48 Commits

Author SHA1 Message Date
eebfaf67f6 test: Vorgang-Detail Seite: Share (mail-to) Link enthält URL zum Vorgang 2025-12-03 13:28:52 +01:00
8762836b46 test: Vorgang-Detail Seite: Share (Teilen) Button deaktiviert bei leerer Tatort-Liste 2025-12-02 12:12:54 +01:00
7c6ff2e250 test: Anmeldung via Token/PIN - falsche PIN und Fehlermeldung 2025-12-02 11:04:04 +01:00
a50c5243a5 test: NameItemEditor component - Focussing of Input element after click 2025-12-02 10:39:40 +01:00
1158c88d43 fix SonarQube issues: mainly unused imports
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
2025-11-24 08:41:46 +01:00
e6add823a5 update packages 2025-11-24 08:36:42 +01:00
b1c246113c Merge pull request 'f112_vorgang_operationen' (#41) from f112_vorgang_operationen into development
Some checks failed
InnoHub Processor/tatort/pipeline/head There was a failure building this commit
Reviewed-on: #41
2025-11-21 13:12:25 +01:00
5c76e77766 add tests for Vorgang operation: change name and pin 2025-11-21 12:00:14 +01:00
3aee87aaed clarify test case description 2025-11-21 09:39:13 +01:00
97aaf2cd12 fix ´onDelete´ function type 2025-11-21 09:33:41 +01:00
9d35079058 change function parameter name to make it more descriptive: newName -> newValue 2025-11-21 09:26:08 +01:00
73cb398aa0 position PIN code on the same line as the label 2025-11-20 13:05:40 +01:00
365fb0f2c7 allow vorgangPIN to be changed on Vorgang page
includes:
- UI and backend logic
- adjustment to `NameItemEditor` to disallow deletion
2025-11-20 12:54:53 +01:00
c81196343f adjust minor test config: global mock of HTML functions and addition of test-id 2025-11-20 09:52:37 +01:00
c7526be3c9 adjust test to work with adjusted NameItemEditor 2025-11-20 09:50:20 +01:00
b6996902cc implement renaming feature for vorgang
UI and backend logic
make ´NameItemEditor´ reusable to be able to use with Vorgang
2025-11-20 09:46:28 +01:00
b3ba6256e0 remove unused import 2025-11-20 09:37:08 +01:00
9d72a99626 Merge pull request 'f113_UI_fixes' (#40) from f113_UI_fixes into development
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
Reviewed-on: #40
2025-11-13 12:51:29 +01:00
320f6d6c8b remove Vorgang label 2025-11-13 12:46:58 +01:00
ac79f10153 adjust ´edit´ and ´delete´ button on Vorgang page with crimesList 2025-11-13 12:45:07 +01:00
dac1c57c98 align Vorgang item on list page and remove ´Vorgang´ description 2025-11-13 12:03:51 +01:00
4582306dc8 Merge pull request 'f111_frontend_ueberarbeitung' (#39) from f111_frontend_ueberarbeitung into development
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
Reviewed-on: #39
2025-11-13 10:11:05 +01:00
64ff7c6e97 add some tests for crimes ´add´-button, further tests to be defined 2025-11-13 09:41:46 +01:00
e1f207f6fe tests for + (plus) button onVorgang list 2025-11-12 08:10:43 +01:00
2e16a0bc03 adjust UI test for removal of ´Hinzufügen´ button 2025-11-11 08:13:14 +01:00
1c4b154e41 add + (plus) button for addition of Vorgaenge and Crimes 2025-11-11 07:57:29 +01:00
b26080f4c1 successful upload modal for crimes 2025-11-10 08:40:52 +01:00
f92bcd5876 successful file upload 2025-11-07 11:17:39 +01:00
939b3174f2 Merge branch 'development' into f111_frontend_ueberarbeitung 2025-11-07 08:24:19 +01:00
44a9669ea4 remove ´Hinzufügen´ button on home view 2025-11-06 12:45:46 +01:00
cc469f67a5 allow for addition of Vorgaenge on Vorgang overview 2025-11-05 12:19:34 +01:00
6b22da6a34 Merge pull request 'f110_undo_skipped_test_API_endpoints' (#38) from f110_undo_skipped_test_API_endpoints into development
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
Reviewed-on: #38
2025-11-05 10:24:20 +01:00
808b56934c remove unused locals parameter 2025-11-05 09:18:05 +01:00
fd907c9851 move API protection check into hooks, adjusting corresponding tests 2025-11-04 09:22:53 +01:00
3c16bc89e5 undo skipped tests, only allow API calls for admin-views, refactor viewer-page to use page.server 2025-11-03 14:21:08 +01:00
a9e3d8264c Merge pull request 'f092_ViewAuth-von-User-vereinfachen' (#37) from f092_ViewAuth-von-User-vereinfachen into development
All checks were successful
InnoHub Processor/tatort/pipeline/head This commit looks good
Reviewed-on: #37
2025-10-30 13:04:08 +01:00
332a3e5c15 change description of test case: load() now returns undefined if not logged-in 2025-10-30 12:16:21 +01:00
4fc6da850b change invalid user login 2025-10-30 12:04:58 +01:00
36273fd426 fix tests for refactoring of viewer Vorgang-PIN-validation 2025-10-30 11:15:07 +01:00
793ddb17d6 magic strings for login and logout 2025-10-30 10:56:23 +01:00
349d2cea6a named actions for logging in and out 2025-10-30 10:38:11 +01:00
23f2feeefb remove ununsed import 2025-10-30 10:36:50 +01:00
48fe999b5b protect admin pages after refactoring 2025-10-30 10:35:45 +01:00
c857041e21 refactor viewer-login page with error messages and validation 2025-10-30 08:57:58 +01:00
e26b36121a refactor homepage for admin-user and login mask if not logged in 2025-10-29 12:34:38 +01:00
416118197b test Login angepasst, return fail wenn formaDaten leer 2025-10-17 12:12:07 +02:00
01afbea9a3 Merge branch 'development' into f092_ViewAuth-von-User-vereinfachen 2025-10-17 10:37:39 +02:00
69422d1f92 refactoring UUID Anzeige, noch keine Tests angepasst 2025-10-13 13:01:12 +02:00
40 changed files with 1752 additions and 1176 deletions

1099
package-lock.json generated

File diff suppressed because it is too large Load Diff

View File

@@ -14,5 +14,15 @@ export const handle: Handle = async ({ event, resolve }) => {
event.cookies.delete('session', {path: ROUTE_NAMES.ROOT}); event.cookies.delete('session', {path: ROUTE_NAMES.ROOT});
event.locals.user = null; event.locals.user = null;
} }
if (event.url.pathname.startsWith('/api')) {
if (!event.locals.user) {
return new Response(JSON.stringify({ error: 'Unauthorized' }), {
status: 401,
headers: { 'Content-Type': 'application/json' }
});
}
}
return await resolve(event); return await resolve(event);
} }

View File

@@ -0,0 +1,54 @@
<script lang="ts">
import { fly, scale, fade } from 'svelte/transition';
import { cubicOut } from 'svelte/easing';
import { tick } from 'svelte';
let expanded = false;
let formContainer: HTMLDivElement;
async function toggle() {
expanded = !expanded;
if (expanded) {
// Wait for DOM to update
await tick();
// Scroll smoothly into view
formContainer?.scrollIntoView({ behavior: 'smooth', block: 'start' });
}
}
</script>
<div data-testid="expand-container" class="flex flex-col items-center">
<!-- + / × button -->
<button
data-testid="expand-button"
class="flex items-center justify-center w-12 h-12 rounded-full bg-blue-600 text-white text-2xl font-bold hover:bg-blue-700 transition"
on:click={toggle}
aria-expanded={expanded}
aria-label="Add item"
>
{#if expanded}
{:else}
+
{/if}
</button>
<!-- Expandable content below button -->
{#if expanded}
<div
bind:this={formContainer}
class="w-full mt-4 flex justify-center"
transition:fade
>
<div
in:fly={{ y: 10, duration: 200, easing: cubicOut }}
out:scale={{ duration: 150 }}
class="w-full max-w-2xl"
>
<slot />
</div>
</div>
{/if}
</div>

View File

@@ -21,7 +21,7 @@
<h1 class="text-3xl text-slate-400 font-bold">Tatort</h1> <h1 class="text-3xl text-slate-400 font-bold">Tatort</h1>
<div class="lg:flex lg:justify-end w-48"> <div class="lg:flex lg:justify-end w-48">
{#if data.user} {#if data.user}
<form method="POST" action="{ROUTE_NAMES.ANMELDUNG_LOGOUT}"> <form method="POST" action="{ROUTE_NAMES.LOGOUT}">
<input type="hidden" /> <input type="hidden" />
<button type="submit" class="text-sm font-semibold leading-6 text-gray-900" <button type="submit" class="text-sm font-semibold leading-6 text-gray-900"
><span ><span

View File

@@ -13,8 +13,9 @@
// props, old syntax // props, old syntax
export let list: ListItem[] = []; export let list: ListItem[] = [];
export let currentName: string; export let currentName: string;
export let onSave: (n: string, o: string) => unknown = () => {}; export let vorgangToken: string | null;
export let onDelete: (n: string) => unknown = () => {}; export let onSave: (n: string, o: string, t?: string) => unknown = () => {};
export let onDelete: ((n: string) => unknown) | null = () => {};
let localName = currentName; let localName = currentName;
let isEditing = false; let isEditing = false;
@@ -43,7 +44,9 @@
} }
function commitEdit() { function commitEdit() {
if (!error && localName != currentName) onSave(localName, currentName); if (!error && localName != currentName) onSave(localName, currentName, vorgangToken);
// restore original value
if (error) { localName = currentName }
isEditing = false; isEditing = false;
} }
@@ -54,30 +57,60 @@
} }
function handleDeleteClick() { function handleDeleteClick() {
onDelete(currentName); // vorgangToken defined when deleting Vorgang, otherwise Crime
onDelete(vorgangToken || currentName);
} }
</script> </script>
<div data-testid="test-nameItemEditor"> <div data-testid="test-nameItemEditor" class="flex flex-col gap-1">
{#if isEditing} {#if isEditing}
<div class="flex items-center gap-1">
<input <input
data-testid="test-input" data-testid="test-input"
bind:this={inputRef} bind:this={inputRef}
bind:value={localName} bind:value={localName}
onkeydown={handleKeydown} onkeydown={handleKeydown}
class="flex-1 border border-gray-300 rounded px-1.5 py-0.5 text-sm focus:outline-none focus:ring-1 focus:ring-blue-500"
/> />
<button <button
data-testid="commit-button" data-testid="commit-button"
disabled={!!error || localName === currentName} disabled={!!error || localName === currentName}
onclick={commitEdit}><Check /></button onclick={commitEdit}
class="text-gray-500 hover:text-green-600 transition disabled:opacity-40"
> >
<button data-testid="cancel-button" onclick={cancelEdit}><X /></button> <Check class="w-4 h-4" />
</button>
<button
data-testid="cancel-button"
onclick={cancelEdit}
class="text-gray-500 hover:text-red-600 transition"
>
<X class="w-4 h-4" />
</button>
</div>
{:else} {:else}
<span>{localName}</span> <div class="flex items-center gap-1">
<button data-testid="edit-button" onclick={startEdit}><Edit /></button> <span class="text-sm font-medium text-gray-900 truncate">{localName}</span>
<button data-testid="delete-button" onclick={handleDeleteClick}><Trash /></button> <button
data-testid="edit-button"
onclick={startEdit}
class="text-gray-500 hover:text-blue-600 transition"
>
<Edit class="w-4 h-4" />
</button>
{#if onDelete}
<button
data-testid="delete-button"
onclick={handleDeleteClick}
class="text-gray-500 hover:text-red-600 transition"
>
<Trash class="w-4 h-4" />
</button>
{/if} {/if}
</div>
{/if}
{#if error} {#if error}
<p class="text-red-500">{error}</p> <p class="text-xs text-red-500 mt-1">{error}</p>
{/if} {/if}
</div> </div>

