35 Commits

Author SHA1 Message Date
542c12cc5f Merge pull request 'f034_sqlite_database' (#19) from f034_sqlite_database into development
Some checks failed
InnoHub Processor/tatort/pipeline/head There was a failure building this commit
Reviewed-on: #19
2025-07-24 14:34:38 +02:00
ee9d9fa8fc fix package-lock.json
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
2025-07-24 14:30:24 +02:00
addcc26a07 Merge branch 'development' into f034_sqlite_database
Some checks failed
InnoHub Processor/tatort/pipeline/head There was a failure building this commit
2025-07-23 12:55:20 +02:00
db1cc78f2c move ´code´ api endpoint to ´casepw´
Some checks failed
InnoHub Processor/tatort/pipeline/head There was a failure building this commit
2025-07-23 12:54:40 +02:00
e8170de947 rename .js to .ts and remove console.logs statements 2025-07-23 09:27:11 +02:00
26c05b4999 remove unused and deprecated crypto package 2025-07-22 12:27:50 +02:00
809c355849 provide init command for database
All checks were successful
InnoHub Processor/tatort/pipeline/pr-main This commit was not built
InnoHub Processor/tatort/pipeline/head This commit was not built
2025-07-21 11:39:13 +02:00
bd9275c378 refactoring part 3: delete function of vorgang uses caseToken 2025-07-17 08:23:13 +02:00
143bb128a5 refactoring part 2: mainly consolidation of token, ids and passwort 2025-07-17 08:09:17 +02:00
34d5034a71 refactoring part 1: camelcase naming, token vs pw naming 2025-07-16 09:39:02 +02:00
b8e5031669 document DB initialization script 2025-07-15 09:48:29 +02:00
51d3f19f3e delete functionality for Vorgang in DB 2025-07-15 09:06:45 +02:00
5070ac9f7a remove console.logs 2025-07-15 08:03:27 +02:00
873a382f69 refactor 'Datei zu Vorgang hinzufügen': Add model files to existing cases 2025-07-14 13:54:08 +02:00
fa59db7a88 make 'Vorgangsname' column unique 2025-07-14 13:25:19 +02:00
484acd3bcf refactoring: 'Datei zu Vorgang hinzufügen' an DB angepasst 2025-07-14 13:21:49 +02:00
cd5389666e fix import error from default to explicit import 2025-07-14 08:23:27 +02:00
a7eb81151f refactor DB access 2025-07-11 11:39:42 +02:00
8408d63f40 add copy button for sharing vorgang 2025-07-11 11:24:25 +02:00
f2bde76969 prefill homepage with token 2025-07-11 10:35:50 +02:00
83bcaca918 remove console.log 2025-07-11 10:25:42 +02:00
9ddec90214 rewrite vorgang exist and token validation check to use DB 2025-07-11 10:19:43 +02:00
f7245fac90 correctly display Vorgangsname in Vorgang page 2025-07-10 11:03:15 +02:00
564716e853 store tatort under case token name 2025-07-10 10:45:24 +02:00
ffa34b3b61 refactor getVorgaenge to return vorgaenge as objects 2025-07-10 08:40:36 +02:00
307894c980 listing of cases based on db 2025-07-10 08:31:45 +02:00
40599f4ffa adding new vorgang in database 2025-07-10 08:30:41 +02:00
8b1b3532fc refactor init-script and display tables with data 2025-07-10 08:29:07 +02:00
f6513c9ed8 add uuid-package for token generation 2025-07-10 08:28:01 +02:00
c034064d41 refactor db design 2025-07-09 12:20:16 +02:00
dc2d038b1b remove old, commented implementation of authenticate 2025-07-09 12:13:19 +02:00
0c6dbe30ab replace with 2025-07-09 12:07:34 +02:00
64aa1d404e Merge branch 'development' into f034_merge_dev 2025-07-09 08:12:02 +02:00
fa69fa9dcd include packages 2025-07-09 08:08:59 +02:00
8d92e94bd6 populate db with default user 2025-07-09 08:07:22 +02:00
21 changed files with 2382 additions and 866 deletions

View File

@@ -36,3 +36,24 @@ npm run build
You can preview the production build with `npm run preview`. You can preview the production build with `npm run preview`.
> To deploy your app, you may need to install an [adapter](https://svelte.dev/docs/kit/adapters) for your target environment. > To deploy your app, you may need to install an [adapter](https://svelte.dev/docs/kit/adapters) for your target environment.
## Initializing the SQLite DB
A database initialization script `init_db.js` in included in the `src/init` folder. It will create a users database (if not existing) and populate it with a default admin user. Additionally, an empty cases table will be created.
It can be run with `node init_db.js`
Database schema:
Users
- id
- name
- pw
Cases
- id
- token
- name
- pw

