diff --git a/app/api/categories/route.ts b/app/api/categories/route.ts
index aae1aa4..c32ffa7 100644
--- a/app/api/categories/route.ts
+++ b/app/api/categories/route.ts
@@ -1,6 +1,7 @@
import { NextResponse } from "next/server";
import { prisma } from "../../../lib/prisma";
import { isAdminSession, requireSession } from "../../../lib/auth-helpers";
+import { getAccessSettings } from "../../../lib/system-settings";
export async function GET() {
const { session } = await requireSession();
@@ -26,7 +27,7 @@ export async function POST(request: Request) {
}
const body = await request.json();
- const { name } = body || {};
+ const { name, isPublic } = body || {};
if (!name) {
return NextResponse.json({ error: "Name erforderlich." }, { status: 400 });
@@ -37,8 +38,9 @@ export async function POST(request: Request) {
return NextResponse.json({ error: "Kategorie existiert bereits." }, { status: 409 });
}
+ const { publicAccessEnabled } = await getAccessSettings();
const category = await prisma.category.create({
- data: { name }
+ data: { name, isPublic: publicAccessEnabled && isPublic === true }
});
const views = await prisma.userView.findMany({
@@ -68,25 +70,42 @@ export async function PATCH(request: Request) {
}
const body = await request.json();
- const { id, name } = body || {};
+ const { id, name, isPublic } = body || {};
- if (!id || !name) {
- return NextResponse.json({ error: "ID und Name erforderlich." }, { status: 400 });
+ if (!id) {
+ return NextResponse.json({ error: "ID erforderlich." }, { status: 400 });
}
- const trimmed = String(name).trim();
- if (!trimmed) {
- return NextResponse.json({ error: "Name erforderlich." }, { status: 400 });
+ const data: { name?: string; isPublic?: boolean } = {};
+
+ if (name !== undefined) {
+ const trimmed = String(name).trim();
+ if (!trimmed) {
+ return NextResponse.json({ error: "Name erforderlich." }, { status: 400 });
+ }
+
+ const existing = await prisma.category.findUnique({ where: { name: trimmed } });
+ if (existing && existing.id !== id) {
+ return NextResponse.json({ error: "Kategorie existiert bereits." }, { status: 409 });
+ }
+ data.name = trimmed;
}
- const existing = await prisma.category.findUnique({ where: { name: trimmed } });
- if (existing && existing.id !== id) {
- return NextResponse.json({ error: "Kategorie existiert bereits." }, { status: 409 });
+ const { publicAccessEnabled } = await getAccessSettings();
+ if (publicAccessEnabled && typeof isPublic === "boolean") {
+ data.isPublic = isPublic;
+ }
+
+ if (Object.keys(data).length === 0) {
+ return NextResponse.json(
+ { error: "Keine Änderungen angegeben." },
+ { status: 400 }
+ );
}
const category = await prisma.category.update({
where: { id },
- data: { name: trimmed }
+ data
});
return NextResponse.json(category);
diff --git a/app/api/events/[id]/route.ts b/app/api/events/[id]/route.ts
index 3f5fd65..6dbefa3 100644
--- a/app/api/events/[id]/route.ts
+++ b/app/api/events/[id]/route.ts
@@ -1,6 +1,7 @@
import { NextResponse } from "next/server";
import { prisma } from "../../../../lib/prisma";
import { isAdminSession, requireSession } from "../../../../lib/auth-helpers";
+import { getAccessSettings } from "../../../../lib/system-settings";
export async function PATCH(request: Request, context: { params: { id: string } }) {
const { session } = await requireSession();
@@ -23,7 +24,8 @@ export async function PATCH(request: Request, context: { params: { id: string }
locationLng,
startAt,
endAt,
- categoryId
+ categoryId,
+ publicOverride
} = body || {};
if (status && ["APPROVED", "REJECTED"].includes(status)) {
@@ -44,6 +46,13 @@ export async function PATCH(request: Request, context: { params: { id: string }
const startDate = new Date(startAt);
const endDate = endAt ? new Date(endAt) : null;
+ const { publicAccessEnabled } = await getAccessSettings();
