chore(history): squash 67 commit(s) from 2026-09-25

- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints
- feat(frontend): app shell, routing and landing page with the chat-command hero
- feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion
- docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans
- feat(accounts): internal gRPC AuthenticateDevice guarded by internal key
- feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch
- feat(accounts): GET /me profile endpoint
- feat(gateway): scaffold crate with config validation and health check
- feat(gateway): reverse proxy to accounts and configs services
- feat(gateway): resolve identity once from access JWT or device token via gRPC
- feat(gateway): per-route and global rate limits with Retry-After
- feat(gateway): CORS for the site origin; docs for gateway and internal contract
- feat(configs): scaffold service with schema, config validation and health check
- feat(configs): four config slots per account with list, get and save
- feat(configs): permanent share codes with regenerate and public load-by-code
- feat(accounts): GetPublicProfiles gRPC for showcase author info
- style(accounts,common): apply rustfmt to existing sources
- feat(configs): public showcase with publish, browse, detail and copy-to-slot
- feat(backend): public profile endpoint and showcase author filter
- fix(gateway): silence clippy collapsible-if and needless-ref warnings
- docs(backend): configs-service implemented; Подсистема 1 backend complete
- feat(mod): add Optimize module skeleton with OptimizeState holder
- feat(mod): gate glass blur behind Optimize no_glass knob
- feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob
- feat(mod): trim procedural sky noise behind lite_sky knob
- feat(mod): drop fade gradients and digit rolls behind lean_hud knob
- docs(todo): mark Optimize module phase 9.2 complete
- refactor(mod): drop dead Renderer2D compatibility shims
- refactor(mod): prune unreachable Renderer2D overload towers
- refactor(mod): remove unused Renderer2D overloads and imports
- docs(todo): mark Renderer2D giant-splitting done (2179 to 1597)
- refactor(mod): extract shader id constants from LoVisualRenderPipelines
- docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines)
- refactor(mod): move Renderer2D instance state into base class
- refactor(mod): extract Renderer2DRounded drawing family
- refactor(mod): extract Renderer2DPath connector and chamfer family
- refactor(mod): extract Renderer2DShapes circle line and texture primitives
- refactor(mod): extract Renderer2DGlass and Renderer2DItem families
- refactor(mod): prune Renderer2D imports after facade split
- docs(todo): record Renderer2D facade inheritance split (1597 to 475)
- docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot
- feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer)
- refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants)
- refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec
- feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution
- feat(mod): flat fallback for no-glass optimize mode and persist global HUD config
- feat(mod): default HUD bg effects to Auto so the global surface style drives widgets
- feat(mod): add global cycle-style hotkey with surface style notification
- feat(mod): add surface style swatch strip under the global style picker
- feat(gateway): reject ambiguous paths and answer .env probes with a honeypot
- fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth
- feat(frontend): ClickGui theme pipeline generated from the mod, live site theming
- feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip
- docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9
- feat(gateway): answer /coffee with a 418 teapot
- feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer
- feat(frontend): one-click download from GitHub releases, changelog page, release CI
- feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links
- fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping)
- style(frontend): apply ClickGui glass effect to landing HUD playground widgets
- fix(frontend): prevent color field row overflow in theme editor grid
- fix(frontend): never attach stale bearer token to /auth/* requests
- fix(configs): unpublish/publish can no longer bypass moderation
- refactor(accounts): shrink auth/handlers.rs under the 250-line cap
- fix(accounts): tolerate concurrent refresh without killing every session
- fix(gateway): minor hardening from the backend review
- feat(configs): IDDQD easter egg config
This commit is contained in:
loki5512344 2026-09-25 20:22:13 +02:00
parent 72bc4c7148
commit 7f4b532f99
257 changed files with 13085 additions and 6582 deletions

View file

@ -0,0 +1,66 @@
use common::internal::GrpcKeyAttach;
use common::pb::accounts::{
AuthenticateDeviceRequest, accounts_internal_client::AccountsInternalClient,
};
use std::{future::Future, pin::Pin};
use tonic::{
Code,
service::interceptor::InterceptedService,
transport::{Channel, Endpoint},
};
use uuid::Uuid;
pub enum DeviceAuth {
Valid(Uuid),
Invalid,
/// accounts-service unreachable — the gateway answers 503, not 401,
/// so the mod doesn't wrongly forget its token.
Unavailable,
}
pub type DeviceAuthFuture<'a> = Pin<Box<dyn Future<Output = DeviceAuth> + Send + 'a>>;
pub trait DeviceAuthenticator: Send + Sync + 'static {
fn authenticate<'a>(&'a self, token: &'a str) -> DeviceAuthFuture<'a>;
}
pub struct GrpcDevices {
client: AccountsInternalClient<InterceptedService<Channel, GrpcKeyAttach>>,
}
impl GrpcDevices {
/// Lazy: the gateway boots even if accounts-service is still starting.
pub fn connect_lazy(url: &str, internal_key: &str) -> anyhow::Result<Self> {
let channel = Endpoint::from_shared(url.to_owned())?
.timeout(std::time::Duration::from_secs(5))
.connect_lazy();
Ok(GrpcDevices {
client: AccountsInternalClient::with_interceptor(
channel,
GrpcKeyAttach::new(internal_key)?,
),
})
}
}
impl DeviceAuthenticator for GrpcDevices {
fn authenticate<'a>(&'a self, token: &'a str) -> DeviceAuthFuture<'a> {
Box::pin(async move {
let mut client = self.client.clone();
match client
.authenticate_device(AuthenticateDeviceRequest {
device_token: token.to_owned(),
})
.await
{
Ok(reply) => Uuid::parse_str(&reply.into_inner().account_id)
.map_or(DeviceAuth::Invalid, DeviceAuth::Valid),
Err(status) if status.code() == Code::Unauthenticated => DeviceAuth::Invalid,
Err(status) => {
tracing::warn!("AuthenticateDevice failed: {status}");
DeviceAuth::Unavailable
}
}
})
}
}

