From e7a1743dc7a3660115aeb67714c37d2c2e7581e1 Mon Sep 17 00:00:00 2001
From: alex <alex@alexloehr.net>
Date: Wed, 04 Jun 2025 08:35:57 +0000
Subject: [PATCH] use api everywhere

---
 app.js |  133 +++++++++++++++++++++++++++++++++++++++++++-
 1 files changed, 130 insertions(+), 3 deletions(-)

diff --git a/app.js b/app.js
index e0d7ec2..c563cc2 100644
--- a/app.js
+++ b/app.js
@@ -1,11 +1,33 @@
+const path = require("path")
 const fastify = require('fastify')({
    logger: true
 })
+const _ = require("lodash")
 const db = require("./lib/db")
+
+const settings = require("./settings")
+const fs = require("node:fs")
 
 /////////////////////////////////////////////////////////////////////////
 
+// AUTH
+fastify.addHook("onRequest", async (req, res) => {
+   console.log(req.url)
+   const token = req.query.token
+   console.log(req.url)
+   if (token !== settings.authtoken && !req.url.startsWith("/ui/")) {
+      console.error("# AUTH ERROR #", token)
+      await promiseDelay(500) // delay response to avoid denial of service attacks
+      res.code(403)
+      return res.send({status: "error", error: "access denied"})
+   }
+   else {
+      console.log("NO AUTH FOR ",req.url)
+   }
+})
+
 fastify
+   /////// USER ////////////////////////////////////////////////////////////////
    .get('/api/users', async function (req, res) {
       const {offset, limit} = req.query
       const users = await db.getUsers(offset, limit)
@@ -27,22 +49,127 @@
    })
    .get("/api/user/userid/:userid", async function (req, res) {
       const {userid} = req.params
+      if(!userid || isNaN(Number(userid))) {
+         return res.code(500).send({status: "error", msg: "userid error"})
+      }
       const user = await db.getUserByUserId(userid)
-      if (user.length) {
-         return res.send(user[0])
+      if (user) {
+         return res.send(user)
       }
       else {
          return res.code(404).send({status: "error", msg: "not found"})
       }
    })
 
+   /////// ref_id / obj_id  ////////////////////////////////////////////////////////////////
+
+   .get("/api/ref_id/:ref_id", async function (req, res) {
+      const {ref_id} = req.params
+      const data = await db.getObjIdFromRefId(ref_id)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+   .get("/api/obj_id/:obj_id", async function (req, res) {
+      const {obj_id} = req.params
+      let data = await db.getRefIdFromObjId(obj_id)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+
+   /////// Kurs ////////////////////////////////////////////////////////////////
+   .get("/api/kurs", async function (req, res) {
+      let data = await db.getKurse()
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+   .get("/api/kurs/:refId", async function (req, res) {
+      const {refId} = req.params
+      let data = await db.getKurs(refId)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+   .get("/api/kurs/items/:refId", async function (req, res) {
+      const {refId} = req.params
+      let data = await db.getKursItems(refId)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+   .get("/api/kurs/teilnehmer/:refId", async function (req, res) {
+      const {refId} = req.params
+      let data = await db.getKursTeilnehmer(refId)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+   .get("/api/kurs/teilnehmer/:refId/count", async function (req, res) {
+      const {refId} = req.params
+      let data = await db.getKursTeilnehmerCount(refId)
+      if (data) {
+         return res.send(data)
+      }
+      else {
+         return res.code(404).send({status: "error", msg: "not found"})
+      }
+   })
+
+fastify.register(require('@fastify/static'), {
+   root: path.join(__dirname, 'vue/dist'),
+   prefix: '/ui/', // optional: default '/'
+
+   // constraints: { host: 'example.com' } // optional: default {}
+})
+
+
+// fastify.get('*', function (req, reply) {
+//    console.log("!!!!!!!!! send index")
+//    // index.html should never be cached
+//    reply.sendFile('dist/index.html', {maxAge: 0, immutable: false})
+// })
+
+const indexFile = fs.readFileSync(path.join(__dirname, "vue/dist", 'index.html'), 'utf8')
+fastify.setNotFoundHandler(function (req, res) {
+   console.log("!!!")
+   // res.sendFile("vue/dist/index.html")
+   res.type("text/html").send(indexFile)
+})
+
 
 /////////////////////////////////////////////////////////////////////////
 
-fastify.listen({port: 4101}, function (err, address) {
+fastify.listen({port: settings.port}, function (err, address) {
+   console.log("📡 -=> Listening on", address)
    if (err) {
       fastify.log.error(err)
       process.exit(1)
    }
    // Server is now listening on ${address}
 })
+
+/////////////////////////////////////////////////////////////////////////
+
+async function promiseDelay (ms) {
+   return new Promise(resolve => setTimeout(resolve, ms))
+}

--
Gitblit v1.8.0