2747
package-lock.json generated

File diff suppressed because it is too large Load Diff

View File

@@ -13,7 +13,8 @@
"format": "prettier --write .", "format": "prettier --write .",
"lint": "prettier --check . && eslint .", "lint": "prettier --check . && eslint .",
"test:unit": "vitest", "test:unit": "vitest",
"test": "npm run test:unit -- --run && npm run test:e2e" "test": "npm run test:unit -- --run && npm run test:e2e",
"init_db": "npx vite-node src/init/init_db.ts"
}, },
"devDependencies": { "devDependencies": {
"@eslint/compat": "^1.2.9", "@eslint/compat": "^1.2.9",
@@ -44,9 +45,13 @@
"@sveltejs/adapter-node": "^5.2.12", "@sveltejs/adapter-node": "^5.2.12",
"@tailwindcss/forms": "^0.5.10", "@tailwindcss/forms": "^0.5.10",
"autoprefixer": "^10.4.21", "autoprefixer": "^10.4.21",
"better-sqlite3": "^12.2.0",
"jsonwebtoken": "^9.0.2", "jsonwebtoken": "^9.0.2",
"jssha": "^3.3.1",
"minio": "^8.0.5", "minio": "^8.0.5",
"postcss": "^8.5.4", "postcss": "^8.5.4",
"tailwindcss": "^3.4.17" "sqlite3": "^5.1.7",
"tailwindcss": "^3.4.17",
"uuid": "^11.1.0"
} }
} }

37
src/init/init_db.ts Normal file
View File

@@ -0,0 +1,37 @@
import Database from 'better-sqlite3';
import jsSHA from 'jssha';
const db = new Database('./src/lib/data/tatort.db');
let createSQLStmt = `CREATE TABLE IF NOT EXISTS users
(id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
pw TEXT NOT NULL)`;
db.exec(createSQLStmt);
// check if there are any users; if not add one default admin one
let password = 'pass-123';
let hashedPassword = new jsSHA('SHA-512', 'TEXT').update(password).getHash('HEX');
let checkInsertSQLStmt = `INSERT INTO users (name, pw) SELECT 'admin', '${hashedPassword}'
WHERE NOT EXISTS (SELECT * FROM users);`;
db.exec(checkInsertSQLStmt);
let usersSQLStmt = `SELECT * FROM USERS`;
let SQLStatement = db.prepare(usersSQLStmt);
// cases table
createSQLStmt = `CREATE TABLE IF NOT EXISTS cases
(id INTEGER PRIMARY KEY AUTOINCREMENT,
token TEXT NOT NULL UNIQUE,
name TEXT NOT NULL UNIQUE,
pw TEXT NOT NULL)`;
db.exec(createSQLStmt);
let casesSQLStmt = `SELECT * FROM cases`;
SQLStatement = db.prepare(casesSQLStmt);
db.close();

View File

@@ -1,4 +1,7 @@
import jwt from 'jsonwebtoken'; import jwt from 'jsonwebtoken';
import jsSHA from 'jssha';
import process from 'process';
import { db } from '$lib/server/dbService';
import config from '$lib/config'; import config from '$lib/config';
@@ -16,14 +19,18 @@ export function decryptToken(token: string) {
} }
export function authenticate(user, pass) { export function authenticate(user, pass) {
let userData = null; let JWTToken;
if (AUTH[user]) { // hash user password
const { password, ...data } = AUTH[user]; let hashedPW = new jsSHA('SHA-512', 'TEXT').update(pass).getHash('HEX');
if (password && password === pass) userData = data;
let getUserSQLStmt = 'SELECT name, pw FROM users WHERE name = ?';
const row = db.prepare(getUserSQLStmt).get(user);
let storedPW = row.pw;
if (hashedPW && hashedPW === storedPW) {
JWTToken = createToken({ id: user, admin: true });
} }
if (userData == null) return null; return JWTToken;
return createToken({ id: user, ...userData });
} }

BIN
src/lib/data/tatort.db Normal file

Binary file not shown.