View file

@ -0,0 +1,114 @@
pub mod device;
use axum::{
Json,
extract::{Request, State},
http::{HeaderValue, StatusCode, header::AUTHORIZATION},
middleware::Next,
response::{IntoResponse, Response},
};
use common::internal::{ACCOUNT_ID_HEADER, DEVICE_TOKEN_PREFIX, INTERNAL_KEY_HEADER};
use common::jwt::{TokenType, bearer_token, verify_token};
use device::{DeviceAuth, DeviceAuthenticator};
use serde_json::json;
use std::sync::Arc;
use uuid::Uuid;
/// Who made the request, as far as the gateway could verify.
#[derive(Clone, Copy)]
pub struct Identity(pub Option<Uuid>);
/// How the caller's credentials resolved. Recorded by `identify`, acted on by
/// `authorize` — resolution must not reject on its own, because it sits before
/// rate limiting and an unknown device token already cost a gRPC round trip.
#[derive(Clone, Copy, PartialEq, Eq)]
pub enum Credentials {
/// No `Authorization` header at all.
Anonymous,
/// Verified; `Identity` carries the account.
Valid,
/// Present but not verifiable (expired/garbage/unknown device token).
Invalid,
/// Device lookup failed; the caller is neither allowed nor blamed.
Unavailable,
}
#[derive(Clone)]
pub struct IdentityState {
pub jwt_secret: Arc<str>,
pub devices: Arc<dyn DeviceAuthenticator>,
}
fn reject(status: StatusCode, message: &str) -> Response {
(status, Json(json!({ "error": message }))).into_response()
}
/// Public auth endpoints: stale credentials there must not lock the caller
/// out of logout/refresh — they are treated as anonymous instead of 401.
fn is_auth_path(path: &str) -> bool {
path.starts_with("/auth/")
}
/// Resolves the caller into `Identity` + `Credentials` extensions, never
/// rejecting; the gate is `authorize`.
pub async fn identify(
State(state): State<IdentityState>,
mut req: Request,
next: Next,
) -> Response {
// Client-supplied copies of trusted headers are never forwarded.
req.headers_mut().remove(ACCOUNT_ID_HEADER);
req.headers_mut().remove(INTERNAL_KEY_HEADER);
let (account, credentials) = match bearer_token(req.headers()) {
None => (None, Credentials::Anonymous),
Some(token) if token.starts_with(DEVICE_TOKEN_PREFIX) => {
match state.devices.authenticate(token).await {
DeviceAuth::Valid(id) => (Some(id), Credentials::Valid),
DeviceAuth::Invalid => (None, Credentials::Invalid),
DeviceAuth::Unavailable => (None, Credentials::Unavailable),
}
}
Some(token) => {
let id = verify_token(token, &state.jwt_secret, TokenType::Access)
.and_then(|claims| Uuid::parse_str(&claims.sub).ok());
match id {
Some(id) => (Some(id), Credentials::Valid),
None => (None, Credentials::Invalid),
}
}
};
// The client's bearer token stops here either way.
req.headers_mut().remove(AUTHORIZATION);
if let Some(id) = account
&& let Ok(value) = HeaderValue::from_str(&id.to_string())
{
req.headers_mut().insert(ACCOUNT_ID_HEADER, value);
}
req.extensions_mut().insert(Identity(account));
req.extensions_mut().insert(credentials);
next.run(req).await
}
/// Turns a failed resolution into an HTTP rejection — positioned after rate
/// limiting so that a rejected credential still costs the caller a token.
pub async fn authorize(req: Request, next: Next) -> Response {
let credentials = req
.extensions()
.get::<Credentials>()
.copied()
.unwrap_or(Credentials::Anonymous);
let allowed = credentials == Credentials::Anonymous
|| credentials == Credentials::Valid
|| is_auth_path(req.uri().path());
if !allowed {
return match credentials {
Credentials::Unavailable => {
reject(StatusCode::SERVICE_UNAVAILABLE, "auth backend unavailable")
}
_ => reject(StatusCode::UNAUTHORIZED, "unauthorized"),
};
}
next.run(req).await
}