update promo
This commit is contained in:
@@ -0,0 +1,57 @@
|
||||
import { createAdminClient } from "npm:@insforge/sdk";
|
||||
|
||||
const corsHeaders = {
|
||||
"Access-Control-Allow-Origin": "*",
|
||||
"Access-Control-Allow-Methods": "POST, OPTIONS",
|
||||
"Access-Control-Allow-Headers": "Content-Type, Authorization",
|
||||
};
|
||||
|
||||
export default async function (req: Request): Promise<Response> {
|
||||
if (req.method === "OPTIONS") {
|
||||
return new Response(null, { status: 204, headers: corsHeaders });
|
||||
}
|
||||
if (req.method !== "POST") {
|
||||
return new Response(JSON.stringify({ error: "Method not allowed" }), {
|
||||
status: 405,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
const { id, approved } = await req.json();
|
||||
|
||||
if (typeof id !== "string" || id.length === 0) {
|
||||
return new Response(JSON.stringify({ error: "ID user tidak valid." }), {
|
||||
status: 400,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
const admin = createAdminClient({
|
||||
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { error } = await admin.database
|
||||
.from("app_users")
|
||||
.update({ approved: approved === true })
|
||||
.eq("id", id);
|
||||
|
||||
if (error) {
|
||||
return new Response(JSON.stringify({ error: error.message }), {
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ ok: true }), {
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
} catch (err) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
|
||||
{ status: 500, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,46 @@
|
||||
import { createAdminClient } from "npm:@insforge/sdk";
|
||||
|
||||
const corsHeaders = {
|
||||
"Access-Control-Allow-Origin": "*",
|
||||
"Access-Control-Allow-Methods": "GET, POST, OPTIONS",
|
||||
"Access-Control-Allow-Headers": "Content-Type, Authorization",
|
||||
};
|
||||
|
||||
export default async function (req: Request): Promise<Response> {
|
||||
if (req.method === "OPTIONS") {
|
||||
return new Response(null, { status: 204, headers: corsHeaders });
|
||||
}
|
||||
|
||||
try {
|
||||
const admin = createAdminClient({
|
||||
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { data, error } = await admin.database
|
||||
.from("visitor_stats")
|
||||
.select("count")
|
||||
.eq("id", "global")
|
||||
.maybeSingle();
|
||||
|
||||
if (error) {
|
||||
return new Response(JSON.stringify({ error: error.message }), {
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ count: Number(data?.count ?? 0) }), {
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
} catch (err) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
|
||||
{
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
}
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
import { createAdminClient } from "npm:@insforge/sdk";
|
||||
|
||||
const corsHeaders = {
|
||||
"Access-Control-Allow-Origin": "*",
|
||||
"Access-Control-Allow-Methods": "POST, OPTIONS",
|
||||
"Access-Control-Allow-Headers": "Content-Type, Authorization",
|
||||
};
|
||||
|
||||
export default async function (req: Request): Promise<Response> {
|
||||
if (req.method === "OPTIONS") {
|
||||
return new Response(null, { status: 204, headers: corsHeaders });
|
||||
}
|
||||
if (req.method !== "POST") {
|
||||
return new Response(JSON.stringify({ error: "Method not allowed" }), {
|
||||
status: 405,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
const admin = createAdminClient({
|
||||
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { data, error } = await admin.database
|
||||
.from("app_users")
|
||||
.select("id, username, approved, created_at")
|
||||
.order("created_at", { ascending: true });
|
||||
|
||||
if (error) {
|
||||
return new Response(JSON.stringify({ error: error.message }), {
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ users: data ?? [] }), {
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
} catch (err) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
|
||||
{ status: 500, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
}
|
||||
+13
-2
@@ -49,7 +49,7 @@ export default async function (req: Request): Promise<Response> {
|
||||
|
||||
const { data: user } = await admin.database
|
||||
.from("app_users")
|
||||
.select("username, password_hash, salt")
|
||||
.select("username, password_hash, salt, approved")
|
||||
.eq("username", username.trim())
|
||||
.maybeSingle();
|
||||
|
||||
@@ -60,6 +60,13 @@ export default async function (req: Request): Promise<Response> {
|
||||
});
|
||||
}
|
||||
|
||||
if (!user.approved) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: "Akun Anda belum disetujui oleh admin." }),
|
||||
{ status: 403, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
|
||||
const pepper = Deno.env.get("AUTH_PEPPER") ?? "";
|
||||
const hash = await sha256Hex(`${user.salt}|${password}|${pepper}`);
|
||||
|
||||
@@ -70,7 +77,11 @@ export default async function (req: Request): Promise<Response> {
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ ok: true, username: user.username }), {
|
||||
const token = await sha256Hex(`${user.username}|${pepper}`);
|
||||
|
||||
return new Response(
|
||||
JSON.stringify({ ok: true, username: user.username, token }),
|
||||
{
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
|
||||
@@ -55,17 +55,6 @@ export default async function (req: Request): Promise<Response> {