View File

@@ -12,7 +12,8 @@ export const loginUser = async ({ request, cookies }: { request: Request; cookie
const token = authenticate(user, password); const token = authenticate(user, password);
if (!token) return fail(400, { user, incorrect: true }); if (!token) return fail(400, { user, incorrect: true,
message: "Ungültige Zugangsdaten" });
cookies.set(COOKIE_NAME, token, { cookies.set(COOKIE_NAME, token, {
path: ROUTE_NAMES.ROOT, path: ROUTE_NAMES.ROOT,
@@ -26,5 +27,5 @@ export const loginUser = async ({ request, cookies }: { request: Request; cookie
export const logoutUser = async (event: RequestEvent) => { export const logoutUser = async (event: RequestEvent) => {
event.cookies.delete(COOKIE_NAME, { path: ROUTE_NAMES.ROOT }); event.cookies.delete(COOKIE_NAME, { path: ROUTE_NAMES.ROOT });
event.locals.user = null; event.locals.user = null;
return { success: true }; return redirect(303, ROUTE_NAMES.ROOT);
}; };

View File

@@ -1,6 +1,7 @@
import { fail } from '@sveltejs/kit'; import { fail } from '@sveltejs/kit';
import { BUCKET, client, CONFIGFILENAME, TOKENFILENAME } from '$lib/minio'; import { BUCKET, client, CONFIGFILENAME, TOKENFILENAME } from '$lib/minio';
import { checkIfExactDirectoryExists, getContentOfTextObject } from './s3ClientService'; import { checkIfExactDirectoryExists, getContentOfTextObject } from './s3ClientService';
import { v4 as uuidv4 } from 'uuid';
import { db } from './dbService'; import { db } from './dbService';
@@ -45,6 +46,31 @@ export const getVorgangByToken = (
return result; return result;
}; };
/**
* Create Vorgang, using a vorgangName and vorgangPIN
* @param vorgangName
* @param vorgangPIN
* @returns {string || false} vorgangToken if successful
*/
export const createVorgang = (vorgangName: string, vorgangPIN: string): string | boolean => {
const vorgangExists = vorgangNameExists(vorgangName);
if (vorgangExists) {
return false;
}
const vorgangToken = uuidv4();
const insertSQLStatement = `INSERT INTO cases (token, name, pin) VALUES (?, ?, ?)`;
const statement = db.prepare(insertSQLStatement);
const info = statement.run(vorgangToken, vorgangName, vorgangPIN);
if (info.changes) {
return vorgangToken;
} else {
return false;
}
};
/** /**
* Get Vorgang * Get Vorgang
* @param vorgangName * @param vorgangName
@@ -208,3 +234,27 @@ export const vorgangPINValidation = function (vorgangToken: string, vorgangPIN:
return true; return true;
}; };
/**
* Change VorgangName or VorgangPIN
* @param vorgangToken
* @param newValue
* @returns {int} number of affected lines
*/
export const updateVorgangAttrByToken = function (vorgangToken: string,
newValue: string,
column: string) {
const renameSQLStmt = `UPDATE cases set ${column} = ? WHERE token = ?`;
const statement = db.prepare(renameSQLStmt);
let info;
try {
info = statement.run(newValue, vorgangToken);
} catch (err) {
console.log(`error: ${err}`)
return 0;
}
return info.changes;
};

View File

@@ -1,12 +1,10 @@
import { redirect, type ServerLoadEvent } from '@sveltejs/kit'; import { type ServerLoadEvent } from '@sveltejs/kit';
import type { PageServerLoad } from '../anmeldung/$types'; import type { PageServerLoad } from '../anmeldung/$types';
import { ROUTE_NAMES } from '..';
export const load: PageServerLoad = (event: ServerLoadEvent) => { export const load: PageServerLoad = (event: ServerLoadEvent) => {
if (!event.locals.user && event.url.pathname !== ROUTE_NAMES.ANMELDUNG) if (event.locals.user) {
throw redirect(303, ROUTE_NAMES.ANMELDUNG);
return { return {
user: event.locals.user user: event.locals.user
}; };
}
}; };

View File

@@ -5,6 +5,8 @@
export let data; export let data;
</script> </script>
{#if data.user?.admin}
<div class="h-screen v-screen flex flex-col"> <div class="h-screen v-screen flex flex-col">
<div class="flex flex-col h-full"> <div class="flex flex-col h-full">
<Header {data}/> <Header {data}/>
@@ -16,3 +18,10 @@
</div> </div>
</div> </div>
{:else}
<div class="h-screen bg-white"><slot /></div>
{/if}

View File

@@ -0,0 +1,6 @@
import { loginUser, logoutUser } from '$lib/server/authService';
export const actions = {
login: ({ request, cookies }) => loginUser({ request, cookies }),
logout: (event) => logoutUser(event),
} as const;

View File

@@ -2,18 +2,21 @@
import AddProcess from '$lib/icons/Add-Process.svelte'; import AddProcess from '$lib/icons/Add-Process.svelte';
import FileRect from '$lib/icons/File-rect.svelte'; import FileRect from '$lib/icons/File-rect.svelte';
import ListIcon from '$lib/icons/List-icon.svelte'; import ListIcon from '$lib/icons/List-icon.svelte';
import Button from '$lib/components/Button.svelte';
import ArrowRight from '$lib/icons/Arrow-right.svelte';
import { ROUTE_NAMES } from '../index.js'; import { ROUTE_NAMES } from '../index.js';
export let data; export let data;
export let form;
export let outline = true; export let outline = true;
</script> </script>
{#if data.user?.admin}
<div <div
class=" inset-x-0 top-0 -z-10 h-full flex items-center justify-center bg-white shadow-lg ring-1 ring-gray-900/5" class=" inset-x-0 top-0 -z-10 h-full flex items-center justify-center bg-white shadow-lg ring-1 ring-gray-900/5"
> >
<div class="mx-auto flex justify-center max-w-7xl py-10 px-8 w-full"> <div class="mx-auto flex justify-center max-w-7xl py-10 px-8 w-full">
{#if data.user.admin}
<div class="group relative rounded-lg p-6 text-sm leading-6 hover:bg-gray-50 w-1/4"> <div class="group relative rounded-lg p-6 text-sm leading-6 hover:bg-gray-50 w-1/4">
<div <div
class="flex h-11 w-11 items-center justify-center rounded-lg bg-gray-50 group-hover:bg-white" class="flex h-11 w-11 items-center justify-center rounded-lg bg-gray-50 group-hover:bg-white"
@@ -28,21 +31,6 @@
Verschaffe Dir einen Überblick über alle gespeicherten Tatorte. Verschaffe Dir einen Überblick über alle gespeicherten Tatorte.
</p> </p>
</div> </div>
{/if}
{#if data.user.admin}
<div class="group relative rounded-lg p-6 text-sm leading-6 hover:bg-gray-50 w-1/4">
<div
class="flex h-11 w-11 items-center justify-center rounded-lg bg-gray-50 group-hover:bg-white"
>
<AddProcess class=" group-hover:text-indigo-600" />
</div>
<a href="{ROUTE_NAMES.UPLOAD}" class="mt-6 block font-semibold text-gray-900">
Hinzufügen
<span class="absolute inset-0"></span>
</a>
<p class="mt-1 text-gray-600">Fügen Sie einem Tatort Bilder hinzu.</p>
</div>
{/if}
<div class="group relative rounded-lg p-6 text-sm leading-6 hover:bg-gray-50 w-1/4"> <div class="group relative rounded-lg p-6 text-sm leading-6 hover:bg-gray-50 w-1/4">
<div <div
class="flex h-11 w-11 items-center justify-center rounded-lg bg-gray-50 group-hover:bg-white" class="flex h-11 w-11 items-center justify-center rounded-lg bg-gray-50 group-hover:bg-white"
@@ -58,5 +46,64 @@
</div> </div>
</div> </div>
{:else}
<div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8">
<div class="sm:mx-auto sm:w-full sm:max-w-sm">
<img class="mx-auto h-10 w-auto" src="/Landeswappen_NI.svg" alt="Landeswappen Niedersachsen" />
<h2 class="mt-10 text-center text-2xl font-bold leading-9 tracking-tight text-gray-900">
Willkommen beim 3D Tatort
</h2>
</div>
<div class="w-full max-w-sm mx-auto">
<div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1">
<div class="mt-10">
<form action="{ROUTE_NAMES.LOGIN}" method="POST">
<div>
<label for="user" class="text-sm font-medium leading-6 text-gray-900">Name</label>
<div class="mt-2">
<input
id="user"
name="user"
type="text"
autocomplete="email"
required
class="rounded-md border-0 py-1.5 text-gray-900 shadow-sm ring-1 ring-inset ring-gray-300 placeholder:text-gray-400 focus:ring-2 focus:ring-inset focus:ring-indigo-600 sm:text-sm sm:leading-6"
/>
</div>
</div>
<div>
<label for="password" class="block text-sm font-medium leading-6 text-gray-900"
>Passwort</label
>
<div class="mt-2">
<input
id="password"
name="password"
type="password"
autocomplete="current-password"
required
class="block w-full rounded-md border-0 py-1.5 text-gray-900 shadow-sm ring-1 ring-inset ring-gray-300 placeholder:text-gray-400 focus:ring-2 focus:ring-inset focus:ring-indigo-600 sm:text-sm sm:leading-6"
/>
</div>
</div>
{#if form?.incorrect}
<p class="block text-sm leading-6 text-red-900 mt-2">{form.message}</p>
{/if}
<div class="flex justify-end">
<Button type="submit" class="mt-5">Anmelden</Button>
</div>
</form>
</div>
</div>
</div>
</div>
{/if}
<style> <style>
</style> </style>

View File

@@ -1,10 +1,35 @@
import { getVorgaenge } from '$lib/server/vorgangService'; import { createVorgang, getVorgaenge } from '$lib/server/vorgangService';
import type { PageServerLoad } from '../../(token-based)/view/$types'; import type { PageServerLoad } from '../../(token-based)/view/$types';
import { error, fail } from '@sveltejs/kit';
export const load: PageServerLoad = async (event) => {
if (!event.locals.user) {
error(404, 'Not Found')
}
export const load: PageServerLoad = async () => {
const vorgangList = getVorgaenge(); const vorgangList = getVorgaenge();
return { return {
vorgangList vorgangList
}; };
}; };
export const actions = {
default: async ({ request }: { request: Request }) => {
const data = await request.formData();
const vorgangName: string | null = data.get('vorgang') as string;
const vorgangPIN: string | null = data.get('pin') as string;
const err = {};
const token = createVorgang(vorgangName, vorgangPIN);
if (!token) {
err.message = "Der Vorgang konnte nicht angelegt werden"
return fail(400, err)
} else {
// success
return { token }
}
}
};

