chore(history): squash 67 commit(s) from 2026-09-25

- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints
- feat(frontend): app shell, routing and landing page with the chat-command hero
- feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion
- docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans
- feat(accounts): internal gRPC AuthenticateDevice guarded by internal key
- feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch
- feat(accounts): GET /me profile endpoint
- feat(gateway): scaffold crate with config validation and health check
- feat(gateway): reverse proxy to accounts and configs services
- feat(gateway): resolve identity once from access JWT or device token via gRPC
- feat(gateway): per-route and global rate limits with Retry-After
- feat(gateway): CORS for the site origin; docs for gateway and internal contract
- feat(configs): scaffold service with schema, config validation and health check
- feat(configs): four config slots per account with list, get and save
- feat(configs): permanent share codes with regenerate and public load-by-code
- feat(accounts): GetPublicProfiles gRPC for showcase author info
- style(accounts,common): apply rustfmt to existing sources
- feat(configs): public showcase with publish, browse, detail and copy-to-slot
- feat(backend): public profile endpoint and showcase author filter
- fix(gateway): silence clippy collapsible-if and needless-ref warnings
- docs(backend): configs-service implemented; Подсистема 1 backend complete
- feat(mod): add Optimize module skeleton with OptimizeState holder
- feat(mod): gate glass blur behind Optimize no_glass knob
- feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob
- feat(mod): trim procedural sky noise behind lite_sky knob
- feat(mod): drop fade gradients and digit rolls behind lean_hud knob
- docs(todo): mark Optimize module phase 9.2 complete
- refactor(mod): drop dead Renderer2D compatibility shims
- refactor(mod): prune unreachable Renderer2D overload towers
- refactor(mod): remove unused Renderer2D overloads and imports
- docs(todo): mark Renderer2D giant-splitting done (2179 to 1597)
- refactor(mod): extract shader id constants from LoVisualRenderPipelines
- docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines)
- refactor(mod): move Renderer2D instance state into base class
- refactor(mod): extract Renderer2DRounded drawing family
- refactor(mod): extract Renderer2DPath connector and chamfer family
- refactor(mod): extract Renderer2DShapes circle line and texture primitives
- refactor(mod): extract Renderer2DGlass and Renderer2DItem families
- refactor(mod): prune Renderer2D imports after facade split
- docs(todo): record Renderer2D facade inheritance split (1597 to 475)
- docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot
- feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer)
- refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants)
- refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec
- feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution
- feat(mod): flat fallback for no-glass optimize mode and persist global HUD config
- feat(mod): default HUD bg effects to Auto so the global surface style drives widgets
- feat(mod): add global cycle-style hotkey with surface style notification
- feat(mod): add surface style swatch strip under the global style picker
- feat(gateway): reject ambiguous paths and answer .env probes with a honeypot
- fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth
- feat(frontend): ClickGui theme pipeline generated from the mod, live site theming
- feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip
- docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9
- feat(gateway): answer /coffee with a 418 teapot
- feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer
- feat(frontend): one-click download from GitHub releases, changelog page, release CI
- feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links
- fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping)
- style(frontend): apply ClickGui glass effect to landing HUD playground widgets
- fix(frontend): prevent color field row overflow in theme editor grid
- fix(frontend): never attach stale bearer token to /auth/* requests
- fix(configs): unpublish/publish can no longer bypass moderation
- refactor(accounts): shrink auth/handlers.rs under the 250-line cap
- fix(accounts): tolerate concurrent refresh without killing every session
- fix(gateway): minor hardening from the backend review
- feat(configs): IDDQD easter egg config
This commit is contained in:
loki5512344 2026-09-25 20:22:13 +02:00
parent 72bc4c7148
commit 7f4b532f99
257 changed files with 13085 additions and 6582 deletions

