mirror of
https://github.com/donpat1to/Schichtenplaner.git
synced 2025-12-01 15:05:45 +01:00
Compare commits
12 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 23f1dd7aa0 | |||
| 5319ed5d7a | |||
| 65ebf1748b | |||
| 4321763a2b | |||
| 24525043e9 | |||
| d870523685 | |||
| 50a1f1a9b9 | |||
| 1927937109 | |||
| b3b3250f23 | |||
| 5f8a6bef31 | |||
| a838ba44e8 | |||
| 1057fd9954 |
@@ -1,4 +0,0 @@
|
|||||||
# .env.production example
|
|
||||||
NODE_ENV=production
|
|
||||||
JWT_SECRET=your-super-secure-minimum-32-character-secret-key-here
|
|
||||||
DATABASE_PATH=/app/data/production.db
|
|
||||||
16
.env.template
Normal file
16
.env.template
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
# === SCHICHTPLANER DOCKER COMPOSE ENVIRONMENT VARIABLES ===
|
||||||
|
# Diese Datei wird von docker-compose automatisch geladen
|
||||||
|
|
||||||
|
# Security
|
||||||
|
JWT_SECRET=${JWT_SECRET:-your-secret-key-please-change}
|
||||||
|
NODE_ENV=${NODE_ENV:-production}
|
||||||
|
|
||||||
|
# Database
|
||||||
|
DB_PATH=${DB_PATH:-/app/data/database.db}
|
||||||
|
|
||||||
|
# Server
|
||||||
|
PORT=${PORT:-3002}
|
||||||
|
|
||||||
|
# App Configuration
|
||||||
|
APP_TITLE="Shift Planning App"
|
||||||
|
ENABLE_PRO=${ENABLE_PRO:-false}
|
||||||
26
Dockerfile
26
Dockerfile
@@ -30,19 +30,24 @@ RUN npm install --workspace=frontend
|
|||||||
RUN npm run build --only=production --workspace=backend
|
RUN npm run build --only=production --workspace=backend
|
||||||
|
|
||||||
# Build frontend
|
# Build frontend
|
||||||
RUN npm run build --only=production --workspace=frontend
|
RUN npm run build --workspace=frontend
|
||||||
|
|
||||||
# Verify Python and OR-Tools installation
|
# Verify Python and OR-Tools installation
|
||||||
RUN python -c "from ortools.sat.python import cp_model; print('OR-Tools installed successfully')"
|
RUN python -c "from ortools.sat.python import cp_model; print('OR-Tools installed successfully')"
|
||||||
|
|
||||||
# Production stage (same as above)
|
# Production stage
|
||||||
FROM node:20-bookworm
|
FROM node:20-bookworm
|
||||||
|
|
||||||
WORKDIR /app
|
WORKDIR /app
|
||||||
|
|
||||||
|
# Install system dependencies including gettext-base for envsubst
|
||||||
|
RUN apt-get update && apt-get install -y gettext-base && \
|
||||||
|
rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
RUN npm install -g pm2
|
RUN npm install -g pm2
|
||||||
RUN mkdir -p /app/data
|
RUN mkdir -p /app/data
|
||||||
|
|
||||||
|
# Copy application files
|
||||||
COPY --from=builder /app/backend/dist/ ./dist/
|
COPY --from=builder /app/backend/dist/ ./dist/
|
||||||
COPY --from=builder /app/backend/package*.json ./
|
COPY --from=builder /app/backend/package*.json ./
|
||||||
|
|
||||||
@@ -54,6 +59,14 @@ COPY --from=builder /app/ecosystem.config.cjs ./
|
|||||||
COPY --from=builder /app/backend/src/database/ ./dist/database/
|
COPY --from=builder /app/backend/src/database/ ./dist/database/
|
||||||
COPY --from=builder /app/backend/src/database/ ./database/
|
COPY --from=builder /app/backend/src/database/ ./database/
|
||||||
|
|
||||||
|
# Copy init script and env template
|
||||||
|
COPY docker-init.sh /usr/local/bin/
|
||||||
|
COPY .env.template ./
|
||||||
|
|
||||||
|
# Set execute permissions for init script
|
||||||
|
RUN chmod +x /usr/local/bin/docker-init.sh
|
||||||
|
|
||||||
|
# Create user and set permissions
|
||||||
RUN groupadd -g 1001 nodejs && \
|
RUN groupadd -g 1001 nodejs && \
|
||||||
useradd -m -u 1001 -s /bin/bash -g nodejs schichtplan && \
|
useradd -m -u 1001 -s /bin/bash -g nodejs schichtplan && \
|
||||||
chown -R schichtplan:nodejs /app && \
|
chown -R schichtplan:nodejs /app && \
|
||||||
@@ -61,10 +74,13 @@ RUN groupadd -g 1001 nodejs && \
|
|||||||
chmod 775 /app/data
|
chmod 775 /app/data
|
||||||
|
|
||||||
ENV PM2_HOME=/app/.pm2
|
ENV PM2_HOME=/app/.pm2
|
||||||
|
|
||||||
|
# Set entrypoint to init script and keep existing cmd
|
||||||
|
ENTRYPOINT ["/usr/local/bin/docker-init.sh"]
|
||||||
|
CMD ["pm2-runtime", "ecosystem.config.cjs"]
|
||||||
|
|
||||||
USER schichtplan
|
USER schichtplan
|
||||||
EXPOSE 3002
|
EXPOSE 3002
|
||||||
|
|
||||||
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
|
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
|
||||||
CMD wget --no-verbose --tries=1 --spider http://localhost:3002/api/health || exit 1
|
CMD wget --no-verbose --tries=1 --spider http://localhost:3002/api/health || exit 1
|
||||||
|
|
||||||
CMD ["pm2-runtime", "ecosystem.config.cjs"]
|
|
||||||
@@ -19,7 +19,10 @@
|
|||||||
"express": "^4.18.2",
|
"express": "^4.18.2",
|
||||||
"jsonwebtoken": "^9.0.2",
|
"jsonwebtoken": "^9.0.2",
|
||||||
"sqlite3": "^5.1.6",
|
"sqlite3": "^5.1.6",
|
||||||
"uuid": "^9.0.0"
|
"uuid": "^9.0.0",
|
||||||
|
"express-rate-limit": "8.1.0",
|
||||||
|
"helmet": "8.1.0",
|
||||||
|
"express-validator": "7.3.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/bcryptjs": "^2.4.2",
|
"@types/bcryptjs": "^2.4.2",
|
||||||
|
|||||||
@@ -1,3 +1,8 @@
|
|||||||
|
PRAGMA journal_mode = WAL;
|
||||||
|
PRAGMA foreign_keys = ON;
|
||||||
|
PRAGMA secure_delete = ON;
|
||||||
|
PRAGMA auto_vacuum = INCREMENTAL;
|
||||||
|
|
||||||
-- Employee Types
|
-- Employee Types
|
||||||
CREATE TABLE IF NOT EXISTS employee_types (
|
CREATE TABLE IF NOT EXISTS employee_types (
|
||||||
type TEXT PRIMARY KEY,
|
type TEXT PRIMARY KEY,
|
||||||
@@ -149,9 +154,3 @@ CREATE INDEX IF NOT EXISTS idx_scheduled_shifts_required_employees ON scheduled_
|
|||||||
CREATE INDEX IF NOT EXISTS idx_shift_assignments_employee ON shift_assignments(employee_id);
|
CREATE INDEX IF NOT EXISTS idx_shift_assignments_employee ON shift_assignments(employee_id);
|
||||||
CREATE INDEX IF NOT EXISTS idx_shift_assignments_shift ON shift_assignments(scheduled_shift_id);
|
CREATE INDEX IF NOT EXISTS idx_shift_assignments_shift ON shift_assignments(scheduled_shift_id);
|
||||||
CREATE INDEX IF NOT EXISTS idx_employee_availability_employee_plan ON employee_availability(employee_id, plan_id);
|
CREATE INDEX IF NOT EXISTS idx_employee_availability_employee_plan ON employee_availability(employee_id, plan_id);
|
||||||
|
|
||||||
PRAGMA journal_mode = WAL;
|
|
||||||
PRAGMA synchronous = NORMAL;
|
|
||||||
PRAGMA foreign_keys = ON;
|
|
||||||
PRAGMA secure_delete = ON;
|
|
||||||
PRAGMA auto_vacuum = INCREMENTAL;
|
|
||||||
48
backend/src/middleware/rateLimit.ts
Normal file
48
backend/src/middleware/rateLimit.ts
Normal file
@@ -0,0 +1,48 @@
|
|||||||
|
import rateLimit from 'express-rate-limit';
|
||||||
|
import { Request } from 'express';
|
||||||
|
|
||||||
|
// Helper to check if request should be limited
|
||||||
|
const shouldSkipLimit = (req: Request): boolean => {
|
||||||
|
const skipPaths = [
|
||||||
|
'/api/health',
|
||||||
|
'/api/setup/status',
|
||||||
|
'/api/auth/validate'
|
||||||
|
];
|
||||||
|
|
||||||
|
// Skip for successful GET requests (data fetching)
|
||||||
|
if (req.method === 'GET' && req.path.startsWith('/api/')) {
|
||||||
|
return true;
|
||||||
|
}
|
||||||
|
|
||||||
|
return skipPaths.includes(req.path);
|
||||||
|
};
|
||||||
|
|
||||||
|
// Main API limiter - nur für POST/PUT/DELETE
|
||||||
|
export const apiLimiter = rateLimit({
|
||||||
|
windowMs: 15 * 60 * 1000, // 15 minutes
|
||||||
|
max: 200, // 200 non-GET requests per 15 minutes
|
||||||
|
message: {
|
||||||
|
error: 'Zu viele Anfragen, bitte verlangsamen Sie Ihre Aktionen'
|
||||||
|
},
|
||||||
|
standardHeaders: true,
|
||||||
|
legacyHeaders: false,
|
||||||
|
skip: (req) => {
|
||||||
|
// ✅ Skip für GET requests (Data Fetching)
|
||||||
|
if (req.method === 'GET') return true;
|
||||||
|
|
||||||
|
// ✅ Skip für Health/Status Checks
|
||||||
|
return shouldSkipLimit(req);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
// Strict limiter for auth endpoints
|
||||||
|
export const authLimiter = rateLimit({
|
||||||
|
windowMs: 15 * 60 * 1000,
|
||||||
|
max: 5,
|
||||||
|
message: {
|
||||||
|
error: 'Zu viele Login-Versuche, bitte versuchen Sie es später erneut'
|
||||||
|
},
|
||||||
|
standardHeaders: true,
|
||||||
|
legacyHeaders: false,
|
||||||
|
skipSuccessfulRequests: true,
|
||||||
|
});
|
||||||
457
backend/src/middleware/validation.ts
Normal file
457
backend/src/middleware/validation.ts
Normal file
@@ -0,0 +1,457 @@
|
|||||||
|
import { body, validationResult, param, query } from 'express-validator';
|
||||||
|
import { Request, Response, NextFunction } from 'express';
|
||||||
|
|
||||||
|
// ===== AUTH VALIDATION =====
|
||||||
|
export const validateLogin = [
|
||||||
|
body('email')
|
||||||
|
.isEmail()
|
||||||
|
.withMessage('Must be a valid email')
|
||||||
|
.normalizeEmail(),
|
||||||
|
|
||||||
|
body('password')
|
||||||
|
.isLength({ min: 6 })
|
||||||
|
.withMessage('Password must be at least 6 characters')
|
||||||
|
.trim()
|
||||||
|
.escape()
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateRegister = [
|
||||||
|
body('firstname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('First name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('lastname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('Last name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('password')
|
||||||
|
.isLength({ min: 8 })
|
||||||
|
.withMessage('Password must be at least 8 characters')
|
||||||
|
.matches(/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)/)
|
||||||
|
.withMessage('Password must contain uppercase, lowercase and number')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== EMPLOYEE VALIDATION =====
|
||||||
|
export const validateEmployee = [
|
||||||
|
body('firstname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('First name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('lastname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('Last name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('password')
|
||||||
|
.optional()
|
||||||
|
.isLength({ min: 8 })
|
||||||
|
.withMessage('Password must be at least 8 characters')
|
||||||
|
.matches(/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)/)
|
||||||
|
.withMessage('Password must contain uppercase, lowercase and number'),
|
||||||
|
|
||||||
|
body('employeeType')
|
||||||
|
.isIn(['manager', 'personell', 'apprentice', 'guest'])
|
||||||
|
.withMessage('Employee type must be manager, personell, apprentice or guest'),
|
||||||
|
|
||||||
|
body('contractType')
|
||||||
|
.optional()
|
||||||
|
.isIn(['small', 'large', 'flexible'])
|
||||||
|
.withMessage('Contract type must be small, large or flexible'),
|
||||||
|
|
||||||
|
body('roles')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Roles must be an array'),
|
||||||
|
|
||||||
|
body('roles.*')
|
||||||
|
.optional()
|
||||||
|
.isIn(['admin', 'maintenance', 'user'])
|
||||||
|
.withMessage('Invalid role. Allowed: admin, maintenance, user'),
|
||||||
|
|
||||||
|
body('canWorkAlone')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('canWorkAlone must be a boolean'),
|
||||||
|
|
||||||
|
body('isTrainee')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isTrainee must be a boolean'),
|
||||||
|
|
||||||
|
body('isActive')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isActive must be a boolean')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateEmployeeUpdate = [
|
||||||
|
body('firstname')
|
||||||
|
.optional()
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('First name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('lastname')
|
||||||
|
.optional()
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('Last name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('employeeType')
|
||||||
|
.optional()
|
||||||
|
.isIn(['manager', 'personell', 'apprentice', 'guest'])
|
||||||
|
.withMessage('Employee type must be manager, personell, apprentice or guest'),
|
||||||
|
|
||||||
|
body('contractType')
|
||||||
|
.optional()
|
||||||
|
.isIn(['small', 'large', 'flexible'])
|
||||||
|
.withMessage('Contract type must be small, large or flexible'),
|
||||||
|
|
||||||
|
body('roles')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Roles must be an array'),
|
||||||
|
|
||||||
|
body('roles.*')
|
||||||
|
.optional()
|
||||||
|
.isIn(['admin', 'maintenance', 'user'])
|
||||||
|
.withMessage('Invalid role. Allowed: admin, maintenance, user'),
|
||||||
|
|
||||||
|
body('canWorkAlone')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('canWorkAlone must be a boolean'),
|
||||||
|
|
||||||
|
body('isTrainee')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isTrainee must be a boolean'),
|
||||||
|
|
||||||
|
body('isActive')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isActive must be a boolean')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateChangePassword = [
|
||||||
|
body('currentPassword')
|
||||||
|
.optional()
|
||||||
|
.isLength({ min: 6 })
|
||||||
|
.withMessage('Current password must be at least 6 characters'),
|
||||||
|
|
||||||
|
body('newPassword')
|
||||||
|
.isLength({ min: 8 })
|
||||||
|
.withMessage('New password must be at least 8 characters')
|
||||||
|
.matches(/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)/)
|
||||||
|
.withMessage('New password must contain uppercase, lowercase and number')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== SHIFT PLAN VALIDATION =====
|
||||||
|
export const validateShiftPlan = [
|
||||||
|
body('name')
|
||||||
|
.isLength({ min: 1, max: 200 })
|
||||||
|
.withMessage('Name must be between 1-200 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('description')
|
||||||
|
.optional()
|
||||||
|
.isLength({ max: 1000 })
|
||||||
|
.withMessage('Description cannot exceed 1000 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('startDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('endDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('isTemplate')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isTemplate must be a boolean'),
|
||||||
|
|
||||||
|
body('status')
|
||||||
|
.optional()
|
||||||
|
.isIn(['draft', 'published', 'archived', 'template'])
|
||||||
|
.withMessage('Status must be draft, published, archived or template'),
|
||||||
|
|
||||||
|
body('timeSlots')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Time slots must be an array'),
|
||||||
|
|
||||||
|
body('timeSlots.*.name')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('Time slot name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('timeSlots.*.startTime')
|
||||||
|
.matches(/^([0-1]?[0-9]|2[0-3]):[0-5][0-9]$/)
|
||||||
|
.withMessage('Start time must be in HH:MM format'),
|
||||||
|
|
||||||
|
body('timeSlots.*.endTime')
|
||||||
|
.matches(/^([0-1]?[0-9]|2[0-3]):[0-5][0-9]$/)
|
||||||
|
.withMessage('End time must be in HH:MM format'),
|
||||||
|
|
||||||
|
body('timeSlots.*.description')
|
||||||
|
.optional()
|
||||||
|
.isLength({ max: 500 })
|
||||||
|
.withMessage('Time slot description cannot exceed 500 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('shifts')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Shifts must be an array'),
|
||||||
|
|
||||||
|
body('shifts.*.dayOfWeek')
|
||||||
|
.isInt({ min: 1, max: 7 })
|
||||||
|
.withMessage('Day of week must be between 1-7 (Monday-Sunday)'),
|
||||||
|
|
||||||
|
body('shifts.*.timeSlotId')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Time slot ID must be a valid UUID'),
|
||||||
|
|
||||||
|
body('shifts.*.requiredEmployees')
|
||||||
|
.isInt({ min: 0 })
|
||||||
|
.withMessage('Required employees must be a positive integer'),
|
||||||
|
|
||||||
|
body('shifts.*.color')
|
||||||
|
.optional()
|
||||||
|
.isHexColor()
|
||||||
|
.withMessage('Color must be a valid hex color')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateShiftPlanUpdate = [
|
||||||
|
body('name')
|
||||||
|
.optional()
|
||||||
