f1cfb61d13
Security hardening (CRITICAL/HIGH from production-readiness audit):
- Require strong JWT_SECRET + separate INTEGRATION_ENCRYPTION_KEY at boot;
refuse placeholder defaults. Integration key now derived via HKDF.
- SSRF guard (src/lib/server/utils/safeFetch.ts): DNS-resolves and rejects
RFC1918/loopback/link-local/IPv4-mapped IPv6/decimal-IP/cloud-metadata.
Manual redirect handling re-validates each 3xx Location hop. Applied to
healthcheck, RSS, calendar, metric, system-stats, camera, notifications,
discovery, apps/preview, and all integration clients.
- API tokens, session refresh tokens, invite tokens, password-reset tokens
switched from bcrypt to sha256 with @unique indexed lookup (O(1) instead
of O(N) bcrypt-compares; eliminates a trivial DoS).
- Refresh-token reuse detection via Session.previousTokenHash.
- Permission checks on App PATCH/DELETE and Widget/Section endpoints.
- /api/integrations/alerts now requires auth.
- SVG uploads sanitized through DOMPurify (svg profile, scheme allow-list).
- Custom CSS sanitizer + selector scoping (decodes CSS unicode escapes
before pattern match, drops forbidden at-rules incl. @import without
whitespace, strips dangerous url() args). Scoped to .custom-css-scope.
- Backup restore validates SQLite magic header, takes a safety snapshot,
uses atomic rename, re-applies pragmas.
- SQLite WAL + busy_timeout + foreign_keys + synchronous=NORMAL at startup.
- Healthcheck scheduler was dead code; wired in hooks.server.ts with
HMR-safe singleton, concurrency cap, overlap prevention, retention jobs
for AppClick/Notification/AuditLog. Composite indexes added on hot paths.
- Security headers (CSP, HSTS-on-https, X-Frame-Options, Permissions-Policy)
emitted on every response.
- Account-enumeration mitigation on login (dummy bcrypt on no-user/oauth
branches) + rate limiting on login/register/onboarding/refresh/invite/
password-reset.
- OAuth callback sanitizes IdP error_description before echoing.
New features:
- Custom +error.svelte pages (root + boards + admin) via shared
ErrorState component. Inverted hierarchy (status as label, title as hero).
- /forgot-password + /reset-password + admin-mediated /admin/password-resets
page. SHA256 tokens, 24h TTL, all sessions revoked on apply.
- /invite page for manual invite-token redemption.
- /api/metrics Prometheus exposition with optional METRICS_TOKEN bearer
auth. Counters for login/healthcheck/notification/integration; gauges
for users/boards/apps + per-status app counts.
- Webhook HMAC-SHA256 signing for HTTP notification channels (optional
shared secret + configurable signature header, default X-Signature-256).
- PATCH /api/users/me/password for self-service password change.
- Persistent uploads at /app/data/uploads with served-from-volume handler
at /uploads/[...path]. SVGs served with CSP: sandbox.
- /api/health does a DB ping; returns 503 on disconnect.
- Public /status filtered to guest-accessible-board apps when unauthenticated.
- Audit log coverage: LOGIN_SUCCESS/FAILED, LOGOUT, OAUTH_LOGIN,
OAUTH_USER_PROVISIONED, SESSION_REVOKED, API_TOKEN_*, INVITE_*,
APP_UPDATED, PASSWORD_CHANGED, PASSWORD_RESET_*.
Performance:
- Board page: removed double findAll() over-fetch; include links + appTags
in board query; widgets lazy-loaded via dynamic imports (marked,
DOMPurify, hls.js, integration renderers).
- uptimeService.getAllAppsUptime: single batched query instead of N+1.
- 30s in-memory user-locals cache; invalidated on user mutation.
- pruneOldStatuses: single window-function DELETE instead of N+1.
Code quality:
- Typed error classes (NotFoundError, PermissionError, RateLimitError,
IntegrationError) with toHttpError mapper.
- Locals.user shape exposes avatarUrl and narrows role via guard.
- App input types derived from Zod schemas via z.infer.
- 274 tests passing (up from 212); 62 new tests covering SSRF guard,
CSS sanitizer, SVG sanitizer, rate limiter.
CI / Docker / config:
- Test workflow adds build, docker-build, audit jobs. Release workflow
uses buildx multi-arch (amd64+arm64) with provenance + SBOM.
