Add register + logout auth flows, and batch-5 resources

Auth (hand-built, uses the auth core):
- /register + register() action: validates, hashes with argon2id (hashPassword),
  creates an emulator-compatible users row (accountCreated/ipRegister/ipCurrent/
  look), redirect kept outside try so NEXT_REDIRECT propagates. Login/register
  cross-links; header shows Register (logged-out) and a Logout (signOut) button.

Batch 5 (parallel agents): /admin/rooms (+[id]) search+detail, /admin/vouchers
(CRUD), /admin/subscriptions (read), /admin/calendar (campaigns+rewards read),
/marketplace (public). Header + admin nav extended.

Verified: tsc exit 0, vitest 48/48, next build exit 0 (52 page routes).
This commit is contained in:
Simo committed 2026-06-28 13:52:32 +02:00
1 parent e8be0461d8
commit 08a9882be8
13 files changed
+1001 -4

No files matched your search

+66
View File
@@ -0,0 +1,66 @@
"use server";
import { revalidatePath } from "next/cache";
import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
export async function createVoucher(formData: FormData): Promise<void> {
await requireStaff();
const code = String(formData.get("code") ?? "").trim().slice(0, 255);
const amount = Number(formData.get("amount"));
const maxUsesRaw = Number(formData.get("maxUses"));
const maxUses = Number.isFinite(maxUsesRaw) && maxUsesRaw > 0 ? Math.floor(maxUsesRaw) : 1;
if (!code || !(amount > 0)) return;
const expiresRaw = String(formData.get("expiresAt") ?? "").trim();
let expiresAt: Date | null = null;
if (expiresRaw) {
const parsed = new Date(expiresRaw);
if (!Number.isNaN(parsed.getTime())) expiresAt = parsed;
}
const now = new Date();
try {
await prisma.websiteShopVouchers.create({
data: {
code,
amount: Math.floor(amount),
maxUses,
useCount: 0,
expiresAt,
createdAt: now,
updatedAt: now,
},
});
} catch {
// Unique constraint on `code` (or DB unavailable) — swallow and re-render.
return;
}
revalidatePath("/admin/vouchers");
}
export async function deleteVoucher(formData: FormData): Promise<void> {
await requireStaff();
const raw = String(formData.get("id") ?? "").trim();
if (!raw) return;
let id: bigint;
try {
id = BigInt(raw);
} catch {
return;
}
try {
await prisma.websiteShopVouchers.delete({ where: { id } });
} catch {
return;
}
revalidatePath("/admin/vouchers");
}
+61
View File
@@ -0,0 +1,61 @@
"use server";
import { headers } from "next/headers";
import { redirect } from "next/navigation";
import { hashPassword } from "@/lib/auth/password";
import { prisma } from "@/lib/prisma";
const USERNAME_RE = /^[A-Za-z0-9_\-=?!@:.,]{3,25}$/;
const EMAIL_RE = /^[^@\s]+@[^@\s]+\.[^@\s]+$/;
// A valid starter Habbo figure so the avatar renders in-client immediately.
const DEFAULT_LOOK = "hr-100-.hd-180-1.ch-255-66.lg-280-110.sh-305-62";
export async function register(formData: FormData): Promise<void> {
const username = String(formData.get("username") ?? "").trim();
const mail = String(formData.get("mail") ?? "").trim().toLowerCase();
const password = String(formData.get("password") ?? "");
let error: string | null = null;
if (!USERNAME_RE.test(username)) error = "Username must be 3-25 valid characters";
else if (password.length < 6) error = "Password must be at least 6 characters";
else if (!EMAIL_RE.test(mail)) error = "Enter a valid email address";
// Uniqueness check (kept out of the success path's try so NEXT_REDIRECT propagates).
if (!error) {
try {
const existing = await prisma.user.findUnique({
where: { username },
select: { id: true },
});
if (existing) error = "That username is already taken";
} catch {
error = "Registration is temporarily unavailable";
}
}
if (!error) {
const h = await headers();
const ip =
h.get("x-forwarded-for")?.split(",")[0]?.trim() ?? h.get("x-real-ip") ?? "0.0.0.0";
const now = Math.floor(Date.now() / 1000);
try {
await prisma.user.create({
data: {
username,
password: await hashPassword(password),
mail,
accountCreated: now,
ipRegister: ip,
ipCurrent: ip,
look: DEFAULT_LOOK,
},
});
} catch {
error = "Could not create the account (is the username unique?)";
}
}
// redirect() throws NEXT_REDIRECT — must be OUTSIDE any try/catch.
if (error) redirect(`/register?error=${encodeURIComponent(error)}`);
redirect("/login?registered=1");
}