feat: two-way sync between support tickets and Gitea issues (v0.63.0)
Outbound (already existed one-way: ticket create -> Gitea issue) now also mirrors status changes: closing/reopening a ticket in the admin UI closes/reopens the linked Gitea issue, and replies posted from Epicure (by the ticket owner or an admin) post as a comment on the issue. Captures and stores the Gitea issue number at creation time to address these follow-up calls without re-parsing the issue URL. Inbound: new webhook receiver at /api/webhooks/gitea, verified via HMAC-SHA256 signature (X-Gitea-Signature) with a configurable GITEA_WEBHOOK_SECRET site setting, deduped by delivery id the same way the existing Stripe receiver dedupes events. Handles "issues" (closed/reopened -> ticket status) and "issue_comment" (created -> appends to the ticket's comment thread), skipping comments Epicura already posted itself (matched by Gitea comment id) to avoid loops. New support_ticket_comments table backs a lightweight conversation thread on both the user-facing support page and the admin support manager, each comment tagged by author (user/admin/gitea). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -25,6 +25,7 @@ const ALLOWED_KEYS: SiteSettingKey[] = [
|
||||
"GITEA_URL",
|
||||
"GITEA_TOKEN",
|
||||
"GITEA_REPO",
|
||||
"GITEA_WEBHOOK_SECRET",
|
||||
];
|
||||
|
||||
export async function PUT(req: NextRequest) {
|
||||
|
||||
@@ -0,0 +1,60 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import crypto from "node:crypto";
|
||||
import { z } from "zod";
|
||||
import { db, supportTickets, supportTicketComments, eq, asc } from "@epicure/db";
|
||||
import { requireAdmin } from "@/lib/api-auth";
|
||||
import { postGiteaComment } from "@/lib/gitea";
|
||||
|
||||
const CreateCommentBody = z.object({
|
||||
body: z.string().trim().min(1).max(3000),
|
||||
});
|
||||
|
||||
export async function GET(_req: NextRequest, { params }: { params: Promise<{ id: string }> }) {
|
||||
const { response } = await requireAdmin();
|
||||
if (response) return response;
|
||||
|
||||
const { id } = await params;
|
||||
const comments = await db.query.supportTicketComments.findMany({
|
||||
where: eq(supportTicketComments.ticketId, id),
|
||||
orderBy: asc(supportTicketComments.createdAt),
|
||||
});
|
||||
|
||||
return NextResponse.json(comments);
|
||||
}
|
||||
|
||||
export async function POST(req: NextRequest, { params }: { params: Promise<{ id: string }> }) {
|
||||
const { session, response } = await requireAdmin();
|
||||
if (response) return response;
|
||||
|
||||
const { id } = await params;
|
||||
const ticket = await db.query.supportTickets.findFirst({ where: eq(supportTickets.id, id) });
|
||||
if (!ticket) return NextResponse.json({ error: "Not found" }, { status: 404 });
|
||||
|
||||
const parsed = CreateCommentBody.safeParse(await req.json());
|
||||
if (!parsed.success) {
|
||||
return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 });
|
||||
}
|
||||
|
||||
let giteaCommentId: number | null = null;
|
||||
if (ticket.giteaIssueNumber) {
|
||||
const { id: commentId } = await postGiteaComment(ticket.giteaIssueNumber, parsed.data.body);
|
||||
giteaCommentId = commentId;
|
||||
}
|
||||
|
||||
const commentId = crypto.randomUUID();
|
||||
const now = new Date();
|
||||
await db.insert(supportTicketComments).values({
|
||||
id: commentId,
|
||||
ticketId: id,
|
||||
authorType: "admin",
|
||||
authorId: session!.user.id,
|
||||
body: parsed.data.body,
|
||||
giteaCommentId,
|
||||
createdAt: now,
|
||||
});
|
||||
|
||||
return NextResponse.json(
|
||||
{ id: commentId, ticketId: id, authorType: "admin", authorId: session!.user.id, body: parsed.data.body, createdAt: now.toISOString() },
|
||||
{ status: 201 }
|
||||
);
|
||||
}
|
||||
@@ -2,7 +2,7 @@ import { NextRequest, NextResponse } from "next/server";
|
||||
import { z } from "zod";
|
||||
import { db, supportTickets, supportTicketAttachments, eq } from "@epicure/db";
|
||||
import { requireAdmin } from "@/lib/api-auth";
|
||||
import { createGiteaIssue, buildGiteaIssueBody } from "@/lib/gitea";
|
||||
import { createGiteaIssue, buildGiteaIssueBody, setGiteaIssueState } from "@/lib/gitea";
|
||||
|
||||
const UpdateTicketBody = z.object({
|
||||
status: z.enum(["open", "triaged", "closed"]).optional(),
|
||||
@@ -27,6 +27,11 @@ export async function PATCH(req: NextRequest, { params }: { params: Promise<{ id
|
||||
|
||||
if (parsed.data.status) {
|
||||
updates.status = parsed.data.status;
|
||||
// Mirror the status change onto the linked Gitea issue — best-effort,
|
||||
// never blocks the ticket update on Gitea being reachable.
