Admin panel changes and sidebar scrolling fix
All checks were successful
Automated Container Build / build-and-push (push) Successful in 17s

This commit is contained in:
Elijah 2026-05-20 19:14:07 -07:00
parent 9577fd1cf3
commit 692ef068a1
4 changed files with 341 additions and 61 deletions

View file

@ -7,6 +7,30 @@ const { PDFDocument } = require('pdf-lib');
const { WebSocketServer } = require('ws');
const http = require('http');
// ── UA Parsing Helper ──────────────────────────────────────
function parseUserAgent(ua) {
if (!ua) return { browser: 'Unknown', os: 'Unknown' };
let browser = 'Unknown';
if (ua.includes('Edg/')) browser = 'Edge';
else if (ua.includes('OPR/') || ua.includes('Opera')) browser = 'Opera';
else if (ua.includes('Chrome/')) browser = 'Chrome';
else if (ua.includes('Safari/') && !ua.includes('Chrome')) browser = 'Safari';
else if (ua.includes('Firefox/')) browser = 'Firefox';
else if (ua.includes('MSIE') || ua.includes('Trident/')) browser = 'IE';
let os = 'Unknown';
if (ua.includes('Windows')) os = 'Windows';
else if (ua.includes('Mac OS')) os = 'macOS';
else if (ua.includes('Android')) os = 'Android';
else if (ua.includes('iPhone') || ua.includes('iPad')) os = 'iOS';
else if (ua.includes('Linux')) os = 'Linux';
else if (ua.includes('CrOS')) os = 'ChromeOS';
return { browser, os };
}
const app = express();
const server = http.createServer(app);
const PORT = process.env.PORT || 3000;
@ -104,7 +128,7 @@ const upload = multer({
});
// ── Session Tracking ───────────────────────────────────────
// Map sessionId -> { filePath, originalName, connectedClients, lastAccess }
// Map sessionId -> { filePath, originalName, connectedClients, lastAccess, ip, userAgent, browser, os, startTime }
const sessions = new Map();
@ -145,8 +169,10 @@ setInterval(() => {
const wss = new WebSocketServer({ server });
wss.on('connection', (ws) => {
wss.on('connection', (ws, req) => {
let wsSessionId = null;
const wsIp = req.headers['x-forwarded-for']?.split(',')[0]?.trim() || req.socket.remoteAddress;
const wsUserAgent = req.headers['user-agent'] || '';
ws.on('message', (msg) => {
try {
@ -163,6 +189,16 @@ wss.on('connection', (ws) => {
const session = sessions.get(wsSessionId);
if (session) {
session.connectedClients++;
// Update connection metadata from WebSocket
if (!session.ip || session.ip === 'unknown') {
session.ip = wsIp;
}
if (!session.userAgent) {
session.userAgent = wsUserAgent;
const parsed = parseUserAgent(wsUserAgent);
session.browser = parsed.browser;
session.os = parsed.os;
}
touchSession(wsSessionId);
console.log(`[ws] Client connected to session ${wsSessionId} (${session.connectedClients} clients)`);
}
@ -232,11 +268,30 @@ app.post('/api/login', checkBruteForce, (req, res) => {
app.get('/api/admin/stats', requireAuth, requireAdmin, (req, res) => {
const mem = process.memoryUsage();
const blockedIps = [];
// All tracked IPs (including non-blocked)
const trackedIps = [];
for (const [ip, record] of loginAttempts) {
if (record.lockoutUntil > Date.now()) {
blockedIps.push({ ip, attempts: record.attempts, lockoutRemaining: Math.ceil((record.lockoutUntil - Date.now()) / 1000) });
}
const isLocked = record.lockoutUntil && record.lockoutUntil > Date.now();
trackedIps.push({
ip,
attempts: record.attempts,
locked: isLocked,
lockoutRemaining: isLocked ? Math.ceil((record.lockoutUntil - Date.now()) / 1000) : 0
});
}
// Detailed session info
const sessionDetails = [];
for (const [id, session] of sessions) {
sessionDetails.push({
id: id.substring(0, 8),
originalName: session.originalName,
ip: session.ip || 'Unknown',
browser: session.browser || 'Unknown',
os: session.os || 'Unknown',
startTime: session.startTime || null,
connectedClients: session.connectedClients
});
}
res.json({
@ -244,7 +299,8 @@ app.get('/api/admin/stats', requireAuth, requireAdmin, (req, res) => {
memoryUsedMB: Math.round(mem.rss / 1024 / 1024),
activeSessions: sessions.size,
loginAttemptsTracked: loginAttempts.size,
blockedIps
trackedIps,
sessionDetails
});
});
@ -259,6 +315,16 @@ app.post('/api/admin/clear-cache', requireAuth, requireAdmin, (req, res) => {
} catch (e) { /* ignore */ }
}
sessions.clear();
// Broadcast cache-cleared event to all connected WebSocket clients
for (const client of wss.clients) {
if (client.readyState === 1) { // WebSocket.OPEN
try {
client.send(JSON.stringify({ type: 'cache-cleared' }));
} catch (e) { /* ignore */ }
}
}
res.json({ success: true, deletedCount });
});
@ -267,11 +333,7 @@ app.post('/api/admin/clear-logins', requireAuth, requireAdmin, (req, res) => {
res.json({ success: true });
});
app.post('/api/admin/change-password', requireAuth, requireAdmin, (req, res) => {
const { newPassword } = req.body;
currentAppPassword = newPassword || null;
res.json({ success: true });
});
// (Change-password endpoint removed)
// ── API: Upload PDF ────────────────────────────────────────
@ -280,11 +342,19 @@ app.post('/api/upload', requireAuth, upload.single('pdf'), (req, res) => {
const sessionId = path.basename(req.file.filename, path.extname(req.file.filename));
const ua = req.headers['user-agent'] || '';
const parsed = parseUserAgent(ua);
sessions.set(sessionId, {
filePath: req.file.path,
originalName: req.file.originalname,
connectedClients: 0,
lastAccess: Date.now()
lastAccess: Date.now(),
ip: req.ip || 'unknown',
userAgent: ua,
browser: parsed.browser,
os: parsed.os,
startTime: Date.now()
});
console.log(`[upload] ${req.file.originalname} -> session ${sessionId}`);