mirror of
https://github.com/Cockatrice/Cockatrice.git
synced 2026-09-29 17:32:17 -07:00
Security: - Promote RESET_USER_PASSWORD to admin-only dispatch (was moderator-accessible) - Reject password reset on users with equal/higher privilege than caller - Notify affected user via Event_NotifyUser::CUSTOM when password is reset - Add server-side category whitelist for reports - Drop reporter name fallback in comment/details authorization (ID-only) - Force password change: new DB column + login enforcement + client disconnect Bugs: - XSS via QTextEdit::append() → insertPlainText() in report tab and utils - allNotified initialized to true even with empty recipients list - Warning combo box: use currentData() instead of baked-in display text - Report resolution now records who resolved (resolved_by column + audit) Performance: - IP-correlation subquery: add 6-month window + LIMIT 200 - getUserSessions: clamp limit to 500 Non-blocking: - Palette-aware colors in report_utils.cpp (dark/light mode) - Report list pagination: offset/limit fields + total_count in response - SessionCommand enum gap comment for reserved values 1201-1203 Schema: 36→37 (force_password_change), 37→38 (resolved_by) Took 12 minutes Took 16 seconds
47 lines
1.1 KiB
Protocol Buffer
47 lines
1.1 KiB
Protocol Buffer
syntax = "proto2";
|
|
message AdminCommand {
|
|
enum AdminCommandType {
|
|
UPDATE_SERVER_MESSAGE = 1000;
|
|
SHUTDOWN_SERVER = 1001;
|
|
RELOAD_CONFIG = 1002;
|
|
ADJUST_MOD = 1003;
|
|
RESET_USER_PASSWORD = 1016;
|
|
}
|
|
extensions 100 to max;
|
|
}
|
|
|
|
message Command_UpdateServerMessage {
|
|
extend AdminCommand {
|
|
optional Command_UpdateServerMessage ext = 1000;
|
|
}
|
|
}
|
|
|
|
message Command_ShutdownServer {
|
|
extend AdminCommand {
|
|
optional Command_ShutdownServer ext = 1001;
|
|
}
|
|
optional string reason = 1;
|
|
optional uint32 minutes = 2;
|
|
}
|
|
|
|
message Command_ReloadConfig {
|
|
extend AdminCommand {
|
|
optional Command_ReloadConfig ext = 1002;
|
|
}
|
|
}
|
|
|
|
message Command_AdjustMod {
|
|
extend AdminCommand {
|
|
optional Command_AdjustMod ext = 1003;
|
|
}
|
|
required string user_name = 1;
|
|
optional bool should_be_mod = 2;
|
|
optional bool should_be_judge = 3;
|
|
}
|
|
|
|
message Command_ResetUserPassword {
|
|
extend AdminCommand {
|
|
optional Command_ResetUserPassword ext = 1016;
|
|
}
|
|
optional string user_name = 1;
|
|
}
|