Refactor monolithic modules and harden booking, email, and auth infrastructure.
Split oversized frontend API client, email service, and admin/booking pages into focused modules while preserving import surfaces, and add Redis-backed queues, stale booking cleanup, stronger auth, and scale deployment configs. Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
+10
-19
@@ -6,6 +6,16 @@ import { getNow } from '../lib/utils.js';
|
||||
|
||||
const adminRouter = new Hono();
|
||||
|
||||
// Escape a value for inclusion in a CSV cell (RFC 4180 quoting).
|
||||
const csvEscape = (value: string) => {
|
||||
if (value == null) return '';
|
||||
const str = String(value);
|
||||
if (str.includes(',') || str.includes('"') || str.includes('\n') || str.includes('\r')) {
|
||||
return '"' + str.replace(/"/g, '""') + '"';
|
||||
}
|
||||
return str;
|
||||
};
|
||||
|
||||
// Dashboard overview stats (admin)
|
||||
adminRouter.get('/dashboard', requireAuth(['admin', 'organizer']), async (c) => {
|
||||
const now = getNow();
|
||||
@@ -291,16 +301,6 @@ adminRouter.get('/events/:eventId/attendees/export', requireAuth(['admin']), asy
|
||||
})
|
||||
);
|
||||
|
||||
// Generate CSV
|
||||
const csvEscape = (value: string) => {
|
||||
if (value == null) return '';
|
||||
const str = String(value);
|
||||
if (str.includes(',') || str.includes('"') || str.includes('\n') || str.includes('\r')) {
|
||||
return '"' + str.replace(/"/g, '""') + '"';
|
||||
}
|
||||
return str;
|
||||
};
|
||||
|
||||
const columns = [
|
||||
'Ticket ID', 'Full Name', 'Email', 'Phone',
|
||||
'Status', 'Checked In', 'Check-in Time', 'Payment Status',
|
||||
@@ -380,15 +380,6 @@ adminRouter.get('/events/:eventId/tickets/export', requireAuth(['admin']), async
|
||||
});
|
||||
}
|
||||
|
||||
const csvEscape = (value: string) => {
|
||||
if (value == null) return '';
|
||||
const str = String(value);
|
||||
if (str.includes(',') || str.includes('"') || str.includes('\n') || str.includes('\r')) {
|
||||
return '"' + str.replace(/"/g, '""') + '"';
|
||||
}
|
||||
return str;
|
||||
};
|
||||
|
||||
const columns = ['Ticket ID', 'Booking ID', 'Attendee Name', 'Status', 'Check-in Time', 'Booked At'];
|
||||
|
||||
const rows = ticketList.map((ticket: any) => ({
|
||||
|
||||
@@ -229,6 +229,21 @@ auth.post('/login', authRateLimit, zValidator('json', loginSchema), async (c) =>
|
||||
|
||||
// Clear failed attempts on successful login
|
||||
clearFailedAttempts(data.email);
|
||||
|
||||
// Transparently upgrade legacy bcrypt hashes to argon2 now that we have the
|
||||
// plaintext and have verified it. Best-effort: a failure here must not block
|
||||
// the login.
|
||||
if (!String(user.password).startsWith('$argon2')) {
|
||||
try {
|
||||
const upgradedHash = await hashPassword(data.password);
|
||||
await (db as any)
|
||||
.update(users)
|
||||
.set({ password: upgradedHash })
|
||||
.where(eq((users as any).id, user.id));
|
||||
} catch (err: any) {
|
||||
console.error('[auth] Failed to upgrade legacy password hash:', err?.message || err);
|
||||
}
|
||||
}
|
||||
|
||||
const token = await createToken(user.id, user.email, user.role, user.tokenVersion ?? 0);
|
||||
const refreshToken = await createRefreshToken(user.id);
|
||||
|
||||
@@ -4,7 +4,7 @@ import { z } from 'zod';
|
||||
import { db, dbGet, dbAll, contacts, emailSubscribers, legalSettings } from '../db/index.js';
|
||||
import { eq, desc } from 'drizzle-orm';
|
||||
import { requireAuth } from '../lib/auth.js';
|
||||
import { generateId, getNow } from '../lib/utils.js';
|
||||
import { generateId, getNow, sanitizeHtml } from '../lib/utils.js';
|
||||
import { emailService } from '../lib/email.js';
|
||||
import { rateLimitMiddleware } from '../lib/rateLimit.js';
|
||||
|
||||
@@ -16,19 +16,6 @@ const publicFormLimit = rateLimitMiddleware({ max: 5, windowMs: 10 * 60 * 1000,
|
||||
|
||||
// ==================== Sanitization Helpers ====================
|
||||
|
||||
/**
|
||||
* Sanitize a string to prevent HTML injection
|
||||
* Escapes HTML special characters
|
||||
*/
|
||||
function sanitizeHtml(str: string): string {
|
||||
return str
|
||||
.replace(/&/g, '&')
|
||||
.replace(/</g, '<')
|
||||
.replace(/>/g, '>')
|
||||
.replace(/"/g, '"')
|
||||
.replace(/'/g, ''');
|
||||
}
|
||||
|
||||
/**
|
||||
* Sanitize email header values to prevent email header injection
|
||||
* Strips newlines and carriage returns that could be used to inject headers
|
||||
|
||||
@@ -163,9 +163,8 @@ emailsRouter.put('/templates/:id', requireAuth(['admin']), zValidator('json', up
|
||||
|
||||
const updateData: any = { updatedAt: getNow() };
|
||||
|
||||
// Only allow updating certain fields for system templates
|
||||
const systemProtectedFields = ['slug', 'isSystem'];
|
||||
|
||||
// System templates cannot have their slug or isSystem flag changed; only the
|
||||
// editable fields below are applied.
