Files
EpicNext-Cms/src/app/(site)/apply/team/page.tsx
T
openhands 6cc45d7413
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
feat: harden atoms-nexst against review findings (37 items)
Second review pass covering security, performance, admin tooling and the
public/room flows. All HIGH and MEDIUM findings from the audit are resolved;
nothing in this commit changes the visible feature set.

Authentication & session security
- CSP is now set on the request headers in the proxy, which is what Next.js
  uses to derive the render nonce, so the nonce is effective.
- 2FA: an already-enabled user cannot re-enroll, the setup endpoint is
  rate-limited per account, and confirmed codes are persisted so the second
  secret no longer silently never applies.
- Password reset revokes the ticket, authTicket and all personal access
  tokens, and bumps the token version so existing sessions die. The same
  revocation is now wired into the staff-side password reset.
- /reset and /verify return a stable error code instead of raw text; the
  mail lookups are ordered by id so duplicates cannot vary between runs.
- Resending the verification mail gets a per-address cooldown on top of the
  per-user limit.
- Issue API tokens with the narrower radio/ticket ability set instead of "*".

Authorization & input handling
- Mid-rank staff can no longer keep dynamically granted non-view admin.*
  permissions: existing grants are revoked by migration and the grant lookup
  is restricted to "%.view". Rank guards use the dynamic super-admin check.
- Alerting a user is permission-checked and audited like the other tools.
- Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user
  actions route, bulk user actions) are capped and rank-guarded, and bulk
  ids are bounded.
- updateRoom / updateRoomItem write through a field allowlist, and items
  may only be edited through their own room.
- Classnames reaching the filesystem are validated before use so a crafted
  value cannot escape the asset directories.
- The word filter now also covers offline mails, guild forum threads and
  replies, and user mottos.
- Media uploads are validated by magic bytes, /api/media requires the page
  edit permission, APP_URL must be configured once mail is enabled, and the
  diagnostics error route checks the fetch site header.

Admin tooling
- Secret settings render masked and cannot be overwritten with a blank or
  an arbitrary raw key; radio credentials are new password inputs.
- Commandocentrum balance changes are audited.
- Admin list pagination reads the caller's per-page instead of the max, and
  the log exporter caps offset and search length.

Performance
- Catalog translations are cached per module, with a cheap revision hash;
  the public online count uses a stale window instead of hammering the DB.
- The cache warmup now primes the payload the home route actually reads.
- TopHeader batches its queries into one round trip, and LCP avatars load
  eagerly.
- motion/react and sonner are no longer part of the root layout; the nav
  dropdown and mobile nav panels are lazy client chunks. Anonymous visitors
  again get the navigation chrome, and public pages get an edge cacheable
  response.

Accessibility
- Nested <main> elements in phase pages became <section>; the page entrance
  and route progress animations are pure CSS that respect reduced motion.
2026-10-09 16:19:48 +02:00

