mirror of
https://github.com/mudabbir-ahmad/peworkshop.git
synced 2026-10-07 19:50:20 +00:00
fixed some CSS styling errors with the team member list page and also added the admin dashboard to allow them to start a hunt with either a stop watch style hunt or a predetermined hunt duration. also fixed some css styling issues I ran into due to using some template code to make the dev process quicker
This commit is contained in:
1 parent
673ea41a4c
commit
c05c8829dd
11 files changed
+691
-185
No files matched your search
@@ -0,0 +1,109 @@
|
||||
import { query, queryOne, run } from "@/lib/db";
|
||||
import { cookies } from "next/headers";
|
||||
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
|
||||
|
||||
export const dynamic = "force-dynamic"; // Disable caching
|
||||
|
||||
// GET endpoint to get current timer status
|
||||
export async function GET(request) {
|
||||
try {
|
||||
// Verify the user is authenticated
|
||||
const cookieStore = cookies();
|
||||
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return Response.json({ error: "Invalid session" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Get the current hunt timer status
|
||||
const timerStatus = await queryOne(
|
||||
"SELECT active, start_time, end_time FROM hunt_timer ORDER BY id DESC LIMIT 1"
|
||||
);
|
||||
|
||||
if (!timerStatus) {
|
||||
return Response.json({
|
||||
active: false,
|
||||
startTime: null,
|
||||
endTime: null,
|
||||
});
|
||||
}
|
||||
|
||||
return Response.json({
|
||||
active: !!timerStatus.active,
|
||||
startTime: timerStatus.start_time,
|
||||
endTime: timerStatus.end_time,
|
||||
});
|
||||
} catch (error) {
|
||||
console.error("Error getting timer status:", error);
|
||||
return Response.json(
|
||||
{ error: "Failed to get timer status" },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// POST endpoint to start/stop timer
|
||||
export async function POST(request) {
|
||||
try {
|
||||
// Verify the user is authenticated and is an admin
|
||||
const cookieStore = cookies();
|
||||
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData || userData.role !== "admin") {
|
||||
return Response.json(
|
||||
{ error: "Unauthorized: Admin access required" },
|
||||
{ status: 403 }
|
||||
);
|
||||
}
|
||||
|
||||
const body = await request.json();
|
||||
const { action, endTime } = body;
|
||||
|
||||
if (action === "start") {
|
||||
// Get current time in ISO format
|
||||
const startTime = new Date().toISOString();
|
||||
|
||||
// Insert new timer record
|
||||
await run(
|
||||
"INSERT INTO hunt_timer (active, start_time, end_time) VALUES (?, ?, ?)",
|
||||
[1, startTime, endTime || null]
|
||||
);
|
||||
|
||||
return Response.json({
|
||||
success: true,
|
||||
message: "Timer started successfully",
|
||||
startTime,
|
||||
endTime: endTime || null,
|
||||
});
|
||||
} else if (action === "stop") {
|
||||
// Update the most recent timer to inactive
|
||||
await run(
|
||||
"UPDATE hunt_timer SET active = 0, end_time = ? WHERE id = (SELECT id FROM hunt_timer ORDER BY id DESC LIMIT 1)",
|
||||
[new Date().toISOString()]
|
||||
);
|
||||
|
||||
return Response.json({
|
||||
success: true,
|
||||
message: "Timer stopped successfully",
|
||||
});
|
||||
} else {
|
||||
return Response.json(
|
||||
{ error: "Invalid action. Use 'start' or 'stop'." },
|
||||
{ status: 400 }
|
||||
);
|
||||
}
|
||||
} catch (error) {
|
||||
console.error("Error managing timer:", error);
|
||||
return Response.json({ error: "Failed to manage timer" }, { status: 500 });
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,76 @@
|
||||
import { query, queryOne, run } from "@/lib/db";
|
||||
import { cookies } from "next/headers";
|
||||
import { verifyToken } from "@/app/api/auth/[...nextauth]/route";
|
||||
|
||||
export const dynamic = "force-dynamic"; // Disable caching
|
||||
|
||||
// GET to list admin users
|
||||
export async function GET(request) {
|
||||
try {
|
||||
// Verify the user is authenticated
|
||||
const cookieStore = cookies();
|
||||
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return Response.json({ error: "Invalid session" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Get all admin users
|
||||
const adminUsers = await query(
|
||||
"SELECT id, username, email FROM users WHERE is_admin = 1"
|
||||
);
|
||||
|
||||
return Response.json({ users: adminUsers });
|
||||
} catch (error) {
|
||||
console.error("Error fetching admin users:", error);
|
||||
return Response.json(
|
||||
{ error: "Failed to fetch admin users" },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// DELETE to remove admin privileges from a user
|
||||
export async function DELETE(request) {
|
||||
try {
|
||||
// Verify the user is authenticated
|
||||
const cookieStore = cookies();
|
||||
const sessionToken = cookieStore.get("next-auth.session-token")?.value;
|
||||
|
||||
if (!sessionToken) {
|
||||
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
||||
}
|
||||
|
||||
const userData = verifyToken(sessionToken);
|
||||
if (!userData) {
|
||||
return Response.json({ error: "Invalid session" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Get the user ID from the URL or request body
|
||||
const { searchParams } = new URL(request.url);
|
||||
const userId = searchParams.get("userId");
|
||||
|
||||
if (!userId) {
|
||||
return Response.json({ error: "User ID is required" }, { status: 400 });
|
||||
}
|
||||
|
||||
// Remove admin privileges by setting is_admin to 0
|
||||
await run("UPDATE users SET is_admin = 0 WHERE id = ?", [userId]);
|
||||
|
||||
return Response.json({
|
||||
success: true,
|
||||
message: "Admin privileges removed successfully",
|
||||
});
|
||||
} catch (error) {
|
||||
console.error("Error removing admin privileges:", error);
|
||||
return Response.json(
|
||||
{ error: "Failed to remove admin privileges" },
|
||||
{ status: 500 }
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user