Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
236 lines
6.2 KiB
TypeScript
236 lines
6.2 KiB
TypeScript
import { asc, eq } from "drizzle-orm";
|
|
import { CheckCircle2, Clock, MailX } from "lucide-react";
|
|
import type { Metadata } from "next";
|
|
import { getTranslations } from "next-intl/server";
|
|
import { ResendVerificationForm } from "@/components/auth/resend-verification-form";
|
|
import Link from "@/components/link";
|
|
import { SurfaceCard } from "@/components/surface-card";
|
|
import { isValidVerificationToken } from "@/lib/auth/email-verification";
|
|
import { db, User } from "@/lib/db";
|
|
|
|
export async function generateMetadata(): Promise<Metadata> {
|
|
const t = await getTranslations("pages.verify");
|
|
return {
|
|
title: t("verifiedTitle"),
|
|
description: t("invalidSubtitle"),
|
|
// Token links are single-use; the page itself has nothing to index.
|
|
robots: { index: false, follow: false },
|
|
};
|
|
}
|
|
|
|
type Status = "verified" | "already" | "invalid" | "unavailable";
|
|
|
|
function StatusCard({
|
|
icon,
|
|
title,
|
|
subtitle,
|
|
children,
|
|
color,
|
|
}: {
|
|
icon: React.ReactNode;
|
|
title: string;
|
|
subtitle: string;
|
|
children: React.ReactNode;
|
|
color: string;
|
|
}) {
|
|
const tintMap: Record<string, string> = {
|
|
green: "#16a34a",
|
|
yellow: "#d97706",
|
|
red: "#dc2626",
|
|
blue: "#2563eb",
|
|
};
|
|
const tint = tintMap[color] ?? tintMap.blue;
|
|
|
|
return (
|
|
<section className="flex min-h-[60vh] items-center justify-center px-4">
|
|
<SurfaceCard className="w-full max-w-md">
|
|
<div
|
|
className="flex items-center gap-2.5 border-b px-5 py-4"
|
|
style={{
|
|
background: `color-mix(in srgb, ${tint} 12%, var(--color-surface))`,
|
|
borderColor:
|
|
"color-mix(in srgb, var(--color-text-muted) 10%, transparent)",
|
|
}}
|
|
>
|
|
<span
|
|
className="flex h-7 w-7 items-center justify-center rounded-lg"
|
|
style={{
|
|
background: `color-mix(in srgb, ${tint} 18%, transparent)`,
|
|
color: tint,
|
|
}}
|
|
>
|
|
{icon}
|
|
</span>
|
|
<h1
|
|
className="text-sm font-bold tracking-tight"
|
|
style={{ color: "var(--color-text-readable)" }}
|
|
>
|
|
{title}
|
|
</h1>
|
|
</div>
|
|
<div className="flex flex-col items-center gap-4 px-6 py-8 text-center">
|
|
<div
|
|
className="flex h-16 w-16 items-center justify-center rounded-full"
|
|
style={{
|
|
background: `color-mix(in srgb, ${tint} 12%, transparent)`,
|
|
color: tint,
|
|
}}
|
|
>
|
|
{icon}
|
|
</div>
|
|
<p
|
|
className="text-sm font-semibold"
|
|
style={{ color: "var(--color-text-muted)" }}
|
|
>
|
|
{subtitle}
|
|
</p>
|
|
{children}
|
|
</div>
|
|
</SurfaceCard>
|
|
</section>
|
|
);
|
|
}
|
|
|
|
export default async function VerifyPage({
|
|
searchParams,
|
|
}: {
|
|
searchParams: Promise<{
|
|
token?: string;
|
|
email?: string;
|
|
}>;
|
|
}) {
|
|
const t = await getTranslations("pages.verify");
|
|
const { token = "", email = "" } = await searchParams;
|
|
const normalisedEmail = email.trim().toLowerCase();
|
|
|
|
let status: Status = "invalid";
|
|
|
|
if (normalisedEmail && token) {
|
|
const ok = await isValidVerificationToken(normalisedEmail, token);
|
|
if (ok) {
|
|
try {
|
|
// Legacy databases allow duplicate addresses; always resolve the
|
|
// oldest account so the link cannot verify a different one.
