Local Build and Deploy / deploy (push) Successful in 56s
Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks. Co-authored-by: Cursor <[email protected]>
92 lines
2.5 KiB
TypeScript
92 lines
2.5 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { redirect } from "next/navigation";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import { formPositiveBigInt } from "@/lib/form-data";
|
|
import { prisma } from "@/lib/prisma";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
|
|
// CRUD for website advertisements (website_ads). Emulator does not own this
|
|
// table; it only stores an image URL rendered in the site layout/widgets.
|
|
|
|
export async function createAd(formData: FormData): Promise<void> {
|
|
const staff = await requirePermission(PERMS.PAGES_EDIT);
|
|
const image = String(formData.get("image") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
if (!image) return;
|
|
|
|
const now = new Date();
|
|
try {
|
|
const ad = await prisma.websiteAds.create({
|
|
data: { image, createdAt: now, updatedAt: now },
|
|
});
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "ad_create",
|
|
description: `Created advertisement #${ad.id} (${image})`,
|
|
targetType: "website_ad",
|
|
targetId: Number(ad.id),
|
|
});
|
|
} catch {
|
|
// DB error — page re-renders unchanged.
|
|
revalidatePath("/admin/ads");
|
|
return;
|
|
}
|
|
redirect("/admin/ads");
|
|
}
|
|
|
|
export async function updateAd(formData: FormData): Promise<void> {
|
|
const staff = await requirePermission(PERMS.PAGES_EDIT);
|
|
const raw = String(formData.get("id") ?? "").normalize("NFC");
|
|
if (!/^\d+$/.test(raw)) return;
|
|
const id = BigInt(raw);
|
|
const image = String(formData.get("image") ?? "")
|
|
.normalize("NFC")
|
|
.trim()
|
|
.slice(0, 255);
|
|
if (!image) return;
|
|
|
|
try {
|
|
await prisma.websiteAds.update({
|
|
where: { id },
|
|
data: { image, updatedAt: new Date() },
|
|
});
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "ad_update",
|
|
description: `Updated advertisement #${id} (${image})`,
|
|
targetType: "website_ad",
|
|
targetId: Number(id),
|
|
});
|
|
} catch {
|
|
// Not found or DB error — ignore.
|
|
revalidatePath(`/admin/ads/${id}`);
|
|
return;
|
|
}
|
|
redirect("/admin/ads");
|
|
}
|
|
|
|
export async function deleteAd(formData: FormData): Promise<void> {
|
|
const staff = await requirePermission(PERMS.PAGES_EDIT);
|
|
const id = formPositiveBigInt(formData, "id");
|
|
if (!id) return;
|
|
|
|
try {
|
|
await prisma.websiteAds.delete({ where: { id } });
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "ad_delete",
|
|
description: `Deleted advertisement #${id}`,
|
|
targetType: "website_ad",
|
|
targetId: Number(id),
|
|
});
|
|
} catch {
|
|
// Not found or DB error — ignore.
|
|
}
|
|
redirect("/admin/ads");
|
|
}
|