|
.isLength({ min: 1, max: 200 })
|
||||||
|
.withMessage('Name must be between 1-200 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('description')
|
||||||
|
.optional()
|
||||||
|
.isLength({ max: 1000 })
|
||||||
|
.withMessage('Description cannot exceed 1000 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('startDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('endDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('status')
|
||||||
|
.optional()
|
||||||
|
.isIn(['draft', 'published', 'archived', 'template'])
|
||||||
|
.withMessage('Status must be draft, published, archived or template'),
|
||||||
|
|
||||||
|
body('timeSlots')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Time slots must be an array'),
|
||||||
|
|
||||||
|
body('shifts')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Shifts must be an array')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateCreateFromPreset = [
|
||||||
|
body('presetName')
|
||||||
|
.isLength({ min: 1 })
|
||||||
|
.withMessage('Preset name is required')
|
||||||
|
.isIn(['standardWeek', 'extendedWeek', 'weekendFocused', 'morningOnly', 'eveningOnly', 'ZEBRA_STANDARD'])
|
||||||
|
.withMessage('Invalid preset name'),
|
||||||
|
|
||||||
|
body('name')
|
||||||
|
.isLength({ min: 1, max: 200 })
|
||||||
|
.withMessage('Name must be between 1-200 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('startDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('endDate')
|
||||||
|
.optional()
|
||||||
|
.isISO8601()
|
||||||
|
.withMessage('Must be a valid date (ISO format)'),
|
||||||
|
|
||||||
|
body('isTemplate')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('isTemplate must be a boolean')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== SCHEDULED SHIFTS VALIDATION =====
|
||||||
|
export const validateScheduledShiftUpdate = [
|
||||||
|
body('assignedEmployees')
|
||||||
|
.isArray()
|
||||||
|
.withMessage('assignedEmployees must be an array'),
|
||||||
|
|
||||||
|
body('assignedEmployees.*')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Each assigned employee must be a valid UUID'),
|
||||||
|
|
||||||
|
body('requiredEmployees')
|
||||||
|
.optional()
|
||||||
|
.isInt({ min: 0 })
|
||||||
|
.withMessage('Required employees must be a positive integer')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== SETUP VALIDATION =====
|
||||||
|
export const validateSetupAdmin = [
|
||||||
|
body('firstname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('First name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('lastname')
|
||||||
|
.isLength({ min: 1, max: 100 })
|
||||||
|
.withMessage('Last name must be between 1-100 characters')
|
||||||
|
.trim()
|
||||||
|
.escape(),
|
||||||
|
|
||||||
|
body('password')
|
||||||
|
.isLength({ min: 8 })
|
||||||
|
.withMessage('Password must be at least 8 characters')
|
||||||
|
.matches(/^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)/)
|
||||||
|
.withMessage('Password must contain uppercase, lowercase and number')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== SCHEDULING VALIDATION =====
|
||||||
|
export const validateSchedulingRequest = [
|
||||||
|
body('shiftPlan')
|
||||||
|
.isObject()
|
||||||
|
.withMessage('Shift plan is required'),
|
||||||
|
|
||||||
|
body('shiftPlan.id')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Shift plan ID must be a valid UUID'),
|
||||||
|
|
||||||
|
body('employees')
|
||||||
|
.isArray({ min: 1 })
|
||||||
|
.withMessage('At least one employee is required'),
|
||||||
|
|
||||||
|
body('employees.*.id')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Each employee must have a valid UUID'),
|
||||||
|
|
||||||
|
body('availabilities')
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Availabilities must be an array'),
|
||||||
|
|
||||||
|
body('constraints')
|
||||||
|
.optional()
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Constraints must be an array')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== AVAILABILITY VALIDATION =====
|
||||||
|
export const validateAvailabilities = [
|
||||||
|
body('planId')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Plan ID must be a valid UUID'),
|
||||||
|
|
||||||
|
body('availabilities')
|
||||||
|
.isArray()
|
||||||
|
.withMessage('Availabilities must be an array'),
|
||||||
|
|
||||||
|
body('availabilities.*.shiftId')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Each shift ID must be a valid UUID'),
|
||||||
|
|
||||||
|
body('availabilities.*.preferenceLevel')
|
||||||
|
.isInt({ min: 0, max: 2 })
|
||||||
|
.withMessage('Preference level must be 0 (unavailable), 1 (available), or 2 (preferred)'),
|
||||||
|
|
||||||
|
body('availabilities.*.notes')
|
||||||
|
.optional()
|
||||||
|
.isLength({ max: 500 })
|
||||||
|
.withMessage('Notes cannot exceed 500 characters')
|
||||||
|
.trim()
|
||||||
|
.escape()
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== COMMON VALIDATORS =====
|
||||||
|
export const validateId = [
|
||||||
|
param('id')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Must be a valid UUID')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validateEmployeeId = [
|
||||||
|
param('employeeId')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Must be a valid UUID')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validatePlanId = [
|
||||||
|
param('planId')
|
||||||
|
.isUUID()
|
||||||
|
.withMessage('Must be a valid UUID')
|
||||||
|
];
|
||||||
|
|
||||||
|
export const validatePagination = [
|
||||||
|
query('page')
|
||||||
|
.optional()
|
||||||
|
.isInt({ min: 1 })
|
||||||
|
.withMessage('Page must be a positive integer'),
|
||||||
|
|
||||||
|
query('limit')
|
||||||
|
.optional()
|
||||||
|
.isInt({ min: 1, max: 100 })
|
||||||
|
.withMessage('Limit must be between 1-100'),
|
||||||
|
|
||||||
|
query('includeInactive')
|
||||||
|
.optional()
|
||||||
|
.isBoolean()
|
||||||
|
.withMessage('includeInactive must be a boolean')
|
||||||
|
];
|
||||||
|
|
||||||
|
// ===== MIDDLEWARE TO CHECK VALIDATION RESULTS =====
|
||||||
|
export const handleValidationErrors = (req: Request, res: Response, next: NextFunction) => {
|
||||||
|
const errors = validationResult(req);
|
||||||
|
|
||||||
|
if (!errors.isEmpty()) {
|
||||||
|
const errorMessages = errors.array().map(error => ({
|
||||||
|
field: error.type === 'field' ? error.path : error.type,
|
||||||
|
message: error.msg,
|
||||||
|
value: error.msg
|
||||||
|
}));
|
||||||
|
|
||||||
|
return res.status(400).json({
|
||||||
|
error: 'Validation failed',
|
||||||
|
details: errorMessages
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
next();
|
||||||
|
};
|
||||||
@@ -8,12 +8,13 @@ import {
|
|||||||
validateToken
|
validateToken
|
||||||
} from '../controllers/authController.js';
|
} from '../controllers/authController.js';
|
||||||
import { authMiddleware } from '../middleware/auth.js';
|
import { authMiddleware } from '../middleware/auth.js';
|
||||||
|
import { validateLogin, validateRegister, handleValidationErrors } from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
// Public routes
|
// Public routes
|
||||||
router.post('/login', login);
|
router.post('/login', validateLogin, handleValidationErrors, login);
|
||||||
router.post('/register', register);
|
router.post('/register', validateRegister, handleValidationErrors, register);
|
||||||
router.get('/validate', validateToken);
|
router.get('/validate', validateToken);
|
||||||
|
|
||||||
// Protected routes (require authentication)
|
// Protected routes (require authentication)
|
||||||
|
|||||||
@@ -1,4 +1,3 @@
|
|||||||
// backend/src/routes/employees.ts
|
|
||||||
import express from 'express';
|
import express from 'express';
|
||||||
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
||||||
import {
|
import {
|
||||||
@@ -12,6 +11,16 @@ import {
|
|||||||
changePassword,
|
changePassword,
|
