feat(admin): drizzle trade-lock + RCON sync and photo local purge
CI / check (push) Successful in 24s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m2s

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-31 21:14:03 +02:00
1 parent 67656a9aad
commit 9854719cfd
7 files changed
+250 -45

No files matched your search

+62 -22
View File
@@ -1,6 +1,8 @@
"use server";
import { eq, sql } from "drizzle-orm";
import { requirePermission } from "@/lib/admin/guard";
import { db, Sanctions, User, UsersSettings } from "@/lib/db";
import { PERMS } from "@/lib/permissions";
import { prisma } from "@/lib/prisma";
import type { ActionResult } from "@/lib/safe-action-shared";
@@ -271,8 +273,8 @@ export async function bulkAdjustCurrency({
}
/**
* Persist trade lock on `sanctions.trade_locked_until`.
* No first-class RCON trade-lock helper in this CMS — DB only.
* Persist trade lock on `sanctions.trade_locked_until` + `users_settings.can_trade`
* via Drizzle, then best-effort RCON sync (settradelock + alert + disconnect if online).
*/
export async function setTradeLock({
userId,
@@ -284,33 +286,71 @@ export async function setTradeLock({
}): Promise<ActionResult<{ userId: number; untilUnix: number }>> {
const staff = await requirePermission(PERMS.USERS_EDIT);
const until = Math.max(0, Math.trunc(untilUnix));
const locked = until > 0;
const existing = await prisma.sanctions.findFirst({
where: { habboId: userId },
select: { id: true },
});
if (existing) {
await prisma.sanctions.update({
where: { id: existing.id },
data: { tradeLockedUntil: until },
});
} else {
await prisma.sanctions.create({
data: {
const [user] = await db
.select({
id: User.id,
username: User.username,
online: User.online,
})
.from(User)
.where(eq(User.id, userId))
.limit(1);
if (!user) {
return { ok: false as const, error: "User not found" };
}
await db.transaction(async (tx) => {
const [existing] = await tx
.select({ id: Sanctions.id })
.from(Sanctions)
.where(eq(Sanctions.habboId, userId))
.limit(1);
if (existing) {
await tx
.update(Sanctions)
.set({
tradeLockedUntil: until,
...(locked ? { reason: "Trade lock (CMS)" } : {}),
})
.where(eq(Sanctions.id, existing.id));
} else {
await tx.insert(Sanctions).values({
habboId: userId,
tradeLockedUntil: until,
reason: until > 0 ? "Trade lock (CMS)" : "",
},
});
reason: locked ? "Trade lock (CMS)" : "",
});
}
await tx
.update(UsersSettings)
.set({
canTrade: locked ? "0" : "1",
...(locked
? { tradelockAmount: sql`${UsersSettings.tradelockAmount} + 1` }
: {}),
})
.where(eq(UsersSettings.userId, userId));
});
await rcon.setTradeLock(userId, locked);
await rcon.alertUser(
userId,
locked
? "Trading has been disabled by staff."
: "Trading has been re-enabled by staff.",
);
if (user.online === "1") {
await rcon.disconnectUser(userId, user.username);
}
await logStaffActivity({
staffId: staff.id,
action: until > 0 ? "trade_lock" : "trade_unlock",
description:
until > 0
? `Trade-locked user #${userId} until ${until}`
: `Cleared trade lock for user #${userId}`,
action: locked ? "trade_lock" : "trade_unlock",
description: locked
? `Trade-locked ${user.username} (#${userId}) until ${until}`
: `Cleared trade lock for ${user.username} (#${userId})`,
targetType: "user",
targetId: userId,
});