Gitea Actions Runner Test / test-job (push) Successful in 2s
CI / check (push) Successful in 30s
CI / tests-integration (push) Successful in 1m42s
CI / tests-unit (push) Failing after 1m49s
CI / tests-ui (push) Successful in 2m31s
CI / preflight (push) Skipped
CI / deploy (push) Skipped
Second review pass covering security, performance, admin tooling and the public/room flows. All HIGH and MEDIUM findings from the audit are resolved; nothing in this commit changes the visible feature set. Authentication & session security - CSP is now set on the request headers in the proxy, which is what Next.js uses to derive the render nonce, so the nonce is effective. - 2FA: an already-enabled user cannot re-enroll, the setup endpoint is rate-limited per account, and confirmed codes are persisted so the second secret no longer silently never applies. - Password reset revokes the ticket, authTicket and all personal access tokens, and bumps the token version so existing sessions die. The same revocation is now wired into the staff-side password reset. - /reset and /verify return a stable error code instead of raw text; the mail lookups are ordered by id so duplicates cannot vary between runs. - Resending the verification mail gets a per-address cooldown on top of the per-user limit. - Issue API tokens with the narrower radio/ticket ability set instead of "*". Authorization & input handling - Mid-rank staff can no longer keep dynamically granted non-view admin.* permissions: existing grants are revoked by migration and the grant lookup is restricted to "%.view". Rank guards use the dynamic super-admin check. - Alerting a user is permission-checked and audited like the other tools. - Material mutations (giveCredits/giveDuckets/giveDiamonds, the admin user actions route, bulk user actions) are capped and rank-guarded, and bulk ids are bounded. - updateRoom / updateRoomItem write through a field allowlist, and items may only be edited through their own room. - Classnames reaching the filesystem are validated before use so a crafted value cannot escape the asset directories. - The word filter now also covers offline mails, guild forum threads and replies, and user mottos. - Media uploads are validated by magic bytes, /api/media requires the page edit permission, APP_URL must be configured once mail is enabled, and the diagnostics error route checks the fetch site header. Admin tooling - Secret settings render masked and cannot be overwritten with a blank or an arbitrary raw key; radio credentials are new password inputs. - Commandocentrum balance changes are audited. - Admin list pagination reads the caller's per-page instead of the max, and the log exporter caps offset and search length. Performance - Catalog translations are cached per module, with a cheap revision hash; the public online count uses a stale window instead of hammering the DB. - The cache warmup now primes the payload the home route actually reads. - TopHeader batches its queries into one round trip, and LCP avatars load eagerly. - motion/react and sonner are no longer part of the root layout; the nav dropdown and mobile nav panels are lazy client chunks. Anonymous visitors again get the navigation chrome, and public pages get an edge cacheable response. Accessibility - Nested <main> elements in phase pages became <section>; the page entrance and route progress animations are pure CSS that respect reduced motion.
