Security (launch blockers): - src/middleware.ts (edge): forwards x-pathname + real client IP. - access-guard.ts (Node, from root layout): routes non-staff to /maintenance when maintenance mode is on, banned users to /banned. New /banned + /maintenance pages (the consumers the admin toggle was missing). Admin layout enforces force_staff_2fa before /admin. - staff-activity.ts audit log wired into ban/lift/give-currency/set-rank actions. Infra (parallel agents): alert service (alert_logs + Discord embed + email), PayPal top-up (create/capture API routes + /shop/topup), cron worker (scripts/jobs-worker.ts via croner: emulator-ping->alert, maintenance-check, bans-cleanup), social connections page, admin radio settings/banners/ranks. Public radio subsystem: /radio (+schedule, shouts+post, contests, giveaways, apply, leaderboard) and /apply/staff + /apply/team submission forms. Radio nav link added. .env.example documents the new optional vars. (radio song-requests dropped: its table is a stub in AtomCMS — columns added by un-modeled alter-migrations.) Verified: tsc exit 0, vitest 48/48, next build exit 0 (82 page routes).
38 lines
1.0 KiB
TypeScript
38 lines
1.0 KiB
TypeScript
import { headers } from "next/headers";
|
|
import { prisma } from "@/lib/prisma";
|
|
|
|
/**
|
|
* Append a staff-action audit entry (AtomCMS StaffActivity). Never throws —
|
|
* logging must not block the action it records.
|
|
*/
|
|
export async function logStaffActivity(opts: {
|
|
staffId: number;
|
|
action: string;
|
|
description: string;
|
|
targetType?: string;
|
|
targetId?: number;
|
|
}): Promise<void> {
|
|
try {
|
|
let ip: string | null = null;
|
|
try {
|
|
const h = await headers();
|
|
ip = h.get("x-real-client-ip") ?? h.get("x-forwarded-for")?.split(",")[0]?.trim() ?? null;
|
|
} catch {
|
|
ip = null;
|
|
}
|
|
await prisma.staffActivities.create({
|
|
data: {
|
|
userId: BigInt(opts.staffId),
|
|
action: opts.action.slice(0, 50),
|
|
description: opts.description,
|
|
targetType: opts.targetType ?? null,
|
|
targetId: opts.targetId != null ? BigInt(opts.targetId) : null,
|
|
ipAddress: ip,
|
|
createdAt: new Date(),
|
|
},
|
|
});
|
|
} catch {
|
|
// swallow — audit logging is best-effort
|
|
}
|
|
}
|