mirror of
https://github.com/saltbo/zpan.git
synced 2026-08-29 00:01:42 +08:00
7bad8d2aea
* fix(downloads): block SSRF targets in remote-download source URL The remote-download source URI was only length-validated, so an authenticated editor could point a task at the cloud metadata endpoint, loopback, or RFC 1918 hosts and have the response exfiltrated to their own drive. Add a shared isSafeHttpUrl/isBlockedUrlHost guard (scheme allowlist + private/loopback/link-local/metadata/IPv6 blocking) and cross-check source type vs uri in createDownloadTaskSchema. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(api): cover 9 untested src/lib/api.ts wrappers Adds api.test.ts coverage (RPC path, method, payload, success + ApiError paths) for listObjectsByPath, isNameConflictError, listAdminAuthProviders, upsertAuthProvider, deleteAuthProvider, listInviteCodes, generateInviteCodes, deleteInviteCode, and listTeamActivities — satisfying the CLAUDE.md coverage gate that otherwise blocks PRs touching api.ts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(spaces): release source quota on cross-space move A cross-space "move" copied bytes into the target (reserving quota there) but only trashed the source. Trashed files still count toward usage, so the moved bytes were billed in both spaces and the source never freed — contrary to the design doc ("copy + delete source, quota effectively transfers"). Purge the source subtree (independent S3 copy already exists in the target) instead of trashing it, which deletes the objects, cascades share cleanup, and reconciles usage. Rename the response field sourceTrashed -> sourceDeleted and update the move hint copy accordingly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(upload): wire S3 multipart for large files The upload UI only ever did a single presigned PUT, which caps at S3's 5 GiB limit and fails the whole transfer on any network blip — despite a complete multipart backend (object-upload-sessions) sitting unused. Add uploadPartToS3 (PUTs a part, returns its ETag) and a multipart-upload orchestrator: open session -> presign parts in batches of 100 -> PUT parts with bounded concurrency and per-part retry -> complete. Files over 100 MiB take this path; smaller files keep the single-PUT flow. Cancellation aborts the multipart and the draft. Also fixes the presignObjectUploadParts wrapper type to match the server's actual `url` field. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(auth): add password-reset flow There was no self-service password recovery — a forgotten password needed admin intervention. SMTP/email sending was already built; this wires the last mile: better-auth sendResetPassword (reset email), a "Forgot password?" link on sign-in, and /forgot-password + /reset-password pages. The forgot-password page never reveals whether an account exists. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(trash): auto-purge trashed items past a retention window Trashed files counted toward quota forever — trash never auto-emptied, so storage was never reclaimed without a manual "empty trash". Add a daily cron (CF Workers 0 4 * * * + Node setInterval) that purges trashed items older than ZPAN_TRASH_RETENTION_DAYS (default 30, 0 disables) across all orgs, reusing the existing purge path so S3 objects, share references, and quota are all cleaned. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(notifications): typed NotificationType, i18n rendering, team-join Notifications were a bare-string type with only 3 producers, and server copy was stored as hardcoded English (zh users saw English). - Add a NotificationType union in shared/ and type the notification service. - Render notification title/body client-side from type + metadata via i18n, falling back to stored strings for older rows (fixes the hardcoded-English gap). - Notify users when they join a team (team_join). (Login auditing was intentionally dropped: reusing the activity-events feed for sign_in events would spam every user's per-org activity timeline. Proper auth auditing belongs in a dedicated log and can be added separately.) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test: cover SSRF guard and multipart upload branches Raise patch coverage on the new code: uploadPartToS3 pre-aborted-signal and network-error paths, the url-safety octet-overflow and public-IPv6 branches, and the invalid-magnet rejection in the download-task schema. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>