3 Commits

13 changed files with 152 additions and 152 deletions

View File

@@ -3,42 +3,42 @@ import jsSHA from 'jssha';
const db = new Database('./src/lib/data/tatort.db');
let create_stmt = `CREATE TABLE IF NOT EXISTS users
let createSQLStmt = `CREATE TABLE IF NOT EXISTS users
(id INTEGER PRIMARY KEY AUTOINCREMENT,
name TEXT NOT NULL,
pw TEXT NOT NULL)`;
db.exec(create_stmt);
db.exec(createSQLStmt);
// check if there are any users; if not add one default admin one
let pw = 'pass-123';
let hashed_pw = new jsSHA('SHA-512', 'TEXT').update(pw).getHash('HEX');
let password = 'pass-123';
let hashedPassword = new jsSHA('SHA-512', 'TEXT').update(password).getHash('HEX');
let check_ins_stmt = `INSERT INTO users (name, pw) SELECT 'admin', '${hashed_pw}'
let checkInsertSQLStmt = `INSERT INTO users (name, pw) SELECT 'admin', '${hashedPassword}'
WHERE NOT EXISTS (SELECT * FROM users);`;
db.exec(check_ins_stmt);
db.exec(checkInsertSQLStmt);
let users_stmt = `SELECT * FROM USERS`;
let stmt = db.prepare(users_stmt);
let usersSQLStmt = `SELECT * FROM USERS`;
let SQLStatement = db.prepare(usersSQLStmt);
console.log(`\n`, `*** Users table`);
for (const usr of stmt.iterate()) {
for (const usr of SQLStatement.iterate()) {
console.log(`[r] ${usr.name} + ${usr.pw}`);
}
// cases table
create_stmt = `CREATE TABLE IF NOT EXISTS cases
createSQLStmt = `CREATE TABLE IF NOT EXISTS cases
(id INTEGER PRIMARY KEY AUTOINCREMENT,
token TEXT NOT NULL UNIQUE,
name TEXT NOT NULL UNIQUE,
pw TEXT NOT NULL)`;
db.exec(create_stmt);
db.exec(createSQLStmt);
let cases_stmt = `SELECT * FROM cases`;
stmt = db.prepare(cases_stmt);
let casesSQLStmt = `SELECT * FROM cases`;
SQLStatement = db.prepare(casesSQLStmt);
console.log(`\n`, `*** Cases table`);
for (const usr of stmt.iterate()) {
for (const usr of SQLStatement.iterate()) {
console.log(`[r] ${usr.name} + ${usr.token} + ${usr.pw}`);
}

View File

@@ -19,18 +19,18 @@ export function decryptToken(token: string) {
}
export function authenticate(user, pass) {
let token;
let JWTToken;
// hash user password
let hashed_pw = new jsSHA('SHA-512', 'TEXT').update(pass).getHash('HEX');
let hashedPW = new jsSHA('SHA-512', 'TEXT').update(pass).getHash('HEX');
let get_usr_stmt = 'SELECT name, pw FROM users WHERE name = ?';
const row = db.prepare(get_usr_stmt).get(user);
let stored_pw = row.pw;
let getUserSQLStmt = 'SELECT name, pw FROM users WHERE name = ?';
const row = db.prepare(getUserSQLStmt).get(user);
let storedPW = row.pw;
if (hashed_pw && hashed_pw === stored_pw) {
token = createToken({ id: user, admin: true });
if (hashedPW && hashedPW === storedPW) {
JWTToken = createToken({ id: user, admin: true });
}
return token;
return JWTToken;
}