- Dockerfile uses tini, multi-stage prune, persistent uploads dir, single
prisma migrate deploy (no destructive db push fallback).
- docker-compose: JWT_SECRET + INTEGRATION_ENCRYPTION_KEY required at
startup, log rotation, resource limits.
- README documents breaking-change upgrade path.
Bug fixes from UI/UX review:
- ~55 missing i18n keys added to en/ru (auth flows, error pages, admin
nav, register invite banner, settings.card_style).
- Hardcoded English on login replaced with $t('auth.remember_me').
- Admin nav uses i18n keys; mobile horizontal-scroll layout.
- Page <title> tags standardized.
- Password-resets: separated error/info/success surfaces, ConfirmDialog
replaces window.confirm.
- Auth pages have matching lucide icon badges.
- Webhook secret has eye toggle and monospace input.
- text-green-500 → text-emerald-500 to match codebase convention.
Pre-existing CI lint failures cleaned up (31 errors → 0): each-key
attributes added, unused-svelte-ignore comments removed, two any casts
typed, dead skeleton components removed, /boards/[id]/edit redirect to
inline edit mode.
Tests: 274 / 274 passing
Type check: 0 errors / 0 warnings
Build: green
404 lines
11 KiB
Plaintext
404 lines
11 KiB
Plaintext
generator client {
|
|
provider = "prisma-client-js"
|
|
}
|
|
|
|
datasource db {
|
|
provider = "sqlite"
|
|
url = env("DATABASE_URL")
|
|
}
|
|
|
|
model User {
|
|
id String @id @default(cuid())
|
|
email String @unique
|
|
password String?
|
|
displayName String
|
|
avatarUrl String?
|
|
authProvider String @default("local") // local | oauth
|
|
role String @default("user") // admin | user
|
|
onboardingComplete Boolean @default(false)
|
|
trackRecentApps Boolean @default(true)
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
themeMode String?
|
|
primaryHue Int?
|
|
primarySaturation Int?
|
|
backgroundType String?
|
|
locale String?
|
|
|
|
groups UserGroup[]
|
|
sessions Session[]
|
|
createdApps App[]
|
|
boards Board[]
|
|
favorites UserFavorite[]
|
|
clicks AppClick[]
|
|
notificationChannels NotificationChannel[]
|
|
notifications Notification[]
|
|
apiTokens ApiToken[]
|
|
auditLogs AuditLog[]
|
|
boardTemplates BoardTemplate[]
|
|
passwordResets PasswordReset[]
|
|
|
|
@@index([email])
|
|
}
|
|
|
|
model PasswordReset {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
tokenHash String @unique // sha256 of the raw reset token
|
|
expiresAt DateTime
|
|
usedAt DateTime?
|
|
createdById String? // admin who issued (if admin-mediated), null if self-service
|
|
createdAt DateTime @default(now())
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([userId])
|
|
@@index([expiresAt])
|
|
}
|
|
|
|
model Invite {
|
|
id String @id @default(cuid())
|
|
tokenHash String @unique
|
|
email String? // optional — lock the invite to a specific email
|
|
role String @default("user") // user | admin
|
|
expiresAt DateTime
|
|
usedAt DateTime?
|
|
usedByUserId String?
|
|
createdById String?
|
|
createdAt DateTime @default(now())
|
|
|
|
@@index([tokenHash])
|
|
@@index([createdById])
|
|
}
|
|
|
|
model Session {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
tokenHash String // sha256 hash of current refresh token
|
|
previousTokenHash String? // sha256 hash of the immediately-previous refresh token (reuse detection)
|
|
label String?
|
|
userAgent String?
|
|
ipAddress String?
|
|
rememberMe Boolean @default(false)
|
|
lastUsedAt DateTime @default(now())
|
|
expiresAt DateTime
|
|
createdAt DateTime @default(now())
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
|
|
@@unique([tokenHash])
|
|
@@index([userId])
|
|
@@index([expiresAt])
|
|
}
|
|
|
|
model Group {
|
|
id String @id @default(cuid())
|
|
name String @unique
|
|
description String?
