feat(photos): community film strip uploads + admin moderation

Backend
- photos table + upload storage under DATA_DIR/uploads (magic-byte sniffing,
  no multipart dep, SVG rejected, wx exclusive writes)
- POST/GET /api/photos, GET /api/photos/:id/file with nosniff + sandboxed CSP
- admin routes (ADMIN_EMAILS allowlist): list, delete one, clear all
- identity-keyed rate limits (login 20/15m, signup 5/h, upload 60/h)
- cookie gains Secure when the request is https (via trustProxy)
- /api/auth/me now 200 {user:null} instead of 401 when signed out

Frontend
- landing strip section: signed-in users upload straight from the reel,
  guests get a /app?auth=1 link
- /admin page: grid of uploads with delete + clear all
- nginx: nosniff / X-Frame-Options / Referrer-Policy, forward
  X-Forwarded-Proto so the API can mark cookies Secure behind TLS

Tests: docker/backend test/security.mjs (45 checks)
This commit is contained in:
2026-09-17 22:35:12 +07:00
parent 9ba2667c6c
commit ffdefd2c9c
15 changed files with 871 additions and 18 deletions
+13
View File
@@ -227,6 +227,19 @@ html { scroll-behavior: smooth; scroll-padding-top: 78px; }
.lp-marquee:hover .lp-track { animation-play-state: paused; }
@keyframes lp-marquee { from { transform: translateX(0); } to { transform: translateX(-50%); } }
@media (prefers-reduced-motion: reduce) { .lp-track { animation: none; } }
/* Contribute control above the reel. The strip itself stays centred on the
viewport, so this head is the only wrapped part of the marquee section. */
.lp-film-head {
display: flex;
flex-wrap: wrap;
align-items: flex-end;
justify-content: space-between;
gap: 16px;
margin-bottom: 22px;
}
.lp-film-head > div { max-width: 620px; }
.lp-film-head h2 { font-size: clamp(20px, 3vw, 30px); margin-top: 8px; }
.lp-film-head p { color: var(--lp-muted); margin-top: 8px; font-size: 13.5px; }
.lp-frame {
width: 236px;
margin-right: 18px;