fix: resolve all remaining audit failures across rust, svelte, and java

This commit is contained in:
scoped committed 2026-09-29 15:51:15 -04:00
1 parent bc12a25a01
commit 590178e41a
35 files changed
+958 -300

No files matched your search

+27 -27
View File
@@ -626,11 +626,14 @@ pub async fn create_guild(
pub async fn get_guild_claims(
state: State<'_, AppState>,
instance_id: String,
server_id: i64,
dimension: Option<String>,
center_x: i32,
center_z: i32,
) -> Res<Vec<GuildClaim>> {
let panel = state.panel_url().ok_or("no panel configured")?;
let dim = dimension.unwrap_or_else(|| "minecraft:overworld".into());
let resp = state.http.get(format!("{panel}/api/v1/guilds/claims/grid?instance_id={instance_id}&dimension={dim}"))
let resp = state.http.get(format!("{panel}/api/v1/guilds/claims/grid?instance_id={instance_id}&server_id={server_id}&dimension={dim}&center_x={center_x}&center_z={center_z}"))
.send().await.map_err(err)?;
if !resp.status().is_success() {
return Err("unable to load claims".into());
@@ -643,6 +646,7 @@ pub async fn claim_guild_chunk(
state: State<'_, AppState>,
guild_id: String,
instance_id: String,
server_id: i64,
dimension: String,
chunk_x: i32,
chunk_z: i32,
@@ -650,6 +654,7 @@ pub async fn claim_guild_chunk(
let req = account_api(&state, reqwest::Method::POST, &format!("/guilds/{guild_id}/claim")).await?;
let resp = req.json(&serde_json::json!({
"instance_id": instance_id,
"server_id": server_id,
"dimension": dimension,
"chunk_x": chunk_x,
"chunk_z": chunk_z,
@@ -662,25 +667,9 @@ pub async fn claim_guild_chunk(
}
#[tauri::command]
pub async fn unclaim_guild_chunk(
state: State<'_, AppState>,
guild_id: String,
instance_id: String,
dimension: String,
chunk_x: i32,
chunk_z: i32,
) -> Res<()> {
let req = account_api(&state, reqwest::Method::POST, &format!("/guilds/{guild_id}/unclaim")).await?;
let resp = req.json(&serde_json::json!({
"instance_id": instance_id,
"dimension": dimension,
"chunk_x": chunk_x,
"chunk_z": chunk_z,
})).send().await.map_err(err)?;
if !resp.status().is_success() {
let body: serde_json::Value = resp.json().await.unwrap_or_default();
return Err(body["error"].as_str().unwrap_or("unable to unclaim chunk").to_string());
}
pub async fn unclaim_guild_chunk(state: State<'_, AppState>, claim_id: i64) -> Res<()> {
let req = account_api(&state, reqwest::Method::DELETE, &format!("/guilds/claims/{claim_id}")).await?;
req.send().await.map_err(err)?.error_for_status().map_err(err)?;
Ok(())
}
@@ -827,8 +816,18 @@ pub async fn get_transactions(state: State<'_, AppState>) -> Res<Vec<EconomyTran
}
#[tauri::command]
pub async fn get_direct_messages(state: State<'_, AppState>, friend_uuid: String) -> Res<Vec<DirectMessage>> {
let req = account_api(&state, reqwest::Method::GET, &format!("/messages/{friend_uuid}")).await?;
pub async fn get_direct_messages(
state: State<'_, AppState>,
friend_uuid: String,
before_id: Option<i64>,
) -> Res<Vec<DirectMessage>> {
// FIX #13: Support optional before_id for loading older messages beyond the first 100.
let path = if let Some(before) = before_id {
format!("/messages/{friend_uuid}?before_id={before}")
} else {
format!("/messages/{friend_uuid}")
};
let req = account_api(&state, reqwest::Method::GET, &path).await?;
let resp = req.send().await.map_err(err)?;
if !resp.status().is_success() {
return Err("unable to load messages".into());
@@ -863,7 +862,7 @@ pub async fn send_game_invite(
recipient_uuid: String,
instance_id: String,
server_id: Option<i64>,
) -> Res<GameInvite> {
) -> Res<()> {
let req = account_api(&state, reqwest::Method::POST, "/invites").await?;
let resp = req.json(&serde_json::json!({
"recipient_uuid": recipient_uuid,
@@ -874,13 +873,13 @@ pub async fn send_game_invite(
let body: serde_json::Value = resp.json().await.unwrap_or_default();
return Err(body["error"].as_str().unwrap_or("unable to send invite").to_string());
}
resp.json().await.map_err(err)
Ok(())
}
#[tauri::command]
pub async fn respond_game_invite(state: State<'_, AppState>, invite_id: String, accept: bool) -> Res<()> {
let req = account_api(&state, reqwest::Method::POST, &format!("/invites/{invite_id}/respond")).await?;
let resp = req.json(&serde_json::json!({ "accept": accept })).send().await.map_err(err)?;
let resp = req.json(&serde_json::json!({ "action": if accept { "accept" } else { "decline" } })).send().await.map_err(err)?;
if !resp.status().is_success() {
let body: serde_json::Value = resp.json().await.unwrap_or_default();
return Err(body["error"].as_str().unwrap_or("unable to respond to invite").to_string());
@@ -917,7 +916,8 @@ pub async fn update_my_profile(
let body: serde_json::Value = resp.json().await.unwrap_or_default();
return Err(body["error"].as_str().unwrap_or("unable to update profile").to_string());
}
resp.json().await.map_err(err)
let uuid = state.accounts.read().unwrap().active().ok_or("no active account")?.uuid.clone();
get_user_profile(state, uuid).await
}
#[tauri::command]
@@ -937,7 +937,7 @@ pub async fn create_user_post(
content: String,
image_url: Option<String>,
) -> Res<UserPost> {
let req = account_api(&state, reqwest::Method::POST, "/posts").await?;
let req = account_api(&state, reqwest::Method::POST, "/profiles/me/posts").await?;
let resp = req.json(&serde_json::json!({
"content": content,
"image_url": image_url,