Harden admin ACL on critical write paths.
Local Build and Deploy / deploy (push) Successful in 54s

Gate translations, RCON, and user mutations on SETTINGS_EDIT, RCON_EXECUTE, and USERS_EDIT instead of dashboard/rank checks; redirect the legacy user-edit URL to the guarded canonical page.

Co-authored-by: Cursor <[email protected]>
This commit is contained in:
SimoandCursor committed 2026-07-15 20:07:15 +02:00
1 parent bae543baf6
commit f2427b3483
8 files changed
+127 -284

No files matched your search

+7 -188
View File
@@ -1,197 +1,16 @@
import { User } from "lucide-react";
import Link from "next/link";
import { notFound } from "next/navigation";
import { getTranslations } from "next-intl/server";
import { updateUser } from "@/actions/admin-user-edit";
import { requireStaff } from "@/lib/admin/guard";
import { prisma } from "@/lib/prisma";
import { redirect } from "next/navigation";
export const dynamic = "force-dynamic";
// users_currency.type values for the non-credits currencies (see send-currency.ts).
const DUCKETS_TYPE = 0;
const DIAMONDS_TYPE = 5;
export default async function AdminUserEdit({
/**
* Legacy URL — the canonical edit UI lives at /admin/users/edit/[id]
* and is gated by PERMS.USERS_EDIT.
*/
export default async function AdminUserEditRedirect({
params,
}: {
params: Promise<{ id: string }>;
}) {
// Gate the page with the SAME helper the action re-checks.
await requireStaff();
const { id } = await params;
const t = await getTranslations("pages.admin.users.editForm");
const userId = Number(id);
if (!Number.isInteger(userId) || userId <= 0) notFound();
let user: {
id: number;
username: string;
mail: string | null;
motto: string;
look: string;
rank: number;
credits: number;
pixels: number;
points: number;
} | null = null;
let duckets = 0;
let diamonds = 0;
try {
user = await prisma.user.findUnique({
where: { id: userId },
select: {
id: true,
username: true,
mail: true,
motto: true,
look: true,
rank: true,
credits: true,
pixels: true,
points: true,
},
});
if (user) {
const currencies = await prisma.usersCurrency.findMany({
where: { userId, type: { in: [DUCKETS_TYPE, DIAMONDS_TYPE] } },
select: { type: true, amount: true },
});
for (const c of currencies) {
if (c.type === DUCKETS_TYPE) duckets = c.amount;
else if (c.type === DIAMONDS_TYPE) diamonds = c.amount;
}
}
} catch {
return (
<main>
<p className="text-sm theme-text-muted dark:theme-text-muted">
<Link href="/admin/users">← {t("title")}</Link>
</p>
<h1>{t("title")}</h1>
<p className="text-xs theme-text-muted dark:theme-text-muted">
{t("loadError")}
</p>
</main>
);
}
if (!user) notFound();
return (
<main>
<p className="text-sm theme-text-muted dark:theme-text-muted mb-2">
<Link href={`/admin/users/${user.id}`}>← {user.username}</Link>
</p>
<div className="flex items-center gap-3 mb-6">
<div className="w-10 h-10 rounded-xl bg-gradient-to-br from-[var(--admin-accent)]/20 to-[var(--admin-accent)]/5 grid place-items-center">
<User size={20} className="text-[var(--admin-accent)]" />
</div>
<div>
<h1 className="m-0 text-xl font-extrabold text-[var(--admin-text)]">
{t("title", { username: user.username })}
</h1>
<p className="m-0 text-xs text-[var(--admin-text-muted)] mt-0.5">
{t("idLabel", { id: user.id })}
</p>
</div>
</div>
<form action={updateUser} className="admin-card">
<input type="hidden" name="id" value={user.id} />
<div className="grid grid-cols-1 gap-4 md:grid-cols-2">
<label>
{t("email")}
<input
name="mail"
type="email"
defaultValue={user.mail ?? ""}
maxLength={500}
/>
</label>
<label>
{t("rank")}
<input name="rank" type="number" min={1} defaultValue={user.rank} />
</label>
<label>
{t("motto")}
<input name="motto" defaultValue={user.motto} maxLength={127} />
</label>
<label>
{t("look")}
<input name="look" defaultValue={user.look} maxLength={256} />
</label>
<label>
{t("credits")}
<input
name="credits"
type="number"
min={0}
defaultValue={user.credits}
/>
</label>
<label>
{t("pixels")}
<input
name="pixels"
type="number"
min={0}
defaultValue={user.pixels}
/>
</label>
<label>
{t("points")}
<input
name="points"
type="number"
min={0}
defaultValue={user.points}
/>
</label>
<label>
{t("duckets")}
<input
name="duckets"
type="number"
min={0}
defaultValue={duckets}
/>
</label>
<label>
{t("diamonds")}
<input
name="diamonds"
type="number"
min={0}
defaultValue={diamonds}
/>
</label>
</div>
<p className="text-xs theme-text-muted dark:theme-text-muted">
{t("hint")}
</p>
<div className="flex gap-2 mt-2">
<button type="submit" className="btn btn-primary">
{t("save")}
</button>
<Link href={`/admin/users/${user.id}`} className="btn">
{t("cancel")}
</Link>
</div>
</form>
</main>
);
redirect(`/admin/users/edit/${id}`);
}