View File

@@ -6,11 +6,11 @@ import { db } from './dbService';
/**
* Get Vorgang and corresponend list of tatorte
* @param caseId
* @param caseToken
* @returns
*/
export const getVorgangByCaseId = async (caseId: string) => {
const prefix = `${caseId}/`;
export const getCrimesListByToken = async (caseToken: string) => {
const prefix = `${caseToken}/`;
const stream = client.listObjectsV2(BUCKET, prefix, false, '');
@@ -28,34 +28,39 @@ export const getVorgangByCaseId = async (caseId: string) => {
/**
* Get Vorgang
* @param caseId
* @param caseToken
* @returns caseObj with keys `token`, `name`, `pw` || undefined
*/
export const getVorgang = function (caseId: string) {
let getVorgang_stmt = `SELECT token, name, pw FROM cases WHERE token = ?`;
const stmt = db.prepare(getVorgang_stmt);
const res = stmt.get(caseId);
export const getVorgangByToken = function (caseToken: string) {
let getVorgangSQLStmt = `SELECT token, name, pw FROM cases WHERE token = ?`;
const statement = db.prepare(getVorgangSQLStmt);
const result = statement.get(caseToken);
return res;
return result;
};
/**
* Get Vorgang
* @param caseName
* @returns caseObj with keys `token`, `name`, `pw` || undefined
*/
export const getVorgangByName = function (caseName: string) {
let getVorgangByName_stmt = `SELECT token, name, pw FROM cases WHERE name = ?`;
const stmt = db.prepare(getVorgangByName_stmt);
const res = stmt.get(caseName);
let getVorgangByNameSQLStmt = `SELECT token, name, pw FROM cases WHERE name = ?`;
const statement = db.prepare(getVorgangByNameSQLStmt);
const result = statement.get(caseName);
return res;
return result;
};
/**
* Delete Vorgang
* @param caseName
* @param caseToken
* @returns int: number of changes
*/
export const deleteVorgangByName = function (caseName: string) {
let delete_stmt = 'DELETE FROM cases WHERE name = ?';
const stmt = db.prepare(delete_stmt);
const info = stmt.run(caseName);
export const deleteVorgangByToken = function (caseToken: string) {
let deleteSQLStmt = 'DELETE FROM cases WHERE token = ?';
const statement = db.prepare(deleteSQLStmt);
const info = statement.run(caseToken);
return info.changes;
};
@@ -84,11 +89,11 @@ export const getListOfVorgänge = async () => {
* @returns list with of available cases
*/
export const getVorgaenge = function () {
let getVorgaenge_stmt = `SELECT token, name, pw from cases`;
const stmt = db.prepare(getVorgaenge_stmt);
const res = stmt.all();
let getVorgaengeSQLStmt = `SELECT token, name, pw from cases`;
const statement = db.prepare(getVorgaengeSQLStmt);
const result = statement.all();
const vorgaenge_list = [];
for (const r of res) {
for (const r of result) {
const vorg = { token: r.token, name: r.name, pw: r.pw };
vorgaenge_list.push(vorg);
}
@@ -121,11 +126,11 @@ export const checkIfVorgangExists = async (caseId: string | null) => {
return true;
};
export const vorgangExists = function (caseId: string | null) {
if (!caseId) {
export const vorgangExists = function (caseToken: string | null) {
if (!caseToken) {
return fail(400, {
success: false,
caseId,
caseId: caseToken,
error: { message: 'Die Vorgangsnummer darf nicht leer sein.' }
});
}
@@ -133,16 +138,16 @@ export const vorgangExists = function (caseId: string | null) {
let vorgaenge = getVorgaenge();
const vorgaenge_tokens = vorgaenge.map((vorg) => vorg.token);
const found = vorgaenge_tokens.indexOf(caseId) != -1;
const found = vorgaenge_tokens.indexOf(caseToken) != -1;
return found;
};
export const vorgangNameExists = function (caseName: string) {
let vorgaenge = getVorgaenge();
const vorgaenge_names = vorgaenge.map((vorg) => vorg.name);
const vorgaengeNames = vorgaenge.map((vorg) => vorg.name);
const found = vorgaenge_names.indexOf(caseName) != -1;
const found = vorgaengeNames.indexOf(caseName) != -1;
return found;
};
@@ -169,14 +174,14 @@ export const hasValidToken = async (caseId: string, caseToken: string) => {
}
};
export const tokenValid = function (caseId, caseToken) {
if (!caseToken) {
export const passwordValid = function (caseToken, casePassword) {
if (!casePassword) {
return false;
}
const vorg = getVorgang(caseId);
const vorg = getVorgangByToken(caseToken);
if (!vorg || vorg.pw !== caseToken) {
if (!vorg || vorg.pw !== casePassword) {
return false;
}

View File

@@ -46,7 +46,7 @@
<ul role="list" class="divide-y divide-gray-100">
{#each caseList as item}
<li>
<a href="/list/{item.token}?token={item.pw}" class="flex justify-between gap-x-6 py-5">
<a href="/list/{item.token}?pw={item.pw}" class="flex justify-between gap-x-6 py-5">
<div class="flex gap-x-4">
<!-- Ordner -->
<Folder />
@@ -55,7 +55,7 @@
<!-- Delete button -->
<button
style="padding: 2px"
id="del__{item.name}"
id="del__{item.token}"
on:click|preventDefault={delete_item}
aria-label="Vorgang {item.name} löschen"
>

