1 Commits

Author SHA1 Message Date
435ac52ba1 docs: add welcome hello world file 2026-02-21 22:51:52 +00:00
55 changed files with 82 additions and 2908 deletions

View File

@@ -10,15 +10,6 @@ AUTH_URL=https://cloud.campbellwireless.net/trips/auth
# Auth.js secret — generate with: openssl rand -base64 32
AUTH_SECRET=
# Local auth
LOCAL_AUTH_ENABLED=false
LOCAL_AUTH_ARGON2_MEMORY_KB=65536
LOCAL_AUTH_ARGON2_TIME_COST=3
LOCAL_AUTH_ARGON2_PARALLELISM=1
LOCAL_AUTH_MAX_ATTEMPTS=5
LOCAL_AUTH_WINDOW_SECONDS=900
LOCAL_AUTH_LOCKOUT_SECONDS=900
# Admin — comma-separated user IDs (from auth provider) that can access /admin
ADMIN_USER_IDS=

View File

@@ -1,21 +0,0 @@
# E2E test environment — used by the dev server during Playwright runs.
# Never touches trips.db.
AUTH_URL=http://127.0.0.1:5173/trips/auth
AUTH_SECRET=e2e-test-secret-do-not-use-in-production-32b
LOCAL_AUTH_ENABLED=true
LOCAL_AUTH_ARGON2_MEMORY_KB=8192
LOCAL_AUTH_ARGON2_TIME_COST=2
LOCAL_AUTH_ARGON2_PARALLELISM=1
# e2e_admin username is matched by isAdminUser() via DB lookup
ADMIN_USER_IDS=e2e_admin
# Separate test database — never touches trips.db
DATABASE_URL=file:trips.test.db
# Synology OIDC — not exercised in E2E tests but must be present to avoid startup errors
SYNOLOGY_ISSUER=https://cloud.campbellwireless.net/auth/webman/sso
SYNOLOGY_CLIENT_ID=e2e-placeholder
SYNOLOGY_CLIENT_SECRET=e2e-placeholder

View File

@@ -31,14 +31,6 @@
- Framework: Vitest with `node` environment.
- Test file pattern: `src/**/*.test.ts`.
- Keep tests near the code they cover; use `src/tests/stubs` for runtime stubbing.
- For every user-facing feature or behavior change, add/update Playwright e2e coverage under `e2e/`.
- When work is tied to a Gitea issue, record an e2e run video and upload it to that issue.
- One-off video run: `PW_VIDEO_MODE=on PW_TRACE_MODE=on bunx playwright test <spec>`
- Prefer comment-level attachments: post a comment first, then upload the video to that comment.
- Create comment: `tea comment -l <login> -r <owner>/<repo> <issue-index> "<message>"`
- Upload with `curl` (example, `tea api` in this repo's toolchain does not send multipart correctly):
- `TOKEN=$(awk '/- name: cloud.campbellwireless.net/{f=1} f && $1=="token:"{print $2; exit}' "$HOME/Library/Application Support/tea/config.yml")`
- `curl -fsS -X POST "https://cloud.campbellwireless.net/git/api/v1/repos/{owner}/{repo}/issues/comments/{comment_id}/assets" -H "Authorization: token $TOKEN" -F "name=<filename>" -F "attachment=@<path>"`
## Commit & Pull Request Guidelines
- Commit messages currently follow a light “scope) message” pattern, e.g.,

View File

@@ -28,18 +28,6 @@ After making changes, always verify:
1. `bun run lint` — must exit with 0 errors (warnings are acceptable)
2. `bun run test` — all tests must pass
For user-facing feature work, also add/update e2e coverage and validate it:
3. `bunx playwright test <target spec or suite>`
When work maps to a Gitea issue, upload an e2e run video to the issue:
- Generate one-off video artifacts with:
- `PW_VIDEO_MODE=on PW_TRACE_MODE=on bunx playwright test <target spec>`
- Prefer comment-level attachments: create a comment first, then attach video to that comment.
- `tea comment -l <login> -r <owner>/<repo> <issue-index> "<message>"`
- Upload with `curl` (the current `tea api` build here does not send multipart/form-data correctly for attachments):
- `TOKEN=$(awk '/- name: cloud.campbellwireless.net/{f=1} f && $1=="token:"{print $2; exit}' "$HOME/Library/Application Support/tea/config.yml")`
- `curl -fsS -X POST "https://cloud.campbellwireless.net/git/api/v1/repos/{owner}/{repo}/issues/comments/{comment_id}/assets" -H "Authorization: token $TOKEN" -F "name=<filename>" -F "attachment=@<path>"`
### Write unit tests after every major feature
When adding or significantly modifying server-side business logic (files under `src/lib/server/`), write corresponding unit tests in a `.test.ts` file alongside the module (e.g. `src/lib/server/lodgings.test.ts`).

11
HELLOWORLD.md Normal file
View File

@@ -0,0 +1,11 @@
Hello and welcome to the trips project!
We are glad you are here. This repository exists to help you build and
improve travel experiences, and your contributions make it better for
everyone.
If you are new, start by reading the README and checking the scripts and
configuration files to understand how the project is set up. Then pick an
issue or improvement you are interested in and dive in.
Thanks for being part of the team and happy coding!

View File

@@ -43,19 +43,6 @@ bun install
bun run dev
```
## Local authentication
Local auth is optional and off by default. Enable it with the env vars in `.env.example` and ensure users have a matching row in both `users` and `local_credentials`.
To seed a local password hash, use Argon2id with the configured parameters and insert it into `local_credentials`:
```sql
INSERT INTO local_credentials (user_id, password_hash)
VALUES ('<user-id>', '<argon2id hash>');
```
Passwords must be at least 12 characters. Avoid storing plaintext passwords anywhere.
## Quality and Tests
```sh

View File

@@ -6,19 +6,16 @@
"name": "trips",
"dependencies": {
"@auth/sveltekit": "^1.11.1",
"argon2": "^0.41.1",
},
"devDependencies": {
"@biomejs/biome": "^2.4.4",
"@eslint/js": "^10.0.1",
"@playwright/test": "^1.58.2",
"@sveltejs/adapter-node": "^5.5.3",
"@sveltejs/kit": "^2.50.2",
"@sveltejs/vite-plugin-svelte": "^6.2.4",
"@tailwindcss/vite": "^4.2.0",
"@vitest/coverage-v8": "^4.0.18",
"bun-types": "^1.3.9",
"dotenv": "^17.3.1",
"eslint": "^10.0.0",
"eslint-plugin-svelte": "^3.15.0",
"globals": "^17.3.0",
@@ -156,10 +153,6 @@
"@panva/hkdf": ["@panva/hkdf@1.2.1", "", {}, "sha512-6oclG6Y3PiDFcoyk8srjLfVKyMfVCKJ27JwNPViuXziFpmdz+MZnZN/aKY0JGXgYuO/VghU0jcOAZgWXZ1Dmrw=="],
"@phc/format": ["@phc/format@1.0.0", "", {}, "sha512-m7X9U6BG2+J+R1lSOdCiITLLrxm+cWlNI3HUFA92oLO77ObGNzaKdh8pMLqdZcshtkKuV84olNNXDfMc4FezBQ=="],
"@playwright/test": ["@playwright/test@1.58.2", "", { "dependencies": { "playwright": "1.58.2" }, "bin": { "playwright": "cli.js" } }, "sha512-akea+6bHYBBfA9uQqSYmlJXn61cTa+jbO87xVLCWbTqbWadRVmhxlXATaOjOgcBaWU4ePo0wB41KMFv3o35IXA=="],
"@polka/url": ["@polka/url@1.0.0-next.29", "", {}, "sha512-wwQAWhWSuHaag8c4q/KN/vCoeOJYshAIvMQwD4GpSb3OiZklFfvAgmj0VCBBImRpuF/aFgIRzllXlVX93Jevww=="],
"@rollup/plugin-commonjs": ["@rollup/plugin-commonjs@29.0.0", "", { "dependencies": { "@rollup/pluginutils": "^5.0.1", "commondir": "^1.0.1", "estree-walker": "^2.0.2", "fdir": "^6.2.0", "is-reference": "1.2.1", "magic-string": "^0.30.3", "picomatch": "^4.0.2" }, "peerDependencies": { "rollup": "^2.68.0||^3.0.0||^4.0.0" }, "optionalPeers": ["rollup"] }, "sha512-U2YHaxR2cU/yAiwKJtJRhnyLk7cifnQw0zUpISsocBDoHDJn+HTV74ABqnwr5bEgWUwFZC9oFL6wLe21lHu5eQ=="],
@@ -322,8 +315,6 @@
"ajv": ["ajv@6.12.6", "", { "dependencies": { "fast-deep-equal": "^3.1.1", "fast-json-stable-stringify": "^2.0.0", "json-schema-traverse": "^0.4.1", "uri-js": "^4.2.2" } }, "sha512-j3fVLgvTo527anyYyJOGTYJbG+vnnQYvE0m5mmkc1TK+nxAppkCLMIL0aZ4dblVCNoGShhm+kzE4ZUykBoMg4g=="],
"argon2": ["argon2@0.41.1", "", { "dependencies": { "@phc/format": "^1.0.0", "node-addon-api": "^8.1.0", "node-gyp-build": "^4.8.1" } }, "sha512-dqCW8kJXke8Ik+McUcMDltrbuAWETPyU6iq+4AhxqKphWi7pChB/Zgd/Tp/o8xRLbg8ksMj46F/vph9wnxpTzQ=="],
"aria-query": ["aria-query@5.3.2", "", {}, "sha512-COROpnaoap1E2F000S62r6A60uHZnmlvomhfyT2DlTcrY1OrBKn2UhH7qn5wTC9zMvD0AY7csdPSNwKP+7WiQw=="],
"assertion-error": ["assertion-error@2.0.1", "", {}, "sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA=="],
@@ -362,8 +353,6 @@
"devalue": ["devalue@5.6.2", "", {}, "sha512-nPRkjWzzDQlsejL1WVifk5rvcFi/y1onBRxjaFMjZeR9mFpqu2gmAZ9xUB9/IEanEP/vBtGeGganC/GO1fmufg=="],
"dotenv": ["dotenv@17.3.1", "", {}, "sha512-IO8C/dzEb6O3F9/twg6ZLXz164a2fhTnEWb95H23Dm4OuN+92NmEAlTrupP9VW6Jm3sO26tQlqyvyi4CsnY9GA=="],
"enhanced-resolve": ["enhanced-resolve@5.19.0", "", { "dependencies": { "graceful-fs": "^4.2.4", "tapable": "^2.3.0" } }, "sha512-phv3E1Xl4tQOShqSte26C7Fl84EwUdZsyOuSSk9qtAGyyQs2s3jJzComh+Abf4g187lUUAvH+H26omrqia2aGg=="],
"es-module-lexer": ["es-module-lexer@1.7.0", "", {}, "sha512-jEQoCwk8hyb2AZziIOLhDqpm5+2ww5uIE6lkO/6jcOCusfk6LhMHpXXfBLXTZ7Ydyt0j4VoUQv6uGNYbdW+kBA=="],
@@ -520,10 +509,6 @@
"natural-compare": ["natural-compare@1.4.0", "", {}, "sha512-OWND8ei3VtNC9h7V60qff3SVobHr996CTwgxubgyQYEpg290h9J0buyECNNJexkFm5sOajh5G116RYA1c8ZMSw=="],
"node-addon-api": ["node-addon-api@8.5.0", "", {}, "sha512-/bRZty2mXUIFY/xU5HLvveNHlswNJej+RnxBjOMkidWfwZzgTbPG1E3K5TOxRLOR+5hX7bSofy8yf1hZevMS8A=="],
"node-gyp-build": ["node-gyp-build@4.8.4", "", { "bin": { "node-gyp-build": "bin.js", "node-gyp-build-optional": "optional.js", "node-gyp-build-test": "build-test.js" } }, "sha512-LA4ZjwlnUblHVgq0oBF3Jl/6h/Nvs5fzBLwdEF4nuxnFdsfajde4WfxtJr3CaiH+F6ewcIB/q4jQ4UzPyid+CQ=="],
"oauth4webapi": ["oauth4webapi@3.8.5", "", {}, "sha512-A8jmyUckVhRJj5lspguklcl90Ydqk61H3dcU0oLhH3Yv13KpAliKTt5hknpGGPZSSfOwGyraNEFmofDYH+1kSg=="],
"obug": ["obug@2.1.1", "", {}, "sha512-uTqF9MuPraAQ+IsnPf366RG4cP9RtUi7MLO1N3KEc+wb0a6yKpeL0lmk2IB1jY5KHPAlTc6T/JRdC/YqxHNwkQ=="],
@@ -546,10 +531,6 @@
"picomatch": ["picomatch@4.0.3", "", {}, "sha512-5gTmgEY/sqK6gFXLIsQNH19lWb4ebPDLA4SdLP7dsWkIXHWlG66oPuVvXSGFPppYZz8ZDZq0dYYrbHfBCVUb1Q=="],
"playwright": ["playwright@1.58.2", "", { "dependencies": { "playwright-core": "1.58.2" }, "optionalDependencies": { "fsevents": "2.3.2" }, "bin": { "playwright": "cli.js" } }, "sha512-vA30H8Nvkq/cPBnNw4Q8TWz1EJyqgpuinBcHET0YVJVFldr8JDNiU9LaWAE1KqSkRYazuaBhTpB5ZzShOezQ6A=="],
"playwright-core": ["playwright-core@1.58.2", "", { "bin": { "playwright-core": "cli.js" } }, "sha512-yZkEtftgwS8CsfYo7nm0KE8jsvm6i/PTgVtB8DL726wNf6H2IMsDuxCpJj59KDaxCtSnrWan2AeDqM7JBaultg=="],
"postcss": ["postcss@8.5.6", "", { "dependencies": { "nanoid": "^3.3.11", "picocolors": "^1.1.1", "source-map-js": "^1.2.1" } }, "sha512-3Ybi1tAuwAP9s0r1UQ2J4n5Y0G05bJkpUIO0/bI9MhwmD70S5aTWbXGBwxHrelT+XM1k6dM0pk+SwNkpTRN7Pg=="],
"postcss-load-config": ["postcss-load-config@3.1.4", "", { "dependencies": { "lilconfig": "^2.0.5", "yaml": "^1.10.2" }, "peerDependencies": { "postcss": ">=8.0.9", "ts-node": ">=9.0.0" }, "optionalPeers": ["postcss", "ts-node"] }, "sha512-6DiM4E7v4coTE4uzA8U//WhtPwyhiim3eyjEMFCnUpzbrkK9wJHgKDT2mR+HbtSrd/NubVaYTOpSpjUl8NQeRg=="],
@@ -684,8 +665,6 @@
"eslint-plugin-svelte/globals": ["globals@16.5.0", "", {}, "sha512-c/c15i26VrJ4IRt5Z89DnIzCGDn9EcebibhAOjw5ibqEHsE1wLUgkPn9RDmNcUKyU87GeaL633nyJ+pplFR2ZQ=="],
"playwright/fsevents": ["fsevents@2.3.2", "", { "os": "darwin" }, "sha512-xiqMQR4xAeHTuB9uWm+fFRcIOgKBMiOBP+eXiyT7jsgVCq1bkVygt00oASowB7EdtpOHaaPgKt812P9ab+DDKA=="],
"svelte-eslint-parser/eslint-scope": ["eslint-scope@8.4.0", "", { "dependencies": { "esrecurse": "^4.3.0", "estraverse": "^5.2.0" } }, "sha512-sNXOfKCn74rt8RICKMvJS7XKV/Xk9kA7DyJr8mJik3S7Cwgy3qlkkmyS2uQB3jiJg6VNdZd/pDBJu0nvG2NlTg=="],
"svelte-eslint-parser/eslint-visitor-keys": ["eslint-visitor-keys@4.2.1", "", {}, "sha512-Uhdk5sfqcee/9H/rCOJikYz67o0a2Tw2hGRPOG2Y1R2dg7brRe1uG0yaNQDHu+TO/uQPF/5eCapvYSmHUjt7JQ=="],

