Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
188 lines
5.2 KiB
TypeScript
188 lines
5.2 KiB
TypeScript
// @ts-nocheck
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import {
|
|
bulkBan,
|
|
bulkGiveBadge,
|
|
bulkGiveCurrency,
|
|
bulkUnban,
|
|
} from "./bulk-users";
|
|
|
|
const {
|
|
deleteWhere,
|
|
insertValues,
|
|
updateWhere,
|
|
selectLimit,
|
|
selectWhereResolved,
|
|
onDuplicateKeyUpdate,
|
|
} = vi.hoisted(() => {
|
|
const deleteWhere = vi.fn().mockResolvedValue([{ affectedRows: 3 }]);
|
|
const onDuplicateKeyUpdate = vi.fn().mockResolvedValue([{ affectedRows: 1 }]);
|
|
const insertValues = vi.fn(() => ({
|
|
onDuplicateKeyUpdate,
|
|
// biome-ignore lint/suspicious/noThenProperty: Drizzle query thenable mock
|
|
then(resolve, reject) {
|
|
return Promise.resolve([{ insertId: 1 }]).then(resolve, reject);
|
|
},
|
|
}));
|
|
const updateWhere = vi.fn().mockResolvedValue([{ affectedRows: 1 }]);
|
|
const selectLimit = vi.fn().mockResolvedValue([]);
|
|
/** Rows returned when a select chain is awaited without `.limit()`. */
|
|
const selectWhereResolved = vi.fn().mockResolvedValue([]);
|
|
return {
|
|
deleteWhere,
|
|
insertValues,
|
|
updateWhere,
|
|
selectLimit,
|
|
selectWhereResolved,
|
|
onDuplicateKeyUpdate,
|
|
};
|
|
});
|
|
|
|
vi.mock("@/lib/admin/guard", () => ({ requirePermission: vi.fn() }));
|
|
vi.mock("@/lib/permissions", () => ({
|
|
PERMS: { USERS_EDIT: "users.edit" },
|
|
// Staff (rank 7) may act on anyone below the hotel's top rank.
|
|
getHighestRank: vi.fn(() => Promise.resolve(10)),
|
|
}));
|
|
vi.mock("@/lib/db", () => ({
|
|
db: {
|
|
delete: vi.fn(() => ({ where: deleteWhere })),
|
|
insert: vi.fn(() => ({ values: insertValues })),
|
|
update: vi.fn(() => ({
|
|
set: vi.fn(() => ({ where: updateWhere })),
|
|
})),
|
|
select: vi.fn(() => ({
|
|
from: vi.fn(() => ({
|
|
where: vi.fn(() => ({
|
|
limit: selectLimit,
|
|
// biome-ignore lint/suspicious/noThenProperty: Drizzle query thenable mock
|
|
then(resolve, reject) {
|
|
return selectWhereResolved().then(resolve, reject);
|
|
},
|
|
})),
|
|
})),
|
|
})),
|
|
transaction: vi.fn(),
|
|
},
|
|
Ban: { userId: "userId", id: "id" },
|
|
User: {
|
|
id: "id",
|
|
credits: "credits",
|
|
username: "username",
|
|
online: "online",
|
|
},
|
|
UsersCurrency: { userId: "userId", type: "type", amount: "amount" },
|
|
UsersBadges: {
|
|
id: "id",
|
|
userId: "userId",
|
|
badgeCode: "badgeCode",
|
|
slotId: "slotId",
|
|
},
|
|
Sanctions: { id: "id", habboId: "habboId" },
|
|
UsersSettings: {
|
|
userId: "userId",
|
|
canTrade: "canTrade",
|
|
tradelockAmount: "tradelockAmount",
|
|
},
|
|
}));
|
|
vi.mock("@/lib/services/rcon", () => ({
|
|
rcon: {
|
|
giveCredits: vi.fn(),
|
|
giveDuckets: vi.fn(),
|
|
givePointsGotw: vi.fn(),
|
|
giveBadge: vi.fn(),
|
|
},
|
|
}));
|
|
vi.mock("@/lib/services/staff-activity", () => ({ logStaffActivity: vi.fn() }));
|
|
|
|
const staff = { id: 1, rank: 7, username: "admin" };
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
vi.mocked(requirePermission).mockResolvedValue(staff as never);
|
|
deleteWhere.mockResolvedValue([{ affectedRows: 3 }]);
|
|
insertValues.mockImplementation(() => ({
|
|
onDuplicateKeyUpdate,
|
|
// biome-ignore lint/suspicious/noThenProperty: Drizzle query thenable mock
|
|
then(resolve, reject) {
|
|
return Promise.resolve([{ insertId: 1 }]).then(resolve, reject);
|
|
},
|
|
}));
|
|
onDuplicateKeyUpdate.mockResolvedValue([{ affectedRows: 1 }]);
|
|
updateWhere.mockResolvedValue([{ affectedRows: 1 }]);
|
|
selectLimit.mockResolvedValue([]);
|
|
// Rank rows for the per-id rank guard: every target sits below staff rank 7.