+ const overrideValue =
+ publicAccessEnabled && publicOverride !== undefined
+ ? publicOverride === null || publicOverride === true || publicOverride === false
+ ? publicOverride
+ : null
+ : undefined;
const event = await prisma.event.update({
where: { id: context.params.id },
@@ -56,7 +65,8 @@ export async function PATCH(request: Request, context: { params: { id: string }
locationLng: locationLng ? Number(locationLng) : null,
startAt: startDate,
endAt: endDate,
- category: { connect: { id: categoryId } }
+ category: { connect: { id: categoryId } },
+ publicOverride: overrideValue
}
});
diff --git a/app/api/events/route.ts b/app/api/events/route.ts
index a2b73d5..8648652 100644
--- a/app/api/events/route.ts
+++ b/app/api/events/route.ts
@@ -1,16 +1,66 @@
import { NextResponse } from "next/server";
+import { getServerSession } from "next-auth";
import { prisma } from "../../../lib/prisma";
import { isAdminSession, requireSession } from "../../../lib/auth-helpers";
+import { authOptions } from "../../../lib/auth";
+import { getAccessSettings } from "../../../lib/system-settings";
export async function GET(request: Request) {
- const { session } = await requireSession();
- if (!session) {
- return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
+ const session = await getServerSession(authOptions);
+ if (session?.user?.status && session.user.status !== "ACTIVE") {
+ return NextResponse.json(
+ { error: "Account nicht freigeschaltet." },
+ { status: 403 }
+ );
+ }
+ if (session?.user?.emailVerified === false) {
+ return NextResponse.json(
+ { error: "E-Mail nicht verifiziert." },
+ { status: 403 }
+ );
}
-
const { searchParams } = new URL(request.url);
const status = searchParams.get("status");
const isAdmin = isAdminSession(session);
+ const { publicAccessEnabled } = await getAccessSettings();
+
+ if (!session?.user?.email) {
+ if (!publicAccessEnabled) {
+ return NextResponse.json(
+ { error: "Öffentlicher Zugriff ist deaktiviert." },
+ { status: 403 }
+ );
+ }
+ const events = await prisma.event.findMany({
+ where: {
+ status: "APPROVED",
+ OR: [
+ { publicOverride: true },
+ { publicOverride: null, category: { isPublic: true } }
+ ]
+ },
+ orderBy: { startAt: "asc" },
+ select: {
+ id: true,
+ title: true,
+ location: true,
+ locationPlaceId: true,
+ locationLat: true,
+ locationLng: true,
+ startAt: true,
+ endAt: true,
+ status: true,
+ category: {
+ select: {
+ id: true,
+ name: true
+ }
+ }
+ }
+ });
+
+ return NextResponse.json(events);
+ }
const where = isAdmin
? status
diff --git a/app/api/settings/system/route.ts b/app/api/settings/system/route.ts
index 9c22d04..15339e4 100644
--- a/app/api/settings/system/route.ts
+++ b/app/api/settings/system/route.ts
@@ -1,29 +1,15 @@
import { NextResponse } from "next/server";
import { prisma } from "../../../../lib/prisma";
import { isSuperAdminSession, requireSession } from "../../../../lib/auth-helpers";
+import { getSystemSettings } from "../../../../lib/system-settings";
export async function GET() {
const { session } = await requireSession();
if (!session) {
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
}
-
- const apiKeySetting = await prisma.setting.findUnique({
- where: { key: "google_places_api_key" }
- });
- const providerSetting = await prisma.setting.findUnique({
- where: { key: "geocoding_provider" }
- });
- const registrationSetting = await prisma.setting.findUnique({
- where: { key: "registration_enabled" }
- });
-
- const apiKey = apiKeySetting?.value || "";
- const provider =
- providerSetting?.value || (apiKey ? "google" : "osm");
- const registrationEnabled = registrationSetting?.value !== "false";
-
- return NextResponse.json({ apiKey, provider, registrationEnabled });
+ const settings = await getSystemSettings();
+ return NextResponse.json(settings);
