ files });
-}
+ return apiOk({ files });
+});
diff --git a/src/app/api/photos/route.ts b/src/app/api/photos/route.ts
index 603d0091..923a9b87 100644
--- a/src/app/api/photos/route.ts
+++ b/src/app/api/photos/route.ts
@@ -31,8 +31,20 @@ export async function GET(req: Request) {
.limit(take)
.offset(skip),
]);
+
+ // Photo privacy is a per-user setting, so the API honours it like
+ // the /photos page does.
+ const { loadProfilePrivacyMap } = await import(
+ "@/lib/services/profile-privacy"
+ );
+ const photoPrivacy = await loadProfilePrivacyMap(
+ photos.map((p) => p.userId),
+ );
+
return cacheSafe({
- data: photos,
+ data: photos.filter(
+ (p) => photoPrivacy.get(p.userId)?.photos !== false,
+ ),
meta: {
page,
perPage,
diff --git a/src/app/api/radio/shouts/route.ts b/src/app/api/radio/shouts/route.ts
index ec904780..ca6276d9 100644
--- a/src/app/api/radio/shouts/route.ts
+++ b/src/app/api/radio/shouts/route.ts
@@ -4,6 +4,7 @@ import { bearerUserId } from "@/lib/api-auth";
import { db, RadioShouts, User } from "@/lib/db";
import { rateLimit } from "@/lib/rate-limit";
import { apiCacheKey, redisCache } from "@/lib/redis-cache";
+import { moderateOrThrow } from "@/lib/services/moderation";
// Latest 50 radio shouts with their author's username/look resolved. Mirrors the
// query behind the public /radio/shouts page (radio_shouts ordered by created_at
@@ -93,6 +94,14 @@ export async function POST(req: Request) {
);
}
+ // The same word filter the server action applies — the API path used to
+ // skip it entirely, so a filtered message could be posted with one fetch.
+ try {
+ await moderateOrThrow(message);
+ } catch (error) {
+ return apiError((error as Error).message, 422);
+ }
+
try {
const now = new Date();
await db.insert(RadioShouts).values({
diff --git a/src/app/api/users/[username]/route.ts b/src/app/api/users/[username]/route.ts
index 26761409..4f352280 100644
--- a/src/app/api/users/[username]/route.ts
+++ b/src/app/api/users/[username]/route.ts
@@ -23,6 +23,7 @@ export async function GET(
async () => {
const [row] = await db
.select({
+ id: User.id,
username: User.username,
look: User.look,
motto: User.motto,
@@ -39,13 +40,21 @@ export async function GET(
return null;
}
+ // Wallet / online visibility are per-user settings; the public API
+ // used to hand both out unconditionally, which made bulk scraping
+ // of hidden wallets possible.
+ const { loadProfilePrivacy } = await import(
+ "@/lib/services/profile-privacy"
+ );
+ const privacy = await loadProfilePrivacy(row.id);
+
return cacheSafe({
username: row.username,
look: row.look,
motto: row.motto,
rank: row.rank,
- credits: row.credits,
- online: row.online === "1",
+ credits: privacy.values.wallet ? row.credits : null,
+ online: privacy.values.online ? row.online === "1" : null,
accountCreated: row.accountCreated,
});
},
diff --git a/src/app/client/page.tsx b/src/app/client/page.tsx
index 0acdae16..96bf115e 100644
--- a/src/app/client/page.tsx
+++ b/src/app/client/page.tsx
@@ -1,12 +1,11 @@
-import { count, eq } from "drizzle-orm";
import { headers } from "next/headers";
import { redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { issueSsoTicket } from "@/lib/auth/sso-ticket";
-import { cached } from "@/lib/cache";
import { resolveClientIp } from "@/lib/client-ip";
-import { db, User } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
+import { cachedOnlineCount } from "@/lib/services/public-counters";
+
import { siteSettings } from "@/lib/services/site-settings";
import { ClientView } from "./client-view";
@@ -27,13 +26,7 @@ export default async function ClientPage() {
// render as fast as possible since the player is waiting for the game.
const [ticket, onlineCount] = await Promise.all([
issueSsoTicket(userId, hotelName, ip),
- cached("online_count", 10_000, async () => {
- const [row] = await db
- .select({ total: count() })
- .from(User)
- .where(eq(User.online, "1"));
- return row?.total ?? 0;
- }).catch(() => 0),
+ cachedOnlineCount().catch(() => 0),
]);
return (
diff --git a/src/app/globals.css b/src/app/globals.css
index 8ea10e32..a9bd9afd 100644
--- a/src/app/globals.css
+++ b/src/app/globals.css
@@ -167,6 +167,61 @@ html {
text-size-adjust: 100%;
}
+/* ── Route transition (CSS only — no animation runtime on public pages) ── */
+@keyframes page-enter-rise {
+ from {
+ opacity: 0;
+ transform: translate3d(0, 10px, 0);
+ }
+ to {
+ opacity: 1;
+ transform: none;
+ }
+}
+.page-enter {
+ animation: page-enter-rise 240ms ease-out both;
+}
+
+/* ── Route progress indicator ─────────────────────────────────────────── */
+.route-progress {
+ position: fixed;
+ inset: 0 0 auto 0;
+ z-index: 99999;
+ height: 3px;
+ overflow: hidden;
+ background: transparent;
+ pointer-events: none;
+ opacity: 0;
+ transition: opacity 200ms linear;
+}
+.route-progress[data-loading="true"] {
+ opacity: 1;
+}
+@keyframes route-progress-run {
+ from {
+ width: 0%;
+ opacity: 1;
+ }
+ 70% {
+ width: 85%;
+ opacity: 1;
+ }
+ to {
+ width: 100%;
+ opacity: 0;
+ }
+}
+.route-progress__bar {
+ display: block;
+ height: 100%;
+ width: 0;
+ background: var(--color-primary);
+ box-shadow: 0 0 10px var(--color-primary);
+}
+.route-progress[data-loading="true"] .route-progress__bar {
+ animation: route-progress-run 400ms ease-in-out both;
+}
+
@media (prefers-reduced-motion: reduce) {
html:focus-within {
scroll-behavior: auto;
diff --git a/src/app/layout.tsx b/src/app/layout.tsx
index 1e76b5bd..423d9bb9 100644
--- a/src/app/layout.tsx
+++ b/src/app/layout.tsx
@@ -6,7 +6,6 @@ import { NextIntlClientProvider } from "next-intl";
import { getLocale, getMessages } from "next-intl/server";
import { type ReactNode, Suspense } from "react";
-import { Toaster } from "sonner";
import { GlobalProgressBar } from "@/components/global-progress-bar";
import { PwaRegister } from "@/components/pwa-register";
import { ScopedThemeVars } from "@/components/scoped-theme-vars";
@@ -106,19 +105,6 @@ export default async function RootLayout({
{children}
-