Compare commits

...

2 Commits

Author SHA1 Message Date
opencode f851305d78 fix(tools): OR'ed where clauses now AND'd so search excludes soft-deleted tools; localize delete confirm dialog
Build & Push Docker Image / build (push) Successful in 2m25s
2026-08-03 08:48:08 +02:00
opencode 743b177c89 fix(auth): password min length 6 + show/hide toggle on password inputs
Build & Push Docker Image / build (push) Successful in 2m21s
2026-08-03 08:01:52 +02:00
15 changed files with 74 additions and 40 deletions
+1 -1
View File
@@ -293,7 +293,7 @@ router.get("/auth/password-redirect", async (req, res): Promise<void> => {
const ChangePasswordSchema = z.object({ const ChangePasswordSchema = z.object({
currentPassword: z.string().min(1), currentPassword: z.string().min(1),
newPassword: z.string().min(8), newPassword: z.string().min(6),
}); });
router.post("/auth/me/password", passwordRateLimit, async (req, res): Promise<void> => { router.post("/auth/me/password", passwordRateLimit, async (req, res): Promise<void> => {
+8 -6
View File
@@ -1,5 +1,5 @@
import { Router, type IRouter } from "express"; import { Router, type IRouter } from "express";
import { eq, desc, asc, sql, and, not, isNull, inArray } from "drizzle-orm"; import { eq, desc, asc, sql, and, not, isNull, inArray, type SQL } from "drizzle-orm";
import { z } from "zod"; import { z } from "zod";
import { db, toolsTable, ratingsTable, toolRelationsTable } from "@workspace/db"; import { db, toolsTable, ratingsTable, toolRelationsTable } from "@workspace/db";
import { import {
@@ -57,21 +57,23 @@ router.get("/tools", async (req, res): Promise<void> => {
const tagList = (tags ?? "").split(",").map((t) => t.trim()).filter(Boolean); const tagList = (tags ?? "").split(",").map((t) => t.trim()).filter(Boolean);
const featureList = (features ?? "").split(",").map((f) => f.trim()).filter(Boolean); const featureList = (features ?? "").split(",").map((f) => f.trim()).filter(Boolean);
let query = db.select().from(toolsTable).where(isNull(toolsTable.deletedAt)).$dynamic(); const conditions: SQL[] = [isNull(toolsTable.deletedAt)];
if (category) { if (category) {
query = query.where(eq(toolsTable.category, category)); conditions.push(eq(toolsTable.category, category));
} }
if (search) { if (search) {
const escaped = search.replace(/[%_\\]/g, (m) => `\\${m}`); const escaped = search.replace(/[%_\\]/g, (m) => `\\${m}`);
query = query.where(sql`${toolsTable.name} ilike ${`%${escaped}%`} escape '\\'`); conditions.push(sql`${toolsTable.name} ilike ${`%${escaped}%`} escape '\\'`);
} }
if (tagList.length > 0) { if (tagList.length > 0) {
query = query.where(sql`${toolsTable.tags} @> ARRAY[${sql.join(tagList.map((t) => sql`${t}`), sql`, `)}]::text[]`); conditions.push(sql`${toolsTable.tags} @> ARRAY[${sql.join(tagList.map((t) => sql`${t}`), sql`, `)}]::text[]`);
} }
if (featureList.length > 0) { if (featureList.length > 0) {
query = query.where(sql`${toolsTable.features} @> ARRAY[${sql.join(featureList.map((f) => sql`${f}`), sql`, `)}]::text[]`); conditions.push(sql`${toolsTable.features} @> ARRAY[${sql.join(featureList.map((f) => sql`${f}`), sql`, `)}]::text[]`);
} }
const query = db.select().from(toolsTable).where(and(...conditions));
const tools = await query.orderBy(desc(toolsTable.createdAt)); const tools = await query.orderBy(desc(toolsTable.createdAt));
const toolIds = tools.map((t) => t.id); const toolIds = tools.map((t) => t.id);
+1 -1
View File
@@ -25,7 +25,7 @@ const UserUpdateSchema = z.object({
}); });
const SetPasswordSchema = z.object({ const SetPasswordSchema = z.object({
password: z.string().min(8), password: z.string().min(6),
}); });
router.patch("/users/:id/password", requireAdmin, passwordRateLimit, async (req, res): Promise<void> => { router.patch("/users/:id/password", requireAdmin, passwordRateLimit, async (req, res): Promise<void> => {
@@ -0,0 +1,25 @@
import { useState } from "react";
import { Eye, EyeOff } from "lucide-react";
import { Input } from "@/components/ui/input";
import { cn } from "@/lib/utils";
export function PasswordInput({
className,
