Commit Graph

90 Commits

Author SHA1 Message Date
ryan 39f02b5d7a refactor(message_gateway): upgrade notification template engine with text/template and rich helpers 2026-09-02 22:04:48 +08:00
ryan cf0cba0679 refactor(mail): modernize smtp sending with go-mail and unify message gateway pusher 2026-09-02 21:59:47 +08:00
ryan 88ed98b013 chore: remove accidental test upload
fix(user): backfill snowflake id on login for legacy zero user
2026-09-02 21:47:12 +08:00
ryan 40c2212dd3 fix(upload): apply login middleware to /f/:id route
/f/:id had no LoginRequired middleware, so AuthUserObjKey was never
populated and GetCurrentUser/GetUserIDFromContext could not authenticate
even logged-in users, returning 401 未登录 on private files. Add loginMW.
2026-09-02 20:32:33 +08:00
ryan df6aa9ff4d fix(auth): encode snowflake user ids as strings in session and /user-info
Registered users get snowflake ids above JS MAX_SAFE_INTEGER.
/user-info emitted them as JSON numbers and login stored uint64 in
the session. Both now use decimal strings. Tests cover admin vs
non-admin cookie access to /user/self, /user-info, and /upload/my.
2026-09-02 20:22:22 +08:00
ryan c27da41b64 fix(auth): forward session cookies through the Next API proxy
Login Set-Cookie was dropped by Next rewrites, so non-admin sessions
never stuck and every later API looked unauthenticated. Proxy JSON
APIs in proxy.ts, copy Set-Cookie, send 401 to login and 403 to /403.
2026-09-02 18:49:42 +08:00
ryan 353a5f9f75 fix(user): assign snowflake IDs on registration
The HTTP register path left ID at 0, so SQLite/GORM filled a
serial primary key. CreateUser now generates a snowflake ID when
none is set, matching admin create and OAuth signup.
2026-09-02 18:41:37 +08:00
ryan b7e5e811d1 fix(auth): register CAP scope, 400 on captcha, 403 for permission
Navigating from login reused a send_email_code token on register.
Captcha failure used 401 so the client stored /register as the
post-login target and never left the page. Permission denials now
return 403, and the API client no longer wipes the session on 401.
2026-09-02 18:26:22 +08:00
ryan df7ad453cc fix(tasks): canonicalize triggered_by so execution labels resolve
Unknown values such as http and inproc_cron made the admin UI call
t(undefined). Dispatch sites now write system/manual/retry/schedule,
the list API maps legacy rows, and the table skips missing i18n keys.
2026-09-02 18:04:32 +08:00
ryan 1f1f4efec7 fix(admin): stop console Intl errors and log websocket drops
Use raw i18n for push template hints so ICU does not parse
{{placeholders}}. Pass total into the user list record count.
Allow log websocket origins behind the Next rewrite, skip the
proxy on Upgrade, and do not open a socket after unmount.
2026-09-02 17:52:57 +08:00
ryan 8aa0753b12 fix(logs): flush small access-log batches within two seconds
Default MinBatchSize of 50 left quiet admin traffic in memory
forever because MaxFlushWait was unset. Force a timed flush so
the logs page can show recent authenticated requests.
2026-09-02 17:40:43 +08:00
ryan bec1352ef7 fix(logs): collect access logs regardless of plugin order
Global Router.Use middleware is applied at HTTP Start instead of
being snapshotted when each route is registered, so risk_control
still wraps admin APIs that mount earlier. Access-log collection
is enabled by default on SQLite/Postgres, not only ClickHouse.
2026-09-02 17:39:40 +08:00
ryan 455e2f8be5 fix(config): serve public settings and enforce login CAP
Public config now comes from admin as a flat visibility=1 map instead of
a cross-plugin query that compared an integer column to "visible". Login
and register resolve CaptchaService per request so CAP is not skipped
when user applies before cap.
2026-09-02 17:07:07 +08:00
ryan 4f50f6a8f9 feat(core): bind request services and implement registered tasks
Wire plugin services through Bind/InjectFrom and AppContext so HTTP and
workers resolve dependencies after Apply. Register TaskHandler objects
with persisted results, and implement send_email_code, mail:send,
cleanup_inactive_users, and dispatch_bot_msg.
