feat: add Staff Activity Log (audit trail) page

This commit is contained in:
remco committed 2026-07-01 18:44:32 +02:00
1 parent beb36d2dbf
commit 393e6ccbee
1 file changed
+126 -204
+126 -204
View File
@@ -3,246 +3,157 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic";
const CRITICAL = new Set(["critical", "error", "danger"]);
// chatlogs_room and commandlogs are @@ignore'd in the schema (no PK), so Prisma
// generates no delegate for them — they are read via $queryRaw against the real
// emulator columns. chatlogs_private has a delegate (prisma.chatlogsPrivate) but
// is read here via $queryRaw too, mirroring the room-chat section and selecting
// defensively so a column mismatch degrades to an empty list rather than a 500.
// alert_logs has a proper delegate (prisma.alertLogs).
type ChatlogRoomRow = {
room_id: number;
user_from_id: number;
user_to_id: number;
message: string;
timestamp: number;
};
type ChatlogPrivateRow = {
user_from_id: number;
user_to_id: number;
message: string;
timestamp: number;
};
type CommandlogRow = {
user_id: number;
timestamp: number;
command: string;
params: string;
succes: string;
};
function fromUnix(ts: number | null | undefined): string {
if (!ts || Number(ts) <= 0) return "—";
return new Date(Number(ts) * 1000)
.toISOString()
.slice(0, 16)
.replace("T", " ");
}
const PER_PAGE = 25;
function fromDate(d: Date | null | undefined): string {
return d ? d.toISOString().slice(0, 16).replace("T", " ") : "—";
}
export default async function AdminLogs() {
let chatlogs: ChatlogRoomRow[] = [];
try {
chatlogs = await prisma.$queryRaw<ChatlogRoomRow[]>`
SELECT room_id, user_from_id, user_to_id, message, timestamp
FROM chatlogs_room
ORDER BY timestamp DESC
LIMIT 50
`;
} catch {
chatlogs = [];
export default async function AdminStaffActivities({
searchParams,
}: {
searchParams: Promise<{ q?: string; page?: string; staffId?: string; action?: string }>;
}) {
const sp = await searchParams;
const q = (sp.q ?? "").trim();
const page = Math.max(1, Number(sp.page ?? "1") || 1);
const staffId = sp.staffId ? Number(sp.staffId) : null;
const action = sp.action ?? null;
let whereClause = {};
if (q) {
whereClause = {
OR: [
{ action: { contains: q } },
{ description: { contains: q } },
{ ipAddress: { contains: q } },
],
};
}
// Private (whisper) chat. Defensive SELECT + try/catch — the table may be
// absent or have differing columns on some emulators, in which case we show
// an empty section instead of crashing the page.
let privateChatlogs: ChatlogPrivateRow[] = [];
try {
privateChatlogs = await prisma.$queryRaw<ChatlogPrivateRow[]>`
SELECT user_from_id, user_to_id, message, timestamp
FROM chatlogs_private
ORDER BY timestamp DESC
LIMIT 50
`;
} catch {
privateChatlogs = [];
if (staffId) {
whereClause = {
...whereClause,
userId: BigInt(staffId),
};
}
let commandlogs: CommandlogRow[] = [];
try {
commandlogs = await prisma.$queryRaw<CommandlogRow[]>`
SELECT user_id, timestamp, command, params, succes
FROM commandlogs
ORDER BY timestamp DESC
LIMIT 50
`;
} catch {
commandlogs = [];
if (action) {
whereClause = {
...whereClause,
action: { contains: action },
};
}
let alertLogs: Awaited<ReturnType<typeof prisma.alertLogs.findMany>> = [];
try {
alertLogs = await prisma.alertLogs.findMany({
orderBy: { id: "desc" },
take: 50,
});
} catch {
alertLogs = [];
}
const activities = await prisma.staffActivities
.findMany({
where: whereClause,
select: {
id: true,
userId: true,
username: true,
action: true,
description: true,
targetType: true,
targetId: true,
ipAddress: true,
createdAt: true,
},
orderBy: { createdAt: "desc" },
skip: (page - 1) * PER_PAGE,
take: PER_PAGE,
})
.catch(() => []);
const total = await prisma.staffActivities.count({ where: whereClause }).catch(() => 0);
const pages = Math.max(1, Math.ceil(total / PER_PAGE));
const onlineCount = activities.filter((a) => a.createdAt && new Date(a.createdAt).getTime() > Date.now() - 60000).length;
return (
<main>
<h1>Logs</h1>
<h1>Staff Activities</h1>
<p className="muted" style={{ marginTop: "-0.4rem" }}>
Read-only · 50 most recent of each.
Auditor trail of all staff actions in the hotel.
