chore(history): squash 67 commit(s) from 2026-09-25
- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
This commit is contained in:
parent
72bc4c7148
commit
7f4b532f99
257 changed files with 13085 additions and 6582 deletions
66
backend/gateway/src/identity/device.rs
Normal file
66
backend/gateway/src/identity/device.rs
Normal file
|
|
@ -0,0 +1,66 @@
|
|||
use common::internal::GrpcKeyAttach;
|
||||
use common::pb::accounts::{
|
||||
AuthenticateDeviceRequest, accounts_internal_client::AccountsInternalClient,
|
||||
};
|
||||
use std::{future::Future, pin::Pin};
|
||||
use tonic::{
|
||||
Code,
|
||||
service::interceptor::InterceptedService,
|
||||
transport::{Channel, Endpoint},
|
||||
};
|
||||
use uuid::Uuid;
|
||||
|
||||
pub enum DeviceAuth {
|
||||
Valid(Uuid),
|
||||
Invalid,
|
||||
/// accounts-service unreachable — the gateway answers 503, not 401,
|
||||
/// so the mod doesn't wrongly forget its token.
|
||||
Unavailable,
|
||||
}
|
||||
|
||||
pub type DeviceAuthFuture<'a> = Pin<Box<dyn Future<Output = DeviceAuth> + Send + 'a>>;
|
||||
|
||||
pub trait DeviceAuthenticator: Send + Sync + 'static {
|
||||
fn authenticate<'a>(&'a self, token: &'a str) -> DeviceAuthFuture<'a>;
|
||||
}
|
||||
|
||||
pub struct GrpcDevices {
|
||||
client: AccountsInternalClient<InterceptedService<Channel, GrpcKeyAttach>>,
|
||||
}
|
||||
|
||||
impl GrpcDevices {
|
||||
/// Lazy: the gateway boots even if accounts-service is still starting.
|
||||
pub fn connect_lazy(url: &str, internal_key: &str) -> anyhow::Result<Self> {
|
||||
let channel = Endpoint::from_shared(url.to_owned())?
|
||||
.timeout(std::time::Duration::from_secs(5))
|
||||
.connect_lazy();
|
||||
Ok(GrpcDevices {
|
||||
client: AccountsInternalClient::with_interceptor(
|
||||
channel,
|
||||
GrpcKeyAttach::new(internal_key)?,
|
||||
),
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
impl DeviceAuthenticator for GrpcDevices {
|
||||
fn authenticate<'a>(&'a self, token: &'a str) -> DeviceAuthFuture<'a> {
|
||||
Box::pin(async move {
|
||||
let mut client = self.client.clone();
|
||||
match client
|
||||
.authenticate_device(AuthenticateDeviceRequest {
|
||||
device_token: token.to_owned(),
|
||||
})
|
||||
.await
|
||||
{
|
||||
Ok(reply) => Uuid::parse_str(&reply.into_inner().account_id)
|
||||
.map_or(DeviceAuth::Invalid, DeviceAuth::Valid),
|
||||
Err(status) if status.code() == Code::Unauthenticated => DeviceAuth::Invalid,
|
||||
Err(status) => {
|
||||
tracing::warn!("AuthenticateDevice failed: {status}");
|
||||
DeviceAuth::Unavailable
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
114
backend/gateway/src/identity/mod.rs
Normal file
114
backend/gateway/src/identity/mod.rs
Normal file
|
|
@ -0,0 +1,114 @@
|
|||
pub mod device;
|
||||
|
||||
use axum::{
|
||||
Json,
|
||||
extract::{Request, State},
|
||||
http::{HeaderValue, StatusCode, header::AUTHORIZATION},
|
||||
middleware::Next,
|
||||
response::{IntoResponse, Response},
|
||||
};
|
||||
use common::internal::{ACCOUNT_ID_HEADER, DEVICE_TOKEN_PREFIX, INTERNAL_KEY_HEADER};
|
||||
use common::jwt::{TokenType, bearer_token, verify_token};
|
||||
use device::{DeviceAuth, DeviceAuthenticator};
|
||||
use serde_json::json;
|
||||
use std::sync::Arc;
|
||||
use uuid::Uuid;
|
||||
|
||||
/// Who made the request, as far as the gateway could verify.
