Batch commit of the pending working tree on security/audit-fixes-2026-07. Major areas: - Outbound webhooks / Zapier: schema + signed delivery with retries, public v1 API (REST-hook subscribe/unsubscribe), settings UI, cron drain. - Deploy hardening: email via SMTP2GO (Resend fully removed), verified DB TLS (DATABASE_SSL=require + DATABASE_CA), storage fails loud in production when Spaces is unconfigured instead of silently using ephemeral disk. - Integrations & features (concurrent work): accounting (QuickBooks/Xero), e-signature (DocuSign/Dropbox Sign), PayPal, geocoding/maps, onboarding, expanded legal pages. - DB migrations 0006–0009. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
57 lines
2.1 KiB
TypeScript
57 lines
2.1 KiB
TypeScript
import { redirect } from "next/navigation"
|
|
import { eq } from "drizzle-orm"
|
|
import { db } from "@/lib/db"
|
|
import { profiles } from "@/lib/db/schema"
|
|
import { getSession, isAdminUser } from "@/lib/session"
|
|
import { getMaintenanceMode } from "@/lib/settings"
|
|
import { MaintenanceScreen } from "@/components/shared/maintenance-screen"
|
|
import { Sidebar } from "@/components/dashboard/sidebar"
|
|
import { Header } from "@/components/dashboard/header"
|
|
import { CommandPalette } from "@/components/dashboard/command-palette"
|
|
import { PageTransition } from "@/components/dashboard/page-transition"
|
|
import { Breadcrumbs } from "@/components/dashboard/breadcrumbs"
|
|
import { ScrollToTop } from "@/components/ui/scroll-to-top"
|
|
import { ImpersonationBanner } from "@/components/admin/impersonation-banner"
|
|
|
|
export default async function DashboardLayout({ children }: { children: React.ReactNode }) {
|
|
const session = await getSession()
|
|
const user = session?.user
|
|
|
|
if (!user) {
|
|
redirect("/login")
|
|
}
|
|
|
|
// Site maintenance mode: everyone except admins sees the maintenance screen.
|
|
const maintenance = await getMaintenanceMode()
|
|
if (maintenance.enabled && !isAdminUser(user)) {
|
|
return <MaintenanceScreen message={maintenance.message} />
|
|
}
|
|
|
|
const profile = await db.query.profiles.findFirst({
|
|
where: eq(profiles.id, user.id),
|
|
})
|
|
|
|
// Set by the Better Auth admin plugin while an admin is impersonating.
|
|
const impersonating = Boolean((session?.session as { impersonatedBy?: string })?.impersonatedBy)
|
|
|
|
return (
|
|
<div className="flex h-screen flex-col bg-[#09090b] overflow-hidden">
|
|
{impersonating && <ImpersonationBanner label={profile?.email ?? user.email} />}
|
|
<div className="flex flex-1 overflow-hidden">
|
|
<Sidebar profile={profile ?? null} isAdmin={isAdminUser(user)} />
|
|
<div className="flex flex-1 flex-col overflow-hidden">
|
|
<Header />
|
|
<main id="main-scroll" className="flex-1 overflow-y-auto p-4 sm:p-6">
|
|
<Breadcrumbs />
|
|
<PageTransition>
|
|
{children}
|
|
</PageTransition>
|
|
</main>
|
|
</div>
|
|
<CommandPalette />
|
|
<ScrollToTop />
|
|
</div>
|
|
</div>
|
|
)
|
|
}
|