Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
300 lines
7.7 KiB
TypeScript
300 lines
7.7 KiB
TypeScript
// @ts-nocheck
|
|
import { beforeEach, describe, expect, it, vi } from "vitest";
|
|
|
|
vi.mock("next/server", () => ({
|
|
NextResponse: { json: vi.fn() },
|
|
}));
|
|
|
|
vi.mock("next-auth", () => ({
|
|
default: vi.fn(() => ({ handlers: {}, auth: vi.fn(), signOut: vi.fn() })),
|
|
}));
|
|
|
|
vi.mock("@/lib/auth", () => ({
|
|
auth: vi.fn(),
|
|
invalidateLoginCache: vi.fn(),
|
|
}));
|
|
|
|
vi.mock("@/lib/auth/password", () => ({
|
|
hashPassword: vi.fn().mockResolvedValue("hashed_pass_123"),
|
|
}));
|
|
|
|
const { insertValues, deleteWhere, updateSet, selectLimit } = vi.hoisted(
|
|
() => ({
|
|
insertValues: vi.fn(),
|
|
deleteWhere: vi.fn(),
|
|
updateSet: vi.fn(),
|
|
selectLimit: vi.fn(),
|
|
}),
|
|
);
|
|
|
|
vi.mock("@/lib/db", () => ({
|
|
db: {
|
|
insert: vi.fn(() => ({
|
|
values: insertValues,
|
|
onDuplicateKeyUpdate: vi.fn().mockResolvedValue([]),
|
|
})),
|
|
update: vi.fn(() => ({ set: vi.fn(() => ({ where: updateSet })) })),
|
|
delete: vi.fn(() => ({ where: deleteWhere })),
|
|
select: vi.fn(() => ({
|
|
from: vi.fn(() => ({
|
|
where: vi.fn(() => ({ limit: selectLimit })),
|
|
})),
|
|
})),
|
|
transaction: vi.fn(async (cb: (tx: any) => Promise<any>) => {
|
|
const mockTx = {
|
|
insert: vi.fn(() => ({
|
|
values: vi.fn().mockResolvedValue([{ insertId: 42n }]),
|
|
})),
|
|
};
|
|
return cb(mockTx);
|
|
}),
|
|
},
|
|
User: { id: "User.id", username: "User.username", rank: "User.rank" },
|
|
Ban: { userId: "Ban.userId" },
|
|
UsersSettings: {},
|
|
UsersCurrency: {},
|
|
UsersBadges: { id: "UsersBadges.id" },
|
|
}));
|
|
|
|
vi.mock("@/lib/permissions", () => ({
|
|
PERMS: {
|
|
USERS_EDIT: "users.edit",
|
|
USERS_BAN: "users.ban",
|
|
USERS_RESET_PASSWORD: "users.reset_password",
|
|
},
|
|
// Staff in the fixtures is rank 7 and the hotel's top rank is 10, so rank
|
|
// guards act as "below-your-own-rank only".
|
|
getHighestRank: vi.fn(() => Promise.resolve(10)),
|
|
}));
|
|
|
|
vi.mock("@/lib/safe-action", () => ({
|
|
adminAction: vi.fn((_o: unknown, f: (...args: unknown[]) => unknown) => f),
|
|
}));
|
|
|
|
vi.mock("@/lib/safe-action-shared", () => ({
|
|
ActionError: class ActionError extends Error {},
|
|
actionOk: vi.fn((res) => ({ ok: true, data: res })),
|
|
}));
|
|
|
|
vi.mock("@/lib/services/audit", () => ({
|
|
logAudit: vi.fn(),
|
|
}));
|
|
|
|
vi.mock("@/lib/auth/session-revocation", () => ({
|
|
revokeUserCredentials: vi.fn(() => Promise.resolve()),
|
|
}));
|
|
|
|
vi.mock("@/lib/services/webhook", () => ({
|
|
notify: vi.fn(),
|
|
}));
|
|
|
|
vi.mock("@/lib/services/rcon", () => ({
|
|
rcon: {
|
|
disconnectUser: vi.fn().mockResolvedValue(true),
|
|
giveBadge: vi.fn().mockResolvedValue(true),
|
|
removeBadge: vi.fn().mockResolvedValue(true),
|
|
alertUser: vi.fn().mockResolvedValue(true),
|
|
muteUser: vi.fn().mockResolvedValue(true),
|
|
unmuteUser: vi.fn().mockResolvedValue(true),
|
|
giveCredits: vi.fn().mockResolvedValue(true),
|
|
},
|
|
}));
|
|
|
|
import { ActionError } from "@/lib/safe-action-shared";
|
|
import { logAudit } from "@/lib/services/audit";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import {
|
|
alertUser,
|
|
banUser,
|
|
createUser,
|
|
disconnectUser,
|
|
giveBadge,
|
|
muteUser,
|
|
removeBadge,
|
|
resetPassword,
|
|
unbanUser,
|
|
unmuteUser,
|
|
} from "./users";
|
|
|
|
const mockContext = (data: any, rank = 7) => ({
|
|
data,
|
|
session: {
|
|
user: {
|
|
id: 1,
|
|
username: "superadmin",
|
|
rank,
|
|
},
|
|
},
|
|
});
|
|
|
|
beforeEach(() => {
|
|
vi.clearAllMocks();
|
|
selectLimit.mockResolvedValue([
|
|
{ username: "targetuser", rank: 1, mail: "[email protected]" },
|
|
]);
|
|
deleteWhere.mockResolvedValue([{ affectedRows: 1 }]);
|
|
updateSet.mockResolvedValue([{ affectedRows: 1 }]);
|
|
insertValues.mockResolvedValue([{ insertId: 100n }]);
|
|
});
|
|
|
|
describe("createUser action", () => {
|
|
it("creates a user successfully and logs audit", async () => {
|
|
const ctx = mockContext({
|
|
username: "newuser",
|
|
mail: "[email protected]",
|
|
password: "password123",
|
|
rank: 1,
|
|
motto: "Hello world",
|
|
});
|
|
|
|
const res = await (createUser as any)(ctx);
|
|
|
|
