1. env.ts: APP_KEY placeholder detection with validation 2. schema.prisma: password column widened to varchar(255) for argon2id 3. auth.ts: trustHost restricted to development only 4. next.config.ts: added CSP, HSTS, X-Frame-Options, and other security headers 5. api.ts: CORS restricted to APP_URL instead of wildcard 6. register-form.tsx: migrated from REST API fetch to server action (useActionState) 7. twofactor.ts + 2fa page: TOTP recovery codes (8 one-time codes, generated and displayed) 8. register.ts: password min length 8 + complexity requirements (upper, lower, digit) 9. register.ts + help-tickets.ts + radio-shouts.ts: Zod schema validation 10. rate-limit.ts: improved periodic cleanup with aggressive eviction at 10k buckets 11. guard.ts + admin actions: rate-limited admin actions (30 req/min per staff) 12. help-tickets.ts + radio-shouts.ts: content moderation via moderateOrThrow
72 lines
2.6 KiB
TypeScript
72 lines
2.6 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { requireStaff, requireStaffRateLimited } from "@/lib/admin/guard";
|
|
import { prisma } from "@/lib/prisma";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import { type CurrencyName, sendCurrency } from "@/lib/services/send-currency";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
|
|
const CURRENCIES: ReadonlySet<string> = new Set(["credits", "duckets", "diamonds", "points"]);
|
|
|
|
export async function giveCurrency(formData: FormData): Promise<void> {
|
|
const staff = await requireStaffRateLimited();
|
|
const userId = Number(formData.get("userId"));
|
|
const type = String(formData.get("type"));
|
|
const amount = Number(formData.get("amount"));
|
|
if (userId > 0 && amount > 0 && CURRENCIES.has(type)) {
|
|
await sendCurrency({ rcon, db: prisma }, userId, type as CurrencyName, amount);
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "give_currency",
|
|
description: `Gave ${amount} ${type} to user #${userId}`,
|
|
targetType: "user",
|
|
targetId: userId,
|
|
});
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function setMotto(formData: FormData): Promise<void> {
|
|
await requireStaff();
|
|
const userId = Number(formData.get("userId"));
|
|
const motto = String(formData.get("motto") ?? "").slice(0, 127);
|
|
if (userId > 0) {
|
|
await prisma.user.update({ where: { id: userId }, data: { motto } });
|
|
await rcon.setMotto(userId, motto);
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function setRank(formData: FormData): Promise<void> {
|
|
const staff = await requireStaffRateLimited();
|
|
const userId = Number(formData.get("userId"));
|
|
const rank = Number(formData.get("rank"));
|
|
if (userId > 0 && rank > 0) {
|
|
await prisma.user.update({ where: { id: userId }, data: { rank } });
|
|
await rcon.setRank(userId, rank);
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "rank_change",
|
|
description: `Set rank of user #${userId} to ${rank}`,
|
|
targetType: "user",
|
|
targetId: userId,
|
|
});
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function alertUser(formData: FormData): Promise<void> {
|
|
await requireStaff();
|
|
const userId = Number(formData.get("userId"));
|
|
const message = String(formData.get("message") ?? "").trim();
|
|
if (userId > 0 && message) await rcon.alertUser(userId, message);
|
|
}
|
|
|
|
export async function disconnectUser(formData: FormData): Promise<void> {
|
|
await requireStaff();
|
|
const userId = Number(formData.get("userId"));
|
|
const username = String(formData.get("username") ?? "");
|
|
if (userId > 0) await rcon.disconnectUser(userId, username);
|
|
}
|