376 lines
9.1 KiB
TypeScript
376 lines
9.1 KiB
TypeScript
"use server";
|
|
|
|
import { and, eq, inArray, max, sql } from "drizzle-orm";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import {
|
|
Ban,
|
|
db,
|
|
Sanctions,
|
|
User,
|
|
UsersBadges,
|
|
UsersCurrency,
|
|
UsersSettings,
|
|
} from "@/lib/db";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import type { ActionResult } from "@/lib/safe-action-shared";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
|
|
export async function bulkUnban({
|
|
userIds,
|
|
}: {
|
|
userIds: number[];
|
|
}): Promise<ActionResult<{ unbanned: number; total: number }>> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
const result = await db.delete(Ban).where(inArray(Ban.userId, userIds));
|
|
const unbanned = Number(
|
|
(result as unknown as [{ affectedRows: number }])[0]?.affectedRows ?? 0,
|
|
);
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "bulk_unban",
|
|
description: `Unbanned ${unbanned} user(s)`,
|
|
targetType: "user",
|
|
});
|
|
return {
|
|
ok: true as const,
|
|
data: { unbanned, total: userIds.length },
|
|
};
|
|
}
|
|
|
|
export async function bulkBan({
|
|
userIds,
|
|
reason,
|
|
duration,
|
|
}: {
|
|
userIds: number[];
|
|
reason: string;
|
|
duration: number;
|
|
}): Promise<ActionResult<{ banned: number }>> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
const now = Math.floor(Date.now() / 1000);
|
|
let banned = 0;
|
|
|
|
for (const userId of userIds) {
|
|
try {
|
|
await db.insert(Ban).values({
|
|
userId,
|
|
ip: "",
|
|
machineId: "",
|
|
userStaffId: staff.id,
|
|
timestamp: now,
|
|
banExpire: duration > 0 ? now + duration : 0,
|
|
banReason: reason,
|
|
type: "account",
|
|
});
|
|
banned++;
|
|
} catch {
|
|
// skip duplicates
|
|
}
|
|
}
|
|
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "bulk_ban",
|
|
description: `Banned ${banned} user(s)`,
|
|
targetType: "user",
|
|
});
|
|
return { ok: true as const, data: { banned } };
|
|
}
|
|
|
|
export async function bulkGiveCurrency({
|
|
userIds,
|
|
amount,
|
|
type,
|
|
}: {
|
|
userIds: number[];
|
|
amount: number;
|
|
type: "credits" | "pixels" | "points";
|
|
}): Promise<
|
|
ActionResult<{
|
|
given: number;
|
|
total: number;
|
|
failedIds: Array<{ userId: number; reason: string }>;
|
|
}>
|
|
> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
let given = 0;
|
|
const failedIds: Array<{ userId: number; reason: string }> = [];
|
|
|
|
for (const userId of userIds) {
|
|
try {
|
|
if (type === "credits") {
|
|
await db
|
|
.update(User)
|
|
.set({ credits: sql`${User.credits} + ${amount}` })
|
|
.where(eq(User.id, userId));
|
|
await rcon.giveCredits(userId, amount);
|
|
} else if (type === "pixels") {
|
|
await db
|
|
.insert(UsersCurrency)
|
|
.values({ userId, type: 0, amount })
|
|
.onDuplicateKeyUpdate({
|
|
set: { amount: sql`${UsersCurrency.amount} + ${amount}` },
|
|
});
|
|
await rcon.giveDuckets(userId, amount);
|
|
} else if (type === "points") {
|
|
await db
|
|
.insert(UsersCurrency)
|
|
.values({ userId, type: 101, amount })
|
|
.onDuplicateKeyUpdate({
|
|
set: { amount: sql`${UsersCurrency.amount} + ${amount}` },
|
|
});
|
|
await rcon.givePointsGotw(userId, amount);
|
|
}
|
|
given++;
|
|
} catch {
|
|
