Add security middleware, audit log, alerts, PayPal, cron, radio + apps

Security (launch blockers):
- src/middleware.ts (edge): forwards x-pathname + real client IP.
- access-guard.ts (Node, from root layout): routes non-staff to /maintenance
  when maintenance mode is on, banned users to /banned. New /banned + /maintenance
  pages (the consumers the admin toggle was missing). Admin layout enforces
  force_staff_2fa before /admin.
- staff-activity.ts audit log wired into ban/lift/give-currency/set-rank actions.

Infra (parallel agents): alert service (alert_logs + Discord embed + email),
PayPal top-up (create/capture API routes + /shop/topup), cron worker
(scripts/jobs-worker.ts via croner: emulator-ping->alert, maintenance-check,
bans-cleanup), social connections page, admin radio settings/banners/ranks.
Public radio subsystem: /radio (+schedule, shouts+post, contests, giveaways,
apply, leaderboard) and /apply/staff + /apply/team submission forms. Radio nav
link added. .env.example documents the new optional vars.

(radio song-requests dropped: its table is a stub in AtomCMS — columns added by
un-modeled alter-migrations.)

Verified: tsc exit 0, vitest 48/48, next build exit 0 (82 page routes).
This commit is contained in:
Simo committed 2026-06-28 15:10:19 +02:00
1 parent e19debb795
commit 22d53d0e9c
40 files changed
+3781 -6

