import { headers } from "next/headers" import { db } from "@/lib/db" import { admin_audit_log } from "@/lib/db/schema" export type AdminAction = | "plan_change" | "ban" | "unban" | "set_role" | "impersonate" | "stop_impersonate" | "delete_user" | "resend_verification" | "maintenance_mode" | "ai_provider" /** * Append one immutable row to admin_audit_log. Call this for EVERY mutating * admin action (the caller must already have passed getAdminSession()). */ export async function logAdminAction(opts: { adminId: string action: AdminAction targetUserId?: string | null metadata?: Record }) { let ip: string | null = null try { const h = await headers() ip = h.get("x-forwarded-for")?.split(",")[0]?.trim() ?? h.get("x-real-ip") ?? null } catch { // headers() unavailable outside a request — fine. } await db.insert(admin_audit_log).values({ admin_id: opts.adminId, action: opts.action, target_user_id: opts.targetUserId ?? null, metadata: opts.metadata ?? {}, ip_address: ip, }) }