Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks. Co-authored-by: Cursor <[email protected]>
87 lines
2.8 KiB
TypeScript
87 lines
2.8 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { requirePermission, requirePermissionRateLimited } from "@/lib/admin/guard";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import { prisma } from "@/lib/prisma";
|
|
import { rcon } from "@/lib/services/rcon";
|
|
import { type CurrencyName, sendCurrency } from "@/lib/services/send-currency";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
|
|
const CURRENCIES: ReadonlySet<string> = new Set([
|
|
"credits",
|
|
"duckets",
|
|
"diamonds",
|
|
"points",
|
|
]);
|
|
|
|
export async function giveCurrency(formData: FormData): Promise<void> {
|
|
const staff = await requirePermissionRateLimited(PERMS.USERS_EDIT);
|
|
const userId = Number(formData.get("userId"));
|
|
const type = String(formData.get("type"));
|
|
const amount = Number(formData.get("amount"));
|
|
if (userId > 0 && amount > 0 && CURRENCIES.has(type)) {
|
|
await sendCurrency(
|
|
{ rcon, db: prisma },
|
|
userId,
|
|
type as CurrencyName,
|
|
amount,
|
|
);
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "give_currency",
|
|
description: `Gave ${amount} ${type} to user #${userId}`,
|
|
targetType: "user",
|
|
targetId: userId,
|
|
});
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function setMotto(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.USERS_EDIT);
|
|
const userId = Number(formData.get("userId"));
|
|
const motto = String(formData.get("motto") ?? "")
|
|
.normalize("NFC")
|
|
.slice(0, 127);
|
|
if (userId > 0) {
|
|
await prisma.user.update({ where: { id: userId }, data: { motto } });
|
|
await rcon.setMotto(userId, motto);
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function setRank(formData: FormData): Promise<void> {
|
|
const staff = await requirePermissionRateLimited(PERMS.USERS_EDIT);
|
|
const userId = Number(formData.get("userId"));
|
|
const rank = Number(formData.get("rank"));
|
|
if (userId > 0 && rank > 0) {
|
|
await prisma.user.update({ where: { id: userId }, data: { rank } });
|
|
await rcon.setRank(userId, rank);
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "rank_change",
|
|
description: `Set rank of user #${userId} to ${rank}`,
|
|
targetType: "user",
|
|
targetId: userId,
|
|
});
|
|
}
|
|
revalidatePath(`/admin/users/${userId}`);
|
|
}
|
|
|
|
export async function alertUser(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.USERS_EDIT);
|
|
const userId = Number(formData.get("userId"));
|
|
const message = String(formData.get("message") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
if (userId > 0 && message) await rcon.alertUser(userId, message);
|
|
}
|
|
|
|
export async function disconnectUser(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.USERS_EDIT);
|
|
const userId = Number(formData.get("userId"));
|
|
const username = String(formData.get("username") ?? "").normalize("NFC");
|
|
if (userId > 0) await rcon.disconnectUser(userId, username);
|
|
}
|