|
||||
const allowedFields = ['name', 'subject', 'subjectEs', 'bodyHtml', 'bodyHtmlEs', 'bodyText', 'bodyTextEs', 'description', 'variables', 'isActive'];
|
||||
if (!existing.isSystem) {
|
||||
allowedFields.push('slug');
|
||||
@@ -486,7 +485,7 @@ emailsRouter.post('/test', requireAuth(['admin']), async (c) => {
|
||||
|
||||
// Get email queue status
|
||||
emailsRouter.get('/queue/status', requireAuth(['admin']), async (c) => {
|
||||
const status = getQueueStatus();
|
||||
const status = await getQueueStatus();
|
||||
return c.json({ status });
|
||||
});
|
||||
|
||||
|
||||
@@ -9,24 +9,6 @@ import path from 'path';
|
||||
|
||||
const legalPagesRouter = new Hono();
|
||||
|
||||
// Helper: Convert plain text to simple markdown
|
||||
// Preserves paragraphs and line breaks, nothing fancy
|
||||
function textToMarkdown(text: string): string {
|
||||
if (!text) return '';
|
||||
|
||||
// Split into paragraphs (double newlines)
|
||||
const paragraphs = text.split(/\n\s*\n/);
|
||||
|
||||
// Process each paragraph
|
||||
const processed = paragraphs.map(para => {
|
||||
// Replace single newlines with double spaces + newline for markdown line breaks
|
||||
return para.trim().replace(/\n/g, ' \n');
|
||||
});
|
||||
|
||||
// Join paragraphs with double newlines
|
||||
return processed.join('\n\n');
|
||||
}
|
||||
|
||||
// Helper: Convert markdown to plain text for editing
|
||||
function markdownToText(markdown: string): string {
|
||||
if (!markdown) return '';
|
||||
|
||||
@@ -5,15 +5,26 @@ import { eq, and } from 'drizzle-orm';
|
||||
import { getNow } from '../lib/utils.js';
|
||||
import { verifyWebhookPayment, getPaymentStatus } from '../lib/lnbits.js';
|
||||
import emailService from '../lib/email.js';
|
||||
import { getPubSub } from '../lib/stores/pubsub.js';
|
||||
import { getLock } from '../lib/stores/lock.js';
|
||||
|
||||
const lnbitsRouter = new Hono();
|
||||
|
||||
// Store for active SSE connections (ticketId -> Set of response writers)
|
||||
// Local SSE connections owned by THIS process (ticketId -> Set of response writers).
|
||||
// Cross-instance delivery is handled by pub/sub: see paymentChannel below.
|
||||
const activeConnections = new Map<string, Set<(data: any) => Promise<void>>>();
|
||||
|
||||
// Pub/sub unsubscribe handles per ticket (one local subscription per ticket).
|
||||
const channelUnsubs = new Map<string, () => void>();
|
||||
|
||||
// Store for active background checkers (ticketId -> intervalId)
|
||||
const activeCheckers = new Map<string, NodeJS.Timeout>();
|
||||
|
||||
/** Pub/sub channel that carries payment events for a ticket. */
|
||||
function paymentChannel(ticketId: string): string {
|
||||
return `payment:${ticketId}`;
|
||||
}
|
||||
|
||||
/**
|
||||
* LNbits webhook payload structure
|
||||
*/
|
||||
@@ -32,9 +43,21 @@ interface LNbitsWebhookPayload {
|
||||
}
|
||||
|
||||
/**
|
||||
* Notify all connected clients for a ticket
|
||||
* Notify every client for a ticket across all instances.
|
||||
*
|
||||
* Publishes to the ticket's pub/sub channel. In single-instance / in-memory
|
||||
* mode this is an in-process broadcast; with Redis it reaches whichever
|
||||
* instance(s) actually hold the SSE socket(s) for this ticket.