View File

@@ -1,24 +1,94 @@
<script lang="ts"> <script lang="ts">
import ExpandableForm from '$lib/components/ExpandableForm.svelte';
import Trash from '$lib/icons/Trash.svelte'; import Trash from '$lib/icons/Trash.svelte';
import Folder from '$lib/icons/Folder.svelte'; import Folder from '$lib/icons/Folder.svelte';
import EmptyList from '$lib/components/EmptyList.svelte'; import EmptyList from '$lib/components/EmptyList.svelte';
import NameItemEditor from '$lib/components/NameItemEditor.svelte';
import Alert from '$lib/components/Alert.svelte';
import Button from '$lib/components/Button.svelte';
import Modal from '$lib/components/Modal/Modal.svelte';
import ModalTitle from '$lib/components/Modal/ModalTitle.svelte';
import ModalContent from '$lib/components/Modal/ModalContent.svelte';
import ModalFooter from '$lib/components/Modal/ModalFooter.svelte';
import { API_ROUTES, ROUTE_NAMES } from '../../index.js'; import { API_ROUTES, ROUTE_NAMES } from '../../index.js';
import { invalidateAll } from '$app/navigation';
let { data } = $props(); let { data, form } = $props();
let vorgangList = data.vorgangList; let vorgangList = $state(data.vorgangList);
// same as `vorgangList` but with one different property to be used
// with ´NameItemEditor`
const derivedList = $derived.by(
() => {
return vorgangList.map(
({ vorgangName, ...rest }) => (
{
name: vorgangName,
...rest
}
)
)
}
);
let isEmptyList = vorgangList.length === 0; let isEmptyList = vorgangList.length === 0;
async function delete_item(ev: Event) { let vorgangName = $state('');
let vorgangPIN = $state('');
let errorMsg = $state('');
// reset input fields when submission successful
$effect(() => {
if (form?.token) {
vorgangName = '';
vorgangPIN = '';
errorMsg = '';
}
});
async function submitVorgang(ev: Event) {
const isValid = inputValid(vorgangName, vorgangPIN);
if (!isValid) {
ev.preventDefault();
return;
}
// continue form action on server
}
/**
* Check for required fields
* @param vorgangName
* @param vorgangPIN
* @returns {boolean} Indicates whether input is valid
*/
function inputValid(vorgangName, vorgangPIN) {
if (!(vorgangName || vorgangPIN)) {
errorMsg = 'Bitte beide Felder ausfüllen.';
return false;
} else if (!vorgangName) {
errorMsg = 'Bitte einen Vorgangsnamen vergeben.';
return false;
} else if (!vorgangPIN) {
errorMsg = 'Bitte einen Vorgangs-PIN eingeben.';
return false;
}
const existing = vorgangList.some((vorg) => vorg.vorgangName === vorgangName);
if (existing) {
errorMsg = 'Der Name existiert bereits.';
return false;
}
return true;
}
async function deleteVorgang(vorgangToken: string) {
let delete_item = window.confirm('Bist du sicher?'); let delete_item = window.confirm('Bist du sicher?');
if (delete_item) { if (delete_item) {
const target = ev.currentTarget as HTMLElement | null; let url = API_ROUTES.VORGANG(vorgangToken);
if (!target) return;
let filename = target.id.split('del__')[1];
let url = API_ROUTES.VORGANG(filename);
try { try {
const response = await fetch(url, { method: 'DELETE' }); const response = await fetch(url, { method: 'DELETE' });
@@ -36,6 +106,46 @@
} }
} }
} }
//Variablen für Modal
let open = $state(false);
let inProgress = $state(false);
let isError = $state(false);
async function handleSave(newName: string, oldName: string, vorgangToken: string) {
open = true;
inProgress = true;
isError = false;
try {
const res = await fetch(API_ROUTES.VORGANG(vorgangToken), {
method: 'PUT',
headers: {
'Content-Type': 'application/json'
},
body: JSON.stringify({ vorgangToken, oldName, newName })
});
if (!res.ok) {
throw new Error('Fehler beim Speichern');
}
await invalidateAll();
vorgangList = data.vorgangList;
open = false;
} catch (err) {
console.error('⚠️ Netzwerkfehler beim Speichern', err);
isError = true;
} finally {
inProgress = false;
}
}
async function closeModal() {
open = false;
isError = false;
}
</script> </script>
<div class="-z-10 bg-white"> <div class="-z-10 bg-white">
@@ -49,30 +159,21 @@
{:else} {:else}
{#each vorgangList as vorgangItem} {#each vorgangList as vorgangItem}
<li data-testid="test-list-item"> <li data-testid="test-list-item">
<div class="flex items-center justify-center gap-3">
<a <a
href="{ROUTE_NAMES.VORGANG(vorgangItem.vorgangToken)}" href="{ROUTE_NAMES.VORGANG(vorgangItem.vorgangToken)}"
class="flex justify-between gap-x-6 py-5" class="flex flex-col items-center justify-center gap-2 py-4 rounded-lg hover:bg-gray-50 transition text-center"
> >
<div class="flex gap-x-4"> <Folder class="w-6 h-6 text-gray-600" />
<Folder />
<div class="min-w-0 flex-auto">
<span class="text-sm font-semibold leading-6 text-gray-900"
>{vorgangItem.vorgangName}</span
>
<button
style="padding: 2px"
id="del__{vorgangItem.vorgangToken}"
on:click|preventDefault={delete_item}
aria-label="Vorgang {vorgangItem.name} löschen"
>
<Trash />
</button>
</div>
</div>
<div class="hidden sm:flex sm:flex-col sm:items-end">
<p class="text-sm leading-6 text-gray-900">Vorgang</p>
</div>
</a> </a>
<NameItemEditor
list={derivedList}
currentName={vorgangItem.vorgangName}
vorgangToken={vorgangItem.vorgangToken}
onSave={handleSave}
onDelete={deleteVorgang}
/>
</div>
</li> </li>
{/each} {/each}
{/if} {/if}
@@ -80,8 +181,84 @@
</div> </div>
</div> </div>
<ExpandableForm>
<form class="flex flex-col items-center" method="POST">
<div class="flex flex-col sm:flex-row sm:space-x-4 w-full max-w-lg">
<div class="flex-1">
<label for="vorgang" class="block text-sm font-medium leading-6 text-gray-900">
<span class="flex"> Vorgangsname </span>
</label>
<div class="mt-2">
<div
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
required
bind:value={vorgangName}
type="text"
name="vorgang"
id="vorgang"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/>
</div>
</div>
</div>
<div class="flex-1 mt-4 sm:mt-0">
<label for="pin" class="block text-sm font-medium leading-6 text-gray-900">
<span class="flex"> PIN </span>
</label>
<div class="mt-2">
<div
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
required
type="password"
bind:value={vorgangPIN}
name="pin"
id="pin"
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/>
</div>
</div>
</div>
</div>
{#if errorMsg}
<p>{errorMsg}</p>
{/if}
{#if form?.message}
<p>{form.message}</p>
{/if}
<button
type="submit"
on:click={submitVorgang}
class="mt-4 bg-indigo-600 text-white px-6 py-2 rounded hover:bg-indigo-700 transition"
>
Neuen Vorgang hinzufügen
</button>
</form>
</ExpandableForm>
<Modal {open}
><ModalTitle>Umbenennen</ModalTitle><ModalContent>
{#if inProgress}
<p class="py-2 mb-1">Vorgang läuft...</p>
{:else if isError}
<Alert class="w-full" type="error">Fehler beim Umbenennen</Alert>
{:else}
<Alert class="w-full">Umbenennen erfolgreich</Alert>
{/if}
</ModalContent>
<ModalFooter><Button disabled={inProgress} on:click={closeModal}>Ok</Button></ModalFooter>
</Modal>
<style> <style>
ul { ul {
min-width: 24rem; min-width: 24rem;
} }
</style> </style>

View File

@@ -1,10 +1,8 @@
import { Readable } from 'stream'; import { Readable } from 'stream';
import { BUCKET, client } from '$lib/minio'; import { BUCKET, client } from '$lib/minio';
import { fail } from '@sveltejs/kit'; import { fail, error } from '@sveltejs/kit';
import { v4 as uuidv4 } from 'uuid';
import { db } from '$lib/server/dbService'; import { getVorgangByName } from '$lib/server/vorgangService';
import { getVorgangByName, vorgangNameExists } from '$lib/server/vorgangService';
const isRequiredFieldValid = (value: unknown) => { const isRequiredFieldValid = (value: unknown) => {
if (value == null) return false; if (value == null) return false;
@@ -20,26 +18,11 @@ export const actions = {
const vorgangName: string | null = data.get('vorgang') as string; const vorgangName: string | null = data.get('vorgang') as string;
const crimeName: string | null = data.get('name') as string; const crimeName: string | null = data.get('name') as string;
const type: string | null = data.get('type') as string; const type: string | null = data.get('type') as string;
const vorgangPIN: string | null = data.get('vorgangPIN') as string;
const fileName: string | null = data.get('fileName') as string; const fileName: string | null = data.get('fileName') as string;
const vorgangExists = vorgangNameExists(vorgangName);
let vorgangToken; let vorgangToken;
if (!vorgangExists) {
vorgangToken = uuidv4();
const insertSQLStatement = `INSERT INTO cases (token, name, pin) VALUES (?, ?, ?)`;
const statement = db.prepare(insertSQLStatement);
statement.run(vorgangToken, vorgangName, vorgangPIN);
} else {
const vorgang = getVorgangByName(vorgangName); const vorgang = getVorgangByName(vorgangName);
vorgangToken = vorgang.token; vorgangToken = vorgang.token;
if (vorgang && vorgang.pin != vorgangPIN) {
const updateSQLStmt = `UPDATE cases SET pin = ? WHERE token = ?`;
const statement = db.prepare(updateSQLStmt);
statement.run(vorgangPIN, vorgangToken);
}
}
let objectName = `${vorgangToken}/${crimeName}`; let objectName = `${vorgangToken}/${crimeName}`;
switch (type) { switch (type) {
@@ -60,7 +43,6 @@ export const actions = {
const data = Object.fromEntries(requestData); const data = Object.fromEntries(requestData);
const vorgang = data.vorgang; const vorgang = data.vorgang;
const name = data.name; const name = data.name;
const vorgangPIN = data.vorgangPIN;
let success = true; let success = true;
const err = {}; const err = {};
if (isRequiredFieldValid(vorgang)) { if (isRequiredFieldValid(vorgang)) {
@@ -77,13 +59,6 @@ export const actions = {
success = false; success = false;
} }
if (isRequiredFieldValid(vorgangPIN)) {
err.vorgangPIN = null;
} else {
err.vorgangPIN = 'Das Feld Zugangspasswort darf nicht leer bleiben.';
success = false;
}
if (success) return { success }; if (success) return { success };
return fail(400, err); return fail(400, err);
@@ -123,3 +98,10 @@ export const actions = {
return { etag, error }; return { etag, error };
} }
}; };
export const load: PageServerLoad = async (event) => {
if (!event.locals.user) {
error(404, 'Not found')
}
};

View File

@@ -0,0 +1,8 @@
import type { PageServerLoad } from '../../(token-based)/view/$types';
import { error } from '@sveltejs/kit';
export const load: PageServerLoad = async (event) => {
if (!event.locals.user) {
error(404, 'Not Found')
}
};