|
|
selectWhereResolved.mockResolvedValue([{ rank: 1 }]);
|
|
// Max slot of existing badges (consumed by the badge loop, not the guard).
|
|
selectWhereResolved.mockResolvedValueOnce([{ rank: 1 }]);
|
|
});
|
|
|
|
describe("bulkUnban", () => {
|
|
it("unbans users", async () => {
|
|
const r = await bulkUnban({ userIds: [1, 2, 3] });
|
|
expect(r.ok).toBe(true);
|
|
expect(r.data).toEqual({ unbanned: 3, total: 3 });
|
|
});
|
|
});
|
|
|
|
describe("bulkBan", () => {
|
|
it("bans users", async () => {
|
|
const r = await bulkBan({
|
|
userIds: [1, 2],
|
|
reason: "Spam",
|
|
duration: 3600,
|
|
});
|
|
expect(r.ok).toBe(true);
|
|
expect(r.data.banned).toBe(2);
|
|
expect(insertValues).toHaveBeenCalledTimes(2);
|
|
});
|
|
});
|
|
|
|
describe("bulkGiveCurrency", () => {
|
|
it("gives credits", async () => {
|
|
const r = await bulkGiveCurrency({
|
|
userIds: [1],
|
|
amount: 100,
|
|
type: "credits",
|
|
});
|
|
expect(r.data.given).toBe(1);
|
|
expect(rcon.giveCredits).toHaveBeenCalledWith(1, 100);
|
|
expect(updateWhere).toHaveBeenCalled();
|
|
});
|
|
|
|
it("gives pixels", async () => {
|
|
const r = await bulkGiveCurrency({
|
|
userIds: [2],
|
|
amount: 50,
|
|
type: "pixels",
|
|
});
|
|
expect(r.data.given).toBe(1);
|
|
expect(rcon.giveDuckets).toHaveBeenCalledWith(2, 50);
|
|
expect(onDuplicateKeyUpdate).toHaveBeenCalled();
|
|
});
|
|
|
|
it("gives points", async () => {
|
|
const r = await bulkGiveCurrency({
|
|
userIds: [3],
|
|
amount: 25,
|
|
type: "points",
|
|
});
|
|
expect(r.data.given).toBe(1);
|
|
expect(rcon.givePointsGotw).toHaveBeenCalledWith(3, 25);
|
|
expect(onDuplicateKeyUpdate).toHaveBeenCalled();
|
|
});
|
|
});
|
|
|
|
describe("bulkGiveBadge", () => {
|
|
it("gives badge to user", async () => {
|
|
selectLimit.mockResolvedValueOnce([]);
|
|
selectWhereResolved.mockResolvedValueOnce([{ maxSlot: 5 }]);
|
|
const r = await bulkGiveBadge({ userIds: [1], badgeCode: "ADM" });
|
|
expect(r.data.given).toBe(1);
|
|
expect(insertValues).toHaveBeenCalled();
|
|
expect(rcon.giveBadge).toHaveBeenCalledWith(1, "ADM");
|
|
});
|
|
});
|