||||||
updateLastLogin
|
updateLastLogin
|
||||||
} from '../controllers/employeeController.js';
|
} from '../controllers/employeeController.js';
|
||||||
|
import {
|
||||||
|
handleValidationErrors,
|
||||||
|
validateEmployee,
|
||||||
|
validateEmployeeUpdate,
|
||||||
|
validateChangePassword,
|
||||||
|
validateId,
|
||||||
|
validateEmployeeId,
|
||||||
|
validateAvailabilities,
|
||||||
|
validatePagination
|
||||||
|
} from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
@@ -19,16 +28,18 @@ const router = express.Router();
|
|||||||
router.use(authMiddleware);
|
router.use(authMiddleware);
|
||||||
|
|
||||||
// Employee CRUD Routes
|
// Employee CRUD Routes
|
||||||
router.get('/', authMiddleware, getEmployees);
|
router.get('/', validatePagination, handleValidationErrors, getEmployees);
|
||||||
router.get('/:id', requireRole(['admin', 'maintenance']), getEmployee);
|
router.get('/:id', validateId, handleValidationErrors, requireRole(['admin', 'maintenance']), getEmployee);
|
||||||
router.post('/', requireRole(['admin']), createEmployee);
|
router.post('/', validateEmployee, handleValidationErrors, requireRole(['admin']), createEmployee);
|
||||||
router.put('/:id', requireRole(['admin', 'maintenance']), updateEmployee);
|
router.put('/:id', validateId, validateEmployeeUpdate, handleValidationErrors, requireRole(['admin', 'maintenance']), updateEmployee);
|
||||||
router.delete('/:id', requireRole(['admin']), deleteEmployee);
|
router.delete('/:id', validateId, handleValidationErrors, requireRole(['admin']), deleteEmployee);
|
||||||
router.put('/:id/password', authMiddleware, changePassword);
|
|
||||||
router.put('/:id/last-login', authMiddleware, updateLastLogin);
|
// Password & Login Routes
|
||||||
|
router.put('/:id/password', validateId, validateChangePassword, handleValidationErrors, changePassword);
|
||||||
|
router.put('/:id/last-login', validateId, handleValidationErrors, updateLastLogin);
|
||||||
|
|
||||||
// Availability Routes
|
// Availability Routes
|
||||||
router.get('/:employeeId/availabilities', authMiddleware, getAvailabilities);
|
router.get('/:employeeId/availabilities', validateEmployeeId, handleValidationErrors, getAvailabilities);
|
||||||
router.put('/:employeeId/availabilities', authMiddleware, updateAvailabilities);
|
router.put('/:employeeId/availabilities', validateEmployeeId, validateAvailabilities, handleValidationErrors, updateAvailabilities);
|
||||||
|
|
||||||
export default router;
|
export default router;
|
||||||
@@ -1,4 +1,3 @@
|
|||||||
// backend/src/routes/scheduledShifts.ts
|
|
||||||
import express from 'express';
|
import express from 'express';
|
||||||
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
||||||
import {
|
import {
|
||||||
@@ -8,23 +7,21 @@ import {
|
|||||||
getScheduledShiftsFromPlan,
|
getScheduledShiftsFromPlan,
|
||||||
updateScheduledShift
|
updateScheduledShift
|
||||||
} from '../controllers/shiftPlanController.js';
|
} from '../controllers/shiftPlanController.js';
|
||||||
|
import {
|
||||||
|
validateId,
|
||||||
|
validatePlanId,
|
||||||
|
validateScheduledShiftUpdate,
|
||||||
|
handleValidationErrors
|
||||||
|
} from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
router.use(authMiddleware);
|
router.use(authMiddleware);
|
||||||
|
|
||||||
|
router.post('/:id/generate-shifts', validateId, handleValidationErrors, requireRole(['admin', 'maintenance']), generateScheduledShiftsForPlan);
|
||||||
router.post('/:id/generate-shifts', requireRole(['admin', 'maintenance']), generateScheduledShiftsForPlan);
|
router.post('/:id/regenerate-shifts', validateId, handleValidationErrors, requireRole(['admin', 'maintenance']), regenerateScheduledShifts);
|
||||||
|
router.get('/plan/:planId', validatePlanId, handleValidationErrors, getScheduledShiftsFromPlan);
|
||||||
router.post('/:id/regenerate-shifts', requireRole(['admin', 'maintenance']), regenerateScheduledShifts);
|
router.get('/:id', validateId, handleValidationErrors, getScheduledShift);
|
||||||
|
router.put('/:id', validateId, validateScheduledShiftUpdate, handleValidationErrors, updateScheduledShift);
|
||||||
// GET all scheduled shifts for a plan
|
|
||||||
router.get('/plan/:planId', authMiddleware, getScheduledShiftsFromPlan);
|
|
||||||
|
|
||||||
// GET specific scheduled shift
|
|
||||||
router.get('/:id', authMiddleware, getScheduledShift);
|
|
||||||
|
|
||||||
// UPDATE scheduled shift
|
|
||||||
router.put('/:id', authMiddleware, updateScheduledShift);
|
|
||||||
|
|
||||||
export default router;
|
export default router;
|
||||||
@@ -1,9 +1,10 @@
|
|||||||
import express from 'express';
|
import express from 'express';
|
||||||
import { SchedulingService } from '../services/SchedulingService.js';
|
import { SchedulingService } from '../services/SchedulingService.js';
|
||||||
|
import { validateSchedulingRequest, handleValidationErrors } from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
router.post('/generate-schedule', async (req, res) => {
|
router.post('/generate-schedule', validateSchedulingRequest, handleValidationErrors, async (req: express.Request, res: express.Response) => {
|
||||||
try {
|
try {
|
||||||
const { shiftPlan, employees, availabilities, constraints } = req.body;
|
const { shiftPlan, employees, availabilities, constraints } = req.body;
|
||||||
|
|
||||||
@@ -14,18 +15,6 @@ router.post('/generate-schedule', async (req, res) => {
|
|||||||
constraintCount: constraints?.length
|
constraintCount: constraints?.length
|
||||||
});
|
});
|
||||||
|
|
||||||
// Validate required data
|
|
||||||
if (!shiftPlan || !employees || !availabilities) {
|
|
||||||
return res.status(400).json({
|
|
||||||
error: 'Missing required data',
|
|
||||||
details: {
|
|
||||||
shiftPlan: !!shiftPlan,
|
|
||||||
employees: !!employees,
|
|
||||||
availabilities: !!availabilities
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const scheduler = new SchedulingService();
|
const scheduler = new SchedulingService();
|
||||||
const result = await scheduler.generateOptimalSchedule({
|
const result = await scheduler.generateOptimalSchedule({
|
||||||
shiftPlan,
|
shiftPlan,
|
||||||
|
|||||||
@@ -1,10 +1,10 @@
|
|||||||
// backend/src/routes/setup.ts
|
|
||||||
import express from 'express';
|
import express from 'express';
|
||||||
import { checkSetupStatus, setupAdmin } from '../controllers/setupController.js';
|
import { checkSetupStatus, setupAdmin } from '../controllers/setupController.js';
|
||||||
|
import { validateSetupAdmin, handleValidationErrors } from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
router.get('/status', checkSetupStatus);
|
router.get('/status', checkSetupStatus);
|
||||||
router.post('/admin', setupAdmin);
|
router.post('/admin', validateSetupAdmin, handleValidationErrors, setupAdmin);
|
||||||
|
|
||||||
export default router;
|
export default router;
|
||||||
@@ -1,4 +1,3 @@
|
|||||||
// backend/src/routes/shiftPlans.ts
|
|
||||||
import express from 'express';
|
import express from 'express';
|
||||||
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
import { authMiddleware, requireRole } from '../middleware/auth.js';
|
||||||
import {
|
import {
|
||||||
@@ -10,32 +9,25 @@ import {
|
|||||||
createFromPreset,
|
createFromPreset,
|
||||||
clearAssignments
|
clearAssignments
|
||||||
} from '../controllers/shiftPlanController.js';
|
} from '../controllers/shiftPlanController.js';
|
||||||
|
import {
|
||||||
|
validateShiftPlan,
|
||||||
|
validateShiftPlanUpdate,
|
||||||
|
validateCreateFromPreset,
|
||||||
|
handleValidationErrors,
|
||||||
|
validateId
|
||||||
|
} from '../middleware/validation.js';
|
||||||
|
|
||||||
const router = express.Router();
|
const router = express.Router();
|
||||||
|
|
||||||
router.use(authMiddleware);
|
router.use(authMiddleware);
|
||||||
|
|
||||||
// Combined routes for both shift plans and templates
|
