feat: role-based ACL + admin management UI
Backend:
- Add acl.ts with requireAuth/requireRole/requireOwnerOrAdmin helpers
- Gate premium videos from unauthenticated users in videos query/resolver
- Fix updateVideoPlay to verify ownership before updating
- Add admin mutations: adminListUsers, adminUpdateUser, adminDeleteUser
- Add admin mutations: createVideo, updateVideo, deleteVideo, setVideoModels, adminListVideos
- Add admin mutations: createArticle, updateArticle, deleteArticle, adminListArticles
- Add deleteComment mutation (owner or admin only)
- Add AdminUserListType to GraphQL types
- Fix featured filter on articles query
Frontend:
- Install marked for markdown rendering
- Add /admin/* section with sidebar layout and admin-only guard
- Admin users page: paginated table with search, role filter, inline role change, delete
- Admin videos pages: list, create form, edit form with file upload and model assignment
- Admin articles pages: list, create form, edit form with split-pane markdown editor
- Add admin nav link in header (desktop + mobile) for admin users
- Render article content through marked in magazine detail page
- Add all admin GraphQL service functions to services.ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-06 12:31:33 +01:00
|
|
|
<script lang="ts">
|
|
|
|
|
import { goto } from "$app/navigation";
|
|
|
|
|
import { toast } from "svelte-sonner";
|
|
|
|
|
import { updateVideo, setVideoModels, uploadFile } from "$lib/services";
|
|
|
|
|
import { Button } from "$lib/components/ui/button";
|
|
|
|
|
import { Input } from "$lib/components/ui/input";
|
|
|
|
|
import { Label } from "$lib/components/ui/label";
|
|
|
|
|
import { Textarea } from "$lib/components/ui/textarea";
|
|
|
|
|
import { TagsInput } from "$lib/components/ui/tags-input";
|
|
|
|
|
import { FileDropZone, MEGABYTE } from "$lib/components/ui/file-drop-zone";
|
|
|
|
|
import { getAssetUrl } from "$lib/api";
|
|
|
|
|
|
|
|
|
|
const { data } = $props();
|
|
|
|
|
|
|
|
|
|
let title = $state(data.video.title);
|
|
|
|
|
let slug = $state(data.video.slug);
|
|
|
|
|
let description = $state(data.video.description ?? "");
|
|
|
|
|
let tags = $state<string[]>(data.video.tags ?? []);
|
|
|
|
|
let premium = $state(data.video.premium ?? false);
|
|
|
|
|
let featured = $state(data.video.featured ?? false);
|
|
|
|
|
let uploadDate = $state(
|
2026-03-06 12:35:11 +01:00
|
|
|
data.video.upload_date ? new Date(data.video.upload_date).toISOString().slice(0, 16) : "",
|
feat: role-based ACL + admin management UI
Backend:
- Add acl.ts with requireAuth/requireRole/requireOwnerOrAdmin helpers
- Gate premium videos from unauthenticated users in videos query/resolver
- Fix updateVideoPlay to verify ownership before updating
- Add admin mutations: adminListUsers, adminUpdateUser, adminDeleteUser
- Add admin mutations: createVideo, updateVideo, deleteVideo, setVideoModels, adminListVideos
- Add admin mutations: createArticle, updateArticle, deleteArticle, adminListArticles
- Add deleteComment mutation (owner or admin only)
- Add AdminUserListType to GraphQL types
- Fix featured filter on articles query
Frontend:
- Install marked for markdown rendering
- Add /admin/* section with sidebar layout and admin-only guard
- Admin users page: paginated table with search, role filter, inline role change, delete
- Admin videos pages: list, create form, edit form with file upload and model assignment
- Admin articles pages: list, create form, edit form with split-pane markdown editor
- Add admin nav link in header (desktop + mobile) for admin users
- Render article content through marked in magazine detail page
- Add all admin GraphQL service functions to services.ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-06 12:31:33 +01:00
|
|
|
);
|
|
|
|
|
let imageId = $state<string | null>(data.video.image ?? null);
|
|
|
|
|
let movieId = $state<string | null>(data.video.movie ?? null);
|
|
|
|
|
let selectedModelIds = $state<string[]>(
|
|
|
|
|
data.video.models?.map((m: { id: string }) => m.id) ?? [],
|
|
|
|
|
);
|
|
|
|
|
let saving = $state(false);
|
|
|
|
|
|
|
|
|
|
async function handleImageUpload(files: File[]) {
|
|
|
|
|
const file = files[0];
|
|
|
|
|
if (!file) return;
|
|
|
|
|
const fd = new FormData();
|
|
|
|
|
fd.append("file", file);
|
|
|
|
|
try {
|
|
|
|
|
const res = await uploadFile(fd);
|
|
|
|
|
imageId = res.id;
|
|
|
|
|
toast.success("Cover image uploaded");
|
|
|
|
|
} catch {
