mirror of
https://github.com/screentinker/screentinker.git
synced 2026-08-13 13:53:12 -06:00
Each of these views carries its own copy of a fetch helper ending in `.then(r => r.json())`. A 403, 404 or 500 body resolves as an ordinary value, so the surrounding try/catch is unreachable and every handler treats the failure as success. The shared client in api.js has always thrown on !res.ok; these local copies never did. Two concrete consequences, both of which tell the operator something untrue: - The layout editor renders a Delete button on built-in templates for everyone. The server returns 403. The handler shows "Layout deleted" and re-renders the list with the template still sitting there. - A rejected platform-role change in Admin shows "Role updated", and the revert that would put the dropdown back lives only in the dead catch — so the UI keeps displaying a value the server refused. The same control in Settings uses the throwing client, so the two pages disagree about whether the change happened. All eight now match the shared contract: reject on !ok with the server's own message, and treat 401 as session expiry the way api.js does. This makes previously-silent failures visible, which is the point — some of them will surface refusals that were always happening. The layout template Delete button, for instance, is now honestly reported as refused rather than falsely confirmed; whether that button should be shown at all is a separate question. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Uaeo9MvzKoyXuN6ZsbhtkL
124 lines
5.6 KiB
JavaScript
124 lines
5.6 KiB
JavaScript
import { showToast } from '../components/toast.js';
|
|
import { esc } from '../utils.js';
|
|
import { t } from '../i18n.js';
|
|
|
|
// A refused request must reject, not resolve.
|
|
//
|
|
// This helper used to end in `.then(r => r.json())`, so a 403/404/500 body resolved as an ordinary
|
|
// value and the surrounding try/catch was unreachable — every handler took the failure for success.
|
|
// Concretely: deleting a built-in layout template showed "Layout deleted" while the server had
|
|
// returned 403 and the template was still there, and a rejected platform-role change showed "Role
|
|
// updated" while the dropdown kept displaying a value the server refused (its revert lives only in
|
|
// the dead catch). The shared client in api.js has always thrown on !res.ok; these local copies did
|
|
// not. Same contract now, including the 401 session-expiry reload.
|
|
const API = (url) => fetch('/api' + url, { headers: { Authorization: `Bearer ${localStorage.getItem('token')}` }}).then(async (r) => {
|
|
if (r.status === 401) { localStorage.removeItem('token'); window.location.reload(); throw new Error('Session expired'); }
|
|
if (!r.ok) { const e = await r.json().catch(() => ({})); throw new Error(e.error || `Request failed (${r.status})`); }
|
|
return r.json();
|
|
});
|
|
|
|
export async function render(container) {
|
|
container.innerHTML = `
|
|
<div class="page-header">
|
|
<div><h1>${t('activity.title')} <span class="help-tip" data-tip="${t('activity.help_tip')}">?</span></h1><div class="subtitle">${t('activity.subtitle')}</div></div>
|
|
</div>
|
|
<div id="activityList"><div class="empty-state"><h3>${t('common.loading')}</h3></div></div>
|
|
<div style="text-align:center;margin-top:16px">
|
|
<button class="btn btn-secondary btn-sm" id="loadMoreBtn" style="display:none">${t('activity.load_more')}</button>
|
|
</div>
|
|
`;
|
|
|
|
let offset = 0;
|
|
const limit = 50;
|
|
|
|
async function loadActivity(append = false) {
|
|
try {
|
|
const items = await API(`/activity?limit=${limit}&offset=${offset}`);
