Commit Graph
1671 Commits
Author SHA1 Message Date
Neko Ayaka eb35c4d66a refactor(*): cleaner provider design, simplified chat store 2026-08-08 01:34:44 +08:00
Neko 8df21d09d6 fix(stage-tamagotchi): guard background material by platform (#2235) 2026-08-07 00:16:59 +08:00
Neko Ayaka 6aba0dcb03 fix(stage-tamagotchi): cleanup tray related resources before app quit 2026-08-06 05:25:38 +08:00
ff7f64ace8 feat(server): add Steam OpenID sign-in and account linking plugin (#2226)
## Summary

Adds a self-contained better-auth plugin
(`server/apps/api/src/libs/auth-plugins/steam.ts`) implementing Steam
OpenID 2.0 sign-in, account linking, and callback verification via "dumb
mode".

Steam's web login is OpenID 2.0, not OAuth2/OIDC, so it cannot be
registered as a `socialProviders` entry, and better-auth has no plugin
hook for extending its OAuth2 endpoints with a non-OAuth2 protocol. The
plugin therefore adds the endpoints Steam's protocol needs: `POST
/sign-in/steam`, `POST /link/steam`, and `GET /steam/callback`.

- Callback verification uses OpenID "dumb mode"
(`openid.mode=check_authentication`): one extra round trip to Steam
instead of managing RSA association state.
- New sign-ups get a placeholder `<steamid64>@steam.placeholder.local`
with `emailVerified: true`, mirroring Apple Sign In's
`<sub>@apple.placeholder.local`.
- The plugin's request/query schemas use Zod; a `// NOTICE:` documents
that better-auth's OpenAPI generator is Zod-native. Steam verification
uses `ofetch`.
- Wires Steam into `apps/ui-server-auth` sign-in and profile "Connected
accounts", plus the shared `OAuthProvider` / `defaultSignInProviders` in
`packages/stage-ui`.
- Linking routes through `/link/steam` via the client's `$fetch`;
unlinking needs no special-casing (`/unlink-account` already takes a
free-form `providerId`).

No Steam Web API key is required for this browser-based flow.

We intentionally do not depend on community Steam packages (e.g.
`better-auth-steam`) or the still-open upstream draft
([better-auth#4877](https://github.com/better-auth/better-auth/pull/4877)).
Steam never returns an email, and we need sign-up that does not ask the
user for one plus first-class account linking; the available options
either require an email at sign-in, lack linking, or are abandoned /
blocked — shipping a small in-tree plugin is the safer auth dependency
for this requirement.

## Test plan

- [x] `pnpm exec vitest run
server/apps/api/src/libs/auth-plugins/steam.test.ts` — 6/6 passing
- [x] `pnpm -F @proj-airi/ui-server-auth exec vitest run` — 32/32
passing
- [x] `pnpm -F @proj-airi/stage-ui exec vitest run
src/libs/steam-auth-client.test.ts
src/composables/use-linked-accounts.test.ts` — 5/5 passing
- [x] `pnpm -F @proj-airi/api-server typecheck`
- [x] `pnpm -F @proj-airi/ui-server-auth typecheck`
- [x] `pnpm -F @proj-airi/stage-ui typecheck`

## Follow-ups

- Desktop Steam ticket sign-in (top of this stack): silent startup
ticket exchange for Steam builds; the server resolves or creates the
AIRI user for the verified SteamID before issuing an OIDC code.
- Steam persona name/avatar via `GetPlayerSummaries` inside the plugin,
if display names beyond `Steam User <id>` are wanted.

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
2026-08-05 23:57:55 +08:00
Neko Ayaka b4f9c53ad4 revert fix(electron): make remote inspector opening configurable 2026-08-05 03:35:10 +08:00
RainbowBird bd841d546f fix(electron): make remote inspector opening configurable (#2156) 2026-08-05 00:28:51 +08:00
Neko 7dc8e2c4a3 refactor(stage-ui): improve onboarding, scrollable, and animated (#2215) 2026-08-04 17:51:15 +08:00
Lovehsigure_520 9164ca1bab ci(stage-tamagotchi): add Steam desktop deployment workflow (#1827) 2026-08-04 16:44:40 +08:00
Neko e502efa301 fix(stage-tamagotchi): register router hot updates (#2211) 2026-08-04 15:37:58 +08:00
Neko 9ef61afcd6 fix(stage-tamagotchi): synchronize fade and click-through (#2210) 2026-08-04 15:10:24 +08:00
Neko Ayaka 93af669d14 fix(stage-pocket): guard for beatsync 2026-08-04 04:22:58 +08:00
Neko Ayaka 1226417768 refactor(*): new button 2026-08-04 03:24:32 +08:00
RainbowBird 4ccde2c96e chore: move the server to an independent folder 2026-08-02 18:43:57 +08:00
Garfield Lee cfd9c26f09 feat(stage-tamagotchi-godot): migrate C# projects to .NET 10 (#2169) 2026-08-02 18:43:24 +08:00
RainbowBird 9aa27af108 chore(server): cleanup unused scripts 2026-08-02 17:34:31 +08:00
RainbowBird 61e5470801 chore(server): remove otel config 2026-08-02 17:33:37 +08:00
RainbowBird 4d6e61f77d docs(server): cleanup ai context 2026-08-02 00:10:40 +08:00
RainbowBird 71dd65cb99 fix(rate-limit): clarify trusted proxy documentation and improve client address handling 2026-07-31 22:58:05 +08:00
RainbowBird bbad277671 fix(ui-server-auth): bust poisoned asset caches (#2196) 2026-07-31 22:56:17 +08:00
RainbowBird 2a34a52fdc feat(rate-limit): implement RATE_LIMIT_TRUSTED_PROXY for Railway deployments and update related documentation 2026-07-31 22:16:01 +08:00
RainbowBird 81b8a4d5b4 feat(server): add grouped provider fallback routing (#2170) 2026-07-31 00:22:06 +08:00
Doji 2109446ea4 fix(stage-pocket): enable Android audio input device selection (#2180) 2026-07-30 20:39:50 +08:00
vuyua9 7a94fcfc27 fix(server): sync character engagement counters on deletion (#1871) 2026-07-30 12:06:05 +00:00
RainbowBird 269de5b9e1 fix(server): support native Apple ID token sign-in (#2176) 2026-07-30 19:02:10 +08:00
RainbowBird 204197b8b4 feat(routing): add 404 page and update redirects for proper asset handling 2026-07-30 14:36:15 +08:00
RainbowBird 0ae8c87295 chore(analytics): remove Plausible integration
Signed-off-by: RainbowBird <git@luoling.moe>

Commit-Message-Assisted-by: Claude (via Claude Code)
2026-07-30 14:36:15 +08:00
Neko Ayaka 1927e54c9c fix(stage-ui,stage-pocket,stage-web,stage-tamagotchi,ui-server-auth): analytics import not deferred or lazied 2026-07-30 14:33:21 +08:00
RainbowBird fe470ff81c fix(vite): update rolldownOptions to prevent chunk blocking in Safari 2026-07-30 13:37:56 +08:00
Columbina f63294487f fix(auth-ui): remove unavailable analytics script (#2168)
## Summary

Removes the obsolete Plausible helper script from the hosted auth UI.

## Root cause

The helper endpoint returns 404 on the sign-in page, creating a failed
`script.js` request. The auth UI already uses PostHog, so the unused
Plausible bootstrap can be removed safely.

Fixes #2165.

## Validation

- `pnpm -F @proj-airi/ui-server-auth typecheck`
- `pnpm -F @proj-airi/ui-server-auth lint`
- `pnpm -F @proj-airi/ui-server-auth build`
- `pnpm typecheck`

Deployment is needed to verify the end-to-end hosted sign-in result,
because the local server requires a database configuration that is not
available in this checkout.
2026-07-30 00:14:49 +08:00
RainbowBird 97cf26082f refactor(ui): share user avatar fallbacks (#2143) 2026-07-29 18:38:37 +08:00
RainbowBird c1ca39f1e6 feat(server): add Apple sign-in (#2158) 2026-07-29 18:06:07 +08:00
RainbowBird 742bb80ca5 feat(stage): add global button analytics directive (#2146) 2026-07-29 15:59:53 +08:00
藍+85CD 880d1bf7a9 feat(stage-ui-tachie): add tachie support (#2115) 2026-07-28 23:35:30 +08:00
RainbowBird acbbab0bd7 fix(server): correct observability dashboard signals (#2142) 2026-07-28 21:48:03 +08:00
RainbowBird ae35b580d8 feat(stage): group chat controls and track speech mute (#2139) 2026-07-28 19:34:14 +08:00
RainbowBird 899131b0a1 feat(stage): add persistent speech mute controls (#2128) 2026-07-28 17:58:50 +08:00
5884b0bdba fix(server): validate synced message ownership (#2054)
Co-authored-by: RainbowBird <git@luoling.moe>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
2026-07-27 01:38:32 +08:00
Anfi1andRainbowBird 42925e58f5 feat(stage-tamagotchi): universal TTS stop button in controls island (#2072)
Co-authored-by: RainbowBird <git@luoling.moe>
2026-07-23 00:21:58 +08:00
eabec9a64f feat(stage-ui-mmd): add MMD support (#1997)
---------

Co-authored-by: nyueki <nyuek.i@proton.me>
Co-authored-by: autofix-ci[bot] <114827586+autofix-ci[bot]@users.noreply.github.com>
Co-authored-by: Neko Ayaka <neko@ayaka.moe>
Co-authored-by-agent: Unknown
2026-07-20 16:13:55 +08:00
0xSelenicDove 78d6588cb0 feat(stage-*): add clickable VRM body-part reactions (#2068) 2026-07-20 16:13:03 +08:00
0xSelenicDove 38f7460558 fix(stage-tamagotchi): refresh chats after import (#2088) 2026-07-20 16:10:11 +08:00
Neko Ayaka dbf8124888 release: v0.11.3 2026-07-19 04:03:59 +08:00
Neko Ayaka b43b8944bf release: v0.11.2 2026-07-18 10:37:13 +08:00
Lulu f6b1818abd docs(ui-server-auth): fix stale server-dev auth UI domain in README (#2031) 2026-07-17 17:55:53 +08:00
0xSelenicDove 0eb46620a5 feat(stage-tamagotchi): add desktop chat list (#2065) 2026-07-17 17:54:10 +08:00
0xSelenicDove 8893ba81a6 fix(*): harden local service boundaries (#2062) 2026-07-17 17:50:50 +08:00
Neko Ayaka 089ca99108 release: v0.11.1 2026-07-17 03:35:49 +08:00
RainbowBird c74ed2ff7b fix(server): improve ai generation analytics correlation 2026-07-15 19:06:34 +08:00
RainbowBird 3543a60d3c feat(auth): integrate useAuthProviderSync across multiple components and add tests 2026-07-15 17:26:05 +08:00
RainbowBird 73258b5aba feat: align PostHog API host with airi.build 2026-07-14 23:18:49 +08:00