Commit Graph

247 Commits

Author SHA1 Message Date
hobokenchicken 34c18c13ae fix(android): increase login form button spacing, shrink passkey text
- forgot password link: mt-3 → mt-4
- passkey button: mt-3 → mt-4, added text-xs to prevent overflow
- create account: mt-4 → mt-5
2026-07-21 09:45:40 -04:00
hobokenchicken cca6ea0e37 fix: stop infinite scroll feedback when no more messages
Scroll handler now checks !hasMore to avoid calling fetchOlderMessages
when all messages are loaded. Previously the handler would fire on every
scroll event (since scrollTop stayed < 100), creating a .then() callback
loop that adjusted scroll position repeatedly, causing 'stuck' scrolling.
2026-07-21 09:05:39 -04:00
hobokenchicken 738b9b17ff fix: add unsafe-inline to Tauri script-src CSP
Release Desktop Apps / build-linux (push) Successful in 4m50s
Release Desktop Apps / build-windows (push) Successful in 16m59s
Release Desktop Apps / release (push) Successful in 11s
v0.3.11
2026-07-20 13:42:21 -04:00
hobokenchicken 44370f41e5 ops: .dockerignore, non-root user, network isolation, deploy rollback
- .dockerignore excludes .git, node_modules, certs, *.zip
- Dockerfile runs as non-root appuser
- compose.yml isolates frontend (Caddy only) and backend (DB/cache/media) networks
- deploy.sh snapshots binary before pull and rolls back on failed health check
2026-07-20 13:15:19 -04:00
hobokenchicken 1d6c9bdfe6 perf: rate limiter cleanup goroutine, DB pool constraints
- ipLimiter evicts stale entries after 10 min of inactivity via 5 min sweep
- DB pool capped at 25 max open, 5 idle, 15 min lifetime
2026-07-20 13:13:58 -04:00
hobokenchicken 57aec2c6b3 sec: hash tokens in DB, set Tauri CSP, escape quotes in XSS guard
- Session and email verification/reset tokens stored as SHA-256 hash in DB
  (raw token stays client-side in cookie/email link)
- Tauri CSP set: default-src 'self'; script-src 'self'; style-src 'self' 'unsafe-inline';
  img-src 'self' data: https:; connect-src 'self' wss: https:
- escapeHtml now handles double and single quotes to prevent attribute-based XSS
2026-07-20 13:13:09 -04:00
hobokenchicken d4ca5f576e sec: point coturn at live LE certs, remove old ./certs/ mount 2026-07-20 13:10:27 -04:00
hobokenchicken 5f2b0aea8b sec: remove certs/cookie from tracking, parameterize LiveKit secrets, add .env.example 2026-07-20 13:03:42 -04:00
hobokenchicken 6f6d1329c6 fix(linux): guard WebSocket.prototype assignment — read-only on WebKitGTK 2026-07-20 12:26:14 -04:00
hobokenchicken 156ee4197c fix: remove env() from CSS, set safe-area via JS only 2026-07-20 11:50:07 -04:00
hobokenchicken a5882f32c4 chore: bump to v0.2.9 (version code 2009) 2026-07-20 11:37:26 -04:00
hobokenchicken 516168d290 fix(android): replace env() with JS-set CSS vars for safe areas 2026-07-20 11:30:28 -04:00
hobokenchicken c2be53e53f fix: append messages locally on send, don't rely solely on WS 2026-07-20 11:07:57 -04:00
hobokenchicken 953a1e26e6 fix: add Tauri origins to CSRF allowlist 2026-07-20 11:02:34 -04:00
hobokenchicken 5d9b629dca fix: correct debug symbols structure for Play Store 2026-07-20 10:58:21 -04:00
hobokenchicken 4cc6c6f1ed chore: bump to v0.2.8 (version code 2008) 2026-07-20 10:25:47 -04:00
hobokenchicken 82f329808e fix(android): replace default icons with dumpster fire logo 2026-07-20 10:12:38 -04:00
hobokenchicken 0ab08a9374 chore: bump to v0.2.7 (version code 2007) 2026-07-20 10:01:32 -04:00
hobokenchicken c9884d1cbd chore: add native debug symbols for Play Store 2026-07-20 09:52:24 -04:00
hobokenchicken 974eca4bb2 fix(android): edge-to-edge alignment, keyboard handling, toolbar spacing 2026-07-20 09:49:38 -04:00
hobokenchicken 8437ddcb7f chore: remove leftover hashgen temp file 2026-07-17 15:48:46 -04:00
hobokenchicken aa0af5db4f feat: account deletion in settings + privacy policy with deletion link 2026-07-17 15:47:29 -04:00
hobokenchicken e79505d8b4 fix(tauri): disable WebKitGTK sandbox inside AppImage on Linux and bump version to 0.2.6 2026-07-16 15:28:36 -04:00
hobokenchicken b0d820cd92 fix(tauri): set WEBKIT_DISABLE_DMABUF_RENDERER=1 on Linux to prevent white screen 2026-07-16 15:03:10 -04:00
hobokenchicken a8cb5c5933 fix: use SameSite=Lax for session cookie
SameSite=None requires Secure=true or modern browsers silently reject
the Set-Cookie header. Since the site is served over HTTPS via Caddy,
this was causing login to succeed (200) but the session cookie to be
dropped, making the subsequent /auth/me call fail with 401.