View File

@@ -0,0 +1,23 @@
import { getCrimesListByToken, getVorgaenge } from '$lib/server/vorgangService.js';
import type { PageServerLoad } from './$types';
export const load: PageServerLoad = async ({ params, url }) => {
const vorgangList = getVorgaenge();
const vorgangToken = params.vorgang;
const crimesList = await getCrimesListByToken(vorgangToken);
const vorgang = vorgangList.find((v) => v.vorgangToken === vorgangToken); //vorgang sollte ein eigener Typ werden, und dann kann man es hier vernünftig typisieren
if (!vorgang || !crimesList) {
throw new Error(`Fehlgeschlagen, es wurden keine Daten zum token gefunden`);
}
//Variabeln für NameItemEditor
const crimeNames: string[] = crimesList.map((l) => l.name);
return {
vorgang,
vorgangList,
crimesList,
url,
crimeNames
};
}

View File

@@ -1,7 +1,8 @@
<script lang="ts"> <script lang="ts">
import shortenFileSize from '$lib/helper/shortenFileSize'; import shortenFileSize from '$lib/helper/shortenFileSize';
import timeElapsed from '$lib/helper/timeElapsed'; import timeElapsed from '$lib/helper/timeElapsed';
import { deserialize } from '$app/forms';
import ExpandableForm from '$lib/components/ExpandableForm.svelte';
import Alert from '$lib/components/Alert.svelte'; import Alert from '$lib/components/Alert.svelte';
import Button from '$lib/components/Button.svelte'; import Button from '$lib/components/Button.svelte';
import Modal from '$lib/components/Modal/Modal.svelte'; import Modal from '$lib/components/Modal/Modal.svelte';
@@ -12,10 +13,12 @@
import { invalidateAll } from '$app/navigation'; import { invalidateAll } from '$app/navigation';
import NameItemEditor from '$lib/components/NameItemEditor.svelte'; import NameItemEditor from '$lib/components/NameItemEditor.svelte';
import EmptyList from '$lib/components/EmptyList.svelte'; import EmptyList from '$lib/components/EmptyList.svelte';
import FileRect from '$lib/icons/File-rect.svelte';
import Exclamation from '$lib/icons/Exclamation.svelte';
import { API_ROUTES, ROUTE_NAMES } from '../../../index.js'; import { API_ROUTES, ROUTE_NAMES } from '../../../index.js';
//Seite für die Tatort-Liste //Seite für die Tatort-Liste
let { data } = $props(); let { data, form } = $props();
interface ListItem { interface ListItem {
//sollte Typ Vorgang sein, aber der einfachheit ist es noch ListItem, damit die Komponente NameItemEditor für Vorgang und Tatort eingesetzt werden kann //sollte Typ Vorgang sein, aber der einfachheit ist es noch ListItem, damit die Komponente NameItemEditor für Vorgang und Tatort eingesetzt werden kann
@@ -33,6 +36,126 @@
let vorgangToken: string = data.vorgang.vorgangToken; let vorgangToken: string = data.vorgang.vorgangToken;
let isEmptyList = $derived(crimesList.length === 0); let isEmptyList = $derived(crimesList.length === 0);
// File Upload Variablen
let name = $state('');
let formErrors: Record<string, any> | null = $state(null);
let etag: string | null = $state(null);
let files: FileList | null = $state(null);
// Model Variablen für Upload
let openUL = $state(false);
let inProgressUL = $state(form === null);
async function buttonClick(event: MouseEvent) {
if (!(await validateForm())) {
event.preventDefault();
return;
}
const url = await getUrl();
openUL = true;
inProgressUL = true;
fetch(url, { method: 'PUT', body: files[0] })
.then((response) => {
inProgressUL = false;
etag = '123';
})
.catch((err) => {
inProgressUL = false;
etag = null;
console.log('ERROR', err);
});
}
async function validateForm() {
let data = new FormData();
data.append('vorgang', vorgangName);
data.append('name', name);
const response = await fetch(ROUTE_NAMES.UPLOAD_VALIDATE, { method: 'POST', body: data });
const result = deserialize(await response.text());
let success = true;
if (result.type === 'success') {
formErrors = null;
} else {
if (result.type === 'failure' && result.data) formErrors = result.data;
success = false;
}
if (!files?.length) {
formErrors = { file: 'Sie haben keine Datei ausgewählt.', ...formErrors };
success = false;
}
if (!(await check_valid_glb_file())) {
formErrors = { file: 'Keine gültige .GLD-Datei', ...formErrors };
success = false;
}
return success;
}
async function uploadSuccessful() {
openUL = false;
name = '';
files = null;
await invalidateAll();
crimesList = data.crimesList;
}
// `val` is hex string
function swap_endian(val) {
// from https://www.geeksforgeeks.org/bit-manipulation-swap-endianness-of-a-number/
let leftmost_byte = (val & eval(0x000000ff)) >> 0;
let left_middle_byte = (val & eval(0x0000ff00)) >> 8;
let right_middle_byte = (val & eval(0x00ff0000)) >> 16;
let rightmost_byte = (val & eval(0xff000000)) >> 24;
leftmost_byte <<= 24;
left_middle_byte <<= 16;
right_middle_byte <<= 8;
rightmost_byte <<= 0;
let res = leftmost_byte | left_middle_byte | right_middle_byte | rightmost_byte;
return res;
}
async function check_valid_glb_file() {
// GLD Header, magic value 0x46546C67, identifies data as binary glTF, 4 bytes
// little endian!
const GLD_MAGIC = 0x46546c67;
// big endian!
let file = files[0];
let file_header = file.slice(0, 4);
console.log(file_header);
let header_bytes = await file_header.bytes();
let file_header_hex = '0x' + header_bytes.toHex().toString();
if (GLD_MAGIC == swap_endian(file_header_hex)) {
return true;
} else {
return false;
}
return true;
}
async function getUrl() {
let data = new FormData();
data.append('vorgang', vorgangName);
data.append('name', name);
if (files?.length === 1) {
data.append('type', files[0].type);
data.append('fileName', files[0].name);
}
const response = await fetch(ROUTE_NAMES.UPLOAD_URL, { method: 'POST', body: data });
const result = deserialize(await response.text());
if (result.type === 'success') return result.data?.url;
return null;
}
//Variablen für Modal //Variablen für Modal
let open = $state(false); let open = $state(false);
let inProgress = $state(false); let inProgress = $state(false);
@@ -67,6 +190,34 @@
} }
} }
async function savePIN(newVorgangPIN: string, oldVorgangPIN: string) {
open = true;
inProgress = true;
isError = false;
try {
const res = await fetch(API_ROUTES.VORGANG(vorgangToken), {
method: 'PUT',
headers: {
'Content-Type': 'application/json'
},
body: JSON.stringify({ vorgangToken, oldVorgangPIN, newVorgangPIN,
changePIN: true})
});
if (!res.ok) {
throw new Error('Fehler beim Speichern');
}
await invalidateAll();
crimesList = data.crimesList;
open = false;
} catch (err) {
console.error('⚠️ Netzwerkfehler beim Speichern', err);
isError = true;
} finally {
inProgress = false;
}
}
async function handleDelete(tatort: string) { async function handleDelete(tatort: string) {
open = true; open = true;
inProgress = true; inProgress = true;
@@ -125,10 +276,18 @@ Mit freundlichen Grüßen,
{#if data.vorgang && crimesList} {#if data.vorgang && crimesList}
<div class="-z-10 bg-white"> <div class="-z-10 bg-white">
<div class="flex flex-col items-center justify-center w-full"> <div class="flex flex-col items-center justify-center w-full">
<h1 class="text-xl">Vorgang {vorgangName}</h1> <h1 class="text-xl">{vorgangName}</h1>
{#if admin} {#if admin}
Zugangs-PIN: {vorgangPIN} <div class="flex items-center gap-2">
Zugangs-PIN:
<NameItemEditor
list={[]}
currentName={vorgangPIN}
onSave={savePIN}
onDelete={null}
/>
</div>
<a class="pt-2 pb-6" href={constructMailToLink()} <a class="pt-2 pb-6" href={constructMailToLink()}
><Button disabled={isEmptyList}>Share Link</Button></a ><Button disabled={isEmptyList}>Share Link</Button></a
> >
@@ -140,56 +299,149 @@ Mit freundlichen Grüßen,
<EmptyList></EmptyList> <EmptyList></EmptyList>
{:else} {:else}
{#each crimesList as item (item.name)} {#each crimesList as item (item.name)}
<li data-testid="test-list-item"> <li
<div class=" flex gap-x-4"> data-testid="test-list-item"
class="flex items-center justify-between gap-6 py-4 px-2 hover:bg-gray-50 rounded-lg transition"
>
<div class="flex items-center gap-4 flex-1">
<a <a
data-testid="crime-link" data-testid="crime-link"
href="{ROUTE_NAMES.CRIME(vorgangToken, item.name, vorgangPIN)}" href="{ROUTE_NAMES.CRIME(vorgangToken, item.name, vorgangPIN)}"
class=" flex justify-between gap-x-6 py-5" class="flex items-center justify-center w-8 h-8 text-gray-600 hover:text-blue-600 transition"
aria-label="{ROUTE_NAMES.CRIME(vorgangToken, item.name, vorgangPIN)}" aria-label="{ROUTE_NAMES.CRIME(vorgangToken, item.name, vorgangPIN)}"
title={item.name} title={item.name}
> >
<Cube /> <Cube class="w-5 h-5" />
</a> </a>
<div class="min-w-0 flex-auto">
<div class="flex flex-col flex-1 min-w-0">
{#if admin} {#if admin}
<NameItemEditor <NameItemEditor
list={crimesList} list={crimesList}
currentName={item.name} currentName={item.name}
onSave={handleSave} onSave={handleSave}
onDelete={handleDelete} onDelete={handleDelete}
></NameItemEditor> />
{:else} {:else}
<p <p
data-testid="test-nameItem-p" data-testid="test-nameItem-p"
class="text-sm font-semibold leading-6 text-gray-900 inline-block min-w-1" class="text-sm font-semibold leading-6 text-gray-900 truncate"
> >
{item.name} {item.name}
</p> </p>
{/if} {/if}
<!-- size left, last modified right -->
<div class="flex items-center justify-between mt-1 text-xs leading-5 text-gray-500">
{#if item.size} {#if item.size}
<p class="mt-1 truncate text-xs leading-5 text-gray-500"> <span>{shortenFileSize(item.size)}</span>
{shortenFileSize(item.size)} {:else}
</p> <span></span>
{/if} {/if}
</div>
</div>
<div class="hidden sm:flex sm:flex-col sm:items-end">
<p class="text-sm leading-6 text-gray-900">3D Tatort</p>
{#if item.lastModified} {#if item.lastModified}
<p class="mt-1 text-xs leading-5 text-gray-500"> <span>
Zuletzt geändert <time datetime="2023-01-23T13:23Z" Zuletzt geändert
>{timeElapsed(new Date(item.lastModified))}</time <time datetime={item.lastModified}>
> {timeElapsed(new Date(item.lastModified))}
</p> </time>
</span>
{/if} {/if}
</div> </div>
</div>
</div>
</li> </li>
{/each} {/each}
{/if} {/if}
</ul> </ul>
</div> </div>
{#if admin}
<div class="flex justify-center my-4">
<ExpandableForm>
<div class="mx-auto max-w-2xl">
<div class="flex flex-col items-center space-y-6">
<!-- Name Input -->
<div class="w-full max-w-md">
<label for="name" class="block text-sm font-medium leading-6 text-gray-900">
<span class="flex">
{#if formErrors?.name}
<span class="inline-block mr-1"><Exclamation /></span>
{/if} Modellname
</span>
</label>
<div class="mt-2">
<div
class="flex rounded-md shadow-sm ring-1 ring-inset ring-gray-300 focus-within:ring-2 focus-within:ring-inset focus-within:ring-indigo-600"
>
<input
bind:value={name}
type="text"
name="name"
id="name"
autocomplete={name}
class="block flex-1 border-0 bg-transparent py-1.5 pl-1 text-gray-900 placeholder:text-gray-400 focus:ring-0 sm:text-sm sm:leading-6"
/>
</div>
</div>
{#if formErrors?.name}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.name}</p>
{/if}
</div>
<!-- File Upload -->
<div class="w-full max-w-md">
<label for="file" class="block text-sm font-medium leading-6 text-gray-900">
<span class="flex">
{#if formErrors?.file}
<span class="inline-block mr-1"><Exclamation /></span>
{/if} Datei
</span>
</label>
<div
class="mt-2 flex justify-center rounded-lg border border-dashed border-gray-900/25 px-6 py-10"
>
<div class="text-center">
<FileRect />
<div class="mt-4 flex text-sm leading-6 text-gray-600">
<label
for="file"
class="relative cursor-pointer rounded-md bg-white font-semibold text-indigo-600 focus-within:outline-none focus-within:ring-2 focus-within:ring-indigo-600 focus-within:ring-offset-2 hover:text-indigo-500"
>
<span>Wähle eine Datei aus</span>
<input id="file" bind:files name="file" type="file" class="sr-only" />
</label>
<p class="pl-1">oder ziehe sie ins Feld</p>
</div>
<p class="text-xs leading-5 text-gray-600">GLB Dateien bis zu 1GB</p>
{#if files?.length}
<div class="flex justify-center text-xs mt-2">
<p class="mx-2">Datei: <span class="font-bold">{files[0].name}</span></p>
<p class="mx-2">
Größe: <span class="font-bold">{shortenFileSize(files[0].size)}</span>
</p>
</div>
{/if}
</div>
</div>
{#if formErrors?.file}
<p class="block text-sm leading-6 text-red-900 mt-2">{formErrors.file}</p>
{/if}
</div>
<div class="mt-6 flex items-center justify-end gap-x-6">
<Button
on:click={buttonClick}
class="rounded-md bg-indigo-600 px-3 py-2 text-sm font-semibold text-white shadow-sm hover:bg-indigo-500 focus-visible:outline focus-visible:outline-2 focus-visible:outline-offset-2 focus-visible:outline-indigo-600"
>
Hinzufügen
</Button>
</div>
</div>
</div>
</ExpandableForm>
</div>
{/if}
<Modal {open} <Modal {open}
><ModalTitle>Umbenennen</ModalTitle><ModalContent> ><ModalTitle>Umbenennen</ModalTitle><ModalContent>
{#if inProgress} {#if inProgress}
@@ -202,6 +454,21 @@ Mit freundlichen Grüßen,
</ModalContent> </ModalContent>
<ModalFooter><Button disabled={inProgress} on:click={closeModal}>Ok</Button></ModalFooter> <ModalFooter><Button disabled={inProgress} on:click={closeModal}>Ok</Button></ModalFooter>
</Modal> </Modal>
<Modal open={openUL}
><ModalTitle>Upload</ModalTitle><ModalContent>
{#if inProgressUL}
<p class="py-2 mb-1">Upload läuft...</p>
{:else if etag}
<Alert class="w-full">Upload erfolgreich</Alert>
{:else}
<Alert class="w-full" type="error">Fehler beim Upload</Alert>
{/if}
</ModalContent>
<ModalFooter
><Button disabled={inProgressUL} on:click={uploadSuccessful}>Ok</Button></ModalFooter
>
</Modal>
</div> </div>
{/if} {/if}

