Commit Graph
22 Commits
Author SHA1 Message Date
openhands 5fa342018d chore: remove dead code and unused dependencies
- Delete 4 unused files detected by knip
- Remove lint-staged, eslint-config-prettier, plausible-tracker
- Clean up knip.json entry patterns
2026-07-24 11:59:50 +02:00
openhands 7dbca4117c Fix BCRYPT_ROUNDS override — use function to read env at call time
BCRYPT_ROUNDS was a module-level const evaluated at import time,
so env overrides in tests or CI had no effect. Changed to function
that reads process.env on each call. Also lowered hardcoded
bcryptHash(..., 10) in test to use env var with fallback 4.

CI: BCRYPT_ROUNDS=2. Password test suite: 1860ms → 29ms.
2026-07-23 19:30:47 +02:00
openhands f7551166c5 Speed up tests: lower argon2 params in CI, env overrides
- Allow ARGON2_MEMORY_SIZE, ARGON2_ITERATIONS, ARGON2_PARALLELISM env overrides
- Use m=1024,t=1 in tests (was m=65536,t=4 → ~1s per hash)
- Set fast params in CI and deploy workflows
2026-07-23 19:21:24 +02:00
SimoandCursor 968ca15c27 feat: jwt cache, redis health, help-ticket admin, and write rate limits
Cut Auth.js DB load with cached jwtVersion checks, surface Redis in /api/health and deploy warnings, add admin help-center ticket reply UI, rate-limit API tickets/reactions/referral claims, and revoke PATs on sign-out-everywhere.

Co-authored-by: Cursor <[email protected]>
2026-07-21 21:58:48 +02:00
SimoandCursor 2ff08e5127 chore: patch deps, CSP style nonces, otplib 13, and PR CI
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:46:02 +02:00
SimoandCursor d2120987b0 perf: replace bcryptjs with native bcrypt for password hashing
Co-authored-by: Cursor <[email protected]>
2026-07-21 20:37:02 +02:00
openhands df38dccbf1 style: format code biome 2026-07-13 21:57:41 +02:00
openhands 2e4ed76121 style: format code with prettier 2026-07-12 21:07:34 +02:00
remco e85e4d74ea revert fb8e77bb68
revert style: clean up code with prettier and eslint
2026-07-12 21:02:03 +02:00
openhands fb8e77bb68 style: clean up code with prettier and eslint 2026-07-12 20:31:05 +02:00
Simo 5b4228261a Reapply "Add missing admin action files and navigation links"
This reverts commit 4d515bc400.
2026-07-11 20:52:56 +02:00
Simo 4d515bc400 Revert "Add missing admin action files and navigation links"
This reverts commit 41be6835bf.
2026-07-11 20:37:56 +02:00
Simo 4a1e1115b3 Harden CMS security and theme contrast 2026-07-11 20:27:20 +02:00
openhands 41be6835bf Add missing admin action files and navigation links
- Add 11 missing server action files: badges, bulk-users, catalog, catalog-bc, catalog-items, import-badges, import-furni, multi-account-detect, permissions, rooms, soundtracks
- Add missing admin navigation links: tickets, sounds, translations, import, radio sub-pages
- Add translation keys for all new navigation items
2026-07-11 12:01:05 +02:00
openhands 818df3697b Migrate from AES-256-CBC to AES-256-GCM for authenticated encryption
- Replace CBC+HMAC with GCM (built-in authentication via authTag)
- Remove createHmac and timingSafeEqual imports (no longer needed)
- Remove Snyk-ignore comments (no longer suppressible findings)
- Update test: tampered MAC test -> tampered auth tag test
- Add one-time migration script for existing CBC-encrypted 2FA secrets
2026-07-10 23:51:56 +02:00
openhands 259c0c96ab Fix remaining Snyk findings: XSS in validImageUrl, cipher integrity suppression 2026-07-10 23:40:11 +02:00
openhands d782b7c4c2 Fix Snyk security findings: XSS, open redirect, hardcoded secrets, cookie security, MD5 replacement 2026-07-10 23:34:57 +02:00
openhands 1875a69b83 Fix security scanner findings
- Replace hardcoded test secrets with crypto-generated values in laravel-encrypter.test.ts and totp.test.ts
- Add 'secure' attribute to locale cookie in language-switcher.tsx
- Validate image URLs before rendering in media-grid.tsx and media-picker.tsx (XSS prevention)
- Validate redirect URL is HTTPS before window.location assignment in TopUpForm.tsx (open redirect prevention)
- Document intentional MD5 usage for legacy PHP compatibility in password.ts
- Document HMAC integrity protection for CBC cipher in laravel-encrypter.ts
2026-07-10 23:08:15 +02:00
openhands 5628e7d6b7 Security hardening: 12 improvements across the stack
1. env.ts: APP_KEY placeholder detection with validation
2. schema.prisma: password column widened to varchar(255) for argon2id
3. auth.ts: trustHost restricted to development only
4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers
5. api.ts: CORS restricted to APP_URL instead of wildcard
6. register-form.tsx: migrated from REST API fetch to server action (useActionState)
7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed)
8. register.ts: password min length 8 + complexity requirements (upper, lower, digit)
9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation
10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets
11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff)
12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
2026-07-04 18:52:00 +02:00
Simo 4eccd146ba Default password hashing to bcrypt (fits varchar(64) users.password)
Verified against the live AtomCMS DB: users.password is varchar(64), so
argon2id (~97 chars) overflows the column and registration/upgrade fail
with 'value too long'. bcrypt (60-char $2y$) fits and matches the
existing accounts. hashPassword() now emits bcrypt by default; set
PASSWORD_HASH=argon2id to opt back in (needs a widened column).
verifyPassword() still accepts both, so existing logins keep working.