284 lines
7.1 KiB
TypeScript
284 lines
7.1 KiB
TypeScript
import { asc } from "drizzle-orm";
|
|
import type { Metadata } from "next";
|
|
import { getTranslations } from "next-intl/server";
|
|
import Link from "@/components/link";
|
|
|
|
export async function generateMetadata(): Promise<Metadata> {
|
|
const t = await getTranslations("pages.help");
|
|
return {
|
|
title: t("title"),
|
|
description: t("subtitle"),
|
|
openGraph: {
|
|
title: t("title"),
|
|
description: t("subtitle"),
|
|
type: "website",
|
|
},
|
|
};
|
|
}
|
|
|
|
import { ContentCard, EmptyState } from "@/components/public/ui";
|
|
import {
|
|
db,
|
|
WebsiteHelpCenterCategories,
|
|
WebsiteRuleCategories,
|
|
WebsiteRules,
|
|
} from "@/lib/db";
|
|
|
|
type HelpCategory = {
|
|
id: bigint;
|
|
name: string;
|
|
content: string;
|
|
imageUrl: string | null;
|
|
buttonText: string | null;
|
|
buttonUrl: string | null;
|
|
buttonColor: string;
|
|
buttonBorderColor: string;
|
|
smallBox: boolean;
|
|
};
|
|
|
|
type RuleCategory = {
|
|
id: bigint;
|
|
name: string;
|
|
description: string;
|
|
badge: string;
|
|
};
|
|
|
|
type Rule = {
|
|
id: bigint;
|
|
categoryId: bigint | null;
|
|
paragraph: string;
|
|
rule: string;
|
|
};
|
|
|
|
function isExternal(url: string): boolean {
|
|
return /^https?:\/\//i.test(url);
|
|
}
|
|
|
|
export default async function HelpCenterPage() {
|
|
const t = await getTranslations("pages.help");
|
|
|
|
let categories: HelpCategory[] = [];
|
|
try {
|
|
categories = await db
|
|
.select({
|
|
id: WebsiteHelpCenterCategories.id,
|
|
name: WebsiteHelpCenterCategories.name,
|
|
content: WebsiteHelpCenterCategories.content,
|
|
imageUrl: WebsiteHelpCenterCategories.imageUrl,
|
|
buttonText: WebsiteHelpCenterCategories.buttonText,
|
|
buttonUrl: WebsiteHelpCenterCategories.buttonUrl,
|
|
buttonColor: WebsiteHelpCenterCategories.buttonColor,
|
|
buttonBorderColor: WebsiteHelpCenterCategories.buttonBorderColor,
|
|
smallBox: WebsiteHelpCenterCategories.smallBox,
|
|
})
|
|
.from(WebsiteHelpCenterCategories)
|
|
.orderBy(
|
|
asc(WebsiteHelpCenterCategories.position),
|
|
asc(WebsiteHelpCenterCategories.id),
|
|
);
|
|
} catch {
|
|
// DB unavailable — render the shell without help categories.
|
|
}
|
|
|
|
let ruleCategories: RuleCategory[] = [];
|
|
try {
|
|
ruleCategories = await db
|
|
.select({
|
|
id: WebsiteRuleCategories.id,
|
|
name: WebsiteRuleCategories.name,
|
|
description: WebsiteRuleCategories.description,
|
|
badge: WebsiteRuleCategories.badge,
|
|
})
|
|
.from(WebsiteRuleCategories)
|
|
.orderBy(asc(WebsiteRuleCategories.id));
|
|
} catch {
|
|
// DB unavailable — render the shell without rule categories.
|
|
}
|
|
|
|
let rules: Rule[] = [];
|
|
try {
|
|
rules = await db
|
|
.select({
|
|
id: WebsiteRules.id,
|
|
categoryId: WebsiteRules.categoryId,
|
|
paragraph: WebsiteRules.paragraph,
|
|
rule: WebsiteRules.rule,
|
|
})
|
|
.from(WebsiteRules)
|
|
.orderBy(
|
|
asc(WebsiteRules.categoryId),
|
|
asc(WebsiteRules.paragraph),
|
|
asc(WebsiteRules.id),
|
|
);
|
|
} catch {
|
|
// DB unavailable — render the shell without rules.
|
|
}
|
|
|
|
// Group the rules under their categories.
|
|
const rulesByCategory = new Map<string, Rule[]>();
|
|
for (const r of rules) {
|
|
const key = r.categoryId === null ? "" : String(r.categoryId);
|
|
const list = rulesByCategory.get(key);
|
|
if (list) {
|
|
list.push(r);