|
|
const matches = await db
|
|
.select({ id: User.id, mailVerified: User.mailVerified })
|
|
.from(User)
|
|
.where(eq(User.mail, normalisedEmail))
|
|
.orderBy(asc(User.id));
|
|
const user = matches[0];
|
|
if (!user) {
|
|
status = "invalid";
|
|
} else if (user.mailVerified === "1") {
|
|
status = "already";
|
|
} else {
|
|
await db
|
|
.update(User)
|
|
.set({ mailVerified: "1" })
|
|
.where(eq(User.id, user.id));
|
|
status = "verified";
|
|
}
|
|
} catch {
|
|
status = "unavailable";
|
|
}
|
|
}
|
|
}
|
|
|
|
const linkClass =
|
|
"btn-shine inline-flex items-center gap-2 font-extrabold text-sm px-6 py-3 rounded-xl transition-all duration-200 hover:scale-[1.02] active:scale-95 shadow-lg";
|
|
const linkStyle = {
|
|
background: "var(--color-primary)",
|
|
color: "var(--color-primary-foreground)",
|
|
boxShadow:
|
|
"0 4px 20px color-mix(in srgb, var(--color-primary) 30%, transparent)",
|
|
};
|
|
|
|
return (
|
|
<>
|
|
{status === "verified" && (
|
|
<StatusCard
|
|
icon={<CheckCircle2 size={22} />}
|
|
title={t("verifiedTitle")}
|
|
subtitle={t("verifiedSubtitle")}
|
|
color="green"
|
|
>
|
|
<p className="text-sm" style={{ color: "var(--color-text-muted)" }}>
|
|
{t("verifiedBody")}
|
|
</p>
|
|
<Link href="/login" className={linkClass} style={linkStyle}>
|
|
{t("goToLogin")}
|
|
</Link>
|
|
</StatusCard>
|
|
)}
|
|
|
|
{status === "already" && (
|
|
<StatusCard
|
|
icon={<CheckCircle2 size={22} />}
|
|
title={t("alreadyTitle")}
|
|
subtitle={t("alreadySubtitle")}
|
|
color="yellow"
|
|
>
|
|
<p className="text-sm" style={{ color: "var(--color-text-muted)" }}>
|
|
{t("alreadyBody")}
|
|
</p>
|
|
<Link href="/login" className={linkClass} style={linkStyle}>
|
|
{t("goToLogin")}
|
|
</Link>
|
|
</StatusCard>
|
|
)}
|
|
|
|
{status === "unavailable" && (
|
|
<StatusCard
|
|
icon={<Clock size={22} />}
|
|
title={t("unavailableTitle")}
|
|
subtitle={t("unavailableSubtitle")}
|
|
color="blue"
|
|
>
|
|
<p className="text-sm" style={{ color: "var(--color-text-muted)" }}>
|
|
{t("unavailableBody")}
|
|
</p>
|
|
{/* Transient failure: offer both the retry path and the way out
|
|
instead of leaving the visitor stranded on this card. */}
|
|
<ResendVerificationForm />
|
|
<Link
|
|
href="/login"
|
|
className={`${linkClass} !shadow-none`}
|
|
style={{
|
|
background: "transparent",
|
|
color: "var(--color-text-readable)",
|
|
border:
|
|
"2px solid color-mix(in srgb, var(--color-text-muted) 20%, transparent)",
|
|
}}
|
|
>
|
|
{t("backToLogin")}
|
|
</Link>
|
|
</StatusCard>
|
|
)}
|
|
|
|
{status === "invalid" && (
|
|
<StatusCard
|
|
icon={<MailX size={22} />}
|
|
title={t("invalidTitle")}
|
|
subtitle={t("invalidSubtitle")}
|
|
color="red"
|
|
>
|
|
<p className="text-sm" style={{ color: "var(--color-text-muted)" }}>
|
|
{t("invalidBody")}
|
|
</p>
|
|
<ResendVerificationForm />
|
|
<Link
|
|
href="/login"
|
|
className={`${linkClass} !shadow-none`}
|
|
style={{
|
|
background: "transparent",
|
|
color: "var(--color-text-readable)",
|
|
border:
|
|
"2px solid color-mix(in srgb, var(--color-text-muted) 20%, transparent)",
|
|
}}
|
|
>
|
|
{t("backToLogin")}
|
|
</Link>
|
|
</StatusCard>
|
|
)}
|
|
</>
|
|
);
|
|
}
|