import type { PageServerLoad, Actions } from './$types'; import { db } from '$lib/server/db'; import { events } from '$lib/server/schema'; import { error, fail, redirect } from '@sveltejs/kit'; import { hasPermission } from '$lib/roles'; import type { Role } from '$lib/roles'; import { logAudit } from '$lib/server/audit'; export const load: PageServerLoad = async ({ locals }) => { if (!hasPermission(locals.user!.role as Role, 'events')) error(403, 'Access denied'); return {}; }; export const actions: Actions = { default: async ({ request, locals }) => { if (!hasPermission(locals.user!.role as Role, 'events')) error(403, 'Access denied'); const fd = await request.formData(); const title = fd.get('title')?.toString().trim() ?? ''; const description = fd.get('description')?.toString().trim() || null; const location = fd.get('location')?.toString().trim() || null; const startDateStr = fd.get('startDate')?.toString() ?? ''; const endDateStr = fd.get('endDate')?.toString() || null; const imageUrl = fd.get('imageUrl')?.toString().trim() || null; const facebookEventId = fd.get('facebookEventId')?.toString().trim() || null; const published = fd.get('published') === 'on'; if (!title) return fail(400, { error: 'Title is required' }); if (!startDateStr) return fail(400, { error: 'Start date is required' }); const startDate = new Date(startDateStr); const endDate = endDateStr ? new Date(endDateStr) : null; const [result] = await db.insert(events).values({ title, description, location, startDate, endDate, imageUrl, facebookEventId, published }).$returningId(); await logAudit({ userId: locals.user!.id, action: 'create_event', entity: 'event', entityId: result.id, diff: { title, published } }); redirect(303, `/admin/events/${result.id}`); } };