- Fix missing await in pets API route causing empty responses - Fix updateSetting to use upsert pattern instead of update-only - Create missing /api/admin/sounds/upload route (upload was broken) - Wire bulk delete actions in catalog table - Replace native confirm() with useConfirmDialog() across rooms and clone pages - Add error logging to silent catch blocks in radio actions and audit route - Add graceful degradation to devops health endpoint - Add cache eviction to clone icon route to prevent memory leak - Internationalize hardcoded Italian strings to English - Remove placeholder created_at fields from prefix API responses - Remove dead code and fix type errors in translations and import pages - Standardize PERMS import path in analytics export route
50 lines
1.2 KiB
TypeScript
50 lines
1.2 KiB
TypeScript
import { sql } from "drizzle-orm";
|
|
import { withAdmin } from "@/lib/api-handler";
|
|
import { apiError, apiOk } from "@/lib/api-response";
|
|
import { db } from "@/lib/db";
|
|
import { PERMS } from "@/lib/permissions";
|
|
|
|
interface BlacklistWord {
|
|
id: number;
|
|
word: string;
|
|
}
|
|
|
|
export const GET = withAdmin({ permission: PERMS.PREFIXES_VIEW }, async () => {
|
|
const [words] = (await db.execute(
|
|
sql`SELECT id, word FROM custom_prefix_blacklist ORDER BY word ASC`,
|
|
)) as unknown as [BlacklistWord[], unknown];
|
|
|
|
return apiOk({ words });
|
|
});
|
|
|
|
export const POST = withAdmin(
|
|
{ permission: PERMS.PREFIXES_EDIT },
|
|
async (request) => {
|
|
const body = await request.json();
|
|
const word = typeof body.word === "string" ? body.word.trim() : "";
|
|
|
|
if (!word) return apiError("Word is required");
|
|
|
|
await db.execute(
|
|
sql`INSERT INTO custom_prefix_blacklist (word) VALUES (${word})`,
|
|
);
|
|
|
|
return apiOk();
|
|
},
|
|
);
|
|
|
|
export const DELETE = withAdmin(
|
|
{ permission: PERMS.PREFIXES_EDIT },
|
|
async (request) => {
|
|
const body = await request.json();
|
|
const id = Number(body.id);
|
|
|
|
if (!Number.isInteger(id) || id <= 0)
|
|
return apiError("Missing or invalid word id");
|
|
|
|
await db.execute(sql`DELETE FROM custom_prefix_blacklist WHERE id = ${id}`);
|
|
|
|
return apiOk({ deleted: id });
|
|
},
|
|
);
|