View File

@@ -1,73 +0,0 @@
import { test, expect, type Locator, type Page } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
const LOGIN_URL = '/trips/login';
const ADMIN_USERS_URL = '/trips/admin/users';
async function loginAsLocalUser(page: Page, username: string, password: string): Promise<void> {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL('**/trips/dashboard', { timeout: 15_000 });
}
function rowForUser(page: Page, username: string): Locator {
return page.getByRole('cell', { name: username }).locator('..');
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('admin sees auth source and can set local password', async ({ page }) => {
const suffix = Date.now();
const username = `e2e_auth_source_${suffix}`;
const fullName = `E2E Auth Source ${suffix}`;
const email = `e2e_auth_source_${suffix}@test.local`;
const password = `InitPass-${suffix}-123`;
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto(ADMIN_USERS_URL);
await expect(page.getByRole('heading', { name: 'Users' })).toBeVisible();
const regularRow = rowForUser(page, TEST_USERS.regular.username);
await expect(regularRow.getByText('Local', { exact: true })).toBeVisible();
const adminRow = rowForUser(page, TEST_USERS.admin.username);
await expect(adminRow.getByText('Local', { exact: true })).toBeVisible();
await page.getByRole('button', { name: 'Add User' }).click();
const addDialog = page.getByRole('dialog', { name: 'Add user' });
await expect(addDialog).toBeVisible();
await addDialog.locator('input[type="text"]').nth(0).fill(username);
await addDialog.locator('input[type="text"]').nth(1).fill(fullName);
await addDialog.locator('input[type="email"]').fill(email);
await addDialog.locator('input[type="password"]').nth(0).fill(password);
await addDialog.locator('input[type="password"]').nth(1).fill(password);
await addDialog.getByRole('button', { name: 'Create user' }).click();
const disposableUserRow = rowForUser(page, username);
await expect(disposableUserRow.getByText('Local', { exact: true })).toBeVisible();
await disposableUserRow.getByRole('button', { name: 'Set local password' }).click();
const dialog = page.getByRole('dialog', { name: 'Set local password' });
await expect(dialog).toBeVisible();
await dialog.getByRole('button', { name: 'Save password' }).click();
await expect(dialog.getByText('Password is required')).toBeVisible();
await dialog.locator('input[type="password"]').nth(0).fill('short');
await dialog.locator('input[type="password"]').nth(1).fill('short');
await dialog.getByRole('button', { name: 'Save password' }).click();
await expect(dialog.getByText('Password must be at least 12 characters')).toBeVisible();
await dialog.locator('input[type="password"]').nth(0).fill('long-enough-password');
await dialog.locator('input[type="password"]').nth(1).fill('long-enough-password-mismatch');
await dialog.getByRole('button', { name: 'Save password' }).click();
await expect(dialog.getByText('Passwords do not match')).toBeVisible();
await dialog.locator('input[type="password"]').nth(0).fill('local-password-123');
await dialog.locator('input[type="password"]').nth(1).fill('local-password-123');
await dialog.getByRole('button', { name: 'Save password' }).click();
await expect(dialog).toBeHidden();
});

View File

@@ -1,49 +0,0 @@
import { test, expect, type Page } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
const LOGIN_URL = '/trips/login';
const ADMIN_USERS_URL = '/trips/admin/users';
const DASHBOARD_URL = '/trips/dashboard';
async function loginAsLocalUser(page: Page, username: string, password: string): Promise<void> {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL(`**${DASHBOARD_URL}`, { timeout: 15_000 });
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('admin can create a local user who can sign in', async ({ page }) => {
const suffix = Date.now();
const username = `e2e_new_user_${suffix}`;
const fullName = `E2E New User ${suffix}`;
const email = `e2e_new_user_${suffix}@test.local`;
const password = `TempPass-${suffix}-123`;
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto(ADMIN_USERS_URL);
await expect(page.getByRole('heading', { name: 'Users' })).toBeVisible();
await page.getByRole('button', { name: 'Add User' }).click();
const addDialog = page.getByRole('dialog', { name: 'Add user' });
await expect(addDialog).toBeVisible();
await addDialog.locator('input[type="text"]').nth(0).fill(username);
await addDialog.locator('input[type="text"]').nth(1).fill(fullName);
await addDialog.locator('input[type="email"]').fill(email);
await addDialog.locator('input[type="password"]').nth(0).fill(password);
await addDialog.locator('input[type="password"]').nth(1).fill(password);
await addDialog.getByRole('button', { name: 'Create user' }).click();
await expect(page.getByRole('cell', { name: username, exact: true })).toBeVisible();
await page.context().clearCookies();
await loginAsLocalUser(page, username, password);
await expect(page).toHaveURL(/\/trips\/dashboard/);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/dashboard/);
});

View File

@@ -1,25 +0,0 @@
import { test, expect, type Page } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
const LOGIN_URL = '/trips/login';
const UPCOMING_URL = '/trips/trips/upcoming';
async function submitLocalLogin(page: Page, username: string, password: string): Promise<void> {
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('redirects back to protected route after local login', async ({ page }) => {
await page.goto(UPCOMING_URL);
await expect(page).toHaveURL(/\/trips\/login/);
await submitLocalLogin(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await page.waitForURL(/\/trips\/(trips\/upcoming|dashboard)/, { timeout: 15_000 });
await expect(page).not.toHaveURL(/\/trips\/auth/);
await expect(page).not.toHaveURL(/\/trips\/login/);
});

View File

@@ -1,56 +0,0 @@
import { test, expect, type Page } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
const LOGIN_URL = '/trips/login';
const DASHBOARD_URL = '/trips/dashboard';
const ADMIN_USERS_URL = '/trips/admin/users';
async function loginAsLocalUser(page: Page, username: string, password: string): Promise<void> {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL(`**${DASHBOARD_URL}`, { timeout: 15_000 });
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test.describe('regular user', () => {
test('can log in and lands on dashboard', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await expect(page).toHaveURL(/\/trips\/dashboard/);
});
test('cannot access admin — redirected to dashboard', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/dashboard/);
});
});
test.describe('admin user', () => {
test('can log in and lands on dashboard', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await expect(page).toHaveURL(/\/trips\/dashboard/);
});
test('can access /admin/users', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/admin\/users/);
await expect(page.locator('h1')).toContainText('Users');
});
});
test.describe('error handling', () => {
test('bad password shows error on login page', async ({ page }) => {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', TEST_USERS.regular.username);
await page.fill('input[name="password"]', 'wrong-password-long-enough');
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL(/error=CredentialsSignin/, { timeout: 10_000 });
await expect(page.locator('.text-rose-700')).toContainText('Invalid credentials');
});
});

View File

@@ -1,44 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { loginAsLocalUser } from './helpers/auth.js';
import { addActivity, addPackingList, createTrip, uniqueSuffix } from './helpers/trip.js';
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('checklists and experiences persist after reload', async ({ page }) => {
const suffix = uniqueSuffix();
const tripName = `E2E Checklist ${suffix}`;
const listName = `Packing ${suffix}`;
const itemOne = `Passport ${suffix}`;
const itemTwo = `Sunscreen ${suffix}`;
const activityName = `Museum Visit ${suffix}`;
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await createTrip(page, { name: tripName, description: 'Checklist persistence coverage' });
await addPackingList(page, { name: listName, items: [itemOne, itemTwo] });
await addActivity(page, { name: activityName });
const toggleRequest = page.waitForResponse(
(response) =>
response.request().method() === 'POST' && response.url().includes('/toggleChecklistItem')
);
await page.getByRole('checkbox', { name: itemOne }).check();
await toggleRequest;
await expect(page.getByRole('checkbox', { name: itemOne })).toBeChecked();
await page.reload();
await expect(page.getByText(activityName, { exact: true })).toBeVisible();
await expect(page.getByRole('checkbox', { name: itemOne })).toBeChecked();
await expect(page.getByRole('checkbox', { name: itemTwo })).not.toBeChecked();
const listCard = page
.getByText(listName, { exact: true })
.locator('xpath=ancestor::div[contains(@class,"rounded-xl")]');
const items = listCard.locator('label');
await expect(items.nth(0)).toContainText(itemOne);
await expect(items.nth(1)).toContainText(itemTwo);
});

View File

@@ -1,9 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { loginAsLocalUser } from './helpers/auth.js';
test('evidence workflow @evidence login to dashboard', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await expect(page).toHaveURL(/\/trips\/dashboard/);
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
});

View File

@@ -1,27 +0,0 @@
import { expect, type Page } from '@playwright/test';
import { TEST_USERS } from '../setup/test-users.js';
const LOGIN_URL = '/trips/login';
const DASHBOARD_URL = '/trips/dashboard';
const PROFILE_URL = '/trips/profile';
export async function loginAsLocalUser(
page: Page,
username: string,
password: string
): Promise<void> {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL(`**${DASHBOARD_URL}`, { timeout: 15_000 });
}
export async function ensureSelfProfile(page: Page, email = TEST_USERS.regular.email): Promise<void> {
await page.goto(PROFILE_URL);
await page.fill('#first_name', 'E2E');
await page.fill('#last_name', 'User');
await page.fill('#email', email);
await page.getByRole('button', { name: 'Save profile' }).click();
await expect(page.getByRole('heading', { name: 'My Profile' })).toBeVisible();
}

View File

@@ -1,159 +0,0 @@
import { expect, type Page } from '@playwright/test';
const NEW_TRIP_URL = '/trips/trips/new';
function escapeRegex(text: string): string {
return text.replace(/[.*+?^${}()|[\]\\]/g, '\\$&');
}
export function uniqueSuffix(): string {
return `${Date.now()}-${Math.floor(Math.random() * 1000)}`;
}
export async function createTrip(
page: Page,
values: { name: string; startDate?: string; description?: string }
): Promise<{ tripUrl: string; tripId: string }> {
await page.goto(NEW_TRIP_URL);
await expect(page.getByRole('heading', { name: 'Plan New Trip' })).toBeVisible();
if (values.startDate) {
await page.getByLabel('Start date').fill(values.startDate);
} else {
await page.getByRole('checkbox', { name: "I don't know yet" }).first().check();
}
if (values.description) {
await page.getByLabel('Description').fill(values.description);
}
await page.locator('input[name="name"]').fill(values.name);
await page.getByRole('button', { name: 'Save' }).click();
await expect(page).toHaveURL(/\/trips\/trips\/(?!new$)[^/?#]+$/, { timeout: 15_000 });
const tripUrl = page.url();
const tripId = tripUrl.split('/').pop() ?? '';
return { tripUrl, tripId };
}
export async function openAddToTripMenuItem(page: Page, label: string): Promise<void> {
const addToTripButton = page.getByRole('button', { name: /^Add to trip$/i });
if (await addToTripButton.isVisible().catch(() => false)) {
await addToTripButton.click();
await page.getByRole('button', { name: label, exact: true }).click();
return;
}
// In the welcome state, button names include label + subtitle.
await page
.getByRole('button', { name: new RegExp(`^${escapeRegex(label)}\\b`, 'i') })
.first()
.click();
}
export async function openAddTraveller(page: Page): Promise<void> {
const existingDialog = page.getByRole('dialog', { name: 'Add traveller' });
if (await existingDialog.isVisible().catch(() => false)) return;
const addToTripButton = page.getByRole('button', { name: /^Add to trip$/i });
if (await addToTripButton.isVisible().catch(() => false)) {
await addToTripButton.click();
await page.getByRole('button', { name: 'Travellers', exact: true }).click();
return;
}
await page.getByRole('button', { name: /^Who's travelling\?/ }).click();
}
export async function addTraveller(
page: Page,
values: { firstName: string; lastName: string; email?: string }
): Promise<void> {
await openAddTraveller(page);
const dialog = page.getByRole('dialog', { name: 'Add traveller' });
await expect(dialog).toBeVisible();
const addNewButton = dialog.getByRole('button', { name: 'Add someone new' });
if (await addNewButton.isVisible().catch(() => false)) {
await addNewButton.click();
}
await dialog.getByLabel('First name', { exact: false }).fill(values.firstName);
await dialog.getByLabel('Last name', { exact: false }).fill(values.lastName);
if (values.email) {
await dialog.getByLabel(/Email/).fill(values.email);
}
await dialog.getByRole('button', { name: 'Add traveller' }).click();
await expect(dialog).toBeHidden();
}
export async function addFlight(
page: Page,
values: {
departureDate: string;
airlineCode: string;
flightNumber: string;
departureAirport: string;
arrivalAirport: string;
}
): Promise<void> {
await openAddToTripMenuItem(page, 'Transportation');
const dialog = page.getByRole('dialog', { name: 'Add transportation' });
await expect(dialog).toBeVisible();
await dialog.getByRole('button', { name: /Flight/ }).click();
const form = dialog.locator('form');
await expect(form.locator('input[name="segments[0][departure_date]"]')).toBeVisible();
await form.locator('input[name="segments[0][departure_date]"]').fill(values.departureDate);
await form.getByPlaceholder('Search airline or enter code').fill(values.airlineCode);
await form.locator('input[name="segments[0][flight_number]"]').fill(values.flightNumber);
await form.getByPlaceholder('Code or search').nth(0).fill(values.departureAirport);
await form.getByPlaceholder('Code or search').nth(1).fill(values.arrivalAirport);
await form.getByRole('button', { name: 'Add transportation' }).click();
await expect(dialog).toBeHidden();
}
export async function addLodging(
page: Page,
values: { name: string; guestNames?: string[] }
): Promise<void> {
await openAddToTripMenuItem(page, 'Lodgings');
const dialog = page.getByRole('dialog', { name: 'Add lodging' });
await expect(dialog).toBeVisible();
await dialog.getByLabel('Name', { exact: false }).fill(values.name);
for (const guestName of values.guestNames ?? []) {
await dialog.getByRole('checkbox', { name: guestName }).check();
}
await dialog.getByRole('button', { name: 'Add lodging' }).click();
await expect(dialog).toBeHidden();
}
export async function addPackingList(
page: Page,
values: { name: string; items: string[] }
): Promise<void> {
await openAddToTripMenuItem(page, 'Packing List');
const dialog = page
.locator('[role="dialog"]')
.filter({ has: page.getByRole('heading', { name: /Packing list/i }) })
.first();
await expect(dialog).toBeVisible();
await dialog.getByLabel('Name', { exact: false }).fill(values.name);
const itemInputs = dialog.getByPlaceholder('Item');
await itemInputs.first().fill(values.items[0]);
for (const item of values.items.slice(1)) {
await dialog.getByRole('button', { name: 'Add item' }).click();
await itemInputs.last().fill(item);
}
await dialog.getByRole('button', { name: 'Add', exact: true }).click();
await expect(dialog).toBeHidden();
}
export async function addActivity(page: Page, values: { name: string }): Promise<void> {
await openAddToTripMenuItem(page, 'Attractions & Activities');
const dialog = page
.locator('[role="dialog"]')
.filter({ has: page.getByRole('heading', { name: /Attraction & activity/i }) })
.first();
await expect(dialog).toBeVisible();
await dialog.getByLabel('Name', { exact: false }).fill(values.name);
await dialog.getByRole('button', { name: 'Add' }).click();
await expect(dialog).toBeHidden();
}

