Compare commits

...
67 Commits
Author SHA1 Message Date
lzstealth a7d867dd6f Adjust API source response header spacing
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m15s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-22 01:39:35 +01:00
lzstealth 196c640f9b Release 2.8.7
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m47s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 31s
2026-08-22 01:33:35 +01:00
lzstealth 7bd4a792ee Merge remote-tracking branch 'Gitea_SSH/main'
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m50s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
# Conflicts:
#	CHANGELOG.md
#	build/package.player.json
#	build/package.web.json
#	package-lock.json
#	package.json
2026-08-18 02:25:15 +01:00
lzstealth e1e759f64e Release 2.8.6 2026-08-18 02:23:42 +01:00
lzstealth f071c21219 Release 2.8.5
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m15s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 02:15:18 +01:00
lzstealth e984f36875 Release 2.8.5
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m53s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 02:07:48 +01:00
lzstealth bbd517abbb Fix scheduled task run notification
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 00:54:13 +01:00
lzstealth 403a928b9e Release 2.8.4
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 35s
2026-08-17 00:46:07 +01:00
lzstealth 7bb34f40fe Release 2.8.3
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 00:08:05 +01:00
lzstealth ea72747822 Release 2.8.2
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m12s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 34s
2026-08-16 22:41:39 +01:00
lzstealth a5bf8e6f7f Release 2.8.1
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m16s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-16 22:08:32 +01:00
lzstealth 203d0bfc01 Release 2.8.0
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m49s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-16 17:15:31 +01:00
lzstealth 1bdc122995 Target Node 26
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m17s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-15 15:02:28 +01:00
lzstealth 2d748458d0 Remove GHCR publish path 2026-08-15 14:21:54 +01:00
lzstealth bb8cd98e61 Publish Docker images to both registries
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m25s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
Publish Docker Image / build-and-push-ghcr (./build/Dockerfile, web, pulse-signage-web) (push) Failing after 1m8s
Publish Docker Image / build-and-push-ghcr (./build/Dockerfile.player, player, pulse-signage-player) (push) Failing after 31s
2026-08-15 14:13:49 +01:00
lzstealth aafe112c36 Release 2.7.5
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m18s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 13:06:46 +01:00
lzstealth 1f1ad5d61f Release 2.7.4
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m15s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 12:30:31 +01:00
lzstealth f0177e6628 Release 2.7.3
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m15s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 11:43:07 +01:00
lzstealth 15dc6eb7f2 Release 2.7.2
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m16s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 23:51:38 +01:00
lzstealth 75b5cb5a6b Add player keyboard controls and release 2.7.1
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m17s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 13:50:40 +01:00
lzstealth e7ec276317 Release v2.7.0
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m18s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 33s
2026-08-14 13:36:47 +01:00
lzstealth 30f5ed11b8 Format scheduled task intervals
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m25s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 00:20:48 +01:00
lzstealth d6a8b45357 Fresh initial commit
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m12s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 30s
2026-08-12 02:41:31 +01:00
lzstealth f9425fc640 Release 2.6.25