2026-09-02 16:59:00 +08:00
ryan 30bbe965bf fix(task): execute dispatched jobs and persist run records
Asynq func handlers now go through ProcessTask so admin execution
rows leave pending. The in-process worker resolves admin type
identifiers and writes the same w_task_executions table. Remove
the no-op admin system_cleanup that shadowed the upload handler.
2026-09-02 16:11:45 +08:00
ryan 33f28ad671 fix: sql 2026-09-02 15:37:06 +08:00
ryan 374289bfda fix(api): align upload permissions and mount robots and swagger routes 2026-08-30 17:53:42 +08:00
ryan 6553ac7782 fix(system): expose only GET /api/healthz
Remove /healthz and /api/health so the process advertises a single probe at /api/healthz with {status: ok}.
2026-08-30 16:41:07 +08:00
ryan 12b4c3e54c fix(cap): keep only /api/v1/cap routes
Drop the unversioned /api/cap aliases so Challenge and Redeem exist only under /api/v1/cap.
2026-08-30 16:39:40 +08:00
ryan 56c650c5b5 docs(swagger): restore gold @Router comments on platform APIs 2026-08-30 14:20:21 +08:00
ryan 4ce7110e23 feat(platform): add GET /api/health and GET /api/v1/user/self 2026-08-30 11:32:03 +08:00
ryan 9a5c2fa643 feat(message_gateway): expose PushRegistry contract 2026-08-30 11:23:01 +08:00
ryan 177d771acf feat(upload): mount existing my/update/download routes on user API 2026-08-30 11:17:11 +08:00
ryan 6f25618e83 fix(config): decode *bool so trailing-slash redirect binds from yaml/env 2026-08-30 11:10:36 +08:00
ryan b4c4b0a27e feat(http): make trailing-slash redirect configurable 2026-08-30 11:07:22 +08:00
ryan b8ad06f49f feat(system): allow PublicConfigProvider to replace public config payload 2026-08-30 11:03:17 +08:00
ryan 254533c013 feat(cap): expose CaptchaService and unversioned /api/cap routes 2026-08-30 10:53:43 +08:00
ryan d7c851bc47 autoresearch iter 35: BUGFIX a failed whitelist read is no longer cached as an admin decision 2026-08-29 19:29:25 +08:00
ryan b22f8633ba autoresearch iter 34: BUGFIX an unreadable SMTP config no longer looks like an unconfigured mailer 2026-08-29 19:19:17 +08:00
ryan 99fca9ee09 autoresearch iter 33: BUGFIX storage migration no longer migrates from a config it could not read 2026-08-29 19:12:58 +08:00
ryan f7a86d3608 autoresearch iter 32: PERF whitelist parses patterns once, 14 allocs/op to 1 2026-08-29 19:03:27 +08:00
ryan 9ea0e2bdff autoresearch iter 30: enforce user lookup column allow-list instead of trusting a comment 2026-08-29 18:49:37 +08:00
ryan 2ff0cb87c9 autoresearch iter 29: CORDIS contracts DTO must not carry a table name 2026-08-29 18:45:17 +08:00
ryan ea97b64407 fix(task): restore task metadata contract and type fields in task types api 2026-08-29 12:22:51 +08:00
ryan e568b96388 fix(auth): add missing masked_token column to w_access_tokens table in migrations 2026-08-29 11:57:04 +08:00
ryan 7786f416f8 perf(auth): eliminate redundant password queries during user info retrieval 2026-08-29 11:54:46 +08:00
ryan 64fe1658d4 fix(user): clear need_change_password and invalidate cache on password change 2026-08-29 11:52:41 +08:00
ryan d3d7c783a9 fix(auth): synchronize need_change_password across login, user-info and repositories 2026-08-29 11:49:14 +08:00
ryan 107251891f fix(user): restore plaintext default password checking and warning mechanism 2026-08-29 11:46:39 +08:00
ryan 86c750077f fix(user): seed default administrator account in initial migration 2026-08-29 11:42:43 +08:00
ryan e0f2309520 feat(router): add whitelist mechanism for http driver and auth plugin
- implement route whitelist registration and wildcard matching in RouterExtension
- add cookie store session fallback when Redis is disabled in driver_http
- actively register public auth endpoints to whitelist in auth plugin
- update user handlers to persist session and clear cookie on logout
- document router whitelist mechanism in AGENTS.md and new-api skill
2026-08-29 11:39:13 +08:00
Ryan 53ae3007d0 fix(cordis): fail-closed auth guards for user/message_gateway/admin (#1)
* autoresearch iter 23: fail-closed auth guarding for user/message_gateway

