feat: shop buy, forum replies, tickets, messages, sessions, and UX hardening
Complete remaining product gaps: credit-based shop purchases, guild thread replies, help ticket detail/reply/close, offline message compose, sign-out-everywhere via JWT version, ads delete confirm, soft-fail feedback, rate limits, loading states, and single auth() in site layout. Co-authored-by: Cursor <[email protected]>
This commit is contained in:
1 parent
ed7db6e048
commit
803e8f36c1
47 files changed
+2793
-358
No files matched your search
@@ -6,7 +6,9 @@ import { z } from "zod";
|
||||
import { auth } from "@/lib/auth";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { clientIp, rateLimit } from "@/lib/rate-limit";
|
||||
import { positiveBigInt } from "@/lib/api";
|
||||
import { moderateOrThrow } from "@/lib/services/moderation";
|
||||
import { createOwnedTicketReply } from "@/lib/services/ticket-replies";
|
||||
|
||||
const ticketSchema = z.object({
|
||||
title: z.string().min(1, "Title is required").max(255),
|
||||
@@ -20,11 +22,32 @@ type TicketOutcome =
|
||||
| "ratelimit"
|
||||
| "error";
|
||||
|
||||
type TicketDetailOutcome =
|
||||
| "replied"
|
||||
| "closed"
|
||||
| "invalid"
|
||||
| "not_found"
|
||||
| "closed_ticket"
|
||||
| "moderated"
|
||||
| "ratelimit"
|
||||
| "error";
|
||||
|
||||
function ticketsRedirect(outcome: TicketOutcome): never {
|
||||
if (outcome === "created") redirect("/help/tickets?created=1");
|
||||
redirect(`/help/tickets?error=${outcome}`);
|
||||
}
|
||||
|
||||
function ticketDetailRedirect(
|
||||
ticketId: bigint | null,
|
||||
outcome: TicketDetailOutcome,
|
||||
): never {
|
||||
if (!ticketId) redirect("/help/tickets?error=invalid");
|
||||
const base = `/help/tickets/${ticketId}`;
|
||||
if (outcome === "replied") redirect(`${base}?replied=1`);
|
||||
if (outcome === "closed") redirect(`${base}?closed=1`);
|
||||
redirect(`${base}?error=${outcome}`);
|
||||
}
|
||||
|
||||
function isNextRedirect(e: unknown): boolean {
|
||||
return (
|
||||
!!e &&
|
||||
@@ -99,3 +122,149 @@ export async function createTicket(formData: FormData): Promise<void> {
|
||||
revalidatePath("/help/tickets");
|
||||
ticketsRedirect(outcome);
|
||||
}
|
||||
|
||||
const replyContentSchema = z.object({
|
||||
content: z.string().min(1).max(5000),
|
||||
});
|
||||
|
||||
export async function replyHelpTicket(formData: FormData): Promise<void> {
|
||||
const ticketId = positiveBigInt(String(formData.get("ticketId") ?? ""));
|
||||
let outcome: TicketDetailOutcome = "error";
|
||||
|
||||
try {
|
||||
const session = await auth();
|
||||
const userId = Number(session?.user?.id);
|
||||
if (!Number.isInteger(userId) || userId <= 0) {
|
||||
redirect("/login");
|
||||
}
|
||||
|
||||
if (!ticketId) {
|
||||
outcome = "invalid";
|
||||
} else {
|
||||
await clientIp();
|
||||
if (!(await rateLimit(`ticket-reply:${userId}`, 5, 60_000)).ok) {
|
||||
outcome = "ratelimit";
|
||||
} else {
|
||||
const raw = {
|
||||
content: String(formData.get("content") ?? "")
|
||||
.normalize("NFC")
|
||||
.trim()
|
||||
.slice(0, 5000),
|
||||
};
|
||||
const parsed = replyContentSchema.safeParse(raw);
|
||||
if (!parsed.success) {
|
||||
outcome = "invalid";
