|
| 1 | +import { Router } from 'express'; |
| 2 | +import { z } from 'zod'; |
| 3 | + |
| 4 | +import type { |
| 5 | + JwtSessionManagerImpl, |
| 6 | + SharedLinkService, |
| 7 | + SystemSettingsService, |
| 8 | +} from '@fieldstack/core' with { "resolution-mode": "import" }; |
| 9 | + |
| 10 | +import { requireAuth } from '../middleware/require-auth'; |
| 11 | + |
| 12 | +// ── Zod 스키마 ──────────────────────────────────────────────── |
| 13 | + |
| 14 | +const IssueBody = z.object({ |
| 15 | + resourceType: z.string().min(1), |
| 16 | + resourceId: z.string().min(1), |
| 17 | + expiresAt: z.string().datetime({ offset: true }).optional(), |
| 18 | + password: z.string().min(1).optional(), |
| 19 | + maxAccessCount: z.number().int().positive().optional(), |
| 20 | +}); |
| 21 | + |
| 22 | +// ── 라우터 팩토리 ────────────────────────────────────────────── |
| 23 | + |
| 24 | +export interface ShareRouterDeps { |
| 25 | + sharedLink: SharedLinkService; |
| 26 | + settings: SystemSettingsService; |
| 27 | + jwtManager: JwtSessionManagerImpl; |
| 28 | +} |
| 29 | + |
| 30 | +export function createShareRouter(deps: ShareRouterDeps): Router { |
| 31 | + const router = Router(); |
| 32 | + const { sharedLink, settings, jwtManager } = deps; |
| 33 | + const auth = requireAuth(jwtManager); |
| 34 | + |
| 35 | + // POST /core/share — 링크 발행 |
| 36 | + router.post('/', auth, async (req, res) => { |
| 37 | + const parsed = IssueBody.safeParse(req.body); |
| 38 | + if (!parsed.success) { |
| 39 | + res.status(400).json({ success: false, error: parsed.error.flatten() }); |
| 40 | + return; |
| 41 | + } |
| 42 | + |
| 43 | + try { |
| 44 | + const result = await sharedLink.issue({ |
| 45 | + ...parsed.data, |
| 46 | + createdBy: req.auth!.userId, |
| 47 | + }); |
| 48 | + res.status(201).json({ success: true, data: result }); |
| 49 | + } catch (err) { |
| 50 | + const code = (err as { code?: string }).code; |
| 51 | + const status = code === 'FEATURE_DISABLED' || code === 'DOMAIN_REQUIRED' ? 403 : 500; |
| 52 | + res.status(status).json({ success: false, error: (err as Error).message, code }); |
| 53 | + } |
| 54 | + }); |
| 55 | + |
| 56 | + // GET /core/share — 내가 발행한 링크 목록 |
| 57 | + router.get('/', auth, async (req, res) => { |
| 58 | + try { |
| 59 | + const links = await sharedLink.listByUser(req.auth!.userId); |
| 60 | + res.json({ success: true, data: links }); |
| 61 | + } catch (err) { |
| 62 | + res.status(500).json({ success: false, error: (err as Error).message }); |
| 63 | + } |
| 64 | + }); |
| 65 | + |
| 66 | + // DELETE /core/share/:token — 링크 무효화 |
| 67 | + router.delete('/:token', auth, async (req, res) => { |
| 68 | + try { |
| 69 | + // TODO(Phase 2): isAdmin 플래그는 JWT payload에 역할 추가 후 사용 |
| 70 | + const token = Array.isArray(req.params['token']) ? req.params['token'][0]! : req.params['token']!; |
| 71 | + await sharedLink.revoke(token, req.auth!.userId, false); |
| 72 | + res.json({ success: true, data: { revoked: true } }); |
| 73 | + } catch (err) { |
| 74 | + const msg = (err as Error).message; |
| 75 | + const status = msg === 'Link not found' ? 404 : msg === 'Forbidden' ? 403 : 500; |
| 76 | + res.status(status).json({ success: false, error: msg }); |
| 77 | + } |
| 78 | + }); |
| 79 | + |
| 80 | + // GET /core/share/settings — 공유 링크 기능 상태 조회 (관리자용) |
| 81 | + router.get('/settings', auth, async (req, res) => { |
| 82 | + const enabled = await settings.getBoolean('shared_links_enabled', true); |
| 83 | + res.json({ |
| 84 | + success: true, |
| 85 | + data: { |
| 86 | + enabled, |
| 87 | + domainConfigured: sharedLink.isAvailable(), |
| 88 | + }, |
| 89 | + }); |
| 90 | + }); |
| 91 | + |
| 92 | + // PATCH /core/share/settings — 공유 링크 on/off 토글 (관리자용) |
| 93 | + router.patch('/settings', auth, async (req, res) => { |
| 94 | + const parsed = z.object({ enabled: z.boolean() }).safeParse(req.body); |
| 95 | + if (!parsed.success) { |
| 96 | + res.status(400).json({ success: false, error: parsed.error.flatten() }); |
| 97 | + return; |
| 98 | + } |
| 99 | + await settings.setBoolean('shared_links_enabled', parsed.data.enabled); |
| 100 | + res.json({ success: true, data: { enabled: parsed.data.enabled } }); |
| 101 | + }); |
| 102 | + |
| 103 | + return router; |
| 104 | +} |
0 commit comments