|
||||
*/
|
||||
async function notifyClients(ticketId: string, data: any) {
|
||||
await getPubSub().publish(paymentChannel(ticketId), data);
|
||||
}
|
||||
|
||||
/**
|
||||
* Deliver an event to the SSE sockets held by THIS process for a ticket.
|
||||
* Invoked by the pub/sub subscription handler.
|
||||
*/
|
||||
async function deliverLocal(ticketId: string, data: any) {
|
||||
const connections = activeConnections.get(ticketId);
|
||||
if (connections) {
|
||||
await Promise.all(
|
||||
@@ -49,17 +72,42 @@ async function notifyClients(ticketId: string, data: any) {
|
||||
}
|
||||
}
|
||||
|
||||
// Distributed lock tokens for the per-ticket poller (ticketId -> token).
|
||||
const checkerLockTokens = new Map<string, string>();
|
||||
|
||||
/** Release the per-ticket poller lock if this process holds it. */
|
||||
function releaseCheckerLock(ticketId: string) {
|
||||
const token = checkerLockTokens.get(ticketId);
|
||||
if (token) {
|
||||
checkerLockTokens.delete(ticketId);
|
||||
void getLock().release(`checker:${ticketId}`, token);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Start background payment checking for a ticket
|
||||
* Start background payment checking for a ticket.
|
||||
*
|
||||
* Only one instance should poll LNbits per ticket, so we take a distributed
|
||||
* lock for the lifetime of the poll. Other instances skip polling and instead
|
||||
* receive the result via pub/sub. With no Redis configured the lock is a local
|
||||
* no-op and behavior matches the original single-instance polling.
|
||||
*/
|
||||
function startBackgroundChecker(ticketId: string, paymentHash: string, expirySeconds: number = 900) {
|
||||
// Don't start if already checking
|
||||
async function startBackgroundChecker(ticketId: string, paymentHash: string, expirySeconds: number = 900) {
|
||||
// Don't start if already checking on this instance
|
||||
if (activeCheckers.has(ticketId)) {
|
||||
return;
|
||||
}
|
||||
|
||||
const startTime = Date.now();
|
||||
const expiryMs = expirySeconds * 1000;
|
||||
|
||||
const lockToken = await getLock().acquire(`checker:${ticketId}`, expiryMs);
|
||||
if (!lockToken) {
|
||||
// Another instance is already polling this ticket.
|
||||
return;
|
||||
}
|
||||
checkerLockTokens.set(ticketId, lockToken);
|
||||
|
||||
const startTime = Date.now();
|
||||
let checkCount = 0;
|
||||
|
||||
console.log(`Starting background checker for ticket ${ticketId}, expires in ${expirySeconds}s`);
|
||||
@@ -73,6 +121,7 @@ function startBackgroundChecker(ticketId: string, paymentHash: string, expirySec
|
||||
console.log(`Invoice expired for ticket ${ticketId}`);
|
||||
clearInterval(checkInterval);
|
||||
activeCheckers.delete(ticketId);
|
||||
releaseCheckerLock(ticketId);
|
||||
await notifyClients(ticketId, { type: 'expired', ticketId });
|
||||
return;
|
||||
}
|
||||
@@ -84,6 +133,7 @@ function startBackgroundChecker(ticketId: string, paymentHash: string, expirySec
|
||||
console.log(`Payment confirmed for ticket ${ticketId} (check #${checkCount})`);
|
||||
clearInterval(checkInterval);
|
||||
activeCheckers.delete(ticketId);
|
||||
releaseCheckerLock(ticketId);
|
||||
|
||||
await handlePaymentComplete(ticketId, paymentHash);
|
||||
await notifyClients(ticketId, { type: 'paid', ticketId, paymentHash });
|
||||
@@ -104,6 +154,7 @@ function stopBackgroundChecker(ticketId: string) {
|
||||
if (interval) {
|
||||
clearInterval(interval);
|
||||
activeCheckers.delete(ticketId);
|
||||
releaseCheckerLock(ticketId);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -273,7 +324,7 @@ lnbitsRouter.get('/stream/:ticketId', async (c) => {
|
||||
|
||||
// Start background checker if not already running (only while still pending)
|
||||
if (ticket.status !== 'confirmed' && payment?.reference && !activeCheckers.has(ticketId)) {
|
||||
startBackgroundChecker(ticketId, payment.reference, 900); // 15 min expiry
|
||||
await startBackgroundChecker(ticketId, payment.reference, 900); // 15 min expiry
|
||||
}
|
||||
|
||||
// Prevent proxies/CDNs from buffering the event stream so events flush immediately.
|
||||
@@ -291,9 +342,15 @@ lnbitsRouter.get('/stream/:ticketId', async (c) => {
|
||||
return;
|
||||
}
|
||||
|
||||
// Register this connection
|
||||
// Register this connection. The first local connection for a ticket also
|
||||
// subscribes to the ticket's pub/sub channel so events published by any
|
||||
// instance (webhook or background checker) are delivered to these sockets.
