renaming pw to vorgangPIN, case to vorgang, password to vorgangToken

This commit is contained in:
2025-07-25 14:21:23 +02:00
parent 52e9eba7ed
commit 08d83c9ed4
26 changed files with 2052 additions and 219 deletions

View File

@@ -1,11 +1,10 @@
import { getListOfVorgänge, getVorgaenge } from '$lib/server/vorgangService';
import { getVorgaenge } from '$lib/server/vorgangService';
import type { PageServerLoad } from '../../(token-based)/view/$types';
export const load: PageServerLoad = async () => {
// const caseList = await getListOfVorgänge();
const caseList = getVorgaenge();
const vorgangList = getVorgaenge();
return {
caseList
vorgangList
};
};

View File

@@ -5,7 +5,7 @@
export let data: PageData;
const caseList = data.caseList;
const vorgangList = data.vorgangList;
async function delete_item(ev: Event) {
let delete_item = window.confirm('Bist du sicher?');
@@ -44,20 +44,20 @@
</div>
<div class="mx-auto flex justify-center max-w-7xl h-full">
<ul role="list" class="divide-y divide-gray-100">
{#each caseList as item}
{#each vorgangList as vorgangItem}
<li>
<a href="/list/{item.token}?pw={item.pw}" class="flex justify-between gap-x-6 py-5">
<a href="/list/{vorgangItem.token}?pin={vorgangItem.vorgangPIN}" class="flex justify-between gap-x-6 py-5">
<div class="flex gap-x-4">
<!-- Ordner -->
<Folder />
<div class="min-w-0 flex-auto">
<span class="text-sm font-semibold leading-6 text-gray-900">{item.name}</span>
<span class="text-sm font-semibold leading-6 text-gray-900">{vorgangItem.name}</span>
<!-- Delete button -->
<button
style="padding: 2px"
id="del__{item.token}"
id="del__{vorgangItem.token}"
on:click|preventDefault={delete_item}
aria-label="Vorgang {item.name} löschen"
aria-label="Vorgang {vorgangItem.name} löschen"
>
<Trash />
</button>

View File

@@ -1,34 +1,34 @@
import { client } from '$lib/minio';
import { fail } from '@sveltejs/kit';
import caseNumberOccupied from '$lib/helper/caseNumberOccupied';
import vorgangNumberOccupied from '$lib/helper/vorgangNumberOccupied.js';
/** @type {import('./$types').Actions} */
export const actions = {
default: async ({ request }: {request: Request}) => {
const data = await request.formData();
const caseNumber = data.get('caseNumber');
const vorgangNumber = data.get('vorgangNumber');
const description = data.get('description');
if (!caseNumber) {
if (!vorgangNumber) {
return fail(400, {
caseNumber,
vorgangNumber,
description,
error: { caseNumber: 'Es muss eine Vorgangsnummer vorhanden sein.' }
error: { vorgangNumber: 'Es muss eine Vorgangsnummer vorhanden sein.' }
});
}
if (await caseNumberOccupied(`${caseNumber}`)) {
if (await vorgangNumberOccupied(`${vorgangNumber}`)) {
return fail(400, {
caseNumber,
vorgangNumber,
description,
error: { caseNumber: 'Die Vorgangsnummer wurde im System bereits angelegt.' }
error: { vorgangNumber: 'Die Vorgangsnummer wurde im System bereits angelegt.' }
});
}
const config = `${JSON.stringify({ caseNumber, description, version: 1 })}\n`;
const config = `${JSON.stringify({ vorgangNumber, description, version: 1 })}\n`;
await client.putObject('tatort', `${caseNumber}/config.json`, config, undefined, {
await client.putObject('tatort', `${vorgangNumber}/config.json`, config, undefined, {
'Content-Type': 'application/json'
});