View File

@@ -1,79 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { ensureSelfProfile, loginAsLocalUser } from './helpers/auth.js';
import {
addTraveller,
createTrip,
openAddToTripMenuItem,
openAddTraveller,
uniqueSuffix
} from './helpers/trip.js';
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('lodging guest selection and access boundaries are enforced', async ({ page }) => {
const suffix = uniqueSuffix();
const tripName = `E2E Lodging ${suffix}`;
const guestFirst = 'Jordan';
const guestLast = 'Guest';
const guestEmail = `jordan.${suffix}@test.local`;
const lodgingName = `E2E Lodge ${suffix}`;
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await ensureSelfProfile(page);
const { tripUrl } = await createTrip(page, {
name: tripName,
description: 'Lodging guest coverage'
});
const selfName = 'E2E User';
await openAddTraveller(page);
const travellerDialog = page.getByRole('dialog', { name: 'Add traveller' });
await expect(travellerDialog).toBeVisible();
const selfButton = travellerDialog.getByRole('button', { name: /You/ }).first();
if (await selfButton.isVisible().catch(() => false)) {
await selfButton.click();
await expect(travellerDialog).toBeHidden();
} else {
const selfNameButton = travellerDialog.getByRole('button', { name: selfName }).first();
if (await selfNameButton.isVisible().catch(() => false)) {
await selfNameButton.click();
await expect(travellerDialog).toBeHidden();
} else {
await travellerDialog.getByRole('button', { name: 'Close' }).click();
await expect(travellerDialog).toBeHidden();
}
}
await addTraveller(page, {
firstName: guestFirst,
lastName: guestLast,
email: guestEmail
});
await openAddToTripMenuItem(page, 'Lodgings');
const lodgingDialog = page.getByRole('dialog', { name: 'Add lodging' });
await expect(lodgingDialog).toBeVisible();
const guestName = `${guestFirst} ${guestLast}`;
await expect(lodgingDialog.getByRole('checkbox', { name: guestName })).toBeVisible();
await lodgingDialog.getByLabel('Name', { exact: false }).fill(lodgingName);
await lodgingDialog.getByText(guestName, { exact: true }).click();
await lodgingDialog.getByRole('button', { name: 'Add lodging' }).click();
await expect(lodgingDialog).toBeHidden();
await expect(page.getByText(lodgingName, { exact: true })).toBeVisible();
await page.getByRole('button', { name: 'Edit lodging' }).click();
const editDialog = page.getByRole('dialog', { name: 'Edit lodging' });
await expect(editDialog).toBeVisible();
await expect(editDialog.getByRole('checkbox', { name: guestName })).toBeChecked();
await editDialog.getByRole('button', { name: 'Close' }).click();
await page.context().clearCookies();
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto(tripUrl);
await expect(page.getByText(/Trip not found|Not found/i)).toBeVisible();
});

View File

@@ -1,60 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { loginAsLocalUser } from './helpers/auth.js';
import { createTrip, openAddToTripMenuItem, uniqueSuffix } from './helpers/trip.js';
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('admin can import a package tour and attach it to a trip', async ({ page }) => {
if (!process.env.GADVENTURES_API_KEY) {
test.skip(true, 'G Adventures API key not set for deterministic import');
}
const suffix = uniqueSuffix();
const operatorName = 'G Adventures';
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto('/trips/admin/tour-operators');
await expect(page.getByRole('heading', { name: 'Tour Operators' })).toBeVisible();
await page.getByRole('button', { name: 'Add operator' }).click();
await page.getByPlaceholder('Search or type operator name').fill(operatorName);
await page.getByRole('button', { name: 'Add operator' }).last().click();
await expect(page.getByText(operatorName, { exact: true })).toBeVisible();
const operatorCard = page
.getByText(operatorName, { exact: true })
.locator('xpath=ancestor::div[contains(@class,"rounded-xl")]');
await operatorCard.getByRole('link', { name: 'Tours' }).click();
await expect(page.getByRole('heading', { name: operatorName })).toBeVisible();
await page.getByRole('button', { name: 'Import' }).click();
const importDialog = page.getByRole('dialog', { name: 'Import tours' });
await expect(importDialog).toBeVisible();
await importDialog.getByPlaceholder('Search tours...').fill('a');
const results = importDialog.locator('ul button');
await expect(results.first()).toBeVisible();
const tourTitle = (await results.first().innerText()).trim();
await results.first().click();
await importDialog.getByRole('button', { name: 'Import tour' }).click();
await expect(importDialog).toBeHidden();
await expect(page.getByRole('link', { name: tourTitle })).toBeVisible();
await page.context().clearCookies();
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await createTrip(page, { name: `E2E Tour Trip ${suffix}` });
await openAddToTripMenuItem(page, 'Package Tours');
const addDialog = page.getByRole('dialog', { name: 'Add package tour' });
await expect(addDialog).toBeVisible();
await addDialog.getByPlaceholder('Search or type operator name').fill(operatorName);
await addDialog.getByRole('button', { name: operatorName }).click();
await expect(addDialog.locator('select')).toContainText(tourTitle);
await addDialog.locator('select').first().selectOption({ label: tourTitle });
await addDialog.getByRole('button', { name: 'Add tour' }).click();
await expect(addDialog).toBeHidden();
await expect(page.getByText(tourTitle, { exact: true })).toBeVisible();
});

View File

@@ -1,20 +0,0 @@
import type { FullConfig } from '@playwright/test';
import { spawnSync } from 'child_process';
import { resolve } from 'path';
import { config as dotenvConfig } from 'dotenv';
dotenvConfig({ path: resolve(process.cwd(), '.env.test'), override: true });
async function globalSetup(_config: FullConfig): Promise<void> {
console.log('[e2e] Seeding test database via Bun...');
const result = spawnSync('bun', ['run', 'e2e/setup/seed-db.ts'], {
env: { ...process.env },
stdio: 'inherit',
cwd: process.cwd()
});
if (result.status !== 0) {
throw new Error(`[e2e] DB seed script failed with exit code ${result.status}`);
}
}
export default globalSetup;

View File

@@ -1,17 +0,0 @@
import type { FullConfig } from '@playwright/test';
import { existsSync, unlinkSync } from 'fs';
import { resolve } from 'path';
const DB_PATH = resolve(process.cwd(), 'trips.test.db');
async function globalTeardown(_config: FullConfig): Promise<void> {
for (const ext of ['', '-shm', '-wal']) {
const p = DB_PATH + ext;
if (existsSync(p)) {
unlinkSync(p);
}
}
console.log('[e2e] Removed trips.test.db');
}
export default globalTeardown;

View File

@@ -1,77 +0,0 @@
// Bun script — runs with `bun run e2e/setup/seed-db.ts`.
// Uses bun:sqlite and argon2 directly; must NOT be imported from Node context.
import { Database as BunSqlite } from 'bun:sqlite';
import { existsSync, unlinkSync } from 'fs';
import { resolve } from 'path';
import argon2 from 'argon2';
import { randomUUID } from 'crypto';
import { config as dotenvConfig } from 'dotenv';
import { TEST_USERS } from './test-users.js';
dotenvConfig({ path: resolve(process.cwd(), '.env.test'), override: true });
const DB_PATH = resolve(process.cwd(), 'trips.test.db');
// Delete any existing test DB so we start clean each run
for (const ext of ['', '-shm', '-wal']) {
const p = DB_PATH + ext;
if (existsSync(p)) {
unlinkSync(p);
}
}
const db = new BunSqlite(DB_PATH);
db.exec('PRAGMA foreign_keys = ON');
// Wrap bun:sqlite to match the Database interface expected by runMigrations
const dbWrapper = {
run(sql: string, params: unknown[] = []) {
db.query(sql).run(...(params as [unknown?, ...unknown[]]));
},
get<T = Record<string, unknown>>(sql: string, params: unknown[] = []): T | undefined {
const row = db.query(sql).get(...(params as [unknown?, ...unknown[]]));
return (row === null ? undefined : row) as T | undefined;
},
all<T = Record<string, unknown>>(sql: string, params: unknown[] = []): T[] {
return db.query(sql).all(...(params as [unknown?, ...unknown[]])) as T[];
},
close() {
db.close();
}
};
const { runMigrations } = await import('../../src/lib/server/db/migrations.js');
runMigrations(dbWrapper);
console.log('[e2e] Migrations complete.');
async function hashPassword(password: string): Promise<string> {
return argon2.hash(password, {
type: argon2.argon2id,
memoryCost: 8192,
timeCost: 2,
parallelism: 1
});
}
const regularId = randomUUID();
dbWrapper.run(
`INSERT INTO users (id, username, full_name, email, auth_source) VALUES (?, ?, ?, ?, ?)`,
[regularId, TEST_USERS.regular.username, TEST_USERS.regular.fullName, TEST_USERS.regular.email, 'Local']
);
dbWrapper.run(`INSERT INTO local_credentials (user_id, password_hash) VALUES (?, ?)`, [
regularId,
await hashPassword(TEST_USERS.regular.password)
]);
const adminId = randomUUID();
dbWrapper.run(
`INSERT INTO users (id, username, full_name, email, auth_source) VALUES (?, ?, ?, ?, ?)`,
[adminId, TEST_USERS.admin.username, TEST_USERS.admin.fullName, TEST_USERS.admin.email, 'Local']
);
dbWrapper.run(`INSERT INTO local_credentials (user_id, password_hash) VALUES (?, ?)`, [
adminId,
await hashPassword(TEST_USERS.admin.password)
]);
db.close();
console.log(`[e2e] Seeded users: ${TEST_USERS.regular.username}, ${TEST_USERS.admin.username}`);

View File

@@ -1,15 +0,0 @@
// Shared test user definitions — no runtime deps, importable from both Node and Bun contexts.
export const TEST_USERS = {
regular: {
username: 'e2e_user',
fullName: 'E2E Regular User',
email: 'e2e_user@test.local',
password: 'e2e-regular-password123'
},
admin: {
username: 'e2e_admin',
fullName: 'E2E Admin User',
email: 'e2e_admin@test.local',
password: 'e2e-admin-password123'
}
} as const;

View File

@@ -1,79 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { loginAsLocalUser } from './helpers/auth.js';
import { uniqueSuffix } from './helpers/trip.js';
const DASHBOARD_URL = '/trips/dashboard';
const ADMIN_USERS_URL = '/trips/admin/users';
async function expectDashboardLoaded(page: Parameters<typeof loginAsLocalUser>[0]): Promise<void> {
await expect(page).toHaveURL(/\/trips\/dashboard/);
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('regular user smoke', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await expectDashboardLoaded(page);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/dashboard/);
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
});
test('admin user smoke', async ({ page }) => {
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await expectDashboardLoaded(page);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/admin\/users/);
await expect(page.getByRole('heading', { name: 'Users' })).toBeVisible();
});
test('disposable local user smoke', async ({ page }) => {
const suffix = uniqueSuffix();
const username = `e2e_disposable_${suffix}`;
const fullName = `E2E Disposable ${suffix}`;
const email = `e2e_disposable_${suffix}@test.local`;
const password = `TempPass-${suffix}-1234`;
await loginAsLocalUser(page, TEST_USERS.admin.username, TEST_USERS.admin.password);
await page.goto(ADMIN_USERS_URL);
await expect(page.getByRole('heading', { name: 'Users' })).toBeVisible();
await page.getByRole('button', { name: 'Add User' }).click();
const addDialog = page
.locator('[role="dialog"]')
.filter({ has: page.getByRole('heading', { name: 'Add user' }) })
.first();
await expect(addDialog).toBeVisible();
await addDialog.locator('input[type="text"]').nth(0).fill(username);
await addDialog.locator('input[type="text"]').nth(1).fill(fullName);
await addDialog.getByPlaceholder('name@example.com').fill(email);
await addDialog.locator('input[type="password"]').nth(0).fill(password);
await addDialog.locator('input[type="password"]').nth(1).fill(password);
const createResponse = page.waitForResponse((response) => {
return (
response.url().includes('/admin/api/users') &&
response.request().method() === 'POST' &&
response.ok()
);
});
await addDialog.getByRole('button', { name: 'Create user' }).click();
await createResponse;
await expect(page.getByRole('cell', { name: username, exact: true })).toBeVisible();
await page.context().clearCookies();
await loginAsLocalUser(page, username, password);
await expectDashboardLoaded(page);
await page.goto(ADMIN_USERS_URL);
await expect(page).toHaveURL(/\/trips\/dashboard/);
await expect(page.getByRole('heading', { name: 'Dashboard' })).toBeVisible();
});

