Files
lisilou-portfolio/api/server.js
T
jhodgkin 4ac34ca943
Deploy to Dev / Deploy & Smoke Test (push) Successful in 23s
Add admin config screen (issue #14)
Lets the photographer edit config/site.json from /dashboard instead
of SSHing in and hand-editing the file. Two tiers:
- Quick-edit form for the fields actually touched day to day (site
  title/tagline/hero, photographer bio, contact/social, Venmo
  username, session pricing, theme colors)
- Raw JSON textarea for everything else (portfolio categories,
  locations, session types, Immich settings) - the form's fields are
  a subset of this, not a separate source of truth

Backend: GET/PUT /api/admin/config, gated by the existing requireAdmin
middleware (OIDC admin session or legacy ADMIN_SECRET). PUT validates
the body is an object with the required top-level sections, writes
atomically (temp file + rename), and keeps one prior version as
site.json.bak before overwriting.

Required a docker-compose.yml change: the api service had no volume
mount for config/ at all before this (only portfolio/nginx did, and
read-only) - added a read-write mount so the API can actually write
the file the live site reads.
2026-07-20 06:37:20 +00:00

415 lines
17 KiB
JavaScript

require('dotenv').config();
const express = require('express');
const cors = require('cors');
const fs = require('fs');
const path = require('path');
const db = require('./db');
const { getBusyDates } = require('./google-calendar');
const auth = require('./auth');
const app = express();
const PORT = process.env.PORT || 3001;
const CONTRACTS_DIR = path.join(__dirname, 'contracts');
const SIGNED_DIR = path.join(__dirname, 'signed-contracts');
const CONFIG_PATH = path.join(__dirname, 'config', 'site.json');
const CONFIG_BACKUP_PATH = path.join(__dirname, 'config', 'site.json.bak');
app.use(cors({ origin: process.env.CORS_ORIGIN || '*', credentials: true }));
app.use(express.json({ limit: '10mb' }));
// Fire-and-forget webhook to n8n — failures are logged but never block the booking flow
function notify(event, booking, extra = {}) {
const url = process.env.N8N_WEBHOOK_URL;
if (!url) return;
fetch(url, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
event,
booking,
photographer_email: process.env.PHOTOGRAPHER_EMAIL || 'hello@lisilou.com',
site_url: process.env.SITE_URL || '',
...extra,
}),
}).catch(e => console.error(`[notify] ${event} failed:`, e.message));
}
// ── Auth (issue #10) ──────────────────────────────────────────────────────────
// Admin access is granted by either:
// 1. an Authentik OIDC session whose user is in the admin group (see auth.js), or
// 2. the legacy ADMIN_SECRET bearer token — kept for n8n workflows and tests.
app.use(auth.router);
function requireAdmin(req, res, next) {
const session = auth.getSession(req);
if (session && session.admin) {
req.session = session;
return next();
}
const secret = process.env.ADMIN_SECRET;
const header = req.headers.authorization || '';
if (secret && header === `Bearer ${secret}`) return next();
if (session) return res.status(403).json({ error: 'Admin access required' });
if (!secret && !auth.configured()) {
return res.status(503).json({ error: 'Admin access not configured (set ADMIN_SECRET or OIDC_* vars)' });
}
return res.status(401).json({ error: 'Unauthorized' });
}
// Any signed-in user (client portal)
function requireUser(req, res, next) {
const session = auth.getSession(req);
if (!session) return res.status(401).json({ error: 'Sign in required' });
req.session = session;
next();
}
// ── Public routes ─────────────────────────────────────────────────────────────
app.get('/api/health', (req, res) => {
res.json({ ok: true });
});
// Availability — returns busy dates for a given month from Google Calendar.
// Gracefully returns an empty busy list when Calendar is not configured.