View File

@@ -27,9 +27,9 @@
<div class="mt-10 grid grid-cols-1 gap-x-6 gap-y-8">
<div>
<label for="caseNumber" class="block text-sm font-medium leading-6 text-gray-900"
<label for="vorgangNumber" class="block text-sm font-medium leading-6 text-gray-900"
><span class="flex"
>{#if form?.error?.caseNumber}
>{#if form?.error?.vorgangNumber}
<span class="inline-block mr-1"><Exclamation /></span>
{/if} Vorgangs-Nr.</span
></label
@@ -39,16 +39,16 @@
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
value={form?.caseNumber ?? ''}
value={form?.vorgangNumber ?? ''}
type="text"
name="caseNumber"
id="caseNumber"
name="vorgangNumber"
id="vorgangNumber"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 text-sm leading-6"
/>
</div>
</div>
{#if form?.error?.caseNumber}
<p class="block text-sm leading-6 text-red-900 mt-2">{form.error.caseNumber}</p>
{#if form?.error?.vorgangNumber}
<p class="block text-sm leading-6 text-red-900 mt-2">{form.error.vorgangNumber}</p>
{/if}
</div>
@@ -74,8 +74,8 @@
{/if}
</div>
<label for="code">
<span >Zugangscode (optional) </span>
<label for="vorgang-token">
<span >Zugangstoken (optional) </span>
</label>
<div class="mt-2">
@@ -83,7 +83,7 @@
>
<input
type="text"
id="code"
id="vorgang-token"
/>
</div>
</div>

View File

@@ -17,36 +17,31 @@ const isRequiredFieldValid = (value: unknown) => {
export const actions = {
url: async ({ request }: { request: Request }) => {
const data = await request.formData();
const caseName = data.get('vorgang');
const vorgangName = data.get('vorgang');
const crimeName = data.get('name');
const type = data.get('type');
const password = data.get('password');
const vorgangPIN = data.get('vorgangPIN');
const fileName = data.get('fileName');
// store case in database
// skip if Vorgang exists and token not changed
const vorgangExists = vorgangNameExists(caseName);
let token;
const vorgangExists = vorgangNameExists(vorgangName);
let vorgangToken;
if (!vorgangExists) {
token = uuidv4();
let insertSQLStatement = `INSERT INTO cases (token, name, pw) VALUES (?, ?, ?)`;
vorgangToken = uuidv4();
const insertSQLStatement = `INSERT INTO cases (token, name, pin) VALUES (?, ?, ?)`;
const statement = db.prepare(insertSQLStatement);
statement.run(token, caseName, password);
statement.run(vorgangToken, vorgangName, vorgangPIN);
} else {
// vorgang exists
// check if PW was changed, and update DB if it was
const vorg = getVorgangByName(caseName);
token = vorg.token;
if (vorg.pw != password) {
let updateSQLStmt = `UPDATE cases SET pw = ? WHERE name = ?`;
const vorgang = getVorgangByName(vorgangName);
vorgangToken = vorgang.token;
if (vorgang && vorgang.pin != vorgangPIN) {
const updateSQLStmt = `UPDATE cases SET pin = ? WHERE name = ?`;
const statement = db.prepare(updateSQLStmt);
statement.run(password, vorg);
statement.run(vorgangPIN, vorgang);
}
}
let objectName = `${token}/${crimeName}`;
let objectName = `${vorgangToken}/${crimeName}`;
switch (type) {
case 'image/png':
if (!objectName.endsWith('.png')) objectName += '.png';
@@ -65,24 +60,27 @@ export const actions = {
const data = Object.fromEntries(requestData);
const vorgang = data.vorgang;
const name = data.name;
const password = data.password;
const vorgangPIN = data.vorgangPIN;
let success = true;
const err = {};
if (isRequiredFieldValid(vorgang)) err.vorgang = null;
else {
if (isRequiredFieldValid(vorgang)) {
err.vorgang = null;
} else {
err.vorgang = 'Das Feld Vorgang darf nicht leer bleiben.';
success = false;
}
if (isRequiredFieldValid(name)) err.name = null;
else {
if (isRequiredFieldValid(name)) {
err.name = null;
} else {
err.name = 'Das Feld Name darf nicht leer bleiben.';
success = false;
}
if (isRequiredFieldValid(password)) err.password = null;
else {
err.password = 'Das Feld Zugangspasswort darf nicht leer bleiben.';
if (isRequiredFieldValid(vorgangPIN)) {
err.vorgangPIN = null;
} else {
err.vorgangPIN = 'Das Feld Zugangspasswort darf nicht leer bleiben.';
success = false;
}

