feat: add Staff Activity Log (audit trail) page
This commit is contained in:
1 parent
beb36d2dbf
commit
393e6ccbee
1 file changed
+126
-204
+126
-204
@@ -3,246 +3,157 @@ import { prisma } from "@/lib/prisma";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
const CRITICAL = new Set(["critical", "error", "danger"]);
|
||||
|
||||
// chatlogs_room and commandlogs are @@ignore'd in the schema (no PK), so Prisma
|
||||
// generates no delegate for them — they are read via $queryRaw against the real
|
||||
// emulator columns. chatlogs_private has a delegate (prisma.chatlogsPrivate) but
|
||||
// is read here via $queryRaw too, mirroring the room-chat section and selecting
|
||||
// defensively so a column mismatch degrades to an empty list rather than a 500.
|
||||
// alert_logs has a proper delegate (prisma.alertLogs).
|
||||
|
||||
type ChatlogRoomRow = {
|
||||
room_id: number;
|
||||
user_from_id: number;
|
||||
user_to_id: number;
|
||||
message: string;
|
||||
timestamp: number;
|
||||
};
|
||||
|
||||
type ChatlogPrivateRow = {
|
||||
user_from_id: number;
|
||||
user_to_id: number;
|
||||
message: string;
|
||||
timestamp: number;
|
||||
};
|
||||
|
||||
type CommandlogRow = {
|
||||
user_id: number;
|
||||
timestamp: number;
|
||||
command: string;
|
||||
params: string;
|
||||
succes: string;
|
||||
};
|
||||
|
||||
function fromUnix(ts: number | null | undefined): string {
|
||||
if (!ts || Number(ts) <= 0) return "—";
|
||||
return new Date(Number(ts) * 1000)
|
||||
.toISOString()
|
||||
.slice(0, 16)
|
||||
.replace("T", " ");
|
||||
}
|
||||
const PER_PAGE = 25;
|
||||
|
||||
function fromDate(d: Date | null | undefined): string {
|
||||
return d ? d.toISOString().slice(0, 16).replace("T", " ") : "—";
|
||||
}
|
||||
|
||||
export default async function AdminLogs() {
|
||||
let chatlogs: ChatlogRoomRow[] = [];
|
||||
try {
|
||||
chatlogs = await prisma.$queryRaw<ChatlogRoomRow[]>`
|
||||
SELECT room_id, user_from_id, user_to_id, message, timestamp
|
||||
FROM chatlogs_room
|
||||
ORDER BY timestamp DESC
|
||||
LIMIT 50
|
||||
`;
|
||||
} catch {
|
||||
chatlogs = [];
|
||||
export default async function AdminStaffActivities({
|
||||
searchParams,
|
||||
}: {
|
||||
searchParams: Promise<{ q?: string; page?: string; staffId?: string; action?: string }>;
|
||||
}) {
|
||||
const sp = await searchParams;
|
||||
const q = (sp.q ?? "").trim();
|
||||
const page = Math.max(1, Number(sp.page ?? "1") || 1);
|
||||
const staffId = sp.staffId ? Number(sp.staffId) : null;
|
||||
const action = sp.action ?? null;
|
||||
|
||||
let whereClause = {};
|
||||
if (q) {
|
||||
whereClause = {
|
||||
OR: [
|
||||
{ action: { contains: q } },
|
||||
{ description: { contains: q } },
|
||||
{ ipAddress: { contains: q } },
|
||||
],
|
||||
};
|
||||
}
|
||||
|
||||
// Private (whisper) chat. Defensive SELECT + try/catch — the table may be
|
||||
// absent or have differing columns on some emulators, in which case we show
|
||||
// an empty section instead of crashing the page.
