Add register + logout auth flows, and batch-5 resources

Auth (hand-built, uses the auth core):
- /register + register() action: validates, hashes with argon2id (hashPassword),
  creates an emulator-compatible users row (accountCreated/ipRegister/ipCurrent/
  look), redirect kept outside try so NEXT_REDIRECT propagates. Login/register
  cross-links; header shows Register (logged-out) and a Logout (signOut) button.

Batch 5 (parallel agents): /admin/rooms (+[id]) search+detail, /admin/vouchers
(CRUD), /admin/subscriptions (read), /admin/calendar (campaigns+rewards read),
/marketplace (public). Header + admin nav extended.

Verified: tsc exit 0, vitest 48/48, next build exit 0 (52 page routes).
This commit is contained in:
Simo committed 2026-06-28 13:52:32 +02:00
1 parent e8be0461d8
commit 08a9882be8
13 files changed
+1001 -4

No files matched your search

+168
View File
@@ -0,0 +1,168 @@
import Link from "next/link";
import { notFound } from "next/navigation";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
type Campaign = {
id: number;
name: string;
image: string;
startTimestamp: number;
totalDays: number;
lockExpired: string;
enabled: string;
};
type Reward = {
id: number;
campaignId: number;
productName: string;
customImage: string;
credits: number;
pixels: number;
points: number;
pointsType: number;
badge: string;
itemId: number;
subscriptionType: string | null;
subscriptionDays: number;
};
function fmtDate(ts: number): string {
if (!ts) return "—";
return new Date(ts * 1000).toISOString().slice(0, 10);
}
export default async function AdminCalendarCampaign({
params,
}: {
params: Promise<{ id: string }>;
}) {
const { id } = await params;
const campaignId = Number(id);
if (!Number.isInteger(campaignId)) notFound();
let campaign: Campaign | null = null;
try {
campaign = await prisma.calendarCampaigns.findUnique({
where: { id: campaignId },
select: {
id: true,
name: true,
image: true,
startTimestamp: true,
totalDays: true,
lockExpired: true,
enabled: true,
},
});
} catch {
campaign = null;
}
if (!campaign) notFound();
let rewards: Reward[] = [];
try {
rewards = await prisma.calendarRewards.findMany({
where: { campaignId },
select: {
id: true,
campaignId: true,
productName: true,
customImage: true,
credits: true,
pixels: true,
points: true,
pointsType: true,
badge: true,
itemId: true,
subscriptionType: true,
subscriptionDays: true,
},
orderBy: { id: "asc" },
take: 500,
});
} catch {
rewards = [];
}
const disabled = campaign.enabled !== "1";
return (
<main>
<p className="muted">
<Link href="/admin/calendar">← Calendar campaigns</Link>
</p>
<div className="card" style={{ display: "flex", gap: "1.25rem", alignItems: "center", marginBottom: "1.5rem" }}>
{campaign.image ? (
// eslint-disable-next-line @next/next/no-img-element
<img
className="avatar"
src={campaign.image}
alt={campaign.name}
style={{ width: 96, height: 96, objectFit: "cover" }}
/>
) : null}
<div>
<h1 style={{ margin: "0 0 0.25rem" }}>{campaign.name || `Campaign #${campaign.id}`}</h1>
<p className="muted" style={{ margin: 0 }}>
#{campaign.id} · {campaign.totalDays} day{campaign.totalDays === 1 ? "" : "s"} · starts{" "}
{fmtDate(campaign.startTimestamp)}
{disabled ? " · Disabled" : " · Enabled"}
{campaign.lockExpired === "1" ? " · Locks expired days" : ""}
</p>
</div>
</div>
<h2 style={{ marginTop: "1.5rem" }}>Rewards</h2>
{rewards.length === 0 ? (
<p className="muted">No rewards configured for this campaign.</p>
) : (
<table style={{ width: "100%", borderCollapse: "collapse" }}>
<thead>
<tr style={{ textAlign: "left", color: "var(--muted)" }}>
<th>ID</th>
<th>Product</th>
<th>Item</th>
<th>Credits</th>
<th>Pixels</th>
<th>Points</th>
<th>Badge</th>
<th>Subscription</th>
</tr>
</thead>
<tbody>
{rewards.map((r) => (
<tr key={r.id} style={{ borderTop: "1px solid var(--border)" }}>
<td>{r.id}</td>
<td>{r.productName || <span className="muted">—</span>}</td>
<td className="muted">{r.itemId > 0 ? r.itemId : "—"}</td>
<td>{r.credits > 0 ? r.credits : <span className="muted">—</span>}</td>
<td>{r.pixels > 0 ? r.pixels : <span className="muted">—</span>}</td>
<td>
{r.points > 0 ? (
`${r.points} (type ${r.pointsType})`
) : (
<span className="muted">—</span>
)}
</td>
<td className="muted">{r.badge || "—"}</td>
<td className="muted">
{r.subscriptionType
? `${r.subscriptionType} · ${r.subscriptionDays}d`
: "—"}
</td>
</tr>
))}
</tbody>
</table>
)}
<p className="muted" style={{ marginTop: "1rem" }}>
{rewards.length} reward{rewards.length === 1 ? "" : "s"}
</p>
</main>
);
}
+99
View File
@@ -0,0 +1,99 @@
import Link from "next/link";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
type Campaign = {
id: number;
name: string;
image: string;
startTimestamp: number;
totalDays: number;
lockExpired: string;
enabled: string;
};
function fmtDate(ts: number): string {
if (!ts) return "—";
return new Date(ts * 1000).toISOString().slice(0, 10);
}
export default async function AdminCalendar() {
let campaigns: Campaign[] = [];
try {
campaigns = await prisma.calendarCampaigns.findMany({
select: {
id: true,
name: true,
image: true,
startTimestamp: true,
totalDays: true,
lockExpired: true,
enabled: true,
},
orderBy: { id: "desc" },
});
} catch {
campaigns = [];
}
// Tally reward counts per campaign in JS (avoid prisma.groupBy).
