diff --git a/backend/prisma/schema.prisma b/backend/prisma/schema.prisma
index 2c2615c..f853145 100644
--- a/backend/prisma/schema.prisma
+++ b/backend/prisma/schema.prisma
@@ -34,6 +34,7 @@ model Base {
url String?
imageUrl String?
imagePath String?
+ isPrivate Boolean @default(false)
createdAt DateTime @default(now())
user User @relation(fields: [userId], references: [id])
userId String
diff --git a/backend/src/server.js b/backend/src/server.js
index 6a95c96..430f317 100644
--- a/backend/src/server.js
+++ b/backend/src/server.js
@@ -17,6 +17,7 @@ const app = express();
const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename);
const uploadDir = path.join(__dirname, '..', 'uploads');
+const fsPromises = fs.promises;
const jwtSecret = process.env.JWT_SECRET || 'super-secret-key';
const frontendOrigin = process.env.FRONTEND_ORIGIN || 'http://localhost:3100';
const port = process.env.PORT || 4000;
@@ -205,6 +206,34 @@ app.post('/army-categories', requireAuth, async (req, res) => {
}
});
+app.delete('/army-categories/:categoryId', requireAuth, async (req, res) => {
+ try {
+ const { categoryId } = req.params;
+ const category = await prisma.armyCategory.findFirst({
+ where: { id: categoryId, userId: req.user.id },
+ });
+
+ if (!category) {
+ return res.status(404).json({ error: 'Army category not found' });
+ }
+
+ await prisma.$transaction([
+ prisma.defense.deleteMany({
+ where: {
+ armyCategoryId: category.id,
+ base: { userId: req.user.id },
+ },
+ }),
+ prisma.armyCategory.delete({ where: { id: category.id } }),
+ ]);
+
+ return res.json({ message: 'Army category deleted' });
+ } catch (error) {
+ console.error(error);
+ return res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
app.get('/bases', requireAuth, async (req, res) => {
const bases = await prisma.base.findMany({
where: { userId: req.user.id },
@@ -217,6 +246,7 @@ app.get('/bases', requireAuth, async (req, res) => {
description: base.description || '',
url: base.url || '',
imageUrl: buildImageUrl(base),
+ isPrivate: base.isPrivate,
createdAt: base.createdAt,
})),
});
@@ -224,7 +254,7 @@ app.get('/bases', requireAuth, async (req, res) => {
app.post('/bases', requireAuth, upload.single('imageFile'), async (req, res) => {
try {
- const { title, description, url, imageMode, imageUrl } = req.body;
+ const { title, description, url, imageMode, imageUrl, isPrivate } = req.body;
if (!title || !title.trim()) {
return res.status(400).json({ error: 'Title is required' });
}
@@ -238,7 +268,7 @@ app.post('/bases', requireAuth, upload.single('imageFile'), async (req, res) =>
if (!imageUrl || !isValidUrl(imageUrl)) {
return res.status(400).json({ error: 'Image URL must be valid' });
}
- storedImageUrl = imageUrl;
+ storedImageUrl = imageUrl.trim();
} else if (req.file) {
storedImagePath = req.file.filename;
}
@@ -250,6 +280,7 @@ app.post('/bases', requireAuth, upload.single('imageFile'), async (req, res) =>
url: url?.trim() || null,
imageUrl: storedImageUrl,
imagePath: storedImagePath,
+ isPrivate: parseBoolean(isPrivate),
userId: req.user.id,
},
});
@@ -261,9 +292,141 @@ app.post('/bases', requireAuth, upload.single('imageFile'), async (req, res) =>
description: base.description || '',
url: base.url || '',
imageUrl: buildImageUrl(base),
+ isPrivate: base.isPrivate,
createdAt: base.createdAt,
},
});
+ } catch (error) {
+ console.error(error);
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ }
+ return res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
+app.put('/bases/:baseId', requireAuth, upload.single('imageFile'), async (req, res) => {
+ let newUploadFilename = null;
+ try {
+ const { baseId } = req.params;
+ const {
+ title,
+ description,
+ url,
+ imageMode,
+ imageUrl,
+ removeImage,
+ isPrivate,
+ } = req.body;
+
+ if (!title || !title.trim()) {
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ }
+ return res.status(400).json({ error: 'Title is required' });
+ }
+
+ if (url && !isValidUrl(url)) {
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ }
+ return res.status(400).json({ error: 'Planning link must be a valid URL' });
+ }
+
+ const base = await prisma.base.findFirst({ where: { id: baseId, userId: req.user.id } });
+ if (!base) {
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ }
+ return res.status(404).json({ error: 'Base not found' });
+ }
+
+ const shouldRemoveImage = parseBoolean(removeImage);
+ const parsedIsPrivate = parseBoolean(isPrivate);
+
+ let imagePath = base.imagePath;
+ let storedImageUrl = base.imageUrl;
+ let previousImagePathToDelete = null;
+
+ if (shouldRemoveImage) {
+ previousImagePathToDelete = base.imagePath;
+ imagePath = null;
+ storedImageUrl = null;
+ } else if (imageMode === 'url') {
+ if (imageUrl) {
+ if (!isValidUrl(imageUrl)) {
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ }
+ return res.status(400).json({ error: 'Image URL must be valid' });
+ }
+ previousImagePathToDelete = base.imagePath;
+ imagePath = null;
+ storedImageUrl = imageUrl.trim();
+ }
+ } else if (req.file) {
+ newUploadFilename = req.file.filename;
+ previousImagePathToDelete = base.imagePath;
+ imagePath = req.file.filename;
+ storedImageUrl = null;
+ }
+
+ const updatedBase = await prisma.base.update({
+ where: { id: base.id },
+ data: {
+ title: title.trim(),
+ description: description?.trim() || null,
+ url: url?.trim() || null,
+ imageUrl: storedImageUrl,
+ imagePath,
+ isPrivate: parsedIsPrivate,
+ },
+ });
+
+ if (previousImagePathToDelete && previousImagePathToDelete !== imagePath) {
+ await deleteImageFile(previousImagePathToDelete);
+ }
+
+ return res.json({
+ base: {
+ id: updatedBase.id,
+ title: updatedBase.title,
+ description: updatedBase.description || '',
+ url: updatedBase.url || '',
+ imageUrl: buildImageUrl(updatedBase),
+ isPrivate: updatedBase.isPrivate,
+ createdAt: updatedBase.createdAt,
+ },
+ });
+ } catch (error) {
+ console.error(error);
+ if (req.file) {
+ await deleteImageFile(req.file.filename);
+ } else if (newUploadFilename) {
+ await deleteImageFile(newUploadFilename);
+ }
+ return res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
+app.delete('/bases/:baseId', requireAuth, async (req, res) => {
+ try {
+ const { baseId } = req.params;
+ const base = await prisma.base.findFirst({ where: { id: baseId, userId: req.user.id } });
+ if (!base) {
+ return res.status(404).json({ error: 'Base not found' });
+ }
+
+ await prisma.$transaction([
+ prisma.defense.deleteMany({ where: { baseId: base.id } }),
+ prisma.base.delete({ where: { id: base.id } }),
+ ]);
+
+ if (base.imagePath) {
+ await deleteImageFile(base.imagePath);
+ }
+
+ return res.json({ message: 'Base deleted' });
} catch (error) {
console.error(error);
return res.status(500).json({ error: 'Internal server error' });
@@ -321,6 +484,86 @@ app.post('/bases/:baseId/defenses', requireAuth, async (req, res) => {
}
});
+app.put('/defenses/:defenseId', requireAuth, async (req, res) => {
+ try {
+ const { defenseId } = req.params;
+ const { baseId, armyCategoryId, stars, percent, trophies } = req.body || {};
+
+ if (!baseId) {
+ return res.status(400).json({ error: 'Base is required' });
+ }
+ if (!armyCategoryId) {
+ return res.status(400).json({ error: 'Army category is required' });
+ }
+
+ const parsedStars = Number(stars);
+ const parsedPercent = Number(percent);
+ const parsedTrophies = Number(trophies ?? 0);
+
+ if (!Number.isFinite(parsedStars) || parsedStars < 0 || parsedStars > 3) {
+ return res.status(400).json({ error: 'Stars must be between 0 and 3' });
+ }
+ if (!Number.isFinite(parsedPercent) || parsedPercent < 0 || parsedPercent > 100) {
+ return res.status(400).json({ error: 'Percent must be between 0 and 100' });
+ }
+ if (!Number.isFinite(parsedTrophies) || parsedTrophies < -200 || parsedTrophies > 200) {
+ return res.status(400).json({ error: 'Trophies must be between -200 and 200' });
+ }
+
+ const [defense, base, category] = await Promise.all([
+ prisma.defense.findFirst({
+ where: { id: defenseId, base: { userId: req.user.id } },
