Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
184 lines
4.9 KiB
TypeScript
184 lines
4.9 KiB
TypeScript
"use server";
|
|
|
|
import { and, eq, inArray } from "drizzle-orm";
|
|
import { revalidatePath } from "next/cache";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import { db, Items, Rooms } from "@/lib/db";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
import { notify } from "@/lib/services/webhook";
|
|
|
|
// Only these columns may be patched from the client. Spreading the whole payload
|
|
// into `.set()` let a caller rewrite roomId/userId/extraData of any row, which
|
|
// is mass assignment and IDOR in one.
|
|
const ROOM_ITEM_FIELDS = [
|
|
"wallPos",
|
|
"x",
|
|
"y",
|
|
"z",
|
|
"rot",
|
|
"extraData",
|
|
"wiredData",
|
|
"limitedData",
|
|
"guildId",
|
|
] as const;
|
|
|
|
const ROOM_FIELDS = ["name", "description", "state", "usersMax"] as const;
|
|
|
|
function pickAllowed(
|
|
fields: Record<string, unknown>,
|
|
allowed: readonly string[],
|
|
): Record<string, unknown> {
|
|
const out: Record<string, unknown> = {};
|
|
for (const key of allowed) {
|
|
if (Object.hasOwn(fields, key) && fields[key] !== undefined) {
|
|
out[key] = fields[key];
|
|
}
|
|
}
|
|
return out;
|
|
}
|
|
|
|
function toPositiveInt(value: unknown): number | null {
|
|
const n = typeof value === "number" ? value : Number(value);
|
|
return Number.isInteger(n) && n > 0 ? n : null;
|
|
}
|
|
|
|
export async function updateRoomItem(payload: Record<string, unknown>) {
|
|
const staff = await requirePermission(PERMS.ROOMS_EDIT);
|
|
const roomId = toPositiveInt(payload.roomId);
|
|
const itemId = toPositiveInt(payload.itemId);
|
|
if (!roomId || !itemId) {
|
|
throw new Error("Invalid room or item id");
|
|
}
|
|
// The item must belong to the room the staff member is editing.
|
|
const [item] = await db
|
|
.select({ id: Items.id })
|
|
.from(Items)
|
|
.where(and(eq(Items.id, itemId), eq(Items.roomId, roomId)))
|
|
.limit(1);
|
|
if (!item) throw new Error("Item not found in this room");
|
|
|
|
await db
|
|
.update(Items)
|
|
.set(
|
|
pickAllowed(payload, ROOM_ITEM_FIELDS) as Partial<
|
|
typeof Items.$inferInsert
|
|
>,
|
|
)
|
|
.where(eq(Items.id, itemId));
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "room_item_update",
|
|
description: `Updated item #${itemId} in room #${roomId}`,
|
|
targetType: "room_item",
|
|
targetId: itemId,
|
|
});
|
|
revalidatePath(`/admin/rooms/${roomId}/furni`);
|
|
}
|
|
|
|
export async function bulkDeleteRoomItems({
|
|
roomId,
|
|
itemIds,
|
|
}: {
|
|
roomId: number;
|
|
itemIds: number[];
|
|
}) {
|
|
const staff = await requirePermission(PERMS.ROOMS_EDIT);
|
|
await db
|
|
.delete(Items)
|
|
.where(and(inArray(Items.id, itemIds), eq(Items.roomId, roomId)));
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "room_items_bulk_delete",
|
|
description: `Deleted ${itemIds.length} item(s) from room #${roomId}`,
|
|
targetType: "room_item",
|
|
});
|
|
revalidatePath(`/admin/rooms/${roomId}/furni`);
|
|
}
|
|
|
|
export async function deleteRoomItem({
|
|
roomId,
|
|
itemId,
|
|
}: {
|
|
roomId: number;
|
|
itemId: number;
|
|
}) {
|
|
const staff = await requirePermission(PERMS.ROOMS_EDIT);
|
|
await db.delete(Items).where(eq(Items.id, itemId));
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "room_item_delete",
|
|
description: `Deleted item #${itemId} from room #${roomId}`,
|
|
targetType: "room_item",
|
|
targetId: itemId,
|
|
});
|
|
revalidatePath(`/admin/rooms/${roomId}/furni`);
|
|
}
|
|
|
|
export async function roomRconAction({
|
|
roomId,
|
|
action,
|
|
}: {
|
|
roomId: number;
|
|
action: string;
|
|
}) {
|
|
const staff = await requirePermission(PERMS.ROOMS_EDIT);
|
|
if (action === "reload") {
|
|
await rcon.send("reloadroom", { room_id: roomId });
|
|
} else if (action === "kick") {
|
|
await rcon.send("kickall", { room_id: roomId });
|
|
notify({
|
|
action: "kick",
|
|
actor: staff.username,
|
|
target: String(roomId),
|
|
details: action,
|
|
});
|
|
} else if (action === "lock") {
|
|
await rcon.send("updateroom", { room_id: roomId, state: "locked" });
|
|
} else if (action === "unlock") {
|
|
await rcon.send("updateroom", { room_id: roomId, state: "open" });
|
|
}
|
|
}
|
|
|
|
export async function deleteRoom({ id }: { id: number }) {
|
|
const staff = await requirePermission(PERMS.ROOMS_DELETE);
|
|
const [room] = await db
|
|
.select({ name: Rooms.name })
|
|
.from(Rooms)
|
|
.where(eq(Rooms.id, id))
|
|
.limit(1);
|
|
await db.delete(Rooms).where(eq(Rooms.id, id));
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "room_delete",
|
|
description: `Deleted room #${id}`,
|
|
targetType: "room",
|
|
targetId: id,
|
|
});
|
|
notify({
|
|
action: "room_delete",
|
|
actor: staff.username,
|
|
target: room?.name ?? `#${id}`,
|
|
});
|
|
revalidatePath("/admin/rooms");
|
|
}
|
|
|
|
export async function updateRoom({ id, ...data }: Record<string, unknown>) {
|
|
const staff = await requirePermission(PERMS.ROOMS_EDIT);
|
|
const roomId = toPositiveInt(id);
|
|
if (!roomId) throw new Error("Invalid room id");
|
|
await db
|
|
.update(Rooms)
|
|
.set(pickAllowed(data, ROOM_FIELDS) as Partial<typeof Rooms.$inferInsert>)
|
|
.where(eq(Rooms.id, roomId));
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "room_update",
|
|
description: `Updated room #${roomId}`,
|
|
targetType: "room",
|
|
targetId: roomId,
|
|
});
|
|
revalidatePath(`/admin/rooms/${roomId}`);
|
|
}
|