|
|
isDefault Boolean @default(false)
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
users UserGroup[]
|
|
}
|
|
|
|
model UserGroup {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
groupId String
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
group Group @relation(fields: [groupId], references: [id], onDelete: Cascade)
|
|
|
|
@@unique([userId, groupId])
|
|
@@index([userId])
|
|
@@index([groupId])
|
|
}
|
|
|
|
model App {
|
|
id String @id @default(cuid())
|
|
name String
|
|
url String
|
|
icon String?
|
|
iconType String @default("lucide") // lucide | simple | url | emoji
|
|
description String?
|
|
category String?
|
|
tags String @default("") // comma-separated
|
|
healthcheckEnabled Boolean @default(false)
|
|
healthcheckInterval Int @default(300) // seconds
|
|
healthcheckMethod String @default("GET")
|
|
healthcheckExpectedStatus Int @default(200)
|
|
healthcheckTimeout Int @default(5000) // milliseconds
|
|
integrationType String?
|
|
integrationConfig String?
|
|
integrationEnabled Boolean @default(false)
|
|
createdById String?
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
createdBy User? @relation(fields: [createdById], references: [id], onDelete: SetNull)
|
|
statuses AppStatus[]
|
|
widgets Widget[]
|
|
appTags AppTag[]
|
|
links AppLink[]
|
|
clicks AppClick[]
|
|
notifications Notification[]
|
|
favorites UserFavorite[]
|
|
|
|
@@index([name])
|
|
@@index([category])
|
|
@@index([createdById])
|
|
}
|
|
|
|
model AppStatus {
|
|
id String @id @default(cuid())
|
|
appId String
|
|
status String @default("unknown") // online | offline | degraded | unknown
|
|
responseTime Int? // milliseconds
|
|
checkedAt DateTime @default(now())
|
|
|
|
app App @relation(fields: [appId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([appId, checkedAt])
|
|
@@index([checkedAt])
|
|
}
|
|
|
|
model Board {
|
|
id String @id @default(cuid())
|
|
name String
|
|
icon String?
|
|
description String?
|
|
isDefault Boolean @default(false)
|
|
isGuestAccessible Boolean @default(false)
|
|
backgroundConfig String? // JSON stored as string for SQLite
|
|
themeHue Int?
|
|
themeSaturation Int?
|
|
backgroundType String?
|
|
cardSize String?
|
|
wallpaperUrl String?
|
|
wallpaperBlur Int?
|
|
wallpaperOverlay Float?
|
|
customCss String?
|
|
createdById String?
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
createdBy User? @relation(fields: [createdById], references: [id], onDelete: SetNull)
|
|
sections Section[]
|
|
|
|
@@index([createdById])
|
|
}
|
|
|
|
model Section {
|
|
id String @id @default(cuid())
|
|
boardId String
|
|
title String
|
|
icon String?
|
|
order Int @default(0)
|
|
isExpandedByDefault Boolean @default(true)
|
|
cardSize String?
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
board Board @relation(fields: [boardId], references: [id], onDelete: Cascade)
|
|
widgets Widget[]
|
|
|
|
@@index([boardId])
|
|
}
|
|
|
|
model Widget {
|
|
id String @id @default(cuid())
|
|
sectionId String
|
|
type String // app | bookmark | note | embed | status
|
|
order Int @default(0)
|
|
config String @default("{}") // JSON stored as string for SQLite
|
|
appId String?
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
section Section @relation(fields: [sectionId], references: [id], onDelete: Cascade)
|
|
app App? @relation(fields: [appId], references: [id], onDelete: SetNull)
|
|
|
|
@@index([sectionId])
|
|
@@index([appId])
|
|
}
|
|
|
|
model Permission {
|
|
id String @id @default(cuid())
|
|
entityType String // board | app
|
|
entityId String
|
|
targetType String // user | group
|
|
targetId String
|
|
level String // view | edit | admin
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
|
|
@@unique([entityType, entityId, targetType, targetId])
|
|
@@index([entityType, entityId])
|
|
@@index([targetType, targetId])
|
|
}
|
|
|
|
model SystemSettings {
|
|
id String @id @default("singleton")
|
|
authMode String @default("local") // local | oauth | both
|
|
registrationEnabled Boolean @default(true)
|
|
oauthClientId String?
|
|
oauthClientSecret String?
|
|
oauthDiscoveryUrl String?