+ }),
+ prisma.base.findFirst({ where: { id: baseId, userId: req.user.id } }),
+ prisma.armyCategory.findFirst({ where: { id: armyCategoryId, userId: req.user.id } }),
+ ]);
+
+ if (!defense) {
+ return res.status(404).json({ error: 'Defense not found' });
+ }
+ if (!base) {
+ return res.status(404).json({ error: 'Base not found' });
+ }
+ if (!category) {
+ return res.status(404).json({ error: 'Army category not found' });
+ }
+
+ await prisma.defense.update({
+ where: { id: defense.id },
+ data: {
+ baseId: base.id,
+ armyCategoryId: category.id,
+ stars: parsedStars,
+ percent: parsedPercent,
+ trophies: parsedTrophies,
+ },
+ });
+
+ return res.json({ message: 'Defense updated' });
+ } catch (error) {
+ console.error(error);
+ return res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
+app.delete('/defenses/:defenseId', requireAuth, async (req, res) => {
+ try {
+ const { defenseId } = req.params;
+ const result = await prisma.defense.deleteMany({
+ where: { id: defenseId, base: { userId: req.user.id } },
+ });
+
+ if (!result.count) {
+ return res.status(404).json({ error: 'Defense not found' });
+ }
+
+ return res.json({ message: 'Defense deleted' });
+ } catch (error) {
+ console.error(error);
+ return res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
app.get('/defenses', requireAuth, async (req, res) => {
try {
const user = await prisma.user.findUnique({
@@ -443,6 +686,133 @@ app.get('/defenses', requireAuth, async (req, res) => {
}
});
+app.get('/profiles', requireAuth, async (req, res) => {
+ try {
+ const searchTerm = (req.query.search ?? '').toString().trim();
+ const users = await prisma.user.findMany({
+ where: searchTerm
+ ? {
+ username: {
+ contains: searchTerm,
+ mode: 'insensitive',
+ },
+ }
+ : undefined,
+ orderBy: { username: 'asc' },
+ take: 25,
+ select: {
+ id: true,
+ username: true,
+ createdAt: true,
+ bases: {
+ where: { isPrivate: false },
+ select: {
+ id: true,
+ _count: { select: { defenses: true } },
+ },
+ },
+ },
+ });
+
+ const profiles = users.map((user) => {
+ const publicBaseCount = user.bases.length;
+ const publicDefenseCount = user.bases.reduce((sum, base) => sum + base._count.defenses, 0);
+ return {
+ id: user.id,
+ username: user.username,
+ createdAt: user.createdAt,
+ publicBaseCount,
+ publicDefenseCount,
+ };
+ });
+
+ res.json({ profiles });
+ } catch (error) {
+ console.error(error);
+ res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
+app.get('/profiles/:username', requireAuth, async (req, res) => {
+ try {
+ const usernameParam = req.params.username.toLowerCase();
+ const profileUser = await prisma.user.findUnique({
+ where: { username: usernameParam },
+ select: {
+ id: true,
+ username: true,
+ createdAt: true,
+ },
+ });
+
+ if (!profileUser) {
+ return res.status(404).json({ error: 'Profile not found' });
+ }
+
+ const isOwner = profileUser.id === req.user.id;
+
+ const bases = await prisma.base.findMany({
+ where: {
+ userId: profileUser.id,
+ ...(isOwner ? {} : { isPrivate: false }),
+ },
+ orderBy: { createdAt: 'desc' },
+ include: {
+ defenses: {
+ orderBy: { createdAt: 'desc' },
+ include: {
+ armyCategory: {
+ select: { id: true, name: true },
+ },
+ },
+ },
+ },
+ });
+
+ const serializedBases = bases.map((base) => {
+ const defenses = base.defenses.map((defense) => ({
+ id: defense.id,
+ stars: defense.stars,
+ percent: defense.percent,
+ trophies: defense.trophies,
+ createdAt: defense.createdAt,
+ armyCategoryId: defense.armyCategoryId,
+ armyCategoryName: defense.armyCategory?.name || 'Unknown Army',
+ }));
+ return {
+ id: base.id,
+ title: base.title,
+ description: base.description || '',
+ url: base.url || '',
+ imageUrl: buildImageUrl(base),
+ isPrivate: base.isPrivate,
+ createdAt: base.createdAt,
+ summary: summarizeDefenses(defenses),
+ defenses,
+ };
+ });
+
+ const allVisibleDefenses = serializedBases.flatMap((base) => base.defenses);
+ const overallSummary = summarizeDefenses(allVisibleDefenses);