View File

@@ -1,51 +0,0 @@
import { test, expect } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
import { loginAsLocalUser } from './helpers/auth.js';
import { addFlight, createTrip, uniqueSuffix } from './helpers/trip.js';
function formatDate(offsetDays: number): string {
const date = new Date();
date.setDate(date.getDate() + offsetDays);
return date.toISOString().slice(0, 10);
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('transportation lifecycle updates the trip view', async ({ page }) => {
const suffix = uniqueSuffix();
const tripName = `E2E Transport ${suffix}`;
const departureDate = formatDate(30);
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await createTrip(page, {
name: tripName,
startDate: departureDate,
description: 'Transportation lifecycle coverage'
});
await addFlight(page, {
departureDate,
airlineCode: 'UA',
flightNumber: '1001',
departureAirport: 'SFO',
arrivalAirport: 'LAX'
});
await expect(page.getByRole('heading', { name: 'Transportation' })).toBeVisible();
await expect(page.getByText(/UA\s*1001/)).toBeVisible();
await page.getByRole('button', { name: 'Edit transportation' }).click();
const editDialog = page.getByRole('dialog', { name: 'Edit transportation' });
await expect(editDialog).toBeVisible();
await editDialog.locator('input[name="segments[0][flight_number]"]').fill('1002');
await editDialog.getByRole('button', { name: 'Save changes' }).click();
await expect(editDialog).toBeHidden();
await expect(page.getByText(/UA\s*1002/)).toBeVisible();
await expect(page.getByText(/UA\s*1001/)).toHaveCount(0);
await page.getByRole('button', { name: 'Remove transportation' }).click();
await expect(page.getByRole('heading', { name: 'Transportation' })).toHaveCount(0);
});

View File

@@ -1,186 +0,0 @@
import { test, expect, type Locator, type Page } from '@playwright/test';
import { TEST_USERS } from './setup/test-users.js';
const LOGIN_URL = '/trips/login';
const PROFILE_URL = '/trips/profile';
function formatDate(offsetDays: number): string {
const date = new Date();
date.setDate(date.getDate() + offsetDays);
return date.toISOString().slice(0, 10);
}
async function loginAsLocalUser(page: Page, username: string, password: string): Promise<void> {
await page.goto(LOGIN_URL);
await page.fill('input[name="identifier"]', username);
await page.fill('input[name="password"]', password);
await page.click('button[type="submit"]:has-text("Sign in locally")');
await page.waitForURL('**/trips/dashboard', { timeout: 15_000 });
}
async function ensureSelfProfile(page: Page): Promise<void> {
await page.goto(PROFILE_URL);
await page.fill('#first_name', 'E2E');
await page.fill('#last_name', 'User');
await page.fill('#email', TEST_USERS.regular.email);
await page.getByRole('button', { name: 'Save profile' }).click();
await expect(page.getByRole('heading', { name: 'My Profile' })).toBeVisible();
}
async function openAddToTripMenuItem(page: Page, label: string): Promise<void> {
await page.getByRole('button', { name: 'Add to trip' }).click();
await page.getByRole('button', { name: label, exact: true }).click();
}
async function addLoggedInTraveller(page: Page): Promise<void> {
await page.getByRole('button', { name: "Who's travelling?" }).click();
const dialog = page.getByRole('dialog', { name: 'Add traveller' });
await expect(dialog).toBeVisible();
const selfButton = dialog.getByRole('button', { name: /You/ }).first();
if (await selfButton.isVisible().catch(() => false)) {
await selfButton.click();
} else {
const firstNameInput = dialog.getByLabel('First name *');
if (!(await firstNameInput.isVisible().catch(() => false))) {
await dialog.getByRole('button', { name: 'Add someone new' }).click();
}
await dialog.getByLabel('First name *').fill('E2E');
await dialog.getByLabel('Last name *').fill('User');
await dialog.getByLabel(/Email/).fill(TEST_USERS.regular.email);
await dialog.getByRole('button', { name: 'Add traveller' }).click();
}
await expect(dialog).toBeHidden();
}
async function addNewTraveller(
page: Page,
firstName: string,
lastName: string,
email: string
): Promise<void> {
await openAddToTripMenuItem(page, 'Travellers');
const dialog = page.getByRole('dialog', { name: 'Add traveller' });
await expect(dialog).toBeVisible();
const firstNameInput = dialog.getByLabel('First name *');
if (!(await firstNameInput.isVisible().catch(() => false))) {
await dialog.getByRole('button', { name: 'Add someone new' }).click();
}
await dialog.getByLabel('First name *').fill(firstName);
await dialog.getByLabel('Last name *').fill(lastName);
await dialog.getByLabel(/Email/).fill(email);
await dialog.getByRole('button', { name: 'Add traveller' }).click();
await expect(dialog).toBeHidden();
}
async function addDestination(page: Page, cityQuery: string, startDate: string): Promise<void> {
await openAddToTripMenuItem(page, 'Destinations');
const dialog = page.getByRole('dialog', { name: 'Add destination' });
await expect(dialog).toBeVisible();
await dialog.getByLabel('City *').fill(cityQuery);
const cityOption = dialog.locator('ul button').filter({ hasText: cityQuery }).first();
await expect(cityOption).toBeVisible();
await cityOption.click();
await dialog.getByLabel('Arrival').fill(startDate);
await dialog.getByRole('button', { name: 'Add to trip' }).click();
await expect(dialog).toBeHidden();
}
async function addFlight(page: Page, departureDate: string): Promise<void> {
await openAddToTripMenuItem(page, 'Transportation');
const transportDialog = page.getByRole('dialog', { name: 'Add transportation' });
await expect(transportDialog).toBeVisible();
await transportDialog.getByRole('button', { name: /Flight/ }).click();
const form = transportDialog.locator('form');
await expect(form.locator('input[name="segments[0][departure_date]"]')).toBeVisible();
await form.locator('input[name="segments[0][departure_date]"]').fill(departureDate);
await form.getByPlaceholder('Search airline or enter code').fill('UA');
await form.locator('input[name="segments[0][flight_number]"]').fill('1001');
await form.getByPlaceholder('Code or search').nth(0).fill('SFO');
await form.getByPlaceholder('Code or search').nth(1).fill('LAX');
await expect(form.getByRole('button', { name: 'Add transportation' })).toBeEnabled();
await form.getByRole('button', { name: 'Add transportation' }).click();
await expect(transportDialog).toBeHidden();
}
async function addLodging(page: Page, lodgingName: string): Promise<void> {
await openAddToTripMenuItem(page, 'Lodgings');
const dialog = page.getByRole('dialog', { name: 'Add lodging' });
await expect(dialog).toBeVisible();
await dialog.getByLabel('Name *').fill(lodgingName);
await dialog.getByRole('button', { name: 'Add lodging' }).click();
await expect(dialog).toBeHidden();
}
async function expectPlanSectionsAndDetails(
page: Page,
tripName: string,
destinationQuery: string,
flightText: RegExp,
lodgingName: string,
travellerLocators: Locator[]
): Promise<void> {
await page.getByRole('link', { name: 'Upcoming Trips' }).click();
await expect(page.getByRole('heading', { name: 'Upcoming Trips' })).toBeVisible();
await expect(page.getByRole('link', { name: tripName })).toBeVisible();
await page.getByRole('link', { name: tripName }).click();
await expect(page.getByRole('heading', { name: tripName })).toBeVisible();
await expect(page.getByRole('heading', { name: 'Destinations' })).toBeVisible();
await expect(page.getByRole('heading', { name: 'Transportation' })).toBeVisible();
await expect(page.getByRole('heading', { name: 'Lodgings' })).toBeVisible();
await expect(page.getByText(destinationQuery, { exact: false })).toBeVisible();
await expect(page.getByText(flightText)).toBeVisible();
await expect(page.getByText(lodgingName, { exact: true })).toBeVisible();
for (const traveller of travellerLocators) {
await expect(traveller).toBeVisible();
}
}
test.beforeEach(async ({ context }) => {
await context.clearCookies();
});
test('regular user can plan a detailed future trip with no end date', async ({ page }) => {
const startDate = formatDate(30);
const tripName = `E2E Future Trip ${Date.now()}`;
const tripDescription = 'Future trip created in Playwright e2e scenario';
const destinationQuery = 'Tokyo';
const lodgingName = `E2E Hotel ${Date.now()}`;
const newTravellerFirstName = 'Jamie';
const newTravellerLastName = 'Companion';
const newTravellerEmail = `jamie+${Date.now()}@test.local`;
await loginAsLocalUser(page, TEST_USERS.regular.username, TEST_USERS.regular.password);
await ensureSelfProfile(page);
await page.getByRole('link', { name: 'Plan New Trip' }).click();
await expect(page.getByRole('heading', { name: 'Plan New Trip' })).toBeVisible();
await page.getByLabel('Trip name *').fill(tripName);
await page.getByLabel('Start date').fill(startDate);
await page.getByLabel('End date').fill('');
await page.getByLabel('Description').fill(tripDescription);
await page.getByRole('button', { name: 'Save' }).click();
await page.waitForURL('**/trips/trips/*', { timeout: 15_000 });
await expect(page.getByRole('heading', { name: tripName })).toBeVisible();
await addLoggedInTraveller(page);
await addNewTraveller(page, newTravellerFirstName, newTravellerLastName, newTravellerEmail);
await addDestination(page, destinationQuery, startDate);
await addFlight(page, startDate);
await addLodging(page, lodgingName);
await expectPlanSectionsAndDetails(page, tripName, destinationQuery, /UA\s*1001/, lodgingName, [
page.getByText('E2E User', { exact: false }),
page.getByText(`${newTravellerFirstName} ${newTravellerLastName}`, { exact: false })
]);
});

View File

@@ -14,22 +14,17 @@
"format": "prettier --write .",
"test": "bunx --bun svelte-kit sync && bunx --bun vitest run",
"test:watch": "bunx --bun svelte-kit sync && bunx --bun vitest",
"test:coverage": "vitest run --coverage",
"test:e2e": "bunx playwright test",
"test:e2e:ui": "bunx playwright test --ui",
"test:e2e:debug": "bunx playwright test --debug"
"test:coverage": "vitest run --coverage"
},
"devDependencies": {
"@biomejs/biome": "^2.4.4",
"@eslint/js": "^10.0.1",
"@playwright/test": "^1.58.2",
"@sveltejs/adapter-node": "^5.5.3",
"@sveltejs/kit": "^2.50.2",
"@sveltejs/vite-plugin-svelte": "^6.2.4",
"@tailwindcss/vite": "^4.2.0",
"@vitest/coverage-v8": "^4.0.18",
"bun-types": "^1.3.9",
"dotenv": "^17.3.1",
"eslint": "^10.0.0",
"eslint-plugin-svelte": "^3.15.0",
"globals": "^17.3.0",
@@ -45,7 +40,6 @@
"vitest": "^4.0.18"
},
"dependencies": {
"@auth/sveltekit": "^1.11.1",
"argon2": "^0.41.1"
"@auth/sveltekit": "^1.11.1"
}
}

View File

@@ -1,53 +0,0 @@
import { defineConfig, devices } from '@playwright/test';
import { config as dotenvConfig } from 'dotenv';
import { resolve } from 'path';
// Load .env.test so both this process and the webServer child process see the values.
dotenvConfig({ path: resolve(process.cwd(), '.env.test'), override: true });
export default defineConfig({
testDir: './e2e',
fullyParallel: false,
forbidOnly: !!process.env.CI,
retries: process.env.CI ? 1 : 0,
workers: 1,
reporter: 'html',
use: {
baseURL: 'http://127.0.0.1:5173',
trace: process.env.PW_TRACE_MODE ?? 'on-first-retry',
video: process.env.PW_VIDEO_MODE ?? 'off'
},
projects: [
{
name: 'chromium',
use: { ...devices['Desktop Chrome'] }
}
],
globalTeardown: './e2e/setup/global-teardown.ts',
webServer: {
// Playwright starts webServer before globalSetup. Seed first so the app
// process opens the final DB file and never sees it replaced underneath.
command: 'bun run e2e/setup/seed-db.ts && bunx --bun vite dev --host 127.0.0.1',
url: 'http://127.0.0.1:5173/trips',
// Always start a fresh server to ensure it uses trips.test.db
reuseExistingServer: false,
timeout: 120_000,
env: {
AUTH_URL: process.env.AUTH_URL!,
AUTH_SECRET: process.env.AUTH_SECRET!,
LOCAL_AUTH_ENABLED: process.env.LOCAL_AUTH_ENABLED!,
LOCAL_AUTH_ARGON2_MEMORY_KB: process.env.LOCAL_AUTH_ARGON2_MEMORY_KB!,
LOCAL_AUTH_ARGON2_TIME_COST: process.env.LOCAL_AUTH_ARGON2_TIME_COST!,
LOCAL_AUTH_ARGON2_PARALLELISM: process.env.LOCAL_AUTH_ARGON2_PARALLELISM!,
ADMIN_USER_IDS: process.env.ADMIN_USER_IDS!,
DATABASE_URL: process.env.DATABASE_URL!,
SYNOLOGY_ISSUER: process.env.SYNOLOGY_ISSUER!,
SYNOLOGY_CLIENT_ID: process.env.SYNOLOGY_CLIENT_ID!,
SYNOLOGY_CLIENT_SECRET: process.env.SYNOLOGY_CLIENT_SECRET!
}
}
});

View File

@@ -1,8 +1,5 @@
import { SvelteKitAuth } from '@auth/sveltekit';
import Credentials from '@auth/core/providers/credentials';
import { env } from '$env/dynamic/private';
import { upsertUserFromAuth } from '$lib/server/users.js';
import { verifyLocalCredentials } from '$lib/server/local-auth.js';
export const { handle, signIn, signOut } = SvelteKitAuth({
providers: [
@@ -21,59 +18,12 @@ export const { handle, signIn, signOut } = SvelteKitAuth({
email: profile.email as string | undefined
};
}
},
Credentials({
id: 'local',
name: 'Local',
credentials: {
identifier: { label: 'Username or email', type: 'text' },
password: { label: 'Password', type: 'password' }
},
async authorize(credentials, request) {
const identifier = String(credentials?.identifier ?? '').trim();
const password = String(credentials?.password ?? '').trim();
const ip =
request?.headers?.get?.('x-forwarded-for') ??
request?.headers?.get?.('x-real-ip') ??
undefined;
const result = await verifyLocalCredentials(identifier, password, ip);
if (result.status !== 'success') return null;
return {
id: result.user.id,
name: result.user.name,
email: result.user.email ?? undefined
};
}
})
}
],
trustHost: true,
pages: {
signIn: '/trips/login'
},
callbacks: {
jwt({ token, profile, user }) {
const details = profile as
| {
sub?: string;
name?: string;
email?: string;
username?: string;
preferred_username?: string;
}
| undefined;
if (details?.sub) {
token.sub = details.sub as string;
upsertUserFromAuth({
id: details.sub,
username: details.username ?? details.preferred_username ?? details.name,
fullName: details.name ?? details.username ?? details.preferred_username,
email: details.email,
authSource: 'OIDC - Synology'
});
}
if (user?.id) {
token.sub = user.id as string;
}
jwt({ token, profile }) {
if (profile?.sub) token.sub = profile.sub as string;
return token;
},
session({ session, token }) {

