Files
EpicNext-Cms/src/actions/users.test.ts
T
openhands 6cc45d7413
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
feat: harden atoms-nexst against review findings (37 items)
Second review pass covering security, performance, admin tooling and the
public/room flows. All HIGH and MEDIUM findings from the audit are resolved;
nothing in this commit changes the visible feature set.

Authentication & session security
- CSP is now set on the request headers in the proxy, which is what Next.js
  uses to derive the render nonce, so the nonce is effective.
- 2FA: an already-enabled user cannot re-enroll, the setup endpoint is
  rate-limited per account, and confirmed codes are persisted so the second
  secret no longer silently never applies.
- Password reset revokes the ticket, authTicket and all personal access
  tokens, and bumps the token version so existing sessions die. The same
  revocation is now wired into the staff-side password reset.
- /reset and /verify return a stable error code instead of raw text; the
  mail lookups are ordered by id so duplicates cannot vary between runs.
- Resending the verification mail gets a per-address cooldown on top of the
  per-user limit.
- Issue API tokens with the narrower radio/ticket ability set instead of "*".

Authorization & input handling
- Mid-rank staff can no longer keep dynamically granted non-view admin.*
  permissions: existing grants are revoked by migration and the grant lookup
  is restricted to "%.view". Rank guards use the dynamic super-admin check.
- Alerting a user is permission-checked and audited like the other tools.
- Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user
  actions route, bulk user actions) are capped and rank-guarded, and bulk
  ids are bounded.
- updateRoom / updateRoomItem write through a field allowlist, and items
  may only be edited through their own room.
- Classnames reaching the filesystem are validated before use so a crafted
  value cannot escape the asset directories.
- The word filter now also covers offline mails, guild forum threads and
  replies, and user mottos.
- Media uploads are validated by magic bytes, /api/media requires the page
  edit permission, APP_URL must be configured once mail is enabled, and the
  diagnostics error route checks the fetch site header.

Admin tooling
- Secret settings render masked and cannot be overwritten with a blank or
  an arbitrary raw key; radio credentials are new password inputs.
- Commandocentrum balance changes are audited.
- Admin list pagination reads the caller's per-page instead of the max, and
  the log exporter caps offset and search length.

Performance
- Catalog translations are cached per module, with a cheap revision hash;
  the public online count uses a stale window instead of hammering the DB.
- The cache warmup now primes the payload the home route actually reads.
- TopHeader batches its queries into one round trip, and LCP avatars load
  eagerly.
- motion/react and sonner are no longer part of the root layout; the nav
  dropdown and mobile nav panels are lazy client chunks. Anonymous visitors
  again get the navigation chrome, and public pages get an edge cacheable
  response.

Accessibility
- Nested <main> elements in phase pages became <section>; the page entrance
  and route progress animations are pure CSS that respect reduced motion.
2026-10-09 16:19:48 +02:00

