This commit is contained in:
2026-09-20 21:43:02 +02:00
parent 5601c282b7
commit 4e857fd5ef
26 changed files with 3567 additions and 142 deletions
+41 -2
View File
@@ -1165,7 +1165,7 @@ export default (router, tpl) => {
WITH ghost_users AS (
SELECT
NULL::int as id, i.username as login, i.username as "user", 'Legacy Account' as email,
to_timestamp(MIN(i.stamp)) as created_at, false as banned, false as is_moderator, false as admin, true as activated,
to_timestamp(MIN(i.stamp)) as created_at, false as banned, false as is_moderator, false as admin, ARRAY[]::text[] as groups, true as activated,
NULL::text as avatar_file, NULL::varchar as display_name, 0 as force_comment_display_mode, 0 as comment_display_mode, 'Legacy' as reg_method
FROM items i
WHERE i.username IS NOT NULL AND i.username != ''
@@ -1240,7 +1240,7 @@ export default (router, tpl) => {
users = await db`
WITH filtered_users AS (
SELECT
u.id, u.login, u.user, u.email, u.created_at, u.banned, u.is_moderator, u.admin, u.activated,
u.id, u.login, u.user, u.email, u.created_at, u.banned, u.is_moderator, u.admin, u.groups, u.activated,
uo.avatar_file, uo.display_name, uo.force_comment_display_mode, uo.comment_display_mode,
(SELECT token FROM invite_tokens WHERE used_by = u.id ORDER BY created_at DESC LIMIT 1) as reg_method
FROM "user" u
@@ -1446,6 +1446,45 @@ export default (router, tpl) => {
}
});
router.post(/^\/api\/v2\/admin\/users\/set-groups\/?$/, lib.auth, async (req, res) => {
try {
const { user_id, groups } = req.post;
if (!user_id) throw new Error('Missing user_id');
const target = await db`SELECT id, login FROM "user" WHERE id = ${+user_id} LIMIT 1`;
if (!target.length) throw new Error('User not found.');
let groupsArr = [];
if (Array.isArray(groups)) {
groupsArr = groups.map(s => String(s).trim().toLowerCase()).filter(Boolean);
} else if (typeof groups === 'string') {
groupsArr = groups.split(',').map(s => s.trim().toLowerCase()).filter(Boolean);
}
await db`
UPDATE "user"
SET groups = ${groupsArr}
WHERE id = ${+user_id}
`;
// Invalidate target user's session cache and session table so new groups load immediately
await db`DELETE FROM user_sessions WHERE user_id = ${+user_id}`;
await audit.log(req.session.id, 'admin_set_groups', 'user', +user_id, {
target_login: target[0].login,
groups: groupsArr
});
return res.writeHead(200, { 'Content-Type': 'application/json' }).end(JSON.stringify({
success: true,
groups: groupsArr,
msg: `Groups for "${target[0].login}" updated to: ${groupsArr.join(', ') || 'none'}`
}));
} catch (err) {
console.error('[ADMIN] Set groups failed:', err);
return res.writeHead(200, { 'Content-Type': 'application/json' }).end(JSON.stringify({ success: false, msg: err.message }));
}
});
router.post(/^\/api\/v2\/admin\/users\/lock-layout\/?$/, lib.auth, async (req, res) => {
try {