Member registration fixed
Some checks failed
Code Analysis and Production Deploy / analyze (push) Failing after 6m17s
Code Analysis and Production Deploy / deploy-production (push) Has been skipped
Code Analysis and Production Deploy / deploy-test (push) Has been skipped

This commit is contained in:
Torsten Schulz (local)
2026-08-12 11:15:07 +02:00
parent 281c25b05d
commit cb89fdd911
15 changed files with 263 additions and 41 deletions

View File

@@ -221,14 +221,23 @@ export function normalizeDate(dateString) {
}
// Check for duplicate member based on firstName, lastName, and geburtsdatum
function findDuplicateMember(members, firstName, lastName, geburtsdatum) {
const normalizedFirstName = (firstName || '').trim().toLowerCase()
const normalizedLastName = (lastName || '').trim().toLowerCase()
function normalizeIdentityPart(value) {
return String(value || '')
.normalize('NFKD')
.replace(/[\u0300-\u036f]/g, '')
.replace(/[^a-zA-Z0-9]+/g, ' ')
.trim()
.toLowerCase()
}
export function findDuplicateMember(members, firstName, lastName, geburtsdatum) {
const normalizedFirstName = normalizeIdentityPart(firstName)
const normalizedLastName = normalizeIdentityPart(lastName)
const normalizedDate = normalizeDate(geburtsdatum)
return members.find(m => {
const mFirstName = (m.firstName || '').trim().toLowerCase()
const mLastName = (m.lastName || '').trim().toLowerCase()
const mFirstName = normalizeIdentityPart(m.firstName)
const mLastName = normalizeIdentityPart(m.lastName)
const mDate = normalizeDate(m.geburtsdatum)
return mFirstName === normalizedFirstName &&
@@ -307,4 +316,3 @@ export async function deleteMember(id) {
await writeMembers(filtered)
return true
}

View File

@@ -0,0 +1,105 @@
import { createHash, randomUUID } from 'crypto'
import { promises as fs } from 'fs'
import { decryptObject, encryptObject } from './encryption.js'
import { readMembers, findDuplicateMember, normalizeDate } from './members.js'
import { getServerDataPath } from './paths.js'
const APPLICATIONS_DIR = getServerDataPath('membership-applications')
const LOCKS_DIR = getServerDataPath('membership-application-locks')
function encryptionKey() {
return process.env.ENCRYPTION_KEY || 'local_development_encryption_key_change_in_production'
}
function normalizeName(value) {
return String(value || '')
.normalize('NFKD')
.replace(/[\u0300-\u036f]/g, '')
.replace(/[^a-zA-Z0-9]+/g, ' ')
.trim()
.toLowerCase()
}
function identityHash(data) {
const identity = [normalizeName(data.vorname), normalizeName(data.nachname), normalizeDate(data.geburtsdatum)].join('|')
return createHash('sha256').update(identity).digest('hex')
}
async function withIdentityLock(hash, operation) {
await fs.mkdir(LOCKS_DIR, { recursive: true })
const lockPath = `${LOCKS_DIR}/${hash}.lock`
let handle
try {
handle = await fs.open(lockPath, 'wx')
} catch (error) {
if (error?.code === 'EEXIST') {
throw createError({ statusCode: 409, statusMessage: 'Für diese Person wird bereits ein Mitgliedschaftsantrag bearbeitet.' })
}
throw error
}
try {
return await operation()
} finally {
await handle.close().catch(() => {})
await fs.unlink(lockPath).catch(() => {})
}
}
async function findMatchingApplication(data) {
let files = []
try {
files = await fs.readdir(APPLICATIONS_DIR)
} catch (error) {
if (error?.code !== 'ENOENT') throw error
return null
}
const target = identityHash(data)
for (const file of files.filter(file => file.endsWith('.json'))) {
try {
const application = JSON.parse(await fs.readFile(`${APPLICATIONS_DIR}/${file}`, 'utf8'))
if (application.identityHash === target) return application
if (application.encryptedData) {
const personalData = decryptObject(application.encryptedData, encryptionKey())
if (identityHash(personalData) === target) return application
}
} catch (error) {
console.warn('Mitgliedschaftsantrag konnte bei der Duplikatprüfung nicht gelesen werden:', { file, message: error.message })
}
}
return null
}
export async function createMembershipApplication(data) {
const hash = identityHash(data)
if (!normalizeName(data.vorname) || !normalizeName(data.nachname) || !normalizeDate(data.geburtsdatum)) {
throw createError({ statusCode: 400, statusMessage: 'Vorname, Nachname und ein gültiges Geburtsdatum sind erforderlich.' })
}
return withIdentityLock(hash, async () => {
const members = await readMembers()
if (findDuplicateMember(members, data.vorname, data.nachname, data.geburtsdatum)) {
throw createError({ statusCode: 409, statusMessage: 'Für diese Person besteht bereits eine Mitgliedschaft.' })
}
const existing = await findMatchingApplication(data)
if (existing) {
throw createError({ statusCode: 409, statusMessage: 'Für diese Person liegt bereits ein Mitgliedschaftsantrag vor.' })
}
await fs.mkdir(APPLICATIONS_DIR, { recursive: true })
const application = {
id: randomUUID(),
timestamp: new Date().toISOString(),
status: 'pending',
identityHash: hash,
metadata: { mitgliedschaftsart: data.mitgliedschaftsart },
encryptedData: encryptObject(data, encryptionKey())
}
await fs.writeFile(`${APPLICATIONS_DIR}/${application.id}.json`, `${JSON.stringify(application, null, 2)}\n`, { encoding: 'utf8', flag: 'wx' })
return application
})
}
export async function removeMembershipApplication(applicationId) {
if (!applicationId) return
await fs.unlink(`${APPLICATIONS_DIR}/${applicationId}.json`).catch(error => {
if (error?.code !== 'ENOENT') throw error
})
}

View File

@@ -114,14 +114,14 @@ async function sendFcmMessage({ serviceAccount, accessToken, token, title, body,
body: JSON.stringify({
message: {
token,
notification: { title, body },
data,
android: {
priority: 'high',
notification: {
channel_id: 'harheimer_tc_updates',
click_action: 'OPEN_NEWS'
}
// Keep this as a data message. With a `notification` payload FCM
// renders background messages itself, bypassing our notification
// channel and HarheimerMessagingService. Data messages use the
// same app-controlled channel while the app is foregrounded and
// backgrounded.
}
}
})
@@ -206,7 +206,11 @@ export async function sendPushToUsers({ title, body, data = {}, predicate, bodyF
}
}
if (changed) await writeUsers(users)
return { sent, failed, removed, recipients, tokenCount, skipped: false }
const result = { sent, failed, removed, recipients, tokenCount, skipped: false }
// This makes an absent registration immediately visible in the production
// log without exposing tokens or user data.
console.info('FCM Push Ergebnis:', { failureLabel, ...result })
return result
}
export async function sendNewNewsPush(news) {