Commit Graph

19 Commits

Author SHA1 Message Date
bdb4d0cf32 feat: add login page and API 2026-03-04 02:04:50 +08:00
e2b4105fb6 fix: remove font overrides to use Tailwind configuration 2026-03-04 02:04:02 +08:00
0329bd2ff6 fix: improve font configuration for Chinese support 2026-03-04 02:03:22 +08:00
f3b0d79ef9 feat: update root layout with metadata
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 02:02:31 +08:00
cf7d3d5618 fix: use streaming and add path validation
- Replace fs.readFileSync() with fs.createReadStream() to prevent memory exhaustion
- Export validatePath() from fs-utils.ts
- Use validatePath() to validate full path including project and version parameters
- Fix incomplete path traversal protection
- Add filename encoding in Content-Disposition header

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 02:01:38 +08:00
7d5ee36f56 feat: add /api/download endpoint for APK file downloads
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 02:00:36 +08:00
91c94bde88 fix: add URL encoding and remove unused import
- Add encodeURIComponent() for project, version, and filename parameters in downloadUrl to prevent XSS and URL breakage
- Remove unused formatDateTime import

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:59:53 +08:00
0d1ba31175 feat: add /api/apks endpoint 2026-03-04 01:58:52 +08:00
c032c7fd5d feat: add /api/versions endpoint 2026-03-04 01:57:46 +08:00
5be115d323 feat: add /api/projects endpoint 2026-03-04 01:56:47 +08:00
7609e99076 fix: use constant for cookie value and remove unused import
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:56:14 +08:00
db479c9da1 feat: implement simple cookie-based authentication middleware 2026-03-04 01:54:56 +08:00
2a883c23f9 fix: address race conditions and add path validation
- Fixed race condition in getProjects() by using Promise.all with proper async/await
- Fixed race condition in getVersions() by using Promise.all with proper async/await
- Fixed race condition in getApks() by ensuring Promise.all wraps the async map
- Added validatePath() helper function to prevent path traversal attacks
- Applied path validation to all file system operations

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:54:07 +08:00
5e00e36e57 feat: add file system utility functions 2026-03-04 01:52:44 +08:00
c4a25fced2 fix: address security concerns in constants (path and credentials)
Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:52:02 +08:00
af080cee2a feat: add constants configuration 2026-03-04 01:51:09 +08:00
37e2e2e7d3 fix: remove .env.local from git and add .env.example
Remove credentials file from git tracking and provide template for
environment variables.

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:49:47 +08:00
9b793b9b93 feat: initialize Next.js project with Tailwind CSS and SWR
- Initialize Next.js 16.1.6 with TypeScript and App Router
- Configure Tailwind CSS for styling
- Install SWR for API state management
- Set up environment variables for authentication and resource path
- Update .gitignore to track .env.local

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-03-04 01:47:15 +08:00
a78f029e03 Initial commit from Create Next App 2026-03-04 01:45:44 +08:00