View File

@@ -15,20 +15,20 @@
let open = false;
let inProgress = false;
let vorgang = '';
const code_len = 8;
const PINLength = 8;
function generatePassword() {
function generatePIN() {
return Math.random()
.toString(36)
.slice(2, 2 + code_len);
.slice(2, 2 + PINLength);
}
let zugangspasswort = ''
let zugangspasswordOld = ''
$: zugangspasswordOld = generatePassword();
$: zugangspasswort = zugangspasswordOld
let vorgangPIN = ''
let vorgangPINOld = ''
$: vorgangPINOld = generatePIN();
$: vorgangPIN = vorgangPINOld
let caseExisting = undefined;
$: caseExisting = false;
let vorgangExists = undefined;
$: vorgangExists = false;
let name = '';
let etag: string | null = null;
@@ -42,7 +42,7 @@
let data = new FormData();
data.append('vorgang', vorgang);
data.append('name', name);
data.append('password', zugangspasswort);
data.append('vorgangPIN', vorgangPIN);
const response = await fetch('?/validate', { method: 'POST', body: data });
/** @type {import('@sveltejs/kit').ActionResult} */
const result = deserialize(await response.text());
@@ -71,7 +71,7 @@
let data = new FormData();
data.append('vorgang', vorgang);
data.append('name', name);
data.append('password', zugangspasswort);
data.append('vorgangPIN', vorgangPIN);
if (files?.length === 1) {
data.append('type', files[0].type);
data.append('fileName', files[0].name);
@@ -151,37 +151,37 @@
}
// `/(angemeldet)/view` return true or false
async function caseExists(caseName: string) {
async function checkVorgangExists(vorgangName: string) {
if (caseName == '') {
zugangspasswort = zugangspasswordOld;
if (vorgangName == '') {
vorgangPIN = vorgangPINOld;
return;
}
let url = `/api/list/${caseName}`
let url = `/api/list/${vorgangName}`
const response = await fetch(url, { method: 'HEAD'});
const status = response.status;
if (status == 200) {
caseExisting = true;
const passwort = await getPassword(caseName);
zugangspasswort = passwort;
vorgangExists = true;
const token = await getVorgangPIN(vorgangName);
vorgangPIN = token;
return true
} else {
caseExisting = false;
zugangspasswort = zugangspasswordOld;
vorgangExists = false;
vorgangPIN = vorgangPINOld;
return false
}
}
async function getPassword(caseName: string) {
async function getVorgangPIN(vorgangName: string) {
if (caseName == '') return;
if (vorgangName == '') return;
let url = `/api/list/${caseName}/casepw`;
let url = `/api/list/${vorgangName}/vorgangPIN`;
const response = await fetch(url);
if (response.status == 200) {
@@ -225,14 +225,14 @@
id="vorgang"
autocomplete={vorgang}
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
on:input={() => caseExists(vorgang)}
on:input={() => checkVorgangExists(vorgang)}
/>
</div>
</div>
{#if formErrors?.vorgang}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.vorgang}</p>
{/if}
{#if caseExisting && vorgang.length > 0}
{#if vorgangExists && vorgang.length > 0}
<span>Datei wird zum existierenden Vorgang hinzugefügt.</span>
{:else if vorgang.length > 0}
<span>Neuer Vorgang wird angelegt.</span>
@@ -267,11 +267,11 @@
</div>
<div>
<label for="zugangscode" class="block text-sm font-medium leading-6 text-gray-900"
<label for="vorgang-pin" class="block text-sm font-medium leading-6 text-gray-900"
><span class="flex"
>{#if formErrors?.zugangscode}
>{#if formErrors?.vorgangPIN}
<span class="inline-block mr-1"><Exclamation /></span>
{/if} Zugangscode</span
{/if} Zugangs-PIN</span
></label
>
<div class="mt-2">
@@ -279,11 +279,11 @@
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
bind:value={zugangspasswort}
bind:value={vorgangPIN}
type="text"
name="zugangscode"
id="zugangscode"
on:input="{ (ev) => { zugangspasswordOld = ev.target.value }}"
name="vorgang-pin"
id="vorgang-pin"
on:input="{ (ev) => { vorgangPINOld = ev.target.value }}"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/>
@@ -291,13 +291,13 @@
<button
class="rounded-md bg-blue-500 px-3 py-2 text-sm font-semibold text-white shadow-sm hover:bg-indigo-500 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-indigo-600"
on:click="{() => {
zugangspasswort = zugangspasswordOld = generatePassword(); }}"
vorgangPIN = vorgangPINOld = generatePIN(); }}"
type="button">
Generiere Zugangscode
Generiere Zugangs-PIN
</button>
</div>
{#if formErrors?.code}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.code}</p>
{#if formErrors?.vorgangPIN}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.vorgangPIN}</p>
{/if}
</div>

