Harden CMS security and theme contrast
This commit is contained in:
1 parent
2465ff2170
commit
4a1e1115b3
57 files changed
+1023
-231
No files matched your search
@@ -5,6 +5,7 @@ import { redirect } from "next/navigation";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
// CRUD for website advertisements (website_ads). Emulator does not own this
|
||||
// table; it only stores an image URL rendered in the site layout/widgets.
|
||||
@@ -68,9 +69,8 @@ export async function updateAd(formData: FormData): Promise<void> {
|
||||
|
||||
export async function deleteAd(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!/^\d+$/.test(raw)) return;
|
||||
const id = BigInt(raw);
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteAds.delete({ where: { id } });
|
||||
|
||||
@@ -3,18 +3,12 @@
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
export async function dismissApplication(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "").trim();
|
||||
if (!raw) return;
|
||||
|
||||
let id: bigint;
|
||||
try {
|
||||
id = BigInt(raw);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteStaffApplications.delete({ where: { id } });
|
||||
|
||||
@@ -5,6 +5,7 @@ import { redirect } from "next/navigation";
|
||||
import { slugify } from "@/lib/format";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
async function uniqueSlug(title: string): Promise<string> {
|
||||
const base = slugify(title);
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
export async function createEmailTemplate(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
@@ -61,14 +62,8 @@ export async function updateEmailTemplate(formData: FormData): Promise<void> {
|
||||
|
||||
export async function deleteEmailTemplate(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!raw) return;
|
||||
let id: bigint;
|
||||
try {
|
||||
id = BigInt(raw);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
await prisma.emailTemplates.delete({ where: { id } });
|
||||
revalidatePath("/admin/email-templates");
|
||||
}
|
||||
@@ -5,6 +5,7 @@ import { redirect } from "next/navigation";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
// CRUD for help-center FAQ entries (website_help_center_categories). Each entry
|
||||
// is a titled content block with an optional image and call-to-action button.
|
||||
@@ -72,9 +73,8 @@ export async function createHelpQuestion(formData: FormData): Promise<void> {
|
||||
|
||||
export async function updateHelpQuestion(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!/^\d+$/.test(raw)) return;
|
||||
const id = BigInt(raw);
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
const name = String(formData.get("name") ?? "")
|
||||
.trim()
|
||||
@@ -132,9 +132,8 @@ export async function updateHelpQuestion(formData: FormData): Promise<void> {
|
||||
|
||||
export async function deleteHelpQuestion(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!/^\d+$/.test(raw)) return;
|
||||
const id = BigInt(raw);
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteHelpCenterCategories.delete({ where: { id } });
|
||||
|
||||
@@ -1,9 +1,12 @@
|
||||
"use server";
|
||||
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { redirect } from "next/navigation";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
import { logServerError } from "@/lib/server-log";
|
||||
|
||||
// website_permissions (model WebsitePermissions) is the CMS-owned permission ->
|
||||
// minimum-rank mapping. Editable columns are exactly: permission (unique name),
|
||||
@@ -37,10 +40,13 @@ export async function createPermission(formData: FormData): Promise<void> {
|
||||
description: `Saved permission "${permission}" (min rank ${minRank})`,
|
||||
targetType: "permission",
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.permission_create_failed", error, { staffId: staff.id, permission });
|
||||
redirect("/admin/permissions?error=save");
|
||||
// ignore (e.g. constraint failure) — page re-renders current state
|
||||
}
|
||||
revalidatePath("/admin/permissions");
|
||||
redirect("/admin/permissions?saved=1");
|
||||
}
|
||||
|
||||
export async function updatePermission(formData: FormData): Promise<void> {
|
||||
@@ -63,33 +69,45 @@ export async function updatePermission(formData: FormData): Promise<void> {
|
||||
await logStaffActivity({
|
||||
staffId: staff.id,
|
||||
action: "permission_update",
|
||||
description: `Updated permission #${raw} ("${permission}" min rank ${minRank})`,
|
||||
description: `Updated permission #${id} ("${permission}" min rank ${minRank})`,
|
||||
targetType: "permission",
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.permission_update_failed", error, {
|
||||
staffId: staff.id,
|
||||
permissionId: String(id),
|
||||
});
|
||||
redirect("/admin/permissions?error=save");
|
||||
// ignore (e.g. duplicate) — page re-renders current state
|
||||
}
|
||||
revalidatePath("/admin/permissions");
|
||||
redirect("/admin/permissions?saved=1");
|
||||
}
|
||||
|
||||
export async function deletePermission(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!raw) return;
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
const deleted = await prisma.websitePermissions.delete({
|
||||
where: { id: BigInt(raw) },
|
||||
where: { id },
|
||||
select: { permission: true },
|
||||
});
|
||||
await logStaffActivity({
|
||||
staffId: staff.id,
|
||||
action: "permission_delete",
|
||||
description: `Deleted permission #${raw} ("${deleted.permission}")`,
|
||||
description: `Deleted permission #${id} ("${deleted.permission}")`,
|
||||
targetType: "permission",
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.permission_delete_failed", error, {
|
||||
staffId: staff.id,
|
||||
permissionId: String(id),
|
||||
});
|
||||
redirect("/admin/permissions?error=delete");
|
||||
// ignore (e.g. already removed)
|
||||
}
|
||||
revalidatePath("/admin/permissions");
|
||||
redirect("/admin/permissions?saved=1");
|
||||
}
|
||||
@@ -3,6 +3,7 @@
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
|
||||
export async function createCategory(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
@@ -28,9 +29,8 @@ export async function createCategory(formData: FormData): Promise<void> {
|
||||
|
||||
export async function deleteCategory(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!/^\d+$/.test(raw)) return;
|
||||
const id = BigInt(raw);
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
// Remove the category's values first to avoid orphaned rows.