</p>
<div className="admin-stats">
<StatusCard label="Room chat" value={chatlogs.length} icon="💬" />
<StatusCard label="Private chat" value={privateChatlogs.length} icon="🔒" />
<StatusCard label="Commands" value={commandlogs.length} icon="⌨️" />
<StatusCard label="Alerts" value={alertLogs.length} icon="🔔" />
<StatusCard label="Total activities" value={total} icon="📋" />
<StatusCard label="On this page" value={activities.length} icon="📄" />
<StatusCard
label="Recent (≤1min)"
value={onlineCount}
state={onlineCount > 0 ? "ok" : "neutral"}
icon="🟢"
/>
</div>
<section className="card" style={{ marginBottom: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>Room chat ({chatlogs.length})</h3>
{chatlogs.length === 0 ? (
<p className="muted">No room chat logs.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>Room</th>
<th>From</th>
<th>To</th>
<th>Message</th>
</tr>
</thead>
<tbody>
{chatlogs.map((c, i) => (
<tr key={`${c.timestamp}-${c.user_from_id}-${i}`}>
<td className="muted">{fromUnix(c.timestamp)}</td>
<td>{String(c.room_id)}</td>
<td>{String(c.user_from_id)}</td>
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td>
<td>{c.message}</td>
</tr>
))}
</tbody>
</table>
</div>
<form
className="card"
style={{ display: "flex", gap: "0.5rem", marginBottom: "1.5rem", flexWrap: "wrap" }}
>
<input
name="q"
defaultValue={q}
placeholder="Search action, description, IP..."
style={{ flex: 1, minWidth: 200 }}
/>
<input
name="staffId"
defaultValue={staffId?.toString()}
placeholder="Staff ID"
style={{ width: 120 }}
/>
<input
name="action"
defaultValue={action}
placeholder="Action type (e.g., rank_change)"
style={{ width: 160 }}
/>
<button type="submit" className="btn btn-primary">
Filter
</button>
{(q || staffId || action) && (
<a href="/admin/logs" className="btn btn-outline">
Clear filters
</a>
)}
</section>
</form>
<section className="card" style={{ marginBottom: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>Private chat ({privateChatlogs.length})</h3>
{privateChatlogs.length === 0 ? (
<p className="muted">No private chat logs.</p>
<section className="admin-section">
<h2>Activities ({total})</h2>
{activities.length === 0 ? (
<p className="muted">No staff activities match this search.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>From</th>
<th>To</th>
<th>Message</th>
<th>Staff</th>
<th>Action</th>
<th>Description</th>
<th>Target</th>
<th>IP Address</th>
</tr>
</thead>
<tbody>
{privateChatlogs.map((c, i) => (
<tr key={`${c.timestamp}-${c.user_from_id}-${c.user_to_id}-${i}`}>
<td className="muted">{fromUnix(c.timestamp)}</td>
<td>{String(c.user_from_id)}</td>
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td>
<td>{c.message}</td>
</tr>
))}
</tbody>
</table>
</div>
)}
</section>
<section className="card" style={{ marginBottom: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>Commands ({commandlogs.length})</h3>
{commandlogs.length === 0 ? (
<p className="muted">No command logs.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>User</th>
<th>Command</th>
<th>Params</th>
<th>OK</th>
</tr>
</thead>
<tbody>
{commandlogs.map((c, i) => (
<tr key={`${c.timestamp}-${c.user_id}-${i}`}>
<td className="muted">{fromUnix(c.timestamp)}</td>
<td>{String(c.user_id)}</td>
<td>{c.command}</td>
<td className="muted">{c.params}</td>
<td>
<span className={`admin-badge ${c.succes === "yes" ? "ok" : "danger"}`}>
{c.succes === "yes" ? "OK" : "FAIL"}
</span>
</td>
</tr>
))}
</tbody>
</table>
</div>
)}
</section>
<section className="card">
<h3 style={{ marginTop: 0 }}>Alerts ({alertLogs.length})</h3>
{alertLogs.length === 0 ? (
<p className="muted">No alert logs.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>Type</th>
<th>Severity</th>
<th>Message</th>
<th>Read</th>
</tr>
</thead>
<tbody>
{alertLogs.map((a) => (
{activities.map((a) => (
<tr key={String(a.id)}>
<td className="muted">{fromDate(a.createdAt)}</td>
<td>{a.type}</td>
<td className="muted" style={{ whiteSpace: "nowrap" }}>{fromDate(a.createdAt)}</td>
<td className="muted">#{a.userId} ({a.username ?? "unknown"})</td>
<td>
<span
className={`admin-badge ${CRITICAL.has((a.severity || "").toLowerCase()) ? "danger" : ""}`}
>
{a.severity || "—"}
</span>
<span className="admin-badge">{a.action}</span>
</td>
<td>{a.message}</td>
<td>{a.description}</td>
<td>
<span className={`admin-badge ${a.isRead ? "ok" : ""}`}>
{a.isRead ? "read" : "new"}
</span>
{a.targetType && a.targetId ? (
<span className="muted">{a.targetType === "user" ? "User " : ""}#{String(a.targetId)}</span>
) : (
<span className="muted">—</span>
)}
</td>
<td className="muted">{a.ipAddress || "—"}</td>
</tr>
))}
</tbody>
@@ -250,6 +161,17 @@ export default async function AdminLogs() {
</div>
)}
</section>
<p className="muted">
Page {page} / {pages} · {total} activities
{page < pages ? (
<>
{" · "}
<a href={`/admin/logs?q=${encodeURIComponent(q)}&staffId=${staffId || ""}&action=${action || ""}&page=${page + 1}`}>Next →</a>
</>
) : null}
</p>
</main>
);
}