Files
Epicnabbo-Catalogus-Updated…/src/actions/radio-shouts.ts
T
openhands 942bc6fc8d Security hardening, code quality, and ESLint setup
- Remove production DB dump (db_backup_*.sql) and update.log from git tracking
- Add DB backups to .gitignore
- Replace all console.log/console.error with structured logger module
- Translate Dutch error messages to English (link-discord.ts)
- Remove dead code blocks (register-form.tsx false && pattern)
- Add ESLint flat config with TypeScript, React, Next.js, jsx-a11y, and security plugins
- Add Prettier config
- Add eslint-plugin-security for security-aware linting
- Fix all 119+ ESLint warnings across the codebase:
  - Resolve security/detect-object-injection with safe access patterns
  - Resolve security/detect-non-literal-fs-filename with path traversal validation
  - Replace <img> with next/image <Image> component
  - Remove unused variables and imports
  - Replace non-null assertions with proper type guards
  - Replace <a> with <Link> for internal navigation
  - Use next/script Script component for external scripts
- Fix setState-in-useEffect anti-patterns (navbar-color-picker, logo-generator, theme-switcher)
- Add lint and format scripts to package.json

All checks: typecheck ✓, tests 58/58 ✓, lint 0 errors 0 warnings ✓
2026-07-10 22:48:22 +02:00

63 lines
1.6 KiB
TypeScript

"use server";
import { revalidatePath } from "next/cache";
import { z } from "zod";
import { auth } from "@/lib/auth";
import { prisma } from "@/lib/prisma";
import { moderateOrThrow } from "@/lib/services/moderation";
import { clientIp, rateLimit } from "@/lib/rate-limit";
const shoutSchema = z.object({
message: z.string().min(1, "Message is required").max(255),
});
/**
* Post a radio shout.
*
* The AUTHOR (userId) is re-read from the session via auth() and is never
* trusted from the submitted FormData, so a crafted form cannot impersonate
* another account. radio_shouts.user_id is an UNSIGNED BIGINT, so the Int
* session id is widened to BigInt for the insert.
*/
export async function postShout(formData: FormData): Promise<void> {
const session = await auth();
const userId = Number(session?.user?.id);
if (!Number.isInteger(userId) || userId <= 0) return;
await clientIp();
if (!(await rateLimit(`shout:${userId}`, 5, 30_000)).ok) return;
const raw = {
message: String(formData.get("message") ?? "").trim().slice(0, 255),
};
const parsed = shoutSchema.safeParse(raw);
if (!parsed.success) return;
const { message } = parsed.data;
// Moderation check
try {
await moderateOrThrow(message);
} catch {
return;
}
const now = new Date();
try {
await prisma.radioShouts.create({
data: {
userId: BigInt(userId),
message,
createdAt: now,
updatedAt: now,
},
});
} catch {
// DB unavailable — fail soft; nothing to persist.
return;
}
revalidatePath("/radio/shouts");
}