|
|
defaultTheme String @default("dark")
|
|
defaultPrimaryColor String @default("#6366f1")
|
|
healthcheckDefaults String @default("{}") // JSON stored as string for SQLite
|
|
customCss String?
|
|
onboardingComplete Boolean @default(false)
|
|
backupEnabled Boolean @default(false)
|
|
backupCronExpression String @default("0 3 * * *") // default: daily at 3 AM
|
|
backupMaxCount Int @default(10)
|
|
createdAt DateTime @default(now())
|
|
updatedAt DateTime @updatedAt
|
|
}
|
|
|
|
// --- New models for Phases 4-7 ---
|
|
|
|
model Tag {
|
|
id String @id @default(cuid())
|
|
name String @unique
|
|
color String?
|
|
createdAt DateTime @default(now())
|
|
|
|
appTags AppTag[]
|
|
|
|
@@index([name])
|
|
}
|
|
|
|
model AppTag {
|
|
id String @id @default(cuid())
|
|
appId String
|
|
tagId String
|
|
|
|
app App @relation(fields: [appId], references: [id], onDelete: Cascade)
|
|
tag Tag @relation(fields: [tagId], references: [id], onDelete: Cascade)
|
|
|
|
@@unique([appId, tagId])
|
|
@@index([appId])
|
|
@@index([tagId])
|
|
}
|
|
|
|
model AppLink {
|
|
id String @id @default(cuid())
|
|
appId String
|
|
label String
|
|
url String
|
|
icon String?
|
|
order Int @default(0)
|
|
|
|
app App @relation(fields: [appId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([appId])
|
|
}
|
|
|
|
model UserFavorite {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
appId String
|
|
order Int @default(0)
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
app App @relation(fields: [appId], references: [id], onDelete: Cascade)
|
|
|
|
@@unique([userId, appId])
|
|
@@index([userId])
|
|
@@index([appId])
|
|
}
|
|
|
|
model AppClick {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
appId String
|
|
clickedAt DateTime @default(now())
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
app App @relation(fields: [appId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([userId, clickedAt])
|
|
@@index([appId])
|
|
@@index([clickedAt])
|
|
}
|
|
|
|
model NotificationChannel {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
type String // discord | slack | telegram | http
|
|
config String @default("{}") // JSON stored as string for SQLite
|
|
enabled Boolean @default(true)
|
|
createdAt DateTime @default(now())
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([userId])
|
|
}
|
|
|
|
model Notification {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
appId String?
|
|
event String // app_online | app_offline | app_degraded
|
|
message String
|
|
sentAt DateTime @default(now())
|
|
readAt DateTime?
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
app App? @relation(fields: [appId], references: [id], onDelete: SetNull)
|
|
|
|
@@index([userId, sentAt])
|
|
@@index([appId])
|
|
}
|
|
|
|
model ApiToken {
|
|
id String @id @default(cuid())
|
|
userId String
|
|
name String
|
|
tokenHash String @unique
|
|
scope String // read | write | admin
|
|
lastUsedAt DateTime?
|
|
expiresAt DateTime?
|
|
createdAt DateTime @default(now())
|
|
|
|
user User @relation(fields: [userId], references: [id], onDelete: Cascade)
|
|
|
|
@@index([userId])
|
|
@@index([tokenHash])
|
|
}
|
|
|
|
model AuditLog {
|
|
id String @id @default(cuid())
|
|
userId String?
|
|
action String // user_created | user_deleted | etc.
|
|
entityType String
|
|
entityId String
|
|
details String @default("{}") // JSON stored as string for SQLite
|
|
createdAt DateTime @default(now())
|
|
|
|
user User? @relation(fields: [userId], references: [id], onDelete: SetNull)
|
|
|
|
@@index([userId, createdAt])
|
|
@@index([action])
|
|
@@index([entityType, entityId, createdAt])
|
|
@@index([createdAt])
|
|
}
|
|
|
|
model BoardTemplate {
|
|
id String @id @default(cuid())
|
|
name String
|
|
description String?
|
|
icon String?
|
|
config String @default("{}") // JSON stored as string for SQLite
|
|
isBuiltin Boolean @default(false)
|
|
createdById String?
|
|
createdAt DateTime @default(now())
|
|
|
|
createdBy User? @relation(fields: [createdById], references: [id], onDelete: SetNull)
|
|
|
|
@@index([createdById])
|
|
}
|