chore(history): squash 67 commit(s) from 2026-09-25
- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
This commit is contained in:
parent
72bc4c7148
commit
7f4b532f99
257 changed files with 13085 additions and 6582 deletions
215
backend/accounts-service/src/grpc/mod.rs
Normal file
215
backend/accounts-service/src/grpc/mod.rs
Normal file
|
|
@ -0,0 +1,215 @@
|
|||
use common::internal::GrpcKeyCheck;
|
||||
use common::pb::accounts::accounts_internal_server::{AccountsInternal, AccountsInternalServer};
|
||||
use common::pb::accounts::{
|
||||
AuthenticateDeviceReply, AuthenticateDeviceRequest, GetPublicProfilesReply,
|
||||
GetPublicProfilesRequest, PublicProfile,
|
||||
};
|
||||
use sqlx::PgPool;
|
||||
use tonic::{Request, Response, Status, service::interceptor::InterceptedService};
|
||||
use uuid::Uuid;
|
||||
|
||||
const MAX_PROFILE_IDS: usize = 100;
|
||||
|
||||
pub struct AccountsGrpc {
|
||||
pool: PgPool,
|
||||
avatar_base_url: String,
|
||||
}
|
||||
|
||||
impl AccountsGrpc {
|
||||
pub fn new(pool: PgPool, avatar_base_url: String) -> Self {
|
||||
AccountsGrpc {
|
||||
pool,
|
||||
avatar_base_url,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/// Builds the internal `AccountsInternal` gRPC service, guarded by
|
||||
/// `GrpcKeyCheck` so only callers holding the shared internal key (i.e. the
|
||||
/// gateway) can reach it.
|
||||
pub fn server(
|
||||
pool: PgPool,
|
||||
avatar_base_url: String,
|
||||
internal_key: &str,
|
||||
) -> InterceptedService<AccountsInternalServer<AccountsGrpc>, GrpcKeyCheck> {
|
||||
AccountsInternalServer::with_interceptor(
|
||||
AccountsGrpc::new(pool, avatar_base_url),
|
||||
GrpcKeyCheck::new(internal_key),
|
||||
)
|
||||
}
|
||||
|
||||
#[tonic::async_trait]
|
||||
impl AccountsInternal for AccountsGrpc {
|
||||
async fn authenticate_device(
|
||||
&self,
|
||||
request: Request<AuthenticateDeviceRequest>,
|
||||
) -> Result<Response<AuthenticateDeviceReply>, Status> {
|
||||
let token = request.into_inner().device_token;
|
||||
match crate::device::links::authenticate(&self.pool, &token).await {
|
||||
Ok(Some(account_id)) => Ok(Response::new(AuthenticateDeviceReply {
|
||||
account_id: account_id.to_string(),
|
||||
})),
|
||||
Ok(None) => Err(Status::unauthenticated("unknown or revoked device token")),
|
||||
Err(err) => {
|
||||
tracing::error!("authenticate_device: {err:?}");
|
||||
Err(Status::internal("internal error"))
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
async fn get_public_profiles(
|
||||
&self,
|
||||
request: Request<GetPublicProfilesRequest>,
|
||||
) -> Result<Response<GetPublicProfilesReply>, Status> {
|
||||
let raw = request.into_inner().account_ids;
|
||||
if raw.len() > MAX_PROFILE_IDS {
|
||||
return Err(Status::invalid_argument("at most 100 account ids per call"));
|
||||
}
|
||||
let ids: Vec<Uuid> = raw.iter().filter_map(|s| Uuid::parse_str(s).ok()).collect();
|
||||
let rows = crate::accounts::repo::public_profiles(&self.pool, &ids)
|
||||
.await
|
||||
.map_err(|err| {
|
||||
tracing::error!("get_public_profiles: {err:?}");
|
||||
Status::internal("internal error")
|
||||
})?;
|
||||
let profiles = rows
|
||||
.into_iter()
|
||||
.map(|(id, nick, key)| PublicProfile {
|
||||
account_id: id.to_string(),
|
||||
display_nick: nick,
|
||||
avatar_url: key
|
||||
.map(|k| format!("{}/{k}", self.avatar_base_url))
|
||||
.unwrap_or_default(),
|
||||
})
|
||||
.collect();
|
||||
Ok(Response::new(GetPublicProfilesReply { profiles }))
|
||||
}
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
use common::internal::GrpcKeyAttach;
|
||||
use common::pb::accounts::accounts_internal_client::AccountsInternalClient;
|
||||
|
||||