app.get('/api/availability', async (req, res) => {
const year = parseInt(req.query.year, 10);
const month = parseInt(req.query.month, 10);
if (!year || !month || month < 1 || month > 12) {
return res.status(400).json({ error: 'year and month (1-12) are required' });
}
try {
const result = await getBusyDates(year, month);
res.setHeader('Cache-Control', 'public, max-age=300'); // 5-min CDN cache
res.json(result);
} catch (err) {
console.error('[availability]', err.message);
// Don't expose internal error; return empty so the UI can still function
res.json({ busy: [], configured: false, error: 'calendar_unavailable' });
}
});
// Serve the contract template PDF to the frontend PDF.js viewer
app.get('/api/contracts/template', (req, res) => {
const contractPath = path.join(CONTRACTS_DIR, 'model-release.pdf');
if (!fs.existsSync(contractPath)) {
return res.status(404).json({ error: 'Contract template not available' });
}
res.setHeader('Content-Type', 'application/pdf');
res.setHeader('Cache-Control', 'no-store');
res.sendFile(contractPath);
});
// Serve a signed contract PDF (used by n8n email workflow and admin dashboard)
app.get('/api/bookings/:id/contract', (req, res) => {
const id = parseInt(req.params.id, 10);
const booking = db.prepare('SELECT contract_pdf_path FROM bookings WHERE id = ?').get(id);
if (!booking || !booking.contract_pdf_path) {
return res.status(404).json({ error: 'Signed contract not found' });
}
const pdfPath = path.join(__dirname, booking.contract_pdf_path);
if (!fs.existsSync(pdfPath)) {
return res.status(404).json({ error: 'Contract file missing on disk' });
}
res.setHeader('Content-Type', 'application/pdf');
res.setHeader('Content-Disposition', `attachment; filename="contract-booking-${id}.pdf"`);
res.sendFile(pdfPath);
});
app.post('/api/bookings', (req, res) => {
const {
client_name, client_email, client_phone, client_sub,
session_date, session_type, session_length, location,
payment_status,
} = req.body;
if (!client_email || !session_date || !session_type || !session_length) {
return res.status(400).json({ error: 'Missing required fields' });
}
// If the client is signed in, bind the booking to their OIDC identity so it
// shows up in the /my-bookings portal regardless of what email they typed.
const session = auth.getSession(req);
const sub = session ? session.sub : client_sub;
const ps = payment_status || 'pending';
// Record when the client indicated they sent payment
const paymentNotifiedAt = ps === 'pending_confirmation' ? new Date().toISOString() : null;
const result = db.prepare(`
INSERT INTO bookings
(client_name, client_email, client_phone, client_sub, session_date, session_type,
session_length, location, payment_status, payment_notified_at)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`).run(
client_name, client_email, client_phone, sub,
session_date, session_type, session_length, location,
ps, paymentNotifiedAt,
);
const booking = db.prepare('SELECT * FROM bookings WHERE id = ?').get(result.lastInsertRowid);
notify('booking_created', booking);
res.status(201).json({ id: result.lastInsertRowid });
});
// Generate a QR code SVG for any URL — used by the Venmo payment step.
app.get('/api/venmo-qr', async (req, res) => {
const { url } = req.query;
if (!url || !url.startsWith('https://venmo.com/')) {
return res.status(400).json({ error: 'url must be a venmo.com URL' });
}
try {
const QRCode = require('qrcode');
const svg = await QRCode.toString(url, { type: 'svg', margin: 2, width: 220, color: { dark: '#2C2C2C', light: '#FDFBF9' } });
res.setHeader('Content-Type', 'image/svg+xml');
res.setHeader('Cache-Control', 'public, max-age=3600');
res.send(svg);
} catch (err) {
res.status(500).json({ error: 'QR generation failed' });
}
});
// Stamp the signature onto the contract PDF and record it
app.post('/api/bookings/:id/sign', async (req, res) => {
const id = parseInt(req.params.id, 10);
const { signature_png, full_name } = req.body;
if (!signature_png || !full_name) {
return res.status(400).json({ error: 'signature_png and full_name are required' });
}
const booking = db.prepare('SELECT * FROM bookings WHERE id = ?').get(id);
if (!booking) return res.status(404).json({ error: 'Booking not found' });
const contractTemplate = path.join(CONTRACTS_DIR, 'model-release.pdf');
let pdfPath = null;
if (fs.existsSync(contractTemplate)) {
try {
const { PDFDocument, rgb, StandardFonts } = require('pdf-lib');
const pdfBytes = fs.readFileSync(contractTemplate);
const pdfDoc = await PDFDocument.load(pdfBytes);
const pages = pdfDoc.getPages();
const sigPageIndex = Math.max(0, parseInt(process.env.CONTRACT_SIG_PAGE || '1', 10) - 1);
const sigX = parseFloat(process.env.CONTRACT_SIG_X || '100');
const sigY = parseFloat(process.env.CONTRACT_SIG_Y || '100');
const page = pages[Math.min(sigPageIndex, pages.length - 1)];
const sigBase64 = signature_png.replace(/^data:image\/png;base64,/, '');
const sigImage = await pdfDoc.embedPng(Buffer.from(sigBase64, 'base64'));
const imgDims = sigImage.scaleToFit(200, 60);
page.drawImage(sigImage, { x: sigX, y: sigY, width: imgDims.width, height: imgDims.height });
const font = await pdfDoc.embedFont(StandardFonts.Helvetica);
const dateStr = new Date().toLocaleDateString('en-US', { year: 'numeric', month: 'long', day: 'numeric' });
page.drawText(`${full_name} · ${dateStr} · Booking #${id}`, {
x: sigX,
y: sigY - 14,
size: 9,
font,
color: rgb(0.2, 0.2, 0.2),
});
fs.mkdirSync(SIGNED_DIR, { recursive: true });
const outPath = path.join(SIGNED_DIR, `${id}.pdf`);
fs.writeFileSync(outPath, await pdfDoc.save());
pdfPath = `signed-contracts/${id}.pdf`;
} catch (err) {
console.error('PDF stamping failed:', err.message);
}
}
const now = new Date().toISOString();
db.prepare(`
UPDATE bookings SET contract_signed_at = ?, contract_pdf_path = ? WHERE id = ?
