Add 2FA, email + password reset, and batch-7 pages

Auth (hand-built on the auth core):
- 2FA: User model gains two_factor_secret/recovery_codes/confirmed_at (+ idempotent
  MariaDB migration). authorize() requires a valid TOTP code when 2FA is confirmed
  (secret decrypted via Laravel APP_KEY, fail-closed). Two-step login (precheckLogin
  reveals the code field). /settings/2fa enable/confirm/disable flow.
- Password reset: nodemailer email service; PasswordReset model + migration;
  /forgot (request, generic response) + /reset (token sha256 + 1h TTL, sets argon2id
  hash). Login links to forgot.

Batch 7 (parallel agents): /admin/commandocentrum (RCON controls + emulator_errors),
social write actions (friend request + guild forum new thread), /help/[category],
/badges (public). env: APP_KEY, APP_URL, SMTP_*. Nav extended.

Verified: tsc exit 0, vitest 48/48, next build exit 0 (64 page routes).
This commit is contained in:
Simo committed 2026-06-28 14:25:19 +02:00
1 parent 486ce51559
commit e668fa85ec
24 files changed
+1223 -34

No files matched your search

+86
View File
@@ -0,0 +1,86 @@
import Link from "next/link";
import { notFound, redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { postThread } from "@/actions/social";
export const dynamic = "force-dynamic";
export default async function NewThreadPage({
params,
}: {
params: Promise<{ id: string }>;
}) {
const { id } = await params;
const guildId = Number(id);
if (!Number.isInteger(guildId) || guildId <= 0) notFound();
// Auth gate: only logged-in users may open a thread.
const session = await auth();
if (!session?.user?.id) redirect("/login");
// Guild header (read-only). A DB hiccup degrades to notFound rather than 500.
let guild: { id: number; name: string } | null = null;
try {
guild = await prisma.guilds.findUnique({
where: { id: guildId },
select: { id: true, name: true },
});
} catch {
guild = null;
}
if (!guild) notFound();
return (
<main>
<p style={{ marginTop: 0 }}>
<Link href={`/guilds/${guild.id}/forum`}>← Back to forum</Link>
</p>
<h1 style={{ marginBottom: "0.25rem" }}>New thread</h1>
<p className="muted" style={{ marginTop: 0 }}>
in {guild.name || "Unnamed guild"} forum
</p>
<form action={postThread} className="card" style={{ marginTop: "1rem" }}>
{/* Guild target drives the write; the author is taken from the session
inside the action, never from this form. */}
<input type="hidden" name="guildId" value={String(guild.id)} />
<label htmlFor="thread-subject" className="muted">
Subject
</label>
<input
id="thread-subject"
name="subject"
required
maxLength={255}
placeholder="Thread subject"
style={{ width: "100%", margin: "0.4rem 0 0.9rem" }}
/>
<label htmlFor="thread-message" className="muted">
Message
</label>
<textarea
id="thread-message"
name="message"
required
rows={8}
placeholder="Write your opening post…"
style={{ width: "100%", margin: "0.4rem 0 1rem", resize: "vertical" }}
/>
<div style={{ display: "flex", gap: "0.5rem", alignItems: "center" }}>
<button type="submit" className="btn btn-primary">
Post thread
</button>
<Link href={`/guilds/${guild.id}/forum`} className="btn btn-outline">
Cancel
</Link>
</div>
</form>
</main>
);
}