- main.ts awaits DatabaseInitService.init() before app.listen(), ensuring
migrations + seed run before the HTTP server accepts traffic.
- AppModule now uses NestModule with consumer.apply() no longer needed for
CSRF (registered globally via app.use after body parsers in main.ts).
- JwtAuthGuard extended from AuthGuard('jwt') so protected endpoints
actually validate the bearer token.
- Admin controller now uses Zod-validated DTOs for body/path/query:
createUser, updateUserRole, userIdParam, listUsersQuery; with @Public
/ @Roles decorators and AdminGuard applied.
- Multer upload module + controller (POST /api/v1/uploads/category-icon
and /challenge-file) with safe-filename strategy, configured
UPLOAD_SIZE_LIMIT, admin-only via AdminGuard, served via /uploads
static handler.
- ThemeLoaderService now requires all 10 canonical theme ids at startup,
backfilling missing themes from built-ins with a warning; validates the
configured themeKey setting and falls back to 'classic' if invalid;
gracefully tolerates missing setting table during early boot.
- Test suite expanded to 76 tests / 17 suites; new specs:
admin-validation, uploads, theme-required, database-init.
- InitSchema migration now issues PRAGMA journal_mode = WAL after
PRAGMA foreign_keys = ON so fresh DBs are created in WAL mode.
- DatabaseInitService.init() also calls ensureWalMode() after
dataSource.initialize() so warm DBs (where migrations are skipped)
have WAL applied and persisted on every startup. Logs whether it
was already set or just enabled.
- main.ts now serves an OpenAPI 3.1 document at /api/docs and
/api/docs-json. A new toOpenApi31() utility converts the
NestJS-generated 3.0 document by setting openapi=3.1.0, normalising
the required info fields, and rewriting every legacy
'nullable: true' marker into a JSON Schema 2020-12 type union
('type: [<orig>, "null"]'). Recursion handles components, paths,
parameters, request bodies, response bodies, properties, items,
oneOf/anyOf/allOf, and parameter/request schemas.
- 7 new unit tests in tests/backend/openapi31.spec.ts lock the
conversion behaviour; total suite: 83 tests across 18 specs.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
This PR was automatically generated by an AI Agent.
- Backend: NestJS 10 + TypeORM (better-sqlite3) feature-modular layout. - Entities: user, setting, category, challenge, challenge_file, solve, refresh_token, blog_post. Auto-run migrations + idempotent 6-system- category seed on startup. - Argon2id password hashing with policy check; JWT access + rotating refresh tokens (HttpOnly cookie); CSRF middleware (SameSite + custom X-CSRF-Token header); global JWT auth guard with @Public() opt-out; per-IP login backoff + per-IP registration rate limit. - Endpoints: auth (login/refresh/logout/csrf), users (first-admin registration), system (bootstrap/event status/SSE), admin (guarded user CRUD with last-admin invariant), frontend module (uploads + SPA fallback). - Security: helmet+CSP+HSTS-gated-by-TLS, CORS allowlist, structured global exception filter, Zod request validation pipes, OpenAPI 3.1 served at /api/docs and /api/docs-json, 10 canonical themes under backend/themes/. - Frontend: Angular 17 standalone components, lazy-loaded feature routes, signals, functional HttpInterceptorFn (csrf + auth), functional CanActivateFn auth guard, HttpOnly-cookie-based auth service. - Tests: Jest + supertest, 46 tests across 13 suites covering migrations, env schema, theme loader, event status, login backoff, registration rate limit, ApiError shape, bootstrap integration, auth refresh rotation, admin guard, last-admin invariant, SSE flat payloads. Single-command runner: `npm test`.- main.ts awaits DatabaseInitService.init() before app.listen(), ensuring migrations + seed run before the HTTP server accepts traffic. - AppModule now uses NestModule with consumer.apply() no longer needed for CSRF (registered globally via app.use after body parsers in main.ts). - JwtAuthGuard extended from AuthGuard('jwt') so protected endpoints actually validate the bearer token. - Admin controller now uses Zod-validated DTOs for body/path/query: createUser, updateUserRole, userIdParam, listUsersQuery; with @Public / @Roles decorators and AdminGuard applied. - Multer upload module + controller (POST /api/v1/uploads/category-icon and /challenge-file) with safe-filename strategy, configured UPLOAD_SIZE_LIMIT, admin-only via AdminGuard, served via /uploads static handler. - ThemeLoaderService now requires all 10 canonical theme ids at startup, backfilling missing themes from built-ins with a warning; validates the configured themeKey setting and falls back to 'classic' if invalid; gracefully tolerates missing setting table during early boot. - Test suite expanded to 76 tests / 17 suites; new specs: admin-validation, uploads, theme-required, database-init.- InitSchema migration now issues PRAGMA journal_mode = WAL after PRAGMA foreign_keys = ON so fresh DBs are created in WAL mode. - DatabaseInitService.init() also calls ensureWalMode() after dataSource.initialize() so warm DBs (where migrations are skipped) have WAL applied and persisted on every startup. Logs whether it was already set or just enabled. - main.ts now serves an OpenAPI 3.1 document at /api/docs and /api/docs-json. A new toOpenApi31() utility converts the NestJS-generated 3.0 document by setting openapi=3.1.0, normalising the required info fields, and rewriting every legacy 'nullable: true' marker into a JSON Schema 2020-12 type union ('type: [<orig>, "null"]'). Recursion handles components, paths, parameters, request bodies, response bodies, properties, items, oneOf/anyOf/allOf, and parameter/request schemas. - 7 new unit tests in tests/backend/openapi31.spec.ts lock the conversion behaviour; total suite: 83 tests across 18 specs.