137 lines
3.8 KiB
TypeScript
137 lines
3.8 KiB
TypeScript
"use server";
|
|
|
|
import { mkdir, unlink, writeFile } from "node:fs/promises";
|
|
import path from "node:path";
|
|
import { eq } from "drizzle-orm";
|
|
import { revalidatePath } from "next/cache";
|
|
import { db, WebsiteSetting } from "@/lib/db";
|
|
import { resolveMediaPath } from "@/lib/media-storage";
|
|
import { siteSettings } from "@/lib/services/site-settings";
|
|
|
|
const FAVICON_DIR = resolveMediaPath("favicon");
|
|
const MAX_SIZE = 2 * 1024 * 1024; // 2MB
|
|
const ALLOWED = [
|
|
"image/png",
|
|
"image/jpeg",
|
|
"image/gif",
|
|
"image/webp",
|
|
"image/x-icon",
|
|
"image/svg+xml",
|
|
];
|
|
|
|
export async function saveFavicon(
|
|
formData: FormData,
|
|
): Promise<{ success: boolean; url?: string; error?: string }> {
|
|
try {
|
|
const file = formData.get("file") as File | null;
|
|
if (!file || file.size === 0)
|
|
return { success: false, error: "No file provided" };
|
|
if (file.size > MAX_SIZE)
|
|
return { success: false, error: "File too large (max 2MB)" };
|
|
if (!ALLOWED.includes(file.type))
|
|
return {
|
|
success: false,
|
|
error: "Invalid file type. Allowed: PNG, JPEG, GIF, WebP, ICO, SVG",
|
|
};
|
|
|
|
const mimeExt: Record<string, string> = {
|
|
"image/png": "png",
|
|
"image/jpeg": "jpg",
|
|
"image/gif": "gif",
|
|
"image/webp": "webp",
|
|
"image/x-icon": "ico",
|
|
"image/svg+xml": "svg",
|
|
};
|
|
const ext = mimeExt[file.type] ?? "png";
|
|
const filename = `favicon-${Date.now()}.${ext}`;
|
|
const baseDir = FAVICON_DIR;
|
|
const filePath = path.resolve(baseDir, filename);
|
|
if (!filePath.startsWith(baseDir + path.sep)) {
|
|
return { success: false, error: "Invalid path" };
|
|
}
|
|
|
|
const buffer = Buffer.from(await file.arrayBuffer());
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
await mkdir(baseDir, { recursive: true });
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
await writeFile(filePath, buffer);
|
|
|
|
const url = `/api/media/favicon/${filename}`;
|
|
|
|
// Remove old favicon file if it exists
|
|
const oldUrl = await siteSettings.get("cms_favicon");
|
|
if (oldUrl?.startsWith("/api/media/favicon/")) {
|
|
const oldName = oldUrl.replace("/api/media/favicon/", "");
|
|
if (!oldName.includes("..") && !oldName.includes("/")) {
|
|
const oldPath = path.resolve(baseDir, oldName);
|
|
if (oldPath.startsWith(baseDir + path.sep)) {
|
|
try {
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
await unlink(oldPath);
|
|
} catch {
|
|
/* ignore if file doesn't exist */
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
await db
|
|
.insert(WebsiteSetting)
|
|
.values({ key: "cms_favicon", value: url, comment: "Favicon URL" })
|
|
.onDuplicateKeyUpdate({ set: { value: url } });
|
|
|
|
siteSettings.reload();
|
|
revalidatePath("/", "layout");
|
|
revalidatePath("/admin/favicon");
|
|
|
|
return { success: true, url };
|
|
} catch (e) {
|
|
return {
|
|
success: false,
|
|
error: e instanceof Error ? e.message : "Unknown error",
|
|
};
|
|
}
|
|
}
|
|
|
|
export async function deleteFavicon(): Promise<{
|
|
success: boolean;
|
|
error?: string;
|
|
}> {
|
|
try {
|
|
const oldUrl = await siteSettings.get("cms_favicon");
|
|
if (oldUrl?.startsWith("/api/media/favicon/")) {
|
|
const baseDir = FAVICON_DIR;
|
|
const oldName = oldUrl.replace("/api/media/favicon/", "");
|
|
if (!oldName.includes("..") && !oldName.includes("/")) {
|
|
const oldPath = path.resolve(baseDir, oldName);
|
|
if (oldPath.startsWith(baseDir + path.sep)) {
|
|
try {
|
|
// eslint-disable-next-line security/detect-non-literal-fs-filename
|
|
await unlink(oldPath);
|
|
} catch {
|
|
/* ignore */
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
try {
|
|
await db
|
|
.delete(WebsiteSetting)
|
|
.where(eq(WebsiteSetting.key, "cms_favicon"));
|
|
} catch {
|
|
/* ignore missing row */
|
|
}
|
|
siteSettings.reload();
|
|
revalidatePath("/", "layout");
|
|
revalidatePath("/admin/favicon");
|
|
|
|
return { success: true };
|
|
} catch (e) {
|
|
return {
|
|
success: false,
|
|
error: e instanceof Error ? e.message : "Unknown error",
|
|
};
|
|
}
|
|
}
|