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m12s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 30s
2026-08-10 01:04:49 +01:00
lzstealth 4491c15215 Release 2.6.24 2026-08-10 00:32:28 +01:00
lzstealth 08b06941a4 Adjust dashboard card spacing 2026-08-09 13:53:38 +01:00
lzstealth c0c05f76e3 Make API and RSS refresh notifications change-only 2026-08-09 13:44:17 +01:00
lzstealth 78a34e4105 Release 2.6.23 2026-08-09 13:38:30 +01:00
lzstealth 3c3864e6ac Sync build package versions 2026-08-09 13:06:55 +01:00
lzstealth 6d8bf0f5f0 Release v2.6.22 2026-08-09 13:06:02 +01:00
lzstealth c36b9122c9 Release v2.6.21 2026-08-09 12:30:22 +01:00
lzstealth 39f2098ffe Release v2.6.20 2026-08-09 12:18:44 +01:00
lzstealth 459f84ed94 Release v2.6.19 2026-08-09 11:57:40 +01:00
lzstealth 49c72923b4 Release 2.6.15 2026-08-08 23:15:04 +01:00
lzstealth 6c28a1c028 Release 2.6.14 2026-08-08 21:49:22 +01:00
lzstealth c5172af62d Release 2.6.13 2026-08-08 21:11:34 +01:00
lzstealth cd8e333afd Restore Docker tag fan-out 2026-08-08 20:48:36 +01:00
lzstealth c3b5a0053c Split web and player build artifacts 2026-08-08 20:38:44 +01:00
lzstealth 38565a533d Wire remote player reconnect delay 2026-08-08 16:29:38 +01:00
lzstealth 5a08ccddbb Release v2.6.11 2026-08-08 15:11:11 +01:00
lzstealth 2c97fe81d1 Release v2.6.10 2026-08-08 14:14:52 +01:00
lzstealth ee3b1b51bf Release v2.6.9 2026-08-08 14:08:16 +01:00
lzstealth 4e5a1bc393 Release 2.6.8 2026-08-08 13:18:52 +01:00
lzstealth 7e46fffc34 Release 2.6.7 2026-08-08 13:02:31 +01:00
lzstealth b20beb250b update env files 2026-08-08 00:13:23 +01:00
lzstealth 9d93634382 Readme, addition of changelog. 2026-08-08 00:09:56 +01:00
lzstealth 3cba68e256 Fix compose network service placement 2026-08-08 00:05:09 +01:00
lzstealth bcae4bb318 Add timetable end-time validation 2026-08-08 00:00:51 +01:00
lzstealth 0b300d6ddb Update gitignore 2026-08-07 22:52:03 +01:00
lzstealth 1101ffac34 Ignore leaked compose env files 2026-08-07 22:47:43 +01:00
lzstealth 7e758ecca8 Merge branch 'feature/player-agent-control-plane' 2026-08-07 22:42:03 +01:00
lzstealth 2bd47fb96a Add player control-plane and dashboard updates 2026-08-07 22:35:27 +01:00
lzstealth 0801c119ae Add player control-plane and dashboard updates 2026-08-07 22:23:46 +01:00
lzstealth 433be06bc7 Refine player control-plane flow 2026-08-07 13:10:16 +01:00
lzstealth 74318eb34e Add multi-player and remote bridge support 2026-08-07 02:58:18 +01:00
lzstealth a4f8a807ff Add kiosk launcher downloads and player URL resolution 2026-08-06 18:51:33 +01:00
lzstealth 59730837ad Release 2.5.13 2026-08-05 22:30:03 +01:00
lzstealth 4c459e2745 Release v2.5.12 2026-08-05 22:24:08 +01:00
lzstealth b9dd4178c4 Apply remaining changes 2026-08-05 21:57:16 +01:00
lzstealth a6a5d71ef0 Release v2.5.11 2026-08-05 21:56:46 +01:00
lzstealth c55c3d2baf Release v2.5.10 2026-08-05 21:25:02 +01:00
lzstealth d3e059a878 Release v2.5.9 2026-08-05 21:05:43 +01:00
lzstealth 38d82d2ac6 Fix QR background gradient handling 2026-08-05 19:51:54 +01:00
lzstealth 9f831f04bc Release v2.5.6 2026-08-05 19:38:16 +01:00
lzstealth a8ef35b287 Fix dashboard test bootstrap 2026-08-03 21:21:54 +01:00
lzstealth a45552fed3 Release v2.5.4 2026-08-03 21:20:54 +01:00
lzstealth a5e8ecb21f Release v2.5.3 2026-08-03 20:04:43 +01:00
338 changed files with 32568 additions and 4618 deletions
+5
View File
@@ -1,4 +1,9 @@
*
!package.json
!package-lock.json
!build/
!build/**
!src/
!src/**
!scripts/
!scripts/**
-18
View File
@@ -1,18 +0,0 @@
PULSE_SIGNAGE_IMAGE=git.lzstealth.com/lzstealth/pulse-signage:latest
PULSE_SIGNAGE_SHARED_SECRET=
DB_HOST=mysql
DB_PORT=3306
DB_NAME=pulse-signage
DB_USER=pulse-signage
DB_PASSWORD=signage_password
MYSQL_ROOT_PASSWORD=root_password
PLAYER_PUBLIC_BASE_URL=http://localhost:8081
PLAYER_INTERNAL_BASE_URL=http://player:8081
SESSION_MAX_AGE_DAYS=14
DEFAULT_ADMIN_USERNAME=admin
DEFAULT_ADMIN_NAME=Admin
DEFAULT_ADMIN_PASSWORD=admin
PASSWORD_HASH_ITERATIONS=310000
+3
View File
@@ -3,6 +3,9 @@
## Versioning and releases
- Treat `package.json` as the source of truth for the application version.