View File

@@ -1,11 +1,10 @@
import { Buffer } from 'buffer';
import { Readable } from 'stream';
import { client } from '$lib/minio';
import { fail } from '@sveltejs/kit';
import { v4 as uuidv4 } from 'uuid';
import { db } from '$lib/server/dbService';
import { getVorgangByName, vorgangExists, vorgangNameExists } from '$lib/server/vorgangService';
import { getVorgangByName, vorgangNameExists } from '$lib/server/vorgangService';
const isRequiredFieldValid = (value: unknown) => {
if (value == null) return false;
@@ -18,36 +17,36 @@ const isRequiredFieldValid = (value: unknown) => {
export const actions = {
url: async ({ request }: { request: Request }) => {
const data = await request.formData();
const vorgang = data.get('vorgang');
const name = data.get('name');
const caseName = data.get('vorgang');
const crimeName = data.get('name');
const type = data.get('type');
const code = data.get('zugangscode');
const password = data.get('password');
const fileName = data.get('fileName');
// store case in database
// skip if Vorgang exists and token not changed
const vorgang_exists = vorgangNameExists(vorgang);
const vorgangExists = vorgangNameExists(caseName);
let token;
if (!vorgang_exists) {
if (!vorgangExists) {
token = uuidv4();
let insert_stmt = `INSERT INTO cases (token, name, pw) VALUES (?, ?, ?)`;
const stmt = db.prepare(insert_stmt);
stmt.run(token, vorgang, code);
let insertSQLStatement = `INSERT INTO cases (token, name, pw) VALUES (?, ?, ?)`;
const statement = db.prepare(insertSQLStatement);
statement.run(token, caseName, password);
} else {
// vorgang exists
// check if PW was changed, and update DB if it was
const vorg = getVorgangByName(vorgang);
const vorg = getVorgangByName(caseName);
token = vorg.token;
if (vorg.pw != code) {
let update_stmt = `UPDATE cases SET pw = ? WHERE name = ?`;
const stmt = db.prepare(update_stmt);
stmt.run(code, vorgang);
if (vorg.pw != password) {
let updateSQLStmt = `UPDATE cases SET pw = ? WHERE name = ?`;
const statement = db.prepare(updateSQLStmt);
statement.run(password, vorg);
}
}
let objectName = `${token}/${name}`;
let objectName = `${token}/${crimeName}`;
switch (type) {
case 'image/png':
if (!objectName.endsWith('.png')) objectName += '.png';
@@ -66,10 +65,9 @@ export const actions = {
const data = Object.fromEntries(requestData);
const vorgang = data.vorgang;
const name = data.name;
const zugangscode = data.zugangscode;
const password = data.password;
let success = true;
const err = {};
if (isRequiredFieldValid(vorgang)) err.vorgang = null;
else {
err.vorgang = 'Das Feld Vorgang darf nicht leer bleiben.';
@@ -82,9 +80,9 @@ export const actions = {
success = false;
}
if (isRequiredFieldValid(zugangscode)) err.zugangscode = null;
if (isRequiredFieldValid(password)) err.password = null;
else {
err.zugangscode = 'Das Feld Zugangscode darf nicht leer bleiben.';
err.password = 'Das Feld Zugangspasswort darf nicht leer bleiben.';
success = false;
}

