fix: enforce public contrast and audit rank errors
This commit is contained in:
1 parent
e1381c0f40
commit
b695a33ead
12 files changed
+184
-29
No files matched your search
+10
-24
@@ -2,6 +2,7 @@ import { getTranslations } from "next-intl/server";
|
||||
import { ScrollText } from "lucide-react";
|
||||
import { StatusCard } from "@/components/admin/dashboard";
|
||||
import { prisma } from "@/lib/prisma";
|
||||
import { buildStaffActivityWhere } from "@/lib/admin/log-filters";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -14,7 +15,7 @@ function fromDate(d: Date | null | undefined): string {
|
||||
export default async function AdminStaffActivities({
|
||||
searchParams,
|
||||
}: {
|
||||
searchParams: Promise<{ q?: string; page?: string; staffId?: string; action?: string }>;
|
||||
searchParams: Promise<{ q?: string; page?: string; staffId?: string; action?: string; authorization?: string }>;
|
||||
}) {
|
||||
const t = await getTranslations("pages.admin.logs");
|
||||
|
||||
@@ -23,27 +24,8 @@ export default async function AdminStaffActivities({
|
||||
const page = Math.max(1, Number(sp.page ?? "1") || 1);
|
||||
const staffId = sp.staffId ? Number(sp.staffId) : null;
|
||||
const action = sp.action ?? null;
|
||||
|
||||
let whereClause = {};
|
||||
if (q) {
|
||||
whereClause = {
|
||||
OR: [{ action: { contains: q } }, { description: { contains: q } }, { ipAddress: { contains: q } }],
|
||||
};
|
||||
}
|
||||
|
||||
if (staffId) {
|
||||
whereClause = {
|
||||
...whereClause,
|
||||
userId: BigInt(staffId),
|
||||
};
|
||||
}
|
||||
|
||||
if (action) {
|
||||
whereClause = {
|
||||
...whereClause,
|
||||
action: { contains: action },
|
||||
};
|
||||
}
|
||||
const authorizationOnly = sp.authorization === "1";
|
||||
const whereClause = buildStaffActivityWhere({ q, staffId, action, authorizationOnly });
|
||||
|
||||
const activities = await prisma.staffActivities
|
||||
.findMany({
|
||||
@@ -111,6 +93,10 @@ export default async function AdminStaffActivities({
|
||||
placeholder={t("searchPlaceholder")}
|
||||
className="flex-1 min-w-[200px]"
|
||||
/>
|
||||
<label className="flex items-center gap-2 text-sm">
|
||||
<input type="checkbox" name="authorization" value="1" defaultChecked={authorizationOnly} />
|
||||
Authorization errors
|
||||
</label>
|
||||
<input
|
||||
name="staffId"
|
||||
defaultValue={staffId?.toString()}
|
||||
@@ -127,7 +113,7 @@ export default async function AdminStaffActivities({
|
||||
<button type="submit" className="btn btn-primary">
|
||||
{t("filter")}
|
||||
</button>
|
||||
{(q || staffId || action) && (
|
||||
{(q || staffId || action || authorizationOnly) && (
|
||||
<a href="/admin/logs" className="btn btn-outline">
|
||||
{t("clearFilters")}
|
||||
</a>
|
||||
@@ -195,7 +181,7 @@ export default async function AdminStaffActivities({
|
||||
<>
|
||||
{" · "}
|
||||
<a
|
||||
href={`/admin/logs?q=${encodeURIComponent(q)}&staffId=${staffId || ""}&action=${action || ""}&page=${page + 1}`}
|
||||
href={`/admin/logs?q=${encodeURIComponent(q)}&staffId=${staffId || ""}&action=${action || ""}&authorization=${authorizationOnly ? "1" : ""}&page=${page + 1}`}
|
||||
>
|
||||
{t("next")} →
|
||||
</a>
|
||||
|
||||
Reference in new issue
Block a user