make em private

This commit is contained in:
Your Name 2026-08-21 09:37:19 -04:00
parent 1394ce1e0c
commit 02cdca748d
4 changed files with 123 additions and 37 deletions

View file

@ -320,7 +320,12 @@ wsRouter.ws("*", (ws, req) => {
}
const { route } = found;
if (!model.canAccessStructure(req.session && req.session.userId, route.structure_id)) {
if (
!model.canAccessStructure(
req.session && req.session.userId,
route.structure_id,
)
) {
return ws.close(1008, "WebSocket route not found");
}
req.params = found.params;
@ -382,7 +387,11 @@ buildRoutes();
// crafted ?next= can't bounce someone to another origin (open redirect). A
// leading `//` is protocol-relative and would escape our origin, so reject it.
function safeNext(next) {
if (typeof next !== "string" || !next.startsWith("/") || next.startsWith("//")) {
if (
typeof next !== "string" ||
!next.startsWith("/") ||
next.startsWith("//")
) {
return null;
}
return next;
@ -1000,14 +1009,18 @@ app.put("/workshop/:structure_id/settings", (req, res) => {
routePrefix = routePrefix.substring(0, routePrefix.length - 1);
}
// An unchecked checkbox sends no field at all, so absence means "public".
// An unchecked checkbox sends no field at all, so absence means "off".
const wantPrivate = req.body.private === "on" || req.body.private === "1";
const wantPublic = req.body.public === "on" || req.body.public === "1";
if (wantPrivate && !req.session.userId) {
return res
.status(403)
.send("log in before making a structure private, or you'll lock everyone out");
.send(
"log in before making a structure private, or you'll lock everyone out",
);
}
model.setStructurePrivacy(structId, wantPrivate, req.session.userId);
model.setStructurePublic(structId, wantPublic);
model.updateStruct({
...struct,
@ -1093,9 +1106,13 @@ app.all("*", async (req, res) => {
// logged-in non-members still 404.
if (!model.canAccessStructure(req.session.userId, route.structure_id)) {
if (!req.session.userId && verb === "GET") {
return res.redirect("/login?next=" + encodeURIComponent(req.originalUrl));
return res.redirect(
"/login?next=" + encodeURIComponent(req.originalUrl),
);
}
return res.status(404).json({ success: false, message: "Path not found" });
return res
.status(404)
.json({ success: false, message: "Path not found" });
}
// Minimal, handcrafted view of the logged-in Bliss user for user routes.