perf: optimize CMS queries, caching, and asset delivery
Database: - Add missing indexes (users.credits, users_currency(type,amount), users_settings.respects_received, camera_web.timestamp, messenger_offline.user_id) via migrations 0020/0021 - Use partial .select() everywhere instead of SELECT * (tickets, users, rooms, audit logs, catalog tree, polls, radio, password reset) - Add queryPrepared/queryPreparedOne (server-side prepared statements) and switch the login check to a prepared statement; drop dead cache options from the pool config - Raise total_users/total_rooms COUNT(*) cache TTL to 5m Caching: - Consolidate the three cache helpers (cached, redisCache, cachedQuery) into a single memory-first implementation backed by Redis - invalidateKey now clears the in-process cache as well as Redis - Cache homepage sections, news list, and leaderboard tabs; share one news_list cache key between homepage and news archive - siteSettings: in-process cache with TTL so repeated getters no longer pay a Redis round-trip per call - Share a 10s poll cache across all radio SSE connections - Normalize timestamps after cache reads (Redis JSON round-trip) Assets: - Enable AVIF/WebP via images.formats and remove unoptimized from news covers and the homepage hero (149KB jpg) with proper sizes/priority - Support ?format=webp|avif|png in the /imaging proxy via sharp Other: - Fix pnpm supply-chain minimumReleaseAge failures by excluding the freshly-published packages (next 16.3.1, hookform resolvers 5.8.0, resend 6.20.0) - Remove unused before/after fields from housekeeping AuditEntry
This commit is contained in:
1 parent
dc9e5a567c
commit
e5ec3c1f06
29 files changed
+532
-322
No files matched your search
@@ -6,31 +6,14 @@ import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
import { precheckLogin } from "./auth-precheck";
|
||||
|
||||
const { selectLimit } = vi.hoisted(() => {
|
||||
const selectLimit = vi.fn().mockResolvedValue([]);
|
||||
return { selectLimit };
|
||||
const { queryPreparedOne } = vi.hoisted(() => {
|
||||
const queryPreparedOne = vi.fn().mockResolvedValue(null);
|
||||
return { queryPreparedOne };
|
||||
});
|
||||
|
||||
vi.mock("@/env", () => ({ env: { CONVERT_PASSWORDS: false } }));
|
||||
vi.mock("@/lib/auth/password", () => ({ checkLogin: vi.fn() }));
|
||||
vi.mock("@/lib/db", () => ({
|
||||
db: {
|
||||
select: vi.fn(() => ({
|
||||
from: vi.fn(() => ({
|
||||
where: vi.fn(() => ({
|
||||
limit: selectLimit,
|
||||
})),
|
||||
})),
|
||||
})),
|
||||
},
|
||||
User: {
|
||||
password: "password",
|
||||
twoFactorConfirmedAt: "twoFactorConfirmedAt",
|
||||
mail: "mail",
|
||||
mailVerified: "mailVerified",
|
||||
username: "username",
|
||||
},
|
||||
}));
|
||||
vi.mock("@/lib/db", () => ({ queryPreparedOne }));
|
||||
vi.mock("@/lib/rate-limit", () => ({ clientIp: vi.fn(), rateLimit: vi.fn() }));
|
||||
vi.mock("@/lib/services/captcha", () => ({
|
||||
captchaConfig: vi.fn(),
|
||||
@@ -46,31 +29,27 @@ beforeEach(() => {
|
||||
vi.mocked(rateLimit).mockResolvedValue({ ok: true });
|
||||
vi.mocked(checkLogin).mockResolvedValue({ valid: true } as never);
|
||||
vi.mocked(captchaConfig).mockResolvedValue({ provider: "none" } as never);
|
||||
selectLimit.mockResolvedValue([]);
|
||||
queryPreparedOne.mockResolvedValue(null);
|
||||
});
|
||||
|
||||
describe("precheckLogin", () => {
|
||||
it("returns ok for valid login without 2FA", async () => {
|
||||
selectLimit.mockResolvedValue([
|
||||
{
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
},
|
||||
]);
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
expect(await precheckLogin("user", "pass")).toBe("ok");
|
||||
});
|
||||
|
||||
it("returns twofactor when 2FA is set up", async () => {
|
||||
selectLimit.mockResolvedValue([
|
||||
{
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: new Date(),
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
},
|
||||
]);
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: new Date(),
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
expect(await precheckLogin("user", "pass")).toBe("twofactor");
|
||||
});
|
||||
|
||||
@@ -83,33 +62,29 @@ describe("precheckLogin", () => {
|
||||
provider: "hcaptcha",
|
||||
} as never);
|
||||
vi.mocked(verifyCaptcha).mockResolvedValue(false);
|
||||
selectLimit.mockResolvedValue([
|
||||
{
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
},
|
||||
]);
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: null,
|
||||
mailVerified: "0",
|
||||
});
|
||||
expect(await precheckLogin("user", "pass", "bad-token")).toBe("captcha");
|
||||
});
|
||||
|
||||
it("returns invalid when user not found (dummy hash check)", async () => {
|
||||
selectLimit.mockResolvedValue([]);
|
||||
queryPreparedOne.mockResolvedValue(null);
