feat: harden admin security, add AI trip planner, map view, and SEO/notification improvements
Security: - requireAdmin() session check added to every admin-only server action (previously relied only on middleware path matching, which Next.js Server Actions don't reliably respect) - Real Prisma + bcrypt admin auth, replacing hardcoded credentials; split into an Edge-safe auth.config.ts (used by proxy.ts) and the full Prisma-backed auth.ts (route handler, server actions, server components) - Removed hardcoded fallback secret on the Instagram sync cron endpoint - Honeypot field + per-IP rate limiting on contact/business-submission forms and the analytics events endpoint Features: - AI trip planner (/plan-olustur, /plan/[id]) backed by DeepSeek, grounded to only recommend isLocalApproved listings, with a deterministic link-injection fallback for anything the model doesn't format as markdown - Interactive Leaflet/OpenStreetMap view on category listing pages - Telegram notifications for new contact messages and business submissions SEO: - Brand-consistent favicon/apple-icon/PWA icons and default Open Graph/ Twitter share images, generated via next/og (replacing default Next.js placeholders) - BreadcrumbList structured data on category and listing detail pages - Fixed two remaining raw <img> tags to use next/image Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
390bd699a6
commit
1b8cfeda95
@@ -2,6 +2,7 @@
|
||||
|
||||
import { useState } from 'react'
|
||||
import { submitBusinessAction } from '@/app/actions'
|
||||
import HoneypotField from '@/components/HoneypotField'
|
||||
|
||||
interface Option {
|
||||
value: string
|
||||
@@ -73,6 +74,8 @@ export default function BusinessForm({ translations, categories, neighborhoods }
|
||||
</div>
|
||||
)}
|
||||
|
||||
<HoneypotField />
|
||||
|
||||
{/* Business name */}
|
||||
<div className="space-y-1.5">
|
||||
<label className="block text-xs font-mono uppercase tracking-wider text-shutter">{translations.businessName} *</label>
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import type { Metadata } from 'next'
|
||||
import { basicMetadata } from '@/lib/seo'
|
||||
import { getTranslations, setRequestLocale } from 'next-intl/server'
|
||||
import { mockDb } from '@/lib/mockDb'
|
||||
import BusinessForm from './BusinessForm'
|
||||
@@ -6,6 +8,13 @@ interface AddBusinessPageProps {
|
||||
params: Promise<{ locale: string }>
|
||||
}
|
||||
|
||||
export async function generateMetadata({ params }: AddBusinessPageProps): Promise<Metadata> {
|
||||
const { locale } = await params
|
||||
const title = locale === 'en' ? 'Add Your Business — Marmaris Local' : locale === 'ru' ? 'Добавить заведение — Marmaris Local' : 'İşletme Ekle — Marmaris Local'
|
||||
const description = locale === 'en' ? 'Apply to get your Marmaris business curated and featured with the Yerel Onaylı seal.' : locale === 'ru' ? 'Подайте заявку на включение вашего заведения в гид Marmaris Local.' : 'İşletmenizi Marmaris Local rehberine ekleyin ve Yerel Onaylı mührünü alın.'
|
||||
return basicMetadata(title, description, locale, '/add-business')
|
||||
}
|
||||
|
||||
export default async function AddBusinessPage({ params }: AddBusinessPageProps) {
|
||||
const { locale } = await params
|
||||
setRequestLocale(locale)
|
||||
|
||||
Reference in New Issue
Block a user