- Keep `package.json`, `build/package.player.json`, and `build/package.web.json` on the same version number.
- Keep dependency versions and package metadata in `package.json`, `package-lock.json`, `build/package.player.json`, and `build/package.web.json` aligned unless a dependency is intentionally omitted from a specific bundle.
- When changing bundled library versions, update the About page source data from the same package metadata or vendored asset banner rather than hardcoding a fresh literal.
- When the app version changes, update `CHANGELOG.md` in the same change.
- Keep database migration versions aligned with the release they actually belong to.
- If only part of a migration batch belongs to a newer release, split that batch into a separate migration entry instead of relabeling the earlier release.
+17 -5
View File
@@ -7,9 +7,20 @@ on:
workflow_dispatch:
jobs:
build-and-push:
build-and-push-existing-registry:
runs-on: ubuntu-latest
strategy:
fail-fast: false
matrix:
include:
- name: web
repository: pulse-signage-web
dockerfile: ./build/Dockerfile
- name: player
repository: pulse-signage-player
dockerfile: ./build/Dockerfile.player
steps:
- name: Checkout repository
uses: actions/checkout@v4
@@ -17,7 +28,7 @@ jobs:
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Log in to container registry
- name: Log in to existing package registry
uses: docker/login-action@v3
with:
registry: git.lzstealth.com
@@ -28,18 +39,19 @@ jobs:
id: meta
uses: docker/metadata-action@v5
with:
images: git.lzstealth.com/LZStealth/pulse-signage
images: |
git.lzstealth.com/lzstealth/${{ matrix.repository }}
tags: |
type=raw,value=latest
type=ref,event=tag
type=semver,pattern=v{{major}}.{{minor}}
type=semver,pattern=v{{major}}
type=semver,pattern=v{{major}}.{{minor}}
- name: Build and push image
uses: docker/build-push-action@v6
with:
context: .
file: ./Dockerfile
file: ${{ matrix.dockerfile }}
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
+3
View File
@@ -3,6 +3,8 @@ media/
!src/web/lib/media/
!src/web/lib/media/**
docker-compose.dev.yml
/docker-compose/*.dev.yml
/docker-compose/*.env
/dev-demo-seed.js
.vscode/
.env
@@ -10,3 +12,4 @@ npm-debug.log*
yarn-debug.log*
yarn-error.log*
.DS_Store
TODO.md
+527
View File
@@ -2,6 +2,533 @@
All notable changes to this project will be documented in this file.
## 2.8.7 - 2026-08-22
### Added
- Added configurable JSON POST requests and two-step login-then-token authentication for API sources.
## 2.8.6 - 2026-08-18
### Fixed
- Added live URL validation with inline feedback and explicit HTTP or HTTPS scheme enforcement for URL fields.
- Prevented Enter in slide editor inputs from implicitly saving the slide.
- Collapsed nested API response JSON sections by default while keeping the root response visible.
## 2.8.5 - 2026-08-17
### Fixed
- Fixed thumbnail capture timing so video assets are ready before the preview canvas is captured.
- Replaced unavailable webpage thumbnails with a subdued placeholder while keeping live webpage previews intact.
## 2.8.4 - 2026-08-17
### Added
- Added local caching for API and RSS image placeholders under `player-cache/remote-images` for offline player playback.
- Added reconciliation of cached remote images so files no longer referenced by slides are removed.
### Fixed
- Fixed popup preview authentication for background thumbnail capture.
- Fixed thumbnails so they use the same popup-preview canvas and resolve API/RSS placeholders, fonts, styles, and cached images correctly.
