feat: Implement Phase 2 cross-cutting services with email and notification enhancements
- Refactor email verification and password reset utilities to use new email service. - Introduce email delivery queue and notification delivery model for better tracking. - Enhance file validation and storage services for improved security and ownership management. - Add cron job for cleaning inactive notifications with retention policy. - Update document worker to handle document generation and storage more efficiently. - Implement logging improvements in activity and log workers. - Create comprehensive documentation for new API endpoints and services. - Add unit tests for file validation and notification policies to ensure robustness.
This commit is contained in:
@@ -48,31 +48,8 @@ router.get("/view/:file", docsSession, (req, res) => {
|
||||
});
|
||||
|
||||
// Docs login (simple)
|
||||
router.post("/login", sensitiveLimiter, (req, res) => {
|
||||
const { username, password } = req.body;
|
||||
router.post("/login", sensitiveLimiter, (_req, res) => res.status(410).json({ success: false, error: { code: "DEPRECATED", message: "Use an authenticated ADMIN or SUPER_ADMIN session" } }));
|
||||
|
||||
if (
|
||||
username === process.env.DOCS_USER &&
|
||||
password === process.env.DOCS_PASS
|
||||
) {
|
||||
res.cookie("docsAuth", "true", {
|
||||
httpOnly: true,
|
||||
sameSite: "lax",
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
});
|
||||
|
||||
return res.json({ success: true });
|
||||
}
|
||||
|
||||
return res.status(401).json({
|
||||
success: false,
|
||||
message: "Invalid credentials",
|
||||
});
|
||||
});
|
||||
|
||||
router.post("/logout", (req, res) => {
|
||||
res.clearCookie("docsAuth");
|
||||
res.json({ success: true });
|
||||
});
|
||||
router.post("/logout", (_req, res) => res.status(410).json({ success: false, error: { code: "DEPRECATED", message: "Use the authentication logout endpoint" } }));
|
||||
|
||||
module.exports = router;
|
||||
|
||||
Reference in New Issue
Block a user