failedIds.push({ userId, reason: "Database error" });
|
|
}
|
|
}
|
|
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "bulk_give_currency",
|
|
description: `Gave ${amount} ${type} to ${given} user(s)`,
|
|
targetType: "user",
|
|
});
|
|
return {
|
|
ok: true as const,
|
|
data: { given, total: userIds.length, failedIds },
|
|
};
|
|
}
|
|
|
|
export async function bulkGiveBadge({
|
|
userIds,
|
|
badgeCode,
|
|
}: {
|
|
userIds: number[];
|
|
badgeCode: string;
|
|
}): Promise<
|
|
ActionResult<{
|
|
given: number;
|
|
total: number;
|
|
failedIds: Array<{ userId: number; reason: string }>;
|
|
}>
|
|
> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
let given = 0;
|
|
const failedIds: Array<{ userId: number; reason: string }> = [];
|
|
|
|
for (const userId of userIds) {
|
|
try {
|
|
const [existing] = await db
|
|
.select({ id: UsersBadges.id })
|
|
.from(UsersBadges)
|
|
.where(
|
|
and(
|
|
eq(UsersBadges.userId, userId),
|
|
eq(UsersBadges.badgeCode, badgeCode),
|
|
),
|
|
)
|
|
.limit(1);
|
|
if (!existing) {
|
|
const [agg] = await db
|
|
.select({ maxSlot: max(UsersBadges.slotId) })
|
|
.from(UsersBadges)
|
|
.where(eq(UsersBadges.userId, userId));
|
|
const slotId = (agg?.maxSlot ?? 0) + 1;
|
|
await db.insert(UsersBadges).values({ userId, slotId, badgeCode });
|
|
await rcon.giveBadge(userId, badgeCode);
|
|
}
|
|
given++;
|
|
} catch {
|
|
failedIds.push({ userId, reason: "Database error" });
|
|
}
|
|
}
|
|
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "bulk_give_badge",
|
|
description: `Gave badge "${badgeCode}" to ${given} user(s)`,
|
|
targetType: "user",
|
|
});
|
|
return {
|
|
ok: true as const,
|
|
data: { given, total: userIds.length, failedIds },
|
|
};
|
|
}
|
|
|
|
export async function bulkAdjustCurrency({
|
|
userIds,
|
|
amount,
|
|
type,
|
|
}: {
|
|
userIds: number[];
|
|
/** Positive = give, negative = take. Balances clamped at 0. */
|
|
amount: number;
|
|
type: "credits" | "pixels" | "points";
|
|
}): Promise<
|
|
ActionResult<{
|
|
adjusted: number;
|
|
total: number;
|
|
failedIds: Array<{ userId: number; reason: string }>;
|
|
}>
|
|
> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
if (!Number.isFinite(amount) || amount === 0) {
|
|
return { ok: false as const, error: "Amount must be a non-zero number" };
|
|
}
|
|
|
|
if (amount > 0) {
|
|
const given = await bulkGiveCurrency({ userIds, amount, type });
|
|
if (!given.ok) return given;
|
|
if (!given.data) {
|
|
return { ok: false as const, error: "Currency adjustment failed" };
|
|
}
|
|
return {
|
|
ok: true as const,
|
|
data: {
|
|
adjusted: given.data.given,
|
|
total: given.data.total,
|
|
failedIds: given.data.failedIds,
|
|
},
|
|
};
|
|
}
|
|
|
|
const take = Math.abs(Math.trunc(amount));
|
|
let adjusted = 0;
|
|
const failedIds: Array<{ userId: number; reason: string }> = [];
|
|
|
|
for (const userId of userIds) {
|
|
try {
|
|
if (type === "credits") {
|
|
const [user] = await db
|
|
.select({ credits: User.credits })
|
|
.from(User)
|
|
.where(eq(User.id, userId))
|
|
.limit(1);
|
|
if (!user) {
|
|
failedIds.push({ userId, reason: "Not found" });
|
|
continue;
|
|
}
|
|
const next = Math.max(0, user.credits - take);
|
|
await db.update(User).set({ credits: next }).where(eq(User.id, userId));
|
|
} else {
|
|