View File

@@ -1,5 +1,5 @@
export default async function get_code(case_no) { export default async function get_code(case_no) {
let url = `/api/list/${case_no}/code`; let url = `/api/list/${case_no}/casepw`;
const response = await fetch(url); const response = await fetch(url);
if (response.status == 200) { if (response.status == 200) {

View File

@@ -0,0 +1,3 @@
import Database from 'better-sqlite3';
export const db = new Database('./src/lib/data/tatort.db');

View File

@@ -2,13 +2,15 @@ import { fail } from '@sveltejs/kit';
import { BUCKET, client, CONFIGFILENAME, TOKENFILENAME } from '$lib/minio'; import { BUCKET, client, CONFIGFILENAME, TOKENFILENAME } from '$lib/minio';
import { checkIfExactDirectoryExists, getContentOfTextObject } from './s3ClientService'; import { checkIfExactDirectoryExists, getContentOfTextObject } from './s3ClientService';
import { db } from './dbService';
/** /**
* Get Vorgang and corresponend list of tatorte * Get Vorgang and corresponend list of tatorte
* @param caseId * @param caseToken
* @returns * @returns
*/ */
export const getVorgangByCaseId = async (caseId: string) => { export const getCrimesListByToken = async (caseToken: string) => {
const prefix = `${caseId}/`; const prefix = `${caseToken}/`;
const stream = client.listObjectsV2(BUCKET, prefix, false, ''); const stream = client.listObjectsV2(BUCKET, prefix, false, '');
@@ -17,13 +19,51 @@ export const getVorgangByCaseId = async (caseId: string) => {
const splittedNameParts = chunk.name.split('/'); const splittedNameParts = chunk.name.split('/');
const prefix = splittedNameParts[0]; const prefix = splittedNameParts[0];
const name = splittedNameParts[1]; const name = splittedNameParts[1];
if (name === CONFIGFILENAME || name === TOKENFILENAME) continue; if (name === CONFIGFILENAME || name === TOKENFILENAME) continue;
list.push({ ...chunk, name: name, prefix: prefix, show_button: true }); list.push({ ...chunk, name: name, prefix: prefix, show_button: true });
} }
return list; return list;
}; };
/**
* Get Vorgang
* @param caseToken
* @returns caseObj with keys `token`, `name`, `pw` || undefined
*/
export const getVorgangByToken = function (caseToken: string) {
let getVorgangSQLStmt = `SELECT token, name, pw FROM cases WHERE token = ?`;
const statement = db.prepare(getVorgangSQLStmt);
const result = statement.get(caseToken);
return result;
};
/**
* Get Vorgang
* @param caseName
* @returns caseObj with keys `token`, `name`, `pw` || undefined
*/
export const getVorgangByName = function (caseName: string) {
let getVorgangByNameSQLStmt = `SELECT token, name, pw FROM cases WHERE name = ?`;
const statement = db.prepare(getVorgangByNameSQLStmt);
const result = statement.get(caseName);
return result;
};
/**
* Delete Vorgang
* @param caseToken
* @returns int: number of changes
*/
export const deleteVorgangByToken = function (caseToken: string) {
let deleteSQLStmt = 'DELETE FROM cases WHERE token = ?';
const statement = db.prepare(deleteSQLStmt);
const info = statement.run(caseToken);
return info.changes;
};
/** /**
* Fetches list of vorgänge from s3 bucket * Fetches list of vorgänge from s3 bucket
@@ -31,7 +71,7 @@ export const getVorgangByCaseId = async (caseId: string) => {
*/ */
export const getListOfVorgänge = async () => { export const getListOfVorgänge = async () => {
const stream = client.listObjectsV2(BUCKET, '', false, ''); const stream = client.listObjectsV2(BUCKET, '', false, '');
const list = []; const list = [];
for await (const chunk of stream) { for await (const chunk of stream) {
const objPath = `${chunk.prefix}${TOKENFILENAME}`; const objPath = `${chunk.prefix}${TOKENFILENAME}`;
@@ -44,6 +84,23 @@ export const getListOfVorgänge = async () => {
return list; return list;
}; };
/**
* Fetches list of vorgänge from database
* @returns list with of available cases
*/
export const getVorgaenge = function () {
let getVorgaengeSQLStmt = `SELECT token, name, pw from cases`;
const statement = db.prepare(getVorgaengeSQLStmt);
const result = statement.all();
const vorgaenge_list = [];
for (const r of result) {
const vorg = { token: r.token, name: r.name, pw: r.pw };
vorgaenge_list.push(vorg);
}
return vorgaenge_list;
};
/** /**
* Checks if Vorgang exists * Checks if Vorgang exists
* @param request * @param request
@@ -69,6 +126,32 @@ export const checkIfVorgangExists = async (caseId: string | null) => {
return true; return true;
}; };
export const vorgangExists = function (caseToken: string | null) {
if (!caseToken) {
return fail(400, {
success: false,
caseId: caseToken,
error: { message: 'Die Vorgangsnummer darf nicht leer sein.' }
});
}
let vorgaenge = getVorgaenge();
const vorgaenge_tokens = vorgaenge.map((vorg) => vorg.token);
const found = vorgaenge_tokens.indexOf(caseToken) != -1;
return found;
};
export const vorgangNameExists = function (caseName: string) {
let vorgaenge = getVorgaenge();
const vorgaengeNames = vorgaenge.map((vorg) => vorg.name);
const found = vorgaengeNames.indexOf(caseName) != -1;
return found;
};
export const hasValidToken = async (caseId: string, caseToken: string) => { export const hasValidToken = async (caseId: string, caseToken: string) => {
const objPath = `${caseId}/${TOKENFILENAME}`; const objPath = `${caseId}/${TOKENFILENAME}`;
@@ -90,3 +173,17 @@ export const hasValidToken = async (caseId: string, caseToken: string) => {
} }
} }
}; };
export const passwordValid = function (caseToken, casePassword) {
if (!casePassword) {
return false;
}
const vorg = getVorgangByToken(caseToken);
if (!vorg || vorg.pw !== casePassword) {
return false;
}
return true;
};