Verified end-to-end against the live DB: bcrypt $2y$ login round-trips
(correct=true, wrong=false). tsc 0, vitest 8/8 (password suite).
2026-06-28 16:26:33 +02:00
Simo e668fa85ec Add 2FA, email + password reset, and batch-7 pages
Auth (hand-built on the auth core):
- 2FA: User model gains two_factor_secret/recovery_codes/confirmed_at (+ idempotent
  MariaDB migration). authorize() requires a valid TOTP code when 2FA is confirmed
  (secret decrypted via Laravel APP_KEY, fail-closed). Two-step login (precheckLogin
  reveals the code field). /settings/2fa enable/confirm/disable flow.
- Password reset: nodemailer email service; PasswordReset model + migration;
  /forgot (request, generic response) + /reset (token sha256 + 1h TTL, sets argon2id
  hash). Login links to forgot.

Batch 7 (parallel agents): /admin/commandocentrum (RCON controls + emulator_errors),
social write actions (friend request + guild forum new thread), /help/[category],
/badges (public). env: APP_KEY, APP_URL, SMTP_*. Nav extended.

Verified: tsc exit 0, vitest 48/48, next build exit 0 (64 page routes).
2026-06-28 14:25:19 +02:00
Simo ec2d46e583 Add byte-compatible Auth & SSO core primitives
Pure, unit-tested primitives the AtomCMS->Next.js login must reproduce exactly
(verified now with round-trip + known vectors; full end-to-end check deferred
until a real DB + APP_KEY + live emulator are available):

- password.ts: argon2id (m=65536,t=4,p=1 via hash-wasm) + bcrypt ($2y$ accepted)
  verify, and the md5->argon2id on-login upgrade gated by convert_passwords
  (mirrors RedirectIfTwoFactorAuthenticatable).
- sso-ticket.ts: '{hotel_name without spaces}-{uuidv4}' written to auth_ticket +
  ip_current (mirrors User::ssoTicket()).
- laravel-encrypter.ts: AES-256-CBC + HMAC-SHA256 payload compatible with
  Laravel encrypt()/encryptString (for existing 2FA secrets) incl. PHP string
  (de)serialization.
- totp.ts: otplib Google2FA-compatible TOTP verify (SHA1/6/30).

Libs: hash-wasm + bcryptjs + otplib (pure JS/WASM, no native build). 28 tests.
2026-06-27 16:00:25 +02:00