|
||||
let privateChatlogs: ChatlogPrivateRow[] = [];
|
||||
try {
|
||||
privateChatlogs = await prisma.$queryRaw<ChatlogPrivateRow[]>`
|
||||
SELECT user_from_id, user_to_id, message, timestamp
|
||||
FROM chatlogs_private
|
||||
ORDER BY timestamp DESC
|
||||
LIMIT 50
|
||||
`;
|
||||
} catch {
|
||||
privateChatlogs = [];
|
||||
if (staffId) {
|
||||
whereClause = {
|
||||
...whereClause,
|
||||
userId: BigInt(staffId),
|
||||
};
|
||||
}
|
||||
|
||||
let commandlogs: CommandlogRow[] = [];
|
||||
try {
|
||||
commandlogs = await prisma.$queryRaw<CommandlogRow[]>`
|
||||
SELECT user_id, timestamp, command, params, succes
|
||||
FROM commandlogs
|
||||
ORDER BY timestamp DESC
|
||||
LIMIT 50
|
||||
`;
|
||||
} catch {
|
||||
commandlogs = [];
|
||||
if (action) {
|
||||
whereClause = {
|
||||
...whereClause,
|
||||
action: { contains: action },
|
||||
};
|
||||
}
|
||||
|
||||
let alertLogs: Awaited<ReturnType<typeof prisma.alertLogs.findMany>> = [];
|
||||
try {
|
||||
alertLogs = await prisma.alertLogs.findMany({
|
||||
orderBy: { id: "desc" },
|
||||
take: 50,
|
||||
});
|
||||
} catch {
|
||||
alertLogs = [];
|
||||
}
|
||||
const activities = await prisma.staffActivities
|
||||
.findMany({
|
||||
where: whereClause,
|
||||
select: {
|
||||
id: true,
|
||||
userId: true,
|
||||
username: true,
|
||||
action: true,
|
||||
description: true,
|
||||
targetType: true,
|
||||
targetId: true,
|
||||
ipAddress: true,
|
||||
createdAt: true,
|
||||
},
|
||||
orderBy: { createdAt: "desc" },
|
||||
skip: (page - 1) * PER_PAGE,
|
||||
take: PER_PAGE,
|
||||
})
|
||||
.catch(() => []);
|
||||
|
||||
const total = await prisma.staffActivities.count({ where: whereClause }).catch(() => 0);
|
||||
const pages = Math.max(1, Math.ceil(total / PER_PAGE));
|
||||
|
||||
const onlineCount = activities.filter((a) => a.createdAt && new Date(a.createdAt).getTime() > Date.now() - 60000).length;
|
||||
|
||||
return (
|
||||
<main>
|
||||
<h1>Logs</h1>
|
||||
<h1>Staff Activities</h1>
|
||||
<p className="muted" style={{ marginTop: "-0.4rem" }}>
|
||||
Read-only · 50 most recent of each.
|
||||
Auditor trail of all staff actions in the hotel.
|
||||
</p>
|
||||
|
||||
<div className="admin-stats">
|
||||
<StatusCard label="Room chat" value={chatlogs.length} icon="💬" />
|
||||
<StatusCard label="Private chat" value={privateChatlogs.length} icon="🔒" />
|
||||
<StatusCard label="Commands" value={commandlogs.length} icon="⌨️" />
|
||||
<StatusCard label="Alerts" value={alertLogs.length} icon="🔔" />
|
||||
<StatusCard label="Total activities" value={total} icon="📋" />
|
||||
<StatusCard label="On this page" value={activities.length} icon="📄" />
|
||||
<StatusCard
|
||||
label="Recent (≤1min)"
|
||||
value={onlineCount}
|
||||
state={onlineCount > 0 ? "ok" : "neutral"}
|
||||
icon="🟢"
|
||||
/>
|
||||
</div>
|
||||
|
||||
<section className="card" style={{ marginBottom: "1.5rem" }}>
|
||||
<h3 style={{ marginTop: 0 }}>Room chat ({chatlogs.length})</h3>
|
||||
{chatlogs.length === 0 ? (
|
||||
<p className="muted">No room chat logs.</p>
|
||||
) : (
|
||||
<div style={{ overflowX: "auto" }}>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>When</th>
|
||||
<th>Room</th>
|
||||
<th>From</th>
|
||||
<th>To</th>
|
||||
<th>Message</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{chatlogs.map((c, i) => (
|
||||
<tr key={`${c.timestamp}-${c.user_from_id}-${i}`}>
|
||||
<td className="muted">{fromUnix(c.timestamp)}</td>
|
||||
<td>{String(c.room_id)}</td>
|
||||
<td>{String(c.user_from_id)}</td>
|
||||
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td>
|
||||
<td>{c.message}</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
<form
|
||||
className="card"
|
||||
style={{ display: "flex", gap: "0.5rem", marginBottom: "1.5rem", flexWrap: "wrap" }}
|
||||
>
|
||||
<input
|
||||
name="q"
|
||||
defaultValue={q}
|
||||
placeholder="Search action, description, IP..."