View File

@@ -42,15 +42,6 @@
General
</a>
<a
href="{base}/admin/users"
class="rounded-md px-3 py-2 text-sm transition-colors {isActive('/admin/users')
? 'bg-gray-100 font-medium text-gray-900'
: 'text-gray-600 hover:bg-gray-100 hover:text-gray-900'}"
>
Users
</a>
<p class="mt-4 px-3 pb-1 text-xs font-semibold tracking-wider text-gray-400 uppercase">
Reference Data
</p>

View File

@@ -1,81 +0,0 @@
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
import { setupTestDb } from '../../../tests/helpers.js';
import type { Database } from '../db/types.js';
import { upsertUserFromAuth } from '../users.js';
import { isAdminUser, requireAdmin } from './auth.js';
let database: Database;
const originalAdminUserIds = process.env.ADMIN_USER_IDS;
beforeEach(() => {
database = setupTestDb();
process.env.ADMIN_USER_IDS = '';
});
afterEach(() => {
process.env.ADMIN_USER_IDS = originalAdminUserIds;
database.close();
});
describe('isAdminUser', () => {
it('allows direct ID matches', () => {
process.env.ADMIN_USER_IDS = 'oidc-sub-123';
expect(isAdminUser('oidc-sub-123')).toBe(true);
});
it('allows username matches for known users', () => {
upsertUserFromAuth({
id: 'oidc-sub-123',
username: 'shaun',
fullName: 'Shaun Campbell',
email: 'shaun@example.com'
});
process.env.ADMIN_USER_IDS = 'shaun';
expect(isAdminUser('oidc-sub-123')).toBe(true);
});
it('allows email matches for known users', () => {
upsertUserFromAuth({
id: 'oidc-sub-123',
username: 'shaun',
fullName: 'Shaun Campbell',
email: 'shaun@example.com'
});
process.env.ADMIN_USER_IDS = 'shaun@example.com';
expect(isAdminUser('oidc-sub-123')).toBe(true);
});
it('allows email local-part matches from session user', () => {
process.env.ADMIN_USER_IDS = 'shaun';
expect(isAdminUser({ id: 'oidc-sub-123', email: 'shaun@example.com' })).toBe(true);
});
});
describe('requireAdmin', () => {
it('throws when not authenticated', () => {
process.env.ADMIN_USER_IDS = 'shaun';
expect(() => requireAdmin(undefined)).toThrow('Not authenticated');
});
it('throws when user is not admin', () => {
process.env.ADMIN_USER_IDS = 'shaun';
expect(() => requireAdmin('someone-else')).toThrow('Admin access required');
});
it('does not throw when username match grants admin access', () => {
upsertUserFromAuth({
id: 'oidc-sub-123',
username: 'shaun',
fullName: 'Shaun Campbell'
});
process.env.ADMIN_USER_IDS = 'shaun';
expect(() => requireAdmin('oidc-sub-123')).not.toThrow();
});
it('does not throw when session user email local-part matches', () => {
process.env.ADMIN_USER_IDS = 'shaun';
expect(() =>
requireAdmin({ id: 'oidc-sub-123', email: 'shaun@example.com', name: 'Shaun Campbell' })
).not.toThrow();
});
});

View File

@@ -1,73 +1,12 @@
import { env } from '$env/dynamic/private';
import { db } from '$lib/server/db/index.js';
const getAdminIdentifiers = (): string[] =>
(process.env.ADMIN_USER_IDS ?? env.ADMIN_USER_IDS ?? '')
export function requireAdmin(userId: string | undefined): void {
if (!userId) throw new Error('Not authenticated');
const adminIds = (env.ADMIN_USER_IDS ?? '')
.split(',')
.map((s) => s.trim())
.filter(Boolean);
type AdminPrincipal =
| string
| {
id?: string | null;
name?: string | null;
email?: string | null;
}
| undefined;
const normalize = (value: string): string => value.trim().toLowerCase();
const getPrincipalValues = (principal: AdminPrincipal): { userId?: string; values: string[] } => {
if (!principal) return { values: [] };
if (typeof principal === 'string') {
const value = principal.trim();
return value ? { userId: value, values: [value] } : { values: [] };
}
const values = [principal.id, principal.name, principal.email]
.filter((value): value is string => Boolean(value?.trim()))
.map((value) => value.trim());
const localPart = principal.email?.split('@')[0]?.trim();
if (localPart) values.push(localPart);
const userId = principal.id?.trim();
return { userId, values };
};
export function isAdminUser(principal: AdminPrincipal): boolean {
const { userId, values } = getPrincipalValues(principal);
if (values.length === 0) return false;
const adminIds = getAdminIdentifiers();
if (adminIds.length === 0) return false;
const normalizedAdminIds = new Set(adminIds.map(normalize));
for (const value of values) {
if (adminIds.includes(value) || normalizedAdminIds.has(normalize(value))) return true;
}
if (!userId) return false;
const user = db.get<{ username: string; email: string | null }>(
'SELECT username, email FROM users WHERE id = ?',
[userId]
);
if (!user) return false;
const dbValues = [user.username, user.email, user.email?.split('@')[0]]
.filter((value): value is string => Boolean(value?.trim()))
.map((value) => value.trim());
for (const value of dbValues) {
if (adminIds.includes(value) || normalizedAdminIds.has(normalize(value))) return true;
}
return false;
}
export function requireAdmin(principal: AdminPrincipal): void {
if (!principal) throw new Error('Not authenticated');
if (!isAdminUser(principal)) {
if (adminIds.length === 0 || !adminIds.includes(userId)) {
throw new Error('Admin access required');
}
}

View File

@@ -53,27 +53,6 @@ export function runMigrations(db: Database): void {
)
`);
db.run(`
CREATE TABLE IF NOT EXISTS users (
id TEXT PRIMARY KEY,
username TEXT NOT NULL,
full_name TEXT NOT NULL,
email TEXT,
auth_source TEXT NOT NULL,
created_at TEXT NOT NULL DEFAULT (datetime('now')),
updated_at TEXT NOT NULL DEFAULT (datetime('now'))
)
`);
db.run(`
CREATE TABLE IF NOT EXISTS local_credentials (
user_id TEXT PRIMARY KEY REFERENCES users(id) ON DELETE CASCADE,
password_hash TEXT NOT NULL,
created_at TEXT NOT NULL DEFAULT (datetime('now')),
updated_at TEXT NOT NULL DEFAULT (datetime('now'))
)
`);
db.run(`
CREATE TABLE IF NOT EXISTS cities (
id INTEGER PRIMARY KEY,

View File

@@ -1,84 +0,0 @@
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
import { setupTestDb } from '../../tests/helpers.js';
import type { Database } from './db/types.js';
import { setLocalCredentialPassword } from './local-credentials.js';
import { resetLocalAuthRateLimits, verifyLocalCredentials } from './local-auth.js';
import { upsertUserFromAuth } from './users.js';
let database: Database;
beforeEach(() => {
process.env.LOCAL_AUTH_ENABLED = 'true';
process.env.LOCAL_AUTH_ARGON2_MEMORY_KB = '8192';
process.env.LOCAL_AUTH_ARGON2_TIME_COST = '2';
process.env.LOCAL_AUTH_ARGON2_PARALLELISM = '1';
process.env.LOCAL_AUTH_MAX_ATTEMPTS = '2';
process.env.LOCAL_AUTH_WINDOW_SECONDS = '60';
process.env.LOCAL_AUTH_LOCKOUT_SECONDS = '10';
database = setupTestDb();
resetLocalAuthRateLimits();
});
afterEach(() => {
vi.useRealTimers();
resetLocalAuthRateLimits();
database.close();
});
describe('verifyLocalCredentials', () => {
it('authenticates valid local credentials', async () => {
upsertUserFromAuth({
id: 'user-1',
username: 'jdoe',
fullName: 'Jane Doe',
email: 'jane@example.com',
authSource: 'Local'
});
await setLocalCredentialPassword('user-1', 'averysecurepassword');
const result = await verifyLocalCredentials('jdoe', 'averysecurepassword', '127.0.0.1');
expect(result.status).toBe('success');
if (result.status === 'success') {
expect(result.user.id).toBe('user-1');
expect(result.user.email).toBe('jane@example.com');
}
});
it('returns invalid for bad credentials and locks after max attempts', async () => {
upsertUserFromAuth({ id: 'user-2', username: 'sally', fullName: 'Sally Sample' });
await setLocalCredentialPassword('user-2', 'averysecurepassword');
const first = await verifyLocalCredentials('sally', 'wrong-password', '10.0.0.1');
const second = await verifyLocalCredentials('sally', 'wrong-password', '10.0.0.1');
const third = await verifyLocalCredentials('sally', 'wrong-password', '10.0.0.1');
expect(first.status).toBe('invalid');
expect(second.status).toBe('invalid');
expect(third.status).toBe('locked');
});
it('clears lockout after window expires', async () => {
upsertUserFromAuth({ id: 'user-3', username: 'morgan', fullName: 'Morgan West' });
await setLocalCredentialPassword('user-3', 'averysecurepassword');
vi.useFakeTimers();
vi.setSystemTime(new Date('2024-01-01T00:00:00Z'));
await verifyLocalCredentials('morgan', 'wrong-password', '10.0.0.2');
await verifyLocalCredentials('morgan', 'wrong-password', '10.0.0.2');
const locked = await verifyLocalCredentials('morgan', 'averysecurepassword', '10.0.0.2');
expect(locked.status).toBe('locked');
vi.advanceTimersByTime(11_000);
const after = await verifyLocalCredentials('morgan', 'averysecurepassword', '10.0.0.2');
expect(after.status).toBe('success');
});
it('rejects when local auth is disabled', async () => {
process.env.LOCAL_AUTH_ENABLED = 'false';
const result = await verifyLocalCredentials('anyone', 'password', '10.0.0.3');
expect(result.status).toBe('disabled');
});
});

View File

@@ -1,154 +0,0 @@
import { env } from '$env/dynamic/private';
import argon2 from 'argon2';
import { getLocalCredentialByIdentifier, hashLocalPassword } from './local-credentials.js';
export interface LocalAuthUser {
id: string;
name: string;
email?: string | null;
}
export type LocalAuthResult =
| { status: 'success'; user: LocalAuthUser }
| { status: 'invalid' | 'locked' | 'disabled' };
interface AttemptState {
count: number;
firstAttemptAt: number;
lockedUntil?: number;
}
const attemptsByIdentifier = new Map<string, AttemptState>();
const attemptsByIp = new Map<string, AttemptState>();
let dummyHashPromise: Promise<string> | null = null;
const getEnvValue = (key: keyof typeof env): string | undefined => {
return process.env[key] ?? env[key];
};
const getNumberEnv = (value: string | undefined, fallback: number): number => {
const parsed = Number.parseInt(value ?? '', 10);
return Number.isFinite(parsed) ? parsed : fallback;
};
const getLocalAuthConfig = () => {
return {
enabled: getEnvValue('LOCAL_AUTH_ENABLED') === 'true',
maxAttempts: getNumberEnv(getEnvValue('LOCAL_AUTH_MAX_ATTEMPTS'), 5),
windowMs: getNumberEnv(getEnvValue('LOCAL_AUTH_WINDOW_SECONDS'), 900) * 1000,
lockoutMs: getNumberEnv(getEnvValue('LOCAL_AUTH_LOCKOUT_SECONDS'), 900) * 1000
};
};
const normalizeIdentifier = (value: string): string => value.trim().toLowerCase();
const normalizePassword = (value: string): string => value.trim();
const normalizeIp = (value?: string | null): string => {
if (!value) return 'unknown';
const trimmed = value.trim();
if (!trimmed) return 'unknown';
return trimmed.split(',')[0]?.trim() || 'unknown';
};
const getDummyHash = async (): Promise<string> => {
if (!dummyHashPromise) {
dummyHashPromise = hashLocalPassword('invalid-password-placeholder');
}
return dummyHashPromise;
};
const getEffectiveState = (state: AttemptState | undefined, now: number, windowMs: number) => {
if (!state) return { count: 0, firstAttemptAt: now };
if (state.lockedUntil && state.lockedUntil <= now) {
return { count: 0, firstAttemptAt: now };
}
if (now - state.firstAttemptAt > windowMs) {
return { count: 0, firstAttemptAt: now };
}
return { ...state };
};
const isLocked = (state: AttemptState, now: number): boolean => {
return Boolean(state.lockedUntil && state.lockedUntil > now);
};
const recordFailure = (
map: Map<string, AttemptState>,
key: string,
now: number,
windowMs: number,
lockoutMs: number,
maxAttempts: number
): void => {
const state = getEffectiveState(map.get(key), now, windowMs);
const nextCount = state.count + 1;
const nextState: AttemptState = {
count: nextCount,
firstAttemptAt: state.firstAttemptAt
};
if (nextCount >= maxAttempts) {
nextState.lockedUntil = now + lockoutMs;
}
map.set(key, nextState);
};
const clearAttemptState = (map: Map<string, AttemptState>, key: string): void => {
map.delete(key);
};
export function resetLocalAuthRateLimits(): void {
attemptsByIdentifier.clear();
attemptsByIp.clear();
}
export async function verifyLocalCredentials(
identifierInput: string,
passwordInput: string,
ipAddress?: string | null
): Promise<LocalAuthResult> {
const config = getLocalAuthConfig();
if (!config.enabled) return { status: 'disabled' };
const identifier = normalizeIdentifier(identifierInput ?? '');
const password = normalizePassword(passwordInput ?? '');
const identifierKey = identifier || 'unknown';
const ipKey = normalizeIp(ipAddress);
const now = Date.now();
const identifierState = getEffectiveState(
attemptsByIdentifier.get(identifierKey),
now,
config.windowMs
);
const ipState = getEffectiveState(attemptsByIp.get(ipKey), now, config.windowMs);
const locked = isLocked(identifierState, now) || isLocked(ipState, now);
const record = identifier ? getLocalCredentialByIdentifier(identifier) : null;
const passwordHash = record?.passwordHash ?? (await getDummyHash());
const passwordMatches = await argon2.verify(passwordHash, password);
if (!locked && record && passwordMatches) {
clearAttemptState(attemptsByIdentifier, identifierKey);
clearAttemptState(attemptsByIp, ipKey);
return {
status: 'success',
user: {
id: record.userId,
name: record.fullName || record.username,
email: record.email ?? undefined
}
};
}
recordFailure(
attemptsByIdentifier,
identifierKey,
now,
config.windowMs,
config.lockoutMs,
config.maxAttempts
);
recordFailure(attemptsByIp, ipKey, now, config.windowMs, config.lockoutMs, config.maxAttempts);
return { status: locked ? 'locked' : 'invalid' };
}

