Cockatrice/servatrice/migrations
BruebachL ed4eb1cb31
Some checks are pending
Build Desktop / Configure (push) Waiting to run
Build Desktop / Debian 13 (push) Blocked by required conditions
Build Desktop / Debian 12 (push) Blocked by required conditions
Build Desktop / Fedora 44 (push) Blocked by required conditions
Build Desktop / Fedora 43 (push) Blocked by required conditions
Build Desktop / Servatrice_Debian 12 (push) Blocked by required conditions
Build Desktop / Ubuntu 26.04 (push) Blocked by required conditions
Build Desktop / Ubuntu 24.04 (push) Blocked by required conditions
Build Desktop / Arch (push) Blocked by required conditions
Build Desktop / macOS 15 (push) Blocked by required conditions
Build Desktop / macOS 13 Intel (push) Blocked by required conditions
Build Desktop / macOS 14 (push) Blocked by required conditions
Build Desktop / macOS 15 Debug (push) Blocked by required conditions
Build Desktop / Windows 10 (push) Blocked by required conditions
Build Docker Image / amd64 & arm64 (push) Waiting to run
[Server/Client/Protocol] Reporting users + moderation queue functionality (#7091)
* [Server/Client/Protocol] Reporting users + moderation queue functionality

Took 6 minutes

Took 3 minutes

Took 8 seconds

Took 11 minutes

Took 12 minutes

Took 7 minutes

Took 15 seconds

Took 2 minutes

Took 1 minute


Took 30 seconds

Took 16 seconds

* CI Fix

Took 6 minutes

* CI Fix

Took 6 minutes

* [Protocol] Add moderation investigation commands

Adds the protocol layer for the moderation investigation suite:
- Command_GetUserSessions/GetUserAlts/GetModeratorLastLogins/ResetUserPassword/RemoveUserAvatar (1013-1017)
- Response extensions 1215-1219 with ServerInfo messages for sessions, alts, and staff logins
- last_login on Response_ReportUserInfo and warning_il on Response_WarnList

Took 2 minutes

* [Utility] Add warning categories parser with infraction levels

Parses the server's 'officialwarnings' setting (comma-separated, optional
'|IL' suffix) into WarningCategory structs so the client can display the
infraction level of each warning category. Includes GTest coverage.

* [Server] Add moderation investigation tools

Implements the server side of the moderation suite:
- getUserSessions/getUserAlts/getModeratorLastLogins/removeUserAvatar DB methods
- Handlers for all five new commands with audit records (PASSWORD_RESET,
  REMOVE_USER_AVATAR); password resets return a generated temporary password
- cmdGetWarnList now reports per-category infraction levels from the
  officialwarnings setting; cmdReportUserInfo reports last_login
- Update servatrice.ini.example with the warning taxonomy
- Password/avatar mutations report RespNameNotFound when the user does not exist

* [Client] Add moderation tab with investigate, password reset, and avatar removal

- New Moderation tab: search a user to show account info, alternate
  accounts, login sessions, and staff last logins; actions to reset the
  user's password (shows the generated temporary password) and remove the
  user's avatar
- 'Investigate user' entry in the user context menu opens the tab pre-loaded
  for that user
- Warning dialog shows the infraction level of each warning category
- Tab wired into TabSupervisor with a moderator-gated menu action, shortcut,
  and tabs.ini persistence (default closed)

* [Server/Client/Protocol] Address PR #7091 review: security, bug, and perf fixes

Security:
- Promote RESET_USER_PASSWORD to admin-only dispatch (was moderator-accessible)
- Reject password reset on users with equal/higher privilege than caller
- Notify affected user via Event_NotifyUser::CUSTOM when password is reset
- Add server-side category whitelist for reports
- Drop reporter name fallback in comment/details authorization (ID-only)
- Force password change: new DB column + login enforcement + client disconnect

Bugs:
- XSS via QTextEdit::append() → insertPlainText() in report tab and utils
- allNotified initialized to true even with empty recipients list
- Warning combo box: use currentData() instead of baked-in display text
- Report resolution now records who resolved (resolved_by column + audit)

Performance:
- IP-correlation subquery: add 6-month window + LIMIT 200
- getUserSessions: clamp limit to 500

Non-blocking:
- Palette-aware colors in report_utils.cpp (dark/light mode)
- Report list pagination: offset/limit fields + total_count in response
- SessionCommand enum gap comment for reserved values 1201-1203

Schema: 36→37 (force_password_change), 37→38 (resolved_by)