|
|
|
|
|
toast.error("Image upload failed");
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
async function handleVideoUpload(files: File[]) {
|
|
|
|
|
const file = files[0];
|
|
|
|
|
if (!file) return;
|
|
|
|
|
const fd = new FormData();
|
|
|
|
|
fd.append("file", file);
|
|
|
|
|
try {
|
|
|
|
|
const res = await uploadFile(fd);
|
|
|
|
|
movieId = res.id;
|
|
|
|
|
toast.success("Video uploaded");
|
|
|
|
|
} catch {
|
|
|
|
|
toast.error("Video upload failed");
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
function toggleModel(id: string) {
|
|
|
|
|
selectedModelIds = selectedModelIds.includes(id)
|
|
|
|
|
? selectedModelIds.filter((m) => m !== id)
|
|
|
|
|
: [...selectedModelIds, id];
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
async function handleSubmit() {
|
|
|
|
|
saving = true;
|
|
|
|
|
try {
|
|
|
|
|
await updateVideo({
|
|
|
|
|
id: data.video.id,
|
|
|
|
|
title,
|
|
|
|
|
slug,
|
|
|
|
|
description: description || undefined,
|
|
|
|
|
imageId: imageId || undefined,
|
|
|
|
|
movieId: movieId || undefined,
|
|
|
|
|
tags,
|
|
|
|
|
premium,
|
|
|
|
|
featured,
|
|
|
|
|
uploadDate: uploadDate || undefined,
|
|
|
|
|
});
|
|
|
|
|
await setVideoModels(data.video.id, selectedModelIds);
|
|
|
|
|
toast.success("Video updated");
|
|
|
|
|
goto("/admin/videos");
|
|
|
|
|
} catch (e: any) {
|
|
|
|
|
toast.error(e?.message ?? "Failed to update video");
|
|
|
|
|
} finally {
|
|
|
|
|
saving = false;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
</script>
|
|
|
|
|
|
|
|
|
|
<div class="p-6 max-w-2xl">
|
|
|
|
|
<div class="flex items-center gap-4 mb-6">
|
|
|
|
|
<Button variant="ghost" href="/admin/videos" size="sm">
|
|
|
|
|
<span class="icon-[ri--arrow-left-line] h-4 w-4 mr-1"></span>Back
|
|
|
|
|
</Button>
|
|
|
|
|
<h1 class="text-2xl font-bold">Edit video</h1>
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-5">
|
|
|
|
|
<div class="grid grid-cols-2 gap-4">
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label for="title">Title *</Label>
|
|
|
|
|
<Input id="title" bind:value={title} placeholder="Video title" />
|
|
|
|
|
</div>
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label for="slug">Slug *</Label>
|
|
|
|
|
<Input id="slug" bind:value={slug} placeholder="video-slug" />
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label for="description">Description</Label>
|
|
|
|
|
<Textarea id="description" bind:value={description} rows={3} />
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label>Cover image</Label>
|
|
|
|
|
{#if imageId}
|
2026-03-06 12:35:11 +01:00
|
|
|
<img
|
|
|
|
|
src={getAssetUrl(imageId, "thumbnail")}
|
|
|
|
|
alt=""
|
|
|
|
|
class="h-24 rounded object-cover mb-2"
|
|
|
|
|
/>
|
feat: role-based ACL + admin management UI
Backend:
- Add acl.ts with requireAuth/requireRole/requireOwnerOrAdmin helpers
- Gate premium videos from unauthenticated users in videos query/resolver
- Fix updateVideoPlay to verify ownership before updating
- Add admin mutations: adminListUsers, adminUpdateUser, adminDeleteUser
- Add admin mutations: createVideo, updateVideo, deleteVideo, setVideoModels, adminListVideos
- Add admin mutations: createArticle, updateArticle, deleteArticle, adminListArticles
- Add deleteComment mutation (owner or admin only)
- Add AdminUserListType to GraphQL types
- Fix featured filter on articles query
Frontend:
- Install marked for markdown rendering
- Add /admin/* section with sidebar layout and admin-only guard
- Admin users page: paginated table with search, role filter, inline role change, delete
- Admin videos pages: list, create form, edit form with file upload and model assignment
- Admin articles pages: list, create form, edit form with split-pane markdown editor
- Add admin nav link in header (desktop + mobile) for admin users
- Render article content through marked in magazine detail page
- Add all admin GraphQL service functions to services.ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-06 12:31:33 +01:00
|
|
|
{/if}
|
2026-03-06 12:35:11 +01:00
|
|
|
<FileDropZone accept="image/*" maxFileSize={10 * MEGABYTE} onUpload={handleImageUpload} />
|
feat: role-based ACL + admin management UI
Backend:
- Add acl.ts with requireAuth/requireRole/requireOwnerOrAdmin helpers
- Gate premium videos from unauthenticated users in videos query/resolver
- Fix updateVideoPlay to verify ownership before updating
- Add admin mutations: adminListUsers, adminUpdateUser, adminDeleteUser