+
+ res.json({
+ profile: {
+ id: profileUser.id,
+ username: profileUser.username,
+ createdAt: profileUser.createdAt,
+ isOwner,
+ visibleBaseCount: serializedBases.length,
+ defenseCount: allVisibleDefenses.length,
+ summary: overallSummary,
+ },
+ bases: serializedBases,
+ });
+ } catch (error) {
+ console.error(error);
+ res.status(500).json({ error: 'Internal server error' });
+ }
+});
+
function summarizeDefenses(defenses) {
if (!defenses.length) {
return { count: 0, averageStars: 0, averagePercent: 0, averageTrophies: 0 };
@@ -459,6 +829,32 @@ function summarizeDefenses(defenses) {
};
}
+async function deleteImageFile(imagePath) {
+ if (!imagePath) return;
+ const filePath = path.isAbsolute(imagePath) ? imagePath : path.join(uploadDir, imagePath);
+ try {
+ await fsPromises.unlink(filePath);
+ } catch (error) {
+ if (error.code !== 'ENOENT') {
+ console.error(`Failed to delete image file ${filePath}`, error);
+ }
+ }
+}
+
+function parseBoolean(value) {
+ if (typeof value === 'boolean') {
+ return value;
+ }
+ if (typeof value === 'number') {
+ return value !== 0;
+ }
+ if (typeof value === 'string') {
+ const normalized = value.trim().toLowerCase();
+ return ['true', '1', 'yes', 'on'].includes(normalized);
+ }
+ return false;
+}
+
function sanitizeUser(user) {
return {
id: user.id,
diff --git a/frontend/app/page.tsx b/frontend/app/page.tsx
index ca1c34a..51647f5 100644
--- a/frontend/app/page.tsx
+++ b/frontend/app/page.tsx
@@ -32,8 +32,17 @@ const API = {
bases: `${API_BASE}/bases`,
addDefense: (baseId: string) => `${API_BASE}/bases/${baseId}/defenses`,
defenses: `${API_BASE}/defenses`,
+ deleteCategory: (categoryId: string) => `${API_BASE}/army-categories/${categoryId}`,
+ updateBase: (baseId: string) => `${API_BASE}/bases/${baseId}`,
+ deleteBase: (baseId: string) => `${API_BASE}/bases/${baseId}`,
+ updateDefense: (defenseId: string) => `${API_BASE}/defenses/${defenseId}`,
+ deleteDefense: (defenseId: string) => `${API_BASE}/defenses/${defenseId}`,
+ profiles: `${API_BASE}/profiles`,
+ profileDetail: (username: string) => `${API_BASE}/profiles/${encodeURIComponent(username)}`,
};
+const PROFILE_DEFENSE_PREVIEW_LIMIT = 5;
+
type User = {
id: string;
username: string;
@@ -52,6 +61,7 @@ type BaseItem = {
description: string;
url: string;
imageUrl: string;
+ isPrivate: boolean;
createdAt: string;
};
@@ -67,6 +77,49 @@ type DefenseItem = {
categoryName?: string;
};
+type ProfileSummaryItem = {
+ id: string;
+ username: string;
+ createdAt: string;
+ publicBaseCount: number;
+ publicDefenseCount: number;
+};
+
+type ProfileDefense = {
+ id: string;
+ stars: number;
+ percent: number;
+ trophies: number;
+ createdAt: string;
+ armyCategoryId: string;
+ armyCategoryName: string;
+};
+
+type ProfileBase = {
+ id: string;
+ title: string;
+ description: string;
+ url: string;
+ imageUrl: string;
+ isPrivate: boolean;
+ createdAt: string;
+ summary: Summary;
+ defenses: ProfileDefense[];
+};
+
+type ProfileDetail = {
+ profile: {
+ id: string;
+ username: string;
+ createdAt: string;
+ isOwner: boolean;
+ visibleBaseCount: number;
+ defenseCount: number;
+ summary: Summary;
+ };
+ bases: ProfileBase[];
+};
+
type Summary = {
count: number;
averageStars: number;
@@ -144,6 +197,14 @@ export default function Page() {
const [selectedCategoryId, setSelectedCategoryId] = useState No public attacks yet. Private bases stay hidden from other players. Newest entries appear on top.Base Averages
{summaries && summaries.bases.length ? (
- summaries.bases.map((base) => (
-
Search Profiles
+
+ Results
+
+ {profileResults.length ? (
+ profileResults.map((profile) => (
+
+ Profile: {profileDetail.profile.username}
+
+
+ {profileDetail.bases.length ? (
+ profileDetail.bases.map((base) => (
+
+ {!profileDetail.profile.isOwner ? (
+
+ {base.defenses.slice(0, PROFILE_DEFENSE_PREVIEW_LIMIT).map((defense) => (
+
+ ) : (
+ Defense Log
Showing the latest 10 entries.
+ ) : null} +{baseDetailMeta?.description || 'No description yet.'}