Add 2FA, email + password reset, and batch-7 pages
Auth (hand-built on the auth core): - 2FA: User model gains two_factor_secret/recovery_codes/confirmed_at (+ idempotent MariaDB migration). authorize() requires a valid TOTP code when 2FA is confirmed (secret decrypted via Laravel APP_KEY, fail-closed). Two-step login (precheckLogin reveals the code field). /settings/2fa enable/confirm/disable flow. - Password reset: nodemailer email service; PasswordReset model + migration; /forgot (request, generic response) + /reset (token sha256 + 1h TTL, sets argon2id hash). Login links to forgot. Batch 7 (parallel agents): /admin/commandocentrum (RCON controls + emulator_errors), social write actions (friend request + guild forum new thread), /help/[category], /badges (public). env: APP_KEY, APP_URL, SMTP_*. Nav extended. Verified: tsc exit 0, vitest 48/48, next build exit 0 (64 page routes).
This commit is contained in:
1 parent
486ce51559
commit
e668fa85ec
24 files changed
+1223
-34
No files matched your search
@@ -0,0 +1,86 @@
|
||||
import Link from "next/link";
|
||||
import { notFound, redirect } from "next/navigation";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { postThread } from "@/actions/social";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
export default async function NewThreadPage({
|
||||
params,
|
||||
}: {
|
||||
params: Promise<{ id: string }>;
|
||||
}) {
|
||||
const { id } = await params;
|
||||
const guildId = Number(id);
|
||||
if (!Number.isInteger(guildId) || guildId <= 0) notFound();
|
||||
|
||||
// Auth gate: only logged-in users may open a thread.
|
||||
const session = await auth();
|
||||
if (!session?.user?.id) redirect("/login");
|
||||
|
||||
// Guild header (read-only). A DB hiccup degrades to notFound rather than 500.
|
||||
let guild: { id: number; name: string } | null = null;
|
||||
try {
|
||||
guild = await prisma.guilds.findUnique({
|
||||
where: { id: guildId },
|
||||
select: { id: true, name: true },
|
||||
});
|
||||
} catch {
|
||||
guild = null;
|
||||
}
|
||||
|
||||
if (!guild) notFound();
|
||||
|
||||
return (
|
||||
<main>
|
||||
<p style={{ marginTop: 0 }}>
|
||||
<Link href={`/guilds/${guild.id}/forum`}>← Back to forum</Link>
|
||||
</p>
|
||||
|
||||
<h1 style={{ marginBottom: "0.25rem" }}>New thread</h1>
|
||||
<p className="muted" style={{ marginTop: 0 }}>
|
||||
in {guild.name || "Unnamed guild"} forum
|
||||
</p>
|
||||
|
||||
<form action={postThread} className="card" style={{ marginTop: "1rem" }}>
|
||||
{/* Guild target drives the write; the author is taken from the session
|
||||
inside the action, never from this form. */}
|
||||
<input type="hidden" name="guildId" value={String(guild.id)} />
|
||||
|
||||
<label htmlFor="thread-subject" className="muted">
|
||||
Subject
|
||||
</label>
|
||||
<input
|
||||
id="thread-subject"
|
||||
name="subject"
|
||||
required
|
||||
maxLength={255}
|
||||
placeholder="Thread subject"
|
||||
style={{ width: "100%", margin: "0.4rem 0 0.9rem" }}
|
||||
/>
|
||||
|
||||
<label htmlFor="thread-message" className="muted">
|
||||
Message
|
||||
</label>
|
||||
<textarea
|
||||
id="thread-message"
|
||||
name="message"
|
||||
required
|
||||
rows={8}
|
||||
placeholder="Write your opening post…"
|
||||
style={{ width: "100%", margin: "0.4rem 0 1rem", resize: "vertical" }}
|
||||
/>
|
||||
|
||||
<div style={{ display: "flex", gap: "0.5rem", alignItems: "center" }}>
|
||||
<button type="submit" className="btn btn-primary">
|
||||
Post thread
|
||||
</button>
|
||||
<Link href={`/guilds/${guild.id}/forum`} className="btn btn-outline">
|
||||
Cancel
|
||||
</Link>
|
||||
</div>
|
||||
</form>
|
||||
</main>
|
||||
);
|
||||
}
|
||||
Reference in new issue
Block a user