|
||||
@@ -44,9 +44,8 @@ export async function deleteCategory(formData: FormData): Promise<void> {
|
||||
|
||||
export async function createValue(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const categoryRaw = String(formData.get("categoryId") ?? "");
|
||||
if (!/^\d+$/.test(categoryRaw)) return;
|
||||
const categoryId = BigInt(categoryRaw);
|
||||
const categoryId = formPositiveBigInt(formData, "categoryId");
|
||||
if (!categoryId) return;
|
||||
|
||||
const name = String(formData.get("name") ?? "")
|
||||
.trim()
|
||||
@@ -90,9 +89,8 @@ export async function createValue(formData: FormData): Promise<void> {
|
||||
|
||||
export async function deleteValue(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
const raw = String(formData.get("id") ?? "");
|
||||
if (!/^\d+$/.test(raw)) return;
|
||||
const id = BigInt(raw);
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteRareValues.delete({ where: { id } });
|
||||
|
||||
+18
-19
@@ -5,6 +5,8 @@ import { redirect } from "next/navigation";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { logStaffActivity } from "@/lib/services/staff-activity";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
import { logServerError } from "@/lib/server-log";
|
||||
|
||||
// Website store packages (website_shop_articles). This CMS-owned table backs
|
||||
// the public store; rows here are the buyable packages, not orders. The closest
|
||||
@@ -68,7 +70,8 @@ export async function createShopArticle(formData: FormData): Promise<void> {
|
||||
targetType: "shop_article",
|
||||
targetId: Number(created.id),
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.shop_create_failed", error, { staffId: staff.id, name });
|
||||
// Unique constraint on `name` (or DB unavailable) — swallow and re-render.
|
||||
return;
|
||||
}
|
||||
@@ -79,14 +82,8 @@ export async function createShopArticle(formData: FormData): Promise<void> {
|
||||
export async function updateShopArticle(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
|
||||
const raw = String(formData.get("id") ?? "").trim();
|
||||
if (!raw) return;
|
||||
let id: bigint;
|
||||
try {
|
||||
id = BigInt(raw);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
const name = String(formData.get("name") ?? "")
|
||||
.trim()
|
||||
@@ -127,7 +124,11 @@ export async function updateShopArticle(formData: FormData): Promise<void> {
|
||||
targetType: "shop_article",
|
||||
targetId: Number(id),
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.shop_update_failed", error, {
|
||||
staffId: staff.id,
|
||||
articleId: String(id),
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -138,14 +139,8 @@ export async function updateShopArticle(formData: FormData): Promise<void> {
|
||||
export async function deleteShopArticle(formData: FormData): Promise<void> {
|
||||
const staff = await requireStaff();
|
||||
|
||||
const raw = String(formData.get("id") ?? "").trim();
|
||||
if (!raw) return;
|
||||
let id: bigint;
|
||||
try {
|
||||
id = BigInt(raw);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteShopArticles.delete({ where: { id } });
|
||||
@@ -156,7 +151,11 @@ export async function deleteShopArticle(formData: FormData): Promise<void> {
|
||||
targetType: "shop_article",
|
||||
targetId: Number(id),
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.shop_delete_failed", error, {
|
||||
staffId: staff.id,
|
||||
articleId: String(id),
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -3,6 +3,8 @@
|
||||
import { revalidatePath } from "next/cache";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { formPositiveBigInt } from "@/lib/form-data";
|
||||
import { logServerError } from "@/lib/server-log";
|
||||
|
||||
export async function createVoucher(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
@@ -37,7 +39,8 @@ export async function createVoucher(formData: FormData): Promise<void> {
|
||||
updatedAt: now,
|
||||
},
|
||||
});
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.voucher_create_failed", error);
|
||||
// Unique constraint on `code` (or DB unavailable) — swallow and re-render.
|
||||
return;
|
||||
}
|
||||
@@ -48,19 +51,13 @@ export async function createVoucher(formData: FormData): Promise<void> {
|
||||
export async function deleteVoucher(formData: FormData): Promise<void> {
|
||||
await requireStaff();
|
||||
|
||||
const raw = String(formData.get("id") ?? "").trim();
|
||||
if (!raw) return;
|
||||
|
||||
let id: bigint;
|
||||
try {
|
||||
id = BigInt(raw);
|
||||
} catch {
|
||||
return;
|
||||
}
|
||||
const id = formPositiveBigInt(formData, "id");
|
||||
if (!id) return;
|
||||
|
||||
try {
|
||||
await prisma.websiteShopVouchers.delete({ where: { id } });
|
||||
} catch {
|
||||
} catch (error) {
|
||||
logServerError("admin.voucher_delete_failed", error, { voucherId: String(id) });
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user