267e80e2ec
- Refactor server initialization to separate concerns and improve error handling. - Implement centralized environment validation using Zod. - Introduce database, Redis, and queue lifecycle management. - Add health check endpoints for liveness and readiness. - Enhance error handling middleware for better response structure. - Implement rate limiting for API endpoints. - Add request ID middleware for traceability. - Create Sequelize CLI configuration and baseline migration for schema management. - Establish CI workflow with Gitea for testing and syntax checks. - Document foundational changes and migration strategy in PHASE_0_FOUNDATION_STABILIZATION.md. - Add Docker Compose configuration for local development and testing. - Implement unit and integration tests for critical functionality.
70 lines
2.3 KiB
JavaScript
70 lines
2.3 KiB
JavaScript
/**
|
|
* Copyright (c) 2026 Niolla
|
|
* All rights reserved.
|
|
*/
|
|
|
|
const express = require("express");
|
|
const cors = require("cors");
|
|
const helmet = require("helmet");
|
|
const morgan = require("morgan");
|
|
const cookieParser = require("cookie-parser");
|
|
const path = require("path");
|
|
|
|
const routes = require("./app/routes");
|
|
const { healthRouter, live } = require("./app/routes/health.routes");
|
|
const { bullBoardRouter } = require("./app/config/bullBoard.config");
|
|
const { authenticate } = require("./app/middleware/auth.middleware");
|
|
const { authorizedAccountType } = require("./app/middleware/permission.middleware");
|
|
const requestId = require("./app/middleware/requestId.middleware");
|
|
const { generalApiLimiter } = require("./app/middleware/rateLimit.middleware");
|
|
const { notFound, errorHandler } = require("./app/middleware/error.middleware");
|
|
|
|
const app = express();
|
|
const trustProxy = Number(process.env.TRUST_PROXY || 0);
|
|
if (trustProxy > 0) app.set("trust proxy", trustProxy);
|
|
|
|
app.disable("x-powered-by");
|
|
app.use(requestId);
|
|
app.use(helmet({
|
|
contentSecurityPolicy: false,
|
|
hsts: process.env.NODE_ENV === "production" ? undefined : false,
|
|
}));
|
|
app.use(cookieParser());
|
|
app.use(cors({
|
|
origin: process.env.FRONTEND_URL,
|
|
methods: ["GET", "POST", "PUT", "DELETE", "PATCH", "OPTIONS"],
|
|
allowedHeaders: ["Content-Type", "Authorization", "X-Request-ID"],
|
|
exposedHeaders: ["X-Request-ID"],
|
|
credentials: true,
|
|
}));
|
|
app.use(express.json({ limit: process.env.JSON_BODY_LIMIT || "1mb" }));
|
|
app.use(express.urlencoded({ extended: false, limit: process.env.JSON_BODY_LIMIT || "1mb" }));
|
|
|
|
morgan.token("request-id", (req) => req.id);
|
|
app.use(morgan(process.env.NODE_ENV === "production" ? ':remote-addr - :method :url :status :response-time ms req-id=:request-id' : "dev"));
|
|
|
|
app.get("/health", live);
|
|
app.use("/health", healthRouter);
|
|
|
|
// Keep the legacy path while all new clients migrate to the versioned path.
|
|
app.use("/api", generalApiLimiter, routes);
|
|
app.use("/api/v1", generalApiLimiter, routes);
|
|
|
|
app.use(
|
|
"/Documentation",
|
|
(req, res, next) => req.path.endsWith(".md") ? res.status(403).send("Forbidden") : next(),
|
|
express.static(path.join(__dirname, "Documentation")),
|
|
);
|
|
|
|
app.use(
|
|
"/admin/queues",
|
|
authenticate,
|
|
authorizedAccountType(["admin", "superadmin"]),
|
|
bullBoardRouter,
|
|
);
|
|
|
|
app.use(notFound);
|
|
app.use(errorHandler);
|
|
|
|
module.exports = app;
|