feat(api): ручки Фаз(ы) 1 — профиль, серверы, роли, админ инстанса

REST-слой Фазы 1 на huma (OpenAPI 3.1 генерируется из кода):

- профиль: GET/PATCH /users/@me, смена пароля со step-up, публичный профиль,
  завершение онбординга (новая миграция 00003 с onboarding_completed_at);
- серверы: создание/изменение/удаление, join/leave, список серверов
  пользователя, журнал действий;
- комнаты: список с учётом прав, создание/изменение/удаление;
- участники: список с профилями и ролями, никнейм, тайм-аут, исключение;
- роли: CRUD, выдача/снятие с проверкой иерархии и запретом выдачи прав выше
  собственных;
- админ инстанса: публичная информация, настройки, серверы, пользователи,
  аудит, выдача прав администратора со step-up; обход лимитов фиксируется в
  аудите отдельной записью limits.bypass;
- движок прав: участие в сервере стало обязательным условием (IsMember),
  не участник не получает прав роли @user; калькулятор прав общий для API и
  Gateway, инвалидация кэша после изменений;
- Gateway: браузерный клиент аутентифицируется cookie на рукопожатии, IDENTIFY
  без токена использует её; события GUILD/CHANNEL/MEMBER/ROLE рассылаются из
  ручек, USER_UPDATE — адресно;
- ошибки huma отдаются в едином конверте {"error":{"code","message"}}.

Тесты: 8 сценариев API (профиль, жизненный цикл сервера и права, лимиты и
обход админом, иерархия ролей, тайм-аут, скрытие комнаты оверрайдом,
членство в движке прав, cookie-идентификация Gateway).
This commit is contained in:
2026-09-19 21:50:06 +03:00
parent 86dff94a02
commit 1b1a679827
63 changed files with 8477 additions and 187 deletions
+128
View File
@@ -0,0 +1,128 @@
import {
useId,
type InputHTMLAttributes,
type ReactNode,
type TextareaHTMLAttributes,
} from 'react';
interface FieldShellProps {
label: string;
hint?: string | undefined;
error?: string | null | undefined;
children: (ids: { id: string; describedBy: string | undefined }) => ReactNode;
}
/** Общая обёртка поля: label, подсказка и сообщение об ошибке. */
function FieldShell({ label, hint, error, children }: FieldShellProps) {
const id = useId();
const hintId = `${id}-hint`;
const errorId = `${id}-error`;
const describedBy =
[hint === undefined ? null : hintId, error === null || error === undefined ? null : errorId]
.filter((value): value is string => value !== null)
.join(' ') || undefined;
return (
<div className="flex flex-col gap-1">
<label className="text-sm font-medium text-fg" htmlFor={id}>
{label}
</label>
{children({ id, describedBy })}
{hint === undefined ? null : (
<p id={hintId} className="text-xs text-fg-muted">
{hint}
</p>
)}
{error === null || error === undefined ? null : (
<p id={errorId} className="text-xs text-danger" role="alert">
{error}
</p>
)}
</div>
);
}
const controlClass =
'w-full rounded-[var(--radius-md)] border border-border/60 bg-surface-2 px-3 py-2 text-fg placeholder:text-fg-muted/70 disabled:opacity-60';
export type InputFieldProps = {
label: string;
hint?: string | undefined;
error?: string | null | undefined;
} & InputHTMLAttributes<HTMLInputElement>;
export function Field({ label, hint, error, className = '', ...rest }: InputFieldProps) {
return (
<FieldShell label={label} hint={hint} error={error}>
{({ id, describedBy }) => (
<input
id={id}
aria-describedby={describedBy}
aria-invalid={error === null || error === undefined ? undefined : true}
className={`${controlClass} ${className}`}
{...rest}
/>
)}
</FieldShell>
);
}
export type TextAreaFieldProps = {
label: string;
hint?: string | undefined;
error?: string | null | undefined;
} & TextareaHTMLAttributes<HTMLTextAreaElement>;
export function TextAreaField({ label, hint, error, className = '', ...rest }: TextAreaFieldProps) {
return (
<FieldShell label={label} hint={hint} error={error}>
{({ id, describedBy }) => (
<textarea
id={id}
aria-describedby={describedBy}
aria-invalid={error === null || error === undefined ? undefined : true}
className={`${controlClass} ${className}`}
{...rest}
/>
)}
</FieldShell>
);
}
interface SelectFieldProps {
label: string;
hint?: string | undefined;
value: string;
onChange: (value: string) => void;
options: { value: string; label: string }[];
className?: string;
}
export function SelectField({
label,
hint,
value,
onChange,
options,
className = '',
}: SelectFieldProps) {
return (
<FieldShell label={label} hint={hint}>
{({ id, describedBy }) => (
<select
id={id}
aria-describedby={describedBy}
className={`${controlClass} ${className}`}
value={value}
onChange={(event) => onChange(event.target.value)}
>
{options.map((option) => (
<option key={option.value} value={option.value}>
{option.label}
</option>
))}
</select>
)}
</FieldShell>
);
}