View File

@@ -1,10 +1,11 @@
import { getListOfVorgänge } from '$lib/server/vorgangService'; import { getListOfVorgänge, getVorgaenge } from '$lib/server/vorgangService';
import type { PageServerLoad } from '../../(token-based)/view/$types'; import type { PageServerLoad } from '../../(token-based)/view/$types';
export const load: PageServerLoad = async () => { export const load: PageServerLoad = async () => {
const caseList = await getListOfVorgänge(); // const caseList = await getListOfVorgänge();
const caseList = getVorgaenge();
return { return {
caseList caseList
}; };
}; };

View File

@@ -46,7 +46,7 @@
<ul role="list" class="divide-y divide-gray-100"> <ul role="list" class="divide-y divide-gray-100">
{#each caseList as item} {#each caseList as item}
<li> <li>
<a href="/list/{item.name}?token={item.token}" class="flex justify-between gap-x-6 py-5"> <a href="/list/{item.token}?pw={item.pw}" class="flex justify-between gap-x-6 py-5">
<div class="flex gap-x-4"> <div class="flex gap-x-4">
<!-- Ordner --> <!-- Ordner -->
<Folder /> <Folder />
@@ -55,7 +55,7 @@
<!-- Delete button --> <!-- Delete button -->
<button <button
style="padding: 2px" style="padding: 2px"
id="del__{item.name}" id="del__{item.token}"
on:click|preventDefault={delete_item} on:click|preventDefault={delete_item}
aria-label="Vorgang {item.name} löschen" aria-label="Vorgang {item.name} löschen"
> >