...props
}: Omit<React.ComponentProps<"input">, "type">) {
const [visible, setVisible] = useState(false);
return (
<div className={cn("relative", className)}>
<Input type={visible ? "text" : "password"} className="pr-9" {...props} />
<button
type="button"
onClick={() => setVisible((v) => !v)}
className="absolute right-0 top-0 flex h-9 w-9 items-center justify-center text-muted-foreground hover:text-foreground"
aria-label={visible ? "Hide password" : "Show password"}
tabIndex={-1}
>
{visible ? <EyeOff className="w-4 h-4" /> : <Eye className="w-4 h-4" />}
</button>
</div>
);
}
@@ -15,8 +15,8 @@ import {
DropdownMenuTrigger, DropdownMenuTrigger,
} from "@/components/ui/dropdown-menu"; } from "@/components/ui/dropdown-menu";
import { Dialog, DialogContent, DialogHeader, DialogTitle, DialogFooter } from "@/components/ui/dialog"; import { Dialog, DialogContent, DialogHeader, DialogTitle, DialogFooter } from "@/components/ui/dialog";
import { Input } from "@/components/ui/input";
import { Label } from "@/components/ui/label"; import { Label } from "@/components/ui/label";
import { PasswordInput } from "@/components/password-input";
import { useToast } from "@/hooks/use-toast"; import { useToast } from "@/hooks/use-toast";
import { useChangeMyPassword, useGetPasswordRedirect, getGetPasswordRedirectQueryKey } from "@workspace/api-client-react"; import { useChangeMyPassword, useGetPasswordRedirect, getGetPasswordRedirectQueryKey } from "@workspace/api-client-react";
import { useQueryClient } from "@tanstack/react-query"; import { useQueryClient } from "@tanstack/react-query";
@@ -182,8 +182,7 @@ export function UserMenu() {
<div className="space-y-4 py-2"> <div className="space-y-4 py-2">
<div className="space-y-2"> <div className="space-y-2">
<Label>{t("auth.currentPassword")}</Label> <Label>{t("auth.currentPassword")}</Label>
<Input <PasswordInput
type="password"
value={currentPassword} value={currentPassword}
onChange={(e) => setCurrentPassword(e.target.value)} onChange={(e) => setCurrentPassword(e.target.value)}
data-testid="input-current-password" data-testid="input-current-password"
@@ -191,18 +190,16 @@ export function UserMenu() {
</div> </div>
<div className="space-y-2"> <div className="space-y-2">
<Label>{t("auth.newPassword")}</Label> <Label>{t("auth.newPassword")}</Label>
<Input <PasswordInput
type="password"
value={newPassword} value={newPassword}
onChange={(e) => setNewPassword(e.target.value)} onChange={(e) => setNewPassword(e.target.value)}
placeholder="min. 8 characters" placeholder="min. 6 characters"
data-testid="input-new-password" data-testid="input-new-password"
/> />
</div> </div>
<div className="space-y-2"> <div className="space-y-2">
<Label>{t("auth.confirmPassword")}</Label> <Label>{t("auth.confirmPassword")}</Label>
<Input <PasswordInput
type="password"
value={confirmPassword} value={confirmPassword}
onChange={(e) => setConfirmPassword(e.target.value)} onChange={(e) => setConfirmPassword(e.target.value)}
data-testid="input-confirm-password" data-testid="input-confirm-password"
@@ -219,7 +216,7 @@ export function UserMenu() {
toast({ title: t("auth.pwMismatch"), variant: "destructive" }); toast({ title: t("auth.pwMismatch"), variant: "destructive" });
return; return;
} }
if (newPassword.length < 8) { if (newPassword.length < 6) {
toast({ title: t("auth.pwTooShort"), variant: "destructive" }); toast({ title: t("auth.pwTooShort"), variant: "destructive" });
return; return;
} }
+6 -1
View File
@@ -127,7 +127,12 @@
"relatedTools": "Ähnliche Tools", "relatedTools": "Ähnliche Tools",
"costs": "Kosten", "costs": "Kosten",
"addCost": "Kosten hinzufügen", "addCost": "Kosten hinzufügen",
"recentRatings": "Letzte Bewertungen" "recentRatings": "Letzte Bewertungen",
"deleteConfirmTitle": "Dieses Tool löschen?",
"deleteToTrash": "Dies verschiebt {{name}} in den Papierkorb. Es kann später wiederhergestellt werden.",
"deletePermanent": "Dies entfernt {{name}} dauerhaft inklusive aller Bewertungen. Das kann nicht rückgängig gemacht werden.",
"deleting": "Löschen…",
"deleteAction": "Löschen"
}, },
"compare": { "compare": {
"title": "Tools vergleichen", "title": "Tools vergleichen",
+6 -1
View File
@@ -127,7 +127,12 @@
"relatedTools": "Related Tools", "relatedTools": "Related Tools",
"costs": "Costs", "costs": "Costs",
"addCost": "Add Cost", "addCost": "Add Cost",
"recentRatings": "Recent Ratings" "recentRatings": "Recent Ratings",
"deleteConfirmTitle": "Delete this tool?",
"deleteToTrash": "This will move {{name}} to the trash. It can be restored later.",
"deletePermanent": "This will permanently remove {{name}} and all its ratings. This cannot be undone.",
"deleting": "Deleting…",
"deleteAction": "Delete"
}, },
"compare": { "compare": {
"title": "Compare Tools", "title": "Compare Tools",
+6 -6
View File
@@ -17,6 +17,7 @@ import { useAuth } from "@/hooks/use-auth";
import { Layout } from "@/components/layout"; import { Layout } from "@/components/layout";
import { Button } from "@/components/ui/button"; import { Button } from "@/components/ui/button";
import { Input } from "@/components/ui/input"; import { Input } from "@/components/ui/input";
import { PasswordInput } from "@/components/password-input";
import { Label } from "@/components/ui/label"; import { Label } from "@/components/ui/label";
import { Badge } from "@/components/ui/badge"; import { Badge } from "@/components/ui/badge";
import { Card, CardContent, CardHeader, CardTitle, CardDescription } from "@/components/ui/card"; import { Card, CardContent, CardHeader, CardTitle, CardDescription } from "@/components/ui/card";
@@ -115,8 +116,8 @@ export default function Admin() {
const handleSetUserPassword = () => { const handleSetUserPassword = () => {
if (!editUser || !editPassword) return; if (!editUser || !editPassword) return;
if (editPassword.length < 8) { if (editPassword.length < 6) {
toast({ title: "Password too short", description: "Minimum 8 characters.", variant: "destructive" }); toast({ title: "Password too short", description: "Minimum 6 characters.", variant: "destructive" });
return; return;
} }
setUserPassword.mutate( setUserPassword.mutate(
@@ -367,7 +368,7 @@ export default function Admin() {
</div> </div>
<div className="space-y-2"> <div className="space-y-2">
<Label>Password</Label> <Label>Password</Label>
<Input type="password" value={newPassword} onChange={(e) => setNewPassword(e.target.value)} placeholder="min. 6 characters" /> <PasswordInput value={newPassword} onChange={(e) => setNewPassword(e.target.value)} placeholder="min. 6 characters" />
</div> </div>
<div className="space-y-2"> <div className="space-y-2">
<Label>Email (Optional)</Label> <Label>Email (Optional)</Label>
@@ -448,11 +449,10 @@ export default function Admin() {
{editUser?.authProvider !== "oidc" ? ( {editUser?.authProvider !== "oidc" ? (
<div className="space-y-2 border-t pt-4"> <div className="space-y-2 border-t pt-4">
<Label>Set Password</Label> <Label>Set Password</Label>
<Input <PasswordInput
type="password"
value={editPassword} value={editPassword}
onChange={(e) => setEditPassword(e.target.value)} onChange={(e) => setEditPassword(e.target.value)}
placeholder="min. 8 characters" placeholder="min. 6 characters"
data-testid="input-set-password" data-testid="input-set-password"
/> />
<p className="text-xs text-muted-foreground">Resets the user's password immediately.</p> <p className="text-xs text-muted-foreground">Resets the user's password immediately.</p>
+2 -2
View File
@@ -5,6 +5,7 @@ import { useQueryClient } from "@tanstack/react-query";
import { Button } from "@/components/ui/button"; import { Button } from "@/components/ui/button";
import { Input } from "@/components/ui/input"; import { Input } from "@/components/ui/input";
import { Label } from "@/components/ui/label"; import { Label } from "@/components/ui/label";
import { PasswordInput } from "@/components/password-input";
import { Card, CardContent, CardHeader, CardTitle, CardDescription } from "@/components/ui/card"; import { Card, CardContent, CardHeader, CardTitle, CardDescription } from "@/components/ui/card";
import { ThemeToggle } from "@/components/theme-toggle"; import { ThemeToggle } from "@/components/theme-toggle";
import { Wrench, AlertCircle } from "lucide-react"; import { Wrench, AlertCircle } from "lucide-react";
@@ -76,9 +77,8 @@ export default function Login() {
</div> </div>
<div className="space-y-2"> <div className="space-y-2">
<Label htmlFor="password">{t("auth.password")}</Label> <Label htmlFor="password">{t("auth.password")}</Label>
<Input <PasswordInput
id="password" id="password"
type="password"
value={password} value={password}
onChange={(e) => setPassword(e.target.value)} onChange={(e) => setPassword(e.target.value)}
required required
+5 -5
View File
@@ -914,23 +914,23 @@ export default function ToolDetail() {
<AlertDialog open={deleteOpen} onOpenChange={setDeleteOpen}> <AlertDialog open={deleteOpen} onOpenChange={setDeleteOpen}>
<AlertDialogContent> <AlertDialogContent>
<AlertDialogHeader> <AlertDialogHeader>
<AlertDialogTitle>Delete this tool?</AlertDialogTitle> <AlertDialogTitle>{t("detail.deleteConfirmTitle")}</AlertDialogTitle>
<AlertDialogDescription> <AlertDialogDescription>
{hasTrash ? ( {hasTrash ? (
<>This will move <span className="font-medium">{tool?.name}</span> to the trash. It can be restored later.</> <>{t("detail.deleteToTrash", { name: tool?.name })}</>
) : ( ) : (
<>This will permanently remove <span className="font-medium">{tool?.name}</span> and all its ratings. This cannot be undone.</> <>{t("detail.deletePermanent", { name: tool?.name })}</>
)} )}
</AlertDialogDescription> </AlertDialogDescription>
</AlertDialogHeader> </AlertDialogHeader>
<AlertDialogFooter> <AlertDialogFooter>
<AlertDialogCancel>Cancel</AlertDialogCancel> <AlertDialogCancel>{t("common.cancel")}</AlertDialogCancel>
<AlertDialogAction <AlertDialogAction
className="bg-destructive text-destructive-foreground hover:bg-destructive/90" className="bg-destructive text-destructive-foreground hover:bg-destructive/90"
onClick={handleDelete} onClick={handleDelete}
disabled={deleteTool.isPending} disabled={deleteTool.isPending}
> >
{deleteTool.isPending ? "Deleting" : "Delete"} {deleteTool.isPending ? t("detail.deleting") : t("detail.deleteAction")}
</AlertDialogAction> </AlertDialogAction>
</AlertDialogFooter> </AlertDialogFooter>
</AlertDialogContent> </AlertDialogContent>
@@ -123,12 +123,12 @@ export interface UserRoleUpdate {
export interface ChangePasswordInput { export interface ChangePasswordInput {
/** @minLength 1 */ /** @minLength 1 */
currentPassword: string; currentPassword: string;
/** @minLength 8 */ /** @minLength 6 */
newPassword: string; newPassword: string;
} }
export interface SetPasswordInput { export interface SetPasswordInput {
/** @minLength 8 */ /** @minLength 6 */
password: string; password: string;
} }
+2 -2
View File
@@ -1013,7 +1013,7 @@ components:
minLength: 1 minLength: 1
newPassword: newPassword:
type: string type: string
minLength: 8 minLength: 6
SetPasswordInput: SetPasswordInput:
type: object type: object
@@ -1021,7 +1021,7 @@ components:
properties: properties:
password: password:
type: string type: string
minLength: 8 minLength: 6
PasswordRedirect: PasswordRedirect:
type: object type: object
+2 -2
View File
@@ -484,7 +484,7 @@ export const GetMeResponse = zod.object({
* @summary Change own password (local users only) * @summary Change own password (local users only)
*/ */
export const changeMyPasswordBodyNewPasswordMin = 8; export const changeMyPasswordBodyNewPasswordMin = 6;
@@ -626,7 +626,7 @@ export const SetUserPasswordParams = zod.object({
"id": zod.coerce.number() "id": zod.coerce.number()
}) })
export const setUserPasswordBodyPasswordMin = 8; export const setUserPasswordBodyPasswordMin = 6;
@@ -9,6 +9,6 @@
export interface ChangePasswordInput { export interface ChangePasswordInput {
/** @minLength 1 */ /** @minLength 1 */
currentPassword: string; currentPassword: string;
/** @minLength 8 */ /** @minLength 6 */
newPassword: string; newPassword: string;
} }
@@ -7,6 +7,6 @@
*/ */
export interface SetPasswordInput { export interface SetPasswordInput {
/** @minLength 8 */ /** @minLength 6 */
password: string; password: string;
} }