SameSite=Lax is the correct setting for same-origin session cookies.
2026-07-16 14:52:13 -04:00
hobokenchicken bda4c9d73d fix: handle 401 gracefully on web; add Bearer token auth for Tauri
- fetchMe() no longer surfaces 401 as a user-facing error (it just
  means 'no session', not a failure)
- API client auto-clears auth state on 401 mid-session so the user
  gets redirected to login instead of seeing 'ERR: Request failed: 401'
- Session middleware now accepts Authorization: Bearer <token> header
  as fallback when no cookie is present (for Tauri/native clients)
- Login, register, and WebAuthn endpoints expose X-Session-Token header
  so non-browser clients can capture the token
2026-07-16 14:46:17 -04:00
hobokenchicken d4fff01e35 fix(desktop): implement bearer token auth for windows webview2 2026-07-16 14:30:28 -04:00
hobokenchicken 77313671b6 fix(auth): set SameSite=None for session cookies to fix cross-origin session loss in Tauri apps 2026-07-16 14:26:18 -04:00
hobokenchicken e76f755abb fix(api): add CORS headers to allow cross-origin requests from Tauri desktop app 2026-07-16 14:21:15 -04:00
hobokenchicken 3bc8f9721e added firebase json 2026-07-16 14:07:29 -04:00
hobokenchicken a66b777712 fix(tauri): unregister and prevent service worker to fix 404 cache routing issues 2026-07-16 13:58:06 -04:00
hobokenchicken 19386c2b33 fix(tauri): redirect relative fetch and websocket urls to production backend for desktop app 2026-07-16 13:27:33 -04:00
hobokenchicken e7deb84660 fix(ci): manually configure caching using actions/cache@v3 for gitea compatibility 2026-07-16 13:03:56 -04:00
hobokenchicken 76230bb9d6 fix(ci): recursively glob artifact files to prevent empty releases 2026-07-16 12:47:45 -04:00
hobokenchicken 908b87eb5d fix(ci): correct rustup download URL for windows 2026-07-16 12:22:18 -04:00
hobokenchicken e62f551e2f fix(ci): use valid release action (softprops/action-gh-release) 2026-07-16 12:17:30 -04:00
hobokenchicken 83409cef0d chore(ci): add rust and npm caching to speed up builds 2026-07-16 11:02:23 -04:00
hobokenchicken a99714eec6 fix(ci): downgrade artifact actions to v3 for gitea compatibility 2026-07-16 10:46:54 -04:00
hobokenchicken 6a24b6f335 fix(ci): use curl and CI=true to prevent Windows runner hang 2026-07-16 10:33:46 -04:00
hobokenchicken 87a49118b5 added rpm to apt get list 2026-07-16 14:08:08 +00:00
hobokenchicken 300aeb219f fix: message area scroll — add min-h-0 to flex column 2026-07-16 09:23:08 -04:00
hobokenchicken 0f19b9089d feat(ui): Discord-style roles/channel perms + IDE themes
Split-pane role editor with tri-state channel overrides (roles/members).
CSS-var themes (Gruvbox default + 9 IDE palettes) in top bar and settings.
2026-07-15 21:46:07 -04:00
hobokenchicken 3c7b8278ce fix: client perms, @everyone/@channel, docs, unit tests
- usePermissions ORs current user roles + @everyone only (not all server roles)
- cache myRolesByServer; load on active server; refresh after self role edit
- gate/notify @everyone and @channel; plain @username push; special mention UI
- refresh FEATURE_PARITY (DMs exist; drop stale critical gaps)
- README production deploy notes dumpster.service
- unit tests for permission bits and broadcast mention tokens
2026-07-15 20:56:53 -04:00
hobokenchicken a277c78e2c feat(ui): BOTS section in member list
Members API appends server bots (is_bot). Sidebar groups ONLINE / OFFLINE / BOTS.
Bots get green BOT badge, no kick menu or profile. Mentions and DMs skip bots.
2026-07-15 20:37:05 -04:00
hobokenchicken 038ac1fe8e fix(bots): intercept /confess so original never hits chat
Root cause of "not anonymous":
1. Confess deleted via raw SQL with no MESSAGE_DELETE broadcast
2. Frontend extractIds only accepted message_id, but deletes send id
   so live clients never removed deleted messages without refresh