View file

@ -7,7 +7,18 @@ service AccountsInternal {
// Resolves a mod's long-lived device token to its account and bumps
// device_links.last_seen. UNAUTHENTICATED if the token is unknown/revoked.
rpc AuthenticateDevice(AuthenticateDeviceRequest) returns (AuthenticateDeviceReply);
// Nick + avatar for showcase authors etc. Never returns email or role.
rpc GetPublicProfiles(GetPublicProfilesRequest) returns (GetPublicProfilesReply);
}
message AuthenticateDeviceRequest { string device_token = 1; }
message AuthenticateDeviceReply { string account_id = 1; }
message GetPublicProfilesRequest { repeated string account_ids = 1; }
message PublicProfile {
string account_id = 1;
string display_nick = 2;
string avatar_url = 3; // empty string when the account has no avatar
}
message GetPublicProfilesReply { repeated PublicProfile profiles = 1; }

View file

@ -3,19 +3,19 @@
//! came through the gateway (which strips client-supplied copies of both).
use axum::{
Json,
extract::{FromRequestParts, Request, State},
http::{request::Parts, StatusCode},
http::{StatusCode, request::Parts},
middleware::Next,
response::{IntoResponse, Response},
Json,
};
use serde_json::json;
use std::sync::Arc;
use subtle::ConstantTimeEq;
use tonic::{
Status,
metadata::{Ascii, MetadataValue},
service::Interceptor,
Status,
};
use uuid::Uuid;
@ -36,7 +36,11 @@ impl InternalKey {
}
}
pub async fn require_internal_key(State(key): State<InternalKey>, req: Request, next: Next) -> Response {
pub async fn require_internal_key(
State(key): State<InternalKey>,
req: Request,
next: Next,
) -> Response {
let ok = req
.headers()
.get(INTERNAL_KEY_HEADER)
@ -64,7 +68,11 @@ impl<S: Send + Sync> FromRequestParts<S> for GatewayIdentity {
.and_then(|s| Uuid::parse_str(s).ok())
.map(|account_id| GatewayIdentity { account_id })
.ok_or_else(|| {
(StatusCode::UNAUTHORIZED, Json(json!({ "error": "unauthorized" }))).into_response()
(
StatusCode::UNAUTHORIZED,
Json(json!({ "error": "unauthorized" })),
)
.into_response()
})
}
}
@ -100,7 +108,8 @@ impl GrpcKeyAttach {
impl Interceptor for GrpcKeyAttach {
fn call(&mut self, mut req: tonic::Request<()>) -> Result<tonic::Request<()>, Status> {
req.metadata_mut().insert(INTERNAL_KEY_HEADER, self.0.clone());
req.metadata_mut()
.insert(INTERNAL_KEY_HEADER, self.0.clone());
Ok(req)
}
}
@ -108,22 +117,31 @@ impl Interceptor for GrpcKeyAttach {
#[cfg(test)]
mod tests {
use super::*;
use axum::{routing::get, Router};
use axum::{Router, routing::get};
use axum_test::TestServer;
const KEY: &str = "internal-key-internal-key-internal!!";
fn app() -> Router {
Router::new()
.route("/whoami", get(|id: GatewayIdentity| async move { id.account_id.to_string() }))
.route(
"/whoami",
get(|id: GatewayIdentity| async move { id.account_id.to_string() }),
)
.route("/open", get(|| async { "open" }))
.layer(axum::middleware::from_fn_with_state(InternalKey::new(KEY.into()), require_internal_key))
.layer(axum::middleware::from_fn_with_state(
InternalKey::new(KEY.into()),
require_internal_key,
))
}
#[tokio::test]
async fn request_without_internal_key_is_forbidden() {
let server = TestServer::new(app());
server.get("/open").await.assert_status(axum::http::StatusCode::FORBIDDEN);
server
.get("/open")
.await
.assert_status(axum::http::StatusCode::FORBIDDEN);
}
#[tokio::test]