View File

@@ -1,7 +1,10 @@
import { Buffer } from 'buffer';
import { Readable } from 'stream'; import { Readable } from 'stream';
import { client } from '$lib/minio'; import { client } from '$lib/minio';
import { fail } from '@sveltejs/kit'; import { fail } from '@sveltejs/kit';
import { v4 as uuidv4 } from 'uuid';
import { db } from '$lib/server/dbService';
import { getVorgangByName, vorgangNameExists } from '$lib/server/vorgangService';
const isRequiredFieldValid = (value: unknown) => { const isRequiredFieldValid = (value: unknown) => {
if (value == null) return false; if (value == null) return false;
@@ -9,47 +12,62 @@ const isRequiredFieldValid = (value: unknown) => {
if (typeof value === 'string' || value instanceof String) return value.trim() !== ''; if (typeof value === 'string' || value instanceof String) return value.trim() !== '';
return true; return true;
} };
export const actions = { export const actions = {
url: async ({ request }: {request: Request}) => { url: async ({ request }: { request: Request }) => {
const data = await request.formData(); const data = await request.formData();
const vorgang = data.get('vorgang'); const caseName = data.get('vorgang');
const name = data.get('name'); const crimeName = data.get('name');
const type = data.get('type'); const type = data.get('type');
const code = data.get('zugangscode'); const password = data.get('password');
const fileName = data.get('fileName'); const fileName = data.get('fileName');
let objectName = `${vorgang}/${name}`; // store case in database
// skip if Vorgang exists and token not changed
const vorgangExists = vorgangNameExists(caseName);
let token;
if (!vorgangExists) {
token = uuidv4();
let insertSQLStatement = `INSERT INTO cases (token, name, pw) VALUES (?, ?, ?)`;
const statement = db.prepare(insertSQLStatement);
statement.run(token, caseName, password);
} else {
// vorgang exists
// check if PW was changed, and update DB if it was
const vorg = getVorgangByName(caseName);
token = vorg.token;
if (vorg.pw != password) {
let updateSQLStmt = `UPDATE cases SET pw = ? WHERE name = ?`;
const statement = db.prepare(updateSQLStmt);
statement.run(password, vorg);
}
}
let objectName = `${token}/${crimeName}`;
switch (type) { switch (type) {
case 'image/png': case 'image/png':
if (!objectName.endsWith('.png')) objectName += '.png'; if (!objectName.endsWith('.png')) objectName += '.png';
break; break;
case '': case '':
if (fileName?.toString().endsWith('.glb') && !objectName.endsWith('.glb')) objectName += '.glb'; if (fileName?.toString().endsWith('.glb') && !objectName.endsWith('.glb'))
objectName += '.glb';
} }
const url = await client.presignedPutObject('tatort', objectName); const url = await client.presignedPutObject('tatort', objectName);
// store code in S3
// tatort/<vorgang>/__perm__
const code_filename = '__perm__';
const buf = Buffer.from(code, 'utf-8');
const code_stream = Readable.from(buf);
const code_path = `${vorgang}/${code_filename}`;
await client.putObject('tatort', code_path, code_stream);
return { url }; return { url };
}, },
validate: async ({ request }: {request: Request}) => { validate: async ({ request }: { request: Request }) => {
const requestData = await request.formData(); const requestData = await request.formData();
const data = Object.fromEntries(requestData); const data = Object.fromEntries(requestData);
const vorgang = data.vorgang; const vorgang = data.vorgang;
const name = data.name; const name = data.name;
const zugangscode = data.zugangscode; const password = data.password;
let success = true; let success = true;
const err = {}; const err = {};
if (isRequiredFieldValid(vorgang)) err.vorgang = null; if (isRequiredFieldValid(vorgang)) err.vorgang = null;
else { else {
err.vorgang = 'Das Feld Vorgang darf nicht leer bleiben.'; err.vorgang = 'Das Feld Vorgang darf nicht leer bleiben.';
@@ -62,9 +80,9 @@ export const actions = {
success = false; success = false;
} }
if (isRequiredFieldValid(zugangscode)) err.zugangscode = null; if (isRequiredFieldValid(password)) err.password = null;
else { else {
err.zugangscode = 'Das Feld Zugangscode darf nicht leer bleiben.'; err.password = 'Das Feld Zugangspasswort darf nicht leer bleiben.';
success = false; success = false;
} }
@@ -73,7 +91,7 @@ export const actions = {
return fail(400, err); return fail(400, err);
}, },
upload: async ({ request }: {request: Request}) => { upload: async ({ request }: { request: Request }) => {
const requestData = await request.formData(); const requestData = await request.formData();
const data = Object.fromEntries(requestData); const data = Object.fromEntries(requestData);
const vorgang = data.vorgang; const vorgang = data.vorgang;
@@ -83,7 +101,7 @@ export const actions = {
return { url }; return { url };
}, },
upload3: async ({ request }: {request: Request}) => { upload3: async ({ request }: { request: Request }) => {
const requestData = await request.formData(); const requestData = await request.formData();
const data = Object.fromEntries(requestData); const data = Object.fromEntries(requestData);
const name = data.name; const name = data.name;