|
||||
#[derive(Clone, Copy)]
|
||||
pub struct Identity(pub Option<Uuid>);
|
||||
|
||||
/// How the caller's credentials resolved. Recorded by `identify`, acted on by
|
||||
/// `authorize` — resolution must not reject on its own, because it sits before
|
||||
/// rate limiting and an unknown device token already cost a gRPC round trip.
|
||||
#[derive(Clone, Copy, PartialEq, Eq)]
|
||||
pub enum Credentials {
|
||||
/// No `Authorization` header at all.
|
||||
Anonymous,
|
||||
/// Verified; `Identity` carries the account.
|
||||
Valid,
|
||||
/// Present but not verifiable (expired/garbage/unknown device token).
|
||||
Invalid,
|
||||
/// Device lookup failed; the caller is neither allowed nor blamed.
|
||||
Unavailable,
|
||||
}
|
||||
|
||||
#[derive(Clone)]
|
||||
pub struct IdentityState {
|
||||
pub jwt_secret: Arc<str>,
|
||||
pub devices: Arc<dyn DeviceAuthenticator>,
|
||||
}
|
||||
|
||||
fn reject(status: StatusCode, message: &str) -> Response {
|
||||
(status, Json(json!({ "error": message }))).into_response()
|
||||
}
|
||||
|
||||
/// Public auth endpoints: stale credentials there must not lock the caller
|
||||
/// out of logout/refresh — they are treated as anonymous instead of 401.
|
||||
fn is_auth_path(path: &str) -> bool {
|
||||
path.starts_with("/auth/")
|
||||
}
|
||||
|
||||
/// Resolves the caller into `Identity` + `Credentials` extensions, never
|
||||
/// rejecting; the gate is `authorize`.
|
||||
pub async fn identify(
|
||||
State(state): State<IdentityState>,
|
||||
mut req: Request,
|
||||
next: Next,
|
||||
) -> Response {
|
||||
// Client-supplied copies of trusted headers are never forwarded.
|
||||
req.headers_mut().remove(ACCOUNT_ID_HEADER);
|
||||
req.headers_mut().remove(INTERNAL_KEY_HEADER);
|
||||
|
||||
let (account, credentials) = match bearer_token(req.headers()) {
|
||||
None => (None, Credentials::Anonymous),
|
||||
Some(token) if token.starts_with(DEVICE_TOKEN_PREFIX) => {
|
||||
match state.devices.authenticate(token).await {
|
||||
DeviceAuth::Valid(id) => (Some(id), Credentials::Valid),
|
||||
DeviceAuth::Invalid => (None, Credentials::Invalid),
|
||||
DeviceAuth::Unavailable => (None, Credentials::Unavailable),
|
||||
}
|
||||
}
|
||||
Some(token) => {
|
||||
let id = verify_token(token, &state.jwt_secret, TokenType::Access)
|
||||
.and_then(|claims| Uuid::parse_str(&claims.sub).ok());
|
||||
match id {
|
||||
Some(id) => (Some(id), Credentials::Valid),
|
||||
None => (None, Credentials::Invalid),
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
// The client's bearer token stops here either way.
|
||||
req.headers_mut().remove(AUTHORIZATION);
|
||||
if let Some(id) = account
|
||||
&& let Ok(value) = HeaderValue::from_str(&id.to_string())
|
||||
{
|
||||
req.headers_mut().insert(ACCOUNT_ID_HEADER, value);
|
||||
}
|
||||
req.extensions_mut().insert(Identity(account));
|
||||
req.extensions_mut().insert(credentials);
|
||||
next.run(req).await
|
||||
}
|
||||
|
||||
/// Turns a failed resolution into an HTTP rejection — positioned after rate
|
||||
/// limiting so that a rejected credential still costs the caller a token.
|
||||
pub async fn authorize(req: Request, next: Next) -> Response {
|
||||
let credentials = req
|
||||
.extensions()
|
||||
.get::<Credentials>()
|
||||
.copied()
|
||||
.unwrap_or(Credentials::Anonymous);
|
||||
let allowed = credentials == Credentials::Anonymous
|
||||
|| credentials == Credentials::Valid
|
||||
|| is_auth_path(req.uri().path());
|
||||
if !allowed {
|
||||
return match credentials {
|
||||
Credentials::Unavailable => {
|
||||
reject(StatusCode::SERVICE_UNAVAILABLE, "auth backend unavailable")
|
||||
}
|
||||
_ => reject(StatusCode::UNAUTHORIZED, "unauthorized"),
|
||||
};
|
||||
}
|
||||
next.run(req).await
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue