362f65656b
Full audit (bugs/UI-UX/backend/feature-gap) turned up a money-leak AI quota bypass, webhook SSRF, and a long tail of missing pagination/auth/a11y work. Fixes land together since HANDOFF.md tracked them as one backlog. - AI routes charge tier quota before generating; nutrition POST is author-only - Webhook dispatch re-validates URL per delivery (SSRF/DNS-rebinding), treats redirects as failures; recipe.published now actually dispatches - New indexes/unique constraints on recipes, meal-planning, comments FK cascade - Recipe PUT/restore snapshot only inside the transaction, after validation - Recipe DELETE cleans up S3 objects (recipe + review photos) - Optimistic UI (favorite/star/follow/shopping-list) rolls back on failure - Upload presign enforces file size cap + per-tier storage quota - Route-level loading/error/not-found states across (app), admin, and root - middleware.ts guards (app)/admin; requireAdmin checks DB role, not cached session; rate limiting applied to both session and API-key branches, bucketed per key; Stripe webhook dedupes by event id - Pagination added to recipes, feed, profile, comments, pantry, admin tables - Nav shows real avatar + profile link + dark-mode toggle; destructive actions standardized on AlertDialog - Unsaved-changes guard + real ingredient/step validation on recipe form; canonical /recipes/[id] used in-app; next/image migration; aria-labels and alt text across icon buttons, avatars, recipe photos - packages/api-types removed (zero callers, too drifted to safely rewire); openapi.ts and ai-keys error shape drift fixed; BYOK decrypt failures now surface instead of silently falling back to the platform key Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
168 lines
6.3 KiB
TypeScript
168 lines
6.3 KiB
TypeScript
"use client";
|
|
|
|
import Link from "next/link";
|
|
import { usePathname, useRouter } from "next/navigation";
|
|
import { useTheme } from "next-themes";
|
|
import { BookOpen, Calendar, Package, ChefHat, User, Rss, FolderOpen, ShoppingCart, Shield, Search, Compass, Menu, Sun, Moon } from "lucide-react";
|
|
import { cn } from "@/lib/utils";
|
|
import { Button, buttonVariants } from "@/components/ui/button";
|
|
import {
|
|
DropdownMenu,
|
|
DropdownMenuContent,
|
|
DropdownMenuItem,
|
|
DropdownMenuSeparator,
|
|
DropdownMenuTrigger,
|
|
} from "@/components/ui/dropdown-menu";
|
|
import {
|
|
Sheet,
|
|
SheetClose,
|
|
SheetContent,
|
|
SheetHeader,
|
|
SheetTitle,
|
|
SheetTrigger,
|
|
} from "@/components/ui/sheet";
|
|
import { Avatar, AvatarFallback, AvatarImage } from "@/components/ui/avatar";
|
|
import { NotificationBell } from "@/components/social/notification-bell";
|
|
import { MessagesNavLink } from "@/components/social/messages-nav-link";
|
|
import { authClient } from "@/lib/auth/client";
|
|
import { useTranslations } from "next-intl";
|
|
|
|
const NAV_ITEMS = [
|
|
{ href: "/recipes", key: "recipes", icon: BookOpen },
|
|
{ href: "/explore", key: "explore", icon: Search },
|
|
{ href: "/feed", key: "feed", icon: Rss },
|
|
{ href: "/collections", key: "collections", icon: FolderOpen },
|
|
{ href: "/meal-plan", key: "mealPlan", icon: Calendar },
|
|
{ href: "/pantry", key: "pantry", icon: Package },
|
|
{ href: "/shopping-lists", key: "shopping", icon: ShoppingCart },
|
|
] as const;
|
|
|
|
export function Nav() {
|
|
const pathname = usePathname();
|
|
const router = useRouter();
|
|
const { data: session } = authClient.useSession();
|
|
const isAdmin = (session?.user as { role?: string } | undefined)?.role === "admin";
