refactor(auth): replace dashboard sessions with stateless tokens and session control (#6329)

* refactor(auth): replace dashboard sessions with stateless tokens

* feat(auth): harden session issuance and distributed enforcement

* fix(proxy): preserve trusted proxy compatibility defaults

* refactor: address dashboard auth review feedback

* refactor: remove classic frontend and flatten web app
This commit is contained in:
Calcium-Ion
2026-07-20 16:48:43 +08:00
committed by GitHub
parent 5a6c53d496
commit 31d70fca39
1605 changed files with 17511 additions and 147913 deletions
+145
View File
@@ -0,0 +1,145 @@
/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
For commercial licensing, please contact support@quantumnous.com
*/
import { create } from 'zustand'
import type { AdminCapabilities } from '@/lib/admin-permissions'
export type UserPermissions = {
sidebar_settings?: boolean
sidebar_modules?: Record<string, unknown>
admin_permissions?: AdminCapabilities
}
export interface AuthUser {
id: number
username: string
display_name?: string
email?: string
role: number
status?: number
group?: string
quota?: number
used_quota?: number
request_count?: number
aff_code?: string
aff_count?: number
aff_quota?: number
aff_history_quota?: number
inviter_id?: number
github_id?: string
discord_id?: string
oidc_id?: string
wechat_id?: string
telegram_id?: string
linux_do_id?: string
language?: string
setting?: Record<string, unknown> | string
stripe_customer?: string
sidebar_modules?: string
permissions?: UserPermissions
}
export interface LoginSession {
sid: string
current: boolean
login_method: string
ip: string
user_agent: string
created_at: number
last_active_at: number
expires_at: number
}
export interface AuthBundle {
access_token: string
token_type: 'Bearer' | string
access_expires_at: number
user: AuthUser
session: LoginSession
}
export type AuthBootstrapState = 'idle' | 'checking' | 'complete'
interface AuthState {
auth: {
user: AuthUser | null
accessToken: string | null
accessExpiresAt: number | null
session: LoginSession | null
pending2FAFlowToken: string | null
bootstrapState: AuthBootstrapState
setBundle: (bundle: AuthBundle) => void
setUser: (user: AuthUser | null) => void
setPending2FAFlowToken: (flowToken: string | null) => void
setBootstrapState: (bootstrapState: AuthBootstrapState) => void
reset: (bootstrapState?: AuthBootstrapState) => void
}
}
export const useAuthStore = create<AuthState>()((set) => ({
auth: {
user: null,
accessToken: null,
accessExpiresAt: null,
session: null,
pending2FAFlowToken: null,
bootstrapState: 'idle',
setBundle: (bundle) =>
set((state) => ({
...state,
auth: {
...state.auth,
user: bundle.user,
accessToken: bundle.access_token,
accessExpiresAt: bundle.access_expires_at,
session: bundle.session,
pending2FAFlowToken: null,
bootstrapState: 'complete',
},
})),
setUser: (user) =>
set((state) => ({
...state,
auth: { ...state.auth, user },
})),
setPending2FAFlowToken: (pending2FAFlowToken) =>
set((state) => ({
...state,
auth: { ...state.auth, pending2FAFlowToken },
})),
setBootstrapState: (bootstrapState) =>
set((state) => ({
...state,
auth: { ...state.auth, bootstrapState },
})),
reset: (bootstrapState = 'complete') =>
set((state) => ({
...state,
auth: {
...state.auth,
user: null,
accessToken: null,
accessExpiresAt: null,
session: null,
pending2FAFlowToken: null,
bootstrapState,
},
})),
},
}))
+88
View File
@@ -0,0 +1,88 @@
/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
For commercial licensing, please contact support@quantumnous.com
*/
import { create } from 'zustand'
import { persist } from 'zustand/middleware'
interface NotificationState {
// Last read Notice content signature (full trimmed message)
lastReadNotice: string
// Array of read announcement keys (id or content hash)
readAnnouncementKeys: string[]
// Timestamp of last "Close Today" action
closedUntilDate: string | null
// Actions
markNoticeRead: (noticeContent: string) => void
markAnnouncementsRead: (keys: string[]) => void
setClosedUntilDate: (date: string | null) => void
isAnnouncementRead: (key: string) => boolean
isNoticeClosed: () => boolean
}
/**
* Notification store for tracking read status of Notice and Announcements