View File

@@ -17,18 +17,18 @@
let vorgang = ''; let vorgang = '';
const code_len = 8; const code_len = 8;
function generate_token() { function generatePassword() {
return Math.random() return Math.random()
.toString(36) .toString(36)
.slice(2, 2 + code_len); .slice(2, 2 + code_len);
} }
let zugangscode = '' let zugangspasswort = ''
let zugangscode_old = '' let zugangspasswordOld = ''
$: zugangscode_old = generate_token(); $: zugangspasswordOld = generatePassword();
$: zugangscode = zugangscode_old $: zugangspasswort = zugangspasswordOld
let case_existing = undefined; let caseExisting = undefined;
$: case_existing = false; $: caseExisting = false;
let name = ''; let name = '';
let etag: string | null = null; let etag: string | null = null;
@@ -42,7 +42,7 @@
let data = new FormData(); let data = new FormData();
data.append('vorgang', vorgang); data.append('vorgang', vorgang);
data.append('name', name); data.append('name', name);
data.append('zugangscode', zugangscode); data.append('password', zugangspasswort);
const response = await fetch('?/validate', { method: 'POST', body: data }); const response = await fetch('?/validate', { method: 'POST', body: data });
/** @type {import('@sveltejs/kit').ActionResult} */ /** @type {import('@sveltejs/kit').ActionResult} */
const result = deserialize(await response.text()); const result = deserialize(await response.text());
@@ -64,7 +64,6 @@
formErrors = { file: 'Keine gültige .GLD-Datei', ...formErrors }; formErrors = { file: 'Keine gültige .GLD-Datei', ...formErrors };
success = false; success = false;
} }
return success; return success;
} }
@@ -72,7 +71,7 @@
let data = new FormData(); let data = new FormData();
data.append('vorgang', vorgang); data.append('vorgang', vorgang);
data.append('name', name); data.append('name', name);
data.append('zugangscode', zugangscode); data.append('password', zugangspasswort);
if (files?.length === 1) { if (files?.length === 1) {
data.append('type', files[0].type); data.append('type', files[0].type);
data.append('fileName', files[0].name); data.append('fileName', files[0].name);
@@ -152,44 +151,37 @@
} }
// `/(angemeldet)/view` return true or false // `/(angemeldet)/view` return true or false
async function case_exists(case_no) { async function caseExists(caseName: string) {
if (case_no == '') { if (caseName == '') {
zugangscode = zugangscode_old; zugangspasswort = zugangspasswordOld;
return;
} }
// ping `/view` with caseNumber in POST body let url = `/api/list/${caseName}`
let url = '/view';
let data = new FormData(); const response = await fetch(url, { method: 'HEAD'});
data.append('caseNumber', case_no); const status = response.status;
if (status == 200) {
caseExisting = true;
const passwort = await getPassword(caseName);
zugangspasswort = passwort;
// fetch code in parallel
const code = await get_code(case_no);
if (code != -1) {
zugangscode = code;
case_existing = true;
return true return true
} else {
caseExisting = false;
zugangspasswort = zugangspasswordOld;
return false
} }
const response = await fetch(url, { method: 'POST', body: data });
const res_json = await response.json();
const status = res_json.status;
if (status != 303) {
case_existing = false;
zugangscode = zugangscode_old;
}
return false;
} }
async function get_code(case_no) { async function getPassword(caseName: string) {
if (case_no == '') return; if (caseName == '') return;
let url = `/api/list/${case_no}/code`; let url = `/api/list/${caseName}/casepw`;
const response = await fetch(url); const response = await fetch(url);
if (response.status == 200) { if (response.status == 200) {
@@ -233,14 +225,14 @@
id="vorgang" id="vorgang"
autocomplete={vorgang} autocomplete={vorgang}
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6" class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
on:input={() => case_exists(vorgang)} on:input={() => caseExists(vorgang)}
/> />
</div> </div>
</div> </div>
{#if formErrors?.vorgang} {#if formErrors?.vorgang}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.vorgang}</p> <p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.vorgang}</p>
{/if} {/if}
{#if case_existing && vorgang.length > 0} {#if caseExisting && vorgang.length > 0}
<span>Datei wird zum existierenden Vorgang hinzugefügt.</span> <span>Datei wird zum existierenden Vorgang hinzugefügt.</span>
{:else if vorgang.length > 0} {:else if vorgang.length > 0}
<span>Neuer Vorgang wird angelegt.</span> <span>Neuer Vorgang wird angelegt.</span>
@@ -287,11 +279,11 @@
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600" class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
> >
<input <input
bind:value={zugangscode} bind:value={zugangspasswort}
type="text" type="text"
name="zugangscode" name="zugangscode"
id="zugangscode" id="zugangscode"
on:input="{ (ev) => { zugangscode_old = ev.target.value }}" on:input="{ (ev) => { zugangspasswordOld = ev.target.value }}"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6" class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/> />
@@ -299,7 +291,7 @@
<button <button
class="rounded-md bg-blue-500 px-3 py-2 text-sm font-semibold text-white shadow-sm hover:bg-indigo-500 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-indigo-600" class="rounded-md bg-blue-500 px-3 py-2 text-sm font-semibold text-white shadow-sm hover:bg-indigo-500 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-indigo-600"
on:click="{() => { on:click="{() => {
zugangscode = zugangscode_old = generate_token(); }}" zugangspasswort = zugangspasswordOld = generatePassword(); }}"
type="button"> type="button">
Generiere Zugangscode Generiere Zugangscode
</button> </button>