|
|
const username = (session?.user as { username?: string } | undefined)?.username;
|
|
const { resolvedTheme, setTheme } = useTheme();
|
|
const t = useTranslations("nav");
|
|
return (
|
|
<header className="sticky top-0 z-50 border-b bg-background/95 backdrop-blur supports-[backdrop-filter]:bg-background/60">
|
|
<div className="container mx-auto flex h-14 items-center gap-6 px-4">
|
|
<Sheet>
|
|
<SheetTrigger
|
|
render={<Button variant="ghost" size="icon" className="md:hidden" aria-label={t("menu")} />}
|
|
>
|
|
<Menu className="h-5 w-5" />
|
|
<span className="sr-only">{t("menu")}</span>
|
|
</SheetTrigger>
|
|
<SheetContent side="left">
|
|
<SheetHeader>
|
|
<SheetTitle className="flex items-center gap-2">
|
|
<ChefHat className="h-5 w-5" />
|
|
Epicure
|
|
</SheetTitle>
|
|
</SheetHeader>
|
|
<nav className="flex flex-col gap-1 px-2">
|
|
{NAV_ITEMS.map(({ href, key, icon: Icon }) => (
|
|
<SheetClose
|
|
key={href}
|
|
nativeButton={false}
|
|
render={
|
|
<Link
|
|
href={href}
|
|
className={cn(
|
|
buttonVariants({ variant: "ghost", size: "sm" }),
|
|
"justify-start",
|
|
pathname.startsWith(href) && "bg-accent"
|
|
)}
|
|
/>
|
|
}
|
|
>
|
|
<Icon className="h-4 w-4" />
|
|
{t(key)}
|
|
</SheetClose>
|
|
))}
|
|
</nav>
|
|
</SheetContent>
|
|
</Sheet>
|
|
<Link href="/recipes" className="flex items-center gap-2 font-semibold">
|
|
<ChefHat className="h-5 w-5" />
|
|
<span>Epicure</span>
|
|
</Link>
|
|
<nav className="hidden md:flex items-center gap-1">
|
|
{NAV_ITEMS.map(({ href, key, icon: Icon }) => (
|
|
<Link
|
|
key={href}
|
|
href={href}
|
|
className={cn(
|
|
buttonVariants({ variant: "ghost", size: "sm" }),
|
|
pathname.startsWith(href) && "bg-accent"
|
|
)}
|
|
>
|
|
<Icon className="h-4 w-4" />
|
|
{t(key)}
|
|
</Link>
|
|
))}
|
|
</nav>
|
|
<div className="ml-auto flex items-center gap-2">
|
|
<MessagesNavLink />
|
|
<NotificationBell />
|
|
<DropdownMenu>
|
|
<DropdownMenuTrigger className="rounded-full outline-none focus-visible:ring-2 focus-visible:ring-ring">
|
|
<Avatar className="h-8 w-8">
|
|
<AvatarImage src={session?.user?.image ?? ""} alt={session?.user?.name ?? ""} />
|
|
<AvatarFallback>
|
|
<User className="h-4 w-4" />
|
|
</AvatarFallback>
|
|
</Avatar>
|
|
</DropdownMenuTrigger>
|
|
<DropdownMenuContent align="end" className="w-48">
|
|
{username && (
|
|
<DropdownMenuItem>
|
|
<Link href={`/u/${username}`} className="w-full">{t("viewProfile")}</Link>
|
|
</DropdownMenuItem>
|
|
)}
|
|
<DropdownMenuItem>
|
|
<Link href="/settings" className="w-full">{t("settings")}</Link>
|
|
</DropdownMenuItem>
|
|
<DropdownMenuItem
|
|
onClick={() => setTheme(resolvedTheme === "dark" ? "light" : "dark")}
|
|
className="flex items-center gap-2"
|
|
>
|
|
{resolvedTheme === "dark" ? <Sun className="h-3.5 w-3.5" /> : <Moon className="h-3.5 w-3.5" />}
|
|
{resolvedTheme === "dark" ? t("lightMode") : t("darkMode")}
|
|
</DropdownMenuItem>
|
|
{isAdmin && (
|
|
<>
|
|
<DropdownMenuSeparator />
|
|
<DropdownMenuItem>
|
|
<Link href="/admin" className="w-full flex items-center gap-2">
|
|
<Shield className="h-3.5 w-3.5 text-destructive" />
|
|
{t("admin")}
|
|
</Link>
|
|
</DropdownMenuItem>
|
|
</>
|
|
)}
|
|
<DropdownMenuSeparator />
|
|
<DropdownMenuItem
|
|
onClick={() => {
|
|
void authClient.signOut({
|
|
fetchOptions: {
|
|
onSuccess: () => {
|
|
router.push("/login");
|
|
router.refresh();
|
|
},
|
|
},
|
|
});
|
|
}}
|
|
>
|
|
{t("signOut")}
|
|
</DropdownMenuItem>
|
|
</DropdownMenuContent>
|
|
</DropdownMenu>
|
|
</div>
|
|
</div>
|
|
</header>
|
|
);
|
|
}
|