|
||||
const result = await precheckLogin("nonexistent", "pass");
|
||||
expect(result).toBe("invalid");
|
||||
expect(checkLogin).toHaveBeenCalled();
|
||||
});
|
||||
|
||||
it("returns unverified when email verification required", async () => {
|
||||
selectLimit.mockResolvedValue([
|
||||
{
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: "[email protected]",
|
||||
mailVerified: "0",
|
||||
},
|
||||
]);
|
||||
queryPreparedOne.mockResolvedValue({
|
||||
password: "hash",
|
||||
twoFactorConfirmedAt: null,
|
||||
mail: "[email protected]",
|
||||
mailVerified: "0",
|
||||
});
|
||||
vi.mocked(siteSettings.getBool).mockResolvedValue(true);
|
||||
expect(await precheckLogin("user", "pass")).toBe("unverified");
|
||||
});
|
||||
|
||||
@@ -1,9 +1,8 @@
|
||||
"use server";
|
||||
|
||||
import { eq } from "drizzle-orm";
|
||||
import { env } from "@/env";
|
||||
import { checkLogin } from "@/lib/auth/password";
|
||||
import { db, User } from "@/lib/db";
|
||||
import { queryPreparedOne } from "@/lib/db";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { captchaConfig, verifyCaptcha } from "@/lib/services/captcha";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
@@ -46,17 +45,17 @@ export async function precheckLogin(
|
||||
mailVerified: string;
|
||||
} | null;
|
||||
try {
|
||||
const [row] = await db
|
||||
.select({
|
||||
password: User.password,
|
||||
twoFactorConfirmedAt: User.twoFactorConfirmedAt,
|
||||
mail: User.mail,
|
||||
mailVerified: User.mailVerified,
|
||||
})
|
||||
.from(User)
|
||||
.where(eq(User.username, u))
|
||||
.limit(1);
|
||||
user = row ?? null;
|
||||
user = await queryPreparedOne<{
|
||||
password: string;
|
||||
twoFactorConfirmedAt: Date | null;
|
||||
mail: string | null;
|
||||
mailVerified: string;
|
||||
}>(
|
||||
`SELECT password, two_factor_confirmed_at AS twoFactorConfirmedAt,
|
||||
mail, mail_verified AS mailVerified
|
||||
FROM users WHERE username = ? LIMIT 1`,
|
||||
[u],
|
||||
);
|
||||
} catch {
|
||||
return "invalid";
|
||||
}
|
||||
|
||||
@@ -90,7 +90,10 @@ export async function resetPassword(formData: FormData): Promise<void> {
|
||||
if (!error) {
|
||||
try {
|
||||
const [row] = await db
|
||||
.select()
|
||||
.select({
|
||||
token: PasswordReset.token,
|
||||
createdAt: PasswordReset.createdAt,
|
||||
})
|
||||
.from(PasswordReset)
|
||||
.where(eq(PasswordReset.email, email))
|
||||
.limit(1);
|
||||
|
||||
+12
-2
@@ -166,7 +166,12 @@ export const voteOnPoll = authAction(
|
||||
}
|
||||
|
||||
const [poll] = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsitePoll.id,
|
||||
status: WebsitePoll.status,
|
||||
startsAt: WebsitePoll.startsAt,
|
||||
endsAt: WebsitePoll.endsAt,
|
||||
})
|
||||
.from(WebsitePoll)
|
||||
.where(eq(WebsitePoll.id, ctx.data.pollId))
|
||||
.limit(1);
|
||||
@@ -184,7 +189,12 @@ export const voteOnPoll = authAction(
|
||||
}
|
||||
|
||||
const questions = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsitePollQuestion.id,
|
||||
pollId: WebsitePollQuestion.pollId,
|
||||
type: WebsitePollQuestion.type,
|
||||
options: WebsitePollQuestion.options,
|
||||
})
|
||||
.from(WebsitePollQuestion)
|
||||
.where(eq(WebsitePollQuestion.pollId, poll.id));
|
||||
|
||||
|
||||
+17
-4
@@ -60,7 +60,10 @@ export const adminReplyTicket = adminAction(
|
||||
},
|
||||
async (ctx) => {
|
||||
const [ticket] = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsiteTicket.id,
|
||||
assigneeId: WebsiteTicket.assigneeId,
|
||||
})
|
||||
.from(WebsiteTicket)
|
||||
.where(eq(WebsiteTicket.id, ctx.data.ticketId))
|
||||
.limit(1);
|
||||
@@ -106,7 +109,11 @@ export const updateTicketStatus = adminAction(
|
||||
},
|
||||
async (ctx) => {
|
||||
const [ticket] = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsiteTicket.id,
|
||||
assigneeId: WebsiteTicket.assigneeId,
|
||||
status: WebsiteTicket.status,
|
||||
})
|
||||
.from(WebsiteTicket)
|
||||
.where(eq(WebsiteTicket.id, ctx.data.ticketId))
|
||||
.limit(1);
|
||||
@@ -149,7 +156,10 @@ export const assignTicket = adminAction(
|
||||
},
|
||||
async (ctx) => {
|
||||
const [ticket] = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsiteTicket.id,
|
||||
assigneeId: WebsiteTicket.assigneeId,
|
||||
})
|
||||
.from(WebsiteTicket)
|
||||
.where(eq(WebsiteTicket.id, ctx.data.ticketId))
|
||||
.limit(1);
|
||||
@@ -185,7 +195,10 @@ export const updateTicketPriority = adminAction(
|
||||
},
|
||||
async (ctx) => {
|
||||
const [ticket] = await db
|
||||
.select()
|
||||
.select({
|
||||
id: WebsiteTicket.id,
|
||||
priority: WebsiteTicket.priority,
|
||||
})
|
||||
.from(WebsiteTicket)
|
||||
.where(eq(WebsiteTicket.id, ctx.data.ticketId))
|
||||
.limit(1);
|
||||
|
||||
Reference in new issue
Block a user