|
|
const list = document.getElementById('activityList');
|
|
|
|
if (!append) list.innerHTML = '';
|
|
|
|
if (items.length === 0 && offset === 0) {
|
|
list.innerHTML = `<div class="empty-state"><h3>${t('activity.empty_title')}</h3><p>${t('activity.empty_desc')}</p></div>`;
|
|
return;
|
|
}
|
|
|
|
const html = items.map(item => {
|
|
const time = new Date(item.created_at * 1000);
|
|
const timeStr = time.toLocaleDateString(undefined, { month: 'short', day: 'numeric' }) + ' ' +
|
|
time.toLocaleTimeString(undefined, { hour: '2-digit', minute: '2-digit' });
|
|
const icon = getActionIcon(item.action);
|
|
|
|
return `
|
|
<div style="display:flex;gap:12px;padding:12px 0;border-bottom:1px solid var(--border);align-items:flex-start">
|
|
<div style="width:32px;height:32px;border-radius:50%;background:var(--bg-card);display:flex;align-items:center;justify-content:center;flex-shrink:0;font-size:14px">${icon}</div>
|
|
<div style="flex:1;min-width:0">
|
|
<div style="font-size:13px">
|
|
<strong>${esc(item.user_name || item.user_email || t('activity.system'))}</strong>
|
|
<span style="color:var(--text-secondary)"> ${esc(formatAction(item.action))}</span>
|
|
</div>
|
|
${item.details ? `<div style="font-size:12px;color:var(--text-muted);margin-top:2px">${esc(item.details)}</div>` : ''}
|
|
</div>
|
|
<div style="font-size:11px;color:var(--text-muted);white-space:nowrap;flex-shrink:0">${timeStr}</div>
|
|
</div>
|
|
`;
|
|
}).join('');
|
|
|
|
if (append) {
|
|
list.insertAdjacentHTML('beforeend', html);
|
|
} else {
|
|
list.innerHTML = html;
|
|
}
|
|
|
|
document.getElementById('loadMoreBtn').style.display = items.length >= limit ? '' : 'none';
|
|
} catch (err) {
|
|
showToast(err.message, 'error');
|
|
}
|
|
}
|
|
|
|
document.getElementById('loadMoreBtn').onclick = () => {
|
|
offset += limit;
|
|
loadActivity(true);
|
|
};
|
|
|
|
loadActivity();
|
|
}
|
|
|
|
function getActionIcon(action) {
|
|
if (action.includes('DELETE')) return '🗑';
|
|
if (action.includes('POST') && action.includes('content')) return '📤';
|
|
if (action.includes('POST') && action.includes('provision')) return '🔗';
|
|
if (action.includes('POST') && action.includes('assignment')) return '📋';
|
|
if (action.includes('alert')) return '🔔';
|
|
if (action.includes('PUT')) return '✎';
|
|
if (action.includes('POST')) return '➕';
|
|
return '📄';
|
|
}
|
|
|
|
// Action verbs are user-visible; translate them through t() so they switch
|
|
// languages with the rest of the UI. The mapping below preserves the original
|
|
// verb-then-noun structure of the English version.
|
|
function formatAction(action) {
|
|
// Verbs
|
|
let s = action
|
|
.replace('POST /api/', t('activity.verb_created') + ' ')
|
|
.replace('PUT /api/', t('activity.verb_updated') + ' ')
|
|
.replace('DELETE /api/', t('activity.verb_deleted') + ' ');
|
|
// Specific endpoints
|
|
s = s
|
|
.replace('/provision/pair', t('activity.action_paired_device'))
|
|
.replace('/content/remote', t('activity.action_added_remote_content'))
|
|
.replace('/content', t('activity.noun_content'))
|
|
.replace('/devices/:id', t('activity.noun_device'))
|
|
.replace('/assignments/device/:deviceId', t('activity.noun_playlist_assignment'))
|
|
.replace('/assignments/:id', t('activity.noun_assignment'))
|
|
.replace('/layouts', t('activity.noun_layout'))
|
|
.replace('/widgets', t('activity.noun_widget'))
|
|
.replace('/schedules', t('activity.noun_schedule'))
|
|
.replace('/walls', t('activity.noun_video_wall'))
|
|
.replace('alert:device_offline', t('activity.alert_device_offline'));
|
|
return s;
|
|
}
|
|
|
|
export function cleanup() {}
|