- Fixed manual scheduled-task run notifications so they use task-neutral wording.
## 2.8.3 - 2026-08-17
### Added
- Added API, RSS, Timetable, and Time / Date placeholder help panels with shared transform and date-token documentation.
- Added render-time API and RSS image placeholders with proportional sizing and preview-only bounding boxes.
### Changed
- API and RSS regions now preserve authored content when no data source is selected and remain blank when a selected source has no authored content.
- Normal WYSIWYG image insertion remains upload-backed and separate from image placeholder transforms.
## 2.8.2 - 2026-08-16
### Changed
- Standardized update audit events on from/to changes and added readable table diffs for nested JSON, arrays, null values, and empty strings.
- Standardized internal `src/data` imports on the `#src` alias.
## 2.8.1 - 2026-08-16
### Fixed
- Prevented startup and runtime duplicate-key writes from consuming auto-increment values in permission, player, onboarding, settings, and relationship tables.
- Prevented partial timetable schemas from being incorrectly treated as fully migrated during schema version detection.
### Changed
- Renamed the built-in administrator role key to `super-admin`, while allowing its display name and description to be edited without being overwritten on restart.
## 2.8.0 - 2026-08-16
### Added
- Filtered audit-log CSV export with a dedicated `audit-log.export` permission.
- Canvas Sizes as an individual Content audit category.
- Audit events for slide, template, playlist, and screen changes.
- Audit events for System Settings changes.
- Administration audit events for user and role management.
- Audit logging enablement, category selection, and request metadata controls.
- The extensible audit event storage, retention setting, dedicated audit-log permission, and paginated viewer foundation.
- A Defaults settings section for player and announcement defaults.
- A configurable maximum active session limit that removes the oldest sessions first.
- IP address and user-agent metadata to active sessions.
- The option for users to sign out their other active sessions from My Account.
- Persistent administrator-controlled account locking and unlocking.
- Database-backed login rate limiting with configurable attempts, lockout duration, and tracking scope.
- A permissions-gated System Settings page for announcement icon suggestions, media upload limits and MIME types, session lifetime, and password-change policies.
- Configurable forced password changes for newly created users and administrator password resets.
- The database foundation for key-based application settings, including typed defaults and validation.
### Changed
- Updated the API and database documentation and added the Docker publish status badge to the project README.
- Renamed the audit export permission to `audit-log.allow`.
- Made Content and Data Sources audit categories opt-in and excluded automatic data-source refreshes from audit logging.
- Split Content audit logging into individual Slides, Templates, Playlists, Screens, and Announcements categories.
- Renamed the System Settings audit category key from `settings` to `system-settings`.
- Split audit administration events into separate Users and Roles categories.
- Split RSS and API data-source refresh defaults.
- Made the default announcement duration use a value and unit selector, matching announcement forms.
- Replaced password strength presets with customizable length, category, and character requirements.
- Session expiration now uses the configured system setting, and user and role administration is grouped under the Settings area.
- Renamed the system settings permissions to the `system-settings.*` namespace and migrated existing role assignments.
- Added numeric auto-increment identifiers to every table and retained natural or relationship keys as unique constraints.
## 2.7.6 - 2026-08-15
### Changed
- The announcement icon picker now supports searching the full Bootstrap Icons catalog while still showing the curated suggestion set by default.
### Fixed
- The announcement Play/Stop button now refreshes after saving screen-group changes, so Play stays disabled until the announcement actually has targets again.
## 2.7.5 - 2026-08-15
### Changed
- The About page now reads bundled library versions from package metadata and the vendored AdminLTE stylesheet.
- AdminLTE is now reported as 4.3.1.
- Animate.css is now reported as 4.1.1.
- Bootstrap Icons is now reported as 1.13.1.
- Cropper.js is now reported as 1.6.2.
- Express is now reported as 5.2.1.
- Handlebars is now reported as 4.7.8.
- hls.js is now reported as 1.7.0.
- Multer is now reported as 2.2.0.
- MySQL2 is now reported as 3.23.3.
- Sharp is now reported as 0.35.3.
- TinyMCE is now reported from the vendored package metadata.
