feat: add Staff Activity Log (audit trail) page

This commit is contained in:
remco committed 2026-07-01 18:44:32 +02:00
1 parent beb36d2dbf
commit 393e6ccbee
1 file changed
+126 -204
+126 -204
View File
@@ -3,246 +3,157 @@ import { prisma } from "@/lib/prisma";
export const dynamic = "force-dynamic"; export const dynamic = "force-dynamic";
const CRITICAL = new Set(["critical", "error", "danger"]); const PER_PAGE = 25;
// chatlogs_room and commandlogs are @@ignore'd in the schema (no PK), so Prisma
// generates no delegate for them — they are read via $queryRaw against the real
// emulator columns. chatlogs_private has a delegate (prisma.chatlogsPrivate) but
// is read here via $queryRaw too, mirroring the room-chat section and selecting
// defensively so a column mismatch degrades to an empty list rather than a 500.
// alert_logs has a proper delegate (prisma.alertLogs).
type ChatlogRoomRow = {
room_id: number;
user_from_id: number;
user_to_id: number;
message: string;
timestamp: number;
};
type ChatlogPrivateRow = {
user_from_id: number;
user_to_id: number;
message: string;
timestamp: number;
};
type CommandlogRow = {
user_id: number;
timestamp: number;
command: string;
params: string;
succes: string;
};
function fromUnix(ts: number | null | undefined): string {
if (!ts || Number(ts) <= 0) return "—";
return new Date(Number(ts) * 1000)
.toISOString()
.slice(0, 16)
.replace("T", " ");
}
function fromDate(d: Date | null | undefined): string { function fromDate(d: Date | null | undefined): string {
return d ? d.toISOString().slice(0, 16).replace("T", " ") : "—"; return d ? d.toISOString().slice(0, 16).replace("T", " ") : "—";
} }
export default async function AdminLogs() { export default async function AdminStaffActivities({
let chatlogs: ChatlogRoomRow[] = []; searchParams,
try { }: {
chatlogs = await prisma.$queryRaw<ChatlogRoomRow[]>` searchParams: Promise<{ q?: string; page?: string; staffId?: string; action?: string }>;
SELECT room_id, user_from_id, user_to_id, message, timestamp }) {
FROM chatlogs_room const sp = await searchParams;
ORDER BY timestamp DESC const q = (sp.q ?? "").trim();
LIMIT 50 const page = Math.max(1, Number(sp.page ?? "1") || 1);
`; const staffId = sp.staffId ? Number(sp.staffId) : null;
} catch { const action = sp.action ?? null;
chatlogs = [];
let whereClause = {};
if (q) {
whereClause = {
OR: [
{ action: { contains: q } },
{ description: { contains: q } },
{ ipAddress: { contains: q } },
],
};
} }
// Private (whisper) chat. Defensive SELECT + try/catch — the table may be if (staffId) {
// absent or have differing columns on some emulators, in which case we show whereClause = {
// an empty section instead of crashing the page. ...whereClause,
let privateChatlogs: ChatlogPrivateRow[] = []; userId: BigInt(staffId),
try { };
privateChatlogs = await prisma.$queryRaw<ChatlogPrivateRow[]>`
SELECT user_from_id, user_to_id, message, timestamp
FROM chatlogs_private
ORDER BY timestamp DESC
LIMIT 50
`;
} catch {
privateChatlogs = [];
} }
let commandlogs: CommandlogRow[] = []; if (action) {
try { whereClause = {
commandlogs = await prisma.$queryRaw<CommandlogRow[]>` ...whereClause,
SELECT user_id, timestamp, command, params, succes action: { contains: action },
FROM commandlogs };
ORDER BY timestamp DESC
LIMIT 50
`;
} catch {
commandlogs = [];
} }
let alertLogs: Awaited<ReturnType<typeof prisma.alertLogs.findMany>> = []; const activities = await prisma.staffActivities
try { .findMany({
alertLogs = await prisma.alertLogs.findMany({ where: whereClause,
orderBy: { id: "desc" }, select: {
take: 50, id: true,
}); userId: true,
} catch { username: true,
alertLogs = []; action: true,
} description: true,
targetType: true,
targetId: true,
ipAddress: true,
createdAt: true,
},
orderBy: { createdAt: "desc" },
skip: (page - 1) * PER_PAGE,
take: PER_PAGE,
})
.catch(() => []);
const total = await prisma.staffActivities.count({ where: whereClause }).catch(() => 0);
const pages = Math.max(1, Math.ceil(total / PER_PAGE));
const onlineCount = activities.filter((a) => a.createdAt && new Date(a.createdAt).getTime() > Date.now() - 60000).length;
return ( return (
<main> <main>
<h1>Logs</h1> <h1>Staff Activities</h1>
<p className="muted" style={{ marginTop: "-0.4rem" }}> <p className="muted" style={{ marginTop: "-0.4rem" }}>
Read-only · 50 most recent of each. Auditor trail of all staff actions in the hotel.
</p> </p>
<div className="admin-stats"> <div className="admin-stats">
<StatusCard label="Room chat" value={chatlogs.length} icon="💬" /> <StatusCard label="Total activities" value={total} icon="📋" />
<StatusCard label="Private chat" value={privateChatlogs.length} icon="🔒" /> <StatusCard label="On this page" value={activities.length} icon="📄" />
<StatusCard label="Commands" value={commandlogs.length} icon="⌨️" /> <StatusCard
<StatusCard label="Alerts" value={alertLogs.length} icon="🔔" /> label="Recent (≤1min)"
value={onlineCount}
state={onlineCount > 0 ? "ok" : "neutral"}
icon="🟢"
/>
</div> </div>
<section className="card" style={{ marginBottom: "1.5rem" }}> <form
<h3 style={{ marginTop: 0 }}>Room chat ({chatlogs.length})</h3> className="card"
{chatlogs.length === 0 ? ( style={{ display: "flex", gap: "0.5rem", marginBottom: "1.5rem", flexWrap: "wrap" }}
<p className="muted">No room chat logs.</p> >
) : ( <input
<div style={{ overflowX: "auto" }}> name="q"
<table> defaultValue={q}
<thead> placeholder="Search action, description, IP..."
