import { asc, eq } from "drizzle-orm"; import { isLauncherIconName, isLauncherTintName, type LauncherIconName, type LauncherTintName, } from "@/shared/launcher"; import { isNonEmptyString, readJsonBody, requiredParam } from "@/worker/api/request"; import { launcherApps } from "@/worker/db/schema"; import type { AppContext } from "@/worker/hono"; import { HttpError } from "@/worker/http"; import { isSafeHttpUrl } from "@/worker/services/url"; interface CreateLauncherAppBody { name?: unknown; url?: unknown; icon?: unknown; tint?: unknown; enabled?: unknown; } interface UpdateLauncherAppBody { name?: unknown; url?: unknown; icon?: unknown; tint?: unknown; enabled?: unknown; } const toApiShape = (row: typeof launcherApps.$inferSelect) => ({ id: row.id, name: row.name, url: row.url, icon: isLauncherIconName(row.icon) ? row.icon : null, tint: isLauncherTintName(row.tint) ? row.tint : null, enabled: row.enabled, createdAt: row.createdAt, updatedAt: row.updatedAt, }); const validateUrl = (raw: unknown): string => { if (!isNonEmptyString(raw)) { throw new HttpError(400, "invalid_url", "url is required."); } const trimmed = raw.trim(); if (!isSafeHttpUrl(trimmed)) { throw new HttpError(400, "invalid_url", "url must be an absolute https URL (http allowed only on loopback)."); } return trimmed; }; const validateName = (raw: unknown): string => { if (!isNonEmptyString(raw)) { throw new HttpError(400, "invalid_name", "name is required."); } const trimmed = raw.trim(); if (trimmed.length === 0) { throw new HttpError(400, "invalid_name", "name is required."); } return trimmed; }; // Tri-state on PATCH: missing key leaves the field unchanged, `null` or // `""` clears it, a registry-valid string sets it. const validateOptionalIcon = (raw: unknown): { provided: boolean; value: LauncherIconName | null } => { if (raw === undefined) return { provided: false, value: null }; if (raw === null || raw === "") return { provided: true, value: null }; if (!isLauncherIconName(raw)) { throw new HttpError(400, "invalid_icon", "icon must match the curated launcher registry."); } return { provided: true, value: raw }; }; const validateOptionalTint = (raw: unknown): { provided: boolean; value: LauncherTintName | null } => { if (raw === undefined) return { provided: false, value: null }; if (raw === null || raw === "") return { provided: true, value: null }; if (!isLauncherTintName(raw)) { throw new HttpError(400, "invalid_tint", "tint must match the curated launcher registry."); } return { provided: true, value: raw }; }; // `enabled` gates public launcher visibility, so reject anything that // isn't a real boolean. Truthy-coercing a string ("false" -> true) would // silently invert intent. const validateEnabled = (raw: unknown): boolean => { if (typeof raw !== "boolean") { throw new HttpError(400, "invalid_enabled", "enabled must be a boolean."); } return raw; }; export const handleListLauncherApps = async (c: AppContext): Promise => { const rows = await c.var.db.select().from(launcherApps).orderBy(asc(launcherApps.name)); return c.json(rows.map(toApiShape)); }; export const handleCreateLauncherApp = async (c: AppContext): Promise => { const logger = c.var.log.child({ component: "admin.launcher-apps" }); const body = await readJsonBody(c); const name = validateName(body.name); const url = validateUrl(body.url); const icon = validateOptionalIcon(body.icon).value; const tint = validateOptionalTint(body.tint).value; const enabled = body.enabled === undefined ? true : validateEnabled(body.enabled); const id = crypto.randomUUID(); const [created] = await c.var.db.insert(launcherApps).values({ id, name, url, icon, tint, enabled }).returning(); if (!created) { throw new HttpError(500, "create_failed", "Could not load created launcher app."); } logger.info("launcher_app_created", { appId: id, byUserId: c.var.session?.user.id, enabled, iconSet: icon !== null, tintSet: tint !== null, }); return c.json(toApiShape(created), 201); }; export const handleUpdateLauncherApp = async (c: AppContext): Promise => { const logger = c.var.log.child({ component: "admin.launcher-apps" }); const id = requiredParam(c, "id", { status: 400, code: "invalid_id", message: "Launcher app id required." }); const body = await readJsonBody(c); const updates: Partial = {}; const changed: string[] = []; if (body.name !== undefined) { updates.name = validateName(body.name); changed.push("name"); } if (body.url !== undefined) { updates.url = validateUrl(body.url); changed.push("url"); } const iconCheck = validateOptionalIcon(body.icon); if (iconCheck.provided) { updates.icon = iconCheck.value; changed.push("icon"); } const tintCheck = validateOptionalTint(body.tint); if (tintCheck.provided) { updates.tint = tintCheck.value; changed.push("tint"); } if (body.enabled !== undefined) { updates.enabled = validateEnabled(body.enabled); changed.push("enabled"); } if (changed.length === 0) { throw new HttpError(400, "invalid_body", "At least one field is required."); } const [updated] = await c.var.db.update(launcherApps).set(updates).where(eq(launcherApps.id, id)).returning(); if (!updated) { throw new HttpError(404, "not_found", "Launcher app not found."); } logger.info("launcher_app_updated", { appId: id, byUserId: c.var.session?.user.id, fields: changed, }); return c.json(toApiShape(updated)); }; export const handleDeleteLauncherApp = async (c: AppContext): Promise => { const logger = c.var.log.child({ component: "admin.launcher-apps" }); const id = requiredParam(c, "id", { status: 400, code: "invalid_id", message: "Launcher app id required." }); await c.var.db.delete(launcherApps).where(eq(launcherApps.id, id)); logger.info("launcher_app_deleted", { appId: id, byUserId: c.var.session?.user.id }); return c.body(null, 204); };