feat(core): sync framework security hardening and accessibility improvements

- add util.Go with panic recovery for background goroutines
- add util.EscapeLike and explicit ESCAPE clause for SQL LIKE queries
- add DummyCheckPassword and subtle.ConstantTimeCompare against timing attacks
- enforce session ID rotation upon login/oauth callback to prevent session fixation
- add sliding window login failure rate limiting and oauth state rate limiting
- fix redis client capture race in pubsub listeners and wait on stop channel
- adjust global --primary to oklch(51.1% 0.262 276.966) for WCAG AA contrast
- fix semantic heading levels and missing aria-labels across UI components
- document security, concurrency, and a11y standards in AGENTS.md
This commit is contained in:
ryan
2026-08-27 23:01:28 +08:00
parent b66cf3ae9c
commit ae3b792e16
63 changed files with 570 additions and 176 deletions
@@ -219,7 +219,7 @@ export function AccessTokenMain() {
</div>
{/* 安全警告提示 */}
<div className='rounded-xl border border-amber-500/20 bg-amber-500/5 p-4 flex gap-3 text-amber-600 text-xs leading-relaxed'>
<div className='rounded-xl border border-amber-500/20 bg-amber-500/5 p-4 flex gap-3 text-amber-700 text-xs leading-relaxed'>
<AlertTriangle className='size-4 shrink-0 mt-0.5' />
<div className='space-y-1'>
<span className='font-bold'>{ta('securityTitle')}</span>
@@ -23,6 +23,7 @@ export function NotificationsMain() {
return (
<div className='py-6 space-y-6'>
<div className='font-semibold'>
<h1 className='sr-only'>{tn('breadcrumb')}</h1>
<Breadcrumb>
<BreadcrumbList>
<BreadcrumbItem>
@@ -238,7 +238,7 @@ export function UserFileManager() {
<Upload className='size-10' />
</div>
<div className='space-y-1'>
<h3 className='font-semibold text-sm'>{t('noFiles')}</h3>
<p className='font-semibold text-sm'>{t('noFiles')}</p>
<p className='text-xs text-muted-foreground max-w-xs'>
{debouncedKeyword ? t('noMatchingFiles') : t('uploadFirstFile')}
</p>
+1 -1
View File
@@ -81,7 +81,7 @@ export function EmptyState({
</div>
{displayTitle && (
<h3 className='text-base font-medium mb-1'>{displayTitle}</h3>
<p className='text-base font-medium mb-1'>{displayTitle}</p>
)}
{displayDescription && (
+1 -1
View File
@@ -74,7 +74,7 @@ export function ErrorDisplay({
<Icon className='size-6 text-red-600 dark:text-red-400' />
</div>
<h3 className='text-lg font-semibold mb-2'>{displayTitle}</h3>
<p className='text-lg font-semibold mb-2'>{displayTitle}</p>
<p className='text-sm text-muted-foreground max-w-md mb-4'>
{errorMessage}
+1 -1
View File
@@ -160,7 +160,7 @@ export function SiteHeader({
<Search className='absolute left-3 top-1/2 size-4 -translate-y-1/2 text-muted-foreground' />
<div className='flex h-8 items-center rounded-md border border-border/60 bg-muted/70 pl-10 pr-2.5 text-sm text-muted-foreground transition-colors hover:border-border hover:bg-muted'>
<span>{t('search')}</span>
<Kbd className='ml-auto gap-0.5 font-mono'>
<Kbd className='ml-auto gap-0.5 font-mono text-foreground/70'>
<span>{metaKey}</span>
<span>K</span>
</Kbd>
+1 -3
View File
@@ -120,9 +120,7 @@ export function LoadingState({
</div>
{displayTitle && (
<h3 className='text-sm font-medium mb-1 animate-pulse'>
{displayTitle}
</h3>
<p className='text-sm font-medium mb-1 animate-pulse'>{displayTitle}</p>
)}
{displayDescription && (
+3
View File
@@ -217,12 +217,15 @@ export function AppSidebar({ ...props }: React.ComponentProps<typeof Sidebar>) {
<Sidebar
collapsible='icon'
{...props}
role='navigation'
aria-label={t('mainNavigation')}
className='px-2 relative border-r border-border/40 group-data-[collapsible=icon]'
>
<Button
onClick={toggleSidebar}
variant='ghost'
size='icon'
aria-label={t('toggleSidebar')}
className='absolute top-1/2 -right-6 w-2 h-4 text-muted-foreground hover:bg-background hidden md:flex'
>
{state === 'expanded' ? (