Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
186 lines
4.8 KiB
TypeScript
186 lines
4.8 KiB
TypeScript
import { asc, eq, inArray, or } from "drizzle-orm";
|
|
import type { Metadata } from "next";
|
|
import { redirect } from "next/navigation";
|
|
import { getTranslations } from "next-intl/server";
|
|
import type { CSSProperties } from "react";
|
|
import { removeFriendship } from "@/actions/messenger";
|
|
import Link from "@/components/link";
|
|
import { ContentCard, EmptyState, OnlineBadge } from "@/components/public/ui";
|
|
import { UserAvatarThumbnail } from "@/components/shared/user-avatar-thumbnail";
|
|
import { auth } from "@/lib/auth";
|
|
import { db, MessengerFriendships, User } from "@/lib/db";
|
|
|
|
export async function generateMetadata(): Promise<Metadata> {
|
|
const t = await getTranslations("pages.friends");
|
|
return {
|
|
title: t("title"),
|
|
description: t("emptySubtitle"),
|
|
openGraph: {
|
|
title: t("title"),
|
|
description: t("emptySubtitle"),
|
|
type: "website",
|
|
},
|
|
};
|
|
}
|
|
|
|
type SearchParams = Promise<{ removed?: string; error?: string }>;
|
|
|
|
function feedbackStyle(tone: "success" | "error"): CSSProperties {
|
|
const accent =
|
|
tone === "error" ? "var(--color-danger)" : "var(--color-primary)";
|
|
return {
|
|
margin: 0,
|
|
padding: "0.85rem 1rem",
|
|
borderRadius: "var(--radius-md)",
|
|
border: `1px solid ${accent}`,
|
|
color: "var(--color-text-readable, var(--color-text))",
|
|
fontSize: "0.9rem",
|
|
fontWeight: 600,
|
|
background: "var(--color-surface)",
|
|
borderLeft: `4px solid ${accent}`,
|
|
};
|
|
}
|
|
|
|
export default async function FriendsPage({
|
|
searchParams,
|
|
}: {
|
|
searchParams: SearchParams;
|
|
}) {
|
|
const t = await getTranslations("pages.friends");
|
|
const session = await auth();
|
|
if (!session?.user?.id) redirect("/login");
|
|
|
|
const userId = Number(session.user.id);
|
|
const { removed, error } = await searchParams;
|
|
|
|
// Friendships are stored as TWO directional rows (user_one_id→user_two_id
|
|
// and the reverse). Read both directions, then dedupe the friend ids.
|
|
const friendships = await db
|
|
.select({
|
|
userOneId: MessengerFriendships.userOneId,
|
|
userTwoId: MessengerFriendships.userTwoId,
|
|
})
|
|
.from(MessengerFriendships)
|
|
.where(
|
|
or(
|
|
eq(MessengerFriendships.userOneId, userId),
|
|
eq(MessengerFriendships.userTwoId, userId),
|
|
),
|
|
)
|
|
.catch(() => []);
|
|
|
|
const friendIds = Array.from(
|
|
new Set(
|
|
friendships
|
|
.map((f) => (f.userOneId === userId ? f.userTwoId : f.userOneId))
|
|
.filter((id) => id && id !== userId),
|
|
),
|
|
);
|
|
|
|
const friends = friendIds.length
|
|
? await db
|
|
.select({
|
|
id: User.id,
|
|
username: User.username,
|
|
look: User.look,
|
|
motto: User.motto,
|
|
online: User.online,
|
|
})
|
|
.from(User)
|
|
.where(inArray(User.id, friendIds))
|
|
.orderBy(asc(User.username))
|
|
.catch(() => [])
|
|
: [];
|
|
|
|
const errorMessage =
|
|
error === "not_found"
|
|
? t("errors.notFound")
|
|
: error === "invalid"
|
|
? t("errors.invalid")
|
|
: error
|
|
? t("errors.error")
|
|
: null;
|
|
|
|
return (
|
|
<section className="page-grid">
|
|
{removed === "1" ? (
|
|
<div role="status" style={feedbackStyle("success")}>
|
|
{t("success.removed")}
|
|
</div>
|
|
) : null}
|
|
{errorMessage ? (
|
|
<div role="alert" style={feedbackStyle("error")}>
|
|
{errorMessage}
|
|
</div>
|
|
) : null}
|
|
|
|
<ContentCard
|
|
icon="🤝"
|
|
title={t("title")}
|
|
subtitle={
|
|
friends.length === 0
|
|
? t("emptySubtitle")
|
|
: t("subtitle", { count: friends.length })
|
|
}
|
|
/>
|
|
|
|
<ContentCard padded={friends.length === 0}>
|
|
{friends.length === 0 ? (
|
|
<EmptyState icon="🤝">{t("emptyState")}</EmptyState>
|
|
) : (
|
|
<div className="card-grid sm-2 lg-3" style={{ padding: "1rem" }}>
|
|
{friends.map((friend) => {
|
|
const isOnline = friend.online === "1";
|
|
return (
|
|
<div
|
|
key={friend.id}
|
|
className="card hover"
|
|
style={{
|
|
display: "flex",
|
|
gap: "0.85rem",
|
|
alignItems: "center",
|
|
}}
|
|
>
|
|
<UserAvatarThumbnail
|
|
figure={friend.look}
|
|
alt={`${friend.username} avatar`}
|
|
/>
|
|
<div style={{ minWidth: 0, flex: 1 }}>
|
|
<h3 style={{ margin: "0 0 0.3rem", fontSize: "1rem" }}>
|
|
<Link href={`/u/${friend.username}`}>
|
|
{friend.username}
|
|
</Link>
|
|
</h3>
|
|
<p
|
|
className="muted"
|
|
style={{
|
|
margin: "0 0 0.4rem",
|
|
overflow: "hidden",
|
|
textOverflow: "ellipsis",
|
|
whiteSpace: "nowrap",
|
|
}}
|
|
>
|
|
{friend.motto || t("noMotto")}
|
|
</p>
|
|
<OnlineBadge online={isOnline} />
|
|
</div>
|
|
<form action={removeFriendship}>
|
|
<input
|
|
type="hidden"
|
|
name="friendId"
|
|
value={String(friend.id)}
|
|
/>
|
|
<button type="submit" className="btn">
|
|
{t("remove")}
|
|
</button>
|
|
</form>
|
|
</div>
|
|
);
|
|
})}
|
|
</div>
|
|
)}
|
|
</ContentCard>
|
|
</section>
|
|
);
|
|
}
|