- ws is now reported as 8.21.3.
- The runtime and container images now target Node.js 26.
## 2.7.4 - 2026-08-15
### Added
- A new About page.
### Changed
- Refreshed the vendored AdminLTE assets to 4.3.1.
## 2.7.3 - 2026-08-15
### Changed
- The slide image cropper now warns that SVG and GIF files will be rasterized if they are edited, and it keeps the original file only when the full image remains selected.
- The slide image upload flow now accepts PNG, JPG, GIF, WebP, and SVG images, while the WYSIWYG image uploader now matches that same allowlist.
- TIFF is no longer accepted by the WYSIWYG image uploader.
### Fixed
- The player now preserves quoted custom font-family values from rich text content, so fonts with spaces such as Old London render correctly on screens.
## 2.7.2 - 2026-08-14
### Fixed
- HTML and webpage region previews now normalize object-shaped content before rendering, so the player, thumbnails, and popup preview show the intended iframe content instead of leaking raw objects.
- HTML and webpage preview iframes now size explicitly to the full region bounds in the player, thumbnails, and popup preview.
## 2.7.1 - 2026-08-14
### Changed
- The player page now supports keyboard navigation with arrow keys to move between slides.
## 2.7.0 - 2026-08-14
### Added
- The WYSIWYG editor now supports adding small images.
### Changed
- The WYSIWYG image insertion flow also received a small code cleanup to simplify the related helper logic.
- The default table formatting has been applied.
- Timetable regions now use the renamed helpers end to end in the editor and player, including timezone-aware rendering for timetable entry placeholders.
## 2.6.27 - 2026-08-14
### Fixed
- Scheduled task intervals now display the most appropriate exact unit, such as seconds, minutes, hours, or days, while keeping the sort order numeric.
## 2.6.26 - 2026-08-10
### Changed
- API sources and RSS feeds now accept hours as an update interval unit, and the list and background task scheduling paths now format and convert that unit correctly.
## 2.6.25 - 2026-08-10
### Fixed
- Screen group edit now keeps the slug locked after creation, so existing screen group URLs remain stable.
## 2.6.24 - 2026-08-10
### Fixed
- Deferred playlist updates now keep the current slide index when the next playlist snapshot is applied, so playback no longer jumps back to the first slide mid-cycle.
## 2.6.23 - 2026-08-09
### Fixed
- Dashboard quick-action and kiosk-launcher cards now use row spacing instead of extra card padding, so the layout stays consistent at large widths.
- API and RSS refresh jobs now notify affected player screens only when the refreshed data actually changes, so unchanged polls no longer trigger redundant player refreshes.
## 2.6.22 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether pending migrations exist.
### Fixed
- Direct-to-URL player sessions now generate and persist a stable onboarding device id in session storage, so connected screens can still be moved and renamed independently without going through the onboarding flow first.
- The connected-clients move action now tolerates rows that only have a live connection id, which keeps move operations working for screens that skipped onboarding.
## 2.6.21 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether migrations are required.
- The schema documentation now reflects the timetable table rename, the new `o_app_state` table, and startup version tracking.
- Timetable timezone placeholders now use `tz` for the short zone name and `tz_long` for the full IANA zone.
## 2.6.20 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether migrations are required.
## 2.6.19 - 2026-08-09
### Changed
- Timetable editor helpers, routes, and table layout now use timetable-specific naming and tighter card/table styling.
- Connected clients now sort by client identity fields instead of the old IP-based ordering assumption.
## 2.6.18 - 2026-08-09
### Changed
- Timetable tables were renamed from the old `schedule` names to `timetable` names, and existing databases now rename those tables during migration.
- The timetable group editor now uses timetable-specific naming in its shared helpers and keeps the entries table aligned with the standard admin card/table layout.
## 2.6.17 - 2026-08-09
### Changed
- Existing timetable groups and entries are now migrated to Europe/London, and timetable dates are rewritten to UTC using that source timezone so the wall-clock meaning stays intact.
### Fixed
- New timetable groups now default to Europe/London so the timetable editor and saved data start from the same timezone assumption as the migrated rows.
