fix(admin): P0 integrity — permanent bans, ACL sidebar, rank guards
Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
11004626c7
commit
75cdfdebe4
14 files changed
+458
-68
No files matched your search
@@ -1,6 +1,7 @@
|
||||
import { getTranslations } from "next-intl/server";
|
||||
import { ContentCard } from "@/components/public/ui";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { activeBanWhere, unixNow } from "@/lib/bans";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
@@ -12,15 +13,19 @@ export default async function BannedPage() {
|
||||
const session = await auth();
|
||||
let reason = "";
|
||||
let expire = 0;
|
||||
let hasBan = false;
|
||||
if (session?.user?.id) {
|
||||
try {
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
const ban = await prisma.ban.findFirst({
|
||||
where: { userId: Number(session.user.id), banExpire: { gt: now } },
|
||||
orderBy: { banExpire: "desc" },
|
||||
where: {
|
||||
userId: Number(session.user.id),
|
||||
...activeBanWhere(unixNow()),
|
||||
},
|
||||
orderBy: { timestamp: "desc" },
|
||||
select: { banReason: true, banExpire: true },
|
||||
});
|
||||
if (ban) {
|
||||
hasBan = true;
|
||||
reason = ban.banReason;
|
||||
expire = ban.banExpire;
|
||||
}
|
||||
@@ -29,17 +34,16 @@ export default async function BannedPage() {
|
||||
}
|
||||
}
|
||||
|
||||
const expiryText =
|
||||
expire === 0
|
||||
? ""
|
||||
: expire > FAR_FUTURE
|
||||
? t("permanent")
|
||||
: t("expires", {
|
||||
date: new Date(expire * 1000)
|
||||
.toISOString()
|
||||
.slice(0, 16)
|
||||
.replace("T", " "),
|
||||
});
|
||||
const expiryText = !hasBan
|
||||
? ""
|
||||
: expire === 0 || expire > FAR_FUTURE
|
||||
? t("permanent")
|
||||
: t("expires", {
|
||||
date: new Date(expire * 1000)
|
||||
.toISOString()
|
||||
.slice(0, 16)
|
||||
.replace("T", " "),
|
||||
});
|
||||
|
||||
return (
|
||||
<main style={{ maxWidth: 560, margin: "2rem auto" }}>
|
||||
|
||||
@@ -2,6 +2,7 @@ import { redirect } from "next/navigation";
|
||||
import { getTranslations } from "next-intl/server";
|
||||
import { createBan, liftBan } from "@/actions/admin-bans";
|
||||
import { StatusCard } from "@/components/admin/dashboard";
|
||||
import { activeBanWhere, unixNow } from "@/lib/bans";
|
||||
import { canAccess, getAdminContext, PERMS } from "@/lib/permissions";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
|
||||
@@ -18,11 +19,11 @@ export default async function AdminBans() {
|
||||
}
|
||||
|
||||
const t = await getTranslations("pages.admin.bans");
|
||||
const now = Math.floor(Date.now() / 1000);
|
||||
const now = unixNow();
|
||||
let bans: Awaited<ReturnType<typeof prisma.ban.findMany>> = [];
|
||||
try {
|
||||
bans = await prisma.ban.findMany({
|
||||
where: { banExpire: { gt: now } },
|
||||
where: activeBanWhere(now),
|
||||
orderBy: { timestamp: "desc" },
|
||||
take: 100,
|
||||
});
|
||||
@@ -30,7 +31,6 @@ export default async function AdminBans() {
|
||||
bans = [];
|
||||
}
|
||||
|
||||
// banExpire of 0 means permanent in the emulator schema.