`).run(now, pdfPath, id);
const updated = db.prepare('SELECT * FROM bookings WHERE id = ?').get(id);
const contractUrl = pdfPath
? `${process.env.SITE_URL || ''}/api/bookings/${id}/contract`
: null;
notify('contract_signed', updated, { contract_url: contractUrl });
res.json({ ok: true, signed_at: now, pdf_path: pdfPath });
});
// ── Client portal (issue #13) ─────────────────────────────────────────────────
// Bookings belonging to the signed-in client, matched by OIDC subject or email.
app.get('/api/my-bookings', requireUser, (req, res) => {
const { sub, email } = req.session;
const bookings = db.prepare(`
SELECT id, created_at, session_date, session_type, session_length, location,
contract_signed_at, payment_status, status
FROM bookings
WHERE (client_sub = ? AND client_sub IS NOT NULL)
OR (client_email = ? AND client_email IS NOT NULL)
ORDER BY session_date DESC
`).all(sub, email || '');
res.json(bookings);
});
// Signed contract download for the booking's owner (admin route also exists)
app.get('/api/my-bookings/:id/contract', requireUser, (req, res) => {
const id = parseInt(req.params.id, 10);
const booking = db.prepare('SELECT * FROM bookings WHERE id = ?').get(id);
if (!booking) return res.status(404).json({ error: 'Not found' });
const { sub, email } = req.session;
const owns = (booking.client_sub && booking.client_sub === sub) ||
(booking.client_email && email && booking.client_email === email);
if (!owns) return res.status(403).json({ error: 'Not your booking' });
if (!booking.contract_pdf_path) return res.status(404).json({ error: 'No signed contract' });
const pdfPath = path.join(__dirname, booking.contract_pdf_path);
if (!fs.existsSync(pdfPath)) return res.status(404).json({ error: 'Contract file missing on disk' });
res.setHeader('Content-Type', 'application/pdf');
res.setHeader('Content-Disposition', `attachment; filename="contract-booking-${id}.pdf"`);
res.sendFile(pdfPath);
});
// ── Admin routes (OIDC admin session or ADMIN_SECRET bearer token) ────────────
// Stats: counts + next upcoming bookings for the Overview panel
app.get('/api/admin/stats', requireAdmin, (req, res) => {
const now = new Date().toISOString().slice(0, 10);
const monthEnd = new Date(Date.now() + 30 * 864e5).toISOString().slice(0, 10);
const counts = db.prepare(`
SELECT
COUNT(*) FILTER (WHERE session_date >= ? AND session_date <= ? AND status != 'cancelled') AS upcoming,
COUNT(*) FILTER (WHERE payment_status = 'pending_confirmation') AS pending_payment,
COUNT(*) FILTER (WHERE payment_status = 'confirmed') AS confirmed_payment,
COUNT(*) FILTER (WHERE session_length = 'mini' AND payment_status = 'confirmed') AS confirmed_mini,
COUNT(*) FILTER (WHERE session_length = 'full' AND payment_status = 'confirmed') AS confirmed_full
FROM bookings
`).get(now, monthEnd);
const nextUp = db.prepare(`
SELECT id, client_name, client_email, session_date, session_type, session_length,
location, payment_status, status, contract_signed_at
FROM bookings
WHERE session_date >= ? AND status != 'cancelled'
ORDER BY session_date ASC LIMIT 5
`).all(now);
res.json({ ...counts, nextUpcoming: nextUp });
});
// List bookings with optional filters
app.get('/api/admin/bookings', requireAdmin, (req, res) => {
const { status, payment_status, from, to, search, sort = 'session_date', dir = 'asc' } = req.query;
const allowed = ['session_date', 'created_at', 'client_name', 'payment_status', 'status'];
const sortCol = allowed.includes(sort) ? sort : 'session_date';
const sortDir = dir === 'desc' ? 'DESC' : 'ASC';
const conditions = [];
const params = [];
if (status) { conditions.push('status = ?'); params.push(status); }
if (payment_status) { conditions.push('payment_status = ?'); params.push(payment_status); }
if (from) { conditions.push('session_date >= ?'); params.push(from); }
if (to) { conditions.push('session_date <= ?'); params.push(to); }
if (search) {
