feat(dashboard): refine activity telemetry and maps
CI / validate (push) Successful in 5m24s
Release / release (push) Successful in 11m6s

This commit is contained in:
dmg
2026-08-01 20:28:32 -04:00
parent 9116107917
commit ebc7c7df17
32 changed files with 695 additions and 72 deletions
+3 -2
View File
@@ -1,6 +1,6 @@
# Accessibility review
Review date: 2026-08-01
Review date: 2026-08-02
## Scope
@@ -17,8 +17,9 @@ Player account management, administrator navigation, dashboard metrics and chart
- Added `role=status` with polite announcements for successful nickname changes and `role=alert` with assertive announcements for errors.
- Added semantic `time` elements for audit and security activity timestamps.
- Made event JSON keyboard-focusable so horizontally overflowing content can be reviewed without a pointer.
- Added an accessible title, description, per-point labels, and textual values to the registration chart.
- Added an accessible title, description, date labels, per-point labels, and textual values to the daily-active-user chart.
- Added labelled, keyboard-linked world-map markers plus a complete semantic table equivalent for approximate user locations.
- Added keyboard-operable tabs for the server-rendered overview and opt-in interactive OpenStreetMap view.
- Added explicit new-tab context to the external Discord invite link.
- Kept destructive account and group actions behind native keyboard-operable `details` confirmation disclosures.
- Allowed administrator navigation to wrap at narrow viewport widths instead of overflowing.
+7 -3
View File
@@ -29,12 +29,16 @@ Every error response has media type `application/problem+json` and the shape:
| Type | Status | Meaning |
| --- | ---: | --- |
| `urn:error:invalid-velocity-access-request` | 400 | Request JSON does not satisfy the shared Velocity contract |
| `urn:error:invalid-velocity-access-request` | 400 | Access request JSON does not satisfy the shared Velocity contract |
| `urn:error:invalid-velocity-connection-request` | 400 | Confirmed-connection JSON does not satisfy the shared Velocity contract |
| `urn:error:unauthorized` | 401 | Velocity bearer credential is missing, invalid, or revoked |
| `urn:error:expired-velocity-access-request` | 401 | Request timestamp is outside the accepted clock-skew window |
| `urn:error:expired-velocity-access-request` | 401 | Access timestamp is outside the accepted clock-skew window |
| `urn:error:expired-velocity-connection-request` | 401 | Connection timestamp is outside the accepted clock-skew window |
| `urn:error:not-found` | 404 | Unknown application-owned API route |
| `urn:error:unknown-minecraft-account` | 404 | Connection telemetry references an inactive or unknown account |
| `urn:error:method-not-allowed` | 405 | The endpoint does not support the requested HTTP method |
| `urn:error:replayed-velocity-access-request` | 409 | Request ID was already processed |
| `urn:error:replayed-velocity-access-request` | 409 | Admission request ID was already processed |
| `urn:error:replayed-velocity-connection-request` | 409 | Confirmed-connection request ID was already processed |
| `urn:error:unsupported-media-type` | 415 | The request does not use `application/json` |
| `urn:error:service-unavailable` | 503 | A safe access decision could not be completed |
+3 -2
View File
@@ -4,7 +4,7 @@
### Web application
The Next.js application owns user onboarding, account management, admin configuration and metrics, server-side Minecraft profile validation, sessions, and the HTTP API used by Discord and Velocity integrations. Database-backed portal and console pages are dynamic React Server Components: authentication, queries, filtering, dashboard aggregation, and the Natural Earth user-location map execute on the server and return rendered HTML. Map boundaries are bundled open data, so rendering does not disclose administrator or user location requests to a map provider.
The Next.js application owns user onboarding, account management, admin configuration and metrics, server-side Minecraft profile validation, sessions, and the HTTP API used by Discord and Velocity integrations. Database-backed portal and console pages are dynamic React Server Components: authentication, queries, filtering, dashboard aggregation, and the initial Natural Earth user-location map execute on the server and return rendered HTML. Administrators can opt into a hydrated Leaflet/OpenStreetMap view; OSM receives requests only for viewed map tiles, while user marker coordinates remain local to the browser.
User authentication begins with an opaque, short-lived, single-use token created for a Discord user. Only a cryptographic hash of the token is persisted. Admin authentication is a separate Keycloak OIDC flow and requires the `minecraft-account-manager-admin` role.
@@ -16,7 +16,7 @@ The bot creates private login links in response to `/register` and `/account`. D
Velocity sends the authenticated Java UUID, current username, source IP, server ID, request ID, and occurrence time. The API matches UUID first. Username fallback is allowed only when the stored account has no UUID, after which UUID and canonical username are updated.
The decision is fail closed. Unknown players, invalid responses, expired requests, authentication failures, and unavailable API responses are denied with the configured registration message.
The admission decision is fail closed. Unknown players, invalid responses, expired requests, authentication failures, and unavailable API responses are denied with the configured registration message. After admission succeeds, `PostLoginEvent` reports a confirmed proxy connection through a fresh, authenticated, replay-protected request. Connection telemetry is best effort and never disconnects an already admitted player.
## Trust boundaries
@@ -52,3 +52,4 @@ Events use reverse-DNS names beneath `games.minecraft.account-manager`, includin
- `games.minecraft.account-manager.network.vpn-blocked`
- `games.minecraft.account-manager.game.login.allowed`
- `games.minecraft.account-manager.game.login.denied`
- `games.minecraft.account-manager.game.player.connected`
+3 -3
View File
@@ -1,6 +1,6 @@
# Security review
Review date: 2026-08-01
Review date: 2026-08-02
## Scope
@@ -22,12 +22,12 @@ Next.js portal and APIs, Discord bot, PostgreSQL persistence, Keycloak admin aut
- User mutations verify ownership server-side.
- Mojang lookup is server-side and targets a fixed host, avoiding client-forged validation and SSRF.
- Velocity credentials are high-entropy bearer tokens stored only as hashes.
- Velocity requests have a 45-second clock window and database-unique request IDs for cross-instance replay prevention.
- Velocity admission and confirmed-connection requests have a 45-second clock window and database-unique request IDs for cross-instance replay prevention.
- Velocity and its API fail closed.
- Registered players require an enabled effective group; explicit assignments replace rather than combine with the protected, disabled-by-default `everyone` fallback.
- Group and membership mutations re-check the Keycloak administrator role server-side; destructive group deletion and its audit event commit atomically.
- Event filters accept only event types already present in the ledger, and event detail routes remain role-protected.
- The administrator-only location map uses bundled Natural Earth boundaries and approximate cached IP intelligence; it sends no coordinates or map requests to third parties.
- The administrator-only map defaults to bundled Natural Earth boundaries. OpenStreetMap tile requests begin only after an explicit operator opt-in; marker coordinates are not transmitted as data, but the requested tiles disclose the viewed geographic extent along with the administrator's IP and portal origin.
- ORM-parameterized queries are used throughout.
- CSP, clickjacking, MIME-sniffing, referrer, and browser-permission headers are configured.
- Forwarded IP headers are ignored unless `TRUST_PROXY=true` is explicitly configured.