View File

@@ -1,7 +1,5 @@
import {
checkIfVorgangExists,
hasValidToken,
passwordValid,
vorgangPINValidation,
vorgangExists
} from '$lib/server/vorgangService';
import { redirect } from '@sveltejs/kit';
@@ -14,11 +12,11 @@ export const load: PageServerLoad = async ({ params, url, locals }) => {
};
}
const caseToken = params.vorgang;
const casePassword = url.searchParams.get('pw');
const vorgangToken = params.vorgang;
const vorgangPIN = url.searchParams.get('pin');
const isVorgangValid = vorgangExists(caseToken);
const isPasswordValid = passwordValid(caseToken, casePassword);
const isVorgangValid = vorgangExists(vorgangToken);
const isVorgangPINValid = vorgangPINValidation(vorgangToken, vorgangPIN);
if (!isVorgangValid || !isPasswordValid) throw redirect(303, `/anmeldung?vorgang=${caseToken}`);
if (!isVorgangValid || !isVorgangPINValid) throw redirect(303, `/anmeldung?vorgang=${vorgangToken}`);
};

View File

@@ -2,15 +2,15 @@ import { getVorgangByToken, getCrimesListByToken } from '$lib/server/vorgangServ
import type { PageServerLoad } from './$types';
export const load: PageServerLoad = async ({ params, url }) => {
const caseToken = params.vorgang;
const casePassword = url.searchParams.get('pw');
const vorgangToken = params.vorgang;
const vorgangPIN = url.searchParams.get('vorgangPIN');
const crimesList = await getCrimesListByToken(caseToken);
const vorgang = getVorgangByToken(caseToken);
const crimesList = await getCrimesListByToken(vorgangToken);
const vorgang = getVorgangByToken(vorgangToken);
return {
crimesList,
casePassword,
vorgangPIN,
vorgang
};
};

View File

@@ -28,7 +28,7 @@
const vorgang = data.vorgang;
const crimesList: ListItem[] = data.crimesList;
const password: string = data.casePassword;
const vorgangPIN: string = data.vorgangPIN;
let open = false;
$: open;
@@ -143,7 +143,7 @@
<div class="flex flex-col items-center justify-center w-full">
<h1 class="text-xl">Vorgang {vorgang.name}</h1>
{#if data?.user?.admin}
Zugangspasswort: {vorgang.pw}
Zugangs-PIN: {vorgang.pin}
<Button on:click={() => setClipboard($page.url.toString().split('?')[0])}>Copy Link</Button>
{/if}
</div>
@@ -152,7 +152,7 @@
{#each crimesList as item, i}
<li>
<a
href="/view/{$page.params.vorgang}/{item.name}?pw={password}"
href="/view/{$page.params.vorgang}/{item.name}?pin={vorgangPIN}"
class=" flex justify-between gap-x-6 py-5"
aria-label="zum 3D-modell"
>