Both plugins resolve contracts.AuthService in Apply to build their route
middleware, but declared only DBService in Inject(). The kernel gates a
plugin's Apply solely on declared deps, and cmd/app.go registers user
before auth, so user mounted first, core.Inject failed, and loginMW
silently degraded to a pass-through closure — leaving /api/v1/user
change-password, profile and access-tokens unguarded. message_gateway
was saved only by its later list position.

Declare AuthService in Inject() for both, and pin the property with a
reconcile-level test that mirrors production registration order and
asserts the real auth middleware reaches the route table.

* autoresearch iter 24: make auth middleware fallbacks fail closed

user, message_gateway and admin each fell back to a c.Next() closure when
contracts.AuthService could not be resolved, so a route would be served as
if authenticated. For admin this is reachable at runtime: OnDispose calls
service.ResetServices(), which nils the global the per-request guard reads,
so requests still in flight during dispose bypass authorization entirely.

Add ginutil.AuthUnavailable() and bind every fallback to it, with a test
that drives each plugin's registered guard without an auth service present
and asserts the request is aborted rather than passed through.

* chore(autoresearch): log iter 23 (fail-open auth ordering, proven)

* autoresearch iter 24 follow-up: let staticcheck infer the auth guard type

* docs(autoresearch): log iters 24-25 and lessons 9-11 (declared-dep bug class, gate discipline)
2026-08-29 11:21:04 +08:00
ryan 4d65e57f9a merge: feat(core): implement cordis configuration extension and migrate all plugins 2026-08-29 10:54:28 +08:00
ryan ed8491addf feat(core): implement cordis configuration extension and migrate all plugins 2026-08-29 10:53:53 +08:00
ryan 696809899e feat(infra): add viper backed configuration source adapter
实现 core.ConfigSource:按 CONFIG_PATH 或向上查找定位 config.yaml,缺文件
降级为纯环境变量来源,坏文件返回错误而非 log.Fatalf,并把 key 命中与"设为
零值"区分开来。viper 依赖被隔离在此包,内核保持零具体运行时依赖。
2026-08-29 10:06:46 +08:00
ryan ad8384182c autoresearch iter 22: delete lint suppressions that suppress nothing
24 of the 96 nolint directives were dead: they covered findings that no
longer exist. A stale suppression is not inert — it silently claims any
future finding for that linter in that scope, so a real problem raised
there would vanish without anyone noticing. Explanatory prose was kept as
ordinary comments.

Two directives proved load-bearing under the project gate even though
nolintlint reported them unused, and removing them exposed verified
contextcheck false positives: App.Run does forward a sigCtx derived from
the caller's context to Start, and the migration lock renewal must keep
its own deadline because the task context may already be canceled. Both
were restored, narrowed to the live linter, and given the reason the
originals lacked.
2026-08-29 09:54:33 +08:00
ryan 1023fa3adb autoresearch iter 21: remove the telegram inbound media scratch dir after handling
downloadMedia created a fresh os.MkdirTemp for every private message carrying
a photo or document, and no code path anywhere reads Attachment.Path, so each
message permanently grew the disk while burning a Bot API download. The
handler now removes the directory once onInbound returns.

No mechanical proof is possible here: exercising downloadMedia needs a live
telebot download. Verified by reading every consumer of InboundMessage
.Attachments instead.
2026-08-29 09:40:49 +08:00
ryan efa75558af autoresearch iter 20: give the telegram poller a real long-poll window
telebot types LongPoller.Timeout as time.Duration and sends
int(timeout / time.Second) to getUpdates, so the literal 10 meant ten
nanoseconds: Telegram received timeout=0, long polling never held the
connection, and the adapter polled the Bot API in a tight loop instead.
Use 10 seconds and extract the settings so the conversion is asserted.

The adapter also has no media temp-dir cleanup (downloadMedia creates an
MkdirTemp per attachment and nothing removes it); that is left as a separate
change rather than bundled here.
2026-08-29 09:32:27 +08:00
ryan 84eaf3f555 autoresearch iter 19: make task handlers driver-agnostic so they run under both workers
upload's four real background tasks (system cleanup, stats rebuild, storage
migration, image warmup) plus the admin and user stubs registered handlers
typed as func(ctx, *asynq.Task) error. Only the asynq worker accepts that
shape; the Redis-free in-process worker's invokeHandler rejects it with
'unsupported handler type', so none of those tasks could ever run in that
deployment mode. Take payload bytes instead, which both drivers support.

Adds architecture gate check 7 forbidding asynq imports from business and
infrastructure plugins. It deliberately does not cover robfig/cron: the admin
plugin uses cron.ParseStandard only to validate a user-entered spec, which is
a library call rather than a driver binding, and the in-process scheduler
already normalizes 5-field specs.
2026-08-29 09:23:01 +08:00
ryan 8c4955c835 autoresearch iter 18: remove the phantom user:daily_audit schedule
The user plugin registered a cron dispatching to user:daily_audit, a task
pattern it never registers, and no audit logic exists anywhere in the plugin.
The daily run therefore went nowhere while a test asserted the schedule was
registered — proving the wiring existed, not that it worked. Implementing a
real daily audit is unstarted functionality, so the schedule is removed rather
than stubbed.

The combined domain test now asserts the real invariant across all applied
plugins: every schedule's task type must have a registered handler.
2026-08-29 09:11:16 +08:00