"use server"; import { revalidatePath } from "next/cache"; import { redirect } from "next/navigation"; import { requireStaff } from "@/lib/admin/guard"; import { prisma } from "@/lib/prisma"; import { logStaffActivity } from "@/lib/services/staff-activity"; import { formPositiveBigInt } from "@/lib/form-data"; import { logServerError } from "@/lib/server-log"; // Website store packages (website_shop_articles). This CMS-owned table backs // the public store; rows here are the buyable packages, not orders. The closest // "orders" record is website_paypal_transactions, exposed read-only by the page. /** Parse an UnsignedInt form value, returning null when blank/invalid/negative. */ function optUInt(formData: FormData, key: string): number | null { const raw = String(formData.get(key) ?? "") .normalize("NFC") .trim(); if (raw === "") return null; const n = Number(raw); if (!Number.isFinite(n) || n < 0) return null; return Math.floor(n); } /** Parse a required non-negative UnsignedInt, falling back to 0. */ function reqUInt(formData: FormData, key: string): number { const n = optUInt(formData, key); return n ?? 0; } export async function createShopArticle(formData: FormData): Promise { const staff = await requireStaff(); const name = String(formData.get("name") ?? "") .normalize("NFC") .trim() .slice(0, 255); if (!name) return; const now = new Date(); try { const created = await prisma.websiteShopArticles.create({ data: { name, info: String(formData.get("info") ?? "") .normalize("NFC") .trim() .slice(0, 255), iconUrl: String(formData.get("icon") ?? "") .normalize("NFC") .trim() .slice(0, 255), color: String(formData.get("color") ?? "") .normalize("NFC") .trim() .slice(0, 255), costs: reqUInt(formData, "costs"), giveRank: optUInt(formData, "giveRank"), credits: optUInt(formData, "credits"), duckets: optUInt(formData, "duckets"), diamonds: optUInt(formData, "diamonds"), badges: String(formData.get("badges") ?? "") .normalize("NFC") .trim() .slice(0, 255) || null, position: reqUInt(formData, "position"), createdAt: now, updatedAt: now, }, }); await logStaffActivity({ staffId: staff.id, action: "shop_create", description: `Created shop package "${name}" (${created.costs} costs)`, targetType: "shop_article", targetId: Number(created.id), }); } catch (error) { logServerError("admin.shop_create_failed", error, { staffId: staff.id, name }); // Unique constraint on `name` (or DB unavailable) — swallow and re-render. return; } redirect("/admin/shop"); } export async function updateShopArticle(formData: FormData): Promise { const staff = await requireStaff(); const id = formPositiveBigInt(formData, "id"); if (!id) return; const name = String(formData.get("name") ?? "") .normalize("NFC") .trim() .slice(0, 255); if (!name) return; try { await prisma.websiteShopArticles.update({ where: { id }, data: { name, info: String(formData.get("info") ?? "") .normalize("NFC") .trim() .slice(0, 255), iconUrl: String(formData.get("icon") ?? "") .normalize("NFC") .trim() .slice(0, 255), color: String(formData.get("color") ?? "") .normalize("NFC") .trim() .slice(0, 255), costs: reqUInt(formData, "costs"), giveRank: optUInt(formData, "giveRank"), credits: optUInt(formData, "credits"), duckets: optUInt(formData, "duckets"), diamonds: optUInt(formData, "diamonds"), badges: String(formData.get("badges") ?? "") .normalize("NFC") .trim() .slice(0, 255) || null, position: reqUInt(formData, "position"), updatedAt: new Date(), }, }); await logStaffActivity({ staffId: staff.id, action: "shop_update", description: `Updated shop package #${id} ("${name}")`, targetType: "shop_article", targetId: Number(id), }); } catch (error) { logServerError("admin.shop_update_failed", error, { staffId: staff.id, articleId: String(id), }); return; } revalidatePath(`/admin/shop/${id}`); redirect("/admin/shop"); } export async function deleteShopArticle(formData: FormData): Promise { const staff = await requireStaff(); const id = formPositiveBigInt(formData, "id"); if (!id) return; try { await prisma.websiteShopArticles.delete({ where: { id } }); await logStaffActivity({ staffId: staff.id, action: "shop_delete", description: `Deleted shop package #${id}`, targetType: "shop_article", targetId: Number(id), }); } catch (error) { logServerError("admin.shop_delete_failed", error, { staffId: staff.id, articleId: String(id), }); return; } redirect("/admin/shop"); }