// Combined routes for both shift plans and templates
|
||||||
|
router.get('/', getShiftPlans);
|
||||||
// GET all shift plans (including templates)
|
router.get('/:id', validateId, handleValidationErrors, getShiftPlan);
|
||||||
router.get('/' , authMiddleware, getShiftPlans);
|
router.post('/', validateShiftPlan, handleValidationErrors, requireRole(['admin', 'maintenance']), createShiftPlan);
|
||||||
|
router.post('/from-preset', validateCreateFromPreset, handleValidationErrors, requireRole(['admin', 'maintenance']), createFromPreset);
|
||||||
// GET specific shift plan or template
|
router.put('/:id', validateId, validateShiftPlanUpdate, handleValidationErrors, requireRole(['admin', 'maintenance']), updateShiftPlan);
|
||||||
router.get('/:id', authMiddleware, getShiftPlan);
|
router.delete('/:id', validateId, handleValidationErrors, requireRole(['admin', 'maintenance']), deleteShiftPlan);
|
||||||
|
router.post('/:id/clear-assignments', validateId, handleValidationErrors, requireRole(['admin', 'maintenance']), clearAssignments);
|
||||||
// POST create new shift plan
|
|
||||||
router.post('/', requireRole(['admin', 'maintenance']), createShiftPlan);
|
|
||||||
|
|
||||||
// POST create new plan from preset
|
|
||||||
router.post('/from-preset', requireRole(['admin', 'maintenance']), createFromPreset);
|
|
||||||
|
|
||||||
// PUT update shift plan or template
|
|
||||||
router.put('/:id', requireRole(['admin', 'maintenance']), updateShiftPlan);
|
|
||||||
|
|
||||||
// DELETE shift plan or template
|
|
||||||
router.delete('/:id', requireRole(['admin', 'maintenance']), deleteShiftPlan);
|
|
||||||
|
|
||||||
// POST clear assignments and reset to draft
|
|
||||||
router.post('/:id/clear-assignments', requireRole(['admin', 'maintenance']), clearAssignments);
|
|
||||||
|
|
||||||
export default router;
|
export default router;
|
||||||
@@ -4,6 +4,7 @@ import path from 'path';
|
|||||||
import { fileURLToPath } from 'url';
|
import { fileURLToPath } from 'url';
|
||||||
import { initializeDatabase } from './scripts/initializeDatabase.js';
|
import { initializeDatabase } from './scripts/initializeDatabase.js';
|
||||||
import fs from 'fs';
|
import fs from 'fs';
|
||||||
|
import helmet from 'helmet';
|
||||||
|
|
||||||
// Route imports
|
// Route imports
|
||||||
import authRoutes from './routes/auth.js';
|
import authRoutes from './routes/auth.js';
|
||||||
@@ -12,122 +13,184 @@ import shiftPlanRoutes from './routes/shiftPlans.js';
|
|||||||
import setupRoutes from './routes/setup.js';
|
import setupRoutes from './routes/setup.js';
|
||||||
import scheduledShifts from './routes/scheduledShifts.js';
|
import scheduledShifts from './routes/scheduledShifts.js';
|
||||||
import schedulingRoutes from './routes/scheduling.js';
|
import schedulingRoutes from './routes/scheduling.js';
|
||||||
|
import { authLimiter, apiLimiter } from './middleware/rateLimit.js';
|
||||||
|
|
||||||
|
const __filename = fileURLToPath(import.meta.url);
|
||||||
|
const __dirname = path.dirname(__filename);
|
||||||
|
|
||||||
const app = express();
|
const app = express();
|
||||||
const PORT = 3002;
|
const PORT = 3002;
|
||||||
|
const isDevelopment = process.env.NODE_ENV === 'development';
|
||||||
|
|
||||||
|
// Security configuration
|
||||||
|
if (process.env.NODE_ENV === 'production') {
|
||||||
|
console.info('Checking for JWT_SECRET');
|
||||||
|
const JWT_SECRET = process.env.JWT_SECRET;
|
||||||
|
if (!JWT_SECRET || JWT_SECRET === 'your-secret-key-please-change') {
|
||||||
|
console.error('❌ Fatal: JWT_SECRET not set or using default value');
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Security headers
|
||||||
|
app.use(helmet({
|
||||||
|
contentSecurityPolicy: isDevelopment ? false : {
|
||||||
|
directives: {
|
||||||
|
defaultSrc: ["'self'"],
|
||||||
|
scriptSrc: ["'self'", "'unsafe-inline'"],
|
||||||
|
styleSrc: ["'self'", "'unsafe-inline'"],
|
||||||
|
imgSrc: ["'self'", "data:", "https:"],
|
||||||
|
},
|
||||||
|
},
|
||||||
|
crossOriginEmbedderPolicy: false
|
||||||
|
}));
|
||||||
|
|
||||||
|
// Additional security headers
|
||||||
|
app.use((req, res, next) => {
|
||||||
|
res.setHeader('X-Content-Type-Options', 'nosniff');
|
||||||
|
res.setHeader('X-Frame-Options', 'DENY');
|
||||||
|
res.setHeader('X-XSS-Protection', '1; mode=block');
|
||||||
|
next();
|
||||||
|
});
|
||||||
|
|
||||||
// Middleware
|
// Middleware
|
||||||
app.use(express.json());
|
app.use(express.json());
|
||||||
|
|
||||||
|
// Rate limiting - weniger restriktiv in Development
|
||||||
|
if (process.env.NODE_ENV === 'production') {
|
||||||
|
app.use('/api/', apiLimiter);
|
||||||
|
} else {
|
||||||
|
console.log('🔧 Development: Rate limiting relaxed');
|
||||||
|
}
|
||||||
|
|
||||||
// API Routes
|
// API Routes
|
||||||
app.use('/api/setup', setupRoutes);
|
app.use('/api/setup', setupRoutes);
|
||||||
app.use('/api/auth', authRoutes);
|
app.use('/api/auth', authLimiter, authRoutes);
|
||||||
app.use('/api/employees', employeeRoutes);
|
app.use('/api/employees', employeeRoutes);
|
||||||
app.use('/api/shift-plans', shiftPlanRoutes);
|
app.use('/api/shift-plans', shiftPlanRoutes);
|
||||||
app.use('/api/scheduled-shifts', scheduledShifts);
|
app.use('/api/scheduled-shifts', scheduledShifts);
|
||||||
app.use('/api/scheduling', schedulingRoutes);
|
app.use('/api/scheduling', schedulingRoutes);
|
||||||
|
|
||||||
// Health route
|
// Health route
|
||||||
app.get('/api/health', (req: any, res: any) => {
|
app.get('/api/health', (req: express.Request, res: express.Response) => {
|
||||||
res.json({
|
res.json({
|
||||||
status: 'OK',
|
status: 'OK',
|
||||||
message: 'Backend läuft!',
|
message: 'Backend läuft!',
|
||||||
timestamp: new Date().toISOString()
|
timestamp: new Date().toISOString(),
|
||||||
|
mode: process.env.NODE_ENV || 'development'
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
// 🆕 STATIC FILE SERVING
|
// 🆕 IMPROVED STATIC FILE SERVING
|
||||||
// Use absolute path that matches Docker container structure
|
const findFrontendBuildPath = (): string | null => {
|
||||||
const frontendBuildPath = path.resolve('/app/frontend-build');
|
const possiblePaths = [
|
||||||
console.log('📁 Frontend build path:', frontendBuildPath);
|
// Production path (Docker)
|
||||||
|
'/app/frontend-build',
|
||||||
|
// Development paths
|
||||||
|
path.resolve(__dirname, '../../frontend/dist'),
|
||||||
|
path.resolve(__dirname, '../../frontend-build'),
|
||||||
|
path.resolve(process.cwd(), '../frontend/dist'),
|
||||||
|
path.resolve(process.cwd(), 'frontend-build'),
|
||||||
|
];
|
||||||
|
|
||||||
|
for (const testPath of possiblePaths) {
|
||||||
|
try {
|
||||||
|
if (fs.existsSync(testPath)) {
|
||||||
|
const indexPath = path.join(testPath, 'index.html');
|
||||||
|
if (fs.existsSync(indexPath)) {
|
||||||
|
console.log('✅ Found frontend build at:', testPath);
|
||||||
|
return testPath;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
// Silent catch - just try next path
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
};
|
||||||
|
|
||||||
|
const frontendBuildPath = findFrontendBuildPath();
|
||||||
|
|
||||||
if (frontendBuildPath) {
|
if (frontendBuildPath) {
|
||||||
// Serviere statische Dateien
|
|
||||||
app.use(express.static(frontendBuildPath));
|
app.use(express.static(frontendBuildPath));
|
||||||
|
|
||||||
// List files for debugging
|
|
||||||
try {
|
|
||||||
const files = fs.readdirSync(frontendBuildPath);
|
|
||||||
console.log('📄 Files in frontend-build:', files);
|
|
||||||
} catch (err) {
|
|
||||||
console.log('❌ Could not read frontend-build directory:', err);
|
|
||||||
}
|
|
||||||
|
|
||||||
console.log('✅ Static file serving configured');
|
console.log('✅ Static file serving configured');
|
||||||
} else {
|
} else {
|
||||||
console.log('❌ Frontend build directory NOT FOUND in any location');
|
console.log(isDevelopment ?