205 lines
5.9 KiB
TypeScript

import { asc, eq } from "drizzle-orm";
import type { Metadata } from "next";
import { redirect } from "next/navigation";
import { getTranslations } from "next-intl/server";
import type { CSSProperties } from "react";
import { applyTeam } from "@/actions/applications";
import { ContentCard, EmptyState } from "@/components/public/ui";
import { auth } from "@/lib/auth";
import { db, WebsiteStaffApplications, WebsiteTeams } from "@/lib/db";
import { resolveHotelName } from "@/lib/hotel-name";
export async function generateMetadata(): Promise<Metadata> {
const t = await getTranslations("pages.applyTeam");
return {
title: t("title"),
description: t("subtitle"),
openGraph: {
title: t("title"),
description: t("subtitle"),
type: "website",
},
};
}
// Badge codes map to a .gif served through the cached proxy.
const BADGE_IMG_BASE = "/api/imaging/badge?code";
function feedbackStyle(tone: "success" | "error"): CSSProperties {
const accent =
tone === "error" ? "var(--color-danger)" : "var(--color-primary)";
return {
margin: 0,
padding: "0.85rem 1rem",
borderRadius: "var(--radius-md)",
border: `1px solid ${accent}`,
color: "var(--color-text-readable, var(--color-text))",
fontSize: "0.9rem",
fontWeight: 600,
background: "var(--color-surface)",
borderLeft: `4px solid ${accent}`,
};
}
export default async function ApplyTeamPage({
searchParams,
}: {
searchParams: Promise<{ submitted?: string; error?: string }>;
}) {
const session = await auth();
if (!session?.user?.id) redirect("/login");
const t = await getTranslations("pages.applyTeam");
const { submitted, error } = await searchParams;
const errorMessage =
error === "empty"
? t("errors.empty")
: error === "duplicate"
? t("errors.duplicate")
: error === "ratelimit"
? t("errors.ratelimit")
: error === "invalid"
? t("errors.invalid")
: error
? t("errors.error")
: null;
const userId = Number(session.user.id);
const hotelName = await resolveHotelName();
// ── Teams open for application ──────────────────────────────
// Teams are exposed directly (no separate team-position table
// with position_kind), so the team application concept lists website_teams.
// Hidden ranks are excluded from the public apply page.
const teams = await db
.select()
.from(WebsiteTeams)
.where(eq(WebsiteTeams.hiddenRank, false))
.orderBy(asc(WebsiteTeams.rankName))
.catch(() => []);
// Teams this user has already applied to. Team applications reuse the staff
// applications table with rank_id carrying the team id (the team flag).
const myApps = await db
.select({ rankId: WebsiteStaffApplications.rankId })
.from(WebsiteStaffApplications)
.where(eq(WebsiteStaffApplications.userId, userId))
.catch(() => []);
const appliedTeamIds = new Set(myApps.map((a) => a.rankId));
return (
<section className="page-grid">
{submitted === "1" ? (
<div role="status" style={feedbackStyle("success")}>
{t("success.submitted")}
</div>
) : null}
{errorMessage ? (
<div role="alert" style={feedbackStyle("error")}>
{errorMessage}
</div>
) : null}
<ContentCard
icon="🤝"
title={t("title", { hotel: hotelName })}
subtitle={t("subtitle")}
/>
{teams.length === 0 ? (
<ContentCard icon="🤝" title={t("noPositionsTitle")}>
<EmptyState icon="🤝">{t("noPositionsBody")}</EmptyState>
</ContentCard>
) : (
<div className="card-grid sm-2">
{teams.map((team) => {
const teamId = Number(team.id);
const alreadyApplied = appliedTeamIds.has(teamId);
return (
<article key={String(team.id)} className="content-card">
<div className="content-card-head">
{team.badge ? (
/* eslint-disable-next-line @next/next/no-img-element */
<img
src={`${BADGE_IMG_BASE}=${encodeURIComponent(team.badge)}`}
alt={team.rankName}
width={40}
height={40}
/>
) : (
<span className="content-card-icon" aria-hidden>
🤝
</span>
)}
<div className="content-card-head-text">
<p
className="content-card-title"
style={{ color: team.staffColor || undefined }}
>
{team.rankName}
</p>
{team.jobDescription ? (
<p className="content-card-subtitle">
{team.jobDescription}
</p>
) : null}
</div>
</div>
<div className="content-card-body">
{alreadyApplied ? (
<button
type="button"
className="btn btn-danger"
disabled
style={{ width: "100%" }}
>
{t("pending")}
</button>
) : (
<form action={applyTeam}>
{/* The team id is the application's rank flag; the applicant
is re-read from the session inside the action. */}
<input
type="hidden"
name="teamId"
value={String(team.id)}
/>
<label htmlFor={`content-${team.id}`} className="muted">
{t("aboutYou")}
</label>
<textarea
id={`content-${team.id}`}
name="content"
required
minLength={10}
rows={5}
placeholder={t("aboutPlaceholder", {
rank: team.rankName,
})}
style={{
width: "100%",
margin: "0.4rem 0 0.75rem",
resize: "vertical",
}}
/>
<button
type="submit"
className="btn btn-primary"
style={{ width: "100%" }}
>
{t("applyFor", { rank: team.rankName })}
</button>
</form>
)}
</div>
</article>
);
})}
</div>
)}
</section>
);
}