landingpage

This commit is contained in:
2026-08-24 13:38:25 +07:00
commit d8e4e8a502
84 changed files with 12729 additions and 0 deletions
+58
View File
@@ -0,0 +1,58 @@
import { createAdminClient } from "npm:@insforge/sdk";
const corsHeaders = {
"Access-Control-Allow-Origin": "*",
"Access-Control-Allow-Methods": "POST, OPTIONS",
"Access-Control-Allow-Headers": "Content-Type, Authorization",
};
export default async function (req: Request): Promise<Response> {
if (req.method === "OPTIONS") {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== "POST") {
return new Response(JSON.stringify({ error: "Method not allowed" }), {
status: 405,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
try {
const { key } = await req.json();
if (!key || typeof key !== "string") {
return new Response(JSON.stringify({ error: "Missing key" }), {
status: 400,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const admin = createAdminClient({
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
});
const { error } = await admin.storage.from("gallery").remove(key);
if (error) {
return new Response(JSON.stringify({ error: error.message }), {
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
return new Response(JSON.stringify({ success: true }), {
status: 200,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
} catch (err) {
return new Response(
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
{
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
}
);
}
}
+68
View File
@@ -0,0 +1,68 @@
import { createAdminClient } from "npm:@insforge/sdk";
const corsHeaders = {
"Access-Control-Allow-Origin": "*",
"Access-Control-Allow-Methods": "POST, OPTIONS",
"Access-Control-Allow-Headers": "Content-Type, Authorization",
};
export default async function (req: Request): Promise<Response> {
if (req.method === "OPTIONS") {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== "POST") {
return new Response(JSON.stringify({ error: "Method not allowed" }), {
status: 405,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
try {
const { name, contentType, base64 } = await req.json();
if (!base64 || typeof base64 !== "string") {
return new Response(JSON.stringify({ error: "Missing base64 file" }), {
status: 400,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const bytes = Uint8Array.from(atob(base64), (c) => c.charCodeAt(0));
const file = new File([bytes], name || "gallery.jpg", {
type: contentType || "image/jpeg",
});
const admin = createAdminClient({
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
});
const { data, error } = await admin.storage
.from("gallery")
.uploadAuto(file);
if (error || !data) {
return new Response(
JSON.stringify({ error: error?.message || "Upload failed" }),
{
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
}
);
}
return new Response(JSON.stringify({ url: data.url, key: data.key }), {
status: 200,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
} catch (err) {
return new Response(
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
{
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
}
);
}
}
+83
View File
@@ -0,0 +1,83 @@
import { createAdminClient } from "npm:@insforge/sdk";
const corsHeaders = {
"Access-Control-Allow-Origin": "*",
"Access-Control-Allow-Methods": "POST, OPTIONS",
"Access-Control-Allow-Headers": "Content-Type, Authorization",
};
function sha256Hex(text: string): Promise<string> {
return crypto.subtle
.digest("SHA-256", new TextEncoder().encode(text))
.then((buf) =>
Array.from(new Uint8Array(buf))
.map((b) => b.toString(16).padStart(2, "0"))
.join("")
);
}
export default async function (req: Request): Promise<Response> {
if (req.method === "OPTIONS") {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== "POST") {
return new Response(JSON.stringify({ error: "Method not allowed" }), {
status: 405,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
try {
const { username, password } = await req.json();
if (
typeof username !== "string" ||
typeof password !== "string" ||
!username.trim() ||
!password
) {
return new Response(JSON.stringify({ error: "Username & password wajib." }), {
status: 400,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const admin = createAdminClient({
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
});
const { data: user } = await admin.database
.from("app_users")
.select("username, password_hash, salt")
.eq("username", username.trim())
.maybeSingle();
if (!user) {
return new Response(JSON.stringify({ error: "Username atau password salah." }), {
status: 401,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const pepper = Deno.env.get("AUTH_PEPPER") ?? "";
const hash = await sha256Hex(`${user.salt}|${password}|${pepper}`);
if (hash !== user.password_hash) {
