Initial import: property management SaaS + security hardening + admin dashboard

Property Management Network — Next.js 16 (App Router), Better Auth,
Drizzle ORM over PostgreSQL, Stripe, OpenAI, Resend.

Includes:
- Security hardening: access-control/IDOR fixes, TLS-by-default DB layer,
  constant-time cron auth, strict security headers, atomic AI quota gating,
  HTML/email output encoding, demo-backdoor disabled in production.
- Superadmin dashboard at /admin (overview/MRR, server-paginated users with
  ban/impersonate/plan/delete, billing, platform activity + admin audit log,
  AI usage, system health) via the Better Auth admin plugin.
- Seed/migration utility scripts under scripts/.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Leon Serfaty
2026-06-23 20:36:07 -04:00
co-authored by Claude Opus 4.8
commit 857b9a7811
291 changed files with 38996 additions and 0 deletions
+53
View File
@@ -0,0 +1,53 @@
"use client"
import { useState } from "react"
import { useRouter } from "next/navigation"
import { toast } from "sonner"
export function RentActions({ payment }: { payment: any }) {
const router = useRouter()
const [loading, setLoading] = useState(false)
async function markAs(status: string) {
setLoading(true)
await fetch(`/api/rent/${payment.id}`, {
method: "PATCH",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
status,
paid_date: status === "paid" ? new Date().toISOString().slice(0, 10) : null,
}),
})
setLoading(false)
toast.success(status === "paid" ? "Marked as paid" : "Marked as overdue")
router.refresh()
}
async function handleDelete() {
setLoading(true)
await fetch(`/api/rent/${payment.id}`, { method: "DELETE" })
setLoading(false)
toast.success("Payment deleted")
router.refresh()
}
if (loading) return <span className="text-xs text-white/30">Updating...</span>
return (
<div className="flex items-center justify-end gap-2 opacity-0 group-hover:opacity-100 transition">
{payment.status !== "paid" && (
<button onClick={() => markAs("paid")} className="text-xs text-emerald-400 hover:text-emerald-300">
Mark Paid
</button>
)}
{payment.status !== "overdue" && payment.status !== "paid" && (
<button onClick={() => markAs("overdue")} className="text-xs text-red-400 hover:text-red-300">
Mark Overdue
</button>
)}
<button onClick={handleDelete} className="text-xs text-white/30 hover:text-red-400">
Delete
</button>
</div>
)
}