300 lines
7.7 KiB
TypeScript

// @ts-nocheck
import { beforeEach, describe, expect, it, vi } from "vitest";
vi.mock("next/server", () => ({
NextResponse: { json: vi.fn() },
}));
vi.mock("next-auth", () => ({
default: vi.fn(() => ({ handlers: {}, auth: vi.fn(), signOut: vi.fn() })),
}));
vi.mock("@/lib/auth", () => ({
auth: vi.fn(),
invalidateLoginCache: vi.fn(),
}));
vi.mock("@/lib/auth/password", () => ({
hashPassword: vi.fn().mockResolvedValue("hashed_pass_123"),
}));
const { insertValues, deleteWhere, updateSet, selectLimit } = vi.hoisted(
() => ({
insertValues: vi.fn(),
deleteWhere: vi.fn(),
updateSet: vi.fn(),
selectLimit: vi.fn(),
}),
);
vi.mock("@/lib/db", () => ({
db: {
insert: vi.fn(() => ({
values: insertValues,
onDuplicateKeyUpdate: vi.fn().mockResolvedValue([]),
})),
update: vi.fn(() => ({ set: vi.fn(() => ({ where: updateSet })) })),
delete: vi.fn(() => ({ where: deleteWhere })),
select: vi.fn(() => ({
from: vi.fn(() => ({
where: vi.fn(() => ({ limit: selectLimit })),
})),
})),
transaction: vi.fn(async (cb: (tx: any) => Promise<any>) => {
const mockTx = {
insert: vi.fn(() => ({
values: vi.fn().mockResolvedValue([{ insertId: 42n }]),
})),
};
return cb(mockTx);
}),
},
User: { id: "User.id", username: "User.username", rank: "User.rank" },
Ban: { userId: "Ban.userId" },
UsersSettings: {},
UsersCurrency: {},
UsersBadges: { id: "UsersBadges.id" },
}));
vi.mock("@/lib/permissions", () => ({
PERMS: {
USERS_EDIT: "users.edit",
USERS_BAN: "users.ban",
USERS_RESET_PASSWORD: "users.reset_password",
},
// Staff in the fixtures is rank 7 and the hotel's top rank is 10, so rank
// guards act as "below-your-own-rank only".
getHighestRank: vi.fn(() => Promise.resolve(10)),
}));
vi.mock("@/lib/safe-action", () => ({
adminAction: vi.fn((_o: unknown, f: (...args: unknown[]) => unknown) => f),
}));
vi.mock("@/lib/safe-action-shared", () => ({
ActionError: class ActionError extends Error {},
actionOk: vi.fn((res) => ({ ok: true, data: res })),
}));
vi.mock("@/lib/services/audit", () => ({
logAudit: vi.fn(),
}));
vi.mock("@/lib/auth/session-revocation", () => ({
revokeUserCredentials: vi.fn(() => Promise.resolve()),
}));
vi.mock("@/lib/services/webhook", () => ({
notify: vi.fn(),
}));
vi.mock("@/lib/services/rcon", () => ({
rcon: {
disconnectUser: vi.fn().mockResolvedValue(true),
giveBadge: vi.fn().mockResolvedValue(true),
removeBadge: vi.fn().mockResolvedValue(true),
alertUser: vi.fn().mockResolvedValue(true),
muteUser: vi.fn().mockResolvedValue(true),
unmuteUser: vi.fn().mockResolvedValue(true),
giveCredits: vi.fn().mockResolvedValue(true),
},
}));
import { ActionError } from "@/lib/safe-action-shared";
import { logAudit } from "@/lib/services/audit";
import { rcon } from "@/lib/services/rcon";
import {
alertUser,
banUser,
createUser,
disconnectUser,
giveBadge,
muteUser,
removeBadge,
resetPassword,
unbanUser,
unmuteUser,
} from "./users";
const mockContext = (data: any, rank = 7) => ({
data,
session: {
user: {
id: 1,
username: "superadmin",
rank,
},
},
});
beforeEach(() => {
vi.clearAllMocks();
selectLimit.mockResolvedValue([
{ username: "targetuser", rank: 1, mail: "[email protected]" },
]);
deleteWhere.mockResolvedValue([{ affectedRows: 1 }]);
updateSet.mockResolvedValue([{ affectedRows: 1 }]);
insertValues.mockResolvedValue([{ insertId: 100n }]);
});
describe("createUser action", () => {
it("creates a user successfully and logs audit", async () => {
const ctx = mockContext({
username: "newuser",
mail: "[email protected]",
password: "password123",
rank: 1,
motto: "Hello world",
});
const res = await (createUser as any)(ctx);
expect(res).toEqual({ ok: true, data: { id: 42, username: "newuser" } });
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "user_create",
targetId: 42,
}),
);
});
it("throws error if admin assigns rank equal or higher than their own", async () => {
const ctx = mockContext(
{
username: "moduser",
mail: "[email protected]",
password: "password123",
rank: 5,
},
5, // admin with rank 5 trying to set rank 5
);
await expect((createUser as any)(ctx)).rejects.toThrow(ActionError);
});
});
describe("banUser & unbanUser actions", () => {
it("bans target user, disconnects via RCON, and logs audit", async () => {
const ctx = mockContext({
userId: 10,
reason: "Rule breaking",
duration: 24,
type: "account",
});
await (banUser as any)(ctx);
expect(rcon.disconnectUser).toHaveBeenCalledWith(10);
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "ban",
targetId: 10,
}),
);
});
it("unbans target user and logs audit", async () => {
const ctx = mockContext({ userId: 10 });
await (unbanUser as any)(ctx);
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "unban",
targetId: 10,
}),
);
});
});
describe("giveBadge & removeBadge actions", () => {
it("gives badge if user doesn't have it yet", async () => {
selectLimit.mockResolvedValueOnce([
{ username: "targetuser", rank: 1, mail: "[email protected]" },
]); // guardRank
selectLimit.mockResolvedValueOnce([]); // existing badge check (none)
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
await (giveBadge as any)(ctx);
expect(rcon.giveBadge).toHaveBeenCalledWith(10, "ADM");
});
it("throws ActionError if user already has the badge", async () => {
selectLimit.mockResolvedValueOnce([
{ username: "targetuser", rank: 1, mail: "[email protected]" },
]); // guardRank
selectLimit.mockResolvedValueOnce([{ id: 1 }]); // existing badge check (found)
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
await expect((giveBadge as any)(ctx)).rejects.toThrow(
"Badge already assigned",
);
});
it("removes badge if user has it", async () => {
selectLimit.mockResolvedValueOnce([
{ username: "targetuser", rank: 1, mail: "[email protected]" },
]); // guardRank
selectLimit.mockResolvedValueOnce([{ id: 99 }]); // existing badge check (found)
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
await (removeBadge as any)(ctx);
expect(rcon.removeBadge).toHaveBeenCalledWith(10, "ADM");
});
});
describe("resetPassword action", () => {
it("resets password, invalidates login cache and logs audit", async () => {
const ctx = mockContext({ userId: 10 });
const res = await (resetPassword as any)(ctx);
expect(res.data).toHaveProperty("newPassword");
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "reset_password",
targetId: 10,
}),
);
});
});
describe("moderation tools (disconnect, alert, mute, unmute)", () => {
it("disconnects user via RCON", async () => {
const ctx = mockContext({ userId: 10 });
await (disconnectUser as any)(ctx);
expect(rcon.disconnectUser).toHaveBeenCalledWith(10);
});
it("alerts user via RCON", async () => {
const ctx = mockContext({ userId: 10, message: "Hello user!" });
await (alertUser as any)(ctx);
expect(rcon.alertUser).toHaveBeenCalledWith(10, "Hello user!");
});
it("mutes user via RCON and logs audit", async () => {
const ctx = mockContext({ userId: 10, duration: 600 });
await (muteUser as any)(ctx);
expect(rcon.muteUser).toHaveBeenCalledWith(10, 600);
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "user_mute",
targetId: 10,
}),
);
});
it("unmutes user via RCON and logs audit", async () => {
const ctx = mockContext({ userId: 10 });
await (unmuteUser as any)(ctx);
expect(rcon.unmuteUser).toHaveBeenCalledWith(10);
expect(logAudit).toHaveBeenCalledWith(
expect.objectContaining({
action: "user_unmute",
targetId: 10,
}),
);
});
});