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { count } = await admin.database
|
||||
.from("app_users")
|
||||
.select("id", { count: "exact", head: true });
|
||||
|
||||
if ((count ?? 0) > 0) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: "Akun admin sudah dibuat. Pendaftaran ditutup." }),
|
||||
{ status: 403, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
|
||||
const { data: existing } = await admin.database
|
||||
.from("app_users")
|
||||
.select("id")
|
||||
@@ -84,7 +73,7 @@ export default async function (req: Request): Promise<Response> {
|
||||
const hash = await sha256Hex(`${salt}|${password}|${pepper}`);
|
||||
|
||||
const { error } = await admin.database.from("app_users").insert([
|
||||
{ username: username.trim(), password_hash: hash, salt },
|
||||
{ username: username.trim(), password_hash: hash, salt, approved: false },
|
||||
]);
|
||||
|
||||
if (error) {
|
||||
|
||||
@@ -0,0 +1,103 @@
|
||||
import { createAdminClient } from "npm:@insforge/sdk";
|
||||
|
||||
const corsHeaders = {
|
||||
"Access-Control-Allow-Origin": "*",
|
||||
"Access-Control-Allow-Methods": "POST, OPTIONS",
|
||||
"Access-Control-Allow-Headers": "Content-Type, Authorization",
|
||||
};
|
||||
|
||||
function sha256Hex(text: string): Promise<string> {
|
||||
return crypto.subtle
|
||||
.digest("SHA-256", new TextEncoder().encode(text))
|
||||
.then((buf) =>
|
||||
Array.from(new Uint8Array(buf))
|
||||
.map((b) => b.toString(16).padStart(2, "0"))
|
||||
.join("")
|
||||
);
|
||||
}
|
||||
|
||||
export default async function (req: Request): Promise<Response> {
|
||||
if (req.method === "OPTIONS") {
|
||||
return new Response(null, { status: 204, headers: corsHeaders });
|
||||
}
|
||||
if (req.method !== "POST") {
|
||||
return new Response(JSON.stringify({ error: "Method not allowed" }), {
|
||||
status: 405,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
const { username, token, data } = await req.json();
|
||||
|
||||
if (
|
||||
typeof username !== "string" ||
|
||||
typeof token !== "string" ||
|
||||
!username.trim() ||
|
||||
!token
|
||||
) {
|
||||
return new Response(JSON.stringify({ error: "Sesi admin tidak valid." }), {
|
||||
status: 401,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
const admin = createAdminClient({
|
||||
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { data: user } = await admin.database
|
||||
.from("app_users")
|
||||
.select("username")
|
||||
.eq("username", username.trim())
|
||||
.eq("approved", true)
|
||||
.maybeSingle();
|
||||
|
||||
if (!user) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: "Hanya admin yang disetujui boleh menyimpan." }),
|
||||
{ status: 403, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
|
||||
const pepper = Deno.env.get("AUTH_PEPPER") ?? "";
|
||||
const expected = await sha256Hex(`${username.trim()}|${pepper}`);
|
||||
if (expected !== token) {
|
||||
return new Response(JSON.stringify({ error: "Token tidak valid." }), {
|
||||
status: 403,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
if (!data || typeof data !== "object") {
|
||||
return new Response(JSON.stringify({ error: "Data tidak valid." }), {
|
||||
status: 400,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
const { error } = await admin.database.from("site_data").upsert({
|
||||
id: "main",
|
||||
data,
|
||||
updated_at: new Date().toISOString(),
|
||||
});
|
||||
|
||||
if (error) {
|
||||
return new Response(JSON.stringify({ error: error.message }), {
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ ok: true }), {
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
} catch (err) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
|
||||
{ status: 500, headers: { ...corsHeaders, "Content-Type": "application/json" } }
|
||||
);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,49 @@
|
||||
import { createAdminClient } from "npm:@insforge/sdk";
|
||||
|
||||
const corsHeaders = {
|
||||
"Access-Control-Allow-Origin": "*",
|
||||
"Access-Control-Allow-Methods": "POST, OPTIONS",
|
||||
"Access-Control-Allow-Headers": "Content-Type, Authorization",
|
||||
};
|
||||
|
||||
export default async function (req: Request): Promise<Response> {
|
||||
if (req.method === "OPTIONS") {
|
||||
return new Response(null, { status: 204, headers: corsHeaders });
|
||||
}
|
||||
|
||||
if (req.method !== "POST") {
|
||||
return new Response(JSON.stringify({ error: "Method not allowed" }), {
|
||||
status: 405,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
try {
|
||||
const admin = createAdminClient({
|
||||
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
|
||||
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
|
||||
});
|
||||
|
||||
const { data, error } = await admin.database.rpc("increment_visitor");
|
||||
|
||||
if (error) {
|
||||
return new Response(JSON.stringify({ error: error.message }), {
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
}
|
||||
|
||||
return new Response(JSON.stringify({ count: Number(data) }), {
|
||||
status: 200,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
});
|
||||
} catch (err) {
|
||||
return new Response(
|
||||
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
|
||||
{
|
||||
status: 500,
|
||||
headers: { ...corsHeaders, "Content-Type": "application/json" },
|
||||
}
|
||||
);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user