View File

@@ -1,25 +0,0 @@
import { API_ROUTES } from '../../../index.js';
export async function load({fetch, params, url}){
const vorgangResponse = await fetch(API_ROUTES.LIST);
const vorgangList = await vorgangResponse.json()
const vorgangToken = params.vorgang;
const crimesListResponse = await fetch(API_ROUTES.VORGANG(vorgangToken))
const crimesList = await crimesListResponse.json();
const vorgang = vorgangList.find(v => v.vorgangToken === vorgangToken); //vorgang sollte ein eigener Typ werden, und dann kann man es hier vernünftig typisieren
if(!vorgang || !crimesList){
throw new Error(`Fehlgeschlagen, es wurden keine Daten zum token gefunden`);
}
//Variabeln für NameItemEditor
const crimeNames: string[] = crimesList.map((l) => l.name);
return {
vorgang,
vorgangList,
crimesList,
url,
crimeNames
}
}

View File

@@ -1,19 +1,23 @@
import { dev } from '$app/environment'; import { dev } from '$app/environment';
import { loginUser, logoutUser } from '$lib/server/authService'; import { error, fail, redirect } from '@sveltejs/kit';
import { redirect } from '@sveltejs/kit';
import { ROUTE_NAMES } from '../index.js'; import { ROUTE_NAMES } from '../index.js';
import { vorgangPINValidation } from '$lib/server/vorgangService.js';
export const actions = { export const actions = {
login: ({ request, cookies }) => loginUser({ request, cookies }), default: async ({ request, cookies }) => {
logout: (event) => logoutUser(event),
getVorgangByToken: async ({ request, cookies }) => {
const data = await request.formData(); const data = await request.formData();
const vorgangToken = data.get('vorgang-token'); const vorgangToken = data.get('vorgang-token');
const vorgangPIN = data.get('vorgang-pin'); const vorgangPIN = data.get('vorgang-pin') as string;
if (!vorgangToken || !vorgangPIN) return; if (!vorgangPIN) {
return fail(400, { message: 'Bitte einen PIN eingeben.'});
}
const COOKIE_NAME = `token-${vorgangToken}` if (!vorgangPINValidation(vorgangToken, vorgangPIN)) {
return fail(400, { message: 'Falsche Zugangsdaten.'});
}
const COOKIE_NAME = `token-${vorgangToken}`;
cookies.set(COOKIE_NAME, vorgangPIN, { cookies.set(COOKIE_NAME, vorgangPIN, {
path: '/', path: '/',
httpOnly: true, httpOnly: true,
@@ -24,3 +28,8 @@ export const actions = {
throw redirect(303, ROUTE_NAMES.VORGANG(vorgangToken)); throw redirect(303, ROUTE_NAMES.VORGANG(vorgangToken));
} }
} as const; } as const;
export const load: PageServerLoad = async ({ url }) => {
const vorgang = url.searchParams.get('vorgang');
if (!vorgang) error(404, "Not Found");
};

View File

@@ -1,22 +1,15 @@
<script lang="ts"> <script lang="ts">
import BaseInputField from '$lib/components/BaseInputField.svelte'; import BaseInputField from '$lib/components/BaseInputField.svelte';
import Button from '$lib/components/Button.svelte'; import Button from '$lib/components/Button.svelte';
import Modal from '$lib/components/Modal/Modal.svelte';
import ModalContent from '$lib/components/Modal/ModalContent.svelte';
import ModalFooter from '$lib/components/Modal/ModalFooter.svelte';
import ModalTitle from '$lib/components/Modal/ModalTitle.svelte';
import ArrowRight from '$lib/icons/Arrow-right.svelte'; import ArrowRight from '$lib/icons/Arrow-right.svelte';
import Login from '$lib/icons/Login.svelte';
export let form; export let form;
export let open = false;
import { page } from '$app/state'; import { page } from '$app/state';
import { ROUTE_NAMES } from '../index.js'; import { ROUTE_NAMES } from '../index.js';
const vorgangToken = page.url.searchParams.get('vorgang'); const vorgangToken = page.url.searchParams.get('vorgang');
</script> </script>
{#if vorgangToken}
<div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8"> <div class="flex min-h-full flex-col justify-center px-6 py-12 lg:px-8">
<div class="sm:mx-auto sm:w-full sm:max-w-sm"> <div class="sm:mx-auto sm:w-full sm:max-w-sm">
<img class="mx-auto h-10 w-auto" src="/Landeswappen_NI.svg" alt="Landeswappen Niedersachsen" /> <img class="mx-auto h-10 w-auto" src="/Landeswappen_NI.svg" alt="Landeswappen Niedersachsen" />
@@ -28,14 +21,9 @@
<div class="w-full max-w-sm mx-auto"> <div class="w-full max-w-sm mx-auto">
<div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1"> <div class="relative mt-5 bg-gray-50 rounded-xl shadow-xl p-3 pt-1">
<div class="mt-10"> <div class="mt-10">
<form action="{ROUTE_NAMES.ANMELDUNG_GET_VORGANG_BY_TOKEN}" method="POST">
<BaseInputField <form method="POST">
id="vorgang-token" <input type="hidden" name="vorgang-token" value={vorgangToken} />
name="vorgang-token"
label="Vorgangskennung"
type="text"
value={vorgangToken}
/>
<div class="mt-5"> <div class="mt-5">
<BaseInputField <BaseInputField
id="vorgang-pin" id="vorgang-pin"
@@ -46,55 +34,17 @@
error={form?.error?.message} error={form?.error?.message}
/> />
</div> </div>
{#if form?.message}
<p class="block text-sm leading-6 text-red-900 mt-2">{form.message}</p>
{/if}
<div class="flex justify-end pt-4"> <div class="flex justify-end pt-4">
<Button type="submit"><ArrowRight /></Button> <Button type="submit"><ArrowRight /></Button>
</div> </div>
</form> </form>
</div> </div>
</div> </div>
<div class="flex justify-end mt-10 px-3">
<Button on:click={() => (open = true)}><Login /></Button>
</div>
</div> </div>
</div> </div>
<Modal {open}> {/if}
<ModalTitle>Anmelden</ModalTitle>
<ModalContent class="flex justify-center">
<form action="{ROUTE_NAMES.ANMELDUNG_LOGIN}" method="POST">
<div>
<label for="user" class="text-sm font-medium leading-6 text-gray-900">Kennung</label>
<div class="mt-2">
<input
id="user"
name="user"
type="text"
autocomplete="email"
required
class="rounded-md border-0 py-1.5 text-gray-900 shadow-sm ring-1 ring-inset ring-gray-300 placeholder:text-gray-400 focus:ring-2 focus:ring-inset focus:ring-indigo-600 sm:text-sm sm:leading-6"
/>
</div>
</div>
<div>
<label for="password" class="block text-sm font-medium leading-6 text-gray-900"
>Passwort</label
>
<div class="mt-2">
<input
id="password"
name="password"
type="password"
autocomplete="current-password"
required
class="block w-full rounded-md border-0 py-1.5 text-gray-900 shadow-sm ring-1 ring-inset ring-gray-300 placeholder:text-gray-400 focus:ring-2 focus:ring-inset focus:ring-indigo-600 sm:text-sm sm:leading-6"
/>
</div>
</div>
<div class="flex justify-end">
<Button type="submit" class="mt-5">Anmelden</Button>
</div>
</form>
</ModalContent>
<ModalFooter><Button on:click={() => (open = false)}>Ok</Button></ModalFooter>
</Modal>

View File

@@ -1,7 +1,6 @@
import { getVorgaenge } from '$lib/server/vorgangService'; import { getVorgaenge } from '$lib/server/vorgangService';
export async function GET({ locals }) { export async function GET() {
const vorgaenge = getVorgaenge(); const vorgaenge = getVorgaenge();
return new Response(JSON.stringify(vorgaenge), { return new Response(JSON.stringify(vorgaenge), {

