Harden catalog writes: bulk import batch + field allowlists.
Local Build and Deploy / deploy (push) Successful in 1m16s
Local Build and Deploy / deploy (push) Successful in 1m16s
Bulk import resolves names from items_base and refreshes RCON once. Page/item updates only accept an allowlisted field set. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
b52e25578d
commit
2ff5b47104
4 files changed
+288
-50
No files matched your search
@@ -7,12 +7,55 @@ import { prisma } from "@/lib/prisma";
|
||||
import { rcon } from "@/lib/services/rcon";
|
||||
import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
|
||||
const BC_PAGE_FIELDS = [
|
||||
"caption",
|
||||
"parentId",
|
||||
"pageLayout",
|
||||
"enabled",
|
||||
"visible",
|
||||
"orderNum",
|
||||
"iconImage",
|
||||
"iconColor",
|
||||
"pageHeadline",
|
||||
"pageTeaser",
|
||||
"pageSpecial",
|
||||
"pageText1",
|
||||
"pageText2",
|
||||
"pageTextDetails",
|
||||
"pageTextTeaser",
|
||||
] as const;
|
||||
|
||||
const BC_ITEM_FIELDS = [
|
||||
"itemIds",
|
||||
"catalogName",
|
||||
"orderNumber",
|
||||
"extradata",
|
||||
"pageId",
|
||||
] as const;
|
||||
|
||||
function pickAllowed(
|
||||
fields: Record<string, unknown>,
|
||||
allowed: readonly string[],
|
||||
) {
|
||||
const out: Record<string, unknown> = {};
|
||||
for (const key of allowed) {
|
||||
if (Object.hasOwn(fields, key) && fields[key] !== undefined) {
|
||||
out[key] = fields[key];
|
||||
}
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
export async function updateBcPage({
|
||||
id,
|
||||
...fields
|
||||
}: { id: number } & Record<string, unknown>) {
|
||||
const staff = await requirePermission(PERMS.CATALOG_EDIT);
|
||||
await prisma.catalogPagesBc.update({ where: { id }, data: fields as any });
|
||||
const data = pickAllowed(fields, BC_PAGE_FIELDS);
|
||||
if (Object.keys(data).length === 0) {
|
||||
return { ok: false as const, error: "No valid fields to update" };
|
||||
}
|
||||
await prisma.catalogPagesBc.update({ where: { id }, data: data as any });
|
||||
await rcon.updateCatalog();
|
||||
await logStaffActivity({
|
||||
staffId: staff.id,
|
||||
@@ -51,7 +94,11 @@ export async function updateBcItem({
|
||||
extradata?: string;
|
||||
}) {
|
||||
const staff = await requirePermission(PERMS.CATALOG_EDIT);
|
||||
await prisma.catalogItemsBc.update({ where: { id }, data: data as any });
|
||||
const safe = pickAllowed(data as Record<string, unknown>, BC_ITEM_FIELDS);
|
||||
if (Object.keys(safe).length === 0) {
|
||||
return { ok: false as const, error: "No valid fields to update" };
|
||||
}
|
||||
await prisma.catalogItemsBc.update({ where: { id }, data: safe as any });
|
||||
await rcon.updateCatalog();
|
||||
await logStaffActivity({
|
||||
staffId: staff.id,
|
||||
|
||||
Reference in new issue
Block a user