## 2.6.16 - 2026-08-09
### Changed
- Timetable groups now store an IANA time zone and render their entry datetimes in that timetable time zone, so schedules keep the same wall-clock meaning when they are edited from another country.
### Fixed
- Timetable entry date inputs now round-trip through the timetable time zone instead of the browser locale, so saving from Florida while targeting Germany keeps the intended local times.
## 2.6.15 - 2026-08-08
### Fixed
- Slide update media sync on the player now removes uploads that were removed from the slide, so player storage stays aligned with the current slide content.
- Routine player and player-bridge media upload/delete logs were removed to keep remote player and bridge operation quieter.
- Background task descriptions no longer repeat the player slug when the task key already ends with that player name.
## 2.6.14 - 2026-08-08
### Fixed
- Slide updates and template deletes now fan out media sync work across all live players instead of targeting only one player.
## 2.6.13 - 2026-08-08
### Fixed
- The player bundle now keeps the browser-only QR export dependencies lazy-loaded, so the remote player image no longer needs `puppeteer-core` or `@sparticuz/chromium` at startup.
- Remote player startup sync now falls back to `WEB_INTERNAL_URL` when it is configured, which avoids 404s when the bridge is not the correct sync target.
- The player startup sync and media-write info logs were removed to keep normal remote-player operation quieter.
## 2.6.12 - 2026-08-08
### Fixed
- The Docker build inputs now live under `build/`, with separate web and player package manifests so the player image no longer carries the web browser tooling bundle.
- The Docker publish workflow now restores `v2` and `v2.2` style image tags alongside `latest` and the full release tag.
- Remote player sync and upload routing now carry the exact connected player device id through the bridge, so startup media and font jobs target the correct player instance in split-device deployments.
- Player websocket registration now learns the public base URL from the actual screen request origin, so localhost and 127.0.0.1 aliases both keep websocket commands working.
## 2.6.11 - 2026-08-08
### Fixed
- Role edits now save selected permissions from the shared RBAC form, so changes on the role page persist when you submit the form.
- RBAC permission sections now stay open independently in the accordion, so opening one section no longer closes the others.
## 2.6.10 - 2026-08-08
### Fixed
- The onboarding landing page and form no longer restore a previously selected screen, so the screen picker always starts clean while still keeping the saved client name.
## 2.6.9 - 2026-08-08
### Fixed
- The connected-clients view no longer exposes or sorts by client IP, so the table stays focused on the player identity, screen, and playback state.
- The connected-clients dashboard row renderer now keeps the actions column aligned after removing the IP column, so row updates no longer append a duplicate actions cell.
## 2.6.8 - 2026-08-08
### Fixed
- The screen-group command buttons stay disabled until a real target group is selected, so the placeholder "Select Screen Group" state cannot send commands.
## 2.6.7 - 2026-08-08
### Fixed
- Admin client commands now stay on the bridge for remote players, so screen control no longer depends on a public player address.
- The connected-clients screen-group controls now use the same async bulk-command path as the dashboard, including the All Screens option and live pause/blackout toggles.
## 2.6.6 - 2026-08-07
### Fixed
- Timetable entry editing now validates end times locally, requires the end to be at least one minute after the start, and highlights the end field when the value is invalid.
## 2.6.5 - 2026-08-07
### Added
- Multiple players are now supported across the player registry, dashboard snapshots, and screen group management, so a deployment can track more than one connected player at a time.
- The player-agent can now run remotely, which lets a player connect through the bridge instead of requiring everything to stay on the same host.
- The Docker Compose setup now includes a public stack with a player bridge service and a separate remote player stack, so local and split-device deployments share the same documented layout.
- Dedicated local and remote compose manifests now live at `docker-compose/docker-compose.yml` and `docker-compose/docker-compose.remote.yml`, with matching example env files for the two deployment modes.
- Admin client commands now have a dedicated route and test coverage, which keeps dashboard actions aligned with the current player control-plane flow.
### Changed
- Screen group views now show each registered player's public base URL and computed player URL on the edit screen instead of assuming a single local player.
- The dashboard status indicator now reports the connected player count, which makes the live feed status more explicit when several players are online.