|
||||||
|
'🔧 Development: Frontend served by Vite dev server (localhost:3003)' :
|
||||||
|
'❌ Production: No frontend build found'
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Root route
|
// Root route
|
||||||
app.get('/', (req, res) => {
|
app.get('/', (req, res) => {
|
||||||
if (!frontendBuildPath) {
|
if (!frontendBuildPath) {
|
||||||
|
if (isDevelopment) {
|
||||||
|
return res.redirect('http://localhost:3003');
|
||||||
|
}
|
||||||
return res.status(500).send('Frontend build not found');
|
return res.status(500).send('Frontend build not found');
|
||||||
}
|
}
|
||||||
|
|
||||||
const indexPath = path.join(frontendBuildPath, 'index.html');
|
const indexPath = path.join(frontendBuildPath, 'index.html');
|
||||||
console.log('📄 Serving index.html from:', indexPath);
|
res.sendFile(indexPath);
|
||||||
|
|
||||||
if (fs.existsSync(indexPath)) {
|
|
||||||
res.sendFile(indexPath);
|
|
||||||
} else {
|
|
||||||
console.error('❌ index.html not found at:', indexPath);
|
|
||||||
res.status(404).send('Frontend not found - index.html missing');
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
|
|
||||||
// Client-side routing fallback
|
// Client-side routing fallback
|
||||||
app.get('*', (req, res) => {
|
app.get('*', (req, res) => {
|
||||||
// Ignoriere API Routes
|
|
||||||
if (req.path.startsWith('/api/')) {
|
if (req.path.startsWith('/api/')) {
|
||||||
return res.status(404).json({ error: 'API endpoint not found' });
|
return res.status(404).json({ error: 'API endpoint not found' });
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!frontendBuildPath) {
|
if (!frontendBuildPath) {
|
||||||
|
if (isDevelopment) {
|
||||||
|
return res.redirect(`http://localhost:3003${req.path}`);
|
||||||
|
}
|
||||||
return res.status(500).json({ error: 'Frontend application not available' });
|
return res.status(500).json({ error: 'Frontend application not available' });
|
||||||
}
|
}
|
||||||
|
|
||||||
const indexPath = path.join(frontendBuildPath, 'index.html');
|
const indexPath = path.join(frontendBuildPath, 'index.html');
|
||||||
console.log('🔄 Client-side routing for:', req.path, '->', indexPath);
|
res.sendFile(indexPath);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Error handling
|
||||||
|
app.use((err: any, req: express.Request, res: express.Response, next: express.NextFunction) => {
|
||||||
|
console.error('Error:', err);
|
||||||
|
|
||||||
if (fs.existsSync(indexPath)) {
|
if (process.env.NODE_ENV === 'production') {
|
||||||
// Use absolute path with res.sendFile
|
res.status(500).json({
|
||||||
res.sendFile(indexPath, (err) => {
|
error: 'Internal server error',
|
||||||
if (err) {
|
message: 'Something went wrong'
|
||||||
console.error('Error sending index.html:', err);
|
|
||||||
res.status(500).send('Error loading application');
|
|
||||||
}
|
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
console.error('❌ index.html not found for client-side routing at:', indexPath);
|
res.status(500).json({
|
||||||
res.status(404).json({ error: 'Frontend application not found' });
|
error: 'Internal server error',
|
||||||
|
message: err.message,
|
||||||
|
stack: err.stack
|
||||||
|
});
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
// Error handling middleware
|
// 404 handling
|
||||||
app.use((err: any, req: express.Request, res: express.Response, next: express.NextFunction) => {
|
app.use('*', (req, res) => {
|
||||||
console.error('Unhandled error:', err);
|
res.status(404).json({ error: 'Endpoint not found' });
|
||||||
res.status(500).json({ error: 'Internal server error' });
|
|
||||||
});
|
});
|
||||||
|
|
||||||
// Initialize the application
|
// Initialize the application
|
||||||
const initializeApp = async () => {
|
const initializeApp = async () => {
|
||||||
try {
|
try {
|
||||||
// Initialize database with base schema
|
|
||||||
await initializeDatabase();
|
await initializeDatabase();
|
||||||
|
|
||||||
// Apply any pending migrations
|
|
||||||
const { applyMigration } = await import('./scripts/applyMigration.js');
|
const { applyMigration } = await import('./scripts/applyMigration.js');
|
||||||
await applyMigration();
|
await applyMigration();
|
||||||
|
|
||||||
// Start server only after successful initialization
|
|
||||||
app.listen(PORT, () => {
|
app.listen(PORT, () => {
|
||||||
console.log('🎉 APPLICATION STARTED SUCCESSFULLY!');
|
console.log('🎉 APPLICATION STARTED SUCCESSFULLY!');
|
||||||
console.log(`📍 Port: ${PORT}`);
|
console.log(`📍 Port: ${PORT}`);
|
||||||
console.log(`📍 Frontend: http://localhost:${PORT}`);
|
console.log(`📍 Mode: ${process.env.NODE_ENV || 'development'}`);
|
||||||
|
if (frontendBuildPath) {
|
||||||
|
console.log(`📍 Frontend: http://localhost:${PORT}`);
|
||||||
|
} else if (isDevelopment) {
|
||||||
|
console.log(`📍 Frontend (Vite): http://localhost:3003`);
|
||||||
|
}
|
||||||
console.log(`📍 API: http://localhost:${PORT}/api`);
|
console.log(`📍 API: http://localhost:${PORT}/api`);
|
||||||
console.log('');
|
|
||||||
console.log(`🔧 Setup: http://localhost:${PORT}/api/setup/status`);
|
|
||||||
console.log('📝 Create your admin account on first launch');
|
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
console.error('❌ Error during initialization:', error);
|
console.error('❌ Error during initialization:', error);
|
||||||
@@ -135,5 +198,4 @@ const initializeApp = async () => {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
// Start the application
|
|
||||||
initializeApp();
|
initializeApp();
|
||||||
@@ -4,11 +4,19 @@ services:
|
|||||||
schichtplaner:
|
schichtplaner:
|
||||||
container_name: schichtplaner
|
container_name: schichtplaner
|
||||||
image: ghcr.io/donpat1to/schichtenplaner:v1.0.0
|
image: ghcr.io/donpat1to/schichtenplaner:v1.0.0
|
||||||
|
environment:
|
||||||
|
- NODE_ENV=production
|
||||||
|
- JWT_SECRET=${JWT_SECRET:-your-secret-key-please-change}
|
||||||
ports:
|
ports:
|
||||||
- "3002:3002"
|
- "3002:3002"
|
||||||
volumes:
|
volumes:
|
||||||
- app_data:/app/data
|
- app_data:/app/data
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
healthcheck:
|
||||||
|
test: ["CMD", "curl", "-f", "http://localhost:3002/api/health"]
|
||||||
|
interval: 30s
|
||||||
|
timeout: 10s
|
||||||
|
retries: 3
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
app_data:
|
app_data:
|
||||||
50
docker-init.sh
Normal file
50
docker-init.sh
Normal file
@@ -0,0 +1,50 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
set -e
|
||||||
|
|
||||||
|
echo "🚀 Container Initialisierung gestartet..."
|
||||||
|
|
||||||
|
# Funktion zum Generieren eines sicheren Secrets
|
||||||
|
generate_secret() {
|
||||||
|
length=$1
|
||||||
|
tr -dc 'A-Za-z0-9!@#$%^&*()_+-=' < /dev/urandom | head -c $length
|
||||||
|
}
|
||||||
|
|
||||||
|
# Prüfe ob .env existiert
|
||||||
|
if [ ! -f /app/.env ]; then
|
||||||
|
echo "📝 Erstelle .env Datei..."
