feat: shop buy, forum replies, tickets, messages, sessions, and UX hardening
Deploy / release (push) Skipped
Deploy / deploy (push) Failing after 4m23s

Complete remaining product gaps: credit-based shop purchases, guild thread replies, help ticket detail/reply/close, offline message compose, sign-out-everywhere via JWT version, ads delete confirm, soft-fail feedback, rate limits, loading states, and single auth() in site layout.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-21 21:21:02 +02:00
1 parent ed7db6e048
commit 803e8f36c1
47 files changed
+2793 -358

No files matched your search

+86 -70
View File
@@ -1,6 +1,7 @@
"use server";
import { revalidatePath } from "next/cache";
import { redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
@@ -9,91 +10,106 @@ import { prisma } from "@/lib/prisma";
// values. Keep this in sync with REACTIONS in src/app/news/[slug]/page.tsx.
const ALLOWED_REACTIONS = new Set(["like", "love", "wow"]);
type ReactionOutcome = "updated" | "invalid" | "not_found" | "error";
function reactionRedirect(slug: string, outcome: ReactionOutcome): never {
const path = slug ? `/news/${encodeURIComponent(slug)}` : "/news";
if (outcome === "updated") redirect(`${path}?reaction=1`);
redirect(`${path}?error=${outcome}`);
}
function isNextRedirect(e: unknown): boolean {
return (
!!e &&
typeof e === "object" &&
"digest" in e &&
typeof (e as { digest?: unknown }).digest === "string" &&
(e as { digest: string }).digest.startsWith("NEXT_REDIRECT")
);
}
/**
* Toggle the SIGNED-IN user's reaction on a news article.
*
* The voter id is read from the session (re-fetched via auth()), never from the
* submitted FormData, so a crafted form cannot vote as another account. A user
* has at most one ACTIVE reaction per article:
* - clicking the reaction they already have active -> deactivates it (un-vote)
* - clicking a different reaction -> that reaction becomes active and any other
* reaction rows for this user/article are deactivated
* - first-ever reaction of a type -> a new active row is created
*
* Rows are toggled (active flag) rather than deleted so a user's history of
* reaction types is preserved. website_article_reactions has no composite
* unique key, so we resolve the existing row with findFirst rather than upsert.
*/
export async function toggleReaction(formData: FormData): Promise<void> {
const session = await auth();
if (!session?.user?.id) return;
const userId = Number(session.user.id);
if (!Number.isFinite(userId)) return;
const reaction = String(formData.get("reaction") ?? "")
.normalize("NFC")
.trim()
.toLowerCase();
if (!ALLOWED_REACTIONS.has(reaction)) return;
const articleIdRaw = String(formData.get("articleId") ?? "")
const slugHint = String(formData.get("slug") ?? "")
.normalize("NFC")
.trim();
if (!/^\d+$/.test(articleIdRaw)) return;
let articleId: bigint;
let outcome: ReactionOutcome = "error";
let slug = slugHint;
try {
articleId = BigInt(articleIdRaw);
} catch {
return;
}
const session = await auth();
if (!session?.user?.id) {
redirect("/login");
}
let slug: string | null;
try {
// Confirm the article exists (and grab its slug for revalidation).
const article = await prisma.websiteArticles.findUnique({
where: { id: articleId },
select: { slug: true },
});
if (!article) return;
slug = article.slug;
const userId = Number(session.user.id);
if (!Number.isFinite(userId)) {
redirect("/login");
}
// The user's current row for THIS reaction on THIS article, if any.
const existing = await prisma.websiteArticleReactions.findFirst({
where: { userId, articleId, reaction },
select: { id: true, active: true },
});
if (existing?.active) {
// Already reacting with this exact reaction -> un-vote (deactivate it).
await prisma.websiteArticleReactions.update({
where: { id: existing.id },
data: { active: false },
});
const reaction = String(formData.get("reaction") ?? "")
.normalize("NFC")
.trim()
.toLowerCase();
if (!ALLOWED_REACTIONS.has(reaction)) {
outcome = "invalid";
} else {
// Switching to (or first-time picking) this reaction: clear any other
// active reaction by this user on this article, then activate this one.
await prisma.websiteArticleReactions.updateMany({
where: { userId, articleId, active: true },
data: { active: false },
});
if (existing) {
await prisma.websiteArticleReactions.update({
where: { id: existing.id },
data: { active: true },
});
const articleIdRaw = String(formData.get("articleId") ?? "")
.normalize("NFC")
.trim();
if (!/^\d+$/.test(articleIdRaw)) {
outcome = "invalid";
} else {
await prisma.websiteArticleReactions.create({
data: { userId, articleId, reaction, active: true },
const articleId = BigInt(articleIdRaw);
const article = await prisma.websiteArticles.findUnique({
where: { id: articleId },
select: { slug: true },
});
if (!article) {
outcome = "not_found";
} else {
slug = article.slug;
const existing = await prisma.websiteArticleReactions.findFirst({
where: { userId, articleId, reaction },
select: { id: true, active: true },
});
if (existing?.active) {
await prisma.websiteArticleReactions.update({
where: { id: existing.id },
data: { active: false },
});
} else {
await prisma.websiteArticleReactions.updateMany({
where: { userId, articleId, active: true },
data: { active: false },
});
if (existing) {
await prisma.websiteArticleReactions.update({
where: { id: existing.id },
data: { active: true },
});
} else {
await prisma.websiteArticleReactions.create({
data: { userId, articleId, reaction, active: true },
});
}
}
outcome = "updated";
}
}
}
} catch {
// DB unavailable — fail soft; nothing to persist.
return;
} catch (e) {
if (isNextRedirect(e)) throw e;
outcome = "error";
}
if (slug) revalidatePath(`/news/${slug}`);
if (slug && outcome !== "error") revalidatePath(`/news/${slug}`);
reactionRedirect(slug, outcome);
}