View file

@ -1,15 +1,15 @@
use axum::http::{header::AUTHORIZATION, HeaderMap};
use jsonwebtoken::{decode, encode, Algorithm, DecodingKey, EncodingKey, Header, Validation};
use axum::http::{HeaderMap, header::AUTHORIZATION};
use jsonwebtoken::{Algorithm, DecodingKey, EncodingKey, Header, Validation, decode, encode};
use serde::{Deserialize, Serialize};
use uuid::Uuid;
/// Distinguishes token purposes so a long-lived refresh/device token can
/// never be replayed as a short-lived access token (and vice versa).
/// Distinguishes token purposes so a token kind can never be replayed as
/// another. Only access tokens are JWTs today; refresh/device tokens are
/// opaque secrets. The claim stays so future kinds remain distinguishable.
#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "lowercase")]
pub enum TokenType {
Access,
Refresh,
}
#[derive(Debug, Serialize, Deserialize)]
@ -21,20 +21,23 @@ pub struct Claims {
fn issue(account_id: Uuid, secret: &str, token_type: TokenType, ttl_seconds: i64) -> String {
let exp = (chrono::Utc::now() + chrono::Duration::seconds(ttl_seconds)).timestamp() as usize;
let claims = Claims { sub: account_id.to_string(), exp, token_type };
encode(&Header::new(Algorithm::HS256), &claims, &EncodingKey::from_secret(secret.as_bytes()))
.expect("encoding a well-formed Claims struct cannot fail")
let claims = Claims {
sub: account_id.to_string(),
exp,
token_type,
};
encode(
&Header::new(Algorithm::HS256),
&claims,
&EncodingKey::from_secret(secret.as_bytes()),
)
.expect("encoding a well-formed Claims struct cannot fail")
}
pub fn issue_access_token(account_id: Uuid, secret: &str) -> String {
issue(account_id, secret, TokenType::Access, 15 * 60)
}
/// Temporary — deleted in Task 4 once opaque refresh tokens land.
pub fn issue_refresh_token(account_id: Uuid, secret: &str) -> String {
issue(account_id, secret, TokenType::Refresh, 30 * 24 * 60 * 60)
}
/// Returns the claims only if the signature, expiry AND token type all match.
/// HS256 is pinned explicitly (no algorithm confusion) and expiry leeway is 0.
pub fn verify_token(token: &str, secret: &str, expected: TokenType) -> Option<Claims> {
@ -83,19 +86,6 @@ mod tests {
assert!(verify_token("not.a.jwt", "test-secret", TokenType::Access).is_none());
}
#[test]
fn refresh_token_is_rejected_where_access_is_expected() {
let token = issue_refresh_token(Uuid::new_v4(), "test-secret");
assert!(verify_token(&token, "test-secret", TokenType::Access).is_none());
assert!(verify_token(&token, "test-secret", TokenType::Refresh).is_some());
}
#[test]
fn access_token_is_rejected_where_refresh_is_expected() {
let token = issue_access_token(Uuid::new_v4(), "test-secret");
assert!(verify_token(&token, "test-secret", TokenType::Refresh).is_none());
}
#[test]
fn expired_token_fails_verify() {
let token = issue(Uuid::new_v4(), "test-secret", TokenType::Access, -10);
@ -118,14 +108,6 @@ mod tests {
assert!(verify_token(&hs512, "test-secret", TokenType::Access).is_none());
}
use axum::http::HeaderValue;
fn headers_with(value: &str) -> HeaderMap {
let mut headers = HeaderMap::new();
headers.insert(AUTHORIZATION, HeaderValue::from_str(value).unwrap());
headers
}
#[test]
fn bearer_token_extracts_the_token() {
let mut h = HeaderMap::new();
@ -144,7 +126,9 @@ mod tests {
}
#[test]
fn bearer_token_rejects_garbage_headers() {
assert_eq!(bearer_token(&headers_with("Bearer not.a.jwt")).unwrap(), "not.a.jwt");
fn bearer_token_passes_opaque_value_through() {
let mut h = HeaderMap::new();
h.insert(AUTHORIZATION, "Bearer not.a.jwt".parse().unwrap());
assert_eq!(bearer_token(&h), Some("not.a.jwt"));
}
}