conditions.push('(client_name LIKE ? OR client_email LIKE ?)');
params.push(`%${search}%`, `%${search}%`);
}
const where = conditions.length ? `WHERE ${conditions.join(' AND ')}` : '';
const bookings = db.prepare(
`SELECT * FROM bookings ${where} ORDER BY ${sortCol} ${sortDir}`
).all(...params);
res.json(bookings);
});
// Single booking
app.get('/api/admin/bookings/:id', requireAdmin, (req, res) => {
const booking = db.prepare('SELECT * FROM bookings WHERE id = ?').get(parseInt(req.params.id, 10));
if (!booking) return res.status(404).json({ error: 'Not found' });
res.json(booking);
});
// Update booking fields — payment confirm triggers n8n webhook
app.patch('/api/admin/bookings/:id', requireAdmin, (req, res) => {
const id = parseInt(req.params.id, 10);
const booking = db.prepare('SELECT * FROM bookings WHERE id = ?').get(id);
if (!booking) return res.status(404).json({ error: 'Not found' });
const allowed = ['payment_status', 'status', 'notes', 'session_date', 'location'];
const updates = {};
for (const key of allowed) {
if (key in req.body) updates[key] = req.body[key];
}
if (Object.keys(updates).length === 0) return res.status(400).json({ error: 'No valid fields' });
const setClauses = Object.keys(updates).map(k => `${k} = ?`).join(', ');
db.prepare(`UPDATE bookings SET ${setClauses} WHERE id = ?`).run(...Object.values(updates), id);
const updated = db.prepare('SELECT * FROM bookings WHERE id = ?').get(id);
if (updates.payment_status === 'confirmed' && booking.payment_status !== 'confirmed') {
notify('payment_confirmed', updated);
}
res.json(updated);
});
// CSV export of all bookings
app.get('/api/admin/payments/export', requireAdmin, (req, res) => {
const bookings = db.prepare('SELECT * FROM bookings ORDER BY session_date ASC').all();
const cols = ['id', 'created_at', 'client_name', 'client_email', 'client_phone',
'session_date', 'session_type', 'session_length', 'location',
'contract_signed_at', 'payment_status', 'payment_notified_at', 'status', 'notes'];
const escape = v => v == null ? '' : `"${String(v).replace(/"/g, '""')}"`;
const header = cols.join(',');
const rows = bookings.map(b => cols.map(c => escape(b[c])).join(','));
const csv = [header, ...rows].join('\r\n');
const date = new Date().toISOString().slice(0, 10);
res.setHeader('Content-Type', 'text/csv');
res.setHeader('Content-Disposition', `attachment; filename="lisilou-bookings-${date}.csv"`);
res.send(csv);
});
// Site config (issue #14) — lets the photographer edit config/site.json from
// the browser instead of SSHing in. Requires the api service to have a
// read-write mount for ./config (see docker-compose.yml); the portfolio/nginx
// service's own mount of the same host directory is read-only.
app.get('/api/admin/config', requireAdmin, (req, res) => {
try {
res.type('application/json').send(fs.readFileSync(CONFIG_PATH, 'utf8'));
} catch (e) {
res.status(500).json({ error: `Could not read config: ${e.message}` });
}
});
app.put('/api/admin/config', requireAdmin, (req, res) => {
const next = req.body;
if (!next || typeof next !== 'object' || Array.isArray(next)) {
return res.status(400).json({ error: 'Body must be a JSON object' });
}
for (const key of ['site', 'photographer', 'contact']) {
if (!next[key] || typeof next[key] !== 'object') {
return res.status(400).json({ error: `Missing or invalid required section: "${key}"` });
}
}
try {
// Keep one prior version so a bad save can be undone by hand - not a
// full history, just a safety net against fat-fingering the editor.
if (fs.existsSync(CONFIG_PATH)) fs.copyFileSync(CONFIG_PATH, CONFIG_BACKUP_PATH);
const tmpPath = `${CONFIG_PATH}.tmp`;
fs.writeFileSync(tmpPath, JSON.stringify(next, null, 2) + '\n');
fs.renameSync(tmpPath, CONFIG_PATH);
res.json({ ok: true });
} catch (e) {
res.status(500).json({ error: `Could not write config: ${e.message}` });
}
});
app.listen(PORT, () => console.log(`API listening on port ${PORT}`));