View File

@@ -1,67 +0,0 @@
import { env } from '$env/dynamic/private';
import argon2 from 'argon2';
import { db } from './db/index.js';
export interface LocalCredentialRecord {
userId: string;
username: string;
fullName: string;
email: string | null;
passwordHash: string;
}
export const LOCAL_AUTH_MIN_PASSWORD_LENGTH = 12;
const getNumberEnv = (value: string | undefined, fallback: number): number => {
const parsed = Number.parseInt(value ?? '', 10);
return Number.isFinite(parsed) ? parsed : fallback;
};
export function getLocalCredentialByIdentifier(identifier: string): LocalCredentialRecord | null {
const normalized = identifier.trim();
if (!normalized) return null;
return (
db.get<LocalCredentialRecord>(
`SELECT
users.id as userId,
users.username as username,
users.full_name as fullName,
users.email as email,
local_credentials.password_hash as passwordHash
FROM users
INNER JOIN local_credentials ON local_credentials.user_id = users.id
WHERE lower(users.username) = lower(?)
OR (users.email IS NOT NULL AND lower(users.email) = lower(?))
LIMIT 1`,
[normalized, normalized]
) ?? null
);
}
export async function hashLocalPassword(password: string): Promise<string> {
const trimmed = password.trim();
if (trimmed.length < LOCAL_AUTH_MIN_PASSWORD_LENGTH) {
throw new Error(`Password must be at least ${LOCAL_AUTH_MIN_PASSWORD_LENGTH} characters`);
}
const memoryCost = getNumberEnv(env.LOCAL_AUTH_ARGON2_MEMORY_KB, 65536);
const timeCost = getNumberEnv(env.LOCAL_AUTH_ARGON2_TIME_COST, 3);
const parallelism = getNumberEnv(env.LOCAL_AUTH_ARGON2_PARALLELISM, 1);
return argon2.hash(trimmed, {
type: argon2.argon2id,
memoryCost,
timeCost,
parallelism
});
}
export async function setLocalCredentialPassword(userId: string, password: string): Promise<void> {
const passwordHash = await hashLocalPassword(password);
db.run(
`INSERT INTO local_credentials (user_id, password_hash)
VALUES (?, ?)
ON CONFLICT(user_id) DO UPDATE SET
password_hash = excluded.password_hash,
updated_at = datetime('now')`,
[userId, passwordHash]
);
}

View File

@@ -1,6 +1,5 @@
import { db } from './db/index.js';
import { randomUUID } from 'crypto';
import { upsertUserProfile } from './users.js';
export interface Person {
id: string;
@@ -34,7 +33,6 @@ export function upsertSelfProfile(
WHERE id = ?`,
[firstName, lastName, email ?? null, existing.id]
);
upsertUserProfile(userId, `${firstName} ${lastName}`.trim(), email ?? null);
return db.get<Person>('SELECT * FROM people WHERE id = ?', [existing.id])!;
}
const id = randomUUID();
@@ -43,7 +41,6 @@ export function upsertSelfProfile(
VALUES (?, ?, ?, ?, ?, 1)`,
[id, userId, firstName, lastName, email ?? null]
);
upsertUserProfile(userId, `${firstName} ${lastName}`.trim(), email ?? null);
return db.get<Person>('SELECT * FROM people WHERE id = ?', [id])!;
}

View File

@@ -1,151 +0,0 @@
import { beforeEach, afterEach, describe, expect, it } from 'vitest';
import { setupTestDb } from '../../tests/helpers.js';
import type { Database } from './db/types.js';
import {
createLocalUser,
deleteUser,
listUsers,
setLocalPasswordForUser,
updateUser,
upsertUserFromAuth,
upsertUserProfile
} from './users.js';
let database: Database;
beforeEach(() => {
database = setupTestDb();
});
afterEach(() => {
database.close();
});
describe('upsertUserFromAuth', () => {
it('creates a new user with profile data', () => {
const created = upsertUserFromAuth({
id: 'u1',
username: 'jdoe',
fullName: 'Jane Doe',
email: 'jane@example.com',
authSource: 'OIDC - Synology'
});
expect(created.id).toBe('u1');
expect(created.username).toBe('jdoe');
expect(created.full_name).toBe('Jane Doe');
expect(created.email).toBe('jane@example.com');
expect(created.auth_source).toBe('OIDC - Synology');
expect(listUsers()).toHaveLength(1);
});
it('updates existing users with new auth data', () => {
upsertUserFromAuth({
id: 'u1',
username: 'jdoe',
fullName: 'Jane Doe',
email: 'jane@example.com',
authSource: 'OIDC - Synology'
});
const updated = upsertUserFromAuth({
id: 'u1',
username: 'janed',
email: 'jane.doe@example.com'
});
expect(updated.username).toBe('janed');
expect(updated.email).toBe('jane.doe@example.com');
});
});
describe('upsertUserProfile', () => {
it('creates a user from profile details', () => {
const created = upsertUserProfile('u2', 'Sam Sample', 'sam@example.com');
expect(created.id).toBe('u2');
expect(created.full_name).toBe('Sam Sample');
expect(created.email).toBe('sam@example.com');
});
});
describe('updateUser', () => {
it('updates user fields and syncs self profile when present', () => {
upsertUserFromAuth({
id: 'u3',
username: 'sarah',
fullName: 'Sarah Lee',
email: 'sarah@example.com'
});
database.run(
`INSERT INTO people (id, user_id, first_name, last_name, email, is_self)
VALUES (?, ?, ?, ?, ?, 1)`,
['p1', 'u3', 'Sarah', 'Lee', 'sarah@example.com']
);
updateUser({ id: 'u3', username: 'slee', fullName: 'Sarah Smith', email: 'ss@example.com' });
const user = listUsers().find((item) => item.id === 'u3');
expect(user?.username).toBe('slee');
expect(user?.full_name).toBe('Sarah Smith');
expect(user?.email).toBe('ss@example.com');
const profile = database.get<{ first_name: string; last_name: string; email: string | null }>(
'SELECT first_name, last_name, email FROM people WHERE user_id = ? AND is_self = 1',
['u3']
);
expect(profile?.first_name).toBe('Sarah');
expect(profile?.last_name).toBe('Smith');
expect(profile?.email).toBe('ss@example.com');
});
});
describe('deleteUser', () => {
it('removes the user record', () => {
upsertUserFromAuth({ id: 'u4', username: 'delete-me', fullName: 'Delete Me' });
deleteUser('u4');
expect(listUsers().find((item) => item.id === 'u4')).toBeUndefined();
});
});
describe('createLocalUser', () => {
it('creates a local user with credentials', async () => {
const created = await createLocalUser({
username: 'local-user',
fullName: 'Local User',
email: 'local@example.com',
password: 'averysecurepassword'
});
expect(created.username).toBe('local-user');
expect(created.auth_source).toBe('Local');
const row = database.get<{ user_id: string; password_hash: string }>(
'SELECT user_id, password_hash FROM local_credentials WHERE user_id = ?',
[created.id]
);
expect(row?.user_id).toBe(created.id);
expect(row?.password_hash).toBeTruthy();
});
it('rejects duplicate usernames', async () => {
await createLocalUser({
username: 'dup-user',
fullName: 'Dup User',
password: 'averysecurepassword'
});
await expect(
createLocalUser({
username: 'dup-user',
fullName: 'Dup User Two',
password: 'averysecurepassword'
})
).rejects.toThrow('Username already exists');
});
});
describe('setLocalPasswordForUser', () => {
it('sets local credentials for an existing user', async () => {
upsertUserFromAuth({ id: 'u5', username: 'sarah', fullName: 'Sarah Lee' });
await setLocalPasswordForUser('u5', 'averysecurepassword');
const row = database.get<{ user_id: string; password_hash: string }>(
'SELECT user_id, password_hash FROM local_credentials WHERE user_id = ?',
['u5']
);
expect(row?.user_id).toBe('u5');
expect(row?.password_hash).toBeTruthy();
});
});

View File

@@ -1,195 +0,0 @@
import { randomUUID } from 'crypto';
import { db } from './db/index.js';
import { setLocalCredentialPassword } from './local-credentials.js';
export interface AppUser {
id: string;
username: string;
full_name: string;
email: string | null;
auth_source: string;
created_at: string;
updated_at: string;
}
const DEFAULT_AUTH_SOURCE = 'OIDC - Synology';
const LOCAL_AUTH_SOURCE = 'Local';
const normalizeOptional = (value?: string | null): string | undefined => {
const trimmed = value?.trim();
return trimmed ? trimmed : undefined;
};
const normalizeEmail = (value?: string | null): string | null | undefined => {
if (value === undefined) return undefined;
if (value === null) return null;
const trimmed = value.trim();
return trimmed ? trimmed : null;
};
export function listUsers(): (AppUser & { has_local_credentials: boolean })[] {
return db
.all<AppUser & { has_local_credentials: 0 | 1 }>(
`SELECT u.id, u.username, u.full_name, u.email, u.auth_source, u.created_at, u.updated_at,
CASE WHEN lc.user_id IS NOT NULL THEN 1 ELSE 0 END AS has_local_credentials
FROM users u
LEFT JOIN local_credentials lc ON lc.user_id = u.id
ORDER BY u.username COLLATE NOCASE`
)
.map((row) => ({ ...row, has_local_credentials: row.has_local_credentials === 1 }));
}
export function upsertUserFromAuth(input: {
id: string;
username?: string | null;
fullName?: string | null;
email?: string | null;
authSource?: string | null;
}): AppUser {
const existing = db.get<AppUser>('SELECT * FROM users WHERE id = ?', [input.id]);
const username = normalizeOptional(input.username) ?? existing?.username ?? input.id;
const fullName = normalizeOptional(input.fullName) ?? existing?.full_name ?? '';
const email = normalizeOptional(input.email) ?? existing?.email ?? null;
const authSource =
normalizeOptional(input.authSource) ?? existing?.auth_source ?? DEFAULT_AUTH_SOURCE;
if (existing) {
const setClauses: string[] = [];
const values: Array<string | null> = [];
if (username !== existing.username) {
setClauses.push('username = ?');
values.push(username);
}
if (fullName !== existing.full_name) {
setClauses.push('full_name = ?');
values.push(fullName);
}
if (email !== existing.email) {
setClauses.push('email = ?');
values.push(email);
}
if (authSource !== existing.auth_source) {
setClauses.push('auth_source = ?');
values.push(authSource);
}
if (setClauses.length > 0) {
setClauses.push("updated_at = datetime('now')");
values.push(input.id);
db.run(`UPDATE users SET ${setClauses.join(', ')} WHERE id = ?`, values);
}
} else {
db.run(
`INSERT INTO users (id, username, full_name, email, auth_source)
VALUES (?, ?, ?, ?, ?)`,
[input.id, username, fullName, email, authSource]
);
}
return db.get<AppUser>('SELECT * FROM users WHERE id = ?', [input.id])!;
}
export function upsertUserProfile(
userId: string,
fullName: string,
email?: string | null
): AppUser {
return upsertUserFromAuth({ id: userId, fullName, email, authSource: DEFAULT_AUTH_SOURCE });
}
export function updateUser(input: {
id: string;
username: string;
fullName: string;
email?: string | null;
}): void {
const existing = db.get<{ email: string | null }>('SELECT email FROM users WHERE id = ?', [
input.id
]);
const email = normalizeEmail(input.email);
const nextEmail = email === undefined ? existing?.email ?? null : email;
db.run(
`UPDATE users
SET username = ?, full_name = ?, email = ?, updated_at = datetime('now')
WHERE id = ?`,
[input.username.trim(), input.fullName.trim(), nextEmail, input.id]
);
syncSelfProfile(input.id, input.fullName, nextEmail);
}
export function deleteUser(id: string): void {
db.run('DELETE FROM users WHERE id = ?', [id]);
}
export async function createLocalUser(input: {
username: string;
fullName: string;
email?: string | null;
password: string;
}): Promise<AppUser> {
const username = input.username?.trim() ?? '';
const fullName = input.fullName?.trim() ?? '';
if (!username || !fullName) {
throw new Error('Username and full name are required');
}
const email = normalizeEmail(input.email);
const existingUsername = db.get<{ id: string }>(
'SELECT id FROM users WHERE lower(username) = lower(?)',
[username]
);
if (existingUsername) {
throw new Error('Username already exists');
}
if (email) {
const existingEmail = db.get<{ id: string }>(
'SELECT id FROM users WHERE lower(email) = lower(?)',
[email]
);
if (existingEmail) {
throw new Error('Email already exists');
}
}
const id = randomUUID();
db.run(
`INSERT INTO users (id, username, full_name, email, auth_source)
VALUES (?, ?, ?, ?, ?)`,
[id, username, fullName, email ?? null, LOCAL_AUTH_SOURCE]
);
await setLocalCredentialPassword(id, input.password);
return db.get<AppUser>('SELECT * FROM users WHERE id = ?', [id])!;
}
export async function setLocalPasswordForUser(userId: string, password: string): Promise<void> {
const id = userId?.trim() ?? '';
if (!id) {
throw new Error('User id required');
}
const existing = db.get<{ id: string }>('SELECT id FROM users WHERE id = ?', [id]);
if (!existing) {
throw new Error('User not found');
}
await setLocalCredentialPassword(id, password);
}
function syncSelfProfile(userId: string, fullName: string, email?: string | null): void {
const profile = db.get<{ id: string; first_name: string; last_name: string; email: string | null }>(
`SELECT id, first_name, last_name, email FROM people WHERE user_id = ? AND is_self = 1 LIMIT 1`,
[userId]
);
if (!profile) return;
const trimmed = fullName.trim();
let firstName = profile.first_name;
let lastName = profile.last_name;
if (trimmed) {
const parts = trimmed.split(/\s+/);
firstName = parts[0] ?? profile.first_name;
if (parts.length > 1) {
lastName = parts.slice(1).join(' ');
}
}
const nextEmail = email === undefined ? profile.email : email;
db.run(
`UPDATE people SET first_name = ?, last_name = ?, email = ?, updated_at = datetime('now')
WHERE id = ?`,
[firstName, lastName, nextEmail, profile.id]
);
}

View File

@@ -1,6 +1,6 @@
import { redirect } from '@sveltejs/kit';
import { base } from '$app/paths';
import { isAdminUser } from '$lib/server/admin/auth.js';
import { env } from '$env/dynamic/private';
import type { LayoutServerLoad } from './$types';
export const load: LayoutServerLoad = async (event) => {
@@ -9,7 +9,11 @@ export const load: LayoutServerLoad = async (event) => {
redirect(303, `${base}/login`);
}
const isAdmin = isAdminUser(session.user);
const adminIds = (env.ADMIN_USER_IDS ?? '')
.split(',')
.map((s) => s.trim())
.filter(Boolean);
const isAdmin = adminIds.length > 0 && session.user.id && adminIds.includes(session.user.id);
return { session, isAdmin };
};

