Replace leftover requireStaff gates with module PERMS, drop hardcoded room rank thresholds, and expand contract tests so admin mutations cannot regress to dashboard-only checks. Co-authored-by: Cursor <[email protected]>
52 lines
1.4 KiB
TypeScript
52 lines
1.4 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { requirePermission } from "@/lib/admin/guard";
|
|
import { PERMS } from "@/lib/permissions";
|
|
import { prisma } from "@/lib/prisma";
|
|
|
|
export async function createTeam(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.USERS_EDIT);
|
|
|
|
const rankName = String(formData.get("rankName") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
if (!rankName) return;
|
|
|
|
const badge = String(formData.get("badge") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
const jobDescription = String(formData.get("jobDescription") ?? "")
|
|
.normalize("NFC")
|
|
.trim();
|
|
const staffColor =
|
|
String(formData.get("staffColor") ?? "")
|
|
.normalize("NFC")
|
|
.trim() || "#327fa8";
|
|
const hiddenRank = formData.get("hiddenRank") === "on";
|
|
|
|
const now = new Date();
|
|
await prisma.websiteTeams.create({
|
|
data: {
|
|
rankName: rankName.slice(0, 255),
|
|
badge: badge ? badge.slice(0, 255) : null,
|
|
jobDescription: jobDescription ? jobDescription.slice(0, 255) : null,
|
|
staffColor: staffColor.slice(0, 255),
|
|
hiddenRank,
|
|
createdAt: now,
|
|
updatedAt: now,
|
|
},
|
|
});
|
|
|
|
revalidatePath("/admin/teams");
|
|
}
|
|
|
|
export async function deleteTeam(formData: FormData): Promise<void> {
|
|
await requirePermission(PERMS.USERS_EDIT);
|
|
|
|
const id = BigInt(String(formData.get("id")));
|
|
await prisma.websiteTeams.delete({ where: { id } });
|
|
|
|
revalidatePath("/admin/teams");
|
|
}
|