|
||||
} else {
|
||||
const ticket = await prisma.websiteHelpCenterTickets.findUnique({
|
||||
where: { id: ticketId },
|
||||
select: { id: true, userId: true, open: true },
|
||||
});
|
||||
|
||||
if (!ticket || ticket.userId !== userId) {
|
||||
outcome = "not_found";
|
||||
} else if (!ticket.open) {
|
||||
outcome = "closed_ticket";
|
||||
} else {
|
||||
let moderated = false;
|
||||
try {
|
||||
await moderateOrThrow(parsed.data.content);
|
||||
} catch {
|
||||
moderated = true;
|
||||
outcome = "moderated";
|
||||
}
|
||||
|
||||
if (!moderated) {
|
||||
const created = await prisma.$transaction((tx) =>
|
||||
createOwnedTicketReply(
|
||||
{
|
||||
findTicket: (id) =>
|
||||
tx.websiteHelpCenterTickets.findUnique({
|
||||
where: { id },
|
||||
select: { id: true, userId: true, open: true },
|
||||
}),
|
||||
createReply: (data) =>
|
||||
tx.websiteHelpCenterTicketReplies.create({
|
||||
data,
|
||||
select: {
|
||||
id: true,
|
||||
userId: true,
|
||||
content: true,
|
||||
createdAt: true,
|
||||
},
|
||||
}),
|
||||
touchTicket: (id, updatedAt) =>
|
||||
tx.websiteHelpCenterTickets.update({
|
||||
where: { id },
|
||||
data: { updatedAt },
|
||||
select: { id: true },
|
||||
}),
|
||||
},
|
||||
{
|
||||
ticketId,
|
||||
userId,
|
||||
content: parsed.data.content,
|
||||
},
|
||||
),
|
||||
);
|
||||
outcome = created ? "replied" : "not_found";
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (e) {
|
||||
if (isNextRedirect(e)) throw e;
|
||||
outcome = "error";
|
||||
}
|
||||
|
||||
if (ticketId) revalidatePath(`/help/tickets/${ticketId}`);
|
||||
revalidatePath("/help/tickets");
|
||||
ticketDetailRedirect(ticketId, outcome);
|
||||
}
|
||||
|
||||
export async function closeHelpTicket(formData: FormData): Promise<void> {
|
||||
const ticketId = positiveBigInt(String(formData.get("ticketId") ?? ""));
|
||||
let outcome: TicketDetailOutcome = "error";
|
||||
|
||||
try {
|
||||
const session = await auth();
|
||||
const userId = Number(session?.user?.id);
|
||||
if (!Number.isInteger(userId) || userId <= 0) {
|
||||
redirect("/login");
|
||||
}
|
||||
|
||||
if (!ticketId) {
|
||||
outcome = "invalid";
|
||||
} else {
|
||||
await clientIp();
|
||||
if (!(await rateLimit(`ticket-close:${userId}`, 10, 60_000)).ok) {
|
||||
outcome = "ratelimit";
|
||||
} else {
|
||||
const ticket = await prisma.websiteHelpCenterTickets.findUnique({
|
||||
where: { id: ticketId },
|
||||
select: { id: true, userId: true, open: true },
|
||||
});
|
||||
|
||||
if (!ticket || ticket.userId !== userId) {
|
||||
outcome = "not_found";
|
||||
} else if (!ticket.open) {
|
||||
outcome = "closed_ticket";
|
||||
} else {
|
||||
const now = new Date();
|
||||
await prisma.websiteHelpCenterTickets.update({
|
||||
where: { id: ticketId },
|
||||
data: { open: false, updatedAt: now },
|
||||
});
|
||||
outcome = "closed";
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (e) {
|
||||
if (isNextRedirect(e)) throw e;
|
||||
outcome = "error";
|
||||
}
|
||||
|
||||
if (ticketId) revalidatePath(`/help/tickets/${ticketId}`);
|
||||
revalidatePath("/help/tickets");
|
||||
ticketDetailRedirect(ticketId, outcome);
|
||||
}
|
||||
Reference in new issue
Block a user