|
|
} else {
|
|
rulesByCategory.set(key, [r]);
|
|
}
|
|
}
|
|
|
|
return (
|
|
<section className="page-grid">
|
|
<ContentCard
|
|
icon="❓"
|
|
title={t("title")}
|
|
subtitle={t("subtitle")}
|
|
action={
|
|
<Link className="btn btn-outline" href="/help/tickets">
|
|
{t("myTickets")}
|
|
</Link>
|
|
}
|
|
/>
|
|
|
|
<ContentCard
|
|
icon="🧭"
|
|
title={t("topicsTitle")}
|
|
subtitle={t("topicsSubtitle")}
|
|
padded={categories.length === 0}
|
|
>
|
|
{categories.length === 0 ? (
|
|
<EmptyState icon="🧭">{t("topicsEmpty")}</EmptyState>
|
|
) : (
|
|
<div className="card-grid sm-2 lg-3" style={{ padding: "1rem" }}>
|
|
{categories.map((c) => (
|
|
<article key={String(c.id)} className="card hover">
|
|
<div
|
|
style={{
|
|
display: "flex",
|
|
gap: "0.85rem",
|
|
alignItems: "flex-start",
|
|
}}
|
|
>
|
|
{c.imageUrl ? (
|
|
// eslint-disable-next-line @next/next/no-img-element
|
|
<img
|
|
src={c.imageUrl}
|
|
alt=""
|
|
width={48}
|
|
height={48}
|
|
style={{ flexShrink: 0, objectFit: "contain" }}
|
|
/>
|
|
) : null}
|
|
<div style={{ flex: 1, minWidth: 0 }}>
|
|
<h3 style={{ margin: "0 0 0.35rem", fontSize: "1rem" }}>
|
|
{c.name}
|
|
</h3>
|
|
<p className="muted" style={{ margin: 0 }}>
|
|
{c.content}
|
|
</p>
|
|
{c.buttonUrl && c.buttonText ? (
|
|
<div style={{ marginTop: "0.85rem" }}>
|
|
{isExternal(c.buttonUrl) ? (
|
|
<a
|
|
className="btn btn-outline"
|
|
href={c.buttonUrl}
|
|
target="_blank"
|
|
rel="noreferrer"
|
|
style={{
|
|
background: c.buttonColor,
|
|
borderColor: c.buttonBorderColor,
|
|
color: "#3a2c05",
|
|
}}
|
|
>
|
|
{c.buttonText}
|
|
</a>
|
|
) : (
|
|
<Link
|
|
className="btn btn-outline"
|
|
href={c.buttonUrl}
|
|
style={{
|
|
background: c.buttonColor,
|
|
borderColor: c.buttonBorderColor,
|
|
color: "#3a2c05",
|
|
}}
|
|
>
|
|
{c.buttonText}
|
|
</Link>
|
|
)}
|
|
</div>
|
|
) : null}
|
|
</div>
|
|
</div>
|
|
</article>
|
|
))}
|
|
</div>
|
|
)}
|
|
</ContentCard>
|
|
|
|
<ContentCard
|
|
icon="📜"
|
|
title={t("rulesTitle")}
|
|
subtitle={t("rulesSubtitle")}
|
|
padded={ruleCategories.length === 0}
|
|
>
|
|
{ruleCategories.length === 0 ? (
|
|
<EmptyState icon="📜">{t("rulesEmpty")}</EmptyState>
|
|
) : (
|
|
<div style={{ display: "grid", gap: "1rem", padding: "1rem" }}>
|
|
{ruleCategories.map((cat) => {
|
|
const catRules = rulesByCategory.get(String(cat.id)) ?? [];
|
|
return (
|
|
<article key={String(cat.id)} className="card">
|
|
<div
|
|
style={{
|
|
display: "flex",
|
|
alignItems: "baseline",
|
|
gap: "0.6rem",
|
|
flexWrap: "wrap",
|
|
}}
|
|
>
|
|
<h3 style={{ margin: 0, fontSize: "1.05rem" }}>
|
|
{cat.name}
|
|
</h3>
|
|
{cat.badge ? (
|
|
<span className="muted">{cat.badge}</span>
|
|
) : null}
|
|
</div>
|
|
{cat.description ? (
|
|
<p className="muted" style={{ margin: "0.35rem 0 0" }}>
|
|
{cat.description}
|
|
</p>
|
|
) : null}
|
|
|
|
{catRules.length === 0 ? (
|
|
<p className="muted" style={{ marginBottom: 0 }}>
|
|
{t("categoryEmpty")}
|
|
</p>
|
|
) : (
|
|
<ul
|
|
style={{ margin: "0.85rem 0 0", paddingLeft: "1.2rem" }}
|
|
>
|
|
{catRules.map((r) => (
|
|
<li
|
|
key={String(r.id)}
|
|
style={{ marginBottom: "0.5rem" }}
|
|
>
|
|
{r.paragraph ? (
|
|
<strong style={{ marginRight: "0.4rem" }}>
|
|
{r.paragraph}
|
|
</strong>
|
|
) : null}
|
|
{r.rule}
|
|
</li>
|
|
))}
|
|
</ul>
|
|
)}
|
|
</article>
|
|
);
|
|
})}
|
|
</div>
|
|
)}
|
|
</ContentCard>
|
|
</section>
|
|
);
|
|
}
|