feat: Implement Phase 2 cross-cutting services with email and notification enhancements

- Refactor email verification and password reset utilities to use new email service.
- Introduce email delivery queue and notification delivery model for better tracking.
- Enhance file validation and storage services for improved security and ownership management.
- Add cron job for cleaning inactive notifications with retention policy.
- Update document worker to handle document generation and storage more efficiently.
- Implement logging improvements in activity and log workers.
- Create comprehensive documentation for new API endpoints and services.
- Add unit tests for file validation and notification policies to ensure robustness.
This commit is contained in:
Sathira Sri Sathara
2026-09-03 14:22:34 +05:30
parent 9d3d431416
commit b6b345f245
54 changed files with 593 additions and 1248 deletions
+2 -2
View File
@@ -24,7 +24,7 @@ const PERMISSIONS = require("../constants/permissions");
router.get(
"/",
authenticate,
authorizedAccountType(["admin"]),
checkPermission("audit.read", { custom: true }),
activityController.getUserActivities,
);
@@ -32,7 +32,7 @@ router.get(
router.get(
"/user/:userId",
authenticate,
authorizedAccountType(["admin"]),
checkPermission("audit.read", { custom: true }),
activityController.getActivitiesByUserId,
);
+2 -25
View File
@@ -48,31 +48,8 @@ router.get("/view/:file", docsSession, (req, res) => {
});
// Docs login (simple)
router.post("/login", sensitiveLimiter, (req, res) => {
const { username, password } = req.body;
router.post("/login", sensitiveLimiter, (_req, res) => res.status(410).json({ success: false, error: { code: "DEPRECATED", message: "Use an authenticated ADMIN or SUPER_ADMIN session" } }));
if (
username === process.env.DOCS_USER &&
password === process.env.DOCS_PASS
) {
res.cookie("docsAuth", "true", {
httpOnly: true,
sameSite: "lax",
secure: process.env.NODE_ENV === "production",
});
return res.json({ success: true });
}
return res.status(401).json({
success: false,
message: "Invalid credentials",
});
});
router.post("/logout", (req, res) => {
res.clearCookie("docsAuth");
res.json({ success: true });
});
router.post("/logout", (_req, res) => res.status(410).json({ success: false, error: { code: "DEPRECATED", message: "Use the authentication logout endpoint" } }));
module.exports = router;
+12 -94
View File
@@ -1,94 +1,12 @@
/**
* Copyright (c) 2026 Niolla
* All rights reserved.
*
* This source code is proprietary and confidential.
* Unauthorized copying, modification, distribution, or use
* of this file, via any medium, is strictly prohibited.
*/
// app/routes/document.routes.js
const express = require("express");
const router = express.Router();
const generateDocumentController = require("../controllers/generateDocument.controller");
const {
authenticate,
} = require("../middleware/auth.middleware");
const { authorizedAccountType, checkPermission } = require("../middleware/permission.middleware");
const PERMISSIONS = require("../constants/permissions");
// Get available document types
router.get(
"/types",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.getAvailableDocumentTypes
);
// Get saved documents
router.post(
"/saved",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.getSavedDocuments
);
// Generate Document (async - returns jobId immediately)
router.post(
"/generate",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.generateDocument
);
router.post(
"/draft",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.generateDraftDocument
);
// Generate Reference Number
router.get(
"/reference-number/:documentType",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.generateReferenceNo
);
// Get Job Status
router.get(
"/job/:jobId/status",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.getJobStatus
);
// Download Document
router.get(
"/download/:uuid",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.downloadDocument
);
// Cancel Job
router.delete(
"/job/:jobId",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.cancelJob
);
// Get document details
router.get(
"/:docId",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
generateDocumentController.getDocumentData
);
module.exports = router;
const router = require("express").Router();
const c = require("../controllers/generateDocument.controller");
const { authenticate } = require("../middleware/auth.middleware");
router.use(authenticate);
router.get("/types", c.getAvailableDocumentTypes);
router.get("/saved", c.getSavedDocuments); router.post("/saved", c.getSavedDocuments);
router.post("/generate", c.generateDocument); router.post("/draft", c.generateDraftDocument);
router.get("/reference-number/:documentType", c.generateReferenceNo);
router.get("/jobs/:jobId", c.getJobStatus); router.get("/job/:jobId/status", c.getJobStatus);
router.get("/:docId/download", c.downloadDocument); router.get("/download/:docId", c.downloadDocument);
router.delete("/job/:jobId", c.cancelJob); router.get("/:docId", c.getDocumentData);
module.exports = router;
+11 -69
View File
@@ -1,69 +1,11 @@
/**
* Copyright (c) 2026 Niolla
* All rights reserved.
*
* This source code is proprietary and confidential.
* Unauthorized copying, modification, distribution, or use
* of this file, via any medium, is strictly prohibited.
*/
// app/routes/notification.routes.js
const express = require("express");
const router = express.Router();
const notificationController = require("../controllers/notification.controller");
const {
authenticate,
} = require("../middleware/auth.middleware");
const {
authorizedAccountType,
checkPermission,
} = require("../middleware/permission.middleware");
const PERMISSIONS = require("../constants/permissions");
// Create notification
router.post(
"/",
authenticate,
authorizedAccountType(["admin", "management"]),
// checkPermission(PERMISSIONS.NOTIFICATION_CREATE),
notificationController.createNotification,
);
// Get all announcements
router.get(
"/announcements",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
// checkPermission(PERMISSIONS.NOTIFICATION_VIEW),
notificationController.getAnnouncements,
);
// Get notifications for a user
router.get(
"/user/:userId",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
// checkPermission(PERMISSIONS.NOTIFICATION_VIEW),
notificationController.getUserNotifications,
);
// Mark notification as read
router.patch(
"/user/:userId/notification/:notificationId/read",
authenticate,
authorizedAccountType(["admin", "management", "team_head", "user"]),
// checkPermission(PERMISSIONS.NOTIFICATION_READ),
notificationController.markAsRead,
);
module.exports = router;
const router = require("express").Router();
const controller = require("../controllers/notification.controller");
const { authenticate } = require("../middleware/auth.middleware");
const { checkPermission } = require("../middleware/permission.middleware");
router.use(authenticate);
router.post("/", checkPermission("notifications.manage", { custom: true }), controller.createNotification);
router.get("/announcements", controller.getAnnouncements);
router.get("/me", controller.getMyNotifications);
router.patch("/read-all", controller.markAllAsRead);
router.patch("/:notificationId/read", controller.markAsRead);
module.exports = router;
+10
View File
@@ -36,6 +36,16 @@ router.post(
authController.changePassword,
);
router.get(
"/me/avatar",
authenticate,
profileController.getProfileAvatar,
);
router.get(
"/me/background",
authenticate,
profileController.getProfileBackgroundImage,
);
router.get(
"/avatar/:userId",
authenticate,
+2 -3
View File
@@ -24,7 +24,6 @@ const PERMISSIONS = require("../constants/permissions");
router.post(
"/",
authenticate,
authorizedAccountType(["admin", "staff"]),
uploadSingle("file"),
uploadController.uploadFile,
);
@@ -33,8 +32,8 @@ router.post(
router.get(
"/signed-url/:id",
authenticate,
authorizedAccountType(["admin", "staff"]),
uploadController.getFileUrl,
);
router.delete("/:id", authenticate, uploadController.deleteFile);
module.exports = router;
module.exports = router;