|
||||
if (!activeConnections.has(ticketId)) {
|
||||
activeConnections.set(ticketId, new Set());
|
||||
const unsub = await getPubSub().subscribe(paymentChannel(ticketId), (data) => {
|
||||
void deliverLocal(ticketId, data);
|
||||
});
|
||||
channelUnsubs.set(ticketId, unsub);
|
||||
}
|
||||
activeConnections.get(ticketId)!.add(sendEvent);
|
||||
|
||||
@@ -317,6 +374,12 @@ lnbitsRouter.get('/stream/:ticketId', async (c) => {
|
||||
connections.delete(sendEvent);
|
||||
if (connections.size === 0) {
|
||||
activeConnections.delete(ticketId);
|
||||
// Drop the pub/sub subscription once no local sockets remain.
|
||||
const unsub = channelUnsubs.get(ticketId);
|
||||
if (unsub) {
|
||||
unsub();
|
||||
channelUnsubs.delete(ticketId);
|
||||
}
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
@@ -3,13 +3,10 @@ import { db, dbGet, dbAll, media } from '../db/index.js';
|
||||
import { eq, and } from 'drizzle-orm';
|
||||
import { requireAuth } from '../lib/auth.js';
|
||||
import { generateId, getNow } from '../lib/utils.js';
|
||||
import { writeFile, mkdir, unlink } from 'fs/promises';
|
||||
import { existsSync } from 'fs';
|
||||
import { join } from 'path';
|
||||
import { getStorage, keyFromUrl } from '../lib/storage.js';
|
||||
|
||||
const mediaRouter = new Hono();
|
||||
|
||||
const UPLOAD_DIR = './uploads';
|
||||
const MAX_FILE_SIZE =
|
||||
(Number(process.env.MEDIA_MAX_UPLOAD_MB || '10') || 10) * 1024 * 1024; // default 10MB
|
||||
|
||||
@@ -51,13 +48,6 @@ function detectImageType(buf: Buffer): { mime: string; ext: string } | null {
|
||||
return null;
|
||||
}
|
||||
|
||||
// Ensure upload directory exists
|
||||
async function ensureUploadDir() {
|
||||
if (!existsSync(UPLOAD_DIR)) {
|
||||
await mkdir(UPLOAD_DIR, { recursive: true });
|
||||
}
|
||||
}
|
||||
|
||||
// Upload image
|
||||
mediaRouter.post('/upload', requireAuth(['admin', 'organizer']), async (c) => {
|
||||
try {
|
||||
@@ -83,15 +73,13 @@ mediaRouter.post('/upload', requireAuth(['admin', 'organizer']), async (c) => {
|
||||
return c.json({ error: 'Invalid file. Allowed: JPEG, PNG, GIF, WebP, AVIF' }, 400);
|
||||
}
|
||||
|
||||
await ensureUploadDir();
|
||||
|
||||
// Generate unique filename using the *detected* extension (ignore client filename)
|
||||
const id = generateId();
|
||||
const filename = `${id}${detected.ext}`;
|
||||
const filepath = join(UPLOAD_DIR, filename);
|
||||
|
||||
// Write file
|
||||
await writeFile(filepath, buffer);
|
||||
|
||||
// Persist via the storage backend (local disk or S3-compatible object store).
|
||||
const storage = getStorage();
|
||||
await storage.put(filename, buffer, detected.mime);
|
||||
|
||||
// Get related info from form data
|
||||
const relatedId = body['relatedId'] as string | undefined;
|
||||
@@ -101,7 +89,7 @@ mediaRouter.post('/upload', requireAuth(['admin', 'organizer']), async (c) => {
|
||||
const now = getNow();
|
||||
const mediaRecord = {
|
||||
id,
|
||||
fileUrl: `/uploads/${filename}`,
|
||||
fileUrl: storage.publicUrl(filename),
|
||||
type: 'image' as const,
|
||||
relatedId: relatedId || null,
|
||||
relatedType: relatedType || null,
|
||||
@@ -147,12 +135,9 @@ mediaRouter.delete('/:id', requireAuth(['admin', 'organizer']), async (c) => {
|
||||
return c.json({ error: 'Media not found' }, 404);
|
||||
}
|
||||
|
||||
// Delete file from disk
|
||||
// Delete the underlying object from the storage backend.
|
||||
try {
|
||||
const filepath = join('.', mediaRecord.fileUrl);
|
||||
if (existsSync(filepath)) {
|
||||
await unlink(filepath);
|
||||
}
|
||||
await getStorage().delete(keyFromUrl(mediaRecord.fileUrl));
|
||||
} catch (error) {
|
||||
console.error('Failed to delete file:', error);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user