View File

@@ -4,13 +4,13 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const q = event.url.searchParams.get('q') ?? undefined;
return json(data.listAirlines(q));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { name, country, country_code, iata_code, icao_code } = body as {
name?: string;
@@ -32,7 +32,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, name, country, country_code, iata_code, icao_code } = body as {
id?: number;
@@ -55,7 +55,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteAirline(id);

View File

@@ -4,13 +4,13 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const q = event.url.searchParams.get('q') ?? undefined;
return json(data.listAirports(q));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { name, country, country_code, iata_code, icao_code, city, latitude, longitude, timezone } =
body as {
@@ -43,7 +43,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const {
id,
@@ -87,7 +87,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteAirport(id);

View File

@@ -4,14 +4,14 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const q = event.url.searchParams.get('q') ?? undefined;
const countryCode = event.url.searchParams.get('country_code') ?? undefined;
return json(data.listCities(q, countryCode));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { name, country, country_code, population } = body as {
name?: string;
@@ -26,7 +26,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, name, country, country_code, population } = body as {
id?: number;
@@ -43,7 +43,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteCity(id);

View File

@@ -4,13 +4,13 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const q = event.url.searchParams.get('q') ?? undefined;
return json(data.listCountries(q));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { name, country_code } = body as { name?: string; country_code?: string };
if (!name?.trim() || !country_code?.trim()) {
@@ -20,7 +20,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, name, country_code } = body as { id?: number; name?: string; country_code?: string };
if (id == null || !name?.trim() || !country_code?.trim()) {
@@ -31,7 +31,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteCountry(id);

View File

@@ -4,14 +4,14 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const tourId = parseInt(event.url.searchParams.get('operator_tour_id') ?? '');
if (isNaN(tourId)) return json({ error: 'operator_tour_id required' }, { status: 400 });
return json(data.listDaysForOperatorTour(tourId));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { operator_tour_id, title, notes } = body as {
operator_tour_id?: number;
@@ -25,7 +25,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, title, notes } = body as { id?: number; title?: string; notes?: string };
if (id == null) return json({ error: 'id is required' }, { status: 400 });
@@ -34,7 +34,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteOperatorTourDay(id);

View File

@@ -4,14 +4,14 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.url.searchParams.get('operator_id') ?? '');
if (isNaN(operatorId)) return json({ error: 'operator_id required' }, { status: 400 });
return json(data.listToursForOperator(operatorId));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { operator_id, name } = body as { operator_id?: number; name?: string };
if (operator_id == null || !name?.trim()) {
@@ -21,7 +21,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, name } = body as { id?: number; name?: string };
if (id == null || !name?.trim()) {
@@ -32,7 +32,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteOperatorTour(id);

View File

@@ -5,7 +5,7 @@ import { listTourOperators } from '$lib/server/admin/data.js';
import { getProviderForOperator } from '$lib/server/admin/providers/index.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.url.searchParams.get('operator_id') ?? '');
if (isNaN(operatorId)) return json({ error: 'operator_id required' }, { status: 400 });

View File

@@ -4,13 +4,13 @@ import { requireAdmin } from '$lib/server/admin/auth.js';
import * as data from '$lib/server/admin/data.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const q = event.url.searchParams.get('q') ?? undefined;
return json(data.listTourOperators(q));
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { name, website, highlight_color } = body as {
name?: string;
@@ -24,7 +24,7 @@ export const POST: RequestHandler = async (event) => {
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const body = await event.request.json();
const { id, name, website, highlight_color } = body as {
id?: number;
@@ -40,7 +40,7 @@ export const PATCH: RequestHandler = async (event) => {
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const id = parseInt(event.url.searchParams.get('id') ?? '');
if (isNaN(id)) return json({ error: 'id required' }, { status: 400 });
data.deleteTourOperator(id);

View File

@@ -1,61 +0,0 @@
import { json } from '@sveltejs/kit';
import type { RequestHandler } from './$types';
import { requireAdmin } from '$lib/server/admin/auth.js';
import { createLocalUser, deleteUser, listUsers, updateUser } from '$lib/server/users.js';
export const GET: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
return json(listUsers());
};
export const PATCH: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
const body = await event.request.json();
const { id, username, full_name, email } = body as {
id?: string;
username?: string;
full_name?: string;
email?: string | null;
};
if (!id?.trim() || !username?.trim() || !full_name?.trim()) {
return json({ error: 'id, username and full_name required' }, { status: 400 });
}
updateUser({ id: id.trim(), username, fullName: full_name, email });
return json({ ok: true });
};
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
const body = await event.request.json();
const { username, full_name, email, password } = body as {
username?: string;
full_name?: string;
email?: string | null;
password?: string;
};
if (!username?.trim() || !full_name?.trim() || !password?.trim()) {
return json({ error: 'username, full_name and password required' }, { status: 400 });
}
try {
const user = await createLocalUser({
username: username.trim(),
fullName: full_name.trim(),
email,
password
});
return json(user);
} catch (error) {
return json(
{ error: error instanceof Error ? error.message : 'Failed to create user' },
{ status: 400 }
);
}
};
export const DELETE: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
const id = event.url.searchParams.get('id')?.trim();
if (!id) return json({ error: 'id required' }, { status: 400 });
deleteUser(id);
return json({ ok: true });
};

View File

@@ -1,22 +0,0 @@
import { json } from '@sveltejs/kit';
import type { RequestHandler } from './$types';
import { requireAdmin } from '$lib/server/admin/auth.js';
import { setLocalPasswordForUser } from '$lib/server/users.js';
export const POST: RequestHandler = async (event) => {
requireAdmin((await event.locals.auth())?.user);
const body = await event.request.json();
const { id, password } = body as { id?: string; password?: string };
if (!id?.trim() || !password?.trim()) {
return json({ error: 'id and password required' }, { status: 400 });
}
try {
await setLocalPasswordForUser(id.trim(), password);
return json({ ok: true });
} catch (error) {
return json(
{ error: error instanceof Error ? error.message : 'Failed to set password' },
{ status: 400 }
);
}
};

View File

@@ -5,7 +5,7 @@ import { getProviderForOperator } from '$lib/server/admin/providers/index.js';
import type { PageServerLoad, Actions } from './$types';
export const load: PageServerLoad = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.params.operatorId);
if (isNaN(operatorId)) error(404, 'Not found');
@@ -27,7 +27,7 @@ export const load: PageServerLoad = async (event) => {
export const actions: Actions = {
addTour: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.params.operatorId);
if (isNaN(operatorId)) return fail(400, { error: 'Invalid operator ID' });
@@ -45,7 +45,7 @@ export const actions: Actions = {
},
editTour: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);
@@ -63,7 +63,7 @@ export const actions: Actions = {
},
deleteTour: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);
@@ -78,7 +78,7 @@ export const actions: Actions = {
},
importTour: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.params.operatorId);
if (isNaN(operatorId)) return fail(400, { error: 'Invalid operator ID' });

View File

@@ -4,7 +4,7 @@ import * as data from '$lib/server/admin/data.js';
import type { PageServerLoad, Actions } from './$types';
export const load: PageServerLoad = async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const operatorId = parseInt(event.params.operatorId);
const tourId = parseInt(event.params.tourId);
@@ -27,7 +27,7 @@ export const load: PageServerLoad = async (event) => {
export const actions: Actions = {
addDay: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const tourId = parseInt(event.params.tourId);
if (isNaN(tourId)) return fail(400, { error: 'Invalid tour ID' });
@@ -45,7 +45,7 @@ export const actions: Actions = {
},
editDay: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);
@@ -63,7 +63,7 @@ export const actions: Actions = {
},
deleteDay: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);
@@ -78,7 +78,7 @@ export const actions: Actions = {
},
addDayPlan: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const dayId = parseInt(formData.get('dayId') as string);
@@ -247,7 +247,7 @@ export const actions: Actions = {
},
editDayPlan: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);
@@ -310,7 +310,7 @@ export const actions: Actions = {
},
deleteDayPlan: async (event) => {
requireAdmin((await event.locals.auth())?.user);
requireAdmin((await event.locals.auth())?.user?.id);
const formData = await event.request.formData();
const id = parseInt(formData.get('id') as string);

