Merge branch 'main' of https://gitlab.epicnabbo.nl/remco/EpicNext-Cms into codex/housekeeping-complete
This commit is contained in:
commit
139e8cfc3a
26 files changed
+427
-876
No files matched your search
@@ -3,21 +3,8 @@
|
||||
import { asc } from "drizzle-orm";
|
||||
import { requirePermission } from "@/lib/admin/guard";
|
||||
import { db, WebsiteHousekeepingPermissions } from "@/lib/db";
|
||||
import { redirectSafe } from "@/lib/foundation/security";
|
||||
import { PERMS } from "@/lib/permissions";
|
||||
|
||||
/**
|
||||
* Housekeeping table writes are retired. Runtime access uses ACL only.
|
||||
* Redirect editors to live Permissions.
|
||||
*/
|
||||
async function rejectLegacyHousekeepingWrite(): Promise<never> {
|
||||
await requirePermission(PERMS.SETTINGS_EDIT);
|
||||
return redirectSafe(
|
||||
"/admin/permissions?from=housekeeping",
|
||||
"/admin/permissions",
|
||||
);
|
||||
}
|
||||
|
||||
export async function exportPermissions(): Promise<string> {
|
||||
await requirePermission(PERMS.SETTINGS_VIEW);
|
||||
|
||||
@@ -37,7 +24,3 @@ export async function exportPermissions(): Promise<string> {
|
||||
|
||||
return JSON.stringify(perms, null, 2);
|
||||
}
|
||||
|
||||
export async function applyPreset(_formData: FormData): Promise<void> {
|
||||
return rejectLegacyHousekeepingWrite();
|
||||
}
|
||||
@@ -5,20 +5,9 @@ import { db, WebsiteSetting } from "@/lib/db";
|
||||
import { PERMS } from "@/lib/permissions";
|
||||
import { adminAction } from "@/lib/safe-action";
|
||||
import { actionOk } from "@/lib/safe-action-shared";
|
||||
import {
|
||||
cleanupConvertedSwfs,
|
||||
deleteImportedItem,
|
||||
} from "@/lib/services/furni-import";
|
||||
import { deleteImportedItem } from "@/lib/services/furni-import";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
export const cleanSwfFiles = adminAction(
|
||||
{ permission: PERMS.ASSETS_IMPORT },
|
||||
async () => {
|
||||
const result = await cleanupConvertedSwfs();
|
||||
return actionOk(result as unknown as Record<string, unknown>);
|
||||
},
|
||||
);
|
||||
|
||||
const deleteSchema = z.object({ classname: z.string().trim().min(1) });
|
||||
|
||||
export const deleteImportedFurni = adminAction(
|
||||
|
||||
+1
-39
@@ -3,13 +3,11 @@
|
||||
import { eq } from "drizzle-orm";
|
||||
import { db, WebsiteTicket, WebsiteTicketMessage } from "@/lib/db";
|
||||
import { PERMS } from "@/lib/permissions";
|
||||
import { adminAction, authAction } from "@/lib/safe-action";
|
||||
import { adminAction } from "@/lib/safe-action";
|
||||
import { ActionError, actionOk } from "@/lib/safe-action-shared";
|
||||
import { logAudit } from "@/lib/services/audit";
|
||||
import { notify } from "@/lib/services/webhook";
|
||||
import {
|
||||
assignTicketSchema,
|
||||
createTicketSchema,
|
||||
replyTicketSchema,
|
||||
updateTicketPrioritySchema,
|
||||
updateTicketStatusSchema,
|
||||
@@ -17,42 +15,6 @@ import {
|
||||
|
||||
// ── User actions (authenticated, no admin perms needed) ──────────────
|
||||
|
||||
export const createTicket = authAction(
|
||||
{
|
||||
schema: createTicketSchema,
|
||||
rateLimitKey: "ticket-create",
|
||||
rateLimitMax: 5,
|
||||
rateLimitWindowMs: 60_000,
|
||||
},
|
||||
async (ctx) => {
|
||||
const now = new Date();
|
||||
const [result] = await db.insert(WebsiteTicket).values({
|
||||
subject: ctx.data.subject,
|
||||
category: ctx.data.category,
|
||||
creatorId: ctx.session.user.id,
|
||||
updatedAt: now,
|
||||
});
|
||||
const ticketId = Number(result.insertId);
|
||||
|
||||
// Create the first message
|
||||
await db.insert(WebsiteTicketMessage).values({
|
||||
ticketId,
|
||||
userId: ctx.session.user.id,
|
||||
message: ctx.data.message,
|
||||
isStaff: 0,
|
||||
});
|
||||
|
||||
notify({
|
||||
action: "ticket_create",
|
||||
actor: ctx.session.user.username,
|
||||
target: `#${ticketId} - ${ctx.data.subject}`,
|
||||
details: `Category: ${ctx.data.category}`,
|
||||
});
|
||||
|
||||
return actionOk({ id: ticketId });
|
||||
},
|
||||
);
|
||||
|
||||
export const adminReplyTicket = adminAction(
|
||||
{
|
||||
permission: [PERMS.TICKETS_EDIT, PERMS.MOD_TICKETS_EDIT],
|
||||
|
||||
Reference in new issue
Block a user