|
||||
if (ticket.giteaIssueNumber && parsed.data.status !== ticket.status) {
|
||||
void setGiteaIssueState(ticket.giteaIssueNumber, parsed.data.status === "closed" ? "closed" : "open");
|
||||
}
|
||||
}
|
||||
|
||||
if (parsed.data.retryGitea) {
|
||||
@@ -35,12 +40,13 @@ export async function PATCH(req: NextRequest, { params }: { params: Promise<{ id
|
||||
.from(supportTicketAttachments)
|
||||
.where(eq(supportTicketAttachments.ticketId, id));
|
||||
|
||||
const { url, error } = await createGiteaIssue({
|
||||
const { url, number, error } = await createGiteaIssue({
|
||||
type: ticket.type,
|
||||
title: ticket.title,
|
||||
body: buildGiteaIssueBody({ description: ticket.description, userId: ticket.userId, attachments }),
|
||||
});
|
||||
updates.giteaIssueUrl = url;
|
||||
updates.giteaIssueNumber = number;
|
||||
updates.giteaError = error;
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import crypto from "node:crypto";
|
||||
import { z } from "zod";
|
||||
import { db, supportTickets, supportTicketComments, eq, asc } from "@epicure/db";
|
||||
import { requireSession } from "@/lib/api-auth";
|
||||
import { postGiteaComment } from "@/lib/gitea";
|
||||
|
||||
const CreateCommentBody = z.object({
|
||||
body: z.string().trim().min(1).max(3000),
|
||||
});
|
||||
|
||||
export async function GET(_req: NextRequest, { params }: { params: Promise<{ id: string }> }) {
|
||||
const { session, response } = await requireSession();
|
||||
if (response) return response;
|
||||
|
||||
const { id } = await params;
|
||||
const ticket = await db.query.supportTickets.findFirst({ where: eq(supportTickets.id, id) });
|
||||
if (!ticket || ticket.userId !== session!.user.id) {
|
||||
return NextResponse.json({ error: "Not found" }, { status: 404 });
|
||||
}
|
||||
|
||||
const comments = await db.query.supportTicketComments.findMany({
|
||||
where: eq(supportTicketComments.ticketId, id),
|
||||
orderBy: asc(supportTicketComments.createdAt),
|
||||
});
|
||||
|
||||
return NextResponse.json(comments);
|
||||
}
|
||||
|
||||
export async function POST(req: NextRequest, { params }: { params: Promise<{ id: string }> }) {
|
||||
const { session, response } = await requireSession();
|
||||
if (response) return response;
|
||||
|
||||
const { id } = await params;
|
||||
const ticket = await db.query.supportTickets.findFirst({ where: eq(supportTickets.id, id) });
|
||||
if (!ticket || ticket.userId !== session!.user.id) {
|
||||
return NextResponse.json({ error: "Not found" }, { status: 404 });
|
||||
}
|
||||
|
||||
const parsed = CreateCommentBody.safeParse(await req.json());
|
||||
if (!parsed.success) {
|
||||
return NextResponse.json({ error: "Validation error", issues: parsed.error.issues }, { status: 400 });
|
||||
}
|
||||
|
||||
let giteaCommentId: number | null = null;
|
||||
if (ticket.giteaIssueNumber) {
|
||||
const { id: commentId } = await postGiteaComment(ticket.giteaIssueNumber, parsed.data.body);
|
||||
giteaCommentId = commentId;
|
||||
}
|
||||
|
||||
const commentId = crypto.randomUUID();
|
||||
const now = new Date();
|
||||
await db.insert(supportTicketComments).values({
|
||||
id: commentId,
|
||||
ticketId: id,
|
||||
authorType: "user",
|
||||
authorId: session!.user.id,
|
||||
body: parsed.data.body,
|
||||
giteaCommentId,
|
||||
createdAt: now,
|
||||
});
|
||||
|
||||
return NextResponse.json(
|
||||
{ id: commentId, ticketId: id, authorType: "user", authorId: session!.user.id, body: parsed.data.body, createdAt: now.toISOString() },
|
||||
{ status: 201 }
|
||||
);
|
||||
}
|
||||
@@ -66,7 +66,7 @@ export async function POST(req: NextRequest) {
|
||||
const id = crypto.randomUUID();
|
||||
const now = new Date();
|
||||
|
||||
const { url: giteaIssueUrl, error: giteaError } = await createGiteaIssue({
|
||||
const { url: giteaIssueUrl, number: giteaIssueNumber, error: giteaError } = await createGiteaIssue({
|
||||
type,
|
||||
title,
|
||||
body: buildGiteaIssueBody({ description, userId: session!.user.id, attachments }),
|
||||
@@ -80,6 +80,7 @@ export async function POST(req: NextRequest) {
|
||||
description,
|
||||
status: "open",
|
||||
giteaIssueUrl,
|
||||
giteaIssueNumber,
|
||||
giteaError,
|
||||
createdAt: now,
|
||||
updatedAt: now,
|
||||
|
||||
@@ -0,0 +1,86 @@
|
||||
import { NextRequest, NextResponse } from "next/server";
|
||||
import crypto from "node:crypto";
|
||||
import { db, supportTickets, supportTicketComments, processedGiteaEvents, eq } from "@epicure/db";
|
||||
import { getSiteSetting } from "@/lib/site-settings";
|
||||
import { verifyGiteaSignature } from "@/lib/gitea";
|
||||
|
||||
type GiteaIssuePayload = {
|
||||
action?: string;
|
||||
number?: number;
|
||||
issue?: { number?: number };
|
||||
comment?: { id?: number; body?: string };
|
||||
};
|
||||
|
||||
export async function POST(req: NextRequest) {
|
||||
const secret = await getSiteSetting("GITEA_WEBHOOK_SECRET");
|
||||
if (!secret) {
|
||||
return NextResponse.json({ error: "Gitea webhook not configured" }, { status: 400 });
|
||||
}
|
||||
|
||||
const rawBody = await req.text();
|
||||
const signature = req.headers.get("x-gitea-signature");
|
||||
if (!signature || !verifyGiteaSignature(rawBody, signature, secret)) {
|
||||
return NextResponse.json({ error: "Invalid signature" }, { status: 401 });
|
||||
}
|
||||
|
||||
// Gitea includes a per-delivery id that stays stable across redeliveries
|
||||
// of the same event, same dedupe pattern as the Stripe receiver.
|
||||
const deliveryId = req.headers.get("x-gitea-delivery");
|
||||
if (deliveryId) {
|
||||
const [inserted] = await db
|
||||
.insert(processedGiteaEvents)
|
||||
.values({ id: deliveryId })
|
||||
.onConflictDoNothing()
|
||||
.returning({ id: processedGiteaEvents.id });
|
||||
if (!inserted) {
|
||||
return NextResponse.json({ received: true, duplicate: true });
|
||||
}
|
||||
}
|
||||
|
||||
const eventType = req.headers.get("x-gitea-event");
|
||||
let payload: GiteaIssuePayload;
|
||||
try {
|
||||
payload = JSON.parse(rawBody) as GiteaIssuePayload;
|
||||
} catch {
|
||||
return NextResponse.json({ error: "Invalid JSON" }, { status: 400 });
|
||||
}
|
||||
|
||||
const issueNumber = payload.issue?.number ?? payload.number;
|
||||
if (!issueNumber) {
|
||||
return NextResponse.json({ received: true });
|
||||
}
|
||||
|
||||
const ticket = await db.query.supportTickets.findFirst({ where: eq(supportTickets.giteaIssueNumber, issueNumber) });
|
||||
if (!ticket) {
|
||||
return NextResponse.json({ received: true });
|
||||
}
|
||||
|
||||
if (eventType === "issues") {
|
||||
if (payload.action === "closed" && ticket.status !== "closed") {
|
||||
await db.update(supportTickets).set({ status: "closed", updatedAt: new Date() }).where(eq(supportTickets.id, ticket.id));
|
||||
} else if (payload.action === "reopened" && ticket.status === "closed") {
|
||||
await db.update(supportTickets).set({ status: "open", updatedAt: new Date() }).where(eq(supportTickets.id, ticket.id));
|
||||
}
|
||||
} else if (eventType === "issue_comment" && payload.action === "created" && payload.comment?.body) {
|
||||
const giteaCommentId = payload.comment.id ?? null;
|
||||
// A comment Epicure just posted via the API already has a row here
|
||||
// (inserted synchronously when it was sent) — skip it so the webhook
|
||||
// delivery for our own comment doesn't create a duplicate.
|
||||
const existing = giteaCommentId
|
||||
? await db.query.supportTicketComments.findFirst({ where: eq(supportTicketComments.giteaCommentId, giteaCommentId) })
|
||||
: null;
|
||||
if (!existing) {
|
||||
await db.insert(supportTicketComments).values({
|
||||
id: crypto.randomUUID(),
|
||||
ticketId: ticket.id,
|
||||
authorType: "gitea",
|
||||
authorId: null,
|
||||
body: payload.comment.body,
|
||||
giteaCommentId,
|
||||
createdAt: new Date(),
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
return NextResponse.json({ received: true });
|
||||
}
|
||||
Reference in New Issue
Block a user