feat: harden atoms-nexst against review findings (37 items)
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
This commit is contained in:
1 parent
3933214953
commit
6cc45d7413
150 files changed
+2137
-759
No files matched your search
@@ -815,7 +815,8 @@
|
||||
"confirm": "Onayla",
|
||||
"enableIntro": "Kimlik doğrulama uygulamasıyla ikinci bir güvenlik katmanı ekleyin.",
|
||||
"enable": "2FA'yı etkinleştir",
|
||||
"rateLimit": "Too many attempts. Please wait before trying again."
|
||||
"rateLimit": "Too many attempts. Please wait before trying again.",
|
||||
"alreadyEnabled": "İki adımlı doğrulama zaten etkin. Yeniden kurmak istiyorsanız önce devre dışı bırakın."
|
||||
},
|
||||
"title": "Bağlı hesaplar",
|
||||
"subtitle": "Tek tıklamayla giriş için sosyal hesap bağlayın",
|
||||
@@ -849,7 +850,8 @@
|
||||
"showPassword": "Göster",
|
||||
"hidePassword": "Gizle",
|
||||
"registeredSuccess": "Hesap oluşturuldu — doğrulama bağlantısı için gelen kutunuzu kontrol edin, ardından giriş yapın.",
|
||||
"verifyEmailCta": "Yeni doğrulama bağlantısı iste"
|
||||
"verifyEmailCta": "Yeni doğrulama bağlantısı iste",
|
||||
"passwordChanged": "Şifreniz değiştirildi. Yeni şifrenizle giriş yapın."
|
||||
},
|
||||
"register": {
|
||||
"title": "Hesap oluştur",
|
||||
@@ -924,7 +926,8 @@
|
||||
"emailPlaceholder": "E-postanız",
|
||||
"sendResetLink": "Sıfırlama bağlantısını gönder",
|
||||
"backToLogin": "Girişe geri dön",
|
||||
"errorCaptcha": "Captcha verification failed. Please try again."
|
||||
"errorCaptcha": "Captcha verification failed. Please try again.",
|
||||
"sendAnotherLink": "Başka bir bağlantı gönder"
|
||||
},
|
||||
"reset": {
|
||||
"title": "Yeni bir şifre belirleyin",
|
||||
@@ -933,7 +936,9 @@
|
||||
"resetPassword": "Şifreyi sıfırla",
|
||||
"backToLogin": "Girişe geri dön",
|
||||
"passwordMinLength": "Şifre en az 12 karakter olmalıdır",
|
||||
"tooManyAttempts": "Çok fazla deneme — daha sonra tekrar deneyin"
|
||||
"tooManyAttempts": "Çok fazla deneme — daha sonra tekrar deneyin",
|
||||
"invalidLink": "Bu şifre sıfırlama bağlantısı geçersiz veya süresi dolmuş. Yeni bir tane isteyin.",
|
||||
"failed": "Şifre sıfırlanamadı. Lütfen tekrar deneyin."
|
||||
},
|
||||
"verify": {
|
||||
"verifiedTitle": "Artık hazırsınız",
|
||||
|
||||
Reference in new issue
Block a user