feat(core): sync framework security hardening and accessibility improvements

- add util.Go with panic recovery for background goroutines
- add util.EscapeLike and explicit ESCAPE clause for SQL LIKE queries
- add DummyCheckPassword and subtle.ConstantTimeCompare against timing attacks
- enforce session ID rotation upon login/oauth callback to prevent session fixation
- add sliding window login failure rate limiting and oauth state rate limiting
- fix redis client capture race in pubsub listeners and wait on stop channel
- adjust global --primary to oklch(51.1% 0.262 276.966) for WCAG AA contrast
- fix semantic heading levels and missing aria-labels across UI components
- document security, concurrency, and a11y standards in AGENTS.md
This commit is contained in:
ryan
2026-08-27 23:01:28 +08:00
parent b66cf3ae9c
commit ae3b792e16
63 changed files with 570 additions and 176 deletions
@@ -219,7 +219,7 @@ export function AccessTokenMain() {
</div>
{/* 安全警告提示 */}
<div className='rounded-xl border border-amber-500/20 bg-amber-500/5 p-4 flex gap-3 text-amber-600 text-xs leading-relaxed'>
<div className='rounded-xl border border-amber-500/20 bg-amber-500/5 p-4 flex gap-3 text-amber-700 text-xs leading-relaxed'>
<AlertTriangle className='size-4 shrink-0 mt-0.5' />
<div className='space-y-1'>
<span className='font-bold'>{ta('securityTitle')}</span>
@@ -23,6 +23,7 @@ export function NotificationsMain() {
return (
<div className='py-6 space-y-6'>
<div className='font-semibold'>
<h1 className='sr-only'>{tn('breadcrumb')}</h1>
<Breadcrumb>
<BreadcrumbList>
<BreadcrumbItem>
@@ -238,7 +238,7 @@ export function UserFileManager() {
<Upload className='size-10' />
</div>
<div className='space-y-1'>
<h3 className='font-semibold text-sm'>{t('noFiles')}</h3>
<p className='font-semibold text-sm'>{t('noFiles')}</p>
<p className='text-xs text-muted-foreground max-w-xs'>
{debouncedKeyword ? t('noMatchingFiles') : t('uploadFirstFile')}
</p>