fix: resolve all remaining audit failures across rust, svelte, and java

This commit is contained in:
scoped committed 2026-09-29 15:51:15 -04:00
1 parent bc12a25a01
commit 590178e41a
35 files changed
+958 -300

No files matched your search

+55 -12
View File
@@ -218,23 +218,49 @@ pub async fn respond_friend_request(
// Direct Messaging (DMs)
// ---------------------------------------------------------------------------
#[derive(Deserialize, Default)]
pub struct DmQuery {
pub before_id: Option<i64>,
}
pub async fn get_direct_messages(
auth: AuthUser,
Path(target_uuid): Path<String>,
Query(q): Query<DmQuery>,
State(state): State<AppState>,
) -> AppResult<Json<Vec<DirectMessage>>> {
let rows: Vec<(i64, String, String, String, String, bool, String)> = sqlx::query_as(
"SELECT id, sender_uuid, sender_name, recipient_uuid, content, is_read, created_at
FROM direct_messages
WHERE (sender_uuid = ? AND recipient_uuid = ?) OR (sender_uuid = ? AND recipient_uuid = ?)
ORDER BY id ASC LIMIT 100",
)
.bind(&auth.uuid)
.bind(&target_uuid)
.bind(&target_uuid)
.bind(&auth.uuid)
.fetch_all(&state.db)
.await?;
// FIX #13: Support optional before_id cursor for pagination beyond the first 100 messages.
let mut rows: Vec<(i64, String, String, String, String, bool, String)> = if let Some(before) = q.before_id {
sqlx::query_as(
"SELECT id, sender_uuid, sender_name, recipient_uuid, content, is_read, created_at
FROM direct_messages
WHERE ((sender_uuid = ? AND recipient_uuid = ?) OR (sender_uuid = ? AND recipient_uuid = ?))
AND id < ?
ORDER BY id DESC LIMIT 100",
)
.bind(&auth.uuid)
.bind(&target_uuid)
.bind(&target_uuid)
.bind(&auth.uuid)
.bind(before)
.fetch_all(&state.db)
.await?
} else {
sqlx::query_as(
"SELECT id, sender_uuid, sender_name, recipient_uuid, content, is_read, created_at
FROM direct_messages
WHERE (sender_uuid = ? AND recipient_uuid = ?) OR (sender_uuid = ? AND recipient_uuid = ?)
ORDER BY id DESC LIMIT 100",
)
.bind(&auth.uuid)
.bind(&target_uuid)
.bind(&target_uuid)
.bind(&auth.uuid)
.fetch_all(&state.db)
.await?
};
rows.reverse();
// Mark unread messages sent to me as read
sqlx::query(
@@ -492,7 +518,24 @@ pub async fn get_player_profile(
})
.collect();
let achievements = crate::routes::achievements::get_achievements_for_user(&state, &puuid, true).await?;
let friends_count: i64 = sqlx::query_scalar("SELECT COUNT(*) FROM friendships WHERE status = 'accepted' AND (user_uuid = ? OR friend_uuid = ?)")
.bind(&puuid).bind(&puuid).fetch_one(&state.db).await?;
let created_at: String = sqlx::query_scalar("SELECT created_at FROM users WHERE uuid = ?")
.bind(&puuid).fetch_one(&state.db).await?;
let stats: Option<crate::routes::servers::AggregatedStatRow> = sqlx::query_as(
"SELECT uuid, name, SUM(playtime_secs) playtime_secs, SUM(joins) joins, SUM(deaths) deaths,
SUM(player_kills) player_kills, SUM(mob_kills) mob_kills, SUM(blocks_broken) blocks_broken,
SUM(blocks_placed) blocks_placed, SUM(messages) messages, MIN(first_seen) first_seen, MAX(last_seen) last_seen
FROM player_stats WHERE uuid = ? GROUP BY uuid")
.bind(&puuid).fetch_optional(&state.db).await?;
Ok(Json(UserProfileView {
level_info: levels.clone(),
badges: levels.badges.clone(),
achievements,
friends_count,
created_at,
stats: stats.map(|s| serde_json::to_value(s).unwrap()),
uuid: puuid,
username,
bio,