"use server"; import { revalidatePath } from "next/cache"; import { auth } from "@/lib/auth"; import { prisma } from "@/lib/prisma"; import { isAllowed } from "@/lib/services/moderation"; // Emulator/CMS column message is VARCHAR(255); keep the write within bounds. const MESSAGE_MAX = 255; /** * Post a guestbook entry on a profile. * * The AUTHOR (userId) is re-read from the session via auth() and is never * trusted from the submitted FormData, so a crafted form cannot impersonate * another account. Only the PROFILE OWNER id (whose guestbook is written) is * taken from the form, and we resolve a profile username from the form purely * to revalidate the right page. */ export async function postGuestbook(formData: FormData): Promise { const session = await auth(); const userId = Number(session?.user?.id); if (!Number.isInteger(userId) || userId <= 0) return; const profileId = Number(formData.get("profileId")); if (!Number.isInteger(profileId) || profileId <= 0) return; const message = String(formData.get("message") ?? "").trim().slice(0, MESSAGE_MAX); if (!message) return; // Block filtered/AI-flagged content before it touches the DB (fail-open). if (!(await isAllowed(message)).ok) return; // Optional: used only to revalidate the correct profile route. const username = String(formData.get("username") ?? "").trim(); const now = new Date(); try { await prisma.websiteUserGuestbooks.create({ data: { profileId, userId, message, createdAt: now, updatedAt: now, }, }); } catch { // DB unavailable — fail soft; nothing to persist. return; } if (username) revalidatePath(`/u/${username}`); }