View File

@@ -1,4 +1,9 @@
import { checkIfVorgangExists, hasValidToken } from '$lib/server/vorgangService'; import {
checkIfVorgangExists,
hasValidToken,
passwordValid,
vorgangExists
} from '$lib/server/vorgangService';
import { redirect } from '@sveltejs/kit'; import { redirect } from '@sveltejs/kit';
import type { PageServerLoad } from './list/[vorgang]/$types'; import type { PageServerLoad } from './list/[vorgang]/$types';
@@ -9,11 +14,11 @@ export const load: PageServerLoad = async ({ params, url, locals }) => {
}; };
} }
const caseId = params.vorgang; const caseToken = params.vorgang;
const caseToken = url.searchParams.get('token'); const casePassword = url.searchParams.get('pw');
const isVorgangValid = await checkIfVorgangExists(caseId); const isVorgangValid = vorgangExists(caseToken);
const isTokenValid = await hasValidToken(caseId, caseToken); const isPasswordValid = passwordValid(caseToken, casePassword);
if (!isVorgangValid || !isTokenValid) throw redirect(303, `/anmeldung`); if (!isVorgangValid || !isPasswordValid) throw redirect(303, `/anmeldung?vorgang=${caseToken}`);
}; };

View File

@@ -1,14 +1,16 @@
import { getVorgangByCaseId } from '$lib/server/vorgangService'; import { getVorgangByToken, getCrimesListByToken } from '$lib/server/vorgangService';
import type { PageServerLoad } from './$types'; import type { PageServerLoad } from './$types';
export const load: PageServerLoad = async ({ params, url }) => { export const load: PageServerLoad = async ({ params, url }) => {
const caseId = params.vorgang; const caseToken = params.vorgang;
const caseToken = url.searchParams.get('token'); const casePassword = url.searchParams.get('pw');
const crimesList = await getVorgangByCaseId(caseId); const crimesList = await getCrimesListByToken(caseToken);
const vorgang = getVorgangByToken(caseToken);
return { return {
crimesList, crimesList,
caseToken casePassword,
vorgang
}; };
}; };

View File

@@ -26,8 +26,9 @@
// add other properties as needed // add other properties as needed
} }
const vorgang = data.vorgang;
const crimesList: ListItem[] = data.crimesList; const crimesList: ListItem[] = data.crimesList;
const token: string = data.caseToken; const password: string = data.casePassword;
let open = false; let open = false;
$: open; $: open;
@@ -93,7 +94,6 @@
// construct PUT URL // construct PUT URL
const url = $page.url; const url = $page.url;
console.log(url);
let data_obj: { new_name: string; old_name: string } = { new_name: '', old_name: '' }; let data_obj: { new_name: string; old_name: string } = { new_name: '', old_name: '' };
data_obj['new_name'] = new_name; data_obj['new_name'] = new_name;
@@ -128,18 +128,31 @@
return; return;
} }
} }
async function setClipboard(text) {
const type = "text/plain";
const clipboardItemData = {
[type]: text,
};
const clipboardItem = new ClipboardItem(clipboardItemData);
await navigator.clipboard.write([clipboardItem]);
}
</script> </script>
<div class="-z-10 bg-white"> <div class="-z-10 bg-white">
<div class="flex flex-col items-center justify-center w-full"> <div class="flex flex-col items-center justify-center w-full">
<h1 class="text-xl">Vorgang {$page.params.vorgang}</h1> <h1 class="text-xl">Vorgang {vorgang.name}</h1>
{#if data?.user?.admin}
Zugangspasswort: {vorgang.pw}
<Button on:click={() => setClipboard($page.url.toString().split('?')[0])}>Copy Link</Button>
{/if}
</div> </div>
<div class="mx-auto flex justify-center max-w-7xl h-full"> <div class="mx-auto flex justify-center max-w-7xl h-full">
<ul class="divide-y divide-gray-100"> <ul class="divide-y divide-gray-100">
{#each crimesList as item, i} {#each crimesList as item, i}
<li> <li>
<a <a
href="/view/{$page.params.vorgang}/{item.name}?token={token}" href="/view/{$page.params.vorgang}/{item.name}?pw={password}"
class=" flex justify-between gap-x-6 py-5" class=" flex justify-between gap-x-6 py-5"
aria-label="zum 3D-modell" aria-label="zum 3D-modell"
> >