View File

@@ -1,597 +0,0 @@
<script lang="ts">
import { base } from '$app/paths';
import { onMount } from 'svelte';
interface User {
id: string;
username: string;
full_name: string;
email: string | null;
auth_source: string;
has_local_credentials: boolean;
}
let users = $state<User[]>([]);
let loading = $state(true);
let error = $state('');
let editing = $state<User | null>(null);
let editUsername = $state('');
let editFullName = $state('');
let editEmail = $state('');
let addDrawerOpen = $state(false);
let addUsername = $state('');
let addFullName = $state('');
let addEmail = $state('');
let addPassword = $state('');
let addPasswordConfirm = $state('');
let addError = $state('');
let addSubmitting = $state(false);
let passwordDrawerUser = $state<User | null>(null);
let localPassword = $state('');
let localPasswordConfirm = $state('');
let localPasswordError = $state('');
let localPasswordSubmitting = $state(false);
async function loadUsers() {
loading = true;
try {
const res = await fetch(`${base}/admin/api/users`);
if (!res.ok) {
error = 'Failed to load users';
return;
}
users = await res.json();
} catch (e) {
error = e instanceof Error ? e.message : 'Failed to load users';
} finally {
loading = false;
}
}
function startEdit(user: User) {
editing = user;
editUsername = user.username;
editFullName = user.full_name;
editEmail = user.email ?? '';
error = '';
}
function cancelEdit() {
editing = null;
editUsername = '';
editFullName = '';
editEmail = '';
error = '';
}
function openAddDrawer() {
addDrawerOpen = true;
addError = '';
}
function closeAddDrawer() {
addDrawerOpen = false;
addUsername = '';
addFullName = '';
addEmail = '';
addPassword = '';
addPasswordConfirm = '';
addError = '';
}
async function submitAddUser() {
if (!addUsername.trim() || !addFullName.trim() || !addPassword.trim()) {
addError = 'Username, full name, and password are required';
return;
}
if (addPassword.trim().length < 12) {
addError = 'Password must be at least 12 characters';
return;
}
if (addPassword.trim() !== addPasswordConfirm.trim()) {
addError = 'Passwords do not match';
return;
}
addSubmitting = true;
addError = '';
try {
const res = await fetch(`${base}/admin/api/users`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
username: addUsername.trim(),
full_name: addFullName.trim(),
email: addEmail.trim() || null,
password: addPassword
})
});
if (!res.ok) {
const data = await res.json();
addError = data.error ?? 'Failed to create user';
return;
}
closeAddDrawer();
loadUsers();
} catch (e) {
addError = e instanceof Error ? e.message : 'Failed to create user';
} finally {
addSubmitting = false;
}
}
function openPasswordDrawer(user: User) {
passwordDrawerUser = user;
localPassword = '';
localPasswordConfirm = '';
localPasswordError = '';
}
function closePasswordDrawer() {
passwordDrawerUser = null;
localPassword = '';
localPasswordConfirm = '';
localPasswordError = '';
}
async function submitLocalPassword() {
if (!passwordDrawerUser) return;
if (!localPassword.trim()) {
localPasswordError = 'Password is required';
return;
}
if (localPassword.trim().length < 12) {
localPasswordError = 'Password must be at least 12 characters';
return;
}
if (localPassword.trim() !== localPasswordConfirm.trim()) {
localPasswordError = 'Passwords do not match';
return;
}
localPasswordSubmitting = true;
localPasswordError = '';
try {
const res = await fetch(`${base}/admin/api/users/local-credentials`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
id: passwordDrawerUser.id,
password: localPassword
})
});
if (!res.ok) {
const data = await res.json();
localPasswordError = data.error ?? 'Failed to set password';
return;
}
closePasswordDrawer();
} catch (e) {
localPasswordError = e instanceof Error ? e.message : 'Failed to set password';
} finally {
localPasswordSubmitting = false;
}
}
async function submitEdit() {
if (!editing) return;
if (!editUsername.trim() || !editFullName.trim()) {
error = 'Username and full name are required';
return;
}
try {
const res = await fetch(`${base}/admin/api/users`, {
method: 'PATCH',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({
id: editing.id,
username: editUsername.trim(),
full_name: editFullName.trim(),
email: editEmail.trim() || null
})
});
if (!res.ok) {
const data = await res.json();
error = data.error ?? 'Failed to update user';
return;
}
cancelEdit();
loadUsers();
} catch (e) {
error = e instanceof Error ? e.message : 'Failed to update user';
}
}
async function removeUser(user: User) {
if (!confirm(`Remove ${user.username}?`)) return;
try {
const res = await fetch(`${base}/admin/api/users?id=${encodeURIComponent(user.id)}`, {
method: 'DELETE'
});
if (!res.ok) {
const data = await res.json();
alert(data.error ?? 'Failed to remove user');
return;
}
if (editing?.id === user.id) cancelEdit();
loadUsers();
} catch (e) {
alert(e instanceof Error ? e.message : 'Failed to remove user');
}
}
onMount(loadUsers);
</script>
<svelte:head>
<title>Users — Admin — Trips</title>
</svelte:head>
<div class="mx-auto max-w-4xl">
<div class="mb-6 flex items-start justify-between gap-4">
<div>
<h1 class="text-2xl font-bold text-gray-900">Users</h1>
<p class="mt-1 text-sm text-gray-500">Manage application user accounts and access.</p>
</div>
<button
onclick={openAddDrawer}
class="rounded-md bg-blue-600 px-4 py-2 text-sm font-medium text-white hover:bg-blue-700"
>
Add User
</button>
</div>
<div class="flex flex-col gap-4">
{#if error && !editing}
<div class="rounded-md border border-red-200 bg-red-50 px-4 py-3 text-sm text-red-700">
{error}
</div>
{/if}
{#if editing}
<div class="rounded-lg border border-gray-200 bg-gray-50 p-5">
<h3 class="mb-4 text-sm font-semibold text-gray-700">Edit user</h3>
{#if error}
<p class="mb-3 text-sm text-red-600">{error}</p>
{/if}
<div class="grid grid-cols-[1fr_1fr_1fr_auto] items-end gap-3">
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500"
>Username <span class="text-red-500">*</span></label
>
<input
type="text"
bind:value={editUsername}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500"
>Full name <span class="text-red-500">*</span></label
>
<input
type="text"
bind:value={editFullName}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Email</label>
<input
type="email"
bind:value={editEmail}
placeholder="name@example.com"
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex gap-2">
<button
onclick={submitEdit}
class="rounded-md bg-blue-600 px-4 py-2 text-sm font-medium text-white hover:bg-blue-700"
>
Save
</button>
<button
onclick={cancelEdit}
class="rounded-md border border-gray-300 px-4 py-2 text-sm text-gray-700 hover:bg-gray-50"
>
Cancel
</button>
</div>
</div>
</div>
{/if}
<div class="overflow-hidden rounded-lg border border-gray-200">
{#if loading}
<p class="p-8 text-center text-sm text-gray-500">Loading...</p>
{:else if users.length === 0}
<p class="p-8 text-center text-sm text-gray-500">No users found.</p>
{:else}
<table class="min-w-full divide-y divide-gray-200">
<thead class="bg-gray-50">
<tr>
<th
class="px-4 py-3 text-left text-xs font-semibold tracking-wide text-gray-500 uppercase"
>Username</th
>
<th
class="px-4 py-3 text-left text-xs font-semibold tracking-wide text-gray-500 uppercase"
>Full name</th
>
<th
class="px-4 py-3 text-left text-xs font-semibold tracking-wide text-gray-500 uppercase"
>Email</th
>
<th
class="px-4 py-3 text-left text-xs font-semibold tracking-wide text-gray-500 uppercase"
>Auth source</th
>
<th
class="px-4 py-3 text-right text-xs font-semibold tracking-wide text-gray-500 uppercase"
>Actions</th
>
</tr>
</thead>
<tbody class="divide-y divide-gray-200 bg-white">
{#each users as user (user.id)}
<tr class="hover:bg-gray-50">
<td class="px-4 py-3 text-sm font-medium text-gray-900">{user.username}</td>
<td class="px-4 py-3 text-sm text-gray-700">
{user.full_name || '—'}
</td>
<td class="px-4 py-3 text-sm text-gray-700">
{user.email || '—'}
</td>
<td class="px-4 py-3">
<div class="flex flex-wrap gap-1">
<span class="rounded bg-gray-100 px-2 py-0.5 text-xs font-medium text-gray-700"
>{user.auth_source}</span
>
{#if user.has_local_credentials && user.auth_source !== 'Local'}
<span class="rounded bg-blue-100 px-2 py-0.5 text-xs font-medium text-blue-700"
>Local</span
>
{/if}
</div>
</td>
<td class="px-4 py-3 text-right">
<div class="inline-flex items-center gap-1">
<button
onclick={() => openPasswordDrawer(user)}
class="inline-flex h-8 w-8 items-center justify-center rounded-md text-blue-500 hover:bg-blue-50 hover:text-blue-600"
aria-label="Set local password"
title="Set local password"
>
<svg
viewBox="0 0 24 24"
fill="none"
stroke="currentColor"
stroke-width="2"
class="h-4 w-4"
>
<path d="M21 10h-6" />
<path d="M15 10V7a3 3 0 0 0-6 0v3" />
<rect x="3" y="10" width="12" height="10" rx="2" />
</svg>
</button>
<button
onclick={() => startEdit(user)}
class="inline-flex h-8 w-8 items-center justify-center rounded-md text-gray-500 hover:bg-gray-100 hover:text-gray-700"
aria-label="Edit user"
title="Edit"
>
<svg
viewBox="0 0 24 24"
fill="none"
stroke="currentColor"
stroke-width="2"
class="h-4 w-4"
>
<path d="M12 20h9" />
<path
d="M16.5 3.5a2.121 2.121 0 0 1 3 3L7 19l-4 1 1-4 12.5-12.5z"
/>
</svg>
</button>
<button
onclick={() => removeUser(user)}
class="inline-flex h-8 w-8 items-center justify-center rounded-md text-red-500 hover:bg-red-50 hover:text-red-600"
aria-label="Remove user"
title="Remove"
>
<svg
viewBox="0 0 24 24"
fill="none"
stroke="currentColor"
stroke-width="2"
class="h-4 w-4"
>
<path d="M3 6h18" />
<path d="M8 6V4h8v2" />
<path d="M19 6l-1 14H6L5 6" />
</svg>
</button>
</div>
</td>
</tr>
{/each}
</tbody>
</table>
{/if}
</div>
</div>
</div>
{#if addDrawerOpen}
<div
class="fixed inset-0 z-40 bg-black/20"
role="button"
tabindex="-1"
onclick={closeAddDrawer}
onkeydown={(e: KeyboardEvent) => e.key === 'Escape' && closeAddDrawer()}
></div>
<div
class="fixed top-0 right-0 z-50 flex h-full w-full max-w-md flex-col bg-white shadow-xl"
role="dialog"
aria-modal="true"
aria-label="Add user"
onkeydown={(e: KeyboardEvent) => e.key === 'Escape' && closeAddDrawer()}
>
<div class="flex items-center justify-between border-b border-gray-200 px-6 py-4">
<div>
<h2 class="text-base font-semibold text-gray-900">Add user</h2>
<p class="text-xs text-gray-500">Create a new local login user.</p>
</div>
<button
onclick={closeAddDrawer}
class="rounded-md p-1 text-gray-400 hover:bg-gray-100 hover:text-gray-600"
aria-label="Close"
>
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2">
<line x1="18" y1="6" x2="6" y2="18" />
<line x1="6" y1="6" x2="18" y2="18" />
</svg>
</button>
</div>
<form class="flex flex-1 flex-col gap-4 overflow-y-auto px-6 py-4" onsubmit={(e) => { e.preventDefault(); submitAddUser(); }}>
{#if addError}
<p class="rounded-md border border-red-200 bg-red-50 px-3 py-2 text-sm text-red-700">
{addError}
</p>
{/if}
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Username <span class="text-red-500">*</span></label>
<input
type="text"
bind:value={addUsername}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Full name <span class="text-red-500">*</span></label>
<input
type="text"
bind:value={addFullName}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Email</label>
<input
type="email"
placeholder="name@example.com"
bind:value={addEmail}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Password <span class="text-red-500">*</span></label>
<input
type="password"
bind:value={addPassword}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
<p class="text-xs text-gray-500">Minimum 12 characters.</p>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Confirm password <span class="text-red-500">*</span></label>
<input
type="password"
bind:value={addPasswordConfirm}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="mt-2 flex items-center justify-end gap-2">
<button
type="button"
onclick={closeAddDrawer}
class="rounded-md border border-gray-300 px-4 py-2 text-sm text-gray-700 hover:bg-gray-50"
>
Cancel
</button>
<button
type="submit"
disabled={addSubmitting}
class="rounded-md bg-blue-600 px-4 py-2 text-sm font-medium text-white hover:bg-blue-700 disabled:opacity-60"
>
{addSubmitting ? 'Creating...' : 'Create user'}
</button>
</div>
</form>
</div>
{/if}
{#if passwordDrawerUser}
<div
class="fixed inset-0 z-40 bg-black/20"
role="button"
tabindex="-1"
onclick={closePasswordDrawer}
onkeydown={(e: KeyboardEvent) => e.key === 'Escape' && closePasswordDrawer()}
></div>
<div
class="fixed top-0 right-0 z-50 flex h-full w-full max-w-md flex-col bg-white shadow-xl"
role="dialog"
aria-modal="true"
aria-label="Set local password"
onkeydown={(e: KeyboardEvent) => e.key === 'Escape' && closePasswordDrawer()}
>
<div class="flex items-center justify-between border-b border-gray-200 px-6 py-4">
<div>
<h2 class="text-base font-semibold text-gray-900">Set local password</h2>
<p class="text-xs text-gray-500">{passwordDrawerUser.username}</p>
</div>
<button
onclick={closePasswordDrawer}
class="rounded-md p-1 text-gray-400 hover:bg-gray-100 hover:text-gray-600"
aria-label="Close"
>
<svg width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2">
<line x1="18" y1="6" x2="6" y2="18" />
<line x1="6" y1="6" x2="18" y2="18" />
</svg>
</button>
</div>
<form
class="flex flex-1 flex-col gap-4 overflow-y-auto px-6 py-4"
onsubmit={(e) => { e.preventDefault(); submitLocalPassword(); }}
>
{#if localPasswordError}
<p class="rounded-md border border-red-200 bg-red-50 px-3 py-2 text-sm text-red-700">
{localPasswordError}
</p>
{/if}
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">New password <span class="text-red-500">*</span></label>
<input
type="password"
bind:value={localPassword}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
<p class="text-xs text-gray-500">Minimum 12 characters.</p>
</div>
<div class="flex flex-col gap-1.5">
<label class="text-xs font-medium text-gray-500">Confirm password <span class="text-red-500">*</span></label>
<input
type="password"
bind:value={localPasswordConfirm}
class="rounded-md border border-gray-300 px-3 py-2 text-sm focus:border-blue-500 focus:ring-1 focus:ring-blue-500 focus:outline-none"
/>
</div>
<div class="mt-2 flex items-center justify-end gap-2">
<button
type="button"
onclick={closePasswordDrawer}
class="rounded-md border border-gray-300 px-4 py-2 text-sm text-gray-700 hover:bg-gray-50"
>
Cancel
</button>
<button
type="submit"
disabled={localPasswordSubmitting}
class="rounded-md bg-blue-600 px-4 py-2 text-sm font-medium text-white hover:bg-blue-700 disabled:opacity-60"
>
{localPasswordSubmitting ? 'Saving...' : 'Save password'}
</button>
</div>
</form>
</div>
{/if}

View File

@@ -1,22 +1,8 @@
import { env } from '$env/dynamic/private';
import type { PageServerLoad } from './$types';
const resolveErrorMessage = (value: string | null): string | null => {
if (!value) return null;
if (value === 'CredentialsSignin') return 'Invalid credentials';
return null;
};
export const load: PageServerLoad = async ({ url }) => {
const authUrl = process.env.AUTH_URL ?? env.AUTH_URL ?? '';
const localAuthEnabled = (process.env.LOCAL_AUTH_ENABLED ?? env.LOCAL_AUTH_ENABLED) === 'true';
const appRoot = authUrl.replace(/\/auth$/, '');
export const load: PageServerLoad = async () => {
return {
signinUrl: `${authUrl}/signin/synology`,
localSigninUrl: `${authUrl}/callback/local`,
callbackUrl: appRoot,
localAuthEnabled,
error: resolveErrorMessage(url.searchParams.get('error'))
signinUrl: `${env.AUTH_URL}/signin/synology`
};
};

View File

@@ -1,86 +1,22 @@
<script lang="ts">
import { onMount } from 'svelte';
let { data } = $props();
let form: HTMLFormElement;
onMount(() => {
form.submit();
});
</script>
<svelte:head>
<title>Sign in — Trips</title>
</svelte:head>
<div class="mx-auto flex min-h-[70vh] w-full max-w-3xl flex-col justify-center px-6 py-12">
<div class="mb-10">
<h1 class="text-3xl font-semibold text-slate-900">Sign in</h1>
<p class="mt-2 text-sm text-slate-500">
Choose a sign-in method to access Trips.
</p>
</div>
<form bind:this={form} method="POST" action={data.signinUrl} class="hidden">
<input type="hidden" name="csrfToken" />
</form>
{#if data.error}
<div class="mb-6 rounded-lg border border-rose-200 bg-rose-50 px-4 py-3 text-sm text-rose-700">
{data.error}
</div>
{/if}
<div class="grid gap-8 md:grid-cols-2">
<section class="rounded-2xl border border-slate-200 bg-white p-6 shadow-sm">
<h2 class="text-lg font-semibold text-slate-900">Synology account</h2>
<p class="mt-2 text-sm text-slate-500">
Use your Synology SSO account.
</p>
<form method="POST" action={data.signinUrl} class="mt-6">
<input type="hidden" name="csrfToken" />
<button
type="submit"
class="inline-flex w-full items-center justify-center rounded-lg bg-slate-900 px-4 py-2 text-sm font-semibold text-white transition hover:bg-slate-800"
>
Sign in with Synology
</button>
</form>
</section>
<section class="rounded-2xl border border-slate-200 bg-white p-6 shadow-sm">
<h2 class="text-lg font-semibold text-slate-900">Local account</h2>
<p class="mt-2 text-sm text-slate-500">
Sign in with your local username or email.
</p>
{#if data.localAuthEnabled}
<form method="POST" action={data.localSigninUrl} class="mt-6 space-y-4">
<input type="hidden" name="csrfToken" />
<input type="hidden" name="callbackUrl" value={data.callbackUrl} />
<div>
<label class="text-sm font-medium text-slate-700" for="identifier">
Username or email
</label>
<input
id="identifier"
name="identifier"
autocomplete="username"
class="mt-2 w-full rounded-lg border border-slate-200 px-3 py-2 text-sm text-slate-900 shadow-sm focus:border-slate-400 focus:outline-none"
required
/>
</div>
<div>
<label class="text-sm font-medium text-slate-700" for="password">Password</label>
<input
id="password"
name="password"
autocomplete="current-password"
type="password"
class="mt-2 w-full rounded-lg border border-slate-200 px-3 py-2 text-sm text-slate-900 shadow-sm focus:border-slate-400 focus:outline-none"
required
/>
</div>
<button
type="submit"
class="inline-flex w-full items-center justify-center rounded-lg border border-slate-300 bg-white px-4 py-2 text-sm font-semibold text-slate-900 transition hover:border-slate-400"
>
Sign in locally
</button>
</form>
{:else}
<div class="mt-6 rounded-lg border border-slate-200 bg-slate-50 px-4 py-3 text-sm text-slate-500">
Local sign-in is disabled.
</div>
{/if}
</section>
</div>
<div class="flex min-h-[60vh] items-center justify-center">
<p class="text-gray-500">Redirecting to sign in…</p>
</div>

View File

@@ -1,38 +0,0 @@
import { beforeEach, describe, expect, it } from 'vitest';
import { load } from './+page.server';
beforeEach(() => {
process.env.AUTH_URL = 'https://example.com/auth';
});
describe('login page load', () => {
it('returns auth options when local auth is enabled', async () => {
process.env.LOCAL_AUTH_ENABLED = 'true';
const result = await load({
url: new URL('https://example.com/login')
} as Parameters<typeof load>[0]);
expect(result.signinUrl).toBe('https://example.com/auth/signin/synology');
expect(result.localSigninUrl).toBe('https://example.com/auth/callback/local');
expect(result.callbackUrl).toBe('https://example.com');
expect(result.localAuthEnabled).toBe(true);
});
it('maps credentials errors to a generic message', async () => {
process.env.LOCAL_AUTH_ENABLED = 'true';
const result = await load({
url: new URL('https://example.com/login?error=CredentialsSignin')
} as Parameters<typeof load>[0]);
expect(result.error).toBe('Invalid credentials');
});
it('disables local auth in the response when disabled', async () => {
process.env.LOCAL_AUTH_ENABLED = 'false';
const result = await load({
url: new URL('https://example.com/login')
} as Parameters<typeof load>[0]);
expect(result.localAuthEnabled).toBe(false);
});
});

View File

@@ -5,6 +5,6 @@ import { defineConfig } from 'vite';
export default defineConfig({
plugins: [tailwindcss(), sveltekit()],
server: {
allowedHosts: ['cloud.campbellwireless.net', '127.0.0.1', 'localhost']
allowedHosts: ['cloud.campbellwireless.net']
}
});