Fix:
- Intercept /confess at message create: never store or broadcast the
  original; post only the anonymous bot message
- Accept both id and message_id on MESSAGE_DELETE in the WS store
- Include both fields on delete broadcasts
2026-07-15 20:28:47 -04:00
hobokenchicken 07c72b041d fix(bots): auto-join server from channel_id so built-ins can post
Root cause: makeSender requires bot_servers membership, but create
flow never auto-added bots when users only picked a channel.

- Start() resolves config.channel_id → server and upserts bot_servers
- Confess cursor uses (created_at,id) so deletes don't stall polling
2026-07-15 20:17:23 -04:00
hobokenchicken f6322fb779 feat(bots): anonConfess + shitpostLeaderboard built-in bots
- ConfessBot: polls for /confess messages, deletes original, reposts anonymous
- LeaderboardBot: daily top-10 message count recap from DB
- BotFunc extended with *sql.DB param for DB-reading bots
- Both types registered in runner + BotManager UI
2026-07-15 19:46:09 -04:00
hobokenchicken 49ea7c4e3b fix(pwa): replace hamburger overlays with proper mobile bottom nav
- MobileBottomNav: [SERVERS] [CHAT] [MEMBERS] tab bar, always visible
- Servers tab opens sidebar overlay, chat/members switch views
- Removed hamburger + members toggle from mobile top bar
- Top bar compact on mobile (no redundant buttons)
- safe-area-inset-bottom on nav, clean inset on frame
- Desktop status bar hidden on mobile, preserved on desktop
- Dead MobileNav/MobileDrawer left in place (unused, can prune later)
2026-07-15 17:21:10 -04:00
hobokenchicken 95cbcf79a4 docs: update README for bot store, built-in runner, steamfree 2026-07-15 15:40:22 -04:00
hobokenchicken 3fd0b0e9e2 fix(bots): channel picker dropdown instead of ID text input
Server selector + channel dropdown for built-in bot config.
No more asking users to paste UUIDs.
2026-07-15 15:02:39 -04:00