- feat(accounts): persist device links with opaque hashed tokens, list and revoke endpoints - feat(frontend): app shell, routing and landing page with the chat-command hero - feat(frontend): Cyrillic-first fonts (Unbounded, Onest, JetBrains Mono); add i18next and motion - docs: free mod, bilingual site, one-click download, theme editor, public profiles, rich landing in plans - feat(accounts): internal gRPC AuthenticateDevice guarded by internal key - feat(frontend): ru/en i18n with typed per-feature dictionaries and language switch - feat(accounts): GET /me profile endpoint - feat(gateway): scaffold crate with config validation and health check - feat(gateway): reverse proxy to accounts and configs services - feat(gateway): resolve identity once from access JWT or device token via gRPC - feat(gateway): per-route and global rate limits with Retry-After - feat(gateway): CORS for the site origin; docs for gateway and internal contract - feat(configs): scaffold service with schema, config validation and health check - feat(configs): four config slots per account with list, get and save - feat(configs): permanent share codes with regenerate and public load-by-code - feat(accounts): GetPublicProfiles gRPC for showcase author info - style(accounts,common): apply rustfmt to existing sources - feat(configs): public showcase with publish, browse, detail and copy-to-slot - feat(backend): public profile endpoint and showcase author filter - fix(gateway): silence clippy collapsible-if and needless-ref warnings - docs(backend): configs-service implemented; Подсистема 1 backend complete - feat(mod): add Optimize module skeleton with OptimizeState holder - feat(mod): gate glass blur behind Optimize no_glass knob - feat(mod): cut MotionBlur and DoF sample counts behind lite_post knob - feat(mod): trim procedural sky noise behind lite_sky knob - feat(mod): drop fade gradients and digit rolls behind lean_hud knob - docs(todo): mark Optimize module phase 9.2 complete - refactor(mod): drop dead Renderer2D compatibility shims - refactor(mod): prune unreachable Renderer2D overload towers - refactor(mod): remove unused Renderer2D overloads and imports - docs(todo): mark Renderer2D giant-splitting done (2179 to 1597) - refactor(mod): extract shader id constants from LoVisualRenderPipelines - docs(todo): record registry wave 2026-09-25 (Renderer2D, pipelines) - refactor(mod): move Renderer2D instance state into base class - refactor(mod): extract Renderer2DRounded drawing family - refactor(mod): extract Renderer2DPath connector and chamfer family - refactor(mod): extract Renderer2DShapes circle line and texture primitives - refactor(mod): extract Renderer2DGlass and Renderer2DItem families - refactor(mod): prune Renderer2D imports after facade split - docs(todo): record Renderer2D facade inheritance split (1597 to 475) - docs: easter eggs — .env honeypot, konami troll mode, devtools banner, IDDQD config, breakable 404 block, 418 teapot - feat(mod): introduce surface style system core (SurfaceStyle, StyleSpec, StyleConfig, SurfaceRenderer) - refactor(mod): delegate HudRenderUtil liquid glass draws to SurfaceRenderer (dedupe glass constants) - refactor(mod): route bespoke glass call sites through SurfaceRenderer.plateSpec - feat(mod): add Auto option to HUD bg effects via shared HudBgStyles resolution - feat(mod): flat fallback for no-glass optimize mode and persist global HUD config - feat(mod): default HUD bg effects to Auto so the global surface style drives widgets - feat(mod): add global cycle-style hotkey with surface style notification - feat(mod): add surface style swatch strip under the global style picker - feat(gateway): reject ambiguous paths and answer .env probes with a honeypot - fix(gateway): charge failed credentials against the rate limit, allow stale ones on /auth - feat(frontend): ClickGui theme pipeline generated from the mod, live site theming - feat(frontend): landing v2 hero — voxel/particle backdrop, live