const KEY: &str = "internal-key-internal-key-internal!!";
|
||||
const CDN: &str = "http://cdn/avatars";
|
||||
|
||||
async fn pool() -> PgPool {
|
||||
let url = std::env::var("DATABASE_URL")
|
||||
.unwrap_or_else(|_| "postgres://lovisual:lovisual@localhost:5432/accounts_db".into());
|
||||
let pool = PgPool::connect(&url).await.expect("connect");
|
||||
sqlx::migrate!("./migrations")
|
||||
.run(&pool)
|
||||
.await
|
||||
.expect("migrate");
|
||||
pool
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn authenticate_device_over_grpc() {
|
||||
let pool = pool().await;
|
||||
let account = crate::accounts::repo::create(
|
||||
&pool,
|
||||
&format!("g-{}@example.com", Uuid::new_v4()),
|
||||
"x",
|
||||
"Grpc",
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
let token = crate::device::links::create(&pool, account.id)
|
||||
.await
|
||||
.unwrap();
|
||||
|
||||
let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
|
||||
let addr = listener.local_addr().unwrap();
|
||||
tokio::spawn(
|
||||
tonic::transport::Server::builder()
|
||||
.add_service(server(pool.clone(), CDN.into(), KEY))
|
||||
.serve_with_incoming(tokio_stream::wrappers::TcpListenerStream::new(listener)),
|
||||
);
|
||||
let channel = tonic::transport::Endpoint::from_shared(format!("http://{addr}"))
|
||||
.unwrap()
|
||||
.connect_lazy();
|
||||
let mut client = AccountsInternalClient::with_interceptor(
|
||||
channel.clone(),
|
||||
GrpcKeyAttach::new(KEY).unwrap(),
|
||||
);
|
||||
|
||||
let reply = client
|
||||
.authenticate_device(AuthenticateDeviceRequest {
|
||||
device_token: token,
|
||||
})
|
||||
.await
|
||||
.unwrap()
|
||||
.into_inner();
|
||||
assert_eq!(reply.account_id, account.id.to_string());
|
||||
|
||||
let err = client
|
||||
.authenticate_device(AuthenticateDeviceRequest {
|
||||
device_token: "lvd_unknown".into(),
|
||||
})
|
||||
.await
|
||||
.unwrap_err();
|
||||
assert_eq!(err.code(), tonic::Code::Unauthenticated);
|
||||
|
||||
let mut no_key = AccountsInternalClient::new(channel);
|
||||
let err = no_key
|
||||
.authenticate_device(AuthenticateDeviceRequest {
|
||||
device_token: "x".into(),
|
||||
})
|
||||
.await
|
||||
.unwrap_err();
|
||||
assert_eq!(err.code(), tonic::Code::PermissionDenied);
|
||||
|
||||
sqlx::query("DELETE FROM accounts WHERE id = $1")
|
||||
.bind(account.id)
|
||||
.execute(&pool)
|
||||
.await
|
||||
.unwrap();
|
||||
}
|
||||
|
||||
#[tokio::test]
|
||||
async fn public_profiles_over_grpc() {
|
||||
let pool = pool().await;
|
||||
let a = crate::accounts::repo::create(
|
||||
&pool,
|
||||
&format!("p-{}@example.com", Uuid::new_v4()),
|
||||
"x",
|
||||
"Alice",
|
||||
)
|
||||
.await
|
||||
.unwrap();
|
||||
let svc = AccountsGrpc::new(pool.clone(), CDN.into());
|
||||
|
||||
let reply = svc
|
||||
.get_public_profiles(tonic::Request::new(GetPublicProfilesRequest {
|
||||
account_ids: vec![
|
||||
a.id.to_string(),
|
||||
Uuid::new_v4().to_string(),
|
||||
"garbage".into(),
|
||||
],
|
||||
}))
|
||||
.await
|
||||
.unwrap()
|
||||
.into_inner();
|
||||
assert_eq!(reply.profiles.len(), 1);
|
||||
assert_eq!(reply.profiles[0].display_nick, "Alice");
|
||||
assert_eq!(reply.profiles[0].avatar_url, "");
|
||||
|
||||
let too_many: Vec<String> = (0..101).map(|_| Uuid::new_v4().to_string()).collect();
|
||||
let err = svc
|
||||
.get_public_profiles(tonic::Request::new(GetPublicProfilesRequest {
|
||||
account_ids: too_many,
|
||||
}))
|
||||
.await
|
||||
.unwrap_err();
|
||||
assert_eq!(err.code(), tonic::Code::InvalidArgument);
|
||||
|
||||
sqlx::query("DELETE FROM accounts WHERE id = $1")
|
||||
.bind(a.id)
|
||||
.execute(&pool)
|
||||
.await
|
||||
.unwrap();
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue