6 Commits
Author SHA1 Message Date
sbstp 3695fc68d6 meal categories
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-03 21:29:33 -04:00
sbstp cf6853d71e show/hide password button 2026-08-03 21:02:03 -04:00
sbstp fdbf40adac style updates 2026-08-03 14:58:10 -04:00
sbstp a6482ddb0e reset/update password
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline failed
ci/woodpecker/push/test Pipeline was successful
2026-08-03 11:33:24 -04:00
sbstp 3160a898be version 0.2.0 [skip ci]
ci/woodpecker/tag/release Pipeline was successful
2026-08-03 00:24:54 -04:00
sbstp 209363774c passwordless login + proper migrations
ci/woodpecker/push/e2e Pipeline was successful
ci/woodpecker/push/fmt Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
2026-08-03 00:23:10 -04:00
21 changed files with 1631 additions and 277 deletions
Generated
+440 -10
View File
@@ -139,6 +139,9 @@ name = "bitflags"
version = "2.13.1" version = "2.13.1"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da"
dependencies = [
"serde_core",
]
[[package]] [[package]]
name = "blake2" name = "blake2"
@@ -158,6 +161,12 @@ dependencies = [
"generic-array", "generic-array",
] ]
[[package]]
name = "byteorder"
version = "1.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1fd0f2584146f6f2ef48085050886acf353beff7305ebd1ae69500e27c67f64b"
[[package]] [[package]]
name = "bytes" name = "bytes"
version = "1.12.1" version = "1.12.1"
@@ -180,6 +189,12 @@ version = "1.0.4"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801" checksum = "9330f8b2ff13f34540b44e946ef35111825727b38d33286ef986142615121801"
[[package]]
name = "const-oid"
version = "0.9.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c2459377285ad874054d797f3ccebf984978aa39129f6eafde5cdc8315b612f8"
[[package]] [[package]]
name = "cpufeatures" name = "cpufeatures"
version = "0.2.17" version = "0.2.17"
@@ -235,6 +250,17 @@ version = "2.11.0"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a4ae5f15dda3c708c0ade84bfee31ccab44a3da4f88015ed22f63732abe300c8" checksum = "a4ae5f15dda3c708c0ade84bfee31ccab44a3da4f88015ed22f63732abe300c8"
[[package]]
name = "der"
version = "0.7.10"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e7c1832837b905bbfb5101e07cc24c8deddf52f93225eee6ead5f4d63d53ddcb"
dependencies = [
"const-oid",
"pem-rfc7468",
"zeroize",
]
[[package]] [[package]]
name = "digest" name = "digest"
version = "0.10.7" version = "0.10.7"
@@ -242,6 +268,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292" checksum = "9ed9a281f7bc9b7576e61468ba615a66a5c8cfdff42420a70aa82701a3b1e292"
dependencies = [ dependencies = [
"block-buffer", "block-buffer",
"const-oid",
"crypto-common", "crypto-common",
"subtle", "subtle",
] ]
@@ -288,6 +315,17 @@ dependencies = [
"windows-sys 0.61.2", "windows-sys 0.61.2",
] ]
[[package]]
name = "etcetera"
version = "0.8.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "136d1b5283a1ab77bd9257427ffd09d8667ced0570b6f938942bc7568ed5b943"
dependencies = [
"cfg-if",
"home",
"windows-sys 0.48.0",
]
[[package]] [[package]]
name = "event-listener" name = "event-listener"
version = "5.4.2" version = "5.4.2"
@@ -514,6 +552,33 @@ version = "0.4.3"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70" checksum = "7f24254aa9a54b5c858eaee2f5bccdb46aaf0e486a595ed5fd8f86ba55232a70"
[[package]]
name = "hkdf"
version = "0.12.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7b5f8eb2ad728638ea2c7d47a21db23b7b58a72ed6a38256b8a1849f15fbbdf7"
dependencies = [
"hmac",
]
[[package]]
name = "hmac"
version = "0.12.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6c49c37c09c17a53d937dfbb742eb3a961d65a994e6bcdcf37e7399d0cc8ab5e"
dependencies = [
"digest",
]
[[package]]
name = "home"
version = "0.5.12"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "cc627f471c528ff0c4a49e1d5e60450c8f6461dd6d10ba9dcd3a61d3dff7728d"
dependencies = [
"windows-sys 0.61.2",
]
[[package]] [[package]]
name = "http" name = "http"
version = "1.5.0" version = "1.5.0"
@@ -724,6 +789,9 @@ name = "lazy_static"
version = "1.5.0" version = "1.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe" checksum = "bbd2bcb4c963f2ddae06a2efc7e9f3591312473c50c6685e1f298068316e66fe"
dependencies = [
"spin",
]
[[package]] [[package]]
name = "libc" name = "libc"
@@ -731,6 +799,24 @@ version = "0.2.189"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2" checksum = "3eaf3ede3fee6db1a4c2ee091bf8a8b4dccdc6d17f656fb07896ee72867612f2"
[[package]]
name = "libm"
version = "0.2.16"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b6d2cec3eae94f9f509c767b45932f1ada8350c4bdb85af2fcab4a3c14807981"
[[package]]
name = "libredox"
version = "0.1.18"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c943259e342f1e06ff2da7a83eabdfe7f92ce10262688dbf1895ff0b3e6e4652"
dependencies = [
"bitflags",
"libc",
"plain",
"redox_syscall 0.9.1",
]
[[package]] [[package]]
name = "libsqlite3-sys" name = "libsqlite3-sys"
version = "0.30.1" version = "0.30.1"
@@ -800,6 +886,16 @@ dependencies = [
"syn 2.0.119", "syn 2.0.119",
] ]
[[package]]
name = "md-5"
version = "0.10.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d89e7ee0cfbedfc4da3340218492196241d89eefb6dab27de5df917a6d2e78cf"
dependencies = [
"cfg-if",
"digest",
]
[[package]] [[package]]
name = "memchr" name = "memchr"
version = "2.8.3" version = "2.8.3"
@@ -858,6 +954,41 @@ dependencies = [
"windows-sys 0.61.2", "windows-sys 0.61.2",
] ]
[[package]]
name = "num-bigint-dig"
version = "0.8.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e661dda6640fad38e827a6d4a310ff4763082116fe217f279885c97f511bb0b7"
dependencies = [
"lazy_static",
"libm",
"num-integer",
"num-iter",
"num-traits",
"rand 0.8.7",
"smallvec",
"zeroize",
]
[[package]]
name = "num-integer"
version = "0.1.46"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7969661fd2958a5cb096e56c8e1ad0444ac2bbcd0061bd28660485a44879858f"
dependencies = [
"num-traits",
]
[[package]]
name = "num-iter"
version = "0.1.46"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c92800bd69a1eac91786bcfe9da64a897eb72911b8dc3095decbd07429e8048b"
dependencies = [
"num-integer",
"num-traits",
]
[[package]] [[package]]
name = "num-traits" name = "num-traits"
version = "0.2.19" version = "0.2.19"
@@ -865,6 +996,7 @@ source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841" checksum = "071dfc062690e90b734c0b2273ce72ad0ffa95f0c74596bc250dcfd960262841"
dependencies = [ dependencies = [
"autocfg", "autocfg",
"libm",
] ]
[[package]] [[package]]
@@ -934,7 +1066,7 @@ checksum = "2621685985a2ebf1c516881c026032ac7deafcda1a2c9b7850dc81e3dfcb64c1"
dependencies = [ dependencies = [
"cfg-if", "cfg-if",
"libc", "libc",
"redox_syscall", "redox_syscall 0.5.18",
"smallvec", "smallvec",
"windows-link", "windows-link",
] ]
@@ -950,6 +1082,15 @@ dependencies = [
"subtle", "subtle",
] ]
[[package]]
name = "pem-rfc7468"
version = "0.7.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "88b39c9bfcfc231068454382784bb460aae594343fb030d46e9f50a645418412"
dependencies = [
"base64ct",
]
[[package]] [[package]]
name = "percent-encoding" name = "percent-encoding"
version = "2.3.2" version = "2.3.2"
@@ -962,12 +1103,39 @@ version = "0.2.17"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd" checksum = "a89322df9ebe1c1578d689c92318e070967d1042b512afbe49518723f4e6d5cd"
[[package]]
name = "pkcs1"
version = "0.7.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c8ffb9f10fa047879315e6625af03c164b16962a5368d724ed16323b68ace47f"
dependencies = [
"der",
"pkcs8",
"spki",
]
[[package]]
name = "pkcs8"
version = "0.10.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f950b2377845cebe5cf8b5165cb3cc1a5e0fa5cfa3e1f7f55707d8fd82e0a7b7"
dependencies = [
"der",
"spki",
]
[[package]] [[package]]
name = "pkg-config" name = "pkg-config"
version = "0.3.33" version = "0.3.33"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "19f132c84eca552bf34cab8ec81f1c1dcc229b811638f9d283dceabe58c5569e" checksum = "19f132c84eca552bf34cab8ec81f1c1dcc229b811638f9d283dceabe58c5569e"
[[package]]
name = "plain"
version = "0.2.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b4596b6d070b27117e987119b4dac604f3c58cfb0b191112e24771b2faeac1a6"
[[package]] [[package]]
name = "potential_utf" name = "potential_utf"
version = "0.1.5" version = "0.1.5"
@@ -1109,6 +1277,15 @@ dependencies = [
"bitflags", "bitflags",
] ]
[[package]]
name = "redox_syscall"
version = "0.9.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "07507be7b4a5f9f26eeb41eeaebb1f5a7ff29dfb29739facc21d35bf8b11c21e"
dependencies = [
"bitflags",
]
[[package]] [[package]]
name = "regex-automata" name = "regex-automata"
version = "0.4.16" version = "0.4.16"
@@ -1140,6 +1317,26 @@ dependencies = [
"windows-sys 0.52.0", "windows-sys 0.52.0",
] ]
[[package]]
name = "rsa"
version = "0.9.10"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b8573f03f5883dcaebdfcf4725caa1ecb9c15b2ef50c43a07b816e06799bb12d"
dependencies = [
"const-oid",
"digest",
"num-bigint-dig",
"num-integer",
"num-traits",
"pkcs1",
"pkcs8",
"rand_core 0.6.4",
"signature",
"spki",
"subtle",
"zeroize",
]
[[package]] [[package]]
name = "rustls" name = "rustls"
version = "0.23.43" version = "0.23.43"
@@ -1309,6 +1506,16 @@ dependencies = [
"libc", "libc",
] ]
[[package]]
name = "signature"
version = "2.2.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "77549399552de45a898a580c1b41d445bf730df867cc44e6c0233bbc4b8329de"
dependencies = [
"digest",
"rand_core 0.6.4",
]
[[package]] [[package]]
name = "slab" name = "slab"
version = "0.4.12" version = "0.4.12"
@@ -1320,6 +1527,9 @@ name = "smallvec"
version = "1.15.2" version = "1.15.2"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90" checksum = "8ed6a63f02c8539c91a8685a86f4099661ba3da017932f6ebbea6de3f0fa7c90"
dependencies = [
"serde",
]
[[package]] [[package]]
name = "socket2" name = "socket2"
@@ -1340,6 +1550,16 @@ dependencies = [
"lock_api", "lock_api",
] ]
[[package]]
name = "spki"
version = "0.7.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d91ed6c858b01f942cd56b37a94b3e0a1798290327d1236e4d9cf4eaca44d29d"
dependencies = [
"base64ct",
"der",
]
[[package]] [[package]]
name = "sqlx" name = "sqlx"
version = "0.8.6" version = "0.8.6"
@@ -1348,6 +1568,8 @@ checksum = "1fefb893899429669dcdd979aff487bd78f4064e5e7907e4269081e0ef7d97dc"
dependencies = [ dependencies = [
"sqlx-core", "sqlx-core",
"sqlx-macros", "sqlx-macros",
"sqlx-mysql",
"sqlx-postgres",
"sqlx-sqlite", "sqlx-sqlite",
] ]
@@ -1376,6 +1598,7 @@ dependencies = [
"percent-encoding", "percent-encoding",
"rustls", "rustls",
"serde", "serde",
"serde_json",
"sha2", "sha2",
"smallvec", "smallvec",
"thiserror 2.0.19", "thiserror 2.0.19",
@@ -1422,6 +1645,84 @@ dependencies = [
"url", "url",
] ]
[[package]]
name = "sqlx-mysql"
version = "0.8.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "aa003f0038df784eb8fecbbac13affe3da23b45194bd57dba231c8f48199c526"
dependencies = [
"atoi",
"base64 0.22.1",
"bitflags",
"byteorder",
"bytes",
"crc",
"digest",
"dotenvy",
"either",
"futures-channel",
"futures-core",
"futures-io",
"futures-util",
"generic-array",
"hex",
"hkdf",
"hmac",
"itoa",
"log",
"md-5",
"memchr",
"once_cell",
"percent-encoding",
"rand 0.8.7",
"rsa",
"sha1",
"sha2",
"smallvec",
"sqlx-core",
"stringprep",
"thiserror 2.0.19",
"tracing",
"whoami",
]
[[package]]
name = "sqlx-postgres"
version = "0.8.6"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "db58fcd5a53cf07c184b154801ff91347e4c30d17a3562a635ff028ad5deda46"
dependencies = [
"atoi",
"base64 0.22.1",
"bitflags",
"byteorder",
"crc",
"dotenvy",
"etcetera",
"futures-channel",
"futures-core",
"futures-util",
"hex",
"hkdf",
"hmac",
"home",
"itoa",
"log",
"md-5",
"memchr",
"once_cell",
"rand 0.8.7",
"serde",
"serde_json",
"sha2",
"smallvec",
"sqlx-core",
"stringprep",
"thiserror 2.0.19",
"tracing",
"whoami",
]
[[package]] [[package]]
name = "sqlx-sqlite" name = "sqlx-sqlite"
version = "0.8.6" version = "0.8.6"
@@ -1452,6 +1753,17 @@ version = "1.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596" checksum = "6ce2be8dc25455e1f91df71bfa12ad37d7af1092ae736f3a6cd0e37bc7810596"
[[package]]
name = "stringprep"
version = "0.1.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7b4df3d392d81bd458a8a621b8bffbd2302a12ffe288a9d931670948749463b1"
dependencies = [
"unicode-bidi",
"unicode-normalization",
"unicode-properties",
]
[[package]] [[package]]
name = "subtle" name = "subtle"
version = "2.6.1" version = "2.6.1"
@@ -1460,7 +1772,7 @@ checksum = "13c2bddecc57b384dee18652358fb23172facb8a2c51ccc10d74c157bdea3292"
[[package]] [[package]]
name = "sustenance" name = "sustenance"
version = "0.1.2" version = "0.2.0"
dependencies = [ dependencies = [
"argon2", "argon2",
"async-trait", "async-trait",
@@ -1583,6 +1895,21 @@ dependencies = [
"zerovec", "zerovec",
] ]
[[package]]
name = "tinyvec"
version = "1.12.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "bb4ebadaa0af04fab11ae01eb5f9fdb5f9c5b875506e210e71c07873528baa7f"
dependencies = [
"tinyvec_macros",
]
[[package]]
name = "tinyvec_macros"
version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "1f3ccbac311fea05f86f61904b462b55fb3df8837a366dfc601a0161d0532f20"
[[package]] [[package]]
name = "tokio" name = "tokio"
version = "1.53.1" version = "1.53.1"
@@ -1791,12 +2118,33 @@ version = "2.9.0"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "dbc4bc3a9f746d862c45cb89d705aa10f187bb96c76001afab07a0d35ce60142" checksum = "dbc4bc3a9f746d862c45cb89d705aa10f187bb96c76001afab07a0d35ce60142"
[[package]]
name = "unicode-bidi"
version = "0.3.18"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5c1cb5db39152898a79168971543b1cb5020dff7fe43c8dc468b0885f5e29df5"
[[package]] [[package]]
name = "unicode-ident" name = "unicode-ident"
version = "1.0.24" version = "1.0.24"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75" checksum = "e6e4313cd5fcd3dad5cafa179702e2b244f760991f45397d14d4ebf38247da75"
[[package]]
name = "unicode-normalization"
version = "0.1.25"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5fd4f6878c9cb28d874b009da9e8d183b5abc80117c40bbd187a1fde336be6e8"
dependencies = [
"tinyvec",
]
[[package]]
name = "unicode-properties"
version = "0.1.4"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7df058c713841ad818f1dc5d3fd88063241cc61f49f5fbea4b951e8cf5a8d71d"
[[package]] [[package]]
name = "unicode-width" name = "unicode-width"
version = "0.2.2" version = "0.2.2"
@@ -1861,6 +2209,12 @@ dependencies = [
"wit-bindgen", "wit-bindgen",
] ]
[[package]]
name = "wasite"
version = "0.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b8dad83b4f25e74f184f64c43b150b91efe7647395b42289f38e50566d82855b"
[[package]] [[package]]
name = "webauthn-rs" name = "webauthn-rs"
version = "0.3.2" version = "0.3.2"
@@ -1898,19 +2252,38 @@ dependencies = [
"rustls-pki-types", "rustls-pki-types",
] ]
[[package]]
name = "whoami"
version = "1.6.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "5d4a4db5077702ca3015d3d02d74974948aba2ad9e12ab7df718ee64ccd7e97d"
dependencies = [
"libredox",
"wasite",
]
[[package]] [[package]]
name = "windows-link" name = "windows-link"
version = "0.2.1" version = "0.2.1"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5" checksum = "f0805222e57f7521d6a62e36fa9163bc891acd422f971defe97d64e70d0a4fe5"
[[package]]
name = "windows-sys"
version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "677d2418bec65e3338edb076e806bc1ec15693c5d0104683f2efe857f61056a9"
dependencies = [
"windows-targets 0.48.5",
]
[[package]] [[package]]
name = "windows-sys" name = "windows-sys"
version = "0.52.0" version = "0.52.0"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d" checksum = "282be5f36a8ce781fad8c8ae18fa3f9beff57ec1b52cb3de0789201425d9a33d"
dependencies = [ dependencies = [
"windows-targets", "windows-targets 0.52.6",
] ]
[[package]] [[package]]
@@ -1922,34 +2295,67 @@ dependencies = [
"windows-link", "windows-link",
] ]
[[package]]
name = "windows-targets"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9a2fa6e2155d7247be68c096456083145c183cbbbc2764150dda45a87197940c"
dependencies = [
"windows_aarch64_gnullvm 0.48.5",
"windows_aarch64_msvc 0.48.5",
"windows_i686_gnu 0.48.5",
"windows_i686_msvc 0.48.5",
"windows_x86_64_gnu 0.48.5",
"windows_x86_64_gnullvm 0.48.5",
"windows_x86_64_msvc 0.48.5",
]
[[package]] [[package]]
name = "windows-targets" name = "windows-targets"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973" checksum = "9b724f72796e036ab90c1021d4780d4d3d648aca59e491e6b98e725b84e99973"
dependencies = [ dependencies = [
"windows_aarch64_gnullvm", "windows_aarch64_gnullvm 0.52.6",
"windows_aarch64_msvc", "windows_aarch64_msvc 0.52.6",
"windows_i686_gnu", "windows_i686_gnu 0.52.6",
"windows_i686_gnullvm", "windows_i686_gnullvm",
"windows_i686_msvc", "windows_i686_msvc 0.52.6",
"windows_x86_64_gnu", "windows_x86_64_gnu 0.52.6",
"windows_x86_64_gnullvm", "windows_x86_64_gnullvm 0.52.6",
"windows_x86_64_msvc", "windows_x86_64_msvc 0.52.6",
] ]
[[package]]
name = "windows_aarch64_gnullvm"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2b38e32f0abccf9987a4e3079dfb67dcd799fb61361e53e2882c3cbaf0d905d8"
[[package]] [[package]]
name = "windows_aarch64_gnullvm" name = "windows_aarch64_gnullvm"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3" checksum = "32a4622180e7a0ec044bb555404c800bc9fd9ec262ec147edd5989ccd0c02cd3"
[[package]]
name = "windows_aarch64_msvc"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "dc35310971f3b2dbbf3f0690a219f40e2d9afcf64f9ab7cc1be722937c26b4bc"
[[package]] [[package]]
name = "windows_aarch64_msvc" name = "windows_aarch64_msvc"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469" checksum = "09ec2a7bb152e2252b53fa7803150007879548bc709c039df7627cabbd05d469"
[[package]]
name = "windows_i686_gnu"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "a75915e7def60c94dcef72200b9a8e58e5091744960da64ec734a6c6e9b3743e"
[[package]] [[package]]
name = "windows_i686_gnu" name = "windows_i686_gnu"
version = "0.52.6" version = "0.52.6"
@@ -1962,24 +2368,48 @@ version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66" checksum = "0eee52d38c090b3caa76c563b86c3a4bd71ef1a819287c19d586d7334ae8ed66"
[[package]]
name = "windows_i686_msvc"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8f55c233f70c4b27f66c523580f78f1004e8b5a8b659e05a4eb49d4166cca406"
[[package]] [[package]]
name = "windows_i686_msvc" name = "windows_i686_msvc"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66" checksum = "240948bc05c5e7c6dabba28bf89d89ffce3e303022809e73deaefe4f6ec56c66"
[[package]]
name = "windows_x86_64_gnu"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "53d40abd2583d23e4718fddf1ebec84dbff8381c07cae67ff7768bbf19c6718e"
[[package]] [[package]]
name = "windows_x86_64_gnu" name = "windows_x86_64_gnu"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78" checksum = "147a5c80aabfbf0c7d901cb5895d1de30ef2907eb21fbbab29ca94c5b08b1a78"
[[package]]
name = "windows_x86_64_gnullvm"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0b7b52767868a23d5bab768e390dc5f5c55825b6d30b86c844ff2dc7414044cc"
[[package]] [[package]]
name = "windows_x86_64_gnullvm" name = "windows_x86_64_gnullvm"
version = "0.52.6" version = "0.52.6"
source = "registry+https://github.com/rust-lang/crates.io-index" source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d" checksum = "24d5b23dc417412679681396f2b49f3de8c1473deb516bd34410872eff51ed0d"
[[package]]
name = "windows_x86_64_msvc"
version = "0.48.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ed94fce61571a4006852b7389a063ab983c02eb1bb37b47f8272ce92d06d9538"
[[package]] [[package]]
name = "windows_x86_64_msvc" name = "windows_x86_64_msvc"
version = "0.52.6" version = "0.52.6"
+2 -2
View File
@@ -1,6 +1,6 @@
[package] [package]
name = "sustenance" name = "sustenance"
version = "0.1.2" version = "0.2.0"
edition = "2024" edition = "2024"
[dependencies] [dependencies]
@@ -16,7 +16,7 @@ rand = "0.8"
serde = { version = "1", features = ["derive"] } serde = { version = "1", features = ["derive"] }
serde_json = "1" serde_json = "1"
sha2 = "0.10" sha2 = "0.10"
sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio", "sqlite", "macros", "tls-rustls"] } sqlx = { version = "0.8", default-features = false, features = ["runtime-tokio", "sqlite", "macros", "migrate", "tls-rustls"] }
thiserror = "2" thiserror = "2"
tokio = { version = "1", features = ["full"] } tokio = { version = "1", features = ["full"] }
tower = "0.5" tower = "0.5"
+9 -1
View File
@@ -11,9 +11,17 @@ export async function registerAndLogin(page: Page, email: string) {
} }
/** Creates a meal with the given name and markdown description. */ /** Creates a meal with the given name and markdown description. */
export async function createMeal(page: Page, name: string, description: string) { export async function createMeal(
page: Page,
name: string,
description: string,
category?: string,
) {
await page.goto("/meals/new"); await page.goto("/meals/new");
await page.fill("#meal-name", name); await page.fill("#meal-name", name);
if (category) {
await page.selectOption("#meal-category", { label: category });
}
await page.fill("#meal-description", description); await page.fill("#meal-description", description);
await page.click('button:has-text("Save meal")'); await page.click('button:has-text("Save meal")');
await expect(page).toHaveURL(/\/meals\/\d+/); await expect(page).toHaveURL(/\/meals\/\d+/);
+30
View File
@@ -13,3 +13,33 @@ test("a user can log out", async ({ page }) => {
await expect(page).toHaveURL(/\/login/); await expect(page).toHaveURL(/\/login/);
await expect(page.locator("h1")).toContainText("Welcome back"); await expect(page.locator("h1")).toContainText("Welcome back");
}); });
test("a user can change their password", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/account");
await page.fill("#new-password", "a-new-strong-password");
await page.fill("#confirm-password", "a-new-strong-password");
await page.click('button:has-text("Update password")');
await expect(page.locator(".alert-success")).toContainText("updated");
// The old password no longer works; the new one does.
await page.click('button:has-text("Sign out")');
await page.fill("#email", "alice@example.com");
await page.fill("#password", "a-strong-password");
await page.click('button[type="submit"]');
await expect(page.locator(".alert-error")).toContainText("incorrect");
await page.fill("#email", "alice@example.com");
await page.fill("#password", "a-new-strong-password");
await page.click('button[type="submit"]');
await expect(page).toHaveURL(/\/lists/);
});
test("changing password rejects a mismatched confirmation", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/account");
await page.fill("#new-password", "a-new-strong-password");
await page.fill("#confirm-password", "a-different-password");
await page.click('button:has-text("Update password")');
await expect(page.locator(".alert-error")).toContainText("do not match");
});
+111
View File
@@ -0,0 +1,111 @@
import { expect } from "@playwright/test";
import { test } from "../fixtures";
import { registerAndLogin, createMeal } from "../helpers";
test("meals are grouped under their category on the meals page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await createMeal(page, "Chicken Curry", "", "Chicken");
await createMeal(page, "Plain Rice", "");
await page.goto("/meals");
// Each category appears as a heading with its meals beneath it.
const beef = page.locator(".category-group").filter({ hasText: "Beef" });
await expect(beef.locator(".category-heading")).toContainText("Beef");
await expect(beef.locator(".list-card").filter({ hasText: "Beef Stew" })).toBeVisible();
const chicken = page.locator(".category-group").filter({ hasText: "Chicken" });
await expect(chicken.locator(".list-card").filter({ hasText: "Chicken Curry" })).toBeVisible();
// Uncategorized meals land in their own group.
const uncategorized = page.locator(".category-group").filter({ hasText: "Uncategorized" });
await expect(uncategorized.locator(".list-card").filter({ hasText: "Plain Rice" })).toBeVisible();
});
test("a user can create a meal category", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await page.goto("/meals");
await page.fill('form[action="/meals/categories"] input[name="name"]', "Breakfast");
await page.click('form[action="/meals/categories"] button[type="submit"]');
await expect(page).toHaveURL(/\/meals$/);
await expect(page.locator(".meal-category-name").filter({ hasText: "Breakfast" })).toBeVisible();
});
test("a user can delete a meal category and its meals become uncategorized", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
// Create a custom category and a meal in it.
await page.goto("/meals");
await page.fill('form[action="/meals/categories"] input[name="name"]', "Breakfast");
await page.click('form[action="/meals/categories"] button[type="submit"]');
await expect(page).toHaveURL(/\/meals$/);
await createMeal(page, "Pancakes", "", "Breakfast");
// Delete the category.
await page.goto("/meals");
const row = page.locator(".meal-category-row").filter({ hasText: "Breakfast" });
await row.locator(".meal-category-delete").click();
await expect(page).toHaveURL(/\/meals$/);
// The category is gone and the meal is now uncategorized.
await expect(page.locator(".meal-category-name").filter({ hasText: "Breakfast" })).toHaveCount(0);
const uncategorized = page.locator(".category-group").filter({ hasText: "Uncategorized" });
await expect(uncategorized.locator(".list-card").filter({ hasText: "Pancakes" })).toBeVisible();
});
test("a user can change a meal's category via the edit modal", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await page.click('button:has-text("Edit")');
const dialog = page.locator("dialog#meal-edit-modal");
await expect(dialog).toBeVisible();
await dialog.locator("#meal-edit-category").selectOption({ label: "Chicken" });
await dialog.locator("#meal-edit-save").click();
await expect(page).toHaveURL(/\/meals\/\d+/);
await page.goto("/meals");
const chicken = page.locator(".category-group").filter({
has: page.locator(".category-heading", { hasText: "Chicken" }),
});
await expect(chicken.locator(".list-card").filter({ hasText: "Beef Stew" })).toBeVisible();
const beef = page.locator(".category-group").filter({
has: page.locator(".category-heading", { hasText: "Beef" }),
});
await expect(beef.locator(".list-card").filter({ hasText: "Beef Stew" })).toHaveCount(0);
});
test("a meal's category is shown on its page", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await expect(page.locator(".meal-category-label")).toHaveText("(Beef)");
});
test("the add-meal picker groups meals by category", async ({ page }) => {
await registerAndLogin(page, "alice@example.com");
await createMeal(page, "Beef Stew", "", "Beef");
await createMeal(page, "Chicken Curry", "", "Chicken");
// Go to a list to open the picker.
await page.goto("/lists");
await page.fill("#list-name", "Weekly shop");
await page.click('button:has-text("Create list")');
await expect(page).toHaveURL(/\/lists\/\d+/);
await page.click(".add-meal-button");
const picker = page.locator(".meal-picker-backdrop");
await expect(picker).toBeVisible();
const beef = picker.locator(".category-group").filter({ hasText: "Beef" });
await expect(beef.locator(".meal-picker-button").filter({ hasText: "Beef Stew" })).toBeVisible();
const chicken = picker.locator(".category-group").filter({ hasText: "Chicken" });
await expect(chicken.locator(".meal-picker-button").filter({ hasText: "Chicken Curry" })).toBeVisible();
});
+1 -2
View File
@@ -38,8 +38,7 @@ test("a user can register a passkey and sign in with it", async ({ page, browser
await p.click('button:has-text("Sign out")'); await p.click('button:has-text("Sign out")');
await expect(p).toHaveURL(/\/login/); await expect(p).toHaveURL(/\/login/);
// Sign in with the passkey. // Sign in with the passkey without entering an email (userless sign-in).
await p.fill("#email", "alice@example.com");
await p.click("#passkey-login"); await p.click("#passkey-login");
await expect(p).toHaveURL(/\/lists/); await expect(p).toHaveURL(/\/lists/);
+81
View File
@@ -0,0 +1,81 @@
CREATE TABLE users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
email TEXT NOT NULL UNIQUE COLLATE NOCASE,
display_name TEXT NOT NULL,
password_hash TEXT NOT NULL,
user_handle BLOB NOT NULL UNIQUE,
created_at INTEGER NOT NULL
);
CREATE TABLE sessions (
token_hash BLOB PRIMARY KEY,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
csrf_token BLOB NOT NULL,
expires_at INTEGER NOT NULL
);
CREATE TABLE passkeys (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
credential_id TEXT NOT NULL UNIQUE,
credential TEXT NOT NULL,
counter INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE lists (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
revision INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL UNIQUE COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE invitations (
token_hash BLOB PRIMARY KEY,
created_by INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
expires_at INTEGER NOT NULL
);
CREATE TABLE items (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
checked INTEGER NOT NULL DEFAULT 0,
version INTEGER NOT NULL DEFAULT 1,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE meals (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
description TEXT NOT NULL DEFAULT '',
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE meal_ingredients (
id INTEGER PRIMARY KEY AUTOINCREMENT,
meal_id INTEGER NOT NULL REFERENCES meals(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
position INTEGER NOT NULL DEFAULT 0
);
CREATE INDEX items_list_idx ON items(list_id);
CREATE INDEX meal_ingredients_meal_idx ON meal_ingredients(meal_id);
CREATE INDEX sessions_user_idx ON sessions(user_id);
CREATE INDEX passkeys_user_idx ON passkeys(user_id);
@@ -0,0 +1,10 @@
CREATE TABLE meal_categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL UNIQUE COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
ALTER TABLE meals ADD COLUMN category_id INTEGER REFERENCES meal_categories(id) ON DELETE SET NULL;
CREATE INDEX meals_category_idx ON meals(category_id);
+11
View File
@@ -19,6 +19,10 @@ pub struct User {
pub id: i64, pub id: i64,
pub email: String, pub email: String,
pub display_name: String, pub display_name: String,
/// Opaque, random user handle used as the WebAuthn userHandle. Kept
/// high-entropy and unpredictable per the WebAuthn spec to avoid user
/// enumeration and cross-site correlation. Stored as raw bytes.
pub user_handle: Vec<u8>,
} }
#[derive(Clone, Debug)] #[derive(Clone, Debug)]
@@ -61,11 +65,18 @@ pub struct Category {
pub name: String, pub name: String,
} }
#[derive(Clone, Debug)]
pub struct MealCategory {
pub id: i64,
pub name: String,
}
#[derive(Clone, Debug)] #[derive(Clone, Debug)]
pub struct Meal { pub struct Meal {
pub id: i64, pub id: i64,
pub name: String, pub name: String,
pub description: String, pub description: String,
pub category_id: Option<i64>,
pub ingredients: Vec<MealIngredient>, pub ingredients: Vec<MealIngredient>,
} }
+122 -17
View File
@@ -30,6 +30,7 @@ use crate::webauthn::WebAuthnService;
const STYLE_CSS: &[u8] = include_bytes!("../static/style.css"); const STYLE_CSS: &[u8] = include_bytes!("../static/style.css");
const PASSKEY_LOGIN_JS: &[u8] = include_bytes!("../static/passkey-login.js"); const PASSKEY_LOGIN_JS: &[u8] = include_bytes!("../static/passkey-login.js");
const PASSKEY_REGISTER_JS: &[u8] = include_bytes!("../static/passkey-register.js"); const PASSKEY_REGISTER_JS: &[u8] = include_bytes!("../static/passkey-register.js");
const PASSWORD_TOGGLE_JS: &[u8] = include_bytes!("../static/password-toggle.js");
#[derive(Clone)] #[derive(Clone)]
pub struct AppState { pub struct AppState {
@@ -92,6 +93,7 @@ pub fn build_router(state: AppState) -> Router {
"/account/passkeys/{passkey_id}/delete", "/account/passkeys/{passkey_id}/delete",
post(delete_passkey), post(delete_passkey),
) )
.route("/account/password", post(change_password))
.route("/lists", get(lists_page).post(create_list)) .route("/lists", get(lists_page).post(create_list))
.route("/lists/{list_id}", get(list_page)) .route("/lists/{list_id}", get(list_page))
.route("/lists/{list_id}/items", post(add_item)) .route("/lists/{list_id}/items", post(add_item))
@@ -102,6 +104,8 @@ pub fn build_router(state: AppState) -> Router {
.route("/invitations", post(create_invitation)) .route("/invitations", post(create_invitation))
.route("/meals", get(meals_page).post(create_meal)) .route("/meals", get(meals_page).post(create_meal))
.route("/meals/new", get(new_meal_page)) .route("/meals/new", get(new_meal_page))
.route("/meals/categories", post(create_meal_category))
.route("/meals/categories/{category_id}/delete", post(delete_meal_category))
.route("/meals/{meal_id}", get(meal_page)) .route("/meals/{meal_id}", get(meal_page))
.route("/meals/{meal_id}/edit", post(edit_meal)) .route("/meals/{meal_id}/edit", post(edit_meal))
.route("/meals/{meal_id}/delete", post(delete_meal)) .route("/meals/{meal_id}/delete", post(delete_meal))
@@ -259,11 +263,13 @@ struct PasskeyRegisterFinishForm {
#[derive(Debug, Deserialize)] #[derive(Debug, Deserialize)]
struct PasskeyLoginStartForm { struct PasskeyLoginStartForm {
#[serde(default)]
email: String, email: String,
} }
#[derive(Debug, Deserialize)] #[derive(Debug, Deserialize)]
struct PasskeyLoginFinishForm { struct PasskeyLoginFinishForm {
token: String,
response: webauthn_rs::proto::PublicKeyCredential, response: webauthn_rs::proto::PublicKeyCredential,
} }
@@ -272,11 +278,20 @@ struct DeletePasskeyForm {
csrf: String, csrf: String,
} }
#[derive(Debug, Deserialize)]
struct ChangePasswordForm {
csrf: String,
new_password: String,
confirm_password: String,
}
#[derive(Debug, Deserialize)] #[derive(Debug, Deserialize)]
struct MealForm { struct MealForm {
name: String, name: String,
#[serde(default)] #[serde(default)]
description: String, description: String,
#[serde(default)]
category_id: Option<String>,
csrf: String, csrf: String,
} }
@@ -313,6 +328,7 @@ async fn static_asset(Path(path): Path<String>) -> Response {
"style.css" => ("text/css", STYLE_CSS), "style.css" => ("text/css", STYLE_CSS),
"passkey-login.js" => ("application/javascript", PASSKEY_LOGIN_JS), "passkey-login.js" => ("application/javascript", PASSKEY_LOGIN_JS),
"passkey-register.js" => ("application/javascript", PASSKEY_REGISTER_JS), "passkey-register.js" => ("application/javascript", PASSKEY_REGISTER_JS),
"password-toggle.js" => ("application/javascript", PASSWORD_TOGGLE_JS),
_ => return StatusCode::NOT_FOUND.into_response(), _ => return StatusCode::NOT_FOUND.into_response(),
}; };
([(header::CONTENT_TYPE, mime)], data).into_response() ([(header::CONTENT_TYPE, mime)], data).into_response()
@@ -446,9 +462,39 @@ async fn account_page(
&user.session.user, &user.session.user,
&passkeys, &passkeys,
&user.session.csrf_token, &user.session.csrf_token,
None,
false,
))) )))
} }
async fn change_password(
State(state): State<AppState>,
user: CurrentUser,
LoggedForm(form): LoggedForm<ChangePasswordForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
let passkeys = state.webauthn.list_passkeys(user.session.user.id).await?;
let render = |error: Option<&str>, success: bool| {
html_response(views::account_page(
&user.session.user,
&passkeys,
&user.session.csrf_token,
error,
success,
))
};
if form.new_password != form.confirm_password {
return Ok(render(Some("New password and confirmation do not match."), false));
}
state
.auth
.change_password(user.session.user.id, form.new_password)
.await?;
Ok(render(None, true))
}
async fn passkey_register_start( async fn passkey_register_start(
State(state): State<AppState>, State(state): State<AppState>,
user: CurrentUser, user: CurrentUser,
@@ -480,15 +526,28 @@ async fn passkey_login_start(
Json(form): Json<PasskeyLoginStartForm>, Json(form): Json<PasskeyLoginStartForm>,
) -> Result<Response, AppError> { ) -> Result<Response, AppError> {
let email = form.email.trim().to_lowercase(); let email = form.email.trim().to_lowercase();
let Some((user, _)) = state.auth.find_user_by_email(email).await? else { let (challenge, token) = if email.is_empty() {
return Err(AppError::NotFound); // Userless sign-in: no email needed, the authenticator selects a
// discoverable credential and returns a user handle.
state
.webauthn
.start_userless_authentication()
.await
.map_err(AppError::Database)?
} else {
let Some((user, _)) = state.auth.find_user_by_email(email).await? else {
return Err(AppError::NotFound);
};
state
.webauthn
.start_authentication(user.id)
.await
.map_err(AppError::Database)?
}; };
let challenge = state Ok(
.webauthn Json(serde_json::json!({ "token": token, "publicKey": challenge.public_key }))
.start_authentication(user.id) .into_response(),
.await )
.map_err(AppError::Database)?;
Ok(Json(challenge).into_response())
} }
async fn passkey_login_finish( async fn passkey_login_finish(
@@ -497,11 +556,7 @@ async fn passkey_login_finish(
) -> Result<Response, AppError> { ) -> Result<Response, AppError> {
let user_id = state let user_id = state
.webauthn .webauthn
.resolve_user_id_for_assertion(&form.response) .finish_authentication(form.token, form.response)
.await?;
state
.webauthn
.finish_authentication(user_id, form.response)
.await?; .await?;
let (session_token, _) = state.auth.create_session_for_user(user_id).await?; let (session_token, _) = state.auth.create_session_for_user(user_id).await?;
let mut response = Redirect::to("/lists").into_response(); let mut response = Redirect::to("/lists").into_response();
@@ -670,26 +725,65 @@ async fn create_category(
Ok(Redirect::to("/lists").into_response()) Ok(Redirect::to("/lists").into_response())
} }
async fn create_meal_category(
State(state): State<AppState>,
user: CurrentUser,
LoggedForm(form): LoggedForm<CategoryForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
let name = form.name.trim().to_owned();
if name.is_empty() || name.chars().count() > 60 {
return Err(AppError::BadRequest(
"Category names must be between 1 and 60 characters.".into(),
));
}
state.meals.create_meal_category(name).await?;
Ok(Redirect::to("/meals").into_response())
}
async fn delete_meal_category(
State(state): State<AppState>,
user: CurrentUser,
Path(category_id): Path<i64>,
LoggedForm(form): LoggedForm<CsrfForm>,
) -> Result<Response, AppError> {
verify_csrf(&user, &form.csrf)?;
state.meals.delete_meal_category(category_id).await?;
Ok(Redirect::to("/meals").into_response())
}
async fn meals_page( async fn meals_page(
State(state): State<AppState>, State(state): State<AppState>,
user: CurrentUser, user: CurrentUser,
Query(query): Query<MealPickerQuery>, Query(query): Query<MealPickerQuery>,
) -> Result<Response, AppError> { ) -> Result<Response, AppError> {
let meals = state.meals.list_meals().await?; let meals = state.meals.list_meals().await?;
let meal_categories = state.meals.list_meal_categories().await?;
if let Some(list_id) = query.picker { if let Some(list_id) = query.picker {
return Ok(html_response(views::meal_picker( return Ok(html_response(views::meal_picker(
&meals, &meals,
&meal_categories,
list_id, list_id,
&user.session.csrf_token, &user.session.csrf_token,
))); )));
} }
Ok(html_response(views::meals_page(&user.session.user, &meals))) Ok(html_response(views::meals_page(
&user.session.user,
&meals,
&meal_categories,
&user.session.csrf_token,
)))
} }
async fn new_meal_page(user: CurrentUser) -> Result<Response, AppError> { async fn new_meal_page(
State(state): State<AppState>,
user: CurrentUser,
) -> Result<Response, AppError> {
let meal_categories = state.meals.list_meal_categories().await?;
Ok(html_response(views::meal_form_page( Ok(html_response(views::meal_form_page(
&user.session.user, &user.session.user,
None, None,
&meal_categories,
&user.session.csrf_token, &user.session.csrf_token,
))) )))
} }
@@ -708,7 +802,11 @@ async fn create_meal(
} }
let meal = state let meal = state
.meals .meals
.create_meal(name, form.description.trim().to_owned()) .create_meal(
name,
form.description.trim().to_owned(),
parse_category_id(form.category_id),
)
.await?; .await?;
Ok(Redirect::to(&format!("/meals/{}", meal.id)).into_response()) Ok(Redirect::to(&format!("/meals/{}", meal.id)).into_response())
} }
@@ -724,10 +822,12 @@ async fn meal_page(
.await? .await?
.ok_or(AppError::NotFound)?; .ok_or(AppError::NotFound)?;
let categories = state.lists.categories().await?; let categories = state.lists.categories().await?;
let meal_categories = state.meals.list_meal_categories().await?;
Ok(html_response(views::meal_page( Ok(html_response(views::meal_page(
&user.session.user, &user.session.user,
&meal, &meal,
&categories, &categories,
&meal_categories,
&user.session.csrf_token, &user.session.csrf_token,
))) )))
} }
@@ -747,7 +847,12 @@ async fn edit_meal(
} }
state state
.meals .meals
.update_meal(meal_id, name, form.description.trim().to_owned()) .update_meal(
meal_id,
name,
form.description.trim().to_owned(),
parse_category_id(form.category_id),
)
.await?; .await?;
Ok(Redirect::to(&format!("/meals/{meal_id}")).into_response()) Ok(Redirect::to(&format!("/meals/{meal_id}")).into_response())
} }
+1 -1
View File
@@ -35,7 +35,7 @@ impl RealtimeNotifier for InMemoryHub {
} }
}); });
let connection_id = crate::security::new_secret(); let connection_id = hex::encode(crate::security::new_secret());
let already_present = room let already_present = room
.connections .connections
.values() .values()
+7 -4
View File
@@ -20,15 +20,15 @@ use crate::http::{AppState, build_router};
use crate::hub::InMemoryHub; use crate::hub::InMemoryHub;
use crate::ports::{ use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListRepository, CategoryRepository, InvitationRepository, ItemRepository, ListRepository,
MealIngredientRepository, MealRepository, PasskeyRepository, PasswordHasher, RealtimeNotifier, MealCategoryRepository, MealIngredientRepository, MealRepository, PasskeyRepository,
SessionRepository, TokenGenerator, UserRepository, PasswordHasher, RealtimeNotifier, SessionRepository, TokenGenerator, UserRepository,
}; };
use crate::security::{Argon2PasswordHasher, RandomTokenGenerator}; use crate::security::{Argon2PasswordHasher, RandomTokenGenerator};
use crate::services::{AuthService, InvitationService, ListService, MealService, RegistrationMode}; use crate::services::{AuthService, InvitationService, ListService, MealService, RegistrationMode};
use crate::sqlite::{ use crate::sqlite::{
SqliteCategoryRepository, SqliteDatabase, SqliteInvitationRepository, SqliteItemRepository, SqliteCategoryRepository, SqliteDatabase, SqliteInvitationRepository, SqliteItemRepository,
SqliteListRepository, SqliteMealIngredientRepository, SqliteMealRepository, SqliteListRepository, SqliteMealCategoryRepository, SqliteMealIngredientRepository,
SqlitePasskeyRepository, SqliteSessionRepository, SqliteUserRepository, SqliteMealRepository, SqlitePasskeyRepository, SqliteSessionRepository, SqliteUserRepository,
}; };
use crate::webauthn::{AppWebauthnConfig, WebAuthnService}; use crate::webauthn::{AppWebauthnConfig, WebAuthnService};
@@ -77,6 +77,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
let meals: Arc<dyn MealRepository> = Arc::new(SqliteMealRepository); let meals: Arc<dyn MealRepository> = Arc::new(SqliteMealRepository);
let meal_ingredients: Arc<dyn MealIngredientRepository> = let meal_ingredients: Arc<dyn MealIngredientRepository> =
Arc::new(SqliteMealIngredientRepository); Arc::new(SqliteMealIngredientRepository);
let meal_categories: Arc<dyn MealCategoryRepository> = Arc::new(SqliteMealCategoryRepository);
let invitations: Arc<dyn InvitationRepository> = Arc::new(SqliteInvitationRepository); let invitations: Arc<dyn InvitationRepository> = Arc::new(SqliteInvitationRepository);
let passkeys: Arc<dyn PasskeyRepository> = Arc::new(SqlitePasskeyRepository); let passkeys: Arc<dyn PasskeyRepository> = Arc::new(SqlitePasskeyRepository);
let hasher: Arc<dyn PasswordHasher> = Arc::new(Argon2PasswordHasher); let hasher: Arc<dyn PasswordHasher> = Arc::new(Argon2PasswordHasher);
@@ -107,6 +108,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
db.clone(), db.clone(),
Arc::clone(&meals), Arc::clone(&meals),
Arc::clone(&meal_ingredients), Arc::clone(&meal_ingredients),
Arc::clone(&meal_categories),
Arc::clone(&lists), Arc::clone(&lists),
Arc::clone(&items), Arc::clone(&items),
Arc::clone(&realtime), Arc::clone(&realtime),
@@ -132,6 +134,7 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
let webauthn_service = Arc::new(WebAuthnService::new( let webauthn_service = Arc::new(WebAuthnService::new(
db.clone(), db.clone(),
AppWebauthnConfig::new(rp_id, rp_name, origin), AppWebauthnConfig::new(rp_id, rp_name, origin),
Arc::clone(&users),
Arc::clone(&passkeys), Arc::clone(&passkeys),
)); ));
+30 -2
View File
@@ -2,8 +2,8 @@ use async_trait::async_trait;
use sqlx::SqliteConnection; use sqlx::SqliteConnection;
use crate::domain::{ use crate::domain::{
Category, DomainResult, GroceryList, Item, Meal, MealIngredient, Passkey, PresenceUser, Category, DomainResult, GroceryList, Item, Meal, MealCategory, MealIngredient, Passkey,
SessionUser, User, PresenceUser, SessionUser, User,
}; };
/// Repositories take `&mut SqliteConnection` (which a `Transaction` derefs to), /// Repositories take `&mut SqliteConnection` (which a `Transaction` derefs to),
@@ -24,6 +24,17 @@ pub trait UserRepository: Send + Sync {
txn: &mut SqliteConnection, txn: &mut SqliteConnection,
email: String, email: String,
) -> DomainResult<Option<(User, String)>>; ) -> DomainResult<Option<(User, String)>>;
async fn find_user_by_handle(
&self,
txn: &mut SqliteConnection,
user_handle: Vec<u8>,
) -> DomainResult<Option<User>>;
async fn update_password_hash(
&self,
txn: &mut SqliteConnection,
user_id: i64,
password_hash: String,
) -> DomainResult<()>;
async fn has_users(&self, txn: &mut SqliteConnection) -> DomainResult<bool>; async fn has_users(&self, txn: &mut SqliteConnection) -> DomainResult<bool>;
} }
@@ -163,6 +174,21 @@ pub trait InvitationRepository: Send + Sync {
) -> DomainResult<()>; ) -> DomainResult<()>;
} }
#[async_trait]
pub trait MealCategoryRepository: Send + Sync {
async fn meal_categories(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<MealCategory>>;
async fn create_meal_category(
&self,
txn: &mut SqliteConnection,
name: String,
) -> DomainResult<i64>;
async fn delete_meal_category(
&self,
txn: &mut SqliteConnection,
category_id: i64,
) -> DomainResult<()>;
}
#[async_trait] #[async_trait]
pub trait MealRepository: Send + Sync { pub trait MealRepository: Send + Sync {
async fn create_meal( async fn create_meal(
@@ -170,6 +196,7 @@ pub trait MealRepository: Send + Sync {
txn: &mut SqliteConnection, txn: &mut SqliteConnection,
name: String, name: String,
description: String, description: String,
category_id: Option<i64>,
) -> DomainResult<Meal>; ) -> DomainResult<Meal>;
async fn get_meal( async fn get_meal(
&self, &self,
@@ -183,6 +210,7 @@ pub trait MealRepository: Send + Sync {
meal_id: i64, meal_id: i64,
name: String, name: String,
description: String, description: String,
category_id: Option<i64>,
) -> DomainResult<()>; ) -> DomainResult<()>;
async fn delete_meal(&self, txn: &mut SqliteConnection, meal_id: i64) -> DomainResult<()>; async fn delete_meal(&self, txn: &mut SqliteConnection, meal_id: i64) -> DomainResult<()>;
} }
+5 -3
View File
@@ -37,12 +37,14 @@ pub struct RandomTokenGenerator;
#[async_trait] #[async_trait]
impl TokenGenerator for RandomTokenGenerator { impl TokenGenerator for RandomTokenGenerator {
fn generate(&self) -> String { fn generate(&self) -> String {
new_secret() hex::encode(new_secret())
} }
} }
pub fn new_secret() -> String { /// Generates 32 cryptographically random bytes. Callers that need a
/// client-facing string should hex-encode the result.
pub fn new_secret() -> Vec<u8> {
let mut bytes = [0_u8; 32]; let mut bytes = [0_u8; 32];
OsRng.fill_bytes(&mut bytes); OsRng.fill_bytes(&mut bytes);
hex::encode(bytes) bytes.to_vec()
} }
+64 -6
View File
@@ -1,10 +1,12 @@
use std::sync::Arc; use std::sync::Arc;
use crate::domain::{DomainError, DomainResult, GroceryList, Item, Meal, SessionUser, User}; use crate::domain::{
DomainError, DomainResult, GroceryList, Item, Meal, MealCategory, SessionUser, User,
};
use crate::ports::{ use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListRepository, CategoryRepository, InvitationRepository, ItemRepository, ListRepository,
MealIngredientRepository, MealRepository, NewItem, PasswordHasher, RealtimeNotifier, MealCategoryRepository, MealIngredientRepository, MealRepository, NewItem, PasswordHasher,
SessionRepository, TokenGenerator, UserRepository, RealtimeNotifier, SessionRepository, TokenGenerator, UserRepository,
}; };
use crate::sqlite::SqliteDatabase; use crate::sqlite::SqliteDatabase;
@@ -147,6 +149,22 @@ impl AuthService {
}) })
.await .await
} }
/// Replaces the user's password hash with a freshly hashed new password.
/// No current-password check is performed because the account page is
/// already authenticated and this app has no email capabilities.
pub async fn change_password(&self, user_id: i64, new_password: String) -> DomainResult<()> {
let users = Arc::clone(&self.users);
let hasher = Arc::clone(&self.hasher);
self.db
.run(move |txn| {
Box::pin(async move {
let new_hash = hasher.hash(&new_password)?;
users.update_password_hash(txn, user_id, new_hash).await
})
})
.await
}
} }
pub struct ListService { pub struct ListService {
@@ -297,6 +315,7 @@ pub struct MealService {
db: SqliteDatabase, db: SqliteDatabase,
meals: Arc<dyn MealRepository>, meals: Arc<dyn MealRepository>,
ingredients: Arc<dyn MealIngredientRepository>, ingredients: Arc<dyn MealIngredientRepository>,
meal_categories: Arc<dyn MealCategoryRepository>,
lists: Arc<dyn ListRepository>, lists: Arc<dyn ListRepository>,
items: Arc<dyn ItemRepository>, items: Arc<dyn ItemRepository>,
realtime: Arc<dyn RealtimeNotifier>, realtime: Arc<dyn RealtimeNotifier>,
@@ -307,6 +326,7 @@ impl MealService {
db: SqliteDatabase, db: SqliteDatabase,
meals: Arc<dyn MealRepository>, meals: Arc<dyn MealRepository>,
ingredients: Arc<dyn MealIngredientRepository>, ingredients: Arc<dyn MealIngredientRepository>,
meal_categories: Arc<dyn MealCategoryRepository>,
lists: Arc<dyn ListRepository>, lists: Arc<dyn ListRepository>,
items: Arc<dyn ItemRepository>, items: Arc<dyn ItemRepository>,
realtime: Arc<dyn RealtimeNotifier>, realtime: Arc<dyn RealtimeNotifier>,
@@ -315,17 +335,25 @@ impl MealService {
db, db,
meals, meals,
ingredients, ingredients,
meal_categories,
lists, lists,
items, items,
realtime, realtime,
} }
} }
pub async fn create_meal(&self, name: String, description: String) -> DomainResult<Meal> { pub async fn create_meal(
&self,
name: String,
description: String,
category_id: Option<i64>,
) -> DomainResult<Meal> {
let meals = Arc::clone(&self.meals); let meals = Arc::clone(&self.meals);
self.db self.db
.run(move |txn| { .run(move |txn| {
Box::pin(async move { meals.create_meal(txn, name, description).await }) Box::pin(async move {
meals.create_meal(txn, name, description, category_id).await
})
}) })
.await .await
} }
@@ -349,11 +377,41 @@ impl MealService {
meal_id: i64, meal_id: i64,
name: String, name: String,
description: String, description: String,
category_id: Option<i64>,
) -> DomainResult<()> { ) -> DomainResult<()> {
let meals = Arc::clone(&self.meals); let meals = Arc::clone(&self.meals);
self.db self.db
.run(move |txn| { .run(move |txn| {
Box::pin(async move { meals.update_meal(txn, meal_id, name, description).await }) Box::pin(async move {
meals
.update_meal(txn, meal_id, name, description, category_id)
.await
})
})
.await
}
pub async fn list_meal_categories(&self) -> DomainResult<Vec<MealCategory>> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| Box::pin(async move { meal_categories.meal_categories(txn).await }))
.await
}
pub async fn create_meal_category(&self, name: String) -> DomainResult<i64> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| {
Box::pin(async move { meal_categories.create_meal_category(txn, name).await })
})
.await
}
pub async fn delete_meal_category(&self, category_id: i64) -> DomainResult<()> {
let meal_categories = Arc::clone(&self.meal_categories);
self.db
.run(move |txn| {
Box::pin(async move { meal_categories.delete_meal_category(txn, category_id).await })
}) })
.await .await
} }
+303 -105
View File
@@ -7,15 +7,18 @@ use sha2::{Digest, Sha256};
use sqlx::{Connection, Row, SqliteConnection, SqlitePool, sqlite::SqliteConnectOptions}; use sqlx::{Connection, Row, SqliteConnection, SqlitePool, sqlite::SqliteConnectOptions};
use crate::domain::{ use crate::domain::{
Category, DomainError, DomainResult, GroceryList, Item, Meal, MealIngredient, Passkey, Category, DomainError, DomainResult, GroceryList, Item, Meal, MealCategory, MealIngredient,
SessionUser, User, Passkey, SessionUser, User,
}; };
use crate::ports::{ use crate::ports::{
CategoryRepository, InvitationRepository, ItemRepository, ListRepository, CategoryRepository, InvitationRepository, ItemRepository, ListRepository,
MealIngredientRepository, MealRepository, NewItem, PasskeyRepository, SessionRepository, MealCategoryRepository, MealIngredientRepository, MealRepository, NewItem, PasskeyRepository,
UserRepository, SessionRepository, UserRepository,
}; };
/// The embedded SQL migrations, applied automatically on startup.
static MIGRATOR: sqlx::migrate::Migrator = sqlx::migrate!();
#[derive(Clone)] #[derive(Clone)]
pub struct SqliteDatabase { pub struct SqliteDatabase {
pool: SqlitePool, pool: SqlitePool,
@@ -30,8 +33,9 @@ impl SqliteDatabase {
.busy_timeout(std::time::Duration::from_secs(5)) .busy_timeout(std::time::Duration::from_secs(5))
.create_if_missing(true); .create_if_missing(true);
let pool = SqlitePool::connect_with(options).await.map_err(db_error)?; let pool = SqlitePool::connect_with(options).await.map_err(db_error)?;
migrate(&pool).await?; MIGRATOR.run(&pool).await.map_err(migrate_error)?;
seed_default_categories(&pool).await?; seed_default_categories(&pool).await?;
seed_default_meal_categories(&pool).await?;
Ok(Self { pool }) Ok(Self { pool })
} }
@@ -56,8 +60,9 @@ impl SqliteDatabase {
.busy_timeout(std::time::Duration::from_secs(5)) .busy_timeout(std::time::Duration::from_secs(5))
.create_if_missing(true); .create_if_missing(true);
let pool = SqlitePool::connect_with(options).await.map_err(db_error)?; let pool = SqlitePool::connect_with(options).await.map_err(db_error)?;
migrate(&pool).await?; MIGRATOR.run(&pool).await.map_err(migrate_error)?;
seed_default_categories(&pool).await?; seed_default_categories(&pool).await?;
seed_default_meal_categories(&pool).await?;
Ok(Self { pool }) Ok(Self { pool })
} }
} }
@@ -92,85 +97,6 @@ impl SqliteDatabase {
} }
} }
async fn migrate(pool: &SqlitePool) -> DomainResult<()> {
sqlx::raw_sql(
"CREATE TABLE IF NOT EXISTS users (
id INTEGER PRIMARY KEY AUTOINCREMENT,
email TEXT NOT NULL UNIQUE COLLATE NOCASE,
display_name TEXT NOT NULL,
password_hash TEXT NOT NULL,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS sessions (
token_hash TEXT PRIMARY KEY,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
csrf_token TEXT NOT NULL,
expires_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS passkeys (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
credential_id TEXT NOT NULL UNIQUE,
credential TEXT NOT NULL,
counter INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS lists (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
revision INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS categories (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL UNIQUE COLLATE NOCASE,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS invitations (
token_hash TEXT PRIMARY KEY,
created_by INTEGER NOT NULL REFERENCES users(id) ON DELETE CASCADE,
expires_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS items (
id INTEGER PRIMARY KEY AUTOINCREMENT,
list_id INTEGER NOT NULL REFERENCES lists(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
checked INTEGER NOT NULL DEFAULT 0,
version INTEGER NOT NULL DEFAULT 1,
position INTEGER NOT NULL DEFAULT 0,
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS meals (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
description TEXT NOT NULL DEFAULT '',
created_at INTEGER NOT NULL,
updated_at INTEGER NOT NULL
);
CREATE TABLE IF NOT EXISTS meal_ingredients (
id INTEGER PRIMARY KEY AUTOINCREMENT,
meal_id INTEGER NOT NULL REFERENCES meals(id) ON DELETE CASCADE,
name TEXT NOT NULL,
quantity TEXT NOT NULL DEFAULT '',
note TEXT NOT NULL DEFAULT '',
category_id INTEGER REFERENCES categories(id) ON DELETE SET NULL,
position INTEGER NOT NULL DEFAULT 0
);
CREATE INDEX IF NOT EXISTS items_list_idx ON items(list_id);
CREATE INDEX IF NOT EXISTS meal_ingredients_meal_idx ON meal_ingredients(meal_id);
CREATE INDEX IF NOT EXISTS sessions_user_idx ON sessions(user_id);",
)
.execute(pool)
.await
.map_err(db_error)?;
Ok(())
}
/// Inserts the default global categories once, if the categories table is empty. /// Inserts the default global categories once, if the categories table is empty.
async fn seed_default_categories(pool: &SqlitePool) -> DomainResult<()> { async fn seed_default_categories(pool: &SqlitePool) -> DomainResult<()> {
let count: i64 = sqlx::query("SELECT COUNT(*) FROM categories") let count: i64 = sqlx::query("SELECT COUNT(*) FROM categories")
@@ -193,6 +119,30 @@ async fn seed_default_categories(pool: &SqlitePool) -> DomainResult<()> {
Ok(()) Ok(())
} }
/// Inserts the default meal categories once, if the meal_categories table is empty.
async fn seed_default_meal_categories(pool: &SqlitePool) -> DomainResult<()> {
let count: i64 = sqlx::query("SELECT COUNT(*) FROM meal_categories")
.fetch_one(pool)
.await
.map_err(db_error)?
.get(0);
if count > 0 {
return Ok(());
}
for (position, category_name) in DEFAULT_MEAL_CATEGORIES.iter().enumerate() {
sqlx::query(
"INSERT INTO meal_categories (name, position, created_at) VALUES (?1, ?2, ?3)",
)
.bind(category_name)
.bind(position as i64)
.bind(now())
.execute(pool)
.await
.map_err(db_error)?;
}
Ok(())
}
#[derive(Clone, Copy)] #[derive(Clone, Copy)]
pub struct SqliteUserRepository; pub struct SqliteUserRepository;
@@ -205,13 +155,17 @@ impl UserRepository for SqliteUserRepository {
display_name: String, display_name: String,
password_hash: String, password_hash: String,
) -> DomainResult<User> { ) -> DomainResult<User> {
// Generate a random, high-entropy user handle per the WebAuthn spec so
// the value embedded in authenticators is opaque and unguessable.
let user_handle = new_user_handle();
let result = sqlx::query( let result = sqlx::query(
"INSERT INTO users (email, display_name, password_hash, created_at) "INSERT INTO users (email, display_name, password_hash, user_handle, created_at)
VALUES (?1, ?2, ?3, ?4)", VALUES (?1, ?2, ?3, ?4, ?5)",
) )
.bind(&email) .bind(&email)
.bind(&display_name) .bind(&display_name)
.bind(&password_hash) .bind(&password_hash)
.bind(&user_handle)
.bind(now()) .bind(now())
.execute(&mut *txn) .execute(&mut *txn)
.await; .await;
@@ -226,6 +180,7 @@ impl UserRepository for SqliteUserRepository {
id, id,
email, email,
display_name, display_name,
user_handle,
}) })
} }
Err(error) if is_unique_violation(&error) => Err(DomainError::Conflict), Err(error) if is_unique_violation(&error) => Err(DomainError::Conflict),
@@ -239,7 +194,7 @@ impl UserRepository for SqliteUserRepository {
email: String, email: String,
) -> DomainResult<Option<(User, String)>> { ) -> DomainResult<Option<(User, String)>> {
let row = sqlx::query( let row = sqlx::query(
"SELECT id, email, display_name, password_hash "SELECT id, email, display_name, user_handle, password_hash
FROM users WHERE email = ?1 COLLATE NOCASE", FROM users WHERE email = ?1 COLLATE NOCASE",
) )
.bind(&email) .bind(&email)
@@ -252,12 +207,49 @@ impl UserRepository for SqliteUserRepository {
id: row.get(0), id: row.get(0),
email: row.get(1), email: row.get(1),
display_name: row.get(2), display_name: row.get(2),
user_handle: row.get(3),
}, },
row.get(3), row.get(4),
) )
})) }))
} }
async fn find_user_by_handle(
&self,
txn: &mut SqliteConnection,
user_handle: Vec<u8>,
) -> DomainResult<Option<User>> {
let row = sqlx::query(
"SELECT id, email, display_name, user_handle
FROM users WHERE user_handle = ?1",
)
.bind(&user_handle)
.fetch_optional(&mut *txn)
.await
.map_err(db_error)?;
Ok(row.map(|row| User {
id: row.get(0),
email: row.get(1),
display_name: row.get(2),
user_handle: row.get(3),
}))
}
async fn update_password_hash(
&self,
txn: &mut SqliteConnection,
user_id: i64,
password_hash: String,
) -> DomainResult<()> {
sqlx::query("UPDATE users SET password_hash = ?1 WHERE id = ?2")
.bind(&password_hash)
.bind(user_id)
.execute(&mut *txn)
.await
.map_err(db_error)?;
Ok(())
}
async fn has_users(&self, txn: &mut SqliteConnection) -> DomainResult<bool> { async fn has_users(&self, txn: &mut SqliteConnection) -> DomainResult<bool> {
let row = sqlx::query("SELECT EXISTS(SELECT 1 FROM users)") let row = sqlx::query("SELECT EXISTS(SELECT 1 FROM users)")
.fetch_one(&mut *txn) .fetch_one(&mut *txn)
@@ -388,15 +380,15 @@ impl SessionRepository for SqliteSessionRepository {
txn: &mut SqliteConnection, txn: &mut SqliteConnection,
user_id: i64, user_id: i64,
) -> DomainResult<(String, String)> { ) -> DomainResult<(String, String)> {
let session_token = crate::security::new_secret(); let session_token = hex::encode(crate::security::new_secret());
let csrf_token = crate::security::new_secret(); let csrf_token = hex::encode(crate::security::new_secret());
sqlx::query( sqlx::query(
"INSERT INTO sessions (token_hash, user_id, csrf_token, expires_at) "INSERT INTO sessions (token_hash, user_id, csrf_token, expires_at)
VALUES (?1, ?2, ?3, ?4)", VALUES (?1, ?2, ?3, ?4)",
) )
.bind(hash_secret(&session_token)) .bind(hash_secret(&session_token))
.bind(user_id) .bind(user_id)
.bind(&csrf_token) .bind(hex::decode(&csrf_token).expect("csrf_token is valid hex"))
.bind(now() + 60 * 60 * 24 * 30) .bind(now() + 60 * 60 * 24 * 30)
.execute(&mut *txn) .execute(&mut *txn)
.await .await
@@ -410,7 +402,7 @@ impl SessionRepository for SqliteSessionRepository {
session_token: String, session_token: String,
) -> DomainResult<Option<SessionUser>> { ) -> DomainResult<Option<SessionUser>> {
let row = sqlx::query( let row = sqlx::query(
"SELECT u.id, u.email, u.display_name, s.csrf_token "SELECT u.id, u.email, u.display_name, u.user_handle, s.csrf_token
FROM sessions s FROM sessions s
JOIN users u ON u.id = s.user_id JOIN users u ON u.id = s.user_id
WHERE s.token_hash = ?1 AND s.expires_at > ?2", WHERE s.token_hash = ?1 AND s.expires_at > ?2",
@@ -425,8 +417,9 @@ impl SessionRepository for SqliteSessionRepository {
id: row.get(0), id: row.get(0),
email: row.get(1), email: row.get(1),
display_name: row.get(2), display_name: row.get(2),
user_handle: row.get(3),
}, },
csrf_token: row.get(3), csrf_token: hex::encode(row.get::<Vec<u8>, _>(4)),
})) }))
} }
@@ -812,6 +805,78 @@ impl InvitationRepository for SqliteInvitationRepository {
} }
} }
#[derive(Clone, Copy)]
pub struct SqliteMealCategoryRepository;
#[async_trait]
impl MealCategoryRepository for SqliteMealCategoryRepository {
async fn meal_categories(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<MealCategory>> {
let rows = sqlx::query(
"SELECT id, name
FROM meal_categories
ORDER BY position ASC, name COLLATE NOCASE ASC",
)
.fetch_all(&mut *txn)
.await
.map_err(db_error)?;
Ok(rows
.into_iter()
.map(|row| MealCategory {
id: row.get(0),
name: row.get(1),
})
.collect())
}
async fn create_meal_category(
&self,
txn: &mut SqliteConnection,
name: String,
) -> DomainResult<i64> {
let position: i64 = sqlx::query("SELECT COALESCE(MAX(position), -1) + 1 FROM meal_categories")
.fetch_one(&mut *txn)
.await
.map_err(db_error)?
.get(0);
let result = sqlx::query(
"INSERT INTO meal_categories (name, position, created_at)
VALUES (?1, ?2, ?3)",
)
.bind(&name)
.bind(position)
.bind(now())
.execute(&mut *txn)
.await;
match result {
Ok(_) => {}
Err(error) if is_unique_violation(&error) => return Err(DomainError::Conflict),
Err(error) => return Err(db_error(error)),
}
Ok(sqlx::query("SELECT last_insert_rowid()")
.fetch_one(&mut *txn)
.await
.map_err(db_error)?
.get::<i64, _>(0))
}
async fn delete_meal_category(
&self,
txn: &mut SqliteConnection,
category_id: i64,
) -> DomainResult<()> {
let changed = sqlx::query("DELETE FROM meal_categories WHERE id = ?1")
.bind(category_id)
.execute(&mut *txn)
.await
.map_err(db_error)?
.rows_affected();
if changed == 0 {
return Err(DomainError::NotFound);
}
Ok(())
}
}
#[derive(Clone, Copy)] #[derive(Clone, Copy)]
pub struct SqliteMealRepository; pub struct SqliteMealRepository;
@@ -822,14 +887,16 @@ impl MealRepository for SqliteMealRepository {
txn: &mut SqliteConnection, txn: &mut SqliteConnection,
name: String, name: String,
description: String, description: String,
category_id: Option<i64>,
) -> DomainResult<Meal> { ) -> DomainResult<Meal> {
let now = now(); let now = now();
sqlx::query( sqlx::query(
"INSERT INTO meals (name, description, created_at, updated_at) "INSERT INTO meals (name, description, category_id, created_at, updated_at)
VALUES (?1, ?2, ?3, ?3)", VALUES (?1, ?2, ?3, ?4, ?4)",
) )
.bind(&name) .bind(&name)
.bind(&description) .bind(&description)
.bind(category_id)
.bind(now) .bind(now)
.execute(&mut *txn) .execute(&mut *txn)
.await .await
@@ -843,6 +910,7 @@ impl MealRepository for SqliteMealRepository {
id, id,
name, name,
description, description,
category_id,
ingredients: Vec::new(), ingredients: Vec::new(),
}) })
} }
@@ -853,7 +921,7 @@ impl MealRepository for SqliteMealRepository {
meal_id: i64, meal_id: i64,
) -> DomainResult<Option<Meal>> { ) -> DomainResult<Option<Meal>> {
let row = sqlx::query( let row = sqlx::query(
"SELECT id, name, description "SELECT id, name, description, category_id
FROM meals FROM meals
WHERE id = ?1", WHERE id = ?1",
) )
@@ -868,6 +936,7 @@ impl MealRepository for SqliteMealRepository {
id: row.get(0), id: row.get(0),
name: row.get(1), name: row.get(1),
description: row.get(2), description: row.get(2),
category_id: row.get(3),
ingredients: Vec::new(), ingredients: Vec::new(),
}; };
let ingredients = SqliteMealIngredientRepository let ingredients = SqliteMealIngredientRepository
@@ -881,7 +950,7 @@ impl MealRepository for SqliteMealRepository {
async fn list_meals(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Meal>> { async fn list_meals(&self, txn: &mut SqliteConnection) -> DomainResult<Vec<Meal>> {
let rows = sqlx::query( let rows = sqlx::query(
"SELECT id, name, description "SELECT id, name, description, category_id
FROM meals FROM meals
ORDER BY name COLLATE NOCASE ASC", ORDER BY name COLLATE NOCASE ASC",
) )
@@ -894,6 +963,7 @@ impl MealRepository for SqliteMealRepository {
id: row.get(0), id: row.get(0),
name: row.get(1), name: row.get(1),
description: row.get(2), description: row.get(2),
category_id: row.get(3),
ingredients: Vec::new(), ingredients: Vec::new(),
}; };
let ingredients = SqliteMealIngredientRepository let ingredients = SqliteMealIngredientRepository
@@ -913,14 +983,16 @@ impl MealRepository for SqliteMealRepository {
meal_id: i64, meal_id: i64,
name: String, name: String,
description: String, description: String,
category_id: Option<i64>,
) -> DomainResult<()> { ) -> DomainResult<()> {
let changed = sqlx::query( let changed = sqlx::query(
"UPDATE meals "UPDATE meals
SET name = ?1, description = ?2, updated_at = ?3 SET name = ?1, description = ?2, category_id = ?3, updated_at = ?4
WHERE id = ?4", WHERE id = ?5",
) )
.bind(&name) .bind(&name)
.bind(&description) .bind(&description)
.bind(category_id)
.bind(now()) .bind(now())
.bind(meal_id) .bind(meal_id)
.execute(&mut *txn) .execute(&mut *txn)
@@ -1109,10 +1181,19 @@ const DEFAULT_CATEGORIES: &[&str] = &[
"Household", "Household",
]; ];
fn hash_secret(secret: &str) -> String { const DEFAULT_MEAL_CATEGORIES: &[&str] = &[
"Beef",
"Chicken",
"Pasta",
"Sandwiches",
"Salads",
"Soups",
];
fn hash_secret(secret: &str) -> Vec<u8> {
let mut hasher = Sha256::new(); let mut hasher = Sha256::new();
hasher.update(secret.as_bytes()); hasher.update(secret.as_bytes());
hex::encode(hasher.finalize()) hasher.finalize().to_vec()
} }
fn now() -> i64 { fn now() -> i64 {
@@ -1122,6 +1203,17 @@ fn now() -> i64 {
.as_secs() as i64 .as_secs() as i64
} }
/// A random, high-entropy user handle used as the WebAuthn userHandle.
/// 32 random bytes, which is exactly the 64-byte maximum the WebAuthn spec
/// allows for a userHandle while still providing 256 bits of entropy. Opaque
/// and unguessable per the spec. Stored as raw bytes.
fn new_user_handle() -> Vec<u8> {
use rand::RngCore;
let mut bytes = [0_u8; 32];
rand::rngs::OsRng.fill_bytes(&mut bytes);
bytes.to_vec()
}
fn is_unique_violation(error: &sqlx::Error) -> bool { fn is_unique_violation(error: &sqlx::Error) -> bool {
error error
.as_database_error() .as_database_error()
@@ -1133,6 +1225,10 @@ fn db_error(error: sqlx::Error) -> DomainError {
DomainError::Database(error.to_string()) DomainError::Database(error.to_string())
} }
fn migrate_error(error: sqlx::migrate::MigrateError) -> DomainError {
DomainError::Database(error.to_string())
}
#[cfg(test)] #[cfg(test)]
mod tests { mod tests {
use super::*; use super::*;
@@ -1497,6 +1593,108 @@ mod tests {
assert!(matches!(result, Err(DomainError::Conflict))); assert!(matches!(result, Err(DomainError::Conflict)));
} }
// ---- MealCategoryRepository ----
async fn get_meal_categories(db: &SqliteDatabase) -> Vec<MealCategory> {
let categories = SqliteMealCategoryRepository;
db.run(move |txn| {
let categories = categories.clone();
Box::pin(async move { categories.meal_categories(txn).await })
})
.await
.unwrap()
}
#[tokio::test]
async fn meal_categories_are_seeded_with_defaults() {
let db = setup().await;
let categories = get_meal_categories(&db).await;
let names = categories.iter().map(|c| c.name.as_str()).collect::<Vec<_>>();
assert!(names.contains(&"Beef"));
assert!(names.contains(&"Chicken"));
assert!(names.contains(&"Pasta"));
assert!(names.contains(&"Sandwiches"));
assert!(names.contains(&"Salads"));
assert!(names.contains(&"Soups"));
}
#[tokio::test]
async fn create_meal_category_returns_id_and_lists() {
let db = setup().await;
let categories = SqliteMealCategoryRepository;
let id = db
.run(move |txn| {
let categories = categories.clone();
Box::pin(async move {
categories.create_meal_category(txn, "Breakfast".into()).await
})
})
.await
.unwrap();
assert!(id > 0);
let cats = get_meal_categories(&db).await;
assert!(cats.iter().any(|c| c.id == id && c.name == "Breakfast"));
}
#[tokio::test]
async fn create_duplicate_meal_category_conflicts() {
let db = setup().await;
let categories = SqliteMealCategoryRepository;
let result = db
.run(move |txn| {
let categories = categories.clone();
Box::pin(async move {
categories.create_meal_category(txn, "Beef".into()).await
})
})
.await;
assert!(matches!(result, Err(DomainError::Conflict)));
}
#[tokio::test]
async fn delete_meal_category_cascades_to_null_on_meals() {
let db = setup().await;
let categories = SqliteMealCategoryRepository;
let category_id = db
.run(move |txn| {
let categories = categories.clone();
Box::pin(async move {
categories.create_meal_category(txn, "Breakfast".into()).await
})
})
.await
.unwrap();
let meal = create_meal(&db, "Pancakes").await;
let meals = SqliteMealRepository;
db.run(move |txn| {
let meals = meals.clone();
Box::pin(async move {
meals
.update_meal(txn, meal.id, "Pancakes".into(), String::new(), Some(category_id))
.await
})
})
.await
.unwrap();
db.run(move |txn| {
let categories = categories.clone();
Box::pin(async move { categories.delete_meal_category(txn, category_id).await })
})
.await
.unwrap();
let fetched = db
.run(move |txn| {
let meals = meals.clone();
Box::pin(async move { meals.get_meal(txn, meal.id).await })
})
.await
.unwrap()
.unwrap();
assert_eq!(fetched.category_id, None);
}
// ---- ItemRepository ---- // ---- ItemRepository ----
#[tokio::test] #[tokio::test]
@@ -1846,7 +2044,7 @@ mod tests {
let name = name.to_owned(); let name = name.to_owned();
db.run(move |txn| { db.run(move |txn| {
let meals = meals.clone(); let meals = meals.clone();
Box::pin(async move { meals.create_meal(txn, name, String::new()).await }) Box::pin(async move { meals.create_meal(txn, name, String::new(), None).await })
}) })
.await .await
.unwrap() .unwrap()
@@ -1964,7 +2162,7 @@ mod tests {
let meals = meals.clone(); let meals = meals.clone();
Box::pin(async move { Box::pin(async move {
meals meals
.update_meal(txn, meal.id, "Pasta al pomodoro".into(), "desc".into()) .update_meal(txn, meal.id, "Pasta al pomodoro".into(), "desc".into(), None)
.await .await
}) })
}) })
@@ -1991,7 +2189,7 @@ mod tests {
let meals = meals.clone(); let meals = meals.clone();
Box::pin(async move { Box::pin(async move {
meals meals
.update_meal(txn, 9999, "X".into(), String::new()) .update_meal(txn, 9999, "X".into(), String::new(), None)
.await .await
}) })
}) })
+236 -57
View File
@@ -3,7 +3,7 @@ use pulldown_cmark::{Options, Parser, html as cmark_html};
use crate::{ use crate::{
domain::PresenceUser, domain::PresenceUser,
domain::{Category, GroceryList, Item, Meal, MealIngredient, Passkey, User}, domain::{Category, GroceryList, Item, Meal, MealCategory, MealIngredient, Passkey, User},
}; };
pub fn login_page(error: Option<&str>, invite: Option<&str>) -> Markup { pub fn login_page(error: Option<&str>, invite: Option<&str>) -> Markup {
@@ -23,15 +23,19 @@ pub fn login_page(error: Option<&str>, invite: Option<&str>) -> Markup {
input type="hidden" name="invite" value=(invite); input type="hidden" name="invite" value=(invite);
} }
label for="email" { "Email" } label for="email" { "Email" }
input id="email" name="email" type="email" autocomplete="email" required autofocus; input id="email" name="email" type="email" autocomplete="email" autofocus;
label for="password" { "Password" } label for="password" { "Password" }
input id="password" name="password" type="password" autocomplete="current-password" required; div class="password-field" {
input id="password" name="password" type="password" autocomplete="current-password" required;
button class="password-toggle" type="button" data-toggle-for="password" aria-label="Show password" { "Show" }
}
button class="button button-primary" type="submit" { "Sign in" } button class="button button-primary" type="submit" { "Sign in" }
} }
div class="auth-divider" { span { "or" } } div class="auth-divider" { span { "or" } }
button id="passkey-login" class="button button-secondary" type="button" { "Sign in with a passkey" } button id="passkey-login" class="button button-secondary" type="button" { "Sign in with a passkey" }
p class="auth-switch" { "Need an account? " a href="/register" { "Create one" } } p class="auth-switch" { "Need an account? " a href="/register" { "Create one" } }
} }
script src="/static/password-toggle.js" {}
script src="/static/passkey-login.js" {} script src="/static/passkey-login.js" {}
}, },
) )
@@ -58,11 +62,15 @@ pub fn register_page(error: Option<&str>, invite: Option<&str>) -> Markup {
label for="email" { "Email" } label for="email" { "Email" }
input id="email" name="email" type="email" autocomplete="email" required; input id="email" name="email" type="email" autocomplete="email" required;
label for="password" { "Password" } label for="password" { "Password" }
input id="password" name="password" type="password" autocomplete="new-password" required; div class="password-field" {
input id="password" name="password" type="password" autocomplete="new-password" required;
button class="password-toggle" type="button" data-toggle-for="password" aria-label="Show password" { "Show" }
}
button class="button button-primary" type="submit" { "Create account" } button class="button button-primary" type="submit" { "Create account" }
} }
p class="auth-switch" { "Already have an account? " a href="/login" { "Sign in" } } p class="auth-switch" { "Already have an account? " a href="/login" { "Sign in" } }
} }
script src="/static/password-toggle.js" {}
}, },
) )
} }
@@ -82,7 +90,13 @@ pub fn registration_closed_page() -> Markup {
) )
} }
pub fn account_page(user: &User, passkeys: &[Passkey], csrf_token: &str) -> Markup { pub fn account_page(
user: &User,
passkeys: &[Passkey],
csrf_token: &str,
password_error: Option<&str>,
password_success: bool,
) -> Markup {
page( page(
"Account", "Account",
Some(user), Some(user),
@@ -121,7 +135,34 @@ pub fn account_page(user: &User, passkeys: &[Passkey], csrf_token: &str) -> Mark
} }
button id="add-passkey" class="button button-primary" type="button" data-csrf=(csrf_token) { "Add a passkey" } button id="add-passkey" class="button button-primary" type="button" data-csrf=(csrf_token) { "Add a passkey" }
} }
section class="panel" {
div class="panel-heading" {
h2 { "Password" }
}
p { "Set a new password for your account." }
@if let Some(error) = password_error {
div class="alert alert-error" role="alert" { (error) }
}
@if password_success {
div class="alert alert-success" role="alert" { "Your password has been updated." }
}
form method="post" action="/account/password" class="stack" {
input type="hidden" name="csrf" value=(csrf_token);
label for="new-password" { "New password" }
div class="password-field" {
input id="new-password" name="new_password" type="password" autocomplete="new-password" required;
button class="password-toggle" type="button" data-toggle-for="new-password" aria-label="Show password" { "Show" }
}
label for="confirm-password" { "Confirm new password" }
div class="password-field" {
input id="confirm-password" name="confirm_password" type="password" autocomplete="new-password" required;
button class="password-toggle" type="button" data-toggle-for="confirm-password" aria-label="Show password" { "Show" }
}
button class="button button-primary" type="submit" { "Update password" }
}
}
} }
script src="/static/password-toggle.js" {}
script src="/static/passkey-register.js" {} script src="/static/passkey-register.js" {}
}, },
) )
@@ -193,7 +234,12 @@ pub fn lists_page(user: &User, lists: &[GroceryList], csrf_token: &str) -> Marku
) )
} }
pub fn meals_page(user: &User, meals: &[Meal]) -> Markup { pub fn meals_page(
user: &User,
meals: &[Meal],
meal_categories: &[MealCategory],
csrf_token: &str,
) -> Markup {
page( page(
"Meals", "Meals",
Some(user), Some(user),
@@ -206,6 +252,13 @@ pub fn meals_page(user: &User, meals: &[Meal]) -> Markup {
} }
a class="button button-primary" href="/meals/new" { "New meal" } a class="button button-primary" href="/meals/new" { "New meal" }
} }
@if meals.is_empty() {
div class="empty-state" {
div class="empty-mark" { "🍽" }
h3 { "No meals yet" }
p { "Create a meal to reuse its ingredients across your lists." }
}
}
div class="dashboard-grid" { div class="dashboard-grid" {
section class="panel" { section class="panel" {
div class="panel-heading" { div class="panel-heading" {
@@ -213,21 +266,52 @@ pub fn meals_page(user: &User, meals: &[Meal]) -> Markup {
span class="count-badge" { (meals.len()) } span class="count-badge" { (meals.len()) }
} }
@if meals.is_empty() { @if meals.is_empty() {
div class="empty-state" { p class="muted" { "Create a meal to get started." }
div class="empty-mark" { "🍽" }
h3 { "No meals yet" }
p { "Create a meal to reuse its ingredients across your lists." }
}
} @else { } @else {
div class="list-cards" { @for (category_name, category_meals) in meal_groups(meals, meal_categories) {
@for meal in meals { div class="category-group" {
a class="list-card" href=(format!("/meals/{}", meal.id)) { div class="category-heading" {
span class="list-card-icon" { "🍽" } h3 { (category_name) " (" (category_meals.len()) ")" }
span class="list-card-copy" { }
strong { (meal.name) } div class="list-cards" {
small { (meal.ingredients.len()) " ingredients" } @for meal in category_meals {
a class="list-card" href=(format!("/meals/{}", meal.id)) {
span class="list-card-icon" { "🍽" }
span class="list-card-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="list-card-arrow" { "" }
}
}
}
}
}
}
}
aside class="side-column" {
section class="panel categories-panel" {
div class="panel-heading" {
h2 { "Meal categories" }
}
p { "Organize meals by type." }
form method="post" action="/meals/categories" class="category-form" {
input type="hidden" name="csrf" value=(csrf_token);
input name="name" type="text" maxlength="60" placeholder="New category" required;
button class="button button-small button-secondary" type="submit" { "Add" }
}
@if meal_categories.is_empty() {
p class="muted category-empty" { "No categories yet." }
} @else {
div class="meal-category-list" {
@for category in meal_categories {
div class="meal-category-row" {
span class="meal-category-name" { (category.name) }
form method="post" action=(format!("/meals/categories/{}/delete", category.id)) {
input type="hidden" name="csrf" value=(csrf_token);
button class="meal-category-delete" type="submit" aria-label=(format!("Delete {}", category.name)) { "" }
}
} }
span class="list-card-arrow" { "" }
} }
} }
} }
@@ -238,7 +322,47 @@ pub fn meals_page(user: &User, meals: &[Meal]) -> Markup {
) )
} }
pub fn meal_picker(meals: &[Meal], list_id: i64, csrf_token: &str) -> Markup { fn meal_groups<'a>(
meals: &'a [Meal],
meal_categories: &[MealCategory],
) -> Vec<(String, Vec<&'a Meal>)> {
let mut groups = Vec::new();
for category in meal_categories {
let in_category = meals
.iter()
.filter(|meal| meal.category_id == Some(category.id))
.collect::<Vec<_>>();
if !in_category.is_empty() {
groups.push((category.name.clone(), in_category));
}
}
let uncategorized = meals
.iter()
.filter(|meal| meal.category_id.is_none())
.collect::<Vec<_>>();
if !uncategorized.is_empty() {
groups.push(("Uncategorized".into(), uncategorized));
}
groups
}
/// Returns the display name of a meal's category, if it has one.
fn meal_category_name(meal: &Meal, meal_categories: &[MealCategory]) -> Option<String> {
meal.category_id.and_then(|id| {
meal_categories
.iter()
.find(|category| category.id == id)
.map(|category| category.name.clone())
})
}
pub fn meal_picker(
meals: &[Meal],
meal_categories: &[MealCategory],
list_id: i64,
csrf_token: &str,
) -> Markup {
html! { html! {
div class="meal-picker-backdrop" onclick="if (event.target === this) this.remove()" { div class="meal-picker-backdrop" onclick="if (event.target === this) this.remove()" {
div class="meal-picker-modal" role="dialog" aria-modal="true" aria-label="Add a meal" { div class="meal-picker-modal" role="dialog" aria-modal="true" aria-label="Add a meal" {
@@ -258,23 +382,30 @@ pub fn meal_picker(meals: &[Meal], list_id: i64, csrf_token: &str) -> Markup {
} }
} @else { } @else {
div class="meal-picker-list" { div class="meal-picker-list" {
@for meal in meals { @for (category_name, category_meals) in meal_groups(meals, meal_categories) {
form div class="category-group" {
hx-post=(format!("/lists/{}/add-meal", list_id)) div class="category-heading" {
hx-target="#list-items" h3 { (category_name) }
hx-swap="outerHTML" }
hx-on::after-request="if (event.detail.successful) this.closest('.meal-picker-backdrop').remove()" @for meal in category_meals {
class="meal-picker-row" form
{ hx-post=(format!("/lists/{}/add-meal", list_id))
input type="hidden" name="csrf" value=(csrf_token); hx-target="#list-items"
input type="hidden" name="meal_id" value=(meal.id); hx-swap="outerHTML"
button class="meal-picker-button" type="submit" { hx-on::after-request="if (event.detail.successful) this.closest('.meal-picker-backdrop').remove()"
span class="meal-picker-icon" { "🍽" } class="meal-picker-row"
span class="meal-picker-copy" { {
strong { (meal.name) } input type="hidden" name="csrf" value=(csrf_token);
small { (meal.ingredients.len()) " ingredients" } input type="hidden" name="meal_id" value=(meal.id);
button class="meal-picker-button" type="submit" {
span class="meal-picker-icon" { "🍽" }
span class="meal-picker-copy" {
strong { (meal.name) }
small { (meal.ingredients.len()) " ingredients" }
}
span class="meal-picker-add" { "Add" }
}
} }
span class="meal-picker-add" { "Add" }
} }
} }
} }
@@ -285,15 +416,27 @@ pub fn meal_picker(meals: &[Meal], list_id: i64, csrf_token: &str) -> Markup {
} }
} }
pub fn meal_form_page(user: &User, meal: Option<&Meal>, csrf_token: &str) -> Markup { pub fn meal_form_page(
let (title, action, name, description) = match meal { user: &User,
meal: Option<&Meal>,
meal_categories: &[MealCategory],
csrf_token: &str,
) -> Markup {
let (title, action, name, description, category_id) = match meal {
Some(meal) => ( Some(meal) => (
"Edit meal", "Edit meal",
format!("/meals/{}/edit", meal.id), format!("/meals/{}/edit", meal.id),
meal.name.clone(), meal.name.clone(),
meal.description.clone(), meal.description.clone(),
meal.category_id,
),
None => (
"New meal",
"/meals".into(),
String::new(),
String::new(),
None,
), ),
None => ("New meal", "/meals".into(), String::new(), String::new()),
}; };
page( page(
title, title,
@@ -308,6 +451,21 @@ pub fn meal_form_page(user: &User, meal: Option<&Meal>, csrf_token: &str) -> Mar
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label for="meal-name" { "Name" } label for="meal-name" { "Name" }
input id="meal-name" name="name" type="text" maxlength="120" value=(name) required; input id="meal-name" name="name" type="text" maxlength="120" value=(name) required;
label for="meal-category" { "Category" }
select id="meal-category" name="category_id" {
@if category_id.is_none() {
option value="" selected { "Uncategorized" }
} @else {
option value="" { "Uncategorized" }
}
@for category in meal_categories {
@if category_id == Some(category.id) {
option value=(category.id) selected { (category.name) }
} @else {
option value=(category.id) { (category.name) }
}
}
}
label for="meal-description" { "Description (markdown)" } label for="meal-description" { "Description (markdown)" }
textarea id="meal-description" name="description" rows="8" { (description) } textarea id="meal-description" name="description" rows="8" { (description) }
button class="button button-primary" type="submit" { "Save meal" } button class="button button-primary" type="submit" { "Save meal" }
@@ -320,7 +478,13 @@ pub fn meal_form_page(user: &User, meal: Option<&Meal>, csrf_token: &str) -> Mar
) )
} }
pub fn meal_page(user: &User, meal: &Meal, categories: &[Category], csrf_token: &str) -> Markup { pub fn meal_page(
user: &User,
meal: &Meal,
categories: &[Category],
meal_categories: &[MealCategory],
csrf_token: &str,
) -> Markup {
page( page(
&meal.name, &meal.name,
Some(user), Some(user),
@@ -345,6 +509,21 @@ pub fn meal_page(user: &User, meal: &Meal, categories: &[Category], csrf_token:
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label { "Name" } label { "Name" }
input id="meal-edit-name" name="name" value=(meal.name) maxlength="120" required; input id="meal-edit-name" name="name" value=(meal.name) maxlength="120" required;
label { "Category" }
select id="meal-edit-category" name="category_id" {
@if meal.category_id.is_none() {
option value="" selected { "Uncategorized" }
} @else {
option value="" { "Uncategorized" }
}
@for category in meal_categories {
@if meal.category_id == Some(category.id) {
option value=(category.id) selected { (category.name) }
} @else {
option value=(category.id) { (category.name) }
}
}
}
label { "Description (markdown)" } label { "Description (markdown)" }
textarea id="meal-edit-description" name="description" rows="8" { (meal.description) } textarea id="meal-edit-description" name="description" rows="8" { (meal.description) }
button id="meal-edit-save" class="button button-primary" type="submit" { "Save meal" } button id="meal-edit-save" class="button button-primary" type="submit" { "Save meal" }
@@ -356,7 +535,7 @@ pub fn meal_page(user: &User, meal: &Meal, categories: &[Category], csrf_token:
div class="list-heading" { div class="list-heading" {
div { div {
p class="eyebrow" { "MEAL" } p class="eyebrow" { "MEAL" }
h1 { (meal.name) } h1 { (meal.name) @if let Some(category_name) = meal_category_name(meal, meal_categories) { span class="meal-category-label" { "(" (category_name) ")" } } }
} }
} }
@if meal.description.is_empty() { @if meal.description.is_empty() {
@@ -364,7 +543,7 @@ pub fn meal_page(user: &User, meal: &Meal, categories: &[Category], csrf_token:
} @else { } @else {
div class="markdown" { (render_markdown(&meal.description)) } div class="markdown" { (render_markdown(&meal.description)) }
} }
h2 class="category-heading" { "Ingredients" } hr class="ingredients-divider" {}
@if meal.ingredients.is_empty() { @if meal.ingredients.is_empty() {
p class="muted" { "No ingredients yet." } p class="muted" { "No ingredients yet." }
} @else { } @else {
@@ -382,14 +561,14 @@ pub fn meal_page(user: &User, meal: &Meal, categories: &[Category], csrf_token:
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label { "Name" } label { "Name" }
input id="ingredient-name" name="name" type="text" maxlength="120" required; input id="ingredient-name" name="name" type="text" maxlength="120" required;
label { "Quantity" }
input id="ingredient-quantity" name="quantity" type="text" maxlength="40";
label { "Note" }
input id="ingredient-note" name="note" type="text" maxlength="120";
label { "Category" } label { "Category" }
select id="ingredient-category" name="category_id" { select id="ingredient-category" name="category_id" {
(category_options(categories, None)) (category_options(categories, None))
} }
label { "Quantity" }
input id="ingredient-quantity" name="quantity" type="text" maxlength="40";
label { "Note" }
input id="ingredient-note" name="note" type="text" maxlength="120";
button id="add-ingredient-button" class="button button-primary" type="submit" { "Add ingredient" } button id="add-ingredient-button" class="button button-primary" type="submit" { "Add ingredient" }
} }
} }
@@ -431,19 +610,19 @@ fn ingredient_row(
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label { "Name" } label { "Name" }
input id=(format!("ingredient-edit-name-{}", ingredient.id)) name="name" value=(ingredient.name) maxlength="120" required; input id=(format!("ingredient-edit-name-{}", ingredient.id)) name="name" value=(ingredient.name) maxlength="120" required;
label { "Quantity" }
input id=(format!("ingredient-edit-quantity-{}", ingredient.id)) name="quantity" value=(ingredient.quantity) maxlength="40";
label { "Note" }
input id=(format!("ingredient-edit-note-{}", ingredient.id)) name="note" value=(ingredient.note) maxlength="120";
label { "Category" } label { "Category" }
select id=(format!("ingredient-edit-category-{}", ingredient.id)) name="category_id" { select id=(format!("ingredient-edit-category-{}", ingredient.id)) name="category_id" {
(category_options(categories, ingredient.category_id)) (category_options(categories, ingredient.category_id))
} }
label { "Quantity" }
input id=(format!("ingredient-edit-quantity-{}", ingredient.id)) name="quantity" value=(ingredient.quantity) maxlength="40";
label { "Note" }
input id=(format!("ingredient-edit-note-{}", ingredient.id)) name="note" value=(ingredient.note) maxlength="120";
button id=(format!("ingredient-edit-save-{}", ingredient.id)) class="button button-primary" type="submit" { "Save" } button id=(format!("ingredient-edit-save-{}", ingredient.id)) class="button button-primary" type="submit" { "Save" }
} }
form method="post" action=(format!("/meals/{}/ingredients/{}/delete", meal_id, ingredient.id)) { form method="post" action=(format!("/meals/{}/ingredients/{}/delete", meal_id, ingredient.id)) {
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
button id=(format!("ingredient-edit-delete-{}", ingredient.id)) class="danger-link" type="submit" { "Remove" } button id=(format!("ingredient-edit-delete-{}", ingredient.id)) class="button button-danger" type="submit" { "Remove" }
} }
} }
} }
@@ -612,10 +791,10 @@ fn list_content(
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label class="sr-only" for="item-name" { "Item name" } label class="sr-only" for="item-name" { "Item name" }
input id="item-name" name="name" type="text" maxlength="120" placeholder="Add an item..." autocomplete="off" required; input id="item-name" name="name" type="text" maxlength="120" placeholder="Add an item..." autocomplete="off" required;
input id="item-quantity" name="quantity" type="text" maxlength="40" placeholder="Qty" aria-label="Quantity";
select id="item-category" name="category_id" aria-label="Category" { select id="item-category" name="category_id" aria-label="Category" {
(category_options(categories, None)) (category_options(categories, None))
} }
input id="item-quantity" name="quantity" type="text" maxlength="40" placeholder="Qty" aria-label="Quantity";
button id="add-item-button" class="button button-primary add-button" type="submit" { "+ Add" } button id="add-item-button" class="button button-primary add-button" type="submit" { "+ Add" }
} }
(list_items_fragment(list, items, categories, csrf_token, false)) (list_items_fragment(list, items, categories, csrf_token, false))
@@ -741,14 +920,14 @@ fn item_row(item: &Item, categories: &[Category], csrf_token: &str) -> Markup {
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
label { "Name" } label { "Name" }
input id=(format!("item-edit-name-{}", item.id)) name="name" value=(item.name) maxlength="120" required; input id=(format!("item-edit-name-{}", item.id)) name="name" value=(item.name) maxlength="120" required;
label { "Quantity" }
input id=(format!("item-edit-quantity-{}", item.id)) name="quantity" value=(item.quantity) maxlength="40";
label { "Note" }
input id=(format!("item-edit-note-{}", item.id)) name="note" value=(item.note) maxlength="120";
label { "Category" } label { "Category" }
select id=(format!("item-edit-category-{}", item.id)) name="category_id" { select id=(format!("item-edit-category-{}", item.id)) name="category_id" {
(category_options(categories, item.category_id)) (category_options(categories, item.category_id))
} }
label { "Quantity" }
input id=(format!("item-edit-quantity-{}", item.id)) name="quantity" value=(item.quantity) maxlength="40";
label { "Note" }
input id=(format!("item-edit-note-{}", item.id)) name="note" value=(item.note) maxlength="120";
button id=(format!("item-edit-save-{}", item.id)) class="button button-primary" type="submit" { "Save" } button id=(format!("item-edit-save-{}", item.id)) class="button button-primary" type="submit" { "Save" }
} }
form form
@@ -757,7 +936,7 @@ fn item_row(item: &Item, categories: &[Category], csrf_token: &str) -> Markup {
hx-swap="outerHTML" hx-swap="outerHTML"
{ {
input type="hidden" name="csrf" value=(csrf_token); input type="hidden" name="csrf" value=(csrf_token);
button id=(format!("item-edit-delete-{}", item.id)) class="danger-link" type="submit" { "Remove item" } button id=(format!("item-edit-delete-{}", item.id)) class="button button-danger" type="submit" { "Remove item" }
} }
} }
} }
+125 -56
View File
@@ -7,12 +7,13 @@ use webauthn_rs::{
error::WebauthnError as WanError, error::WebauthnError as WanError,
proto::{ proto::{
CreationChallengeResponse, Credential, PublicKeyCredential, RegisterPublicKeyCredential, CreationChallengeResponse, Credential, PublicKeyCredential, RegisterPublicKeyCredential,
RequestChallengeResponse, RequestChallengeResponse, UserVerificationPolicy,
}, },
}; };
use crate::domain::{DomainError, DomainResult, Passkey as DbPasskey, User}; use crate::domain::{DomainError, DomainResult, Passkey as DbPasskey, User};
use crate::ports::PasskeyRepository; use crate::ports::{PasskeyRepository, UserRepository};
use crate::security::new_secret;
use crate::sqlite::SqliteDatabase; use crate::sqlite::SqliteDatabase;
/// Site-specific WebAuthn configuration, derived from env vars. /// Site-specific WebAuthn configuration, derived from env vars.
@@ -20,6 +21,7 @@ pub struct AppWebauthnConfig {
rp_id: String, rp_id: String,
rp_name: String, rp_name: String,
origin: url::Url, origin: url::Url,
require_resident_key: bool,
} }
impl AppWebauthnConfig { impl AppWebauthnConfig {
@@ -28,6 +30,10 @@ impl AppWebauthnConfig {
rp_id, rp_id,
rp_name, rp_name,
origin, origin,
// Resident (discoverable) keys let users sign in without typing an
// email, because the authenticator can select the credential on its
// own and return the user handle.
require_resident_key: true,
} }
} }
} }
@@ -42,18 +48,24 @@ impl WebauthnConfig for AppWebauthnConfig {
fn get_relying_party_id(&self) -> &str { fn get_relying_party_id(&self) -> &str {
&self.rp_id &self.rp_id
} }
fn get_require_resident_key(&self) -> bool {
self.require_resident_key
}
} }
/// A single-use, in-memory challenge store keyed by user id. /// A single-use, in-memory challenge store. Registrations are keyed by user id;
/// authentications are keyed by a random token so that userless (discoverable)
/// ceremonies can be correlated back to the finish request.
#[derive(Default)] #[derive(Default)]
struct ChallengeStore { struct ChallengeStore {
registrations: HashMap<i64, RegistrationState>, registrations: HashMap<i64, RegistrationState>,
authentications: HashMap<i64, AuthenticationState>, authentications: HashMap<String, AuthenticationState>,
} }
pub struct WebAuthnService { pub struct WebAuthnService {
db: SqliteDatabase, db: SqliteDatabase,
webauthn: Webauthn<AppWebauthnConfig>, webauthn: Webauthn<AppWebauthnConfig>,
users: Arc<dyn UserRepository>,
passkeys: Arc<dyn PasskeyRepository>, passkeys: Arc<dyn PasskeyRepository>,
challenges: Mutex<ChallengeStore>, challenges: Mutex<ChallengeStore>,
} }
@@ -62,12 +74,14 @@ impl WebAuthnService {
pub fn new( pub fn new(
db: SqliteDatabase, db: SqliteDatabase,
config: AppWebauthnConfig, config: AppWebauthnConfig,
users: Arc<dyn UserRepository>,
passkeys: Arc<dyn PasskeyRepository>, passkeys: Arc<dyn PasskeyRepository>,
) -> Self { ) -> Self {
let webauthn = Webauthn::new(config); let webauthn = Webauthn::new(config);
Self { Self {
db, db,
webauthn, webauthn,
users,
passkeys, passkeys,
challenges: Mutex::new(ChallengeStore::default()), challenges: Mutex::new(ChallengeStore::default()),
} }
@@ -75,9 +89,19 @@ impl WebAuthnService {
/// Start a passkey registration ceremony for an authenticated user. /// Start a passkey registration ceremony for an authenticated user.
pub fn start_registration(&self, user: &User) -> DomainResult<CreationChallengeResponse> { pub fn start_registration(&self, user: &User) -> DomainResult<CreationChallengeResponse> {
// Use the user's opaque, random user handle as the WebAuthn userHandle
// so that userless (discoverable) sign-in can resolve the owning user
// from the assertion's userHandle without exposing the numeric id.
let (challenge, state) = self let (challenge, state) = self
.webauthn .webauthn
.generate_challenge_register(&user.display_name, true) .generate_challenge_register_options(
user.user_handle.clone(),
user.email.clone(),
user.display_name.clone(),
None,
Some(UserVerificationPolicy::Required),
None,
)
.map_err(webauthn_error)?; .map_err(webauthn_error)?;
self.challenges self.challenges
.lock() .lock()
@@ -127,11 +151,12 @@ impl WebAuthnService {
.await .await
} }
/// Start a passkey authentication ceremony for a user. /// Start a passkey authentication ceremony for a user identified by email.
/// Returns the challenge and a token used to correlate the finish request.
pub async fn start_authentication( pub async fn start_authentication(
&self, &self,
user_id: i64, user_id: i64,
) -> DomainResult<RequestChallengeResponse> { ) -> DomainResult<(RequestChallengeResponse, String)> {
let passkeys = Arc::clone(&self.passkeys); let passkeys = Arc::clone(&self.passkeys);
let db = self.db.clone(); let db = self.db.clone();
let credentials: Vec<Credential> = db let credentials: Vec<Credential> = db
@@ -156,28 +181,91 @@ impl WebAuthnService {
.webauthn .webauthn
.generate_challenge_authenticate(credentials) .generate_challenge_authenticate(credentials)
.map_err(webauthn_error)?; .map_err(webauthn_error)?;
let token = hex::encode(new_secret());
self.challenges self.challenges
.lock() .lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))? .map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications .authentications
.insert(user_id, state); .insert(token.clone(), state);
Ok(challenge) Ok((challenge, token))
} }
/// Finish a passkey authentication ceremony. /// Start a userless passkey authentication ceremony. No email is required:
/// the authenticator selects a discoverable credential and returns a user
/// handle that we resolve to the owning user on finish.
pub async fn start_userless_authentication(
&self,
) -> DomainResult<(RequestChallengeResponse, String)> {
let (challenge, mut state) = self
.webauthn
.generate_challenge_authenticate_options(vec![], None)
.map_err(webauthn_error)?;
// With no allowCredentials the browser will offer any discoverable
// credential for this RP; the credential set is populated from the
// user handle once the assertion is received.
state.set_allowed_credentials(vec![]);
let token = hex::encode(new_secret());
self.challenges
.lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications
.insert(token.clone(), state);
Ok((challenge, token))
}
/// Finish a passkey authentication ceremony, resolving the owning user from
/// the credential id (and, for userless ceremonies, the user handle).
pub async fn finish_authentication( pub async fn finish_authentication(
&self, &self,
user_id: i64, token: String,
response: PublicKeyCredential, response: PublicKeyCredential,
) -> DomainResult<()> { ) -> DomainResult<i64> {
let state = self let mut state = self
.challenges .challenges
.lock() .lock()
.map_err(|_| DomainError::Database("challenge lock poisoned".into()))? .map_err(|_| DomainError::Database("challenge lock poisoned".into()))?
.authentications .authentications
.remove(&user_id) .remove(&token)
.ok_or(DomainError::NotFound)?; .ok_or(DomainError::NotFound)?;
// For userless ceremonies the assertion carries a user handle that
// identifies the user; load that user's credentials so the signature
// can be verified against the correct key.
if let Some(user_handle) = response.get_user_handle() {
let handle = user_handle.to_vec();
let users = Arc::clone(&self.users);
let db = self.db.clone();
let user_id = db
.run(move |txn| {
let users = users.clone();
Box::pin(async move {
let user = users
.find_user_by_handle(txn, handle)
.await?
.ok_or(DomainError::NotFound)?;
Ok(user.id)
})
})
.await?;
let passkeys = Arc::clone(&self.passkeys);
let credentials: Vec<Credential> = db
.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
let rows = passkeys.list_for_user(txn, user_id).await?;
let mut creds = Vec::new();
for row in rows {
let cred: Credential = serde_json::from_str(&row.credential)
.map_err(|e| DomainError::Database(e.to_string()))?;
creds.push(cred);
}
Ok(creds)
})
})
.await?;
state.set_allowed_credentials(credentials);
}
let (cred_id, auth_data) = self let (cred_id, auth_data) = self
.webauthn .webauthn
.authenticate_credential(&response, &state) .authenticate_credential(&response, &state)
@@ -189,28 +277,30 @@ impl WebAuthnService {
let passkeys = Arc::clone(&self.passkeys); let passkeys = Arc::clone(&self.passkeys);
let db = self.db.clone(); let db = self.db.clone();
let credential_id_b64 = base64_url(cred_id); let credential_id_b64 = base64_url(cred_id);
db.run(move |txn| { let user_id = db
let passkeys = passkeys.clone(); .run(move |txn| {
Box::pin(async move { let passkeys = passkeys.clone();
let stored = passkeys Box::pin(async move {
.find_by_credential_id(txn, credential_id_b64) let stored = passkeys
.await? .find_by_credential_id(txn, credential_id_b64)
.ok_or(DomainError::NotFound)?; .await?
let mut cred: Credential = serde_json::from_str(&stored.credential) .ok_or(DomainError::NotFound)?;
.map_err(|e| DomainError::Database(e.to_string()))?; let mut cred: Credential = serde_json::from_str(&stored.credential)
cred.counter = auth_data.counter; .map_err(|e| DomainError::Database(e.to_string()))?;
let serialized = serde_json::to_string(&cred) cred.counter = auth_data.counter;
.map_err(|e| DomainError::Database(e.to_string()))?; let serialized = serde_json::to_string(&cred)
sqlx::query("UPDATE passkeys SET credential = ?1 WHERE id = ?2") .map_err(|e| DomainError::Database(e.to_string()))?;
.bind(&serialized) sqlx::query("UPDATE passkeys SET credential = ?1 WHERE id = ?2")
.bind(stored.id) .bind(&serialized)
.execute(&mut *txn) .bind(stored.id)
.await .execute(&mut *txn)
.map_err(db_error)?; .await
Ok(()) .map_err(db_error)?;
Ok(stored.user_id)
})
}) })
}) .await?;
.await Ok(user_id)
} }
/// List the passkeys registered to a user. /// List the passkeys registered to a user.
@@ -234,27 +324,6 @@ impl WebAuthnService {
}) })
.await .await
} }
/// Resolve the user id that owns the credential in an assertion response.
pub async fn resolve_user_id_for_assertion(
&self,
response: &PublicKeyCredential,
) -> DomainResult<i64> {
let passkeys = Arc::clone(&self.passkeys);
let db = self.db.clone();
let credential_id_b64 = base64_url(&response.raw_id.0);
db.run(move |txn| {
let passkeys = passkeys.clone();
Box::pin(async move {
let stored = passkeys
.find_by_credential_id(txn, credential_id_b64)
.await?
.ok_or(DomainError::NotFound)?;
Ok(stored.user_id)
})
})
.await
}
} }
fn base64_url(bytes: &[u8]) -> String { fn base64_url(bytes: &[u8]) -> String {
+6 -10
View File
@@ -6,31 +6,27 @@ function b64ToBytes(b64) {
} }
document.getElementById("passkey-login").addEventListener("click", async () => { document.getElementById("passkey-login").addEventListener("click", async () => {
const email = document.getElementById("email").value; const email = document.getElementById("email").value.trim();
if (!email) {
alert("Enter your email first.");
return;
}
const start = await fetch("/auth/passkey/login/start", { const start = await fetch("/auth/passkey/login/start", {
method: "POST", method: "POST",
headers: { "Content-Type": "application/json" }, headers: { "Content-Type": "application/json" },
body: JSON.stringify({ email }), body: JSON.stringify({ email }),
}); });
if (!start.ok) { if (!start.ok) {
alert("No passkey found for that email."); alert("No passkey found for that account.");
return; return;
} }
const options = await start.json(); const data = await start.json();
const pk = options.publicKey; const pk = data.publicKey;
pk.challenge = b64ToBytes(pk.challenge); pk.challenge = b64ToBytes(pk.challenge);
if (pk.allowCredentials) { if (pk.allowCredentials) {
pk.allowCredentials.forEach((c) => (c.id = b64ToBytes(c.id))); pk.allowCredentials.forEach((c) => (c.id = b64ToBytes(c.id)));
} }
const credential = await navigator.credentials.get(options); const credential = await navigator.credentials.get({ publicKey: pk });
const finish = await fetch("/auth/passkey/login/finish", { const finish = await fetch("/auth/passkey/login/finish", {
method: "POST", method: "POST",
headers: { "Content-Type": "application/json" }, headers: { "Content-Type": "application/json" },
body: JSON.stringify({ response: credential }), body: JSON.stringify({ token: data.token, response: credential }),
}); });
if (finish.ok) { if (finish.ok) {
window.location.href = "/lists"; window.location.href = "/lists";
+16
View File
@@ -0,0 +1,16 @@
// Toggle password visibility so users can check for typos, especially on mobile.
document.querySelectorAll(".password-toggle").forEach(function (button) {
button.addEventListener("pointerdown", function (event) {
// Toggle on press (not click) for an instant response. preventScroll avoids
// a scroll-to-input animation that makes rapid toggling feel laggy, and
// keeping focus on the input keeps the mobile keyboard open.
event.preventDefault();
var input = document.getElementById(button.getAttribute("data-toggle-for"));
if (!input) return;
var showing = input.type === "text";
input.type = showing ? "password" : "text";
button.textContent = showing ? "Show" : "Hide";
button.setAttribute("aria-label", showing ? "Show password" : "Hide password");
input.focus({ preventScroll: true });
});
});
+21 -1
View File
@@ -75,6 +75,14 @@ h3 { margin-bottom: 6px; font-size: 1rem; }
.stack label { color: var(--muted); font-size: .82rem; font-weight: 700; } .stack label { color: var(--muted); font-size: .82rem; font-weight: 700; }
input { width: 100%; min-height: 46px; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; } input { width: 100%; min-height: 46px; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; }
input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); } input:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
.password-field { position: relative; }
.password-field input { padding-right: 64px; }
.password-toggle { position: absolute; top: 50%; right: 8px; transform: translateY(-50%); min-height: 32px; padding: 5px 10px; border: 0; border-radius: 9px; cursor: pointer; color: var(--deep-sage); background: #e7f0e1; font-weight: 800; font-size: .78rem; }
.password-toggle:hover { background: #dbe9d2; }
select { width: 100%; min-height: 46px; padding: 10px 34px 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; font: inherit; appearance: none; -webkit-appearance: none; background-image: url("data:image/svg+xml;utf8,<svg xmlns='http://www.w3.org/2000/svg' width='16' height='16' viewBox='0 0 16 16'><path d='M4 6l4 4 4-4' fill='none' stroke='%2355715d' stroke-width='2' stroke-linecap='round' stroke-linejoin='round'/></svg>"); background-repeat: no-repeat; background-position: right 12px center; }
select:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
select option { color: var(--ink); background: #fff; }
select option:checked { color: var(--deep-sage); font-weight: 700; }
textarea { width: 100%; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; font: inherit; resize: vertical; } textarea { width: 100%; padding: 10px 13px; border: 1px solid var(--line); border-radius: 12px; outline: none; color: var(--ink); background: #fff; font: inherit; resize: vertical; }
textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); } textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85, 113, 93, .12); }
.button { display: inline-flex; align-items: center; justify-content: center; min-height: 44px; padding: 10px 17px; border: 0; border-radius: 12px; cursor: pointer; text-decoration: none; font-weight: 800; transition: transform .16s ease, box-shadow .16s ease, background .16s ease; } .button { display: inline-flex; align-items: center; justify-content: center; min-height: 44px; padding: 10px 17px; border: 0; border-radius: 12px; cursor: pointer; text-decoration: none; font-weight: 800; transition: transform .16s ease, box-shadow .16s ease, background .16s ease; }
@@ -107,6 +115,7 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.auth-switch a { color: var(--deep-sage); font-weight: 800; } .auth-switch a { color: var(--deep-sage); font-weight: 800; }
.alert { margin-bottom: 18px; padding: 12px 14px; border-radius: 12px; font-size: .9rem; } .alert { margin-bottom: 18px; padding: 12px 14px; border-radius: 12px; font-size: .9rem; }
.alert-error { color: #874d40; background: #fbe7e0; } .alert-error { color: #874d40; background: #fbe7e0; }
.alert-success { color: #3d6b4f; background: #e4f2e6; }
.list-topbar { display: flex; justify-content: space-between; align-items: center; margin-bottom: 27px; } .list-topbar { display: flex; justify-content: space-between; align-items: center; margin-bottom: 27px; }
.back-link { color: var(--muted); font-size: .85rem; font-weight: 700; text-decoration: none; } .back-link { color: var(--muted); font-size: .85rem; font-weight: 700; text-decoration: none; }
@@ -126,7 +135,8 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.list-heading { display: flex; justify-content: space-between; margin-bottom: 25px; } .list-heading { display: flex; justify-content: space-between; margin-bottom: 25px; }
.list-heading h1 { max-width: 100%; margin-bottom: 5px; overflow-wrap: anywhere; font-size: clamp(1.45rem, 2.8vw, 2.05rem); } .list-heading h1 { max-width: 100%; margin-bottom: 5px; overflow-wrap: anywhere; font-size: clamp(1.45rem, 2.8vw, 2.05rem); }
.list-meta { margin: 0; color: var(--muted); font-size: .85rem; } .list-meta { margin: 0; color: var(--muted); font-size: .85rem; }
.add-item-form { display: grid; grid-template-columns: minmax(0, 1fr) 90px 145px auto; gap: 8px; margin-bottom: 19px; } .meal-category-label { margin-left: 10px; color: var(--muted); font-size: .8em; font-weight: 500; white-space: nowrap; }
.add-item-form { display: grid; grid-template-columns: minmax(0, 1fr) 145px 90px auto; gap: 8px; margin-bottom: 19px; }
.add-item-form input { min-height: 50px; } .add-item-form input { min-height: 50px; }
.add-item-form select { min-height: 50px; } .add-item-form select { min-height: 50px; }
.add-button { min-height: 50px; } .add-button { min-height: 50px; }
@@ -134,6 +144,7 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.item-list { display: grid; gap: 6px; } .item-list { display: grid; gap: 6px; }
.category-group + .category-group { margin-top: 18px; } .category-group + .category-group { margin-top: 18px; }
.category-heading { margin: 0 7px 4px; color: var(--deep-sage); font-size: .72rem; letter-spacing: .12em; text-transform: uppercase; } .category-heading { margin: 0 7px 4px; color: var(--deep-sage); font-size: .72rem; letter-spacing: .12em; text-transform: uppercase; }
.ingredients-divider { margin: 26px 0 18px; border: 0; border-top: 1px solid var(--line); }
.item-row { display: flex; align-items: center; gap: 12px; min-height: 66px; padding: 9px 7px 9px 10px; border-bottom: 1px solid #edf0e6; } .item-row { display: flex; align-items: center; gap: 12px; min-height: 66px; padding: 9px 7px 9px 10px; border-bottom: 1px solid #edf0e6; }
.item-row:last-child { border-bottom: 0; } .item-row:last-child { border-bottom: 0; }
.check-form { flex: 0 0 auto; } .check-form { flex: 0 0 auto; }
@@ -207,6 +218,8 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.edit-form { margin-bottom: 12px; } .edit-form { margin-bottom: 12px; }
.edit-form input { min-height: 38px; padding: 7px 10px; font-size: .85rem; } .edit-form input { min-height: 38px; padding: 7px 10px; font-size: .85rem; }
.danger-link { padding: 0; border: 0; color: var(--coral); background: none; cursor: pointer; font-size: .8rem; font-weight: 800; } .danger-link { padding: 0; border: 0; color: var(--coral); background: none; cursor: pointer; font-size: .8rem; font-weight: 800; }
.button-danger { width: 100%; color: var(--coral); background: #fbeae4; }
.button-danger:hover { background: #f7ddd4; }
.empty-items { padding: 34px 10px 18px; color: var(--muted); text-align: center; } .empty-items { padding: 34px 10px 18px; color: var(--muted); text-align: center; }
.empty-items-icon { display: block; margin-bottom: 7px; color: var(--yellow); font-size: 1.7rem; } .empty-items-icon { display: block; margin-bottom: 7px; color: var(--yellow); font-size: 1.7rem; }
.empty-items p { margin-bottom: 2px; color: var(--ink); font-weight: 800; } .empty-items p { margin-bottom: 2px; color: var(--ink); font-weight: 800; }
@@ -217,6 +230,13 @@ textarea:focus { border-color: var(--deep-sage); box-shadow: 0 0 0 4px rgba(85,
.category-form input { min-height: 38px; padding: 7px 10px; font-size: .84rem; } .category-form input { min-height: 38px; padding: 7px 10px; font-size: .84rem; }
.category-list { display: flex; flex-wrap: wrap; gap: 6px; margin-top: 14px; } .category-list { display: flex; flex-wrap: wrap; gap: 6px; margin-top: 14px; }
.category-chip { padding: 5px 9px; border-radius: 99px; color: var(--deep-sage); background: #edf3e8; font-size: .72rem; font-weight: 800; } .category-chip { padding: 5px 9px; border-radius: 99px; color: var(--deep-sage); background: #edf3e8; font-size: .72rem; font-weight: 800; }
/* Meal categories side panel */
.meal-category-list { display: grid; gap: 2px; margin-top: 14px; }
.meal-category-row { display: flex; align-items: center; justify-content: space-between; gap: 8px; padding: 7px 4px; border-bottom: 1px solid #edf0e6; }
.meal-category-row:last-child { border-bottom: 0; }
.meal-category-name { font-size: .9rem; font-weight: 700; }
.meal-category-delete { padding: 2px 6px; border: 0; border-radius: 7px; color: var(--muted); background: transparent; cursor: pointer; font-size: .8rem; line-height: 1; }
.meal-category-delete:hover { color: var(--coral); background: #fbeae4; }
.category-empty { margin: 13px 0 0; font-size: .8rem; } .category-empty { margin: 13px 0 0; font-size: .8rem; }
.category-result { margin-top: 10px; } .category-result { margin-top: 10px; }
.category-success { margin: 0; color: var(--deep-sage); font-size: .76rem; font-weight: 800; } .category-success { margin: 0; color: var(--deep-sage); font-size: .76rem; font-weight: 800; }