|
||||
const permanent = bans.filter((b) => b.banExpire === 0).length;
|
||||
const accountBans = bans.filter((b) => b.type === "account").length;
|
||||
|
||||
|
||||
@@ -10,7 +10,9 @@ import { AdminTopbar } from "@/components/admin/admin-topbar";
|
||||
import { LanguageSwitcher } from "@/components/language-switcher";
|
||||
import { ThemeSwitcher } from "@/components/theme-switcher";
|
||||
import { requireStaff } from "@/lib/admin/guard";
|
||||
import { collectNavPermissionSlugs } from "@/lib/admin-nav";
|
||||
import { setCsrfCookie } from "@/lib/foundation/security";
|
||||
import { canAccess, getAdminContext } from "@/lib/permissions";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { siteSettings } from "@/lib/services/site-settings";
|
||||
|
||||
@@ -66,6 +68,13 @@ async function Sidebar({
|
||||
}) {
|
||||
const t = await getTranslations("pages.admin.nav");
|
||||
const initial = staff.username.charAt(0).toUpperCase();
|
||||
const { permissions } = await getAdminContext();
|
||||
const isSuperAdmin = permissions.isSuperAdmin;
|
||||
const allowedPermissions = isSuperAdmin
|
||||
? []
|
||||
: collectNavPermissionSlugs().filter((slug) =>
|
||||
canAccess(permissions, slug, staff.rank),
|
||||
);
|
||||
|
||||
return (
|
||||
<aside
|
||||
@@ -93,7 +102,10 @@ async function Sidebar({
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<AdminSidebarNav />
|
||||
<AdminSidebarNav
|
||||
allowedPermissions={allowedPermissions}
|
||||
isSuperAdmin={isSuperAdmin}
|
||||
/>
|
||||
|
||||
<div className="shrink-0 border-t border-[var(--admin-border)] px-3 py-3">
|
||||
<Link
|
||||
|
||||
@@ -9,6 +9,7 @@ import {
|
||||
import Link from "next/link";
|
||||
import { getTranslations } from "next-intl/server";
|
||||
import { StatusCard } from "@/components/admin/dashboard";
|
||||
import { activeBanWhere } from "@/lib/bans";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
@@ -31,7 +32,7 @@ export default async function AdminDashboard() {
|
||||
prisma.user.count({ where: { online: "1" } }),
|
||||
prisma.websiteArticles.count(),
|
||||
prisma.ban.count({
|
||||
where: { banExpire: { gt: Math.floor(Date.now() / 1000) } },
|
||||
where: activeBanWhere(),
|
||||
}),
|
||||
]);
|
||||
} catch {}
|
||||
|
||||
@@ -5,7 +5,7 @@ import { logAudit } from "@/lib/services/audit";
|
||||
import { uploadSingleFurni } from "@/lib/services/upload-import";
|
||||
|
||||
export const POST = withAdmin(
|
||||
{ permission: PERMS.ASSETS_IMPORT },
|
||||
{ permission: PERMS.ASSETS_IMPORT, maxBodyBytes: 52 * 1024 * 1024 },
|
||||
async (request, ctx) => {
|
||||
const formData = await request.formData();
|
||||
|
||||
|
||||
@@ -9,6 +9,7 @@ export const POST = withAdmin(
|
||||
{ permission: PERMS.USERS_EDIT },
|
||||
async (request, context) => {
|
||||
const staffId = context.session.user.id;
|
||||
const staffRank = context.session.user.rank;
|
||||
const formData = await request.formData();
|
||||
const userId = Number(formData.get("userId"));
|
||||
const username = String(formData.get("username") || "");
|
||||
@@ -23,13 +24,56 @@ export const POST = withAdmin(
|
||||
|
||||
if (action === "set_rank") {
|
||||
const rank = Number(formData.get("rank") || "0");
|
||||
if (!rank || rank < 0 || rank > 10) {
|
||||
if (!Number.isInteger(rank) || rank < 1) {
|
||||
return NextResponse.json(
|
||||
{ success: false, message: "Invalid rank value" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const rankExists = await prisma.$queryRaw<{ id: number }[]>`
|
||||
SELECT id FROM permission_ranks WHERE id = ${rank} LIMIT 1
|
||||
`.catch(() => [] as { id: number }[]);
|
||||
if (rankExists.length === 0) {
|
||||
return NextResponse.json(
|
||||
{ success: false, message: "Rank does not exist" },
|
||||
{ status: 400 },
|
||||
);
|
||||
}
|
||||
|
||||
const target = await prisma.user.findUnique({
|
||||
where: { id: userId },
|
||||
select: { rank: true },
|
||||
});
|
||||
if (!target) {
|
||||
return NextResponse.json(
|
||||
{ success: false, message: "User not found" },
|
||||
{ status: 404 },
|
||||
);
|
||||
}
|
||||
|
||||
const isSuper = context.permissions.isSuperAdmin;
|
||||
if (!isSuper) {
|
||||
if (target.rank >= staffRank) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
success: false,
|
||||
message: "Cannot change rank of a user at or above your rank",
|
||||
},
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
if (rank >= staffRank) {
|
||||
return NextResponse.json(
|
||||
{
|
||||
success: false,
|
||||
message: "Cannot set a rank equal to or above your own",
|
||||
},
|
||||
{ status: 403 },
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
await prisma.user.update({ where: { id: userId }, data: { rank } });
|
||||
await rcon.setRank(userId, rank);
|
||||
await logStaffActivity({
|
||||
|
||||
Reference in new issue
Block a user