expect(res).toEqual({ ok: true, data: { id: 42, username: "newuser" } });
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "user_create",
|
|
targetId: 42,
|
|
}),
|
|
);
|
|
});
|
|
|
|
it("throws error if admin assigns rank equal or higher than their own", async () => {
|
|
const ctx = mockContext(
|
|
{
|
|
username: "moduser",
|
|
mail: "[email protected]",
|
|
password: "password123",
|
|
rank: 5,
|
|
},
|
|
5, // admin with rank 5 trying to set rank 5
|
|
);
|
|
|
|
await expect((createUser as any)(ctx)).rejects.toThrow(ActionError);
|
|
});
|
|
});
|
|
|
|
describe("banUser & unbanUser actions", () => {
|
|
it("bans target user, disconnects via RCON, and logs audit", async () => {
|
|
const ctx = mockContext({
|
|
userId: 10,
|
|
reason: "Rule breaking",
|
|
duration: 24,
|
|
type: "account",
|
|
});
|
|
|
|
await (banUser as any)(ctx);
|
|
|
|
expect(rcon.disconnectUser).toHaveBeenCalledWith(10);
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "ban",
|
|
targetId: 10,
|
|
}),
|
|
);
|
|
});
|
|
|
|
it("unbans target user and logs audit", async () => {
|
|
const ctx = mockContext({ userId: 10 });
|
|
|
|
await (unbanUser as any)(ctx);
|
|
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "unban",
|
|
targetId: 10,
|
|
}),
|
|
);
|
|
});
|
|
});
|
|
|
|
describe("giveBadge & removeBadge actions", () => {
|
|
it("gives badge if user doesn't have it yet", async () => {
|
|
selectLimit.mockResolvedValueOnce([
|
|
{ username: "targetuser", rank: 1, mail: "[email protected]" },
|
|
]); // guardRank
|
|
selectLimit.mockResolvedValueOnce([]); // existing badge check (none)
|
|
|
|
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
|
|
await (giveBadge as any)(ctx);
|
|
|
|
expect(rcon.giveBadge).toHaveBeenCalledWith(10, "ADM");
|
|
});
|
|
|
|
it("throws ActionError if user already has the badge", async () => {
|
|
selectLimit.mockResolvedValueOnce([
|
|
{ username: "targetuser", rank: 1, mail: "[email protected]" },
|
|
]); // guardRank
|
|
selectLimit.mockResolvedValueOnce([{ id: 1 }]); // existing badge check (found)
|
|
|
|
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
|
|
await expect((giveBadge as any)(ctx)).rejects.toThrow(
|
|
"Badge already assigned",
|
|
);
|
|
});
|
|
|
|
it("removes badge if user has it", async () => {
|
|
selectLimit.mockResolvedValueOnce([
|
|
{ username: "targetuser", rank: 1, mail: "[email protected]" },
|
|
]); // guardRank
|
|
selectLimit.mockResolvedValueOnce([{ id: 99 }]); // existing badge check (found)
|
|
|
|
const ctx = mockContext({ userId: 10, badgeCode: "ADM" });
|
|
await (removeBadge as any)(ctx);
|
|
|
|
expect(rcon.removeBadge).toHaveBeenCalledWith(10, "ADM");
|
|
});
|
|
});
|
|
|
|
describe("resetPassword action", () => {
|
|
it("resets password, invalidates login cache and logs audit", async () => {
|
|
const ctx = mockContext({ userId: 10 });
|
|
const res = await (resetPassword as any)(ctx);
|
|
|
|
expect(res.data).toHaveProperty("newPassword");
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "reset_password",
|
|
targetId: 10,
|
|
}),
|
|
);
|
|
});
|
|
});
|
|
|
|
describe("moderation tools (disconnect, alert, mute, unmute)", () => {
|
|
it("disconnects user via RCON", async () => {
|
|
const ctx = mockContext({ userId: 10 });
|
|
await (disconnectUser as any)(ctx);
|
|
expect(rcon.disconnectUser).toHaveBeenCalledWith(10);
|
|
});
|
|
|
|
it("alerts user via RCON", async () => {
|
|
const ctx = mockContext({ userId: 10, message: "Hello user!" });
|
|
await (alertUser as any)(ctx);
|
|
expect(rcon.alertUser).toHaveBeenCalledWith(10, "Hello user!");
|
|
});
|
|
|
|
it("mutes user via RCON and logs audit", async () => {
|
|
const ctx = mockContext({ userId: 10, duration: 600 });
|
|
await (muteUser as any)(ctx);
|
|
expect(rcon.muteUser).toHaveBeenCalledWith(10, 600);
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "user_mute",
|
|
targetId: 10,
|
|
}),
|
|
);
|
|
});
|
|
|
|
it("unmutes user via RCON and logs audit", async () => {
|
|
const ctx = mockContext({ userId: 10 });
|
|
await (unmuteUser as any)(ctx);
|
|
expect(rcon.unmuteUser).toHaveBeenCalledWith(10);
|
|
expect(logAudit).toHaveBeenCalledWith(
|
|
expect.objectContaining({
|
|
action: "user_unmute",
|
|
targetId: 10,
|
|
}),
|
|
);
|
|
});
|
|
});
|