Web-tier features completing the AtomCMS→Next.js conversion (slice 2): UI/UX: - Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage, no-flash boot script) wired into the nav. - i18n (next-intl, cookie-based / no URL routing): en + it catalogs, request.ts, provider in root layout, LanguageSwitcher; shell (nav, header, footer) fully translated. URLs + access-guard unchanged. - globals.css: --muted/--border aliases used across admin pages. User features: - /messages: offline messages + friend-request accept (server action re-reads session, two directional rows, idempotent). - Email verification: signed-token /verify route + sendVerification wired into register (best-effort, never blocks signup). - Article reactions: toggle UI on news/[slug] + server action. - Content moderation service (website_wordfilter + optional OpenAI moderations, fail-open) wired into article comments + guestbook. Admin CRUD parity (Filament replacement): - /admin/shop (+ new/[id]) packages CRUD + read-only orders. - /admin/transactions read-only PayPal log. - /admin/permissions, /admin/tags, /admin/ads (+ new/[id]), /admin/help-questions (+ new/[id]), /admin/radio/history, /admin/users/[id]/edit. All gated by requireStaff + logStaffActivity. Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new admin CRUD + /messages + /verify).
143 lines
4.3 KiB
TypeScript
143 lines
4.3 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { redirect } from "next/navigation";
|
|
import { requireStaff } from "@/lib/admin/guard";
|
|
import { prisma } from "@/lib/prisma";
|
|
import { logStaffActivity } from "@/lib/services/staff-activity";
|
|
|
|
// Website store packages (website_shop_articles). This CMS-owned table backs
|
|
// the public store; rows here are the buyable packages, not orders. The closest
|
|
// "orders" record is website_paypal_transactions, exposed read-only by the page.
|
|
|
|
/** Parse an UnsignedInt form value, returning null when blank/invalid/negative. */
|
|
function optUInt(formData: FormData, key: string): number | null {
|
|
const raw = String(formData.get(key) ?? "").trim();
|
|
if (raw === "") return null;
|
|
const n = Number(raw);
|
|
if (!Number.isFinite(n) || n < 0) return null;
|
|
return Math.floor(n);
|
|
}
|
|
|
|
/** Parse a required non-negative UnsignedInt, falling back to 0. */
|
|
function reqUInt(formData: FormData, key: string): number {
|
|
const n = optUInt(formData, key);
|
|
return n ?? 0;
|
|
}
|
|
|
|
export async function createShopArticle(formData: FormData): Promise<void> {
|
|
const staff = await requireStaff();
|
|
|
|
const name = String(formData.get("name") ?? "").trim().slice(0, 255);
|
|
if (!name) return;
|
|
|
|
const now = new Date();
|
|
try {
|
|
const created = await prisma.websiteShopArticles.create({
|
|
data: {
|
|
name,
|
|
info: String(formData.get("info") ?? "").trim().slice(0, 255),
|
|
icon: String(formData.get("icon") ?? "").trim().slice(0, 255),
|
|
color: String(formData.get("color") ?? "").trim().slice(0, 255),
|
|
costs: reqUInt(formData, "costs"),
|
|
giveRank: optUInt(formData, "giveRank"),
|
|
credits: optUInt(formData, "credits"),
|
|
duckets: optUInt(formData, "duckets"),
|
|
diamonds: optUInt(formData, "diamonds"),
|
|
badges: (String(formData.get("badges") ?? "").trim().slice(0, 255)) || null,
|
|
position: reqUInt(formData, "position"),
|
|
createdAt: now,
|
|
updatedAt: now,
|
|
},
|
|
});
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "shop_create",
|
|
description: `Created shop package "${name}" (${created.costs} costs)`,
|
|
targetType: "shop_article",
|
|
targetId: Number(created.id),
|
|
});
|
|
} catch {
|
|
// Unique constraint on `name` (or DB unavailable) — swallow and re-render.
|
|
return;
|
|
}
|
|
|
|
redirect("/admin/shop");
|
|
}
|
|
|
|
export async function updateShopArticle(formData: FormData): Promise<void> {
|
|
const staff = await requireStaff();
|
|
|
|
const raw = String(formData.get("id") ?? "").trim();
|
|
if (!raw) return;
|
|
let id: bigint;
|
|
try {
|
|
id = BigInt(raw);
|
|
} catch {
|
|
return;
|
|
}
|
|
|
|
const name = String(formData.get("name") ?? "").trim().slice(0, 255);
|
|
if (!name) return;
|
|
|
|
try {
|
|
await prisma.websiteShopArticles.update({
|
|
where: { id },
|
|
data: {
|
|
name,
|
|
info: String(formData.get("info") ?? "").trim().slice(0, 255),
|
|
icon: String(formData.get("icon") ?? "").trim().slice(0, 255),
|
|
color: String(formData.get("color") ?? "").trim().slice(0, 255),
|
|
costs: reqUInt(formData, "costs"),
|
|
giveRank: optUInt(formData, "giveRank"),
|
|
credits: optUInt(formData, "credits"),
|
|
duckets: optUInt(formData, "duckets"),
|
|
diamonds: optUInt(formData, "diamonds"),
|
|
badges: (String(formData.get("badges") ?? "").trim().slice(0, 255)) || null,
|
|
position: reqUInt(formData, "position"),
|
|
updatedAt: new Date(),
|
|
},
|
|
});
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "shop_update",
|
|
description: `Updated shop package #${id} ("${name}")`,
|
|
targetType: "shop_article",
|
|
targetId: Number(id),
|
|
});
|
|
} catch {
|
|
return;
|
|
}
|
|
|
|
revalidatePath(`/admin/shop/${id}`);
|
|
redirect("/admin/shop");
|
|
}
|
|
|
|
export async function deleteShopArticle(formData: FormData): Promise<void> {
|
|
const staff = await requireStaff();
|
|
|
|
const raw = String(formData.get("id") ?? "").trim();
|
|
if (!raw) return;
|
|
let id: bigint;
|
|
try {
|
|
id = BigInt(raw);
|
|
} catch {
|
|
return;
|
|
}
|
|
|
|
try {
|
|
await prisma.websiteShopArticles.delete({ where: { id } });
|
|
await logStaffActivity({
|
|
staffId: staff.id,
|
|
action: "shop_delete",
|
|
description: `Deleted shop package #${id}`,
|
|
targetType: "shop_article",
|
|
targetId: Number(id),
|
|
});
|
|
} catch {
|
|
return;
|
|
}
|
|
|
|
redirect("/admin/shop");
|
|
}
|