const rewardCounts = new Map<number, number>();
try {
const rewards = await prisma.calendarRewards.findMany({
select: { campaignId: true },
});
for (const r of rewards) {
rewardCounts.set(r.campaignId, (rewardCounts.get(r.campaignId) ?? 0) + 1);
}
} catch {
// leave map empty on failure
}
return (
<main>
<h1>Calendar campaigns</h1>
<p className="muted" style={{ marginTop: 0 }}>
Read-only · {campaigns.length} campaign{campaigns.length === 1 ? "" : "s"}.
</p>
{campaigns.length === 0 ? (
<p className="muted">No calendar campaigns found.</p>
) : (
<div className="grid cols-3">
{campaigns.map((c) => {
const disabled = c.enabled !== "1";
const count = rewardCounts.get(c.id) ?? 0;
return (
<Link
key={c.id}
href={`/admin/calendar/${c.id}`}
className="card hover article"
style={{ color: "inherit" }}
>
{c.image ? (
// eslint-disable-next-line @next/next/no-img-element
<img className="article-img" src={c.image} alt={c.name} />
) : (
<div className="article-img" />
)}
<div className="body">
<h3 style={{ margin: "0 0 0.35rem" }}>{c.name || `Campaign #${c.id}`}</h3>
<p className="muted" style={{ margin: 0 }}>
#{c.id} · {c.totalDays} day{c.totalDays === 1 ? "" : "s"} · {count} reward
{count === 1 ? "" : "s"}
</p>
<p className="muted" style={{ margin: "0.35rem 0 0" }}>
Starts {fmtDate(c.startTimestamp)}
{disabled ? " · Disabled" : ""}
{c.lockExpired === "1" ? " · Locks expired" : ""}
</p>
</div>
</Link>
);
})}
</div>
)}
</main>
);
}
+4
View File
@@ -16,11 +16,15 @@ export default async function AdminLayout({ children }: { children: ReactNode })
<nav style={{ display: "grid", gap: "0.45rem" }}>
<Link href="/admin">Dashboard</Link>
<Link href="/admin/users">Users</Link>
<Link href="/admin/rooms">Rooms</Link>
<Link href="/admin/articles">Articles</Link>
<Link href="/admin/catalog">Catalog</Link>
<Link href="/admin/vouchers">Vouchers</Link>
<Link href="/admin/badges">Badges</Link>
<Link href="/admin/radio">Radio</Link>
<Link href="/admin/achievements">Achievements</Link>
<Link href="/admin/subscriptions">Subscriptions</Link>
<Link href="/admin/calendar">Calendar</Link>
<Link href="/admin/rare-values">Rare Values</Link>
<Link href="/admin/photos">Photos</Link>
<Link href="/admin/bans">Bans</Link>
+76
View File
@@ -0,0 +1,76 @@
import Link from "next/link";
import { notFound } from "next/navigation";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export default async function AdminRoomDetail({
params,
}: {
params: Promise<{ id: string }>;
}) {
const { id } = await params;
// rooms is an emulator-owned table → Int id.
const roomId = Number(id);
if (!Number.isInteger(roomId) || roomId <= 0) notFound();
let room: Awaited<ReturnType<typeof prisma.rooms.findUnique>> = null;
try {
room = await prisma.rooms.findUnique({ where: { id: roomId } });
} catch {
room = null;
}
if (!room) notFound();
const fields: Array<[string, string]> = [
["ID", String(room.id)],
["Name", room.name || "(unnamed)"],
["Description", room.description || "—"],
["Owner", `${room.ownerName || "—"} (#${room.ownerId})`],
["State", room.state],
["Users", `${room.users} / ${room.usersMax}`],
["Category", String(room.category)],
["Score", String(room.score)],
["Model", room.model],
["Guild ID", room.guildId ? String(room.guildId) : "—"],
["Tags", room.tags || "—"],
["Password", room.password ? "yes" : "—"],
["Public", room.isPublic === "1" ? "yes" : "no"],
["Staff picked", room.isStaffPicked === "1" ? "yes" : "no"],
["For sale", room.isForSale === "1" ? "yes" : "no"],
["Trade mode", String(room.tradeMode)],
];
return (
<main>
<p className="muted">
<Link href="/admin/rooms">← Rooms</Link>
</p>
<h1>{room.name || "(unnamed)"}</h1>
<p className="muted">
ID {room.id} · owner {room.ownerName || "—"} · {room.users}/{room.usersMax}{" "}
users · {room.state}
</p>
<div className="card">
<table>
<tbody>
{fields.map(([label, value]) => (
<tr key={label}>
<th style={{ width: "35%", whiteSpace: "nowrap" }}>{label}</th>
<td>{value}</td>
</tr>
))}
</tbody>
</table>
</div>
{room.ownerId ? (
<p className="muted" style={{ marginTop: "1rem" }}>
<Link href={`/admin/users/${room.ownerId}`}>View owner →</Link>
</p>
) : null}
</main>
);
}
+128
View File
@@ -0,0 +1,128 @@
import Link from "next/link";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
const PER_PAGE = 25;
type RoomRow = {
id: number;
name: string;
ownerName: string;
users: number;
usersMax: number;
state: string;
category: number;
};
export default async function AdminRooms({
searchParams,
}: {
searchParams: Promise<{ q?: string; page?: string }>;
}) {
const sp = await searchParams;
const q = (sp.q ?? "").trim();
const page = Math.max(1, Number(sp.page ?? "1") || 1);
// Search matches room name OR owner username (ownerName is denormalised on the
// emulator rooms table, so no join is needed).
const where = q
? { OR: [{ name: { contains: q } }, { ownerName: { contains: q } }] }
: {};
let rooms: RoomRow[] = [];
let total = 0;
try {
[rooms, total] = await Promise.all([
prisma.rooms.findMany({
where,
select: {
id: true,
name: true,
ownerName: true,
users: true,
usersMax: true,
state: true,
category: true,
},
orderBy: { id: "desc" },
skip: (page - 1) * PER_PAGE,
take: PER_PAGE,
}),
prisma.rooms.count({ where }),
]);
} catch {
rooms = [];
total = 0;
}
const pages = Math.max(1, Math.ceil(total / PER_PAGE));
const qs = (p: number) =>
`/admin/rooms?q=${encodeURIComponent(q)}&page=${p}`;
return (
<main>
<h1>Rooms</h1>
<form style={{ display: "flex", gap: "0.5rem", marginBottom: "1rem" }}>
<input name="q" defaultValue={q} placeholder="Search room or owner" />
<button type="submit" className="btn btn-primary">
Search
</button>
</form>
<div className="card" style={{ padding: 0, overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>ID</th>
<th>Name</th>
<th>Owner</th>
<th>Users</th>
<th>State</th>
<th>Cat</th>
</tr>
</thead>
<tbody>
{rooms.map((r) => (
<tr key={r.id}>
<td>{r.id}</td>
<td>
<Link href={`/admin/rooms/${r.id}`}>{r.name || "(unnamed)"}</Link>
</td>
<td>{r.ownerName || "—"}</td>
<td>
{r.users} / {r.usersMax}
</td>
<td>{r.state}</td>
<td>{r.category}</td>
</tr>
))}
</tbody>
</table>
</div>
{rooms.length === 0 ? (
<p className="muted" style={{ marginTop: "1rem" }}>
No rooms found.
</p>
) : null}
<p className="muted" style={{ marginTop: "1rem" }}>
Page {page} / {pages} · {total} rooms
{page > 1 ? (
<>
{" · "}
<Link href={qs(page - 1)}>← Prev</Link>
</>
) : null}
{page < pages ? (
<>
{" · "}
<Link href={qs(page + 1)}>Next →</Link>
</>
) : null}
</p>
</main>
);
}
+74
View File
@@ -0,0 +1,74 @@
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
type SubRow = {
id: number;
userId: number | null;
subscriptionType: string | null;
expiresAt: number;
};
function fmt(ts: number): string {
return new Date(ts * 1000).toISOString().slice(0, 16).replace("T", " ");
}
export default async function AdminSubscriptions() {
const now = Math.floor(Date.now() / 1000);
let active: SubRow[] = [];
try {
// Schema has no timestamp_end column; expiry = timestamp_start + duration.
// Active subs are active=1 with a computed expiry still in the future.
const rows = await prisma.usersSubscriptions.findMany({
where: { active: 1 },
orderBy: { id: "desc" },
take: 500,
});
active = rows
.map((r) => ({
id: r.id,
userId: r.userId,
subscriptionType: r.subscriptionType,
expiresAt: (r.timestampStart ?? 0) + (r.duration ?? 0),
}))
.filter((r) => r.expiresAt > now)
.sort((a, b) => a.expiresAt - b.expiresAt);
} catch {
active = [];
}
return (
<main>
<h1>Subscriptions</h1>
<p className="muted" style={{ marginTop: "-0.25rem", marginBottom: "1rem" }}>
Active Habbo Club / VIP subscriptions (expiry &gt; now). Read-only.
</p>
<div className="card">
<table>
<thead>
<tr>
<th>Sub ID</th>
<th>User ID</th>
<th>Type</th>
<th>Expires</th>
</tr>
</thead>
<tbody>
{active.map((s) => (
<tr key={s.id}>
<td>{s.id}</td>
<td>{s.userId ?? "—"}</td>
<td>{s.subscriptionType ?? "—"}</td>
<td className="muted">{fmt(s.expiresAt)}</td>
</tr>
))}
</tbody>
</table>
{active.length === 0 ? <p className="muted">No active subscriptions.</p> : null}
</div>
</main>
);
}
+123
View File
@@ -0,0 +1,123 @@
import { createVoucher, deleteVoucher } from "@/actions/admin-vouchers";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
type VoucherRow = {
id: bigint;
code: string;
amount: number;
maxUses: number;
useCount: number;
expiresAt: Date | null;
createdAt: Date | null;
};
function fmtDate(d: Date | null): string {
if (!d) return "—";
return d.toISOString().slice(0, 16).replace("T", " ");
}
export default async function AdminVouchers() {
const now = Date.now();
let vouchers: VoucherRow[] = [];
try {
vouchers = await prisma.websiteShopVouchers.findMany({
select: {
id: true,
code: true,
amount: true,
maxUses: true,
useCount: true,
expiresAt: true,
createdAt: true,
},
orderBy: { id: "desc" },
take: 200,
});
} catch {
vouchers = [];
}
return (
<main>
<h1>Shop Vouchers</h1>
<p className="muted">
Codes redeemable on the website shop for a balance top-up. Each user can
use a given voucher once, up to its max uses.
</p>
<form action={createVoucher} className="card" style={{ marginBottom: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>New voucher</h3>
<div className="grid cols-2" style={{ marginBottom: "0.75rem" }}>
<label style={{ display: "flex", flexDirection: "column", gap: "0.3rem" }}>
<span className="muted">Code</span>
<input name="code" placeholder="SUMMER2026" maxLength={255} required />
</label>
<label style={{ display: "flex", flexDirection: "column", gap: "0.3rem" }}>
<span className="muted">Amount (balance added)</span>
<input name="amount" type="number" min={1} placeholder="50" required />
</label>
<label style={{ display: "flex", flexDirection: "column", gap: "0.3rem" }}>
<span className="muted">Max uses</span>
<input name="maxUses" type="number" min={1} defaultValue={1} required />
</label>
<label style={{ display: "flex", flexDirection: "column", gap: "0.3rem" }}>
<span className="muted">Expires at (optional)</span>
<input name="expiresAt" type="datetime-local" />
</label>
</div>
<button type="submit" className="btn btn-primary">Create voucher</button>
</form>
<div className="card">
<table>
<thead>
<tr>
<th>Code</th>
<th>Amount</th>
<th>Uses</th>
<th>Expires</th>
<th>Created</th>
<th />
</tr>
</thead>
<tbody>
{vouchers.map((v) => {
const expired = v.expiresAt ? v.expiresAt.getTime() <= now : false;
const usedUp = v.maxUses > 0 && v.useCount >= v.maxUses;
return (
<tr key={v.id.toString()}>
<td>
<code>{v.code}</code>
{expired ? (
<span className="muted"> · expired</span>
) : usedUp ? (
<span className="muted"> · used up</span>
) : null}
</td>
<td>{v.amount}</td>
<td>
{v.useCount} / {v.maxUses}
</td>
<td className="muted">{fmtDate(v.expiresAt)}</td>
<td className="muted">{fmtDate(v.createdAt)}</td>
<td>
<form action={deleteVoucher}>
<input type="hidden" name="id" value={v.id.toString()} />
<button type="submit" className="btn btn-danger">
Delete
</button>
</form>
</td>
</tr>
);
})}
</tbody>
</table>
{vouchers.length === 0 ? <p className="muted">No vouchers yet.</p> : null}
</div>
</main>
);
}