feat: jwt cache, redis health, help-ticket admin, and write rate limits
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m33s

Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-21 21:58:48 +02:00
1 parent 3bb96eb6f3
commit 968ca15c27
23 files changed
+1344 -205

No files matched your search

+13 -1
View File
@@ -1,11 +1,13 @@
"use server";
import { auth, signOut } from "@/lib/auth";
import { invalidateJwtVersionCache } from "@/lib/auth/jwt-version-cache";
import { personalTokenScope } from "@/lib/auth/personal-token-scope";
import { prisma } from "@/lib/prisma";
/**
* Invalidate every CMS JWT for the signed-in user by bumping website_jwt_version,
* then end the current browser session too.
* revoke personal access tokens, then end the current browser session too.
*/
export async function signOutEverywhere(): Promise<void> {
const session = await auth();
@@ -20,6 +22,16 @@ export async function signOutEverywhere(): Promise<void> {
where: { id: userId },
data: { websiteJwtVersion: { increment: 1 } },
});
await invalidateJwtVersionCache(userId);
} catch {
/* still continue */
}
// Revoke API bearer tokens (Sanctum / personal_access_tokens).
try {
await prisma.personalAccessTokens.deleteMany({
where: personalTokenScope(userId),
});
} catch {
/* still sign out locally */
}