View File

@@ -1,8 +1,10 @@
import { BUCKET, client } from '$lib/minio'; import { BUCKET, client } from '$lib/minio';
import { json } from '@sveltejs/kit';
import { import {
deleteVorgangByToken, deleteVorgangByToken,
getCrimesListByToken, getCrimesListByToken,
vorgangNameExists vorgangNameExists,
updateVorgangAttrByToken
} from '$lib/server/vorgangService'; } from '$lib/server/vorgangService';
export async function DELETE({ params }) { export async function DELETE({ params }) {
@@ -43,8 +45,7 @@ export async function HEAD({ params }) {
} }
} }
export async function GET({ params, locals }) { export async function GET({ params }) {
try { try {
const vorgangToken = params.vorgang; const vorgangToken = params.vorgang;
const crimesList = await getCrimesListByToken(vorgangToken); const crimesList = await getCrimesListByToken(vorgangToken);
@@ -57,3 +58,31 @@ export async function GET({ params, locals }) {
return new Response(null, { status: 500 }); return new Response(null, { status: 500 });
} }
} }
// change Vorgang properties
export async function PUT({ request }) {
const data = await request.json();
const vorgangToken = data['vorgangToken'];
const changePIN = data['changePIN'];
let attrChanged;
let newValue;
if (changePIN) {
attrChanged = 'pin';
newValue = data['newVorgangPIN']
} else {
attrChanged = 'name';
newValue = data['newName']
}
const res = updateVorgangAttrByToken(vorgangToken, newValue, attrChanged);
if (!res) {
return json({ msg: 'Fehler beim Umbenennen' }, { status: 400 });
}
return json({ success: 'success' }, { status: 200 });
}

View File

@@ -24,7 +24,7 @@ export async function GET() {
}); });
} }
export async function DELETE({ request }: { request: Request }) { export async function DELETE({ request }) {
const url_fragments = request.url.split('/'); const url_fragments = request.url.split('/');
const item = url_fragments.at(-1); const item = url_fragments.at(-1);
const vorgang = url_fragments.at(-2); const vorgang = url_fragments.at(-2);

View File

@@ -4,21 +4,14 @@ import bcrypt from 'bcrypt';
const saltRounds = 12; const saltRounds = 12;
export function GET({ locals }) { export function GET() {
if (!locals.user) {
return json({ error: 'Unauthorized' }, { status: 401 });
}
const userList = getUsers(); const userList = getUsers();
return new Response(JSON.stringify(userList)); return new Response(JSON.stringify(userList));
} }
export async function POST({ request, locals }) { export async function POST({ request }) {
if (!locals.user) {
return json({ error: 'Unauthorized' }, { status: 401 });
}
const data = await request.json(); const data = await request.json();
const userName = data.userName; const userName = data.userName;
const userPassword = data.userPassword; const userPassword = data.userPassword;

View File

@@ -1,11 +1,6 @@
import { json } from '@sveltejs/kit';
import { deleteUser } from '$lib/server/userService'; import { deleteUser } from '$lib/server/userService';
export async function DELETE({ params, locals }) { export async function DELETE({ params }) {
if (!locals.user) {
return json({ error: 'Unauthorized' }, { status: 401 });
}
const userId = params.user; const userId = params.user;
const rowCount = deleteUser(userId); const rowCount = deleteUser(userId);

View File

@@ -16,8 +16,8 @@ export const ROUTE_NAMES = {
// Anmeldung: actions // Anmeldung: actions
ANMELDUNG: '/anmeldung', ANMELDUNG: '/anmeldung',
ANMELDUNG_LOGIN: '/anmeldung?/login', LOGIN: '/?/login',
ANMELDUNG_LOGOUT: '/anmeldung?/logout', LOGOUT: '/?/logout',
ANMELDUNG_GET_VORGANG_BY_TOKEN: '/anmeldung?/getVorgangByToken', ANMELDUNG_GET_VORGANG_BY_TOKEN: '/anmeldung?/getVorgangByToken',
ANMELDUNG_VORGANG_PARAM: (vorgangToken: string) => `/anmeldung?vorgang=${vorgangToken}` ANMELDUNG_VORGANG_PARAM: (vorgangToken: string) => `/anmeldung?vorgang=${vorgangToken}`
}; };

View File

@@ -0,0 +1,37 @@
import { describe, test, expect, vi } from 'vitest';
import { handle } from '../../src/hooks.server';
const event = {
url: new URL("http://localhost/api/list"),
cookies: { get: vi.fn(() => null) },
locals: {user: null}
};
vi.mock('$lib/auth', () => ({
decryptToken: vi.fn()
}));
describe('API-Endpoints: Zugangs-Mechanismus', () => {
test('Unautorisierter Zugriff', async () => {
const resolve = vi.fn();
const response = await handle({ event, resolve });
expect(response.status).toBe(401);
const body = await response.json();
expect(body.error).toBe('Unauthorized');
expect(resolve).not.toHaveBeenCalled();
});
test('Authentifizierter Zugriff', async () => {
event.locals = {user: { id: 'admin', admin: true }}
const resolve = vi.fn(() => new Response('ok', { status: 200 }));
const response = await handle({ event, resolve });
expect(response.status).toBe(200);
expect(await response.text()).toBe('ok');
expect(resolve).toHaveBeenCalled();
});
})

View File

@@ -14,21 +14,6 @@ const event = {
}; };
describe('API-Endpoints: list', () => { describe('API-Endpoints: list', () => {
test.skip('Unerlaubter Zugriff', async () => {
const event = {
locals: {
user: null
}
};
const response = await GET(event);
expect(response.status).toBe(401);
const json = await response.json();
const errorObj = { error: 'Unauthorized' };
expect(json).toEqual(errorObj);
});
test('Leere Liste wenn keine Vorgänge existieren', async () => { test('Leere Liste wenn keine Vorgänge existieren', async () => {
vi.mocked(getVorgaenge).mockReturnValueOnce([]); vi.mocked(getVorgaenge).mockReturnValueOnce([]);

View File

@@ -31,21 +31,6 @@ const MockEvent = {
}; };
describe('API-Endpoints: list/[vorgang]', () => { describe('API-Endpoints: list/[vorgang]', () => {
test.skip('Unerlaubter Zugriff', async () => {
const event = {
locals: {
user: null
}
};
const response = await GET(event);
expect(response.status).toBe(401);
const json = await response.json();
const errorObj = { error: 'Unauthorized' };
expect(json).toEqual(errorObj);
});
test('Vorgang ohne Tatorte', async () => { test('Vorgang ohne Tatorte', async () => {
const testCrimesList = []; const testCrimesList = [];

View File

@@ -1,6 +1,7 @@
import { describe, test, expect, vi } from 'vitest'; import { describe, test, expect, vi } from 'vitest';
import { DELETE, PUT } from '$root/routes/api/list/[vorgang]/[tatort]/+server'; import { DELETE, PUT } from '$root/routes/api/list/[vorgang]/[tatort]/+server';
import { BUCKET, client } from '$lib/minio'; import { BUCKET, client } from '$lib/minio';
import { baseData } from '../fixtures';
// Mock data and methods // Mock data and methods
const fakeVorgangToken = `c399423a-ba37-4fe1-bbdf-80e5881168ff`; const fakeVorgangToken = `c399423a-ba37-4fe1-bbdf-80e5881168ff`;
@@ -22,7 +23,8 @@ vi.mock('$lib/minio', () => ({
describe('API-Endpoints: list/[vorgang]/[tatort]', () => { describe('API-Endpoints: list/[vorgang]/[tatort]', () => {
test('Löschen von Tatorten', async () => { test('Löschen von Tatorten', async () => {
const request = new Request(fakeCrimeAPIURL); const request = new Request(fakeCrimeAPIURL);
const response = await DELETE({ request }); const locals = { user: baseData.user }
const response = await DELETE({ locals, request });
expect(client.removeObject).toHaveBeenCalledWith(BUCKET, fakeCrimePath); expect(client.removeObject).toHaveBeenCalledWith(BUCKET, fakeCrimePath);
@@ -40,11 +42,12 @@ describe('API-Endpoints: list/[vorgang]/[tatort]', () => {
}) })
}); });
const params = { vorgang: fakeVorgangToken }; const params = { vorgang: fakeVorgangToken };
const locals = { user: baseData.user }
// Mock Datei nicht gefunden // Mock Datei nicht gefunden
client.statObject.mockRejectedValueOnce(new Error('NotFound')); client.statObject.mockRejectedValueOnce(new Error('NotFound'));
const response = await PUT({ params, request }); const response = await PUT({ locals, params, request });
const fakeCrimeNewPath = `${fakeVorgangToken}/${fakeCrimeNewName}`; const fakeCrimeNewPath = `${fakeVorgangToken}/${fakeCrimeNewName}`;
expect(client.statObject).toHaveBeenCalledWith(BUCKET, fakeCrimeNewPath); expect(client.statObject).toHaveBeenCalledWith(BUCKET, fakeCrimeNewPath);
@@ -62,9 +65,10 @@ describe('API-Endpoints: list/[vorgang]/[tatort]', () => {
newName: '' newName: ''
}) })
}); });
const locals = { user: baseData.user }
const params = { vorgang: fakeVorgangToken }; const params = { vorgang: fakeVorgangToken };
const response = await PUT({ params, request }); const response = await PUT({ locals, params, request });
expect(response.status).toBe(400); expect(response.status).toBe(400);
}); });
@@ -77,11 +81,12 @@ describe('API-Endpoints: list/[vorgang]/[tatort]', () => {
}) })
}); });
const params = { vorgang: fakeVorgangToken }; const params = { vorgang: fakeVorgangToken };
const locals = { user: baseData.user }
// Datei existiert bereits // Datei existiert bereits
client.statObject.mockResolvedValueOnce({}); client.statObject.mockResolvedValueOnce({});
const response = await PUT({ params, request }); const response = await PUT({ locals, params, request });
expect(response.status).toBe(400); expect(response.status).toBe(400);

View File

@@ -16,21 +16,6 @@ vi.mock('bcrypt', () => ({
})); }));
describe('API-Endpoint: Users', () => { describe('API-Endpoint: Users', () => {
test('Unerlaubter Zugriff', async () => {
const event = {
locals: {
user: null
}
};
const response = await GET(event);
expect(response.status).toBe(401);
const errorMessage = { error: 'Unauthorized' };
const json = await response.json();
expect(json).toEqual(errorMessage);
});
// [INFO] Test auf keine User nicht notwendig, da immer min. ein User vorhanden // [INFO] Test auf keine User nicht notwendig, da immer min. ein User vorhanden
// Mock eingelogter User bzw. stelle locals.user zur Verfügung // Mock eingelogter User bzw. stelle locals.user zur Verfügung

View File

@@ -1,9 +1,11 @@
import { describe, test, expect, vi } from 'vitest'; import { describe, test, expect, vi } from 'vitest';
import { GET } from '$root/routes/api/vorgang/[vorgang]/vorgangPIN/+server'; import { GET } from '$root/routes/api/vorgang/[vorgang]/vorgangPIN/+server';
import { db } from '$lib/server/dbService'; import { db } from '$lib/server/dbService';
import { baseData } from '../fixtures';
const mockEvent = { const mockEvent = {
params: { vorgang: '123' } params: { vorgang: '123' },
locals: { user: baseData.user }
}; };
vi.mock('$lib/server/dbService', () => ({ vi.mock('$lib/server/dbService', () => ({

