The bell is a shared pile: every active HR person sees every open note, regardless of who wrote it. That was agreed and it stays the default — this narrows it, it never widens it. You can now untick colleagues whose notes you do not want to see. What gets stored is the *exceptions*, not the selection. The difference shows the day someone new joins HR: had the selection been stored, she would be invisible to everyone until each person ticked her, and nobody would notice her follow-ups piling up. This way she is visible from day one and hiding her is a deliberate act. Same reasoning that made notes a shared inbox in the first place — the silent gap is worse than a row too many. Own notes always come through: `note_mutes` rejects a self-reference, and the predicate says so again rather than depending on a check constraint staying put. Notes with no author come through too — hiding one because nobody knows who wrote it is exactly the loss this list exists to prevent. The rule lives in lib/notes.ts as one SQL expression because two places need it: the bell in the header and the "Anstehend" card on the dashboard. Two copies drift, and then the card counts something the bell does not show. No SQL function and no audit row, unlike anything that touches employee data — this is a personal display preference, and an audit trail recording every tick would make finding real changes harder. Same pattern as saved reports and hire drafts, and the owner policy on note_mutes means a row for someone else cannot be written even with invented values. The checkbox flips immediately and flips back if saving fails; the list gets clicked through several at a time and a round trip per tick feels like hesitation. Verified: 19 tests, five mutation-checked (or→and, dropping the own-notes clause, inverting `not exists`, inverting the default, and losing the email fallback each turn them red). Typecheck, lint, schema drift, 477 tests and the build are clean. Not seen in a browser: login goes through the company account and the database is unreachable — the migration is reviewed but has not been run. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
62 lines
2.4 KiB
TypeScript
62 lines
2.4 KiB
TypeScript
"use server";
|
|
|
|
import { revalidatePath } from "next/cache";
|
|
import { requireUserId } from "@/lib/auth/session";
|
|
import { withUser } from "@/lib/db";
|
|
import type { ActionResult } from "@/lib/db/rpc";
|
|
|
|
/**
|
|
* Notizen einer Kollegin oder eines Kollegen ein- oder ausblenden.
|
|
*
|
|
* Kein Aufruf einer SQL-Funktion und kein Protokolleintrag, anders als bei
|
|
* allem, was Personaldaten ändert: das hier ist eine persönliche
|
|
* Anzeigeeinstellung. Ein Prüfprotokoll, das jeden Haken mitschreibt, machte
|
|
* die Suche nach echten Änderungen mühsamer, ohne etwas nachzuweisen.
|
|
* Dasselbe Muster wie bei gespeicherten Auswertungen und Entwürfen
|
|
* (actions/reports.ts, actions/hireDrafts.ts).
|
|
*
|
|
* Abgesichert ist es trotzdem: die Regel `note_mutes_owner` lässt nur Zeilen
|
|
* zu, deren `user_id` die angemeldete Person ist. Eine fremde Einstellung
|
|
* liesse sich auch mit erfundenen Werten nicht schreiben.
|
|
*/
|
|
export async function setNotizSichtbarkeit(payload: {
|
|
kollegeId: string;
|
|
sichtbar: boolean;
|
|
}): Promise<ActionResult> {
|
|
const userId = await requireUserId();
|
|
|
|
// Die eigenen Notizen bleiben immer sichtbar. Die Prüfbedingung der
|
|
// Tabelle weist das ohnehin ab; hier kommt die Meldung heraus, die jemand
|
|
// lesen kann, statt einer Verletzungsmeldung aus der Datenbank.
|
|
if (payload.kollegeId === userId) {
|
|
return { success: false, error: "Die eigenen Notizen lassen sich nicht ausblenden." };
|
|
}
|
|
|
|
try {
|
|
await withUser(userId, async (tx) => {
|
|
if (payload.sichtbar) {
|
|
await tx
|
|
.deleteFrom("note_mutes")
|
|
.where("user_id", "=", userId)
|
|
.where("muted_user_id", "=", payload.kollegeId)
|
|
.execute();
|
|
} else {
|
|
// `on conflict do nothing`: zweimal dasselbe Ausblenden ist kein
|
|
// Fehler, sondern derselbe Wunsch — etwa wenn zwei Reiter offen sind.
|
|
await tx
|
|
.insertInto("note_mutes")
|
|
.values({ user_id: userId, muted_user_id: payload.kollegeId })
|
|
.onConflict((oc) => oc.columns(["user_id", "muted_user_id"]).doNothing())
|
|
.execute();
|
|
}
|
|
});
|
|
} catch (err) {
|
|
return { success: false, error: err instanceof Error ? err.message : "Unbekannter Fehler." };
|
|
}
|
|
|
|
// Die Glocke steckt in der Hülle jeder Seite, die Karte „Anstehend" auf der
|
|
// Übersicht. Beide zeigen dieselbe Menge und müssen gemeinsam nachziehen.
|
|
revalidatePath("/", "layout");
|
|
return { success: true };
|
|
}
|