* Persists to localStorage to maintain state across sessions
*/
export const useNotificationStore = create<NotificationState>()(
persist(
(set, get) => ({
lastReadNotice: '',
readAnnouncementKeys: [],
closedUntilDate: null,
markNoticeRead: (noticeContent: string) => {
// Persist the full trimmed content so edits beyond 100 chars register
const normalizedContent = noticeContent.trim()
set({ lastReadNotice: normalizedContent })
},
markAnnouncementsRead: (keys: string[]) => {
set((state) => ({
readAnnouncementKeys: [
...new Set([...state.readAnnouncementKeys, ...keys]),
],
}))
},
setClosedUntilDate: (date: string | null) => {
set({ closedUntilDate: date })
},
isAnnouncementRead: (key: string) => {
return get().readAnnouncementKeys.includes(key)
},
isNoticeClosed: () => {
const { closedUntilDate } = get()
if (!closedUntilDate) return false
const today = new Date().toDateString()
return closedUntilDate === today
},
}),
{
name: 'notification-storage',
partialize: (state) => ({
lastReadNotice: state.lastReadNotice,
readAnnouncementKeys: state.readAnnouncementKeys,
closedUntilDate: state.closedUntilDate,
}),
}
)
)
+113
View File
@@ -0,0 +1,113 @@
/*
Copyright (C) 2023-2026 QuantumNous
This program is free software: you can redistribute it and/or modify
it under the terms of the GNU Affero General Public License as
published by the Free Software Foundation, either version 3 of the
License, or (at your option) any later version.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU Affero General Public License for more details.
You should have received a copy of the GNU Affero General Public License
along with this program. If not, see <https://www.gnu.org/licenses/>.
For commercial licensing, please contact support@quantumnous.com
*/
import { create } from 'zustand'
import { persist } from 'zustand/middleware'
import { DEFAULT_SYSTEM_NAME, DEFAULT_LOGO } from '@/lib/constants'
export type CurrencyDisplayType = 'USD' | 'CNY' | 'TOKENS' | 'CUSTOM'
export interface CurrencyConfig {
/** Whether to render quota values as currency instead of raw units */
displayInCurrency: boolean
/** Currency presentation strategy configured by the admin */
quotaDisplayType: CurrencyDisplayType
/** Number of quota units that equal one USD */
quotaPerUnit: number
/** Exchange rate from USD to the configured local currency */
usdExchangeRate: number
/** Custom currency symbol configured by the admin (used when type === CUSTOM) */
customCurrencySymbol: string
/** Exchange rate from USD to the custom currency (used when type === CUSTOM) */
customCurrencyExchangeRate: number
}
export interface SystemConfig {
systemName: string
logo: string
footerHtml?: string
demoSiteEnabled?: boolean
displayTokenStatEnabled?: boolean
currency: CurrencyConfig
}
export const DEFAULT_CURRENCY_CONFIG: CurrencyConfig = {
displayInCurrency: true,
quotaDisplayType: 'USD',
quotaPerUnit: 500000,
usdExchangeRate: 1,
customCurrencySymbol: '¤',
customCurrencyExchangeRate: 1,
}
interface SystemConfigState {
config: SystemConfig
loading: boolean
loadedLogoUrl: string
setConfig: (config: Partial<SystemConfig>) => void
setLoadedLogoUrl: (url: string) => void
setLoading: (loading: boolean) => void
}
/**
* System configuration store with automatic persistence
* Manages system name, logo, footer HTML and loading states
*/
export const useSystemConfigStore = create<SystemConfigState>()(
persist(
(set) => ({
config: {
systemName: DEFAULT_SYSTEM_NAME,
logo: DEFAULT_LOGO,
currency: { ...DEFAULT_CURRENCY_CONFIG },
},
loading: true,
loadedLogoUrl: DEFAULT_LOGO,
setConfig: (newConfig) =>
set((state) => ({
config: {
...state.config,
...newConfig,
currency: {
...state.config.currency,
...(newConfig.currency ?? {}),
},
},
})),
setLoadedLogoUrl: (url) => set({ loadedLogoUrl: url }),
setLoading: (loading) => set({ loading }),
}),
{
name: 'system-config-storage',
partialize: (state) => ({
config: state.config,
loadedLogoUrl: state.loadedLogoUrl,
}),
}
)
)
// Selector helpers for convenience
export const getSystemName = () =>
useSystemConfigStore.getState().config.systemName
export const getLogo = () => useSystemConfigStore.getState().config.logo
export const getFooterHtml = () =>
useSystemConfigStore.getState().config.footerHtml