<tr> style={{ flex: 1, minWidth: 200 }}
<th>When</th> />
<th>Room</th> <input
<th>From</th> name="staffId"
<th>To</th> defaultValue={staffId?.toString()}
<th>Message</th> placeholder="Staff ID"
</tr> style={{ width: 120 }}
</thead> />
<tbody> <input
{chatlogs.map((c, i) => ( name="action"
<tr key={`${c.timestamp}-${c.user_from_id}-${i}`}> defaultValue={action}
<td className="muted">{fromUnix(c.timestamp)}</td> placeholder="Action type (e.g., rank_change)"
<td>{String(c.room_id)}</td> style={{ width: 160 }}
<td>{String(c.user_from_id)}</td> />
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td> <button type="submit" className="btn btn-primary">
<td>{c.message}</td> Filter
</tr> </button>
))} {(q || staffId || action) && (
</tbody> <a href="/admin/logs" className="btn btn-outline">
</table> Clear filters
</div> </a>
)} )}
</section> </form>
<section className="card" style={{ marginBottom: "1.5rem" }}> <section className="admin-section">
<h3 style={{ marginTop: 0 }}>Private chat ({privateChatlogs.length})</h3> <h2>Activities ({total})</h2>
{privateChatlogs.length === 0 ? ( {activities.length === 0 ? (
<p className="muted">No private chat logs.</p> <p className="muted">No staff activities match this search.</p>
) : ( ) : (
<div style={{ overflowX: "auto" }}> <div style={{ overflowX: "auto" }}>
<table> <table>
<thead> <thead>
<tr> <tr>
<th>When</th> <th>When</th>
<th>From</th> <th>Staff</th>
<th>To</th> <th>Action</th>
<th>Message</th> <th>Description</th>
<th>Target</th>
<th>IP Address</th>
</tr> </tr>
</thead> </thead>
<tbody> <tbody>
{privateChatlogs.map((c, i) => ( {activities.map((a) => (
<tr key={`${c.timestamp}-${c.user_from_id}-${c.user_to_id}-${i}`}>
<td className="muted">{fromUnix(c.timestamp)}</td>
<td>{String(c.user_from_id)}</td>
<td>{c.user_to_id ? String(c.user_to_id) : "—"}</td>
<td>{c.message}</td>
</tr>
))}
</tbody>
</table>
</div>
)}
</section>
<section className="card" style={{ marginBottom: "1.5rem" }}>
<h3 style={{ marginTop: 0 }}>Commands ({commandlogs.length})</h3>
{commandlogs.length === 0 ? (
<p className="muted">No command logs.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>User</th>
<th>Command</th>
<th>Params</th>
<th>OK</th>
</tr>
</thead>
<tbody>
{commandlogs.map((c, i) => (
<tr key={`${c.timestamp}-${c.user_id}-${i}`}>
<td className="muted">{fromUnix(c.timestamp)}</td>
<td>{String(c.user_id)}</td>
<td>{c.command}</td>
<td className="muted">{c.params}</td>
<td>
<span className={`admin-badge ${c.succes === "yes" ? "ok" : "danger"}`}>
{c.succes === "yes" ? "OK" : "FAIL"}
</span>
</td>
</tr>
))}
</tbody>
</table>
</div>
)}
</section>
<section className="card">
<h3 style={{ marginTop: 0 }}>Alerts ({alertLogs.length})</h3>
{alertLogs.length === 0 ? (
<p className="muted">No alert logs.</p>
) : (
<div style={{ overflowX: "auto" }}>
<table>
<thead>
<tr>
<th>When</th>
<th>Type</th>
<th>Severity</th>
<th>Message</th>
<th>Read</th>
</tr>
</thead>
<tbody>
{alertLogs.map((a) => (
<tr key={String(a.id)}> <tr key={String(a.id)}>
<td className="muted">{fromDate(a.createdAt)}</td> <td className="muted" style={{ whiteSpace: "nowrap" }}>{fromDate(a.createdAt)}</td>
<td>{a.type}</td> <td className="muted">#{a.userId} ({a.username ?? "unknown"})</td>
<td> <td>
<span <span className="admin-badge">{a.action}</span>
className={`admin-badge ${CRITICAL.has((a.severity || "").toLowerCase()) ? "danger" : ""}`}
>
{a.severity || "—"}
</span>
</td> </td>
<td>{a.message}</td> <td>{a.description}</td>
<td> <td>
<span className={`admin-badge ${a.isRead ? "ok" : ""}`}> {a.targetType && a.targetId ? (
{a.isRead ? "read" : "new"} <span className="muted">{a.targetType === "user" ? "User " : ""}#{String(a.targetId)}</span>
</span> ) : (
<span className="muted">—</span>
)}
</td> </td>
<td className="muted">{a.ipAddress || "—"}</td>
</tr> </tr>
))} ))}
</tbody> </tbody>
@@ -250,6 +161,17 @@ export default async function AdminLogs() {
</div> </div>
)} )}
</section> </section>
<p className="muted">
Page {page} / {pages} · {total} activities
{page < pages ? (
<>
{" · "}
<a href={`/admin/logs?q=${encodeURIComponent(q)}&staffId=${staffId || ""}&action=${action || ""}&page=${page + 1}`}>Next →</a>
</>
) : null}
</p>
</main> </main>
); );
} }