|
||||
style={{ flex: 1, minWidth: 200 }}
|
||||
/>
|
||||
<input
|
||||
name="staffId"
|
||||
defaultValue={staffId?.toString()}
|
||||
placeholder="Staff ID"
|
||||
style={{ width: 120 }}
|
||||
/>
|
||||
<input
|
||||
name="action"
|
||||
defaultValue={action}
|
||||
placeholder="Action type (e.g., rank_change)"
|
||||
style={{ width: 160 }}
|
||||
/>
|
||||
<button type="submit" className="btn btn-primary">
|
||||
Filter
|
||||
</button>
|
||||
{(q || staffId || action) && (
|
||||
<a href="/admin/logs" className="btn btn-outline">
|
||||
Clear filters
|
||||
</a>
|
||||
)}
|
||||
</section>
|
||||
</form>
|
||||
|
||||
<section className="card" style={{ marginBottom: "1.5rem" }}>
|
||||
<h3 style={{ marginTop: 0 }}>Private chat ({privateChatlogs.length})</h3>
|
||||
{privateChatlogs.length === 0 ? (
|
||||
<p className="muted">No private chat logs.</p>
|
||||
<section className="admin-section">
|
||||
<h2>Activities ({total})</h2>
|
||||
{activities.length === 0 ? (
|
||||
<p className="muted">No staff activities match this search.</p>
|
||||
) : (
|
||||
<div style={{ overflowX: "auto" }}>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>When</th>
|
||||
<th>From</th>
|
||||
<th>To</th>
|
||||
<th>Message</th>
|
||||
<th>Staff</th>
|
||||
<th>Action</th>
|
||||
<th>Description</th>
|
||||
<th>Target</th>
|
||||
<th>IP Address</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{privateChatlogs.map((c, i) => (
|
||||
<tr key={`${c.timestamp}-${c.user_from_id}-${c.user_to_id}-${i}`}>
|
||||
<td className="muted">{fromUnix(c.timestamp)}</td>
|
||||
<td>{String(c.user_from_id)}</td>
|
||||
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td>
|
||||
<td>{c.message}</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</section>
|
||||
|
||||
<section className="card" style={{ marginBottom: "1.5rem" }}>
|
||||
<h3 style={{ marginTop: 0 }}>Commands ({commandlogs.length})</h3>
|
||||
{commandlogs.length === 0 ? (
|
||||
<p className="muted">No command logs.</p>
|
||||
) : (
|
||||
<div style={{ overflowX: "auto" }}>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>When</th>
|
||||
<th>User</th>
|
||||
<th>Command</th>
|
||||
<th>Params</th>
|
||||
<th>OK</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{commandlogs.map((c, i) => (
|
||||
<tr key={`${c.timestamp}-${c.user_id}-${i}`}>
|
||||
<td className="muted">{fromUnix(c.timestamp)}</td>
|
||||
<td>{String(c.user_id)}</td>
|
||||
<td>{c.command}</td>
|
||||
<td className="muted">{c.params}</td>
|
||||
<td>
|
||||
<span className={`admin-badge ${c.succes === "yes" ? "ok" : "danger"}`}>
|
||||
{c.succes === "yes" ? "OK" : "FAIL"}
|
||||
</span>
|
||||
</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
</table>
|
||||
</div>
|
||||
)}
|
||||
</section>
|
||||
|
||||
<section className="card">
|
||||
<h3 style={{ marginTop: 0 }}>Alerts ({alertLogs.length})</h3>
|
||||
{alertLogs.length === 0 ? (
|
||||
<p className="muted">No alert logs.</p>
|
||||
) : (
|
||||
<div style={{ overflowX: "auto" }}>
|
||||
<table>
|
||||
<thead>
|
||||
<tr>
|
||||
<th>When</th>
|
||||
<th>Type</th>
|
||||
<th>Severity</th>
|
||||
<th>Message</th>
|
||||
<th>Read</th>
|
||||
</tr>
|
||||
</thead>
|
||||
<tbody>
|
||||
{alertLogs.map((a) => (
|
||||
{activities.map((a) => (
|
||||
<tr key={String(a.id)}>
|
||||
<td className="muted">{fromDate(a.createdAt)}</td>
|
||||
<td>{a.type}</td>
|
||||
<td className="muted" style={{ whiteSpace: "nowrap" }}>{fromDate(a.createdAt)}</td>
|
||||
<td className="muted">#{a.userId} ({a.username ?? "unknown"})</td>
|
||||
<td>
|
||||
<span
|
||||
className={`admin-badge ${CRITICAL.has((a.severity || "").toLowerCase()) ? "danger" : ""}`}
|
||||
>
|
||||
{a.severity || "—"}
|
||||
</span>
|
||||
<span className="admin-badge">{a.action}</span>
|
||||
</td>
|
||||
<td>{a.message}</td>
|
||||
<td>{a.description}</td>
|
||||
<td>
|
||||
<span className={`admin-badge ${a.isRead ? "ok" : ""}`}>
|
||||
{a.isRead ? "read" : "new"}
|
||||
</span>
|
||||
{a.targetType && a.targetId ? (
|
||||
<span className="muted">{a.targetType === "user" ? "User " : ""}#{String(a.targetId)}</span>
|
||||
) : (
|
||||
<span className="muted">—</span>
|
||||
)}
|
||||
</td>
|
||||
<td className="muted">{a.ipAddress || "—"}</td>
|
||||
</tr>
|
||||
))}
|
||||
</tbody>
|
||||
@@ -250,6 +161,17 @@ export default async function AdminLogs() {
|
||||
</div>
|
||||
)}
|
||||
</section>
|
||||
|
||||
<p className="muted">
|
||||
Page {page} / {pages} · {total} activities
|
||||
{page < pages ? (
|
||||
<>
|
||||
{" · "}
|
||||
<a href={`/admin/logs?q=${encodeURIComponent(q)}&staffId=${staffId || ""}&action=${action || ""}&page=${page + 1}`}>Next →</a>
|
||||
</>
|
||||
) : null}
|
||||
</p>
|
||||
</main>
|
||||
);
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user