chore(history): squash 67 commit(s) from 2026-09-25
- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
This commit is contained in:
parent
72bc4c7148
commit
7f4b532f99
257 changed files with 13085 additions and 6582 deletions
141
backend/gateway/tests/common/mod.rs
Normal file
141
backend/gateway/tests/common/mod.rs
Normal file
|
|
@ -0,0 +1,141 @@
|
|||
#![allow(dead_code)]
|
||||
|
||||
use axum::{Json, Router, body::Bytes, extract::Request, routing::any};
|
||||
use gateway::config::Config;
|
||||
use gateway::identity::device::{DeviceAuth, DeviceAuthFuture, DeviceAuthenticator};
|
||||
use std::sync::Arc;
|
||||
use uuid::Uuid;
|
||||
|
||||
pub const JWT_SECRET: &str = "gateway-test-secret-gateway-test!!";
|
||||
pub const INTERNAL_KEY: &str = "internal-key-internal-key-internal!!";
|
||||
|
||||
#[allow(unused_imports)] // used by identity.rs; other test crates don't need it
|
||||
pub use ::common::jwt;
|
||||
|
||||
pub fn config(accounts: &str, configs: &str) -> Config {
|
||||
Config {
|
||||
port: 0,
|
||||
jwt_secret: JWT_SECRET.into(),
|
||||
internal_key: INTERNAL_KEY.into(),
|
||||
accounts_http_url: accounts.into(),
|
||||
accounts_grpc_url: String::new(),
|
||||
configs_http_url: configs.into(),
|
||||
site_origin: "http://localhost:5173".into(),
|
||||
trust_proxy: true,
|
||||
}
|
||||
}
|
||||
|
||||
/// Accepts exactly one device token, mapped to one account.
|
||||
pub struct FakeDevices {
|
||||
pub token: String,
|
||||
pub account: Uuid,
|
||||
}
|
||||
|
||||
impl DeviceAuthenticator for FakeDevices {
|
||||
fn authenticate<'a>(&'a self, token: &'a str) -> DeviceAuthFuture<'a> {
|
||||
Box::pin(async move {
|
||||
if token == self.token {
|
||||
DeviceAuth::Valid(self.account)
|
||||
} else {
|
||||
DeviceAuth::Invalid
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
/// accounts-service unreachable: every device token lookup fails.
|
||||
pub struct DownDevices;
|
||||
|
||||
impl DeviceAuthenticator for DownDevices {
|
||||
fn authenticate<'a>(&'a self, _token: &'a str) -> DeviceAuthFuture<'a> {
|
||||
Box::pin(async { DeviceAuth::Unavailable })
|
||||
}
|
||||
}
|
||||
|
||||
/// An access JWT signed with the right key but already expired.
|
||||
pub fn expired_access_token(account: Uuid) -> String {
|
||||
let exp = std::time::SystemTime::now()
|
||||
.duration_since(std::time::UNIX_EPOCH)
|
||||
.expect("clock after epoch")
|
||||
.as_secs() as usize
|
||||
- 60;
|
||||
let claims = ::common::jwt::Claims {
|
||||
sub: account.to_string(),
|
||||
exp,
|
||||
token_type: ::common::jwt::TokenType::Access,
|
||||
};
|
||||
jsonwebtoken::encode(
|
||||
&jsonwebtoken::Header::new(jsonwebtoken::Algorithm::HS256),
|
||||
&claims,
|
||||
&jsonwebtoken::EncodingKey::from_secret(JWT_SECRET.as_bytes()),
|
||||
)
|
||||
.expect("encode test jwt")
|
||||
}
|
||||
|
||||
pub fn no_devices() -> Arc<dyn DeviceAuthenticator> {
|
||||
Arc::new(FakeDevices {
|
||||
token: "lvd_none".into(),
|
||||
account: Uuid::nil(),
|
||||
})
|
||||
}
|
||||
|
||||
/// Starts a fake service that echoes what it received as JSON; returns its base URL.
|
||||
pub async fn spawn_echo() -> String {
|
||||
async fn echo(req: Request) -> Json<serde_json::Value> {
|
||||
let (parts, body) = req.into_parts();
|
||||
let body: Bytes = axum::body::to_bytes(body, usize::MAX)
|
||||
.await
|
||||
.unwrap_or_default();
|
||||
let header = |name: &str| {
|
||||
parts
|
||||
.headers
|
||||
.get(name)
|
||||
.and_then(|v| v.to_str().ok())
|
||||
.map(str::to_owned)
|
||||
};
|
||||
Json(serde_json::json!({
|
||||
"method": parts.method.as_str(),
|
||||
"path": parts.uri.path(),
|
||||
"query": parts.uri.query(),
|
||||
"body": String::from_utf8_lossy(&body),
|
||||
"account_id": header("x-lovisual-account-id"),
|
||||
"internal_key": header("x-lovisual-internal-key"),
|
||||
"authorization": header("authorization"),
|
||||
}))
|
||||
}
|
||||
let listener = tokio::net::TcpListener::bind("127.0.0.1:0").await.unwrap();
|
||||
let addr = listener.local_addr().unwrap();
|
||||
tokio::spawn(async move {
|
||||
axum::serve(listener, Router::new().fallback(any(echo)))
|
||||
.await
|
||||
.unwrap()
|
||||
});
|
||||
format!("http://{addr}")
|
||||
}
|
||||
|
||||
/// Sends a request straight into the router, bypassing the test client's URL
|
||||
/// handling, so the raw path (`..`, `%2e`, `//`) reaches the gateway as-is.
|
||||
pub async fn raw(
|
||||
app: &axum::Router,
|
||||
method: &str,
|
||||
uri: &str,
|
||||
forwarded_for: &str,
|
||||
) -> (axum::http::StatusCode, axum::http::HeaderMap, String) {
|
||||
use tower::ServiceExt;
|
||||
let req = axum::http::Request::builder()
|
||||
.method(method)
|
||||
.uri(uri)
|
||||
.header("x-forwarded-for", forwarded_for)
|
||||
.body(axum::body::Body::empty())
|
||||
.expect("valid raw request");
|
||||
let res = app.clone().oneshot(req).await.expect("infallible router");
|
||||
let (parts, body) = res.into_parts();
|
||||
let bytes = axum::body::to_bytes(body, usize::MAX)
|
||||
.await
|
||||
.unwrap_or_default();
|
||||
(
|
||||
parts.status,
|
||||
parts.headers,
|
||||
String::from_utf8_lossy(&bytes).into_owned(),
|
||||
)
|
||||
}
|
||||
Loading…
Add table
Add a link
Reference in a new issue