View File

@@ -17,18 +17,18 @@
let vorgang = '';
const code_len = 8;
function generate_token() {
function generatePassword() {
return Math.random()
.toString(36)
.slice(2, 2 + code_len);
}
let zugangscode = ''
let zugangscode_old = ''
$: zugangscode_old = generate_token();
$: zugangscode = zugangscode_old
let zugangspasswort = ''
let zugangspasswordOld = ''
$: zugangspasswordOld = generatePassword();
$: zugangspasswort = zugangspasswordOld
let case_existing = undefined;
$: case_existing = false;
let caseExisting = undefined;
$: caseExisting = false;
let name = '';
let etag: string | null = null;
@@ -42,7 +42,7 @@
let data = new FormData();
data.append('vorgang', vorgang);
data.append('name', name);
data.append('zugangscode', zugangscode);
data.append('password', zugangspasswort);
const response = await fetch('?/validate', { method: 'POST', body: data });
/** @type {import('@sveltejs/kit').ActionResult} */
const result = deserialize(await response.text());
@@ -64,7 +64,6 @@
formErrors = { file: 'Keine gültige .GLD-Datei', ...formErrors };
success = false;
}
return success;
}
@@ -72,7 +71,7 @@
let data = new FormData();
data.append('vorgang', vorgang);
data.append('name', name);
data.append('zugangscode', zugangscode);
data.append('password', zugangspasswort);
if (files?.length === 1) {
data.append('type', files[0].type);
data.append('fileName', files[0].name);
@@ -152,37 +151,37 @@
}
// `/(angemeldet)/view` return true or false
async function case_exists(case_name: string) {
async function caseExists(caseName: string) {
if (case_name == '') {
zugangscode = zugangscode_old;
if (caseName == '') {
zugangspasswort = zugangspasswordOld;
return;
}
let url = `/api/list/${case_name}`
let url = `/api/list/${caseName}`
const response = await fetch(url, { method: 'HEAD'});
const status = response.status;
if (status == 200) {
case_existing = true;
const code = await get_code(case_name);
zugangscode = code;
caseExisting = true;
const passwort = await getPassword(caseName);
zugangspasswort = passwort;
return true
} else {
case_existing = false;
zugangscode = zugangscode_old;
caseExisting = false;
zugangspasswort = zugangspasswordOld;
return false
}
}
async function get_code(case_no: string) {
async function getPassword(caseName: string) {
if (case_no == '') return;
if (caseName == '') return;
let url = `/api/list/${case_no}/code`;
let url = `/api/list/${caseName}/code`;
const response = await fetch(url);
if (response.status == 200) {
@@ -226,14 +225,14 @@
id="vorgang"
autocomplete={vorgang}
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
on:input={() => case_exists(vorgang)}
on:input={() => caseExists(vorgang)}
/>
</div>
</div>
{#if formErrors?.vorgang}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.vorgang}</p>
{/if}
{#if case_existing && vorgang.length > 0}
{#if caseExisting && vorgang.length > 0}
<span>Datei wird zum existierenden Vorgang hinzugefügt.</span>
{:else if vorgang.length > 0}
<span>Neuer Vorgang wird angelegt.</span>
@@ -280,11 +279,11 @@
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
bind:value={zugangscode}
bind:value={zugangspasswort}
type="text"
name="zugangscode"
id="zugangscode"
on:input="{ (ev) => { zugangscode_old = ev.target.value }}"
on:input="{ (ev) => { zugangspasswordOld = ev.target.value }}"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/>
@@ -292,7 +291,7 @@
<button
class="rounded-md bg-blue-500 px-3 py-2 text-sm font-semibold text-white shadow-sm hover:bg-indigo-500 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-indigo-600"
on:click="{() => {
zugangscode = zugangscode_old = generate_token(); }}"
zugangspasswort = zugangspasswordOld = generatePassword(); }}"
type="button">
Generiere Zugangscode
</button>

View File

@@ -1,7 +1,7 @@
import {
checkIfVorgangExists,
hasValidToken,
tokenValid,
passwordValid,
vorgangExists
} from '$lib/server/vorgangService';
import { redirect } from '@sveltejs/kit';
@@ -14,11 +14,11 @@ export const load: PageServerLoad = async ({ params, url, locals }) => {
};
}
const caseId = params.vorgang;
const caseToken = url.searchParams.get('token');
const caseToken = params.vorgang;
const casePassword = url.searchParams.get('pw');
const isVorgangValid = vorgangExists(caseId);
const isTokenValid = tokenValid(caseId, caseToken);
const isVorgangValid = vorgangExists(caseToken);
const isPasswordValid = passwordValid(caseToken, casePassword);
if (!isVorgangValid || !isTokenValid) throw redirect(303, `/anmeldung?vorgang=${caseId}`);
if (!isVorgangValid || !isPasswordValid) throw redirect(303, `/anmeldung?vorgang=${caseToken}`);
};

View File

@@ -1,16 +1,16 @@
import { getVorgang, getVorgangByCaseId } from '$lib/server/vorgangService';
import { getVorgangByToken, getCrimesListByToken } from '$lib/server/vorgangService';
import type { PageServerLoad } from './$types';
export const load: PageServerLoad = async ({ params, url }) => {
const caseId = params.vorgang;
const caseToken = url.searchParams.get('token');
const caseToken = params.vorgang;
const casePassword = url.searchParams.get('pw');
const crimesList = await getVorgangByCaseId(caseId);
const vorg = getVorgang(caseId);
const crimesList = await getCrimesListByToken(caseToken);
const vorgang = getVorgangByToken(caseToken);
return {
crimesList,
caseToken,
vorg
casePassword,
vorgang
};
};

