mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-08 13:53:45 +00:00
Bearer keys (dlk_...) are checked per request against their owner's current account (ban, lock, demotion, sign out everywhere stop or narrow them at once) and their scope: permission routes need the permission in scope, read-only keys only read, level-only routes need an all-permission key, and session-only paths (sign-in, password, 2FA, key management) are never reachable with a key. Per-key rate limit and daily quota with 429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in batches every minute. WebSocket subscriptions honour the scope too. Routes to list, make, rotate and revoke keys; staff with api_keys_manage can see and revoke others' keys under the rank rules. POST /api/auth/token now makes an all-permission key. Audit entries for create/rotate/revoke/denied, and actions done with a key are attributed to "user (key name)". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
82 lines
2.7 KiB
CMake
82 lines
2.7 KiB
CMake
set(DWEBTESTS_SOURCES
|
|
"MiddlewareTests.cpp"
|
|
"RouteIntegrationTests.cpp"
|
|
"ServerStateTests.cpp"
|
|
"AccountActionTests.cpp"
|
|
"RouteUtilsTests.cpp"
|
|
"JWTTests.cpp"
|
|
"RequireAuthMiddlewareTests.cpp"
|
|
"WebTestDependencies.cpp"
|
|
"PlayerActionTests.cpp"
|
|
"SmtpTests.cpp"
|
|
"OAuth2Tests.cpp"
|
|
"EconomyReportTests.cpp"
|
|
"ItemTraceTests.cpp"
|
|
"CronTests.cpp"
|
|
"PermissionsTests.cpp"
|
|
"ApiKeyTests.cpp"
|
|
"SettingsCatalogTests.cpp"
|
|
"BehaviorXmlTests.cpp"
|
|
"CharacterXmlTests.cpp"
|
|
"CharacterXmlCheckTests.cpp"
|
|
"CharacterRestoreTests.cpp"
|
|
"ZonePathsTests.cpp"
|
|
"RawTerrainTests.cpp"
|
|
"LevelObjectsTests.cpp"
|
|
"GameLabelsTests.cpp"
|
|
"VanityJsonTests.cpp"
|
|
"OpenApiTests.cpp"
|
|
"MessageInspectorTests.cpp"
|
|
"CDClientSchemaTests.cpp"
|
|
"ServerOperationsTests.cpp"
|
|
"PublicPagesTests.cpp"
|
|
"ModerationToolsTests.cpp"
|
|
"ModeratorHelperTests.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/ai/ClaudeClient.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/ai/ModeratorPrompt.cpp"
|
|
"WorldViewTests.cpp"
|
|
"NifFileTests.cpp"
|
|
"DeferredReplyTests.cpp"
|
|
"WorkerPoolTests.cpp"
|
|
"OnceCacheTests.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/routes/WorkerPool.cpp"
|
|
"BackupFilesTests.cpp"
|
|
"SecurityFixesTests.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/routes/BackupFiles.cpp"
|
|
"MetricsFormatTests.cpp"
|
|
"TrafficHistoryTests.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/routes/TrafficHistory.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/routes/SettingsCatalog.cpp"
|
|
"AlertsAndTwoFactorTests.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/auth/Totp.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/notify/WebhookFormat.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/email/OAuth2.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/email/SmtpClient.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/auth/JWTUtils.cpp"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/auth/RequireAuthMiddleware.cpp"
|
|
)
|
|
|
|
add_executable(dWebTests ${DWEBTESTS_SOURCES})
|
|
|
|
target_include_directories(dWebTests PRIVATE
|
|
"${PROJECT_SOURCE_DIR}/dCommon"
|
|
"${PROJECT_SOURCE_DIR}/dCommon/dClient"
|
|
"${PROJECT_SOURCE_DIR}/dWeb"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/auth"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/routes"
|
|
"${PROJECT_SOURCE_DIR}/dChatFilter"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/email"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/notify"
|
|
"${PROJECT_SOURCE_DIR}/dDashboardServer/ai"
|
|
"${PROJECT_SOURCE_DIR}/dDatabase/GameDatabase/ITables"
|
|
"${PROJECT_SOURCE_DIR}/dNet"
|
|
"${PROJECT_SOURCE_DIR}/thirdparty/nlohmann"
|
|
)
|
|
|
|
target_link_libraries(dWebTests ${COMMON_LIBRARIES} dWeb sqlite3 OpenSSL::Crypto CURL::libcurl GTest::gtest_main)
|
|
|
|
gtest_discover_tests(dWebTests)
|
|
|
|
target_compile_definitions(dWebTests PRIVATE DLU_SOURCE_DIR="${PROJECT_SOURCE_DIR}")
|