- Fix DOMPurify SSR crash (use isomorphic-dompurify) - Fix SanitizedHtml to sanitize by default - Add auth guards to studio/catalog maintenance pages - Add update/edit to vouchers CRUD - Add update/edit to rare-values CRUD - Add approve workflow to applications page - Add edit form to guilds detail page - Add SEO metadata to all public pages (21 pages) - Fix mobile nav accessibility (focus trap, aria attributes) - Fix missing labels and table accessibility - Add dynamic imports for heavy client components (6 components) - Fix silent error swallowing (40+ locations) - Add content scheduling for articles (publishAt, status) - Wire up 12 missing webhook notification triggers - Add global search to admin panel - Add bulk actions to admin users table - Fix JSON formatting and a11y issues
203 lines
5.3 KiB
TypeScript
203 lines
5.3 KiB
TypeScript
"use server";
|
|
|
|
import { eq } from "drizzle-orm";
|
|
import { revalidatePath } from "next/cache";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import { db, WebsiteRareValueCategories, WebsiteRareValues } from "@/lib/db";
|
|
import { formPositiveBigInt } from "@/lib/form-data";
|
|
import { PERMS } from "@/lib/permissions";
|
|
|
|
export async function createCategory(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const name = String(formData.get("name") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const badge = String(formData.get("badge") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const priorityRaw = Number(formData.get("priority"));
|
|
const priority =
|
|
Number.isFinite(priorityRaw) && priorityRaw > 0
|
|
? Math.floor(priorityRaw)
|
|
: 1;
|
|
if (!name || !badge) return;
|
|
|
|
try {
|
|
await db.insert(WebsiteRareValueCategories).values({
|
|
name,
|
|
badge,
|
|
priority,
|
|
});
|
|
} catch {
|
|
// Unique name collision or DB error — ignore, page will re-render unchanged.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|
|
|
|
export async function deleteCategory(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const id = formPositiveBigInt(formData, "id");
|
|
if (!id) return;
|
|
|
|
try {
|
|
// Remove the category's values first to avoid orphaned rows.
|
|
await db
|
|
.delete(WebsiteRareValues)
|
|
.where(eq(WebsiteRareValues.categoryId, id));
|
|
await db
|
|
.delete(WebsiteRareValueCategories)
|
|
.where(eq(WebsiteRareValueCategories.id, id));
|
|
} catch {
|
|
// Not found or DB error — ignore.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|
|
|
|
export async function createValue(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const categoryId = formPositiveBigInt(formData, "categoryId");
|
|
if (!categoryId) return;
|
|
|
|
const name = String(formData.get("name") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const furnitureIcon = String(formData.get("furnitureIcon") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
if (!name || !furnitureIcon) return;
|
|
|
|
const itemIdRaw = Number(formData.get("itemId"));
|
|
const itemId =
|
|
Number.isFinite(itemIdRaw) && itemIdRaw > 0 ? Math.floor(itemIdRaw) : null;
|
|
|
|
const creditValueRaw = String(formData.get("creditValue") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const currencyValueRaw = String(formData.get("currencyValue") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const currencyType =
|
|
String(formData.get("currencyType") ?? "diamonds")
|
|
.trim()
|
|
.slice(0, 255) || "diamonds";
|
|
|
|
try {
|
|
await db.insert(WebsiteRareValues).values({
|
|
categoryId,
|
|
itemId,
|
|
name,
|
|
creditValue: creditValueRaw || null,
|
|
currencyValue: currencyValueRaw || null,
|
|
currencyType,
|
|
furnitureIcon,
|
|
});
|
|
} catch {
|
|
// DB error — ignore.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|
|
|
|
export async function deleteValue(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const id = formPositiveBigInt(formData, "id");
|
|
if (!id) return;
|
|
|
|
try {
|
|
await db.delete(WebsiteRareValues).where(eq(WebsiteRareValues.id, id));
|
|
} catch {
|
|
// Not found or DB error — ignore.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|
|
|
|
export async function updateCategory(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const id = formPositiveBigInt(formData, "id");
|
|
if (!id) return;
|
|
|
|
const name = String(formData.get("name") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const badge = String(formData.get("badge") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const priorityRaw = Number(formData.get("priority"));
|
|
const priority =
|
|
Number.isFinite(priorityRaw) && priorityRaw > 0
|
|
? Math.floor(priorityRaw)
|
|
: 1;
|
|
if (!name || !badge) return;
|
|
|
|
try {
|
|
await db
|
|
.update(WebsiteRareValueCategories)
|
|
.set({ name, badge, priority })
|
|
.where(eq(WebsiteRareValueCategories.id, id));
|
|
} catch {
|
|
// Unique name collision or DB error — ignore.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|
|
|
|
export async function updateValue(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.SHOP_EDIT);
|
|
const id = formPositiveBigInt(formData, "id");
|
|
if (!id) return;
|
|
|
|
const categoryId = formPositiveBigInt(formData, "categoryId");
|
|
|
|
const name = String(formData.get("name") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const furnitureIcon = String(formData.get("furnitureIcon") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
if (!name || !furnitureIcon) return;
|
|
|
|
const itemIdRaw = Number(formData.get("itemId"));
|
|
const itemId =
|
|
Number.isFinite(itemIdRaw) && itemIdRaw > 0 ? Math.floor(itemIdRaw) : null;
|
|
|
|
const creditValueRaw = String(formData.get("creditValue") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const currencyValueRaw = String(formData.get("currencyValue") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
const currencyType =
|
|
String(formData.get("currencyType") ?? "diamonds")
|
|
.trim()
|
|
.slice(0, 255) || "diamonds";
|
|
|
|
try {
|
|
const sets: Record<string, unknown> = {
|
|
name,
|
|
itemId,
|
|
creditValue: creditValueRaw || null,
|
|
currencyValue: currencyValueRaw || null,
|
|
currencyType,
|
|
furnitureIcon,
|
|
};
|
|
if (categoryId) sets.categoryId = categoryId;
|
|
await db
|
|
.update(WebsiteRareValues)
|
|
.set(sets)
|
|
.where(eq(WebsiteRareValues.id, id));
|
|
} catch {
|
|
// DB error — ignore.
|
|
}
|
|
revalidatePath("/admin/rare-values");
|
|
}
|