Files
EpicNext-Cms/src/app/(site)/forgot/page.tsx
T
openhands 6cc45d7413
Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
feat: harden atoms-nexst against review findings (37 items)
Second review pass covering security, performance, admin tooling and the
public/room flows. All HIGH and MEDIUM findings from the audit are resolved;
nothing in this commit changes the visible feature set.

Authentication & session security
- CSP is now set on the request headers in the proxy, which is what Next.js
  uses to derive the render nonce, so the nonce is effective.
- 2FA: an already-enabled user cannot re-enroll, the setup endpoint is
  rate-limited per account, and confirmed codes are persisted so the second
  secret no longer silently never applies.
- Password reset revokes the ticket, authTicket and all personal access
  tokens, and bumps the token version so existing sessions die. The same
  revocation is now wired into the staff-side password reset.
- /reset and /verify return a stable error code instead of raw text; the
  mail lookups are ordered by id so duplicates cannot vary between runs.
- Resending the verification mail gets a per-address cooldown on top of the
  per-user limit.
- Issue API tokens with the narrower radio/ticket ability set instead of "*".

Authorization & input handling
- Mid-rank staff can no longer keep dynamically granted non-view admin.*
  permissions: existing grants are revoked by migration and the grant lookup
  is restricted to "%.view". Rank guards use the dynamic super-admin check.
- Alerting a user is permission-checked and audited like the other tools.
- Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user
  actions route, bulk user actions) are capped and rank-guarded, and bulk
  ids are bounded.
- updateRoom / updateRoomItem write through a field allowlist, and items
  may only be edited through their own room.
- Classnames reaching the filesystem are validated before use so a crafted
  value cannot escape the asset directories.
- The word filter now also covers offline mails, guild forum threads and
  replies, and user mottos.
- Media uploads are validated by magic bytes, /api/media requires the page
  edit permission, APP_URL must be configured once mail is enabled, and the
  diagnostics error route checks the fetch site header.

Admin tooling
- Secret settings render masked and cannot be overwritten with a blank or
  an arbitrary raw key; radio credentials are new password inputs.
- Commandocentrum balance changes are audited.
- Admin list pagination reads the caller's per-page instead of the max, and
  the log exporter caps offset and search length.

Performance
- Catalog translations are cached per module, with a cheap revision hash;
  the public online count uses a stale window instead of hammering the DB.
- The cache warmup now primes the payload the home route actually reads.
- TopHeader batches its queries into one round trip, and LCP avatars load
  eagerly.
- motion/react and sonner are no longer part of the root layout; the nav
  dropdown and mobile nav panels are lazy client chunks. Anonymous visitors
  again get the navigation chrome, and public pages get an edge cacheable
  response.

Accessibility
- Nested <main> elements in phase pages became <section>; the page entrance
  and route progress animations are pure CSS that respect reduced motion.
2026-10-09 16:19:48 +02:00

109 lines
2.9 KiB
TypeScript

import type { Metadata } from "next";
import { headers } from "next/headers";
import { getTranslations } from "next-intl/server";
import { requestReset } from "@/actions/password-reset";
import { CaptchaWidget } from "@/components/auth/captcha-widget";
import Link from "@/components/link";
import { ContentCard } from "@/components/public/ui";
import { captchaConfig } from "@/lib/services/captcha";
export async function generateMetadata(): Promise<Metadata> {
const t = await getTranslations("pages.forgot");
return {
title: t("title"),
description: t("subtitle"),
robots: { index: false, follow: false },
};
}
export default async function ForgotPage({
searchParams,
}: {
searchParams: Promise<{ sent?: string; error?: string }>;
}) {
const t = await getTranslations("pages.forgot");
const { sent, error } = await searchParams;
const cfg = await captchaConfig();
const nonce = (await headers()).get("x-nonce") ?? undefined;
return (
<section style={{ maxWidth: 420, margin: "2rem auto" }}>
<ContentCard icon="🔑" title={t("title")} subtitle={t("subtitle")}>
{sent ? (
<>
<p className="muted" style={{ textAlign: "center", margin: 0 }}>
{t("sentNotice")}
</p>
{/* A mail that never arrived must be retryable from here,
otherwise the visitor is stuck on a dead end. */}
<form
action={requestReset}
style={{ display: "grid", gap: "0.7rem", marginTop: "1rem" }}
>
<input
name="email"
type="email"
placeholder={t("emailPlaceholder")}
autoComplete="email"
required
/>
<CaptchaWidget
captcha={{
provider: cfg.provider,
siteKey: cfg.siteKey || undefined,
field: cfg.field || undefined,
}}
nonce={nonce}
/>
<button type="submit" className="btn btn-primary">
{t("sendAnotherLink")}
</button>
</form>
</>
) : (
<form
action={requestReset}
style={{ display: "grid", gap: "0.7rem" }}
>
<input
name="email"
type="email"
placeholder={t("emailPlaceholder")}
autoComplete="email"
required
/>
<CaptchaWidget
captcha={{
provider: cfg.provider,
siteKey: cfg.siteKey || undefined,
field: cfg.field || undefined,
}}
nonce={nonce}
/>
{error === "captcha" ? (
<p
style={{
color: "var(--color-danger)",
textAlign: "center",
margin: 0,
}}
>
{t("errorCaptcha")}
</p>
) : null}
<button type="submit" className="btn btn-primary">
{t("sendResetLink")}
</button>
</form>
)}
<p
className="muted"
style={{ textAlign: "center", marginBottom: 0, marginTop: "1rem" }}
>
<Link href="/login">{t("backToLogin")}</Link>
</p>
</ContentCard>
</section>
);
}