Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
143 lines
4.6 KiB
TypeScript
143 lines
4.6 KiB
TypeScript
"use server";
|
|
|
|
import { eq } from "drizzle-orm";
|
|
import { revalidatePath } from "next/cache";
|
|
import { z } from "zod";
|
|
import { MANAGED_SETTING_KEYS } from "@/app/admin/settings/cms-settings-config";
|
|
import { requirePermissionRateLimited } from "@/lib/admin/guard";
|
|
import { db, WebsiteSetting } from "@/lib/db";
|
|
import { actionOk, adminAction } from "@/lib/foundation/action";
|
|
import {
|
|
HABBO_GAMEDATA_HOTEL_SETTING_KEY,
|
|
normalizeHabboGamedataHotel,
|
|
} from "@/lib/habbo-gamedata-hotel";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import { clearOfficialHabboFurnidataCache } from "@/lib/services/habbo-furnidata-cache";
|
|
import { clearBadgeCache } from "@/lib/services/habboassets";
|
|
import {
|
|
isSecretSettingKey,
|
|
SECRET_PLACEHOLDER,
|
|
} from "@/lib/services/setting-secrets";
|
|
import { siteSettings } from "@/lib/services/site-settings";
|
|
|
|
const managedKeySet = new Set(MANAGED_SETTING_KEYS);
|
|
|
|
// Raw keys only the CMS core is allowed to own. Writing an arbitrary key from
|
|
// the generic "advanced key/value" form previously meant a staff member could
|
|
// overwrite `turnstile_secret`, `force_staff_2fa` or `min_staff_rank`.
|
|
const RAW_SETTING_KEY_RE = /^[a-z0-9][a-z0-9_.-]{0,127}$/;
|
|
|
|
function normalizeSettingValue(key: string, value: string): string {
|
|
if (key === HABBO_GAMEDATA_HOTEL_SETTING_KEY) {
|
|
return normalizeHabboGamedataHotel(value);
|
|
}
|
|
return value;
|
|
}
|
|
|
|
function bustGamedataCachesIfNeeded(key: string): void {
|
|
if (key === HABBO_GAMEDATA_HOTEL_SETTING_KEY) {
|
|
clearOfficialHabboFurnidataCache();
|
|
clearBadgeCache();
|
|
}
|
|
}
|
|
|
|
const saveManagedSchema = z.object({
|
|
settings: z.record(z.string(), z.string()),
|
|
});
|
|
|
|
export const saveManagedSettings = adminAction(
|
|
{
|
|
permission: PERMS.SETTINGS_EDIT,
|
|
schema: saveManagedSchema,
|
|
rateLimitKey: "admin-settings-save",
|
|
rateLimitMax: 30,
|
|
},
|
|
async (ctx) => {
|
|
const entries = Object.entries(ctx.data.settings)
|
|
.filter(([key]) => managedKeySet.has(key))
|
|
.map(([key, value]) => [key, normalizeSettingValue(key, value)] as const);
|
|
await Promise.all(
|
|
entries.map(([key, value]) =>
|
|
db
|
|
.insert(WebsiteSetting)
|
|
.values({ key, value })
|
|
.onDuplicateKeyUpdate({ set: { value } }),
|
|
),
|
|
);
|
|
await siteSettings.reload();
|
|
if (entries.some(([key]) => key === HABBO_GAMEDATA_HOTEL_SETTING_KEY)) {
|
|
clearOfficialHabboFurnidataCache();
|
|
clearBadgeCache();
|
|
}
|
|
revalidatePath("/admin/settings");
|
|
revalidatePath("/admin/catalog");
|
|
return actionOk({ saved: entries.length });
|
|
},
|
|
);
|
|
|
|
export async function updateSetting(formData: FormData): Promise<void> {
|
|
await requirePermissionRateLimited(PERMS.SETTINGS_EDIT);
|
|
const key = String(formData.get("key") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
const raw = String(formData.get("value") ?? "").normalize("NFC");
|
|
if (!key || !RAW_SETTING_KEY_RE.test(key)) return;
|
|
// Blank on a secret means "keep what is stored", so the UI can render a
|
|
// placeholder without the risk of wiping the credential.
|
|
if (isSecretSettingKey(key) && raw === SECRET_PLACEHOLDER) return;
|
|
const value = isSecretSettingKey(key) ? raw : normalizeSettingValue(key, raw);
|
|
await db
|
|
.insert(WebsiteSetting)
|
|
.values({ key, value })
|
|
.onDuplicateKeyUpdate({ set: { value } });
|
|
await siteSettings.reload();
|
|
bustGamedataCachesIfNeeded(key);
|
|
revalidatePath("/admin/settings");
|
|
}
|
|
|
|
export async function createSetting(formData: FormData): Promise<void> {
|
|
await requirePermissionRateLimited(PERMS.SETTINGS_EDIT);
|
|
const key = String(formData.get("key") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 128);
|
|
const value = normalizeSettingValue(
|
|
key,
|
|
String(formData.get("value") ?? "").normalize("NFC"),
|
|
);
|
|
const comment = String(formData.get("comment") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
// Managed keys go through `saveManagedSettings`; anything else must be a
|
|
// clearly namespaced custom key, and lockout/security settings are never
|
|
// writable through the free-form form.
|
|
if (!key || !RAW_SETTING_KEY_RE.test(key)) return;
|
|
if (
|
|
key === "force_staff_2fa" ||
|
|
key === "min_staff_rank" ||
|
|
key === "maintenance_enabled"
|
|
) {
|
|
return;
|
|
}
|
|
await db
|
|
.insert(WebsiteSetting)
|
|
.values({ key, value, comment: comment || null })
|
|
.onDuplicateKeyUpdate({ set: { value } });
|
|
await siteSettings.reload();
|
|
bustGamedataCachesIfNeeded(key);
|
|
revalidatePath("/admin/settings");
|
|
}
|
|
|
|
export async function deleteSetting(formData: FormData): Promise<void> {
|
|
await requirePermissionRateLimited(PERMS.SETTINGS_EDIT);
|
|
const key = String(formData.get("key") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
if (!key) return;
|
|
await db.delete(WebsiteSetting).where(eq(WebsiteSetting.key, key));
|
|
await siteSettings.reload();
|
|
bustGamedataCachesIfNeeded(key);
|
|
revalidatePath("/admin/settings");
|
|
}
|