Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
109 lines
2.9 KiB
TypeScript
109 lines
2.9 KiB
TypeScript
import type { Metadata } from "next";
|
|
import { headers } from "next/headers";
|
|
import { getTranslations } from "next-intl/server";
|
|
import { requestReset } from "@/actions/password-reset";
|
|
import { CaptchaWidget } from "@/components/auth/captcha-widget";
|
|
import Link from "@/components/link";
|
|
import { ContentCard } from "@/components/public/ui";
|
|
import { captchaConfig } from "@/lib/services/captcha";
|
|
|
|
export async function generateMetadata(): Promise<Metadata> {
|
|
const t = await getTranslations("pages.forgot");
|
|
return {
|
|
title: t("title"),
|
|
description: t("subtitle"),
|
|
robots: { index: false, follow: false },
|
|
};
|
|
}
|
|
|
|
export default async function ForgotPage({
|
|
searchParams,
|
|
}: {
|
|
searchParams: Promise<{ sent?: string; error?: string }>;
|
|
}) {
|
|
const t = await getTranslations("pages.forgot");
|
|
const { sent, error } = await searchParams;
|
|
const cfg = await captchaConfig();
|
|
const nonce = (await headers()).get("x-nonce") ?? undefined;
|
|
|
|
return (
|
|
<section style={{ maxWidth: 420, margin: "2rem auto" }}>
|
|
<ContentCard icon="🔑" title={t("title")} subtitle={t("subtitle")}>
|
|
{sent ? (
|
|
<>
|
|
<p className="muted" style={{ textAlign: "center", margin: 0 }}>
|
|
{t("sentNotice")}
|
|
</p>
|
|
{/* A mail that never arrived must be retryable from here,
|
|
otherwise the visitor is stuck on a dead end. */}
|
|
<form
|
|
action={requestReset}
|
|
style={{ display: "grid", gap: "0.7rem", marginTop: "1rem" }}
|
|
>
|
|
<input
|
|
name="email"
|
|
type="email"
|
|
placeholder={t("emailPlaceholder")}
|
|
autoComplete="email"
|
|
required
|
|
/>
|
|
<CaptchaWidget
|
|
captcha={{
|
|
provider: cfg.provider,
|
|
siteKey: cfg.siteKey || undefined,
|
|
field: cfg.field || undefined,
|
|
}}
|
|
nonce={nonce}
|
|
/>
|
|
<button type="submit" className="btn btn-primary">
|
|
{t("sendAnotherLink")}
|
|
</button>
|
|
</form>
|
|
</>
|
|
) : (
|
|
<form
|
|
action={requestReset}
|
|
style={{ display: "grid", gap: "0.7rem" }}
|
|
>
|
|
<input
|
|
name="email"
|
|
type="email"
|
|
placeholder={t("emailPlaceholder")}
|
|
autoComplete="email"
|
|
required
|
|
/>
|
|
<CaptchaWidget
|
|
captcha={{
|
|
provider: cfg.provider,
|
|
siteKey: cfg.siteKey || undefined,
|
|
field: cfg.field || undefined,
|
|
}}
|
|
nonce={nonce}
|
|
/>
|
|
{error === "captcha" ? (
|
|
<p
|
|
style={{
|
|
color: "var(--color-danger)",
|
|
textAlign: "center",
|
|
margin: 0,
|
|
}}
|
|
>
|
|
{t("errorCaptcha")}
|
|
</p>
|
|
) : null}
|
|
<button type="submit" className="btn btn-primary">
|
|
{t("sendResetLink")}
|
|
</button>
|
|
</form>
|
|
)}
|
|
<p
|
|
className="muted"
|
|
style={{ textAlign: "center", marginBottom: 0, marginTop: "1rem" }}
|
|
>
|
|
<Link href="/login">{t("backToLogin")}</Link>
|
|
</p>
|
|
</ContentCard>
|
|
</section>
|
|
);
|
|
}
|