ClickGui, theme strip - docs(todo): drop the FPS A/B measurement from phase 9.3, close phase 9 - feat(gateway): answer /coffee with a 418 teapot - feat(frontend): land the rest of landing v2 — HUD, module wall, showcase, FAQ, footer - feat(frontend): one-click download from GitHub releases, changelog page, release CI - feat(frontend): theme editor with live ClickGui preview, mod-compatible export and share links - fix(frontend): landing HUD playground now shows real mod widgets (fps, coordinates, module list, keybinds, ping) - style(frontend): apply ClickGui glass effect to landing HUD playground widgets - fix(frontend): prevent color field row overflow in theme editor grid - fix(frontend): never attach stale bearer token to /auth/* requests - fix(configs): unpublish/publish can no longer bypass moderation - refactor(accounts): shrink auth/handlers.rs under the 250-line cap - fix(accounts): tolerate concurrent refresh without killing every session - fix(gateway): minor hardening from the backend review - feat(configs): IDDQD easter egg config
86 lines
2.9 KiB
Rust
86 lines
2.9 KiB
Rust
pub mod accounts;
|
|
pub mod auth;
|
|
pub mod avatars;
|
|
pub mod config;
|
|
pub mod device;
|
|
pub mod error;
|
|
pub mod grpc;
|
|
|
|
use accounts::handlers::AccountsState;
|
|
use auth::handlers::AuthState;
|
|
use avatars::{handlers::AvatarState, storage::S3Storage};
|
|
use axum::{
|
|
Router,
|
|
extract::DefaultBodyLimit,
|
|
routing::{get, post},
|
|
};
|
|
use config::Config;
|
|
use device::{handlers::DeviceState, store::DeviceStore};
|
|
|
|
pub fn build_app(pool: sqlx::PgPool, cfg: &Config) -> Router {
|
|
let auth_state = AuthState::new(pool.clone(), cfg.jwt_secret.clone(), cfg.cookie_secure);
|
|
let device_state = DeviceState {
|
|
store: DeviceStore::default(),
|
|
pool: pool.clone(),
|
|
};
|
|
let avatar_state = AvatarState {
|
|
pool: pool.clone(),
|
|
storage: S3Storage::from_config(
|
|
&cfg.s3_endpoint,
|
|
&cfg.s3_access_key,
|
|
&cfg.s3_secret_key,
|
|
cfg.s3_bucket.clone(),
|
|
),
|
|
base_url: cfg.avatar_base_url(),
|
|
};
|
|
let accounts_state = AccountsState {
|
|
pool: pool.clone(),
|
|
avatar_base_url: cfg.avatar_base_url(),
|
|
};
|
|
|
|
let auth_routes = Router::new()
|
|
.route("/auth/register", post(auth::handlers::register))
|
|
.route("/auth/login", post(auth::handlers::login))
|
|
.route("/auth/refresh", post(auth::handlers::refresh))
|
|
.route("/auth/logout", post(auth::handlers::logout))
|
|
.with_state(auth_state);
|
|
|
|
let device_routes = Router::new()
|
|
.route("/device/code", post(device::handlers::create_code))
|
|
.route("/device/confirm", post(device::handlers::confirm))
|
|
.route("/device/token", post(device::handlers::token))
|
|
.route("/device/links", get(device::handlers::list_links))
|
|
.route(
|
|
"/device/links/{id}",
|
|
axum::routing::delete(device::handlers::revoke_link),
|
|
)
|
|
.with_state(device_state);
|
|
|
|
let avatar_routes = Router::new()
|
|
.route("/avatars", post(avatars::handlers::upload))
|
|
// Hard transport cap slightly above the 5 MB business limit (413 beyond it).
|
|
.layer(DefaultBodyLimit::max(6 * 1024 * 1024))
|
|
.with_state(avatar_state);
|
|
|
|
let accounts_routes = Router::new()
|
|
.route("/me", get(accounts::handlers::me))
|
|
.route("/users/{id}", get(accounts::handlers::public_profile))
|
|
.with_state(accounts_state);
|
|
|
|
// Everything except /health is internal-only: reachable solely through
|
|
// the gateway, which authenticates the caller and forwards the identity
|
|
// header. Direct traffic (or spoofed headers) is rejected here.
|
|
let api = Router::new()
|
|
.merge(auth_routes)
|
|
.merge(device_routes)
|
|
.merge(avatar_routes)
|
|
.merge(accounts_routes)
|
|
.layer(axum::middleware::from_fn_with_state(
|
|
common::internal::InternalKey::new(cfg.internal_key.clone()),
|
|
common::internal::require_internal_key,
|
|
));
|
|
|
|
Router::new()
|
|
.route("/health", get(|| async { "ok" }))
|
|
.merge(api)
|
|
}
|