- Add admin mutations: createVideo, updateVideo, deleteVideo, setVideoModels, adminListVideos
- Add admin mutations: createArticle, updateArticle, deleteArticle, adminListArticles
- Add deleteComment mutation (owner or admin only)
- Add AdminUserListType to GraphQL types
- Fix featured filter on articles query
Frontend:
- Install marked for markdown rendering
- Add /admin/* section with sidebar layout and admin-only guard
- Admin users page: paginated table with search, role filter, inline role change, delete
- Admin videos pages: list, create form, edit form with file upload and model assignment
- Admin articles pages: list, create form, edit form with split-pane markdown editor
- Add admin nav link in header (desktop + mobile) for admin users
- Render article content through marked in magazine detail page
- Add all admin GraphQL service functions to services.ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-06 12:31:33 +01:00
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label>Video file</Label>
|
|
|
|
|
{#if movieId}
|
|
|
|
|
<p class="text-xs text-muted-foreground mb-1">Current file: {movieId}</p>
|
|
|
|
|
{/if}
|
2026-03-06 12:35:11 +01:00
|
|
|
<FileDropZone accept="video/*" maxFileSize={2000 * MEGABYTE} onUpload={handleVideoUpload} />
|
feat: role-based ACL + admin management UI
Backend:
- Add acl.ts with requireAuth/requireRole/requireOwnerOrAdmin helpers
- Gate premium videos from unauthenticated users in videos query/resolver
- Fix updateVideoPlay to verify ownership before updating
- Add admin mutations: adminListUsers, adminUpdateUser, adminDeleteUser
- Add admin mutations: createVideo, updateVideo, deleteVideo, setVideoModels, adminListVideos
- Add admin mutations: createArticle, updateArticle, deleteArticle, adminListArticles
- Add deleteComment mutation (owner or admin only)
- Add AdminUserListType to GraphQL types
- Fix featured filter on articles query
Frontend:
- Install marked for markdown rendering
- Add /admin/* section with sidebar layout and admin-only guard
- Admin users page: paginated table with search, role filter, inline role change, delete
- Admin videos pages: list, create form, edit form with file upload and model assignment
- Admin articles pages: list, create form, edit form with split-pane markdown editor
- Add admin nav link in header (desktop + mobile) for admin users
- Render article content through marked in magazine detail page
- Add all admin GraphQL service functions to services.ts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-06 12:31:33 +01:00
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label>Tags</Label>
|
|
|
|
|
<TagsInput bind:value={tags} />
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="space-y-1.5">
|
|
|
|
|
<Label for="uploadDate">Publish date</Label>
|
|
|
|
|
<Input id="uploadDate" type="datetime-local" bind:value={uploadDate} />
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
<div class="flex gap-6">
|
|
|
|
|
<label class="flex items-center gap-2 cursor-pointer">
|
|
|
|
|
<input type="checkbox" bind:checked={premium} class="rounded" />
|
|
|
|
|
<span class="text-sm">Premium</span>
|
|
|
|
|
</label>
|
|
|
|
|
<label class="flex items-center gap-2 cursor-pointer">
|
|
|
|
|
<input type="checkbox" bind:checked={featured} class="rounded" />
|
|
|
|
|
<span class="text-sm">Featured</span>
|
|
|
|
|
</label>
|
|
|
|
|
</div>
|
|
|
|
|
|
|
|
|
|
{#if data.models.length > 0}
|
|
|
|
|
<div class="space-y-2">
|
|
|
|
|
<Label>Models</Label>
|
|
|
|
|
<div class="flex flex-wrap gap-2">
|
|
|
|
|
{#each data.models as model (model.id)}
|
|
|
|
|
<button
|
|
|
|
|
type="button"
|
|
|
|
|
class={`px-3 py-1.5 rounded-full text-sm border transition-colors ${
|
|
|
|
|
selectedModelIds.includes(model.id)
|
|
|
|
|
? "border-primary bg-primary/10 text-primary"
|
|
|
|
|
: "border-border/40 text-muted-foreground hover:border-primary/40"
|
|
|
|
|
}`}
|
|
|
|
|
onclick={() => toggleModel(model.id)}
|
|
|
|
|
>
|
|
|
|
|
{model.artist_name || model.id}
|
|
|
|
|
</button>
|
|
|
|
|
{/each}
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
{/if}
|
|
|
|
|
|
|
|
|
|
<div class="flex gap-3 pt-2">
|
|
|
|
|
<Button onclick={handleSubmit} disabled={saving}>
|
|
|
|
|
{saving ? "Saving…" : "Save changes"}
|
|
|
|
|
</Button>
|
|
|
|
|
<Button variant="outline" href="/admin/videos">Cancel</Button>
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|
|
|
|
|
</div>
|