Files
EpicNext-Cms/src/components/public/radio-player-gate.tsx
T
Simo 80f591a343 Add public REST API, anti-abuse protections, radio/GitHub cron jobs
Phase A — Public REST API (was the biggest gap). 20 JSON endpoints under
/api mirroring AtomCMS: users/[username], online(+/count), me, articles
(+/[slug]), photos, home, staff, teams, leaderboard, shop(+/categories),
values(+/categories), settings, radio/{config,now-playing,listeners,
shouts}. Shared src/lib/api.ts (apiJson — BigInt-safe + CORS, pagination).
Read-only, fail-soft, and field-safe (never exposes password/auth_ticket/
2FA secrets/mail).

Phase B — Anti-abuse on registration: CAPTCHA (Cloudflare Turnstile /
Google reCAPTCHA, settings-driven, widget rendered on the register page),
VPN/proxy detection (proxycheck.io / IPQualityScore via /admin/vpn
settings), and max-accounts-per-IP. All fail-open when unconfigured.
src/lib/services/{captcha,ip-lookup}.ts.

Phase C — jobs-worker cron suite: radio-record-songs (30s, logs track
changes to radio_song_plays), radio-auto-dj (rotates radio_auto_dj_playlist
when no live DJ), github-update-check (hourly, sets update_available).
Shared src/lib/services/radio.ts (now-playing/listeners parsing).

Verified live (prod, amx_test): /api/* return real JSON (leaderboard 6
users, settings carry no secrets, user endpoint hides password). tsc 0,
vitest 49/49, next build 0 (20 new API routes).
2026-06-28 21:44:02 +02:00

34 lines
1.2 KiB
TypeScript

import { siteSettings } from "@/lib/services/site-settings";
import RadioPlayer from "./radio-player";
/**
* Server-side guard for the radio player widget. Reads the radio_* settings on
* the server and only mounts the client <RadioPlayer> when the radio is enabled
* AND a stream URL is configured — so the widget's JS (and the polling it does)
* is never shipped to the browser while the radio is off.
*
* Mount this once in the public layout. It is intentionally tiny: the live
* config the player actually plays is refreshed client-side from
* /api/radio/config, which lets staff toggle the radio without a redeploy.
*/
export default async function RadioPlayerGate() {
let enabled = false;
let streamUrl = "";
try {
const [enabledRaw, urlRaw] = await Promise.all([
siteSettings.get("radio_enabled", "0"),
siteSettings.get("radio_stream_url", ""),
]);
const flag = (enabledRaw ?? "0").trim().toLowerCase();
enabled = flag === "1" || flag === "true";
streamUrl = (urlRaw ?? "").trim();
} catch {
// Settings unavailable — fail closed (no widget).
return null;
}
if (!enabled || !streamUrl) return null;
return <RadioPlayer />;
}