View File

@@ -4,13 +4,15 @@ import { redirect } from '@sveltejs/kit';
export const actions = { export const actions = {
login: ({ request, cookies }) => loginUser({ request, cookies }), login: ({ request, cookies }) => loginUser({ request, cookies }),
logout: (event) => logoutUser(event), logout: (event) => logoutUser(event),
getVorgangById: async ({ request }) => { getVorgangByToken: async ({ request }) => {
const data = await request.formData(); const data = await request.formData();
const caseId = data.get('case-id');
const caseToken = data.get('case-token'); const caseToken = data.get('case-token');
const casePassword = data.get('case-password');
if (!caseId || !caseToken) return; console.log(`+++ ${caseToken} + ${casePassword}`);
throw redirect(303, `/list/${caseId}?token=${caseToken}`); if (!caseToken || !casePassword) return;
throw redirect(303, `/list/${caseToken}?pw=${casePassword}`);
} }
} as const; } as const;

View File

@@ -11,6 +11,9 @@
export let form; export let form;
export let open = false; export let open = false;
import { page } from '$app/state';
const vorgangToken = page.url.searchParams.get('vorgang');
</script> </script>
<div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8"> <div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8">
@@ -24,21 +27,21 @@
<div class="w-full max-w-sm mx-auto"> <div class="w-full max-w-sm mx-auto">
<div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1"> <div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1">
<div class="mt-10"> <div class="mt-10">
<form action="?/getVorgangById" method="POST"> <form action="?/getVorgangByToken" method="POST">
<BaseInputField <BaseInputField
id="case-id" id="case-token"
name="case-id" name="case-token"
label="Vorgangskennung" label="Vorgangskennung"
type="text" type="text"
value={form?.caseId} value={vorgangToken}
/> />
<div class="mt-5"> <div class="mt-5">
<BaseInputField <BaseInputField
id="case-token" id="case-password"
name="case-token" name="case-password"
label="Zugangscode" label="Zugangspasswort"
type="text" type="text"
value={form?.token} value={form?.password}
error={form?.error?.message} error={form?.error?.message}
/> />
</div> </div>

View File

@@ -1,11 +1,18 @@
import { client } from '$lib/minio'; import { client } from '$lib/minio';
import { db } from '$lib/server/dbService';
import {
deleteVorgangByToken,
getVorgangByToken,
getVorgangByName,
vorgangNameExists
} from '$lib/server/vorgangService';
export async function DELETE({ params }) { export async function DELETE({ params }) {
const vorgang = params.vorgang; const vorgangToken = params.vorgang;
const object_list = await new Promise((resolve, reject) => { const object_list = await new Promise((resolve, reject) => {
const res = []; const res = [];
const items_str = client.listObjects('tatort', vorgang, true); const items_str = client.listObjects('tatort', vorgangToken, true);
items_str.on('data', (obj) => { items_str.on('data', (obj) => {
res.push(obj.name); res.push(obj.name);
@@ -19,6 +26,19 @@ export async function DELETE({ params }) {
}); });
await client.removeObjects('tatort', object_list); await client.removeObjects('tatort', object_list);
deleteVorgangByToken(vorgangToken);
return new Response(null, { status: 204 }); return new Response(null, { status: 204 });
} }
export async function HEAD({ params }) {
const vorgangName = params.vorgang;
const existing = vorgangNameExists(vorgangName);
if (existing) {
return new Response(null, { status: 200 });
} else {
return new Response(null, { status: 404 });
}
}

View File

@@ -0,0 +1,16 @@
import { db } from '$lib/server/dbService';
/** @type {import('./$types').RequestHandler} */
export async function GET({ params }) {
const vorgangName = params.vorgang;
let getCodeSQLStatement = `SELECT pw FROM cases WHERE name = ?;`;
const row = db.prepare(getCodeSQLStatement).get(vorgangName);
let password = row.pw;
if (password) {
return new Response(password, { status: 200 });
} else {
return new Response(null, { status: 404 });
}
}

View File

@@ -1,25 +0,0 @@
import { client } from '$lib/minio';
/** @type {import('./$types').RequestHandler} */
export async function GET({ params }) {
const prefix = params.vorgang ? `${params.vorgang}` : '';
const code_name = '__perm__';
const obj_path = `${prefix}/${code_name}`;
let result = null;
try {
result = await client.getObject('tatort', obj_path);
} catch (error) {
if (error.name == 'S3Error') {
result = null;
}
}
if (result != null) {
return new Response(result, { status: 200 });
} else {
return new Response(null, { status: 404 });
}
}