Files
rr3-server/RR3CommunityServer/Pages/Purchases.cshtml.cs
Daniel Elliott e03c1d9856 Add admin panel authentication and login system
Features:
- Login page with username/email + password
- Registration page for new accounts
- Logout functionality
- Cookie-based authentication (30-day sessions)
- Auto-redirect to login for unauthorized access
- User dropdown in navbar with logout link

Security:
- All admin pages now require authentication
- [Authorize] attribute on all admin PageModels
- Redirect to /Login if not authenticated
- Auto-login after registration

UI:
- Beautiful gradient login/register pages
- Consistent styling with admin panel
- User info displayed in navbar
- Logout link in dropdown menu

Starting resources for new users:
- 100,000 Gold
- 500,000 Cash
- Level 1
- Full admin panel access

Ready for production deployment!
2026-02-19 15:06:08 -08:00

55 lines
1.5 KiB
C#

using Microsoft.AspNetCore.Mvc;
using Microsoft.AspNetCore.Mvc.RazorPages;
using Microsoft.AspNetCore.Authorization;
using Microsoft.EntityFrameworkCore;
using RR3CommunityServer.Data;
using static RR3CommunityServer.Data.RR3DbContext;
namespace RR3CommunityServer.Pages;
[Authorize]
public class PurchasesModel : PageModel
{
private readonly RR3DbContext _context;
public PurchasesModel(RR3DbContext context)
{
_context = context;
}
public List<Purchase> Purchases { get; set; } = new();
public decimal TotalValue { get; set; }
public string? SearchQuery { get; set; }
public async Task OnGetAsync(string? search)
{
SearchQuery = search;
var query = _context.Purchases.AsQueryable();
if (!string.IsNullOrEmpty(search))
{
query = query.Where(p => p.Sku.Contains(search) ||
(p.UserId != null && p.UserId.ToString()!.Contains(search)));
}
Purchases = await query
.OrderByDescending(p => p.PurchaseDate)
.ToListAsync();
TotalValue = Purchases.Sum(p => p.Price);
}
public async Task<IActionResult> OnPostDeleteAsync(int purchaseId)
{
var purchase = await _context.Purchases.FindAsync(purchaseId);
if (purchase != null)
{
_context.Purchases.Remove(purchase);
await _context.SaveChangesAsync();
}
return RedirectToPage();
}
}