bvcx
This commit is contained in:
@@ -1165,7 +1165,7 @@ export default (router, tpl) => {
|
||||
WITH ghost_users AS (
|
||||
SELECT
|
||||
NULL::int as id, i.username as login, i.username as "user", 'Legacy Account' as email,
|
||||
to_timestamp(MIN(i.stamp)) as created_at, false as banned, false as is_moderator, false as admin, true as activated,
|
||||
to_timestamp(MIN(i.stamp)) as created_at, false as banned, false as is_moderator, false as admin, ARRAY[]::text[] as groups, true as activated,
|
||||
NULL::text as avatar_file, NULL::varchar as display_name, 0 as force_comment_display_mode, 0 as comment_display_mode, 'Legacy' as reg_method
|
||||
FROM items i
|
||||
WHERE i.username IS NOT NULL AND i.username != ''
|
||||
@@ -1240,7 +1240,7 @@ export default (router, tpl) => {
|
||||
users = await db`
|
||||
WITH filtered_users AS (
|
||||
SELECT
|
||||
u.id, u.login, u.user, u.email, u.created_at, u.banned, u.is_moderator, u.admin, u.activated,
|
||||
u.id, u.login, u.user, u.email, u.created_at, u.banned, u.is_moderator, u.admin, u.groups, u.activated,
|
||||
uo.avatar_file, uo.display_name, uo.force_comment_display_mode, uo.comment_display_mode,
|
||||
(SELECT token FROM invite_tokens WHERE used_by = u.id ORDER BY created_at DESC LIMIT 1) as reg_method
|
||||
FROM "user" u
|
||||
@@ -1446,6 +1446,45 @@ export default (router, tpl) => {
|
||||
}
|
||||
});
|
||||
|
||||
router.post(/^\/api\/v2\/admin\/users\/set-groups\/?$/, lib.auth, async (req, res) => {
|
||||
try {
|
||||
const { user_id, groups } = req.post;
|
||||
if (!user_id) throw new Error('Missing user_id');
|
||||
const target = await db`SELECT id, login FROM "user" WHERE id = ${+user_id} LIMIT 1`;
|
||||
if (!target.length) throw new Error('User not found.');
|
||||
|
||||
let groupsArr = [];
|
||||
if (Array.isArray(groups)) {
|
||||
groupsArr = groups.map(s => String(s).trim().toLowerCase()).filter(Boolean);
|
||||
} else if (typeof groups === 'string') {
|
||||
groupsArr = groups.split(',').map(s => s.trim().toLowerCase()).filter(Boolean);
|
||||
}
|
||||
|
||||
await db`
|
||||
UPDATE "user"
|
||||
SET groups = ${groupsArr}
|
||||
WHERE id = ${+user_id}
|
||||
`;
|
||||
|
||||
// Invalidate target user's session cache and session table so new groups load immediately
|
||||
await db`DELETE FROM user_sessions WHERE user_id = ${+user_id}`;
|
||||
|
||||
await audit.log(req.session.id, 'admin_set_groups', 'user', +user_id, {
|
||||
target_login: target[0].login,
|
||||
groups: groupsArr
|
||||
});
|
||||
|
||||
return res.writeHead(200, { 'Content-Type': 'application/json' }).end(JSON.stringify({
|
||||
success: true,
|
||||
groups: groupsArr,
|
||||
msg: `Groups for "${target[0].login}" updated to: ${groupsArr.join(', ') || 'none'}`
|
||||
}));
|
||||
} catch (err) {
|
||||
console.error('[ADMIN] Set groups failed:', err);
|
||||
return res.writeHead(200, { 'Content-Type': 'application/json' }).end(JSON.stringify({ success: false, msg: err.message }));
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
router.post(/^\/api\/v2\/admin\/users\/lock-layout\/?$/, lib.auth, async (req, res) => {
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user