fix: resolve all remaining audit failures across rust, svelte, and java
This commit is contained in:
1 parent
bc12a25a01
commit
590178e41a
35 files changed
+958
-300
No files matched your search
@@ -220,7 +220,7 @@ async fn fetch_guild_detail(state: &AppState, guild_id: &str) -> AppResult<Guild
|
||||
|
||||
// Claims
|
||||
let claim_rows: Vec<(i64, String, i64, String, i32, i32, String, String)> = sqlx::query_as(
|
||||
"SELECT id, guild_id, server_id, dimension, chunk_x, chunk_z, claimed_by_uuid, claimed_at
|
||||
"SELECT id, guild_id, COALESCE(server_id, 0), dimension, chunk_x, chunk_z, claimed_by_uuid, claimed_at
|
||||
FROM guild_claims
|
||||
WHERE guild_id = ?
|
||||
LIMIT 200",
|
||||
@@ -279,6 +279,14 @@ pub async fn get_guild_by_id(
|
||||
fetch_guild_detail(&state, &id).await.map(Json)
|
||||
}
|
||||
|
||||
pub async fn get_guild_members(Path(id): Path<String>, State(state): State<AppState>) -> AppResult<Json<Vec<GuildMember>>> {
|
||||
Ok(Json(fetch_guild_detail(&state, &id).await?.members))
|
||||
}
|
||||
|
||||
pub async fn get_guild_posts(Path(id): Path<String>, State(state): State<AppState>) -> AppResult<Json<Vec<GuildPost>>> {
|
||||
Ok(Json(fetch_guild_detail(&state, &id).await?.posts))
|
||||
}
|
||||
|
||||
#[derive(Deserialize)]
|
||||
pub struct CreateGuildPayload {
|
||||
pub instance_id: String,
|
||||
@@ -366,6 +374,7 @@ pub async fn create_guild(
|
||||
.execute(&mut *tx)
|
||||
.await?;
|
||||
|
||||
crate::routes::leveling::grant_rewards(&mut tx, &auth.uuid, &now).await?;
|
||||
tx.commit().await?;
|
||||
|
||||
fetch_guild_detail(&state, &guild_id).await.map(Json)
|
||||
@@ -549,13 +558,14 @@ pub async fn create_guild_post(
|
||||
.bind(&id)
|
||||
.bind(&auth.uuid)
|
||||
.bind(&auth.username)
|
||||
.bind(payload.title)
|
||||
.bind(payload.content)
|
||||
.bind(&payload.title)
|
||||
.bind(&payload.content)
|
||||
.bind(&now)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
|
||||
Ok(Json(serde_json::json!({ "id": post_id, "ok": true })))
|
||||
Ok(Json(serde_json::json!({ "id": post_id, "guild_id": id, "author_uuid": auth.uuid,
|
||||
"author_name": auth.username, "title": payload.title, "content": payload.content, "created_at": now })))
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
@@ -604,29 +614,28 @@ pub async fn claim_chunk(
|
||||
return Err(AppError::bad_request(format!("Guild reached its max claim limit of {max_claims} chunks")));
|
||||
}
|
||||
|
||||
let server_id = payload.server_id.ok_or_else(|| AppError::bad_request("Select a game server for this claim"))?;
|
||||
let matches: bool = sqlx::query_scalar("SELECT EXISTS(SELECT 1 FROM game_servers s JOIN guilds g ON g.instance_id = s.instance_id WHERE s.id = ? AND g.id = ?)")
|
||||
.bind(server_id).bind(&guild_id).fetch_one(&state.db).await?;
|
||||
if !matches { return Err(AppError::bad_request("Server is not linked to this guild's instance")); }
|
||||
let dim = payload.dimension.unwrap_or_else(|| "minecraft:overworld".into());
|
||||
let now = chrono::Utc::now().to_rfc3339();
|
||||
|
||||
let res = sqlx::query(
|
||||
let res = sqlx::query_scalar::<_, i64>(
|
||||
"INSERT INTO guild_claims (guild_id, server_id, dimension, chunk_x, chunk_z, claimed_by_uuid, claimed_at)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?)",
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?) RETURNING id",
|
||||
)
|
||||
.bind(&guild_id)
|
||||
.bind(payload.server_id)
|
||||
.bind(server_id)
|
||||
.bind(&dim)
|
||||
.bind(payload.chunk_x)
|
||||
.bind(payload.chunk_z)
|
||||
.bind(&auth.uuid)
|
||||
.bind(&now)
|
||||
.execute(&state.db)
|
||||
.fetch_one(&state.db)
|
||||
.await;
|
||||
|
||||
if let Err(e) = res {
|
||||
tracing::warn!("claim chunk failed: {e}");
|
||||
return Err(AppError::bad_request("Chunk is already claimed by another guild"));
|
||||
}
|
||||
|
||||
let claim_id: i64 = sqlx::query_scalar("SELECT last_insert_rowid()").fetch_one(&state.db).await.unwrap_or(1);
|
||||
let claim_id = res.map_err(|_| AppError::bad_request("Chunk is already claimed"))?;
|
||||
|
||||
// Award achievement for claiming land
|
||||
sqlx::query(
|
||||
@@ -638,7 +647,8 @@ pub async fn claim_chunk(
|
||||
.execute(&state.db)
|
||||
.await?;
|
||||
|
||||
Ok(Json(serde_json::json!({ "ok": true, "id": claim_id, "chunk_x": payload.chunk_x, "chunk_z": payload.chunk_z })))
|
||||
let detail = fetch_guild_detail(&state, &guild_id).await?;
|
||||
Ok(Json(serde_json::to_value(detail.claims.into_iter().find(|c| c.id == claim_id).ok_or_else(|| AppError::not_found("Claim not found"))?)?))
