* Code review fixes: type safety, security hardening, and dead code removal
- Fix Socket.IO event types: draft-paused and draft-resumed were typed as
() => void but are emitted with { seasonId, paused } data payloads
- Fix draft.force-manual-pick: add missing season.status === "draft" guard
so commissioners cannot force picks outside an active draft; add duplicate
pick-number check so a slot cannot be assigned two picks (the previous
code only checked participant uniqueness, not slot uniqueness)
- Replace args: any with ActionFunctionArgs / Route.LoaderArgs across all
API routes and league loaders; replace (auth as any).userId casts with
proper const { userId } = await getAuth(args) destructuring
- Remove unused isSnakeDraft = true dead variable from draft.make-pick
- Replace autodraftSettings: any and draftSlots: any[] in draft-utils with
properly typed InferSelectModel / DraftSlot types
- Update force-manual-pick tests: sequence draftPicks.findFirst mock for
the two-call flow; add new tests for status-check and slot-uniqueness
https://claude.ai/code/session_01FKq2gPFYpgdfxr8cw4Z2AZ
* Fix RouterContextProvider type errors in action test files
Cast context argument to RouterContextProvider in test helpers so
ActionFunctionArgs strict typing is satisfied without weakening the
production action signatures back to any.
https://claude.ai/code/session_01FKq2gPFYpgdfxr8cw4Z2AZ
---------
Co-authored-by: Claude <noreply@anthropic.com>
98 lines
2.7 KiB
TypeScript
98 lines
2.7 KiB
TypeScript
import { getAuth } from "@clerk/react-router/server";
|
|
import { eq, and } from "drizzle-orm";
|
|
import { database } from "~/database/context";
|
|
import * as schema from "~/database/schema";
|
|
import { getSocketIO } from "../../../server/socket";
|
|
|
|
import type { ActionFunctionArgs } from "react-router";
|
|
export async function action(args: ActionFunctionArgs) {
|
|
const { request } = args;
|
|
const { userId } = await getAuth(args);
|
|
|
|
if (!userId) {
|
|
return Response.json({ error: "Unauthorized" }, { status: 401 });
|
|
}
|
|
|
|
const formData = await request.formData();
|
|
const seasonId = formData.get("seasonId") as string;
|
|
const teamId = formData.get("teamId") as string;
|
|
const adjustmentRaw = formData.get("adjustment");
|
|
const adjustment = adjustmentRaw !== null ? parseInt(adjustmentRaw as string, 10) : NaN;
|
|
|
|
if (!seasonId || !teamId || isNaN(adjustment)) {
|
|
return Response.json({ error: "seasonId, teamId, and adjustment are required" }, { status: 400 });
|
|
}
|
|
|
|
const db = database();
|
|
|
|
const season = await db.query.seasons.findFirst({
|
|
where: eq(schema.seasons.id, seasonId),
|
|
});
|
|
|
|
if (!season) {
|
|
return Response.json({ error: "Season not found" }, { status: 404 });
|
|
}
|
|
|
|
if (season.status !== "draft") {
|
|
return Response.json({ error: "Draft is not currently active" }, { status: 409 });
|
|
}
|
|
|
|
const isCommissioner = await db.query.commissioners.findFirst({
|
|
where: and(
|
|
eq(schema.commissioners.leagueId, season.leagueId),
|
|
eq(schema.commissioners.userId, userId)
|
|
),
|
|
});
|
|
|
|
if (!isCommissioner) {
|
|
return Response.json(
|
|
{ error: "Only commissioners can adjust time banks" },
|
|
{ status: 403 }
|
|
);
|
|
}
|
|
|
|
const [currentTimer] = await db
|
|
.select()
|
|
.from(schema.draftTimers)
|
|
.where(
|
|
and(
|
|
eq(schema.draftTimers.seasonId, seasonId),
|
|
eq(schema.draftTimers.teamId, teamId)
|
|
)
|
|
);
|
|
|
|
let newTime: number;
|
|
|
|
if (!currentTimer) {
|
|
if (adjustment <= 0) {
|
|
return Response.json({ error: "Timer not found for this team" }, { status: 404 });
|
|
}
|
|
newTime = adjustment;
|
|
await db.insert(schema.draftTimers).values({
|
|
seasonId,
|
|
teamId,
|
|
timeRemaining: newTime,
|
|
});
|
|
} else {
|
|
newTime = Math.max(0, currentTimer.timeRemaining + adjustment);
|
|
await db
|
|
.update(schema.draftTimers)
|
|
.set({ timeRemaining: newTime, updatedAt: new Date() })
|
|
.where(eq(schema.draftTimers.id, currentTimer.id));
|
|
}
|
|
|
|
try {
|
|
getSocketIO()
|
|
.to(`draft-${seasonId}`)
|
|
.emit("timer-update", {
|
|
seasonId,
|
|
teamId,
|
|
timeRemaining: newTime,
|
|
currentPickNumber: season.currentPickNumber ?? 1,
|
|
});
|
|
} catch (error) {
|
|
console.error("Socket.IO error:", error);
|
|
}
|
|
|
|
return Response.json({ success: true, timeRemaining: newTime });
|
|
}
|