Web-tier features completing the AtomCMS→Next.js conversion (slice 2): UI/UX: - Dark mode: html.dark CSS-var overrides + ThemeSwitcher (localStorage, no-flash boot script) wired into the nav. - i18n (next-intl, cookie-based / no URL routing): en + it catalogs, request.ts, provider in root layout, LanguageSwitcher; shell (nav, header, footer) fully translated. URLs + access-guard unchanged. - globals.css: --muted/--border aliases used across admin pages. User features: - /messages: offline messages + friend-request accept (server action re-reads session, two directional rows, idempotent). - Email verification: signed-token /verify route + sendVerification wired into register (best-effort, never blocks signup). - Article reactions: toggle UI on news/[slug] + server action. - Content moderation service (website_wordfilter + optional OpenAI moderations, fail-open) wired into article comments + guestbook. Admin CRUD parity (Filament replacement): - /admin/shop (+ new/[id]) packages CRUD + read-only orders. - /admin/transactions read-only PayPal log. - /admin/permissions, /admin/tags, /admin/ads (+ new/[id]), /admin/help-questions (+ new/[id]), /admin/radio/history, /admin/users/[id]/edit. All gated by requireStaff + logStaffActivity. Verified: tsc 0, vitest 48/48, next build 0 (all routes incl. new admin CRUD + /messages + /verify).
55 lines
1.7 KiB
TypeScript
55 lines
1.7 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { auth } from "@/lib/auth";
|
|
import { prisma } from "@/lib/prisma";
|
|
import { isAllowed } from "@/lib/services/moderation";
|
|
|
|
// Emulator/CMS column message is VARCHAR(255); keep the write within bounds.
|
|
const MESSAGE_MAX = 255;
|
|
|
|
/**
|
|
* Post a guestbook entry on a profile.
|
|
*
|
|
* The AUTHOR (userId) is re-read from the session via auth() and is never
|
|
* trusted from the submitted FormData, so a crafted form cannot impersonate
|
|
* another account. Only the PROFILE OWNER id (whose guestbook is written) is
|
|
* taken from the form, and we resolve a profile username from the form purely
|
|
* to revalidate the right page.
|
|
*/
|
|
export async function postGuestbook(formData: FormData): Promise<void> {
|
|
const session = await auth();
|
|
const userId = Number(session?.user?.id);
|
|
if (!Number.isInteger(userId) || userId <= 0) return;
|
|
|
|
const profileId = Number(formData.get("profileId"));
|
|
if (!Number.isInteger(profileId) || profileId <= 0) return;
|
|
|
|
const message = String(formData.get("message") ?? "").trim().slice(0, MESSAGE_MAX);
|
|
if (!message) return;
|
|
|
|
// Block filtered/AI-flagged content before it touches the DB (fail-open).
|
|
if (!(await isAllowed(message)).ok) return;
|
|
|
|
// Optional: used only to revalidate the correct profile route.
|
|
const username = String(formData.get("username") ?? "").trim();
|
|
|
|
const now = new Date();
|
|
try {
|
|
await prisma.websiteUserGuestbooks.create({
|
|
data: {
|
|
profileId,
|
|
userId,
|
|
message,
|
|
createdAt: now,
|
|
updatedAt: now,
|
|
},
|
|
});
|
|
} catch {
|
|
// DB unavailable — fail soft; nothing to persist.
|
|
return;
|
|
}
|
|
|
|
if (username) revalidatePath(`/u/${username}`);
|
|
}
|