View File

@@ -3,9 +3,9 @@ import { redirect } from '@sveltejs/kit';
export const actions = {
default: async ({request}: {request: Request}) => {
const data = await request.formData();
const caseId = data.get('case-id');
const caseToken = data.get('case-token');
const vorgangId = data.get('vorgang-id');
const vorgangToken = data.get('vorgang-token');
if( caseId && caseToken) throw redirect(303, `/list/${caseId}?token=${caseToken}`);
if( vorgangId && vorgangToken) throw redirect(303, `/list/${vorgangId}?token=${vorgangToken}`);
}
}

View File

@@ -16,19 +16,19 @@
</p>
<form method="POST">
<BaseInputField
id="case-id"
name="case-id"
id="vorgang-id"
name="vorgang-id"
label="Vorgangskennung"
type="text"
value={form?.caseId}
value={form?.vorgangId}
/>
<div class="mt-5">
<BaseInputField
id="case-token"
name="case-token"
label="Zugangscode"
id="vorgang-token"
name="vorgang-token"
label="Zugangstoken"
type="text"
value={form?.token}
value={form?.vorgangToken}
error={form?.error?.message}
/>
</div>

View File

@@ -6,13 +6,11 @@ export const actions = {
logout: (event) => logoutUser(event),
getVorgangByToken: async ({ request }) => {
const data = await request.formData();
const caseToken = data.get('case-token');
const casePassword = data.get('case-password');
const vorgangToken = data.get('vorgang-token');
const vorgangPIN = data.get('vorgang-pin');
console.log(`+++ ${caseToken} + ${casePassword}`);
if (!vorgangToken || !vorgangPIN) return;
if (!caseToken || !casePassword) return;
throw redirect(303, `/list/${caseToken}?pw=${casePassword}`);
throw redirect(303, `/list/${vorgangToken}?pin=${vorgangPIN}`);
}
} as const;

View File

@@ -29,19 +29,19 @@
<div class="mt-10">
<form action="?/getVorgangByToken" method="POST">
<BaseInputField
id="case-token"
name="case-token"
id="vorgang-token"
name="vorgang-token"
label="Vorgangskennung"
type="text"
value={vorgangToken}
/>
<div class="mt-5">
<BaseInputField
id="case-password"
name="case-password"
label="Zugangspasswort"
id="vorgang-pin"
name="vorgang-pin"
label="Zugangs-PIN"
type="text"
value={form?.password}
value={form?.vorgangPIN}
error={form?.error?.message}
/>
</div>

View File

@@ -1,9 +1,6 @@
import { client } from '$lib/minio';
import { db } from '$lib/server/dbService';
import {
deleteVorgangByToken,
getVorgangByToken,
getVorgangByName,
vorgangNameExists
} from '$lib/server/vorgangService';

View File

@@ -4,12 +4,12 @@ import { db } from '$lib/server/dbService';
export async function GET({ params }) {
const vorgangName = params.vorgang;
let getCodeSQLStatement = `SELECT pw FROM cases WHERE name = ?;`;
const row = db.prepare(getCodeSQLStatement).get(vorgangName);
let password = row.pw;
const getPINSQLStatement = `SELECT pin FROM cases WHERE name = ?;`;
const row = db.prepare(getPINSQLStatement).get(vorgangName);
const vorgangPIN = row.pin;
if (password) {
return new Response(password, { status: 200 });
if (vorgangPIN) {
return new Response(vorgangPIN, { status: 200 });
} else {
return new Response(null, { status: 404 });
}