Took 12 minutes


Took 16 seconds

* Fix macOs pedantry

Took 5 minutes

---------

Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de>
2026-08-21 15:00:13 +02:00
..
servatrice_0000_to_0001.sql Implement migrations; fix #153 2015-05-31 17:36:15 +02:00
servatrice_0001_to_0002.sql Refactor servatrice email send 2015-07-25 18:48:34 +02:00
servatrice_0002_to_0003.sql Add database migration script for client id 2015-08-09 08:47:21 -04:00
servatrice_0003_to_0004.sql Add clientid field to sessions table. 2015-08-11 12:45:04 -04:00
servatrice_0004_to_0005.sql Add ability to ban by client id 2015-08-14 00:06:37 -04:00
servatrice_0005_to_0006.sql Add last_login column to user table and populate upon login 2015-08-15 03:00:34 -04:00
servatrice_0006_to_0007.sql Define permission levels for rooms 2015-08-15 21:00:51 -04:00
servatrice_0007_to_0008.sql Added user analytics table to database 2015-09-08 14:56:10 -04:00
servatrice_0008_to_0009.sql Added chat history to a room that is displayed on join. 2015-09-14 17:54:04 -04:00
servatrice_0009_to_0010.sql Added official warning messages moderators can use to inform users 2015-09-22 22:27:46 -04:00
servatrice_0010_to_0011.sql Updated cockatrice_warnings table to use id column as primary key 2015-09-25 07:35:23 -04:00
servatrice_0011_to_0012.sql Updating schema version to 12 and adding migration script. 2015-11-08 03:05:12 -08:00
servatrice_0012_to_0013.sql Move schema to Innodb and add FKs 2016-02-17 21:24:28 +01:00
servatrice_0013_to_0014.sql Implementation of websockets in servatrice and test js client 2016-06-26 19:38:53 +02:00
servatrice_0014_to_0015.sql Update servatrice to respect server id when doing room information lookups 2016-07-21 09:09:06 -04:00
servatrice_0015_to_0016.sql Update maint script files 2016-07-21 10:38:46 -04:00
servatrice_0016_to_0017.sql fix #2118 (#2119) 2016-08-02 21:58:56 -04:00
servatrice_0017_to_0018.sql Added user privilege level (#2228) 2016-10-26 02:07:42 -04:00
servatrice_0018_to_0019.sql Update sessions table columns for consistency (#2299) 2016-12-08 10:43:11 +01:00
servatrice_0019_to_0020.sql Added privilege level start/end columns (#2328) 2016-12-30 16:45:28 -08:00
servatrice_0020_to_0021.sql Simpler forgot password functionality (#2393) 2017-02-15 17:41:40 -05:00
servatrice_0021_to_0022.sql Server audit table (#2423) 2017-02-25 13:48:31 -05:00
servatrice_0022_to_0023.sql Smarter rooms (#2484) 2017-03-22 21:45:16 -04:00
servatrice_0023_to_0024.sql Even out db collation to utfmb4_unicode_ci; fix #2835 ; fix #2218 (#2915) 2018-01-13 04:02:22 -05:00
servatrice_0024_to_0025.sql log moderation stats in the uptime table (#3215) 2018-05-02 17:31:54 -04:00
servatrice_0025_to_0026.sql ensure column ordering is consistent (#3249) 2018-05-18 18:07:39 -04:00
servatrice_0026_to_0027.sql Issue 3015 - store timestamp when password is reset (#3863) 2019-11-22 23:52:45 -05:00
servatrice_0027_to_0028.sql deprecate the gender property from the protocol entirely (#4496) 2021-12-14 01:51:57 -05:00
servatrice_0028_to_0029.sql add database migration from blob to mediumblob (#4568) 2022-02-09 20:11:13 +01:00
servatrice_0029_to_0030.sql Support Mod/Admin Notes Section (#5361) 2024-12-28 18:05:49 +00:00
servatrice_0030_to_0031.sql Improve Database Backup Speed (#5400) 2025-01-01 00:28:57 -05:00
servatrice_0031_to_0032.sql Support more indices (#5503) 2025-01-20 01:42:24 -05:00
servatrice_0032_to_0033.sql Support more indices (#5505) 2025-01-25 04:16:41 +00:00
servatrice_0033_to_0034.sql Add custom server-side pawn colors (#5543) 2025-02-02 03:25:25 +00:00
servatrice_0034_to_0035.sql [UserListDelegate] Consider providerId (#7018) 2026-06-27 11:23:55 -04:00
servatrice_0035_to_0036.sql [Server/Client/Protocol] Reporting users + moderation queue functionality (#7091) 2026-08-21 15:00:13 +02:00