return new Response(JSON.stringify({ error: "Username atau password salah." }), {
status: 401,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
return new Response(JSON.stringify({ ok: true, username: user.username }), {
status: 200,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
} catch (err) {
return new Response(
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
{ status: 500, headers: { ...corsHeaders, "Content-Type": "application/json" } }
);
}
}
+107
View File
@@ -0,0 +1,107 @@
import { createAdminClient } from "npm:@insforge/sdk";
const corsHeaders = {
"Access-Control-Allow-Origin": "*",
"Access-Control-Allow-Methods": "POST, OPTIONS",
"Access-Control-Allow-Headers": "Content-Type, Authorization",
};
function sha256Hex(text: string): Promise<string> {
return crypto.subtle
.digest("SHA-256", new TextEncoder().encode(text))
.then((buf) =>
Array.from(new Uint8Array(buf))
.map((b) => b.toString(16).padStart(2, "0"))
.join("")
);
}
function randomSalt(): string {
const bytes = new Uint8Array(16);
crypto.getRandomValues(bytes);
return Array.from(bytes)
.map((b) => b.toString(16).padStart(2, "0"))
.join("");
}
export default async function (req: Request): Promise<Response> {
if (req.method === "OPTIONS") {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== "POST") {
return new Response(JSON.stringify({ error: "Method not allowed" }), {
status: 405,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
try {
const { username, password } = await req.json();
if (
typeof username !== "string" ||
typeof password !== "string" ||
username.trim().length < 3 ||
password.length < 6
) {
return new Response(
JSON.stringify({ error: "Username min 3 & password min 6 karakter." }),
{ status: 400, headers: { ...corsHeaders, "Content-Type": "application/json" } }
);
}
const admin = createAdminClient({
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
});
const { count } = await admin.database
.from("app_users")
.select("id", { count: "exact", head: true });
if ((count ?? 0) > 0) {
return new Response(
JSON.stringify({ error: "Akun admin sudah dibuat. Pendaftaran ditutup." }),
{ status: 403, headers: { ...corsHeaders, "Content-Type": "application/json" } }
);
}
const { data: existing } = await admin.database
.from("app_users")
.select("id")
.eq("username", username.trim())
.maybeSingle();
if (existing) {
return new Response(JSON.stringify({ error: "Username sudah dipakai." }), {
status: 409,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const salt = randomSalt();
const pepper = Deno.env.get("AUTH_PEPPER") ?? "";
const hash = await sha256Hex(`${salt}|${password}|${pepper}`);
const { error } = await admin.database.from("app_users").insert([
{ username: username.trim(), password_hash: hash, salt },
]);
if (error) {
return new Response(JSON.stringify({ error: error.message }), {
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
return new Response(JSON.stringify({ ok: true }), {
status: 200,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
} catch (err) {
return new Response(
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
{ status: 500, headers: { ...corsHeaders, "Content-Type": "application/json" } }
);
}
}
+60
View File
@@ -0,0 +1,60 @@
import { createAdminClient } from "npm:@insforge/sdk";
const corsHeaders = {
"Access-Control-Allow-Origin": "*",
"Access-Control-Allow-Methods": "POST, OPTIONS",
"Access-Control-Allow-Headers": "Content-Type, Authorization",
};
export default async function (req: Request): Promise<Response> {
if (req.method === "OPTIONS") {
return new Response(null, { status: 204, headers: corsHeaders });
}
if (req.method !== "POST") {
return new Response(JSON.stringify({ error: "Method not allowed" }), {
status: 405,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
try {
const { name, phone } = await req.json();
if (!name || typeof name !== "string" || !phone || typeof phone !== "string") {
return new Response(JSON.stringify({ error: "Missing name or phone" }), {
status: 400,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
const admin = createAdminClient({
baseUrl: Deno.env.get("INSFORGE_BASE_URL")!,
apiKey: Deno.env.get("INSFORGE_API_KEY")!,
});
const { error } = await admin.database
.from("discount_claims")
.insert([{ name: name.trim(), phone: phone.trim() }]);
if (error) {
return new Response(JSON.stringify({ error: error.message }), {
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
}
return new Response(JSON.stringify({ success: true }), {
status: 200,
headers: { ...corsHeaders, "Content-Type": "application/json" },
});
} catch (err) {
return new Response(
JSON.stringify({ error: err instanceof Error ? err.message : "Unknown error" }),
{
status: 500,
headers: { ...corsHeaders, "Content-Type": "application/json" },
}
);
}
}