Register: auto sign-in to /me and speed/cleanup improvements
- Send the verification email after the response via after() so it never blocks sign-up - Invalidate the cached login lookup right after account creation so the automatic sign-in always finds the fresh row - Auto sign in with the submitted credentials and go straight to /me, with a fallback to /login?registered=1 if sign-in is refused (e.g. email verification required) - Cache the register page's online/latest user queries to cut DB load under traffic - Fix terms checkbox label double-toggle cancelling the selection - Add pages.register.redirecting translation to all locales
This commit is contained in:
1 parent
2d09a4a92c
commit
f25a26a93e
25 files changed
+143
-53
No files matched your search
+46
-24
@@ -1,10 +1,11 @@
|
||||
"use server";
|
||||
|
||||
import { count, eq } from "drizzle-orm";
|
||||
import { redirect } from "next/navigation";
|
||||
import { after } from "next/server";
|
||||
import { z } from "zod";
|
||||
import { sendVerification } from "@/actions/email-verify";
|
||||
import { hashPassword } from "@/lib/auth/password";
|
||||
import { invalidateKey } from "@/lib/cached-db";
|
||||
import { db, User } from "@/lib/db";
|
||||
import { logger } from "@/lib/logger";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
@@ -36,10 +37,16 @@ const registerSchema = z.object({
|
||||
// A valid starter Habbo figure so the avatar renders in-client immediately.
|
||||
const DEFAULT_LOOK = "hr-100-.hd-180-1.ch-255-66.lg-280-110.sh-305-62";
|
||||
|
||||
export interface RegisterState {
|
||||
error: string | null;
|
||||
ok: boolean;
|
||||
}
|
||||
|
||||
export async function register(
|
||||
_prevState: string | null,
|
||||
_prevState: RegisterState,
|
||||
formData: FormData,
|
||||
): Promise<string | null> {
|
||||
): Promise<RegisterState> {
|
||||
const fail = (error: string): RegisterState => ({ error, ok: false });
|
||||
const raw = {
|
||||
username: String(formData.get("username") ?? "")
|
||||
.normalize("NFC")
|
||||
@@ -61,11 +68,11 @@ export async function register(
|
||||
|
||||
const parsed = registerSchema.safeParse(raw);
|
||||
if (!parsed.success) {
|
||||
return parsed.error.issues[0]?.message ?? "Invalid input";
|
||||
return fail(parsed.error.issues[0]?.message ?? "Invalid input");
|
||||
}
|
||||
|
||||
if (parsed.data.password !== parsed.data.passwordConfirmation) {
|
||||
return "Passwords do not match";
|
||||
return fail("Passwords do not match");
|
||||
}
|
||||
|
||||
const { username, mail, password, look } = parsed.data;
|
||||
@@ -74,7 +81,9 @@ export async function register(
|
||||
|
||||
// Throttle sign-ups per IP (5 per 10 minutes) to curb account spam.
|
||||
if (!(await rateLimit(`register:${ip}`, 5, 10 * 60_000)).ok) {
|
||||
return "Too many sign-up attempts. Please wait a few minutes and try again.";
|
||||
return fail(
|
||||
"Too many sign-up attempts. Please wait a few minutes and try again.",
|
||||
);
|
||||
}
|
||||
|
||||
// CAPTCHA (Turnstile / reCAPTCHA) — only enforced when configured in settings.
|
||||
@@ -82,18 +91,18 @@ export async function register(
|
||||
if (cfg.provider !== "none") {
|
||||
const token = String(formData.get(cfg.field) ?? "").normalize("NFC");
|
||||
if (!(await verifyCaptcha(token, ip)))
|
||||
return "Captcha verification failed. Please try again.";
|
||||
return fail("Captcha verification failed. Please try again.");
|
||||
}
|
||||
|
||||
// Terms acceptance check.
|
||||
if (!raw.termsAccepted)
|
||||
return "You must accept the terms and conditions to register.";
|
||||
return fail("You must accept the terms and conditions to register.");
|
||||
|
||||
// VPN/proxy block (only when enabled in /admin/vpn).
|
||||
if ((await checkVpn(ip)).blocked) {
|
||||
return (
|
||||
return fail(
|
||||
(await siteSettings.get("vpn_block_message", "")) ||
|
||||
"Registrations from VPN/proxy connections are not allowed."
|
||||
"Registrations from VPN/proxy connections are not allowed.",
|
||||
);
|
||||
}
|
||||
|
||||
@@ -106,7 +115,9 @@ export async function register(
|
||||
.where(eq(User.ipRegister, ip))
|
||||
.catch(() => [{ total: 0 }]);
|
||||
if (Number(row?.total ?? 0) >= max)
|
||||
return "You have reached the maximum number of accounts for your connection.";
|
||||
return fail(
|
||||
"You have reached the maximum number of accounts for your connection.",
|
||||
);
|
||||
}
|
||||
|
||||
// Uniqueness check.
|
||||
@@ -116,10 +127,10 @@ export async function register(
|
||||
.from(User)
|
||||
.where(eq(User.username, username))
|
||||
.limit(1);
|
||||
if (existing) return "That username is already taken";
|
||||
if (existing) return fail("That username is already taken");
|
||||
} catch {
|
||||
logger.warn("Username uniqueness check failed during registration");
|
||||
return "Registration is temporarily unavailable";
|
||||
return fail("Registration is temporarily unavailable");
|
||||
}
|
||||
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
@@ -134,25 +145,36 @@ export async function register(
|
||||
look,
|
||||
termsAccepted: raw.termsAccepted,
|
||||
});
|
||||
|
||||
if (hasEmail) {
|
||||
try {
|
||||
await sendVerification(mail);
|
||||
} catch {
|
||||
logger.warn("Failed to send verification email after registration");
|
||||
}
|
||||
}
|
||||
} catch (err) {
|
||||
const code = (err as { cause?: { code?: string } }).cause?.code;
|
||||
if (code === "ER_DUP_ENTRY") {
|
||||
return "That username is already taken";
|
||||
return fail("That username is already taken");
|
||||
}
|
||||
logger.error("Account creation failed", {
|
||||
code,
|
||||
message: err instanceof Error ? err.message : String(err),
|
||||
});
|
||||
return "Could not create the account. Please try again or contact staff.";
|
||||
return fail(
|
||||
"Could not create the account. Please try again or contact staff.",
|
||||
);
|
||||
}
|
||||
|
||||
redirect("/login?registered=1");
|
||||
// The login lookup is cached for 15s — drop any stale entry so the
|
||||
// immediate auto sign-in sees the fresh row.
|
||||
await invalidateKey(`login:user:${username}`);
|
||||
|
||||
// Verification email must never block the sign-up response — it is sent
|
||||
// after the response is flushed (no-op when mail is unconfigured).
|
||||
if (hasEmail) {
|
||||
after(async () => {
|
||||
try {
|
||||
await sendVerification(mail);
|
||||
} catch {
|
||||
logger.warn("Failed to send verification email after registration");
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
// Client auto signs in with these credentials and navigates to /me.
|
||||
return { error: null, ok: true };
|
||||
}
|
||||
Reference in new issue
Block a user