Files
picpeak/backend/src/routes/adminNotifications.js
T
paul 1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Initial commit - Project start (July 17, 2025)
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked

- Add comprehensive logging for rate limit blocks with full request details
  - IP address (with proper proxy detection), user agent, headers, timestamps
  - Rate limit info (current count, limit, remaining, reset time)
  - Separate tracking for auth vs general endpoints

- Enhance authentication failure logging
  - JWT validation failures with detailed error info
  - Admin auth attempts without token
  - Failed token validation with user context
  - All events include IP, path, method, user agent

- Improve Winston logger configuration for production
  - Add automatic log rotation (10MB errors, 50MB combined)
  - Create separate security.log for auth/rate limit events
  - Ensure logs directory exists automatically
  - Add structured JSON format for log aggregation
  - Support container logging with LOG_TO_CONSOLE env var

- Create comprehensive documentation
  - Security logging guide with examples
  - Monitoring recommendations
  - Configuration reference

- Add test script to verify logging functionality

All rate limit settings remain configurable via admin panel:
- Window duration, max requests, auth limits
- Skip authenticated requests option
- Public endpoints only option

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-24 16:57:07 +02:00

122 lines
3.6 KiB
JavaScript

const express = require('express');
const { db, logActivity } = require('../database/db');
const { adminAuth } = require('../middleware/auth-enhanced-v2');
const router = express.Router();
// Get notifications (unread activity logs)
router.get('/', adminAuth, async (req, res) => {
try {
const { limit = 20, includeRead = false } = req.query;
let query = db('activity_logs')
.select(
'activity_logs.*',
'events.event_name'
)
.leftJoin('events', 'activity_logs.event_id', 'events.id')
.orderBy('activity_logs.created_at', 'desc')
.limit(parseInt(limit));
// By default, only show unread notifications
if (includeRead !== 'true') {
query = query.whereNull('activity_logs.read_at');
}
const notifications = await query;
// Format notifications
const formattedNotifications = notifications.map(notification => ({
id: notification.id,
type: notification.activity_type,
actorType: notification.actor_type,
actorName: notification.actor_name,
eventName: notification.event_name,
eventId: notification.event_id,
metadata: (() => {
try {
if (!notification.metadata) return {};
if (typeof notification.metadata === 'object') return notification.metadata;
return JSON.parse(notification.metadata);
} catch (e) {
console.warn('Failed to parse metadata for notification:', notification.id, e.message);
return {};
}
})(),
createdAt: notification.created_at,
readAt: notification.read_at,
isRead: !!notification.read_at
}));
// Get unread count
const unreadCount = await db('activity_logs')
.whereNull('read_at')
.count('id as count')
.first();
res.json({
notifications: formattedNotifications,
unreadCount: unreadCount.count || 0
});
} catch (error) {
console.error('Notifications fetch error:', error);
res.status(500).json({ error: 'Failed to fetch notifications' });
}
});
// Mark notification as read
router.put('/:id/read', adminAuth, async (req, res) => {
try {
const { id } = req.params;
await db('activity_logs')
.where('id', id)
.update({
read_at: new Date()
});
res.json({ message: 'Notification marked as read' });
} catch (error) {
console.error('Mark notification read error:', error);
res.status(500).json({ error: 'Failed to mark notification as read' });
}
});
// Mark all notifications as read
router.put('/read-all', adminAuth, async (req, res) => {
try {
await db('activity_logs')
.whereNull('read_at')
.update({
read_at: new Date()
});
res.json({ message: 'All notifications marked as read' });
} catch (error) {
console.error('Mark all notifications read error:', error);
res.status(500).json({ error: 'Failed to mark all notifications as read' });
}
});
// Delete old notifications (older than 30 days and read)
router.delete('/clear-old', adminAuth, async (req, res) => {
try {
// Use database-agnostic date calculation
const thirtyDaysAgo = new Date();
thirtyDaysAgo.setDate(thirtyDaysAgo.getDate() - 30);
const deletedCount = await db('activity_logs')
.whereNotNull('read_at')
.where('created_at', '<', thirtyDaysAgo)
.delete();
res.json({
message: 'Old notifications cleared',
deletedCount
});
} catch (error) {
console.error('Clear old notifications error:', error);
res.status(500).json({ error: 'Failed to clear old notifications' });
}
});
module.exports = router;