View File

@@ -18,7 +18,13 @@ describe('NameItemEditor - Funktionalität', () => {
onDelete onDelete
}; };
test.todo('FocusIn nach Klick auf edit'); test('Focus Input nach Klick auf edit', async () => {
render(NameItemEditor, { props: baseProps });
await fireEvent.click(screen.getByTestId('edit-button'));
const input = screen.getByTestId('test-input');
expect(document.activeElement).toBe(input);
});
it('zeigt initial Edit/Delete Buttons und aktuellen Namen', () => { it('zeigt initial Edit/Delete Buttons und aktuellen Namen', () => {
render(NameItemEditor, { props: baseProps }); render(NameItemEditor, { props: baseProps });
@@ -87,7 +93,7 @@ describe('NameItemEditor - Funktionalität', () => {
expect(onSave).not.toHaveBeenCalled(); expect(onSave).not.toHaveBeenCalled();
}); });
it('ruft onSave korrekt auf bei gültigem Namen', async () => { it('ruft onSave korrekt auf bei gültigem Namen: Tatort/Crime', async () => {
render(NameItemEditor, { props: baseProps }); render(NameItemEditor, { props: baseProps });
await fireEvent.click(screen.getByTestId('edit-button')); await fireEvent.click(screen.getByTestId('edit-button'));
@@ -95,7 +101,7 @@ describe('NameItemEditor - Funktionalität', () => {
await fireEvent.input(input, { target: { value: testLocalName } }); await fireEvent.input(input, { target: { value: testLocalName } });
await fireEvent.click(screen.getByTestId('commit-button')); await fireEvent.click(screen.getByTestId('commit-button'));
expect(onSave).toHaveBeenCalledWith(testLocalName, testCurrentName); expect(onSave).toHaveBeenCalledWith(testLocalName, testCurrentName, undefined);
}); });
it('ruft onDelete korrekt auf', async () => { it('ruft onDelete korrekt auf', async () => {
@@ -117,7 +123,7 @@ describe('NameItemEditor - Funktionalität', () => {
expect(screen.getByTestId('edit-button')).toBeInTheDocument(); expect(screen.getByTestId('edit-button')).toBeInTheDocument();
}); });
it('triggert Save bei Enter-Taste', async () => { it('triggert Save bei Enter-Taste: Tatort/Crime', async () => {
render(NameItemEditor, { props: baseProps }); render(NameItemEditor, { props: baseProps });
await fireEvent.click(screen.getByTestId('edit-button')); await fireEvent.click(screen.getByTestId('edit-button'));
@@ -125,7 +131,7 @@ describe('NameItemEditor - Funktionalität', () => {
await fireEvent.input(input, { target: { value: 'ViaEnter' } }); await fireEvent.input(input, { target: { value: 'ViaEnter' } });
await fireEvent.keyDown(input, { key: 'Enter' }); await fireEvent.keyDown(input, { key: 'Enter' });
expect(onSave).toHaveBeenCalledWith('ViaEnter', testCurrentName); expect(onSave).toHaveBeenCalledWith('ViaEnter', testCurrentName, undefined);
}); });
it('bricht ab bei Escape-Taste', async () => { it('bricht ab bei Escape-Taste', async () => {

View File

@@ -41,7 +41,7 @@ export const baseData = {
vorgang: testVorgangsList[0], vorgang: testVorgangsList[0],
vorgangList: testVorgangsList, vorgangList: testVorgangsList,
crimesList: testCrimesList, crimesList: testCrimesList,
url: `https://example.com/list/${testVorgangsList[0].vorgangToken}`, url: new URL(`https://example.com/list/${testVorgangsList[0].vorgangToken}`),
crimeNames: ['modell-A', 'Fall-A'] crimeNames: ['modell-A', 'Fall-A']
}; };

View File

@@ -1,16 +1,18 @@
import { describe, it, expect, vi } from 'vitest'; import { describe, it, expect, vi } from 'vitest';
import { actions } from '$root/routes/anmeldung/+page.server'; // import { actions } from '$root/routes/anmeldung/+page.server';
import { load } from '$root/routes/(token-based)/+layout.server' // import { load } from '$root/routes/(token-based)/+layout.server'
import { actions } from '../../src/routes/anmeldung/+page.server';
import { load } from '../../src/routes/(token-based)/+layout.server';
import { baseData } from '../fixtures'; import { baseData } from '../fixtures';
import { ROUTE_NAMES } from '../../src/routes'; import { ROUTE_NAMES } from '../../src/routes';
import { dev } from '$app/environment'; import { dev } from '$app/environment';
import { vorgangExists, vorgangPINValidation } from '$lib/server/vorgangService'; import { vorgangExists, vorgangPINValidation } from '$lib/server/vorgangService';
import { Redirect } from '@sveltejs/kit'; import type { Redirect } from '@sveltejs/kit';
vi.mock('$lib/server/vorgangService', () => ({ vi.mock('$lib/server/vorgangService', () => ({
vorgangExists: vi.fn(), vorgangExists: vi.fn(),
vorgangPINValidation: vi.fn(), vorgangPINValidation: vi.fn()
})); }));
describe('Vorgang Anzeige via Token', () => { describe('Vorgang Anzeige via Token', () => {
@@ -25,6 +27,7 @@ describe('Vorgang Anzeige via Token', () => {
const mockRequest = { const mockRequest = {
formData: vi.fn().mockResolvedValue(formData) formData: vi.fn().mockResolvedValue(formData)
}; };
vi.mocked(vorgangPINValidation).mockReturnValueOnce(true);
const cookiesSet = vi.fn(); const cookiesSet = vi.fn();
@@ -37,7 +40,7 @@ describe('Vorgang Anzeige via Token', () => {
let thrownRedirect: Redirect | undefined; let thrownRedirect: Redirect | undefined;
try { try {
await actions.getVorgangByToken(event); await actions.default(event);
} catch (e) { } catch (e) {
thrownRedirect = e as Redirect; thrownRedirect = e as Redirect;
} }
@@ -47,7 +50,7 @@ describe('Vorgang Anzeige via Token', () => {
expect(thrownRedirect?.location).toBe(ROUTE_NAMES.VORGANG(vorgObj.vorgangToken)); expect(thrownRedirect?.location).toBe(ROUTE_NAMES.VORGANG(vorgObj.vorgangToken));
// Cookie wurde gesetzt // Cookie wurde gesetzt
const COOKIE_NAME = `token-${vorgObj.vorgangToken}` const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
expect(cookiesSet).toHaveBeenCalledWith(COOKIE_NAME, vorgObj.vorgangPIN, { expect(cookiesSet).toHaveBeenCalledWith(COOKIE_NAME, vorgObj.vorgangPIN, {
path: '/', path: '/',
httpOnly: true, httpOnly: true,
@@ -58,11 +61,38 @@ describe('Vorgang Anzeige via Token', () => {
it('Schlägt fehl wenn keine Daten übergeben werden', async () => { it('Schlägt fehl wenn keine Daten übergeben werden', async () => {
const formData = new FormData(); // no data const formData = new FormData(); // no data
const mockRequest = {
formData: vi.fn().mockResolvedValue(formData)
};
const cookiesSet = vi.fn();
const event = {
request: mockRequest,
cookies: {
set: cookiesSet
}
};
const result = await actions.default(event);
expect(result.status).toBe(400);
expect(result.data.message).toMatch(/PIN eingeben/i);
// Cookie wird nicht gesetzt
expect(cookiesSet).not.toHaveBeenCalled();
});
it('Falsche PIN', async () => {
// Mock formData
const vorgObj = baseData.vorgang;
const formData = new FormData();
formData.set('vorgang-token', vorgObj.vorgangToken);
formData.set('vorgang-pin', vorgObj.vorgangPIN);
const mockRequest = { const mockRequest = {
formData: vi.fn().mockResolvedValue(formData) formData: vi.fn().mockResolvedValue(formData)
}; };
// PIN-Validierung nicht erfolgreich
vi.mocked(vorgangPINValidation).mockReturnValueOnce(false);
const cookiesSet = vi.fn(); const cookiesSet = vi.fn();
const event = { const event = {
@@ -72,33 +102,33 @@ describe('Vorgang Anzeige via Token', () => {
} }
}; };
const result = await actions.getVorgangByToken(event); const result = await actions.default(event);
expect(result.status).toBe(400);
expect(result).toBeUndefined(); expect(result.data.message).toMatch(/Falsch/i);
// Cookie wird nicht gesetzt
expect(cookiesSet).not.toHaveBeenCalled();
}); });
// Nicht vorhandener Vorgang-Token nicht notwendig, da PIN-Check
// entsprechend fehlerhaft
it.skip('Nicht vorhandener Vorgang-Token', () => {});
}); });
describe('Teste Guard', () => { describe('Teste Guard', () => {
it('Lese Cookie aus', async () => { it('Lese Cookie aus', async () => {
const vorgObj = baseData.vorgang; const vorgObj = baseData.vorgang;
const COOKIE_NAME = `token-${vorgObj.vorgangToken}` const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
const cookiesGet = vi.fn().mockImplementation((key: string) => { const cookiesGet = vi.fn().mockImplementation((key: string) => {
if (key === COOKIE_NAME) return vorgObj.vorgangPIN; if (key === COOKIE_NAME) return vorgObj.vorgangPIN;
return undefined; return undefined;
}); });
// mocked objects // mocked objects
const event = { const event = {
cookies: { cookies: {
get: cookiesGet get: cookiesGet
}, },
locals: {}, locals: {},
params: {vorgang: vorgObj.vorgangToken} params: { vorgang: vorgObj.vorgangToken }
}; };
vi.mocked(vorgangExists).mockReturnValueOnce(true); vi.mocked(vorgangExists).mockReturnValueOnce(true);
vi.mocked(vorgangPINValidation).mockReturnValueOnce(true); vi.mocked(vorgangPINValidation).mockReturnValueOnce(true);
@@ -111,20 +141,19 @@ describe('Teste Guard', () => {
it('Kein Cookie gesetzt', async () => { it('Kein Cookie gesetzt', async () => {
const vorgObj = baseData.vorgang; const vorgObj = baseData.vorgang;
const COOKIE_NAME = `token-${vorgObj.vorgangToken}` const COOKIE_NAME = `token-${vorgObj.vorgangToken}`;
const cookiesGet = vi.fn().mockImplementation((key: string) => { const cookiesGet = vi.fn().mockImplementation((key: string) => {
if (key === COOKIE_NAME) return vorgObj.vorgangPIN; if (key === COOKIE_NAME) return vorgObj.vorgangPIN;
return undefined; return undefined;
}); });
// mocked objects // mocked objects
const event = { const event = {
cookies: { cookies: {
get: cookiesGet get: cookiesGet
}, },
locals: {}, locals: {},
params: {vorgang: vorgObj.vorgangToken} params: { vorgang: vorgObj.vorgangToken }
}; };
vi.mocked(vorgangExists).mockReturnValueOnce(true); vi.mocked(vorgangExists).mockReturnValueOnce(true);
vi.mocked(vorgangPINValidation).mockReturnValueOnce(false); vi.mocked(vorgangPINValidation).mockReturnValueOnce(false);
@@ -132,12 +161,14 @@ describe('Teste Guard', () => {
let thrownRedirect; let thrownRedirect;
try { try {
await load(event); await load(event);
throw new Error('Function did not throw') throw new Error('Function did not throw');
} catch (e) { } catch (e) {
thrownRedirect = e; thrownRedirect = e;
} }
expect(thrownRedirect?.status).toBe(303); expect(thrownRedirect?.status).toBe(303);
expect(thrownRedirect?.location).toBe(ROUTE_NAMES.ANMELDUNG_VORGANG_PARAM(vorgObj.vorgangToken)); expect(thrownRedirect?.location).toBe(
ROUTE_NAMES.ANMELDUNG_VORGANG_PARAM(vorgObj.vorgangToken)
);
expect(cookiesGet).toHaveBeenCalledWith(COOKIE_NAME); expect(cookiesGet).toHaveBeenCalledWith(COOKIE_NAME);
}); });