No files matched your search

+141
View File
@@ -0,0 +1,141 @@
import { redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { siteSettings } from "@/lib/services/site-settings";
import { applyStaff } from "@/actions/applications";
export const dynamic = "force-dynamic";
// Canonical Habbo badge image CDN (same base used by the profile page).
const BADGE_IMG_BASE = "https://images.habbo.com/c_images/album1584";
function formatDeadline(d: Date | null | undefined): string {
if (!d) return "No deadline set";
return d.toISOString().slice(0, 16).replace("T", " ");
}
export default async function ApplyStaffPage() {
const session = await auth();
if (!session?.user?.id) redirect("/login");
const userId = Number(session.user.id);
const hotelName = (await siteSettings.get("hotel_name", "Atom")) ?? "Atom";
// ── Open positions ──────────────────────────────────────────
// Each query is isolated so a DB hiccup degrades that section to empty
// rather than 500-ing the whole page.
const positions = await prisma.websiteOpenPositions
.findMany({ orderBy: { createdAt: "desc" } })
.catch(() => []);
// Resolve display info for each position's rank. The rich rank fields
// (rankName/badge/jobDescription/staffColor) live in website_teams, keyed by
// the same rank id the position's permission_id points at.
const rankIds = Array.from(new Set(positions.map((p) => p.permissionId)));
const teams = rankIds.length
? await prisma.websiteTeams
.findMany({
where: { id: { in: rankIds.map((r) => BigInt(r)) } },
})
.catch(() => [])
: [];
const teamByRankId = new Map(teams.map((t) => [Number(t.id), t]));
// Ranks this user has already applied for (block re-applying).
const myApps = await prisma.websiteStaffApplications
.findMany({ where: { userId }, select: { rankId: true } })
.catch(() => []);
const appliedRankIds = new Set(myApps.map((a) => a.rankId));
return (
<main>
<div className="hero">
<h1 style={{ margin: "0 0 0.5rem" }}>Apply for {hotelName} staff</h1>
<p className="muted" style={{ margin: 0 }}>
We open staff applications every now and then. If you come across a position you feel you
would fit perfectly into, do not hesitate to apply for it.
</p>
</div>
{positions.length === 0 ? (
<div className="card">
<h3 style={{ marginTop: 0 }}>No positions open</h3>
<p className="muted" style={{ margin: 0 }}>
There are currently no positions open. Please come back at a later time to check if we
have any openings by then. Thank you for your interest.
</p>
</div>
) : (
<div className="grid cols-2">
{positions.map((position) => {
const team = teamByRankId.get(position.permissionId);
const rankName = team?.rankName ?? `Rank #${position.permissionId}`;
const alreadyApplied = appliedRankIds.has(position.permissionId);
return (
<article key={String(position.id)} className="card">
<div
style={{
display: "flex",
gap: "0.75rem",
alignItems: "center",
marginBottom: "0.5rem",
}}
>
{team?.badge ? (
/* eslint-disable-next-line @next/next/no-img-element */
<img
src={`${BADGE_IMG_BASE}/${team.badge}.gif`}
alt={rankName}
width={40}
height={40}
/>
) : null}
<div>
<h3 style={{ margin: 0, color: team?.staffColor || undefined }}>{rankName}</h3>
{team?.jobDescription ? (
<p className="muted" style={{ margin: 0 }}>
{team.jobDescription}
</p>
) : null}
</div>
</div>
<p style={{ margin: "0 0 0.5rem" }}>{position.description}</p>
<p className="muted" style={{ margin: "0 0 0.75rem" }}>
Application deadline: {formatDeadline(position.applyTo)}
</p>
{alreadyApplied ? (
<button type="button" className="btn btn-danger" disabled style={{ width: "100%" }}>
You have already applied for {rankName}
</button>
) : (
<form action={applyStaff}>
{/* rank_id is the position's permission id; the applicant is
re-read from the session inside the action. */}
<input type="hidden" name="rankId" value={String(position.permissionId)} />
<label htmlFor={`content-${position.id}`} className="muted">
About you
</label>
<textarea
id={`content-${position.id}`}
name="content"
required
minLength={10}
rows={5}
placeholder={`Tell us why you'd be a great ${rankName}…`}
style={{ width: "100%", margin: "0.4rem 0 0.75rem", resize: "vertical" }}
/>
<button type="submit" className="btn btn-secondary" style={{ width: "100%" }}>
Apply for {rankName}
</button>
</form>
)}
</article>
);
})}
</div>
)}
</main>
);
}
+124
View File
@@ -0,0 +1,124 @@
import { redirect } from "next/navigation";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { siteSettings } from "@/lib/services/site-settings";
import { applyTeam } from "@/actions/applications";
export const dynamic = "force-dynamic";
// Canonical Habbo badge image CDN (same base used by the profile page).
const BADGE_IMG_BASE = "https://images.habbo.com/c_images/album1584";
export default async function ApplyTeamPage() {
const session = await auth();
if (!session?.user?.id) redirect("/login");
const userId = Number(session.user.id);
const hotelName = (await siteSettings.get("hotel_name", "Atom")) ?? "Atom";
// ── Teams open for application ──────────────────────────────
// The Prisma slice exposes teams directly (no separate team-position table
// with position_kind), so the team application concept lists website_teams.
// Hidden ranks are excluded from the public apply page.
const teams = await prisma.websiteTeams
.findMany({
where: { hiddenRank: false },
orderBy: { rankName: "asc" },
})
.catch(() => []);
// Teams this user has already applied to. Team applications reuse the staff
// applications table with rank_id carrying the team id (the team flag).
const myApps = await prisma.websiteStaffApplications
.findMany({ where: { userId }, select: { rankId: true } })
.catch(() => []);
const appliedTeamIds = new Set(myApps.map((a) => a.rankId));
return (
<main>
<div className="hero">
<h1 style={{ margin: "0 0 0.5rem" }}>Apply for the {hotelName} team</h1>
<p className="muted" style={{ margin: 0 }}>
We open team applications periodically. If you see a team you fit, do not hesitate to
apply!
</p>
</div>
{teams.length === 0 ? (
<div className="card">
<h3 style={{ marginTop: 0 }}>No team positions open</h3>
<p className="muted" style={{ margin: 0 }}>
There are currently no open team positions. Please come back later to check for new
openings. Thank you!
</p>
</div>
) : (
<div className="grid cols-2">
{teams.map((team) => {
const teamId = Number(team.id);
const alreadyApplied = appliedTeamIds.has(teamId);
return (
<article key={String(team.id)} className="card">
<div
style={{
display: "flex",
gap: "0.75rem",
alignItems: "center",
marginBottom: "0.5rem",
}}
>
{team.badge ? (
/* eslint-disable-next-line @next/next/no-img-element */
<img
src={`${BADGE_IMG_BASE}/${team.badge}.gif`}
alt={team.rankName}
width={40}
height={40}
/>
) : null}
<div>
<h3 style={{ margin: 0, color: team.staffColor || undefined }}>
{team.rankName}
</h3>
{team.jobDescription ? (
<p className="muted" style={{ margin: 0 }}>
{team.jobDescription}
</p>
) : null}
</div>
</div>
{alreadyApplied ? (
<button type="button" className="btn btn-danger" disabled style={{ width: "100%" }}>
Your application is pending
</button>
) : (
<form action={applyTeam}>
{/* The team id is the application's rank flag; the applicant
is re-read from the session inside the action. */}
<input type="hidden" name="teamId" value={String(team.id)} />
<label htmlFor={`content-${team.id}`} className="muted">
About you
</label>
<textarea
id={`content-${team.id}`}
name="content"
required
minLength={10}
rows={5}
placeholder={`Tell us why you'd be a great fit for ${team.rankName}…`}
style={{ width: "100%", margin: "0.4rem 0 0.75rem", resize: "vertical" }}
/>
<button type="submit" className="btn btn-primary" style={{ width: "100%" }}>
Apply for {team.rankName}
</button>
</form>
)}
</article>
);
})}
</div>
)}
</main>
);
}