1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked - Add comprehensive logging for rate limit blocks with full request details - IP address (with proper proxy detection), user agent, headers, timestamps - Rate limit info (current count, limit, remaining, reset time) - Separate tracking for auth vs general endpoints - Enhance authentication failure logging - JWT validation failures with detailed error info - Admin auth attempts without token - Failed token validation with user context - All events include IP, path, method, user agent - Improve Winston logger configuration for production - Add automatic log rotation (10MB errors, 50MB combined) - Create separate security.log for auth/rate limit events - Ensure logs directory exists automatically - Add structured JSON format for log aggregation - Support container logging with LOG_TO_CONSOLE env var - Create comprehensive documentation - Security logging guide with examples - Monitoring recommendations - Configuration reference - Add test script to verify logging functionality All rate limit settings remain configurable via admin panel: - Window duration, max requests, auth limits - Skip authenticated requests option - Public endpoints only option 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
127 lines
3.5 KiB
TypeScript
127 lines
3.5 KiB
TypeScript
import { api } from '../config/api';
|
|
import type { Event } from '../types';
|
|
|
|
interface CreateEventData {
|
|
event_type: string;
|
|
event_name: string;
|
|
event_date: string;
|
|
host_email: string;
|
|
admin_email: string;
|
|
password: string;
|
|
welcome_message?: string;
|
|
color_theme?: string;
|
|
expiration_days: number;
|
|
allow_user_uploads?: boolean;
|
|
upload_category_id?: number | null;
|
|
}
|
|
|
|
interface UpdateEventData {
|
|
event_name?: string;
|
|
event_date?: string;
|
|
host_email?: string;
|
|
admin_email?: string;
|
|
password?: string;
|
|
welcome_message?: string;
|
|
color_theme?: string;
|
|
expires_at?: string;
|
|
is_active?: boolean;
|
|
allow_user_uploads?: boolean;
|
|
upload_category_id?: number | null;
|
|
hero_photo_id?: number | null;
|
|
}
|
|
|
|
interface EventsListResponse {
|
|
events: Event[];
|
|
total: number;
|
|
page: number;
|
|
limit: number;
|
|
}
|
|
|
|
export const eventsService = {
|
|
// Get all events (admin)
|
|
async getEvents(
|
|
page: number = 1,
|
|
limit: number = 20,
|
|
status?: 'active' | 'inactive' | 'archived'
|
|
): Promise<EventsListResponse> {
|
|
const params = new URLSearchParams({
|
|
page: page.toString(),
|
|
limit: limit.toString(),
|
|
});
|
|
|
|
if (status) {
|
|
params.append('status', status);
|
|
}
|
|
|
|
const response = await api.get<EventsListResponse>(`/admin/events?${params}`);
|
|
return response.data;
|
|
},
|
|
|
|
// Get single event details (admin)
|
|
async getEvent(id: number): Promise<Event> {
|
|
const response = await api.get<Event>(`/admin/events/${id}`);
|
|
return response.data;
|
|
},
|
|
|
|
// Create new event (admin)
|
|
async createEvent(data: CreateEventData): Promise<Event> {
|
|
const response = await api.post<Event>('/admin/events', data);
|
|
return response.data;
|
|
},
|
|
|
|
// Update event (admin)
|
|
async updateEvent(id: number, data: UpdateEventData): Promise<Event> {
|
|
const response = await api.put<Event>(`/admin/events/${id}`, data);
|
|
return response.data;
|
|
},
|
|
|
|
// Delete/deactivate event (admin)
|
|
async deleteEvent(id: number): Promise<void> {
|
|
await api.delete(`/admin/events/${id}`);
|
|
},
|
|
|
|
// Force archive event (admin)
|
|
async archiveEvent(id: number): Promise<void> {
|
|
await api.post(`/admin/events/${id}/archive`);
|
|
},
|
|
|
|
// Bulk archive events (admin)
|
|
async bulkArchiveEvents(eventIds: number[]): Promise<{
|
|
message: string;
|
|
results: {
|
|
successful: Array<{ id: number; name: string }>;
|
|
failed: Array<{ id: number; name: string; error: string }>;
|
|
};
|
|
}> {
|
|
const response = await api.post('/admin/events/bulk-archive', {
|
|
eventIds,
|
|
});
|
|
return response.data;
|
|
},
|
|
|
|
// Extend event expiration (admin)
|
|
async extendExpiration(id: number, days: number): Promise<Event> {
|
|
const response = await api.post<Event>(`/events/${id}/extend`, {
|
|
days,
|
|
});
|
|
return response.data;
|
|
},
|
|
|
|
// Get event categories
|
|
async getEventCategories(eventId: number): Promise<Array<{ id: number; name: string; slug: string }>> {
|
|
const response = await api.get(`/admin/categories/event/${eventId}`);
|
|
return response.data || [];
|
|
},
|
|
|
|
// Reset event password
|
|
async resetPassword(eventId: number, sendEmail: boolean = true): Promise<{ message: string; newPassword: string; emailSent: boolean }> {
|
|
const response = await api.post(`/admin/events/${eventId}/reset-password`, { sendEmail });
|
|
return response.data;
|
|
},
|
|
|
|
// Resend creation email
|
|
async resendCreationEmail(eventId: number): Promise<{ success: boolean; message: string }> {
|
|
const response = await api.post(`/admin/events/${eventId}/resend-email`);
|
|
return response.data;
|
|
},
|
|
}; |