|
||||
}
|
||||
|
||||
/// Unclaim a chunk by coordinates.
|
||||
@@ -951,9 +961,10 @@ pub async fn server_claim_chunk(
|
||||
Json(payload): Json<ServerClaimChunkPayload>,
|
||||
) -> AppResult<Json<Value>> {
|
||||
let member: Option<(String, String)> = sqlx::query_as(
|
||||
"SELECT guild_id, role FROM guild_members WHERE uuid = ?",
|
||||
"SELECT gm.guild_id, gm.role FROM guild_members gm JOIN guilds g ON g.id = gm.guild_id WHERE gm.uuid = ? AND g.instance_id = ?",
|
||||
)
|
||||
.bind(&payload.uuid)
|
||||
.bind(&server.instance_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
|
||||
@@ -1036,6 +1047,7 @@ pub async fn server_unclaim_chunk(
|
||||
)
|
||||
.bind(&guild_id)
|
||||
.bind(&payload.uuid)
|
||||
.bind(&server.instance_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
|
||||
@@ -1057,14 +1069,15 @@ pub struct ServerGuildPlayerQuery {
|
||||
}
|
||||
|
||||
pub async fn server_get_player_guild(
|
||||
GameServer(_server): GameServer,
|
||||
GameServer(server): GameServer,
|
||||
State(state): State<AppState>,
|
||||
Json(payload): Json<ServerGuildPlayerQuery>,
|
||||
) -> AppResult<Json<Value>> {
|
||||
let member_opt: Option<(String, String)> = sqlx::query_as(
|
||||
"SELECT guild_id, role FROM guild_members WHERE uuid = ?",
|
||||
"SELECT gm.guild_id, gm.role FROM guild_members gm JOIN guilds g ON g.id = gm.guild_id WHERE gm.uuid = ? AND g.instance_id = ?",
|
||||
)
|
||||
.bind(&payload.uuid)
|
||||
.bind(&server.instance_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
|
||||
@@ -1129,7 +1142,7 @@ pub struct ServerCreateGuildPayload {
|
||||
}
|
||||
|
||||
pub async fn server_create_guild(
|
||||
GameServer(_server): GameServer,
|
||||
GameServer(server): GameServer,
|
||||
State(state): State<AppState>,
|
||||
Json(payload): Json<ServerCreateGuildPayload>,
|
||||
) -> AppResult<Json<Value>> {
|
||||
@@ -1142,8 +1155,9 @@ pub async fn server_create_guild(
|
||||
return Err(AppError::bad_request("Guild tag must be between 2 and 6 characters"));
|
||||
}
|
||||
|
||||
let in_guild: bool = sqlx::query_scalar("SELECT EXISTS(SELECT 1 FROM guild_members WHERE uuid = ?)")
|
||||
let in_guild: bool = sqlx::query_scalar("SELECT EXISTS(SELECT 1 FROM guild_members gm JOIN guilds g ON g.id = gm.guild_id WHERE gm.uuid = ? AND g.instance_id = ?)")
|
||||
.bind(&payload.uuid)
|
||||
.bind(&server.instance_id)
|
||||
.fetch_one(&state.db)
|
||||
.await?;
|
||||
|
||||
@@ -1158,9 +1172,10 @@ pub async fn server_create_guild(
|
||||
|
||||
let res = sqlx::query(
|
||||
"INSERT INTO guilds (id, instance_id, name, tag, description, motd, leader_uuid, created_at)
|
||||
VALUES (?, '', ?, ?, '', 'Welcome to the guild!', ?, ?)",
|
||||
VALUES (?, ?, ?, ?, '', 'Welcome to the guild!', ?, ?)",
|
||||
)
|
||||
.bind(&guild_id)
|
||||
.bind(&server.instance_id)
|
||||
.bind(name)
|
||||
.bind(tag)
|
||||
.bind(&payload.uuid)
|
||||
@@ -1200,14 +1215,15 @@ pub struct ServerGuildLeavePayload {
|
||||
}
|
||||
|
||||
pub async fn server_guild_leave(
|
||||
GameServer(_server): GameServer,
|
||||
GameServer(server): GameServer,
|
||||
State(state): State<AppState>,
|
||||
Json(payload): Json<ServerGuildLeavePayload>,
|
||||
) -> AppResult<Json<Value>> {
|
||||
let member_opt: Option<(String, String)> = sqlx::query_as(
|
||||
"SELECT guild_id, role FROM guild_members WHERE uuid = ?",
|
||||
"SELECT gm.guild_id, gm.role FROM guild_members gm JOIN guilds g ON g.id = gm.guild_id WHERE gm.uuid = ? AND g.instance_id = ?",
|
||||
)
|
||||
.bind(&payload.uuid)
|
||||
.bind(&server.instance_id)
|
||||
.fetch_optional(&state.db)
|
||||
.await?;
|
||||
|
||||
|
||||
Reference in new issue
Block a user