Files
Epicure/apps/web/components/layout/nav.tsx
T
Arnaud 1abab17ca8 feat: notifications system, rate limiting, fix recipe visibility 404, follow race
Part of the social-feature backlog (follow, comments, reactions, ratings,
feed, threading) audited earlier — see conversation.

- notifications table: follow/comment/reply/reaction/rating events,
  replaces the fully-dead feed_items table (feed_item_type enum existed
  but had zero references anywhere in the codebase).
- Bell UI in the nav with unread badge, mark-all-read, 30s poll.
- Rate limiting on comment posting (20/min), follow/unfollow (30/min),
  and comment reactions (60/min) — previously unthrottled.
- /recipes/[id] queried by (id, authorId=session.user) only, so any
  recipe not owned by the viewer 404'd regardless of visibility.
  Widen the query to include public/unlisted recipes and gate the
  owner-only actions (edit, delete, version history, translate, AI
  content generation) behind an isOwner check.
- user_follows had no primary key/unique constraint, so the follow
  route's onConflictDoNothing() was a silent no-op — concurrent follow
  clicks could insert duplicate rows and inflate follower counts. Add
  a composite primary key on (follower_id, following_id).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-03 21:56:34 +02:00

151 lines
5.3 KiB
TypeScript

"use client";
import Link from "next/link";
import { usePathname, useRouter } from "next/navigation";
import { BookOpen, Calendar, Package, ChefHat, User, Rss, FolderOpen, ShoppingCart, Shield, Search, Compass, Menu } from "lucide-react";
import { cn } from "@/lib/utils";
import { Button, buttonVariants } from "@/components/ui/button";
import {
DropdownMenu,
DropdownMenuContent,
DropdownMenuItem,
DropdownMenuSeparator,
DropdownMenuTrigger,
} from "@/components/ui/dropdown-menu";
import {
Sheet,
SheetClose,
SheetContent,
SheetHeader,
SheetTitle,
SheetTrigger,
} from "@/components/ui/sheet";
import { Avatar, AvatarFallback, AvatarImage } from "@/components/ui/avatar";
import { NotificationBell } from "@/components/social/notification-bell";
import { authClient } from "@/lib/auth/client";
import { useTranslations } from "next-intl";
const NAV_ITEMS = [
{ href: "/recipes", key: "recipes", icon: BookOpen },
{ href: "/explore", key: "explore", icon: Search },
{ href: "/feed", key: "feed", icon: Rss },
{ href: "/collections", key: "collections", icon: FolderOpen },
{ href: "/meal-plan", key: "mealPlan", icon: Calendar },
{ href: "/pantry", key: "pantry", icon: Package },
{ href: "/shopping-lists", key: "shopping", icon: ShoppingCart },
] as const;
export function Nav() {
const pathname = usePathname();
const router = useRouter();
const { data: session } = authClient.useSession();
const isAdmin = (session?.user as { role?: string } | undefined)?.role === "admin";
const t = useTranslations("nav");
return (
<header className="sticky top-0 z-50 border-b bg-background/95 backdrop-blur supports-[backdrop-filter]:bg-background/60">
<div className="container mx-auto flex h-14 items-center gap-6 px-4">
<Sheet>
<SheetTrigger
render={<Button variant="ghost" size="icon" className="md:hidden" />}
>
<Menu className="h-5 w-5" />
<span className="sr-only">{t("menu")}</span>
</SheetTrigger>
<SheetContent side="left">
<SheetHeader>
<SheetTitle className="flex items-center gap-2">
<ChefHat className="h-5 w-5" />
Epicure
</SheetTitle>
</SheetHeader>
<nav className="flex flex-col gap-1 px-2">
{NAV_ITEMS.map(({ href, key, icon: Icon }) => (
<SheetClose
key={href}
nativeButton={false}
render={
<Link
href={href}
className={cn(
buttonVariants({ variant: "ghost", size: "sm" }),
"justify-start",
pathname.startsWith(href) && "bg-accent"
)}
/>
}
>
<Icon className="h-4 w-4" />
{t(key)}
</SheetClose>
))}
</nav>
</SheetContent>
</Sheet>
<Link href="/recipes" className="flex items-center gap-2 font-semibold">
<ChefHat className="h-5 w-5" />
<span>Epicure</span>
</Link>
<nav className="hidden md:flex items-center gap-1">
{NAV_ITEMS.map(({ href, key, icon: Icon }) => (
<Link
key={href}
href={href}
className={cn(
buttonVariants({ variant: "ghost", size: "sm" }),
pathname.startsWith(href) && "bg-accent"
)}
>
<Icon className="h-4 w-4" />
{t(key)}
</Link>
))}
</nav>
<div className="ml-auto flex items-center gap-2">
<NotificationBell />
<DropdownMenu>
<DropdownMenuTrigger className="rounded-full outline-none focus-visible:ring-2 focus-visible:ring-ring">
<Avatar className="h-8 w-8">
<AvatarImage src="" alt="" />
<AvatarFallback>
<User className="h-4 w-4" />
</AvatarFallback>
</Avatar>
</DropdownMenuTrigger>
<DropdownMenuContent align="end" className="w-48">
<DropdownMenuItem>
<Link href="/settings" className="w-full">{t("settings")}</Link>
</DropdownMenuItem>
{isAdmin && (
<>
<DropdownMenuSeparator />
<DropdownMenuItem>
<Link href="/admin" className="w-full flex items-center gap-2">
<Shield className="h-3.5 w-3.5 text-destructive" />
{t("admin")}
</Link>
</DropdownMenuItem>
</>
)}
<DropdownMenuSeparator />
<DropdownMenuItem
onClick={() => {
void authClient.signOut({
fetchOptions: {
onSuccess: () => {
router.push("/login");
router.refresh();
},
},
});
}}
>
{t("signOut")}
</DropdownMenuItem>
</DropdownMenuContent>
</DropdownMenu>
</div>
</div>
</header>
);
}