}
export async function POST(request: Request) {
@@ -37,7 +23,12 @@ export async function POST(request: Request) {
}
const body = await request.json();
- const { apiKey, provider, registrationEnabled } = body || {};
+ const {
+ apiKey,
+ provider,
+ registrationEnabled,
+ publicAccessEnabled
+ } = body || {};
if (!provider || !["google", "osm"].includes(provider)) {
return NextResponse.json({ error: "Provider erforderlich." }, { status: 400 });
@@ -68,9 +59,26 @@ export async function POST(request: Request) {
create: { key: "registration_enabled", value: registrationValue }
});
+ const existing = await getSystemSettings();
+ const nextPublicAccessEnabled =
+ typeof publicAccessEnabled === "boolean"
+ ? publicAccessEnabled
+ : existing.publicAccessEnabled;
+
+ const publicAccessValue = nextPublicAccessEnabled ? "true" : "false";
+ await prisma.setting.upsert({
+ where: { key: "public_access_enabled" },
+ update: { value: publicAccessValue },
+ create: { key: "public_access_enabled", value: publicAccessValue }
+ });
+ await prisma.setting.deleteMany({
+ where: { key: { in: ["public_events_enabled", "anonymous_access_enabled"] } }
+ });
+
return NextResponse.json({
apiKey: apiKeySetting.value,
provider: providerSetting.value,
- registrationEnabled: registrationValue !== "false"
+ registrationEnabled: registrationValue !== "false",
+ publicAccessEnabled: nextPublicAccessEnabled
});
}
diff --git a/app/globals.css b/app/globals.css
index 800fbeb..94edf01 100644
--- a/app/globals.css
+++ b/app/globals.css
@@ -250,6 +250,18 @@ html[data-theme="dark"] .nav-link-active:hover {
color: #0f1110;
}
+.mobile-menu-panel {
+ background: rgba(255, 255, 255, 0.92);
+ border-bottom: 1px solid rgba(226, 232, 240, 0.85);
+ box-shadow: 0 18px 36px rgba(15, 23, 42, 0.12);
+}
+
+html[data-theme="dark"] .mobile-menu-panel {
+ background: rgba(30, 37, 34, 0.95);
+ border-bottom-color: rgba(71, 85, 105, 0.35);
+ box-shadow: 0 18px 36px rgba(0, 0, 0, 0.5);
+}
+
html[data-theme="dark"] .fc .fc-button {
border-color: rgba(71, 85, 105, 0.5);
@@ -387,6 +399,9 @@ html[data-theme="dark"] .drag-handle:hover {
color: #475569;
background: #ffffff;
cursor: grab;
+ touch-action: none;
+ user-select: none;
+ -webkit-user-select: none;
transition: transform 0.15s ease, box-shadow 0.15s ease, background 0.15s ease;
}
@@ -436,6 +451,10 @@ html[data-theme="dark"] .drag-handle:hover {
}
@media (max-width: 768px) {
+ .calendar-pane {
+ display: none;
+ }
+
.fc .fc-toolbar {
flex-direction: column;
gap: 0.5rem;
diff --git a/app/login/page.tsx b/app/login/page.tsx
index 8f140b6..b299717 100644
--- a/app/login/page.tsx
+++ b/app/login/page.tsx
@@ -8,10 +8,12 @@ import { useState } from "react";
export default function LoginPage() {
const router = useRouter();
const [error, setError] = useState
- E-Mail nicht bestätigt?{" "} - - Link erneut senden - -
+ {showVerifyLink && ( ++ E-Mail nicht bestätigt?{" "} + + Link erneut senden + +
+ )} ); } diff --git a/app/page.tsx b/app/page.tsx index aa0978c..6c3a0ba 100644 --- a/app/page.tsx +++ b/app/page.tsx @@ -2,21 +2,27 @@ import { getServerSession } from "next-auth"; import { redirect } from "next/navigation"; import CalendarBoard from "../components/CalendarBoard"; import { authOptions } from "../lib/auth"; +import { getAccessSettings } from "../lib/system-settings"; export default async function HomePage() { const session = await getServerSession(authOptions); + const { publicAccessEnabled } = await getAccessSettings(); + if (!session?.user && !publicAccessEnabled) { + redirect("/login"); + } + const isBlocked = + session?.user && + (session.user.status !== "ACTIVE" || session.user.emailVerified === false); return (Dein Konto wartet auf Freischaltung durch einen Admin.
+ Bitte anmelden, um Einstellungen zu verwalten. +
++ Öffentlich +
+