chore(history): squash 67 commit(s) from 2026-09-25
- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
This commit is contained in:
parent
72bc4c7148
commit
7f4b532f99
257 changed files with 13085 additions and 6582 deletions
60
backend/gateway/src/guard/honeypot.rs
Normal file
60
backend/gateway/src/guard/honeypot.rs
Normal file
|
|
@ -0,0 +1,60 @@
|
|||
//! Easter egg for `.env` scanners: instead of a 400 they get a fake file.
|
||||
//! Never forwarded upstream; answered before identity and rate limiting.
|
||||
|
||||
use axum::{
|
||||
http::{StatusCode, header::CONTENT_TYPE},
|
||||
response::{IntoResponse, Response},
|
||||
};
|
||||
|
||||
const FAKE_ENV: &str = "\
|
||||
# LoVisual production secrets — не благодари
|
||||
DATABASE_URL=postgres://idi_naxui:daun_ebani@localhost:5432/tvoya_mamka
|
||||
JWT_SECRET=nice_try_skiddie_tvoy_ip_uzhe_v_bane
|
||||
INTERNAL_KEY=0000-0000-0000-0000-otvali
|
||||
ADMIN_PASSWORD=hunter2
|
||||
S3_SECRET_KEY=lovisual_luchshe_chem_tvoy_chit
|
||||
# P.S. лучше скачай мод: https://github.com/loki5512344/LoVisual-/releases
|
||||
";
|
||||
|
||||
/// Any segment named `.env` or `.env.<suffix>` (dots may be `%2e`-encoded).
|
||||
pub fn is_env_probe(path: &str) -> bool {
|
||||
super::segments(path).any(|raw| {
|
||||
let name = super::decode_dots(raw);
|
||||
name == ".env" || name.starts_with(".env.")
|
||||
})
|
||||
}
|
||||
|
||||
pub fn fake_env() -> Response {
|
||||
(
|
||||
StatusCode::OK,
|
||||
[(CONTENT_TYPE, "text/plain; charset=utf-8")],
|
||||
FAKE_ENV,
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn detects_env_segments_only() {
|
||||
for hit in [
|
||||
"/.env",
|
||||
"/../../.env",
|
||||
"/api/.env",
|
||||
"/.env.local",
|
||||
"/%2e%2e/%2Eenv",
|
||||
] {
|
||||
assert!(is_env_probe(hit), "{hit}");
|
||||
}
|
||||
for miss in [
|
||||
"/auth/login",
|
||||
"/configs/.environment",
|
||||
"/x.env",
|
||||
"/showcase/env",
|
||||
] {
|
||||
assert!(!is_env_probe(miss), "{miss}");
|
||||
}
|
||||
}
|
||||
}
|
||||
111
backend/gateway/src/guard/mod.rs
Normal file
111
backend/gateway/src/guard/mod.rs
Normal file
|
|
@ -0,0 +1,111 @@
|
|||
//! Outermost request filter: answers the gateway's own jokes and refuses paths
|
||||
//! whose meaning changes once the upstream URL is built. reqwest/`url` (WHATWG)
|
||||
//! resolves `..`, `%2e%2e` and backslashes, while rate-limit rules match the raw
|
||||
//! path — so without this, `POST /auth/x/../login` reaches `/auth/login` without
|
||||
//! its 5/min limit.
|
||||
|
||||
pub mod honeypot;
|
||||
|
||||
use crate::rate_limit::client_ip;
|
||||
use axum::{
|
||||
Json,
|
||||
extract::{Request, State},
|
||||
http::StatusCode,
|
||||
middleware::Next,
|
||||
response::{IntoResponse, Response},
|
||||
};
|
||||
use serde_json::json;
|
||||
|
||||
/// A path segment with `%2e`/`%2E` decoded — the only escape WHATWG URL
|
||||
/// parsing treats as a dot when resolving dot-segments.
|
||||
fn decode_dots(segment: &str) -> String {
|
||||
segment.to_ascii_lowercase().replace("%2e", ".")
|
||||
}
|
||||
|
||||
fn segments(path: &str) -> impl Iterator<Item = &str> {
|
||||
path.strip_prefix('/').unwrap_or(path).split('/')
|
||||
}
|
||||
|
||||
/// True when the upstream could see a different path than the one the
|
||||
/// gateway routed and rate-limited.
|
||||
pub fn is_ambiguous(path: &str) -> bool {
|
||||
if path == "/" {
|
||||
return false;
|
||||
}
|
||||
segments(path).any(|raw| {
|
||||
let lower = raw.to_ascii_lowercase();
|
||||
let dots = decode_dots(raw);
|
||||
raw.is_empty()
|
||||
|| dots == "."
|
||||
|| dots == ".."
|
||||
|| raw.contains('\\')
|
||||
|| lower.contains("%2f")
|
||||
|| lower.contains("%5c")
|
||||
})
|
||||
}
|
||||
|
||||
const TEAPOT: &str = "Я чайник. Кофе не варю, зато LoVisual бесплатный: https://github.com/loki5512344/LoVisual-/releases\n";
|
||||
|
||||
fn teapot() -> Response {
|
||||
(
|
||||
StatusCode::IM_A_TEAPOT,
|
||||
[(
|
||||
axum::http::header::CONTENT_TYPE,
|
||||
"text/plain; charset=utf-8",
|
||||
)],
|
||||
TEAPOT,
|
||||
)
|
||||
.into_response()
|
||||
}
|
||||
|
||||
pub async fn reject_ambiguous_paths(
|
||||
State(trust_proxy): State<bool>,
|
||||
req: Request,
|
||||
next: Next,
|
||||
) -> Response {
|
||||
let path = req.uri().path();
|
||||
if path == "/coffee" {
|
||||
return teapot();
|
||||
}
|
||||
if honeypot::is_env_probe(path) {
|
||||
tracing::info!(ip = %client_ip(&req, trust_proxy), path, "honeypot hit");
|
||||
return honeypot::fake_env();
|
||||
}
|
||||
if is_ambiguous(path) {
|
||||
return (
|
||||
StatusCode::BAD_REQUEST,
|
||||
Json(json!({ "error": "bad path" })),
|
||||
)
|
||||
.into_response();
|
||||
}
|
||||
next.run(req).await
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
mod tests {
|
||||
use super::*;
|
||||
|
||||
#[test]
|
||||
fn classifies_paths() {
|
||||
for bad in [
|
||||
"/a/../b",
|
||||
"/a/%2E%2e/b",
|
||||
"/a/.%2E",
|
||||
"/a//b",
|
||||
"/a%2Fb",
|
||||
"/a\\b",
|
||||
"/a/",
|
||||
] {
|
||||
assert!(is_ambiguous(bad), "{bad}");
|
||||
}
|
||||
for ok in [
|
||||
"/",
|
||||
"/auth/login",
|
||||
"/configs/shared/AB2C",
|
||||
"/a/..b",
|
||||
"/a/.x",
|
||||
] {
|
||||
assert!(!is_ambiguous(ok), "{ok}");
|
||||
}
|
||||
}
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue