Fill the remaining gaps: badge upload, radio tools, VPN, writeable boxes

Built the admin tools previously listed as missing:
- Badge upload (/admin/badges): uploads a <code>.gif into the emulator's
  badge dir via BADGE_UPLOAD_DIR (node:fs); validated code/type/size,
  logged. Made configurable rather than skipped.
- Radio tools: /admin/radio/api-keys (CRUD, server-generated keys),
  /admin/radio/autodj (Auto-DJ playlist CRUD), /admin/radio/embed (embed
  snippet generator), /admin/radio/points (points settings),
  /admin/radio/monitoring (live stream/now-playing/listeners status).
  radio_api_keys + radio_auto_dj_playlist already had real columns.
- /admin/vpn: VPN/proxy detection config (block toggle + provider + key),
  complementing /admin/ip's raw blacklist.
- Writeable boxes: new website_writeable_boxes table (model + migration
  0006) + /admin/writeable-boxes CRUD; active boxes render on the public
  home page. env: BADGE_UPLOAD_DIR.

Verified live (prod, amx_test): all 8 pages render with real data; a test
writeable box appeared on the public home and was reverted. tsc 0,
vitest 49/49, next build 0 (7 new admin routes).
This commit is contained in:
Simo committed 2026-06-28 21:04:34 +02:00
1 parent e004dfedaf
commit 0cd4d06ff6
21 files changed
+2443 -61

No files matched your search

+226
View File
@@ -0,0 +1,226 @@
import Link from "next/link";
import { createApiKey, deleteApiKey, toggleApiKey } from "@/actions/admin-radio-api-keys";
import { StatusCard } from "@/components/admin/dashboard";
import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
export const metadata = { title: "Radio API Keys" };
type ApiKey = {
id: bigint;
name: string;
key: string;
allowedIps: string | null;
rateLimit: number;
lastUsedAt: Date | null;
expiresAt: Date | null;
isActive: boolean;
createdAt: Date | null;
};
function formatDate(d: Date | null): string {
return d ? d.toISOString().slice(0, 16).replace("T", " ") : "—";
}
/** Show only the first 8 chars of the secret; the rest stays masked. */
function maskKey(key: string): string {
return key.length > 8 ? `${key.slice(0, 8)}…` : key;
}
export default async function AdminRadioApiKeysPage() {
let keys: ApiKey[] = [];
let dbError = false;
try {
keys = await prisma.radioApiKeys
.findMany({
select: {
id: true,
name: true,
key: true,
allowedIps: true,
rateLimit: true,
lastUsedAt: true,
expiresAt: true,
isActive: true,
createdAt: true,
},
orderBy: [{ isActive: "desc" }, { id: "desc" }],
take: 500,
})
.catch(() => {
dbError = true;
return [];
});
} catch {
dbError = true;
keys = [];
}
const total = keys.length;
const activeCount = keys.filter((k) => k.isActive).length;
const inactiveCount = total - activeCount;
return (
<main>
<nav className="muted" style={{ marginBottom: "0.5rem" }}>
<Link href="/admin/radio">Radio</Link> ·{" "}
<Link href="/admin/radio/settings">Settings</Link> ·{" "}
<Link href="/admin/radio/api-keys">API Keys</Link> ·{" "}
<Link href="/admin/radio/autodj">AutoDJ</Link> ·{" "}
<Link href="/admin/radio/embed">Embed</Link> ·{" "}
<Link href="/admin/radio/points">Points</Link> ·{" "}
<Link href="/admin/radio/monitoring">Monitoring</Link>
</nav>
<section className="admin-section">
<h1>Radio API Keys</h1>
<p className="muted" style={{ marginTop: "-0.4rem" }}>
API keys for external radio integrations (<code>radio_api_keys</code>). Keys are generated
server-side and shown masked — copy the full value from the database when first issued.
</p>
{dbError ? (
<div className="card" style={{ marginTop: "1rem" }}>
<p className="muted" style={{ margin: 0 }}>
Could not load API keys (database unavailable).
</p>
</div>
) : (
<div className="admin-stats">
<StatusCard label="Total keys" value={total} icon="🔑" />
<StatusCard
label="Active"
value={activeCount}
state={activeCount > 0 ? "ok" : "neutral"}
icon="✅"
/>
<StatusCard
label="Inactive"
value={inactiveCount}
state={inactiveCount > 0 ? "warn" : "neutral"}
icon="🚫"
/>
</div>
)}
</section>
<section className="admin-section">
<h2>Generate key</h2>
<p className="muted" style={{ marginTop: "-0.4rem" }}>
The secret key is generated automatically with cryptographic randomness — you do not enter
it.
</p>
<form action={createApiKey} className="card">
<div className="grid cols-2">
<div>
<label htmlFor="new_name" style={{ display: "block", fontWeight: 700 }}>
Name
</label>
<input
id="new_name"
name="name"
placeholder="AzureCast bridge"
required
maxLength={255}
style={{ width: "100%" }}
/>
</div>
<div>
<label htmlFor="new_rateLimit" style={{ display: "block", fontWeight: 700 }}>
Rate limit (requests/min)
</label>
<input
id="new_rateLimit"
name="rateLimit"
type="number"
min={0}
defaultValue={300}
style={{ width: "100%" }}
/>
</div>
<div style={{ gridColumn: "1 / -1" }}>
<label htmlFor="new_allowedIps" style={{ display: "block", fontWeight: 700 }}>
Allowed IPs (optional)
</label>
<input
id="new_allowedIps"
name="allowedIps"
placeholder="comma-separated, blank = any"
maxLength={255}
style={{ width: "100%" }}
/>
</div>
</div>
<div style={{ marginTop: "0.75rem" }}>
<button type="submit" className="btn btn-primary">
Generate key
</button>
</div>
</form>
</section>
<section className="admin-section">
<h2>Existing keys ({total})</h2>
{total === 0 ? (
<p className="muted">No API keys yet — generate one above.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>#</th>
<th>Name</th>
<th>Key</th>
<th>Allowed IPs</th>
<th>Rate limit</th>
<th>Last used</th>
<th>Expires</th>
<th>Status</th>
<th>Actions</th>
</tr>
</thead>
<tbody>
{keys.map((k) => (
<tr key={String(k.id)}>
<td className="muted">{String(k.id)}</td>
<td>{k.name}</td>
<td>
<code title="Only the first 8 characters are shown">{maskKey(k.key)}</code>
</td>
<td className="muted">{k.allowedIps || "any"}</td>
<td className="muted">{k.rateLimit}/min</td>
<td className="muted">{formatDate(k.lastUsedAt)}</td>
<td className="muted">{formatDate(k.expiresAt)}</td>
<td>
<span className={`admin-badge ${k.isActive ? "ok" : "danger"}`}>
{k.isActive ? "active" : "inactive"}
</span>
</td>
<td>
<div style={{ display: "inline-flex", gap: "0.4rem" }}>
<form action={toggleApiKey}>
<input type="hidden" name="id" value={String(k.id)} />
<button type="submit" className="btn">
{k.isActive ? "Deactivate" : "Activate"}
</button>
</form>
<form action={deleteApiKey}>
<input type="hidden" name="id" value={String(k.id)} />
<button type="submit" className="btn btn-danger">
Delete
</button>
</form>
</div>
</td>
</tr>
))}
</tbody>
</table>
</div>
)}
</section>
</main>
);
}