No admin by username, no Swagger in production, no exception text to clients

S14 and the privacy items of P0:
- signing up as "admin" no longer grants admin; `PrivaPub admin promote
  <root>` (and `demote`) does, run on the box against the configured
  database;
- Swagger is served in Development only;
- every service and controller answers "Something went wrong." where it
  used to send ex.Message, and the SMTP warnings no longer log the
  recipient's address;
- sign-up and login no longer log the IP, User-Agent and root id together;
- invitation sign-up takes the persona's own AvatarUserName (and optional
  AvatarName) instead of naming the avatar after the private login, and
  refuses a persona username equal to the login's. Invitation login uses
  the named persona, creating it if it is new;
- recovery mail comes from "PrivaPub", not collAnon's support address name.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 10:58:39 +02:00
1 parent 2eb2a63f1e
commit 0f85030744
11 files changed
+144 -76

No files matched your search

+18 -25
View File
@@ -64,13 +64,6 @@ namespace PrivaPub.Services
UserName = signUpForm.UserName,
HashedPassword = signUpPasswordHashed
};
if (signUpForm.UserName == "admin")
{
newUser.Policies.Clear();
newUser.Policies.Add(Policies.IsAdmin);
newUser.Policies.Add(Policies.IsUser);
newUser.Policies.Add(Policies.IsModerator);
}
var cultureLanguage = CultureInfo.CurrentCulture.TwoLetterISOLanguageName;
var language = await DbEntities.Languages.Match(l => l.International2Code == cultureLanguage).ExecuteFirstAsync();
@@ -111,7 +104,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(SignUpAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -165,7 +158,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(LoginAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -192,7 +185,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -230,7 +223,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserSettingsAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -259,7 +252,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UpdateUserPasswordAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -291,7 +284,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(RemoveUserAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -310,7 +303,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(BanUserAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -329,7 +322,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(UnbanUserAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -357,7 +350,7 @@ namespace PrivaPub.Services
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(GetUserSettingsAsync)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -448,30 +441,30 @@ namespace PrivaPub.Services
{
var toParsed = await smtpClient.VerifyAsync(user.Email);
if (toParsed == null)
return result.Invalidate($"Invalid email of {user.Email}.", (int)SmtpStatusCode.MailboxUnavailable);
return result.Invalidate(Localizer["Invalid email."], (int)SmtpStatusCode.MailboxUnavailable);
}
catch (OperationCanceledException ex)
{
Logger.LogWarning(
$"SMTP operation canceled exception at email verification of {user.Email}. Exception=[{ex.Message}]");
"SMTP operation canceled at email verification: {Error}", ex.Message);
}
catch (SmtpCommandException ex)
{
Logger.LogWarning(
$"SMTP command exception at email verification of {user.Email}. Exception=[{ex.Message}]");
"SMTP command exception at email verification: {Error}", ex.Message);
}
catch (SmtpProtocolException ex)
{
Logger.LogWarning(
$"SMTP protocol exception at email verification of {user.Email}. Exception=[{ex.Message}]");
"SMTP protocol exception at email verification: {Error}", ex.Message);
}
catch (Exception ex)
{
Logger.LogWarning($"General exception at email verification of {user.Email}. Exception=[{ex.Message}]");
Logger.LogWarning("Exception at email verification: {Error}", ex.Message);
}
var message = new MimeMessage();
message.From.Add(new MailboxAddress(Localizer["Eugene - collAnon support"], AppConfigurationService.AppConfiguration.EmailConfiguration.SmtpUsername));
message.From.Add(new MailboxAddress("PrivaPub", AppConfigurationService.AppConfiguration.EmailConfiguration.SmtpUsername));
message.To.Add(MailboxAddress.Parse(user.Email));
message.Subject = Localizer["PrivaPub - Password recovery link"];
message.Body = new TextPart("plain")
@@ -501,7 +494,7 @@ Eugene from collAnon, following is the password recovery link:
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(SetupAndSendRecoveryEmail)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -519,7 +512,7 @@ Eugene from collAnon, following is the password recovery link:
}
catch (Exception ex)
{
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}
@@ -555,7 +548,7 @@ Eugene from collAnon, following is the password recovery link:
catch (Exception ex)
{
Logger.LogError(ex, $"{nameof(RootUsersService)}.{nameof(ChangePassword)}()");
return result.Invalidate(ex.Message, exception: ex);
return result.Invalidate(Localizer["Something went wrong."], exception: ex);
}
}