|
|
e1cdff2b4a
|
security: backend validation for all inputs
- router.param('id'): all :id path params must be positive ints
(tickets/features/polls/auth/users; external/bans/notifications already
had parseInt - now consistent)
- notifications: type enum + webhook URL format + SSRF (isPrivateUrl
exported) + events whitelist + active boolean check on PUT
- bans: type enum + player_name length
- external: all-tickets type/status enums, bans status/type enums,
page/limit floor protection, ticket field length caps, clients active
boolean + id validation
- verified: 28 checks (syntax + validation coverage)
|
2026-08-21 20:10:05 +08:00 |
|
|
|
8c5ce78fd0
|
chore: add AGPLv3 copyright header to all source files
- 52 JS files (backend + public/js): header with
Copyright (C) 2026 Sea Network Technology Studio
Author: CangLan <admin@sea-studio.top>
+ AGPLv3 notice
- idempotent (skips if header present), all syntax-checked
|
2026-08-19 20:27:05 +08:00 |
|
|
|
6e9101a506
|
fix: deploy crash + multiple bug fixes + cleanup
- server.js: fix getSiteName() returning string when not installed causing
'getSiteName(...).then is not a function' crash on homepage (deploy blocker)
- server.js: auto-load business routes after install completes (no restart needed),
HTML cache keyed by api_key
- install: validate db name/email/password, trigger route loading after complete
- app.js: fix forgot/reset/verify pages rendering HomePage (missing page mapping)
- verify.js: support URL token auto-verification for external registration links
- auth: new email_code template for 6-digit code, reset_password template
(forgot-password was using verify_email template)
- upload.js: fix MP4 magic-bytes check using undefined buf variable
- tickets.js: status enum validation, anonymous submission rate limit
- security.js: XSS whitelist preserves email template HTML, strips scripts,
blocks javascript:/data: hrefs; CORS reject returns 403
- bans.js: allow clearing reason/duration, status enum validation
- users.js: fix req.user.role ReferenceError in create user modal
- home.js: tracking results now have detail view button
- .gitignore: ignore data/ (db credentials), logs, session files, temp scripts
|
2026-08-16 21:21:25 +08:00 |
|
|
|
12721d09ee
|
fix: duplicate res.json crash + missing try/catch in bans POST
|
2026-07-18 01:45:00 +08:00 |
|
|
|
dce812aa2f
|
feat: bans show account source + ban source (ticket/manual)
|
2026-07-18 01:35:30 +08:00 |
|
|
|
ce51abc127
|
fix: add source field to bans + display in list
|
2026-07-18 01:26:37 +08:00 |
|
|
|
2a12e7b740
|
fix: ban duration >= not >, auto-prefill min duration
|
2026-07-18 01:11:41 +08:00 |
|
|
|
aa2c296971
|
feat: escalating ban duration - each ban must be longer than previous
|
2026-07-18 01:09:14 +08:00 |
|
|
|
5ed109ec0e
|
feat: ban list with dashboard widget, owner add/edit bans
|
2026-07-18 00:52:33 +08:00 |
|