const currencyType = type === "pixels" ? 0 : 101;
|
|
const [row] = await db
|
|
.select({ amount: UsersCurrency.amount })
|
|
.from(UsersCurrency)
|
|
.where(
|
|
and(
|
|
eq(UsersCurrency.userId, userId),
|
|
eq(UsersCurrency.type, currencyType),
|
|
),
|
|
)
|
|
.limit(1);
|
|
const current = row?.amount ?? 0;
|
|
const next = Math.max(0, current - take);
|
|
await db
|
|
.insert(UsersCurrency)
|
|
.values({ userId, type: currencyType, amount: next })
|
|
.onDuplicateKeyUpdate({ set: { amount: next } });
|
|
}
|
|
adjusted++;
|
|
} catch {
|
|
failedIds.push({ userId, reason: "Database error" });
|
|
}
|
|
}
|
|
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "bulk_adjust_currency",
|
|
description: `Adjusted ${amount} ${type} for ${adjusted} user(s) (DB-only take; no RCON debit)`,
|
|
targetType: "user",
|
|
});
|
|
return {
|
|
ok: true as const,
|
|
data: { adjusted, total: userIds.length, failedIds },
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Persist trade lock on `sanctions.trade_locked_until` + `users_settings.can_trade`
|
|
* via Drizzle, then best-effort RCON sync (settradelock + alert + disconnect if online).
|
|
*/
|
|
export async function setTradeLock({
|
|
userId,
|
|
untilUnix,
|
|
}: {
|
|
userId: number;
|
|
/** Unix seconds; 0 clears the lock. */
|
|
untilUnix: number;
|
|
}): Promise<ActionResult<{ userId: number; untilUnix: number }>> {
|
|
const staff = await requirePermission(PERMS.USERS_EDIT);
|
|
const until = Math.max(0, Math.trunc(untilUnix));
|
|
const locked = until > 0;
|
|
|
|
const [user] = await db
|
|
.select({
|
|
id: User.id,
|
|
username: User.username,
|
|
online: User.online,
|
|
})
|
|
.from(User)
|
|
.where(eq(User.id, userId))
|
|
.limit(1);
|
|
if (!user) {
|
|
return { ok: false as const, error: "User not found" };
|
|
}
|
|
|
|
await db.transaction(async (tx) => {
|
|
const [existing] = await tx
|
|
.select({ id: Sanctions.id })
|
|
.from(Sanctions)
|
|
.where(eq(Sanctions.habboId, userId))
|
|
.limit(1);
|
|
if (existing) {
|
|
await tx
|
|
.update(Sanctions)
|
|
.set({
|
|
tradeLockedUntil: until,
|
|
...(locked ? { reason: "Trade lock (CMS)" } : {}),
|
|
})
|
|
.where(eq(Sanctions.id, existing.id));
|
|
} else {
|
|
await tx.insert(Sanctions).values({
|
|
habboId: userId,
|
|
tradeLockedUntil: until,
|
|
reason: locked ? "Trade lock (CMS)" : "",
|
|
});
|
|
}
|
|
|
|
await tx
|
|
.update(UsersSettings)
|
|
.set({
|
|
canTrade: locked ? "0" : "1",
|
|
...(locked
|
|
? { tradelockAmount: sql`${UsersSettings.tradelockAmount} + 1` }
|
|
: {}),
|
|
})
|
|
.where(eq(UsersSettings.userId, userId));
|
|
});
|
|
|
|
await rcon.setTradeLock(userId, locked);
|
|
await rcon.alertUser(
|
|
userId,
|
|
locked
|
|
? "Trading has been disabled by staff."
|
|
: "Trading has been re-enabled by staff.",
|
|
);
|
|
if (user.online === "1") {
|
|
await rcon.disconnectUser(userId, user.username);
|
|
}
|
|
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: locked ? "trade_lock" : "trade_unlock",
|
|
description: locked
|
|
? `Trade-locked ${user.username} (#${userId}) until ${until}`
|
|
: `Cleared trade lock for ${user.username} (#${userId})`,
|
|
targetType: "user",
|
|
targetId: userId,
|
|
});
|
|
|
|
return { ok: true as const, data: { userId, untilUnix: until } };
|
|
}
|