View File

@@ -26,9 +26,9 @@
// add other properties as needed
}
const vorg = data.vorg;
const vorgang = data.vorgang;
const crimesList: ListItem[] = data.crimesList;
const token: string = data.caseToken;
const password: string = data.casePassword;
let open = false;
$: open;
@@ -141,9 +141,9 @@
<div class="-z-10 bg-white">
<div class="flex flex-col items-center justify-center w-full">
<h1 class="text-xl">Vorgang {vorg.name}</h1>
<h1 class="text-xl">Vorgang {vorgang.name}</h1>
{#if data?.user?.admin}
Zugangscode: {vorg.pw}
Zugangspasswort: {vorgang.pw}
<Button on:click={() => setClipboard($page.url.toString().split('?')[0])}>Copy Link</Button>
{/if}
</div>
@@ -152,7 +152,7 @@
{#each crimesList as item, i}
<li>
<a
href="/view/{$page.params.vorgang}/{item.name}?token={token}"
href="/view/{$page.params.vorgang}/{item.name}?pw={password}"
class=" flex justify-between gap-x-6 py-5"
aria-label="zum 3D-modell"
>

View File

@@ -4,13 +4,15 @@ import { redirect } from '@sveltejs/kit';
export const actions = {
login: ({ request, cookies }) => loginUser({ request, cookies }),
logout: (event) => logoutUser(event),
getVorgangById: async ({ request }) => {
getVorgangByToken: async ({ request }) => {
const data = await request.formData();
const caseId = data.get('case-id');
const caseToken = data.get('case-token');
const casePassword = data.get('case-password');
if (!caseId || !caseToken) return;
console.log(`+++ ${caseToken} + ${casePassword}`);
throw redirect(303, `/list/${caseId}?token=${caseToken}`);
if (!caseToken || !casePassword) return;
throw redirect(303, `/list/${caseToken}?pw=${casePassword}`);
}
} as const;
} as const;

View File

@@ -13,7 +13,7 @@
export let open = false;
import { page } from '$app/state';
const vorgang_token = page.url.searchParams.get('vorgang');
const vorgangToken = page.url.searchParams.get('vorgang');
</script>
<div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8">
@@ -27,21 +27,21 @@
<div class="w-full max-w-sm mx-auto">
<div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1">
<div class="mt-10">
<form action="?/getVorgangById" method="POST">
<form action="?/getVorgangByToken" method="POST">
<BaseInputField
id="case-id"
name="case-id"
id="case-token"
name="case-token"
label="Vorgangskennung"
type="text"
value={vorgang_token}
value={vorgangToken}
/>
<div class="mt-5">
<BaseInputField
id="case-token"
name="case-token"
label="Zugangscode"
id="case-password"
name="case-password"
label="Zugangspasswort"
type="text"
value={form?.token}
value={form?.password}
error={form?.error?.message}
/>
</div>

View File

@@ -1,21 +1,18 @@
import { client } from '$lib/minio';
import { db } from '$lib/server/dbService';
import {
deleteVorgangByName,
getVorgang,
deleteVorgangByToken,
getVorgangByToken,
getVorgangByName,
vorgangNameExists
} from '$lib/server/vorgangService';
export async function DELETE({ params }) {
const vorgang = params.vorgang;
const vorg = getVorgangByName(vorgang);
let vorg_token = vorg.token;
const vorgangToken = params.vorgang;
const object_list = await new Promise((resolve, reject) => {
const res = [];
const items_str = client.listObjects('tatort', vorg_token, true);
const items_str = client.listObjects('tatort', vorgangToken, true);
items_str.on('data', (obj) => {
res.push(obj.name);
@@ -29,15 +26,15 @@ export async function DELETE({ params }) {
});
await client.removeObjects('tatort', object_list);
deleteVorgangByName(vorgang);
deleteVorgangByToken(vorgangToken);
return new Response(null, { status: 204 });
}
export async function HEAD({ params }) {
const vorgang_name = params.vorgang;
const vorgangName = params.vorgang;
const existing = vorgangNameExists(vorgang_name);
const existing = vorgangNameExists(vorgangName);
if (existing) {
return new Response(null, { status: 200 });

View File

@@ -1,16 +1,15 @@
import { client } from '$lib/minio';
import { db } from '$lib/server/dbService';
/** @type {import('./$types').RequestHandler} */
export async function GET({ params }) {
const vorgang_name = params.vorgang;
const vorgangName = params.vorgang;
let get_code_stmt = `SELECT pw FROM cases WHERE name = ?;`;
const row = db.prepare(get_code_stmt).get(vorgang_name);
let pw = row.pw;
let getCodeSQLStatement = `SELECT pw FROM cases WHERE name = ?;`;
const row = db.prepare(getCodeSQLStatement).get(vorgangName);
let password = row.pw;
if (pw) {
return new Response(pw, { status: 200 });
if (password) {
return new Response(password, { status: 200 });
} else {
return new Response(null, { status: 404 });
}