Füge myTischtennis-Verbindung hinzu: Implementiere Authentifizierung, Import von TTR-Werten und speichere Verbindungsdaten sicher
This commit is contained in:
19
server/api/cms/mytischtennis/import.post.js
Normal file
19
server/api/cms/mytischtennis/import.post.js
Normal file
@@ -0,0 +1,19 @@
|
||||
import { getUserFromToken, hasAnyRole } from '../../../utils/auth.js'
|
||||
import { importQttrValues } from '../../../utils/qttr-import.js'
|
||||
import { readMyTischtennisConnection, saveMyTischtennisConnection } from '../../../utils/mytischtennis-connection.js'
|
||||
|
||||
export default defineEventHandler(async (event) => {
|
||||
const token = getCookie(event, 'auth_token') || getHeader(event, 'authorization')?.replace(/^Bearer\s+/i, '')
|
||||
const user = token ? await getUserFromToken(token) : null
|
||||
if (!user) throw createError({ statusCode: 401, statusMessage: 'Nicht authentifiziert' })
|
||||
if (!hasAnyRole(user, 'admin', 'vorstand')) throw createError({ statusCode: 403, statusMessage: 'Keine Berechtigung' })
|
||||
const connection = await readMyTischtennisConnection()
|
||||
if (!connection) throw createError({ statusCode: 409, statusMessage: 'Keine myTischtennis-Verbindung eingerichtet.' })
|
||||
try {
|
||||
const result = await importQttrValues({ connection })
|
||||
return { success: true, rowCount: result.rowCount, importedAt: result.importedAt }
|
||||
} catch (error) {
|
||||
await saveMyTischtennisConnection({ ...connection, lastImportError: String(error.message || error).slice(0, 500) })
|
||||
throw createError({ statusCode: 502, statusMessage: 'TTR-Abruf bei myTischtennis fehlgeschlagen.' })
|
||||
}
|
||||
})
|
||||
Reference in New Issue
Block a user