View File

@@ -13,9 +13,8 @@ describe('Home-Page View', () => {
expect(linkElement).toBeInTheDocument(); expect(linkElement).toBeInTheDocument();
expect(linkElement).toHaveAttribute('href', ROUTE_NAMES.LIST); expect(linkElement).toHaveAttribute('href', ROUTE_NAMES.LIST);
linkElement = screen.getByText('Hinzufügen'); linkElement = screen.queryByText('Hinzufügen');
expect(linkElement).toBeInTheDocument(); expect(linkElement).not.toBeInTheDocument();
expect(linkElement).toHaveAttribute('href', ROUTE_NAMES.UPLOAD);
linkElement = screen.getByText('Benutzerverwaltung'); linkElement = screen.getByText('Benutzerverwaltung');
expect(linkElement).toBeInTheDocument(); expect(linkElement).toBeInTheDocument();

View File

@@ -4,20 +4,15 @@ import { ROUTE_NAMES } from '../../src/routes';
import { baseData, mockEvent } from '../fixtures'; import { baseData, mockEvent } from '../fixtures';
describe('+layout.server load(): Teste korrekte URL', () => { describe('+layout.server load(): Teste korrekte URL', () => {
test('Werfe redirect zu /anmeldung wenn User nicht eingeloggt', async () => { test('Werfe keinen Redirect und gebe nichts zurück', async () => {
const mockEvent = { const mockEvent = {
locals: { locals: {
user: null user: null
}, },
url: new URL(`https://example.com/not-anmeldung`) url: new URL(`https://example.com/not-anmeldung`)
}; };
try { const res = load(mockEvent);
load(mockEvent); expect(res).toBe(undefined);
throw new Error('Expected load() to throw');
} catch (err) {
expect(err.status).toBe(303);
expect(err.location).toBe(ROUTE_NAMES.ANMELDUNG);
}
}); });
}); });

View File

@@ -9,11 +9,46 @@ import { API_ROUTES } from '../../src/routes';
vi.spyOn(nav, 'invalidateAll').mockResolvedValue(); vi.spyOn(nav, 'invalidateAll').mockResolvedValue();
global.fetch = vi.fn().mockResolvedValue({ ok: true }); global.fetch = vi.fn().mockResolvedValue({ ok: true });
async function clickPlusButton() {
// mock animation features of the browser
window.HTMLElement.prototype.scrollIntoView = vi.fn();
window.HTMLElement.prototype.animate = vi.fn(() => ({
finished: Promise.resolve(),
cancel: vi.fn(),
}))
// button is visible
const button = screen.getByRole('button', { name: /add item/i })
expect(button).toBeInTheDocument();
await fireEvent.click(button)
}
describe('Seite: Vorgangsansicht', () => { describe('Seite: Vorgangsansicht', () => {
test.todo('Share Link disabled wenn Liste leer'); test('Share Link disabled wenn Liste leer', () => {
const testData = { ...baseData, crimesList: [] };
render(TatortListPage, { props: { data: testData } });
const button = screen.getByRole('button', { name: /share link/i });
expect(button).toBeInTheDocument()
expect(button).toBeDisabled();
});
describe('Szenario: Admin + Liste gefüllt - Funktionalität', () => { describe('Szenario: Admin + Liste gefüllt - Funktionalität', () => {
test.todo('Share Link Link generierung richtig'); test('Share Link Link generierung richtig', () => {
const testData = { ...baseData};
render(TatortListPage, { props: { data: testData } });
const link = screen.getByRole('link', { name: /share link/i });
expect(link).toBeInTheDocument()
// const vorgangTokenFirstUUIDGroup = testData.vorgangList[0].vorgangToken.split('-')[0]
const vorgangURL = testData.url.toString()
const vorgangURLEncoded = encodeURIComponent(vorgangURL)
expect(link).toHaveAttribute('href', expect.stringContaining(vorgangURLEncoded));
});
it('führt PUT-Request aus und aktualisiert UI nach onSave', async () => { it('führt PUT-Request aus und aktualisiert UI nach onSave', async () => {
const data = structuredClone(baseData); const data = structuredClone(baseData);
@@ -83,3 +118,42 @@ describe('Seite: Vorgangsansicht', () => {
}); });
}); });
}); });
describe('Hinzufügen Button', () => {
it('Unexpandierter Button', () => {
const testData = { ...baseData, vorgangList: [] };
const { getByTestId } = render(TatortListPage, { props: { data: testData } });
const container = getByTestId('expand-container')
expect(container).toBeInTheDocument();
// button is visible
const button = within(container).getByRole('button')
expect(button).toBeInTheDocument();
// input fields are not visible
let label = screen.queryByText('Modellname');
expect(label).not.toBeInTheDocument();
});
it('Expandierter Button nach Klick', async () => {
const testData = { ...baseData, vorgangList: [] };
render(TatortListPage, { props: { data: testData } });
await clickPlusButton();
// input fields are visible
let label = screen.queryByText('Modellname');
expect(label).toBeInTheDocument();
});
it.todo('Check Validation: missing name', async () => {
console.log(`test: input field validation`);
});
it.todo('Create Tatort successful', async () => {
console.log(`test: tatort upload`);
});
});

View File

@@ -100,4 +100,16 @@ describe('Seite: Vorgangsansicht', () => {
expect(linkElement).toHaveAttribute('href', expectedURL); expect(linkElement).toHaveAttribute('href', expectedURL);
}); });
}); });
describe('PIN Anzeige & Button', () => {
it('Teste korrekte Anzeige von PIN Komponente', () => {
const testData = { ...baseData};
render(TatortListPage, { props: { data: testData } });
const vorgObj = baseData.vorgangList[0]
// PIN is being displayed within ´NameItemEditor´
let label = screen.queryByText(vorgObj.vorgangPIN);
expect(label).toBeInTheDocument();
});
});
}); });

View File

@@ -1,8 +1,18 @@
import { render, screen, within } from '@testing-library/svelte'; import { render, fireEvent, screen, within } from '@testing-library/svelte';
import { describe, expect, it } from 'vitest'; import { describe, expect, it, vi } from 'vitest';
import VorgangListPage from '$root/routes/(angemeldet)/list/+page.svelte'; import VorgangListPage from '$root/routes/(angemeldet)/list/+page.svelte';
import { baseData } from '../fixtures'; import { baseData } from '../fixtures';
import { ROUTE_NAMES } from '../../src/routes'; import { ROUTE_NAMES } from '../../src/routes';
import { actions } from '../../src/routes/(angemeldet)/list/+page.server';
import { createVorgang } from '$lib/server/vorgangService';
// mock animation features of the browser
window.HTMLElement.prototype.scrollIntoView = vi.fn();
window.HTMLElement.prototype.animate = vi.fn(() => ({
finished: Promise.resolve(),
cancel: vi.fn(),
}))
describe('Vorgänge Liste Page EmptyList-Komponente View', () => { describe('Vorgänge Liste Page EmptyList-Komponente View', () => {
it('zeigt EmptyList-Komponente an, wenn Liste leer ist', () => { it('zeigt EmptyList-Komponente an, wenn Liste leer ist', () => {
@@ -43,3 +53,132 @@ describe('Teste Links auf Korrektheit', () => {
expect(linkElement.getAttribute('href')?.toLowerCase()).not.toContain('pin'); expect(linkElement.getAttribute('href')?.toLowerCase()).not.toContain('pin');
}); });
}); });
async function clickPlusButton() {
// button is visible
const button = screen.getByTestId('expand-button')
expect(button).toBeInTheDocument();
await fireEvent.click(button)
}
async function inputVorgang() {
const input = document.getElementById("vorgang");
input.value = 'test-vorgang';
// firing the event manually for Svelte
await fireEvent.input(input)
expect(input).toHaveValue('test-vorgang');
}
async function inputVorgangPIN() {
const input = document.getElementById("pin");
input.value = 'test-pin';
// firing the event manually for Svelte
await fireEvent.input(input)
expect(input).toHaveValue('test-pin');
}
describe('Hinzufügen Buton', () => {
it('Unexpandierter Button', () => {
const testData = { ...baseData, vorgangList: [] };
const { getByTestId } = render(VorgangListPage, { props: { data: testData } });
const container = getByTestId('expand-container')
expect(container).toBeInTheDocument();
// button is visible
const button = within(container).getByRole('button')
expect(button).toBeInTheDocument();
// input fields are not visible
let label = screen.queryByText('Vorgangsname');
expect(label).not.toBeInTheDocument();
});
it('Expandierter Button nach Klick', async () => {
const testData = { ...baseData, vorgangList: [] };
render(VorgangListPage, { props: { data: testData } });
await clickPlusButton()
// input fields are visible
let label = screen.queryByText('Vorgangsname');
expect(label).toBeInTheDocument();
});
it('Check Validation: missing PIN', async () => {
const testData = { ...baseData, vorgangList: [] };
render(VorgangListPage, { props: { data: testData } });
await clickPlusButton()
// input
inputVorgang();
// submit
const button = screen.getByText('Neuen Vorgang hinzufügen')
expect(button).toBeInTheDocument()
await fireEvent.click(button);
const errorMsg = 'Bitte einen Vorgangs-PIN eingeben.';
let para = await screen.getByText(errorMsg);
expect(para).toBeInTheDocument();
});
it('Create Vorgang successful', async () => {
const testData = { ...baseData, vorgangList: [] };
render(VorgangListPage, { props: { data: testData } });
await clickPlusButton();
// input fields are visible
let label = screen.queryByText('Vorgangsname');
expect(label).toBeInTheDocument();
inputVorgang();
inputVorgangPIN();
// emulate button click
const button = screen.getByText('Neuen Vorgang hinzufügen');
expect(button).toBeInTheDocument();
await fireEvent.click(button);
// no error message
label = screen.queryByText('Bitte');
expect(label).not.toBeInTheDocument();
});
it('Test default action', async () => {
vi.mock('$lib/server/vorgangService', () => ({
createVorgang: vi.fn(),
}));
const formData = new FormData(); // no data as we are mocking createVorgang
const mockRequest = {
formData: vi.fn().mockResolvedValue(formData)
};
const event = {
request: mockRequest,
};
const testVorgangToken = 'c322f26f-8c5e-4cb9-94b3-b5433bf5109e'
vi.mocked(createVorgang).mockReturnValueOnce(testVorgangToken);
const result = await actions.default(event);
expect(result).toEqual({ token: testVorgangToken });
});
});
describe('Vorgang-Operationen', () => {
it('Teste korrekte Anzeige von Vorgang-Input Komponente', () => {
const testData = { ...baseData};
const { getAllByTestId } = render(VorgangListPage, { props: { data: testData } });
let buttons = getAllByTestId('edit-button')
expect(buttons.length).toBeGreaterThan(1);
});
});