Add dark mode, i18n, messenger/moderation/verify, admin CRUD parity

Web-tier features completing the AtomCMS→Next.js conversion (slice 2):

UI/UX:
- Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage,
  no-flash boot script) wired into the nav.
- i18n (next-intl, cookie-based / no URL routing): en + it catalogs,
  request.ts, provider in root layout, LanguageSwitcher; shell (nav,
  header, footer) fully translated. URLs + access-guard unchanged.
- globals.css: --muted/--border aliases used across admin pages.

User features:
- /messages: offline messages + friend-request accept (server action
  re-reads session, two directional rows, idempotent).
- Email verification: signed-token /verify route + sendVerification wired
  into register (best-effort, never blocks signup).
- Article reactions: toggle UI on news/[slug] + server action.
- Content moderation service (website_wordfilter + optional OpenAI
  moderations, fail-open) wired into article comments + guestbook.

Admin CRUD parity (Filament replacement):
- /admin/shop (+ new/[id]) packages CRUD + read-only orders.
- /admin/transactions read-only PayPal log.
- /admin/permissions, /admin/tags, /admin/ads (+ new/[id]),
  /admin/help-questions (+ new/[id]), /admin/radio/history,
  /admin/users/[id]/edit. All gated by requireStaff + logStaffActivity.

Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new
admin CRUD + /messages + /verify).
This commit is contained in:
Simo committed 2026-06-28 16:06:42 +02:00
1 parent 22d53d0e9c
commit 7daeccb832
45 files changed
+3312 -84

No files matched your search

+98
View File
@@ -0,0 +1,98 @@
"use server";
import { revalidatePath } from "next/cache";
import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
import { logStaffActivity } from "@/lib/services/staff-activity";
// website_permissions (model WebsitePermissions) is the CMS-owned rank-permission
// mapping AtomCMS exposes in admin: a key/value(/comment) row per permission.
// Editable columns on the table are exactly: key (unique), value, comment.
// id is BigInt and created_at/updated_at are managed here — no other columns
// exist, so there are no extra staff flags to toggle.
export async function createPermission(formData: FormData): Promise<void> {
const staff = await requireStaff();
const key = String(formData.get("key") ?? "").trim().slice(0, 255);
const value = String(formData.get("value") ?? "").trim().slice(0, 255);
const comment = String(formData.get("comment") ?? "").trim().slice(0, 255);
if (!key) return;
const now = new Date();
try {
await prisma.websitePermissions.upsert({
where: { key },
update: { value: value || null, comment: comment || null, updatedAt: now },
create: {
key,
value: value || null,
comment: comment || null,
createdAt: now,
updatedAt: now,
},
});
await logStaffActivity({
staffId: staff.id,
action: "permission_create",
description: `Saved permission "${key}" = "${value}"`,
targetType: "permission",
});
} catch {
// ignore (e.g. constraint failure) — page re-renders current state
}
revalidatePath("/admin/permissions");
}
export async function updatePermission(formData: FormData): Promise<void> {
const staff = await requireStaff();
const raw = String(formData.get("id") ?? "");
if (!raw) return;
const id = BigInt(raw);
const key = String(formData.get("key") ?? "").trim().slice(0, 255);
const value = String(formData.get("value") ?? "").trim().slice(0, 255);
const comment = String(formData.get("comment") ?? "").trim().slice(0, 255);
if (!key) return;
try {
await prisma.websitePermissions.update({
where: { id },
data: {
key,
value: value || null,
comment: comment || null,
updatedAt: new Date(),
},
});
await logStaffActivity({
staffId: staff.id,
action: "permission_update",
description: `Updated permission #${raw} ("${key}" = "${value}")`,
targetType: "permission",
});
} catch {
// ignore (e.g. duplicate key) — page re-renders current state
}
revalidatePath("/admin/permissions");
}
export async function deletePermission(formData: FormData): Promise<void> {
const staff = await requireStaff();
const raw = String(formData.get("id") ?? "");
if (!raw) return;
try {
const deleted = await prisma.websitePermissions.delete({
where: { id: BigInt(raw) },
select: { key: true },
});
await logStaffActivity({
staffId: staff.id,
action: "permission_delete",
description: `Deleted permission #${raw} ("${deleted.key}")`,
targetType: "permission",
});
} catch {
// ignore (e.g. already removed)
}
revalidatePath("/admin/permissions");
}