Depot API & v4 (#298)

* feat: nginx + torrential basics & services system

* fix: lint + i18n

* fix: update torrential to remove openssl

* feat: add torrential to Docker build

* feat: move to self hosted runner

* fix: move off self-hosted runner

* fix: update nginx.conf

* feat: torrential cache invalidation

* fix: update torrential for cache invalidation

* feat: integrity check task

* fix: lint

* feat: move to version ids

* fix: client fixes and client-side checks

* feat: new depot apis and version id fixes

* feat: update torrential

* feat: droplet bump and remove unsafe update functions

* fix: lint

* feat: v4 featureset: emulators, multi-launch commands

* fix: lint

* fix: mobile ui for game editor

* feat: launch options

* fix: lint

* fix: remove axios, use $fetch

* feat: metadata and task api improvements

* feat: task actions

* fix: slight styling issue

* feat: fix style and lints

* feat: totp backend routes

* feat: oidc groups

* fix: update drop-base

* feat: creation of passkeys & totp

* feat: totp signin

* feat: webauthn mfa/signin

* feat: launch selecting ui

* fix: manually running tasks

* feat: update add company game modal to use new SelectorGame

* feat: executor selector

* fix(docker): update rust to rust nightly for torrential build (#305)

* feat: new version ui

* feat: move package lookup to build time to allow for deno dev

* fix: lint

* feat: localisation cleanup

* feat: apply localisation cleanup

* feat: potential i18n refactor logic

* feat: remove args from commands

* fix: lint

* fix: lockfile

---------

Co-authored-by: Aden Lindsay <140392385+AdenMGB@users.noreply.github.com>
This commit is contained in:
DecDuck
2026-01-13 15:32:39 +11:00
committed by GitHub
parent 8ef983304c
commit 63ac2b8ffc
190 changed files with 5848 additions and 2309 deletions
+3
View File
@@ -103,4 +103,7 @@ export const systemACLDescriptions: ObjectFromList<typeof systemACLs> = {
"Read tasks and maintenance information, like updates available and cleanup.",
"settings:update": "Update system settings.",
"depot:new": "Create a new download depot",
"depot:delete": "Remove a download depot",
};
+33 -8
View File
@@ -43,6 +43,9 @@ export type UserACL = Array<(typeof userACLs)[number]>;
export const systemACLs = [
"setup",
"depot:new",
"depot:delete",
"auth:read",
"auth:simple:invitation:read",
"auth:simple:invitation:new",
@@ -123,8 +126,12 @@ class ACLManager {
if (!request)
throw new Error("Native web requests not available - weird deployment?");
// Sessions automatically have all ACLs
const user = await sessionHandler.getSession(request);
if (user) return user.userId;
const session = await sessionHandler.getSession(request);
if (session && session.authenticated) {
if (session.authenticated.level >= session.authenticated.requiredLevel)
return session.authenticated.userId;
return undefined;
}
const authorizationToken = this.getAuthorizationToken(request);
if (!authorizationToken) return undefined;
@@ -158,6 +165,19 @@ class ACLManager {
return undefined;
}
async allowUserSuperlevel(request: MinimumRequestObject | undefined) {
if (!request)
throw new Error("Native web requests not available - weird deployment?");
const session = await sessionHandler.getSession(request);
if (!session || !session.authenticated) return undefined;
if (session.authenticated.level < session.authenticated.requiredLevel)
return undefined;
if (session.authenticated.superleveledExpiry === undefined)
return undefined;
if (session.authenticated.superleveledExpiry < Date.now()) return undefined;
return session.authenticated.userId;
}
async allowSystemACL(
request: MinimumRequestObject | undefined,
acls: SystemACL,
@@ -165,14 +185,19 @@ class ACLManager {
if (!request)
throw new Error("Native web requests not available - weird deployment?");
const userSession = await sessionHandler.getSession(request);
if (userSession) {
if (userSession && userSession.authenticated) {
const user = await prisma.user.findUnique({
where: { id: userSession.userId },
where: { id: userSession.authenticated.userId },
});
if (user) {
if (!user) return false;
if (user.admin) return true;
return false;
if (!user.admin) return false;
if (
userSession.authenticated.level <
userSession.authenticated.requiredLevel
)
return false;
return true;
}
}
@@ -221,7 +246,7 @@ class ACLManager {
request: MinimumRequestObject,
): Promise<GlobalACL[] | undefined> {
const userSession = await sessionHandler.getSession(request);
if (!userSession) {
if (!userSession || !userSession.authenticated) {
const authorizationToken = this.getAuthorizationToken(request);
if (!authorizationToken) return undefined;
const token = await prisma.aPIToken.findUnique({
@@ -232,7 +257,7 @@ class ACLManager {
}
const user = await prisma.user.findUnique({
where: { id: userSession.userId },
where: { id: userSession.authenticated.userId },
select: {
admin: true,
},