|
||||||
|
|
||||||
|
# Verwende vorhandenes JWT_SECRET oder generiere ein neues
|
||||||
|
if [ -z "$JWT_SECRET" ] || [ "$JWT_SECRET" = "your-secret-key-please-change" ]; then
|
||||||
|
export JWT_SECRET=$(generate_secret 64)
|
||||||
|
echo "🔑 Automatisch sicheres JWT Secret generiert"
|
||||||
|
else
|
||||||
|
echo "🔑 Verwende vorhandenes JWT Secret aus Umgebungsvariable"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Erstelle .env aus Template mit envsubst
|
||||||
|
envsubst < /app/.env.template > /app/.env
|
||||||
|
echo "✅ .env Datei erstellt"
|
||||||
|
|
||||||
|
else
|
||||||
|
echo "ℹ️ .env Datei existiert bereits"
|
||||||
|
|
||||||
|
# Wenn .env existiert, aber JWT_SECRET Umgebungsvariable gesetzt ist, aktualisiere sie
|
||||||
|
if [ -n "$JWT_SECRET" ] && [ "$JWT_SECRET" != "your-secret-key-please-change" ]; then
|
||||||
|
echo "🔑 Aktualisiere JWT Secret in .env Datei"
|
||||||
|
# Aktualisiere nur das JWT_SECRET in der .env Datei
|
||||||
|
sed -i "s/^JWT_SECRET=.*/JWT_SECRET=$JWT_SECRET/" /app/.env
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Validiere dass JWT_SECERT nicht der Standardwert ist
|
||||||
|
if grep -q "JWT_SECRET=your-secret-key-please-change" /app/.env; then
|
||||||
|
echo "❌ FEHLER: Standard JWT Secret in .env gefunden!"
|
||||||
|
echo "❌ Bitte setzen Sie JWT_SECRET Umgebungsvariable"
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Setze sichere Berechtigungen
|
||||||
|
chmod 600 /app/.env
|
||||||
|
|
||||||
|
echo "🔧 Starte Anwendung..."
|
||||||
|
exec "$@"
|
||||||
@@ -6,7 +6,8 @@
|
|||||||
"dependencies": {
|
"dependencies": {
|
||||||
"react": "^19.0.0",
|
"react": "^19.0.0",
|
||||||
"react-dom": "^19.0.0",
|
"react-dom": "^19.0.0",
|
||||||
"react-router-dom": "^6.28.0"
|
"react-router-dom": "^6.28.0",
|
||||||
|
"date-fns": "4.1.0"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@types/node": "20.19.23",
|
"@types/node": "20.19.23",
|
||||||
@@ -16,7 +17,9 @@
|
|||||||
"@vitejs/plugin-react": "^4.3.3",
|
"@vitejs/plugin-react": "^4.3.3",
|
||||||
"typescript": "^5.7.3",
|
"typescript": "^5.7.3",
|
||||||
"vite": "^6.0.7",
|
"vite": "^6.0.7",
|
||||||
"esbuild": "^0.21.0"
|
"esbuild": "^0.21.0",
|
||||||
|
"terser": "5.44.0",
|
||||||
|
"babel-plugin-transform-remove-console": "6.9.4"
|
||||||
},
|
},
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"dev": "vite",
|
"dev": "vite",
|
||||||
|
|||||||
@@ -185,7 +185,7 @@ const EmployeeForm: React.FC<EmployeeFormProps> = ({
|
|||||||
// Password change logic remains the same
|
// Password change logic remains the same
|
||||||
if (showPasswordSection && passwordForm.newPassword && hasRole(['admin'])) {
|
if (showPasswordSection && passwordForm.newPassword && hasRole(['admin'])) {
|
||||||
if (passwordForm.newPassword.length < 6) {
|
if (passwordForm.newPassword.length < 6) {
|
||||||
throw new Error('Das neue Passwort muss mindestens 6 Zeichen lang sein');
|
throw new Error('Das Passwort muss mindestens 6 Zeichen lang sein, Zahlen und Groß- / Kleinbuchstaben enthalten');
|
||||||
}
|
}
|
||||||
if (passwordForm.newPassword !== passwordForm.confirmPassword) {
|
if (passwordForm.newPassword !== passwordForm.confirmPassword) {
|
||||||
throw new Error('Die Passwörter stimmen nicht überein');
|
throw new Error('Die Passwörter stimmen nicht überein');
|
||||||
@@ -351,10 +351,10 @@ const EmployeeForm: React.FC<EmployeeFormProps> = ({
|
|||||||
borderRadius: '4px',
|
borderRadius: '4px',
|
||||||
fontSize: '16px'
|
fontSize: '16px'
|
||||||
}}
|
}}
|
||||||
placeholder="Mindestens 6 Zeichen"
|
placeholder="Mindestens 6 Zeichen, Zahlen, Groß- / Kleinzeichen"
|
||||||
/>
|
/>
|
||||||
<div style={{ fontSize: '12px', color: '#7f8c8d', marginTop: '5px' }}>
|
<div style={{ fontSize: '12px', color: '#7f8c8d', marginTop: '5px' }}>
|
||||||
Das Passwort muss mindestens 6 Zeichen lang sein.
|
Das Passwort muss mindestens 6 Zeichen lang sein, Zahlen und Groß- / Kleinbuchstaben enthalten.
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
@@ -672,7 +672,7 @@ const EmployeeForm: React.FC<EmployeeFormProps> = ({
|
|||||||
borderRadius: '4px',
|
borderRadius: '4px',
|
||||||
fontSize: '16px'
|
fontSize: '16px'
|
||||||
}}
|
}}
|
||||||
placeholder="Mindestens 6 Zeichen"
|
placeholder="Mindestens 6 Zeichen, Zahlen, Groß- / Kleinzeichen"
|
||||||
/>
|
/>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
|||||||
@@ -107,7 +107,7 @@
|
|||||||
|
|
||||||
.createButton {
|
.createButton {
|
||||||
padding: 10px 20px;
|
padding: 10px 20px;
|
||||||
background-color: #2ecc71;
|
background-color: #51258f;
|
||||||
color: white;
|
color: white;
|
||||||
border: none;
|
border: none;
|
||||||
border-radius: 4px;
|
border-radius: 4px;
|
||||||
@@ -116,7 +116,7 @@
|
|||||||
}
|
}
|
||||||
|
|
||||||
.createButton:hover {
|
.createButton:hover {
|
||||||
background-color: #27ae60;
|
background-color: #51258f;
|
||||||
}
|
}
|
||||||
|
|
||||||
.createButton:disabled {
|
.createButton:disabled {
|
||||||
|
|||||||
@@ -1,45 +1,203 @@
|
|||||||
import { defineConfig } from 'vite'
|
import { defineConfig, loadEnv } from 'vite'
|
||||||
import react from '@vitejs/plugin-react'
|
import react from '@vitejs/plugin-react'
|
||||||
import { resolve } from 'path'
|
import { resolve } from 'path'
|
||||||
|
|
||||||
// https://vitejs.dev/config/
|
// Security-focused Vite configuration
|
||||||
export default defineConfig({
|
export default defineConfig(({ mode }) => {
|
||||||
plugins: [react()],
|
const isProduction = mode === 'production'
|
||||||
server: {
|
const isDevelopment = mode === 'development'
|
||||||
port: 3003,
|
|
||||||
host: true,
|
// Load environment variables securely
|
||||||
open: true,
|
const env = loadEnv(mode, process.cwd(), '')
|
||||||
proxy: {
|
|
||||||
'/api': {
|
// Strictly defined client-safe environment variables
|
||||||
target: 'http://localhost:3002',
|
const clientEnv = {
|
||||||
changeOrigin: true,
|
NODE_ENV: mode,
|
||||||
secure: false,
|
ENABLE_PRO: env.ENABLE_PRO || 'false',
|
||||||
|
VITE_APP_TITLE: env.APP_TITLE || 'Shift Planning App',
|
||||||
|
VITE_API_URL: isProduction ? '/api' : 'http://localhost:3002/api',
|
||||||
|
}
|
||||||
|
|
||||||
|
return {
|
||||||
|
plugins: [
|
||||||
|
react({
|
||||||
|
// React specific security settings
|
||||||
|
jsxRuntime: 'automatic',
|
||||||
|
babel: {
|
||||||
|
plugins: [
|
||||||
|
// Remove console in production
|
||||||
|
isProduction && ['babel-plugin-transform-remove-console', { exclude: ['error', 'warn'] }]
|
||||||
|
].filter(Boolean)
|
||||||
|
}
|
||||||
|
})
|
||||||
|
],
|
||||||
|
|
||||||
|
server: {
|
||||||
|
port: 3003,
|
||||||
|
host: true,
|
||||||
