Multi-phase visual facelift (design tokens, dashboards, sidebar/navbar shell, per-page help guides, and a layout/content pass across every remaining page) plus backend fixes to the dashboard KPI stats: - Admin/Supervisor dashboard KPIs (revenue, donations, registrations, tickets sold) now use a rolling trailing-month window (today back one calendar month, e.g. 9 May - 8 June if today is 8 June) instead of calendar month-to-date, which under-counted for most of the month. The comparison window shifts the same way, so like is still compared with like. - Reports deep-links from those stat tiles now match the same window (range=trailing_month, replacing range=this_month). - Design tokens (brand-* Tailwind scale + shadcn CSS variables), a site-wide contextual help button, fixed dashboard sidebar/navbar, Admin/Supervisor/Staff/User dashboard rebuilds backed by a new GET /api/stats/overview endpoint, a dedicated Contact page, Site Settings restyle with WhatsApp config folded in, and an Account activity feed backed by a new SecurityEvent model. - Every remaining page (home, events, registration flow, auth, legal, payment results, and every Admin/Supervisor/Staff/User tool page) restyled onto the same design tokens, several with real layout upgrades (home hero, events list/detail, donate page, auth pages). - 20+ new dedicated help guides so the whole site has page-specific help content instead of falling back to a generic guide. - Assorted fixes surfaced along the way: donation-leg double-counting in payment stats, donations not counting toward revenue, refund netting in per-method report breakdowns, and donation over-allocation after a refund. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
35 lines
1.2 KiB
JavaScript
35 lines
1.2 KiB
JavaScript
const prisma = require('../config/db');
|
|
const { describeUserAgent } = require('./userAgent');
|
|
|
|
// Fire-and-forget by design — a logging failure must never break login/password-change,
|
|
// so this swallows its own errors rather than propagating them to the caller (same
|
|
// posture as the existing email/WhatsApp notification sends elsewhere in this codebase).
|
|
async function logSecurityEvent({ userId, type, ip, userAgent }) {
|
|
try {
|
|
await prisma.securityEvent.create({
|
|
data: {
|
|
userId: userId || null,
|
|
type,
|
|
ip: ip || null,
|
|
device: describeUserAgent(userAgent),
|
|
},
|
|
});
|
|
} catch (e) {
|
|
console.error('Failed to log security event:', e?.message);
|
|
}
|
|
}
|
|
|
|
// Recent activity for a user's Profile & Security page — no raw IP in the response,
|
|
// just what the mockup shows (what happened, on what device, when).
|
|
async function getRecentSecurityEvents(userId, limit = 10) {
|
|
const rows = await prisma.securityEvent.findMany({
|
|
where: { userId },
|
|
orderBy: { createdAt: 'desc' },
|
|
take: limit,
|
|
select: { id: true, type: true, device: true, createdAt: true },
|
|
});
|
|
return rows;
|
|
}
|
|
|
|
module.exports = { logSecurityEvent, getRecentSecurityEvents };
|