|
open: isDevelopment,
|
||||||
|
// Security headers for dev server
|
||||||
|
headers: {
|
||||||
|
'X-Content-Type-Options': 'nosniff',
|
||||||
|
'X-Frame-Options': 'DENY',
|
||||||
|
'X-XSS-Protection': '1; mode=block',
|
||||||
|
'Referrer-Policy': 'strict-origin-when-cross-origin',
|
||||||
|
'Permissions-Policy': 'camera=(), microphone=(), location=()'
|
||||||
|
},
|
||||||
|
proxy: {
|
||||||
|
'/api': {
|
||||||
|
target: 'http://localhost:3002',
|
||||||
|
changeOrigin: true,
|
||||||
|
secure: false,
|
||||||
|
}
|
||||||
|
},
|
||||||
|
// Security: disable HMR in non-dev environments
|
||||||
|
hmr: isDevelopment
|
||||||
|
},
|
||||||
|
|
||||||
|
build: {
|
||||||
|
outDir: 'dist',
|
||||||
|
// Security: No source maps in production
|
||||||
|
sourcemap: isDevelopment ? 'inline' : false,
|
||||||
|
// Generate deterministic hashes for better caching and security
|
||||||
|
assetsDir: 'assets',
|
||||||
|
rollupOptions: {
|
||||||
|
output: {
|
||||||
|
// Security: Use content hashes for cache busting and integrity
|
||||||
|
chunkFileNames: 'assets/[name]-[hash].js',
|
||||||
|
entryFileNames: 'assets/[name]-[hash].js',
|
||||||
|
assetFileNames: 'assets/[name]-[hash].[ext]',
|
||||||
|
// Security: Manual chunks to separate vendor code
|
||||||
|
manualChunks: (id) => {
|
||||||
|
if (id.includes('node_modules')) {
|
||||||
|
if (id.includes('react') || id.includes('react-dom')) {
|
||||||
|
return 'vendor-react'
|
||||||
|
}
|
||||||
|
if (id.includes('react-router-dom')) {
|
||||||
|
return 'vendor-router'
|
||||||
|
}
|
||||||
|
return 'vendor'
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
// Minification with security-focused settings
|
||||||
|
minify: isProduction ? 'terser' : false,
|
||||||
|
terserOptions: isProduction ? {
|
||||||
|
compress: {
|
||||||
|
drop_console: true,
|
||||||
|
drop_debugger: true,
|
||||||
|
// Security: Remove potentially sensitive code
|
||||||
|
pure_funcs: [
|
||||||
|
'console.log',
|
||||||
|
'console.info',
|
||||||
|
'console.debug',
|
||||||
|
'console.warn',
|
||||||
|
'console.trace',
|
||||||
|
'console.table',
|
||||||
|
'debugger'
|
||||||
|
],
|
||||||
|
dead_code: true,
|
||||||
|
if_return: true,
|
||||||
|
comparisons: true,
|
||||||
|
loops: true,
|
||||||
|
hoist_funs: true,
|
||||||
|
hoist_vars: true,
|
||||||
|
reduce_vars: true,
|
||||||
|
booleans: true,
|
||||||
|
conditionals: true,
|
||||||
|
evaluate: true,
|
||||||
|
sequences: true,
|
||||||
|
unused: true
|
||||||
|
},
|
||||||
|
mangle: {
|
||||||
|
// Security: Obfuscate code
|
||||||
|
toplevel: true,
|
||||||
|
keep_classnames: false,
|
||||||
|
keep_fnames: false,
|
||||||
|
reserved: [
|
||||||
|
'React',
|
||||||
|
'ReactDOM',
|
||||||
|
'useState',
|
||||||
|
'useEffect',
|
||||||
|
'useContext',
|
||||||
|
'createElement'
|
||||||
|
]
|
||||||
|
},
|
||||||
|
format: {
|
||||||
|
comments: false,
|
||||||
|
beautify: false,
|
||||||
|
// Security: ASCII only to prevent encoding attacks
|
||||||
|
ascii_only: true
|
||||||
|
}
|
||||||
|
} : undefined,
|
||||||
|
// Security: Report bundle size issues
|
||||||
|
reportCompressedSize: true,
|
||||||
|
chunkSizeWarningLimit: 1000,
|
||||||
|
// Security: Don't expose source paths
|
||||||
|
assetsInlineLimit: 4096
|
||||||
|
},
|
||||||
|
|
||||||
|
preview: {
|
||||||
|
port: 3004,
|
||||||
|
headers: {
|
||||||
|
// Security headers for preview server
|
||||||
|
'X-Content-Type-Options': 'nosniff',
|
||||||
|
'X-Frame-Options': 'DENY',
|
||||||
|
'X-XSS-Protection': '1; mode=block',
|
||||||
|
'Strict-Transport-Security': 'max-age=31536000; includeSubDomains',
|
||||||
|
'Referrer-Policy': 'strict-origin-when-cross-origin',
|
||||||
|
'Content-Security-Policy': `
|
||||||
|
default-src 'self';
|
||||||
|
script-src 'self' 'unsafe-inline';
|
||||||
|
style-src 'self' 'unsafe-inline';
|
||||||
|
img-src 'self' data: https:;
|
||||||
|
font-src 'self';
|
||||||
|
connect-src 'self';
|
||||||
|
base-uri 'self';
|
||||||
|
form-action 'self';
|
||||||
|
frame-ancestors 'none';
|
||||||
|
`.replace(/\s+/g, ' ').trim()
|
||||||
|
}
|
||||||
|
},
|
||||||
|
|
||||||
|
resolve: {
|
||||||
|
alias: {
|
||||||
|
'@': resolve(__dirname, './src'),
|
||||||
|
'@/components': resolve(__dirname, './src/components'),
|
||||||
|
'@/pages': resolve(__dirname, './src/pages'),
|
||||||
|
'@/contexts': resolve(__dirname, './src/contexts'),
|
||||||
|
'@/models': resolve(__dirname, './src/models'),
|
||||||
|
'@/utils': resolve(__dirname, './src/utils'),
|
||||||
|
'@/services': resolve(__dirname, './src/services'),
|
||||||
|
'@/design': resolve(__dirname, './src/design')
|
||||||
|
}
|
||||||
|
},
|
||||||
|
|
||||||
|
// ✅ SICHER: Strict environment variable control
|
||||||
|
define: Object.keys(clientEnv).reduce((acc, key) => {
|
||||||
|
acc[`import.meta.env.${key}`] = JSON.stringify(clientEnv[key])
|
||||||
|
return acc
|
||||||
|
}, {} as Record<string, string>),
|
||||||
|
|
||||||
|
// Security: Clear build directory
|
||||||
|
emptyOutDir: true,
|
||||||
|
|
||||||
|
// Security: Optimize dependencies
|
||||||
|
optimizeDeps: {
|
||||||
|
include: ['react', 'react-dom', 'react-router-dom'],
|
||||||
|
exclude: ['@vitejs/plugin-react']
|
||||||
|
},
|
||||||
|
|
||||||
|
// Security: CSS configuration
|
||||||
|
css: {
|
||||||
|
devSourcemap: isDevelopment,
|
||||||
|
modules: {
|
||||||
|
localsConvention: 'camelCase',
|
||||||
|
generateScopedName: isProduction
|
||||||
|
? '[hash:base64:8]'
|
||||||
|
: '[name]__[local]--[hash:base64:5]'
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
},
|
|
||||||
build: {
|
|
||||||
outDir: 'dist',
|
|
||||||
sourcemap: true,
|
|
||||||
rollupOptions: {
|
|
||||||
input: {
|
|
||||||
main: resolve(__dirname, 'index.html')
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
resolve: {
|
|
||||||
alias: {
|
|
||||||
'@': resolve(__dirname, './src'),
|
|
||||||
'@/components': resolve(__dirname, './src/components'),
|
|
||||||
'@/pages': resolve(__dirname, './src/pages'),
|
|
||||||
'@/contexts': resolve(__dirname, './src/contexts'),
|
|
||||||
'@/models': resolve(__dirname, './src/models'),
|
|
||||||
'@/utils': resolve(__dirname, './src/utils'),
|
|
||||||
'@/services': resolve(__dirname, './src/services'),
|
|
||||||
'@/design': resolve(__dirname, './src/design')
|
|
||||||
}
|
|
||||||
},
|
|
||||||
// Define environment variables
|
|
||||||
define: {
|
|
||||||
'process.env': process.env
|
|
||||||
}
|
}
|
||||||
})
|
})
|
||||||
4025
package-lock.json
generated
Normal file
4025
package-lock.json
generated
Normal file
File diff suppressed because it is too large
Load Diff
Reference in New Issue
Block a user