- Player command dispatch, playlist playback, and render preloading were tightened so the player keeps using the active web base URL and can warm assets before the slide is shown.
- Playlist video-duration selection now uses the longest matching video region when a slide contains more than one video region.
- Media sync, font sync, and upload sync now follow the newer player-agent workflow, keeping background tasks and dashboard refreshes consistent with split-device deployments.
- The onboarding landing page now shows a built-in QR placeholder and falls back to it when the QR request fails, so the screen never starts blank.
- Upload sync now resolves the player internal base URL once per batch and reuses it for queued upload and delete operations, keeping mirrored media writes pointed at the active player endpoint.
- The connected clients list now defaults to client name, then IP address, so rows stay in a stable order when connection details change.
### Fixed
- Connected clients search results now keep the row action column, because the row template resolves `currentUser` from the parent view context while rendering inside the `clients` loop.
- The move-client modal now carries the row's player base URL through to the redirect step, so clients move correctly even when local and bridge-backed players are mixed.
- Paginated table cards now only apply their minimum height when the table content would otherwise exceed that threshold, which keeps short result sets compact in smaller browser windows.
## 2.6.4 - 2026-08-07
### Fixed
- The screen table no longer stores a player foreign key, and screen/player URLs now resolve from the current player registration instead of a screen assignment.
## 2.6.3 - 2026-08-07
### Fixed
- The screen table no longer enforces a foreign key to the player table, which keeps player assignments flexible while preserving the existing screen schema.
## 2.6.2 - 2026-08-07
### Fixed
- The player registry now upgrades to an integer player id with a separate player identifier so the schema migration can complete cleanly on existing databases.
- Dashboard screen lookups now tolerate the upgraded player table layout during the rollout.
## 2.6.1 - 2026-08-06
### Fixed
### Changed
- The web side now resolves the player base URL from the database-backed player registration record instead of depending on a web-container environment fallback.
- Player registrations now store a separate friendly identifier, so a player can keep the same device key while showing a label like `Shop2`.
## 2.5.14 - 2026-08-06
### Added
- Added branded Windows and Linux kiosk launcher downloads on the dashboard, with updated copy that explains the launcher behavior more clearly.
- Kiosk launchers now start the browser in kiosk mode, suppress notifications for Chromium-based browsers, and use the correct Firefox kiosk flag.
## 2.5.13 - 2026-08-05
### Fixed
- Slide and template save forms now allow larger multipart text fields, so rich region content no longer trips Multer's default field-value limit.
## 2.5.12 - 2026-08-05
### Fixed
- The auth route test now loads the alias bootstrap before the login flow, so isolated test runs do not depend on prior module initialization.
- The slide editor now blocks pasted data images in TinyMCE so image content must come through the upload flow.
## 2.5.11 - 2026-08-05
### Fixed
- Single-slide playlists now re-render the active slide immediately when a refresh arrives, instead of waiting for a transition that never happens.
- Playlist create and update flows now redirect to the canonical `/playlists/:id/edit` path after saving.
- Slide preview popups now keep rich-text spacing and line height consistent with the editor preview.
## 2.5.10 - 2026-08-05
### Fixed
- Slide editor rich-text updates now keep the hidden field and preview state in sync after inline formatting actions.
## 2.5.9 - 2026-08-05
### Fixed
- Screen playlist refreshes now wait until the next slide transition before applying a pending update, so one-slide playlists do not swap immediately during a refresh.
- Playlist rows now show the mute control for any playable media region, including RTMP slides, instead of only video regions.
## 2.5.8 - 2026-08-05
### Fixed
- MariaDB migrations now retry alternate foreign-key constraint names when screen-to-player constraint creation reports a duplicate-key error.
## 2.5.7 - 2026-08-05
### Fixed
- QR template backgrounds now use a single solid color only, and the editor no longer exposes a background gradient mode.
## 2.5.6 - 2026-08-05
### Added
- Onboarding QR rendering now uses the vendored `qr-code-styling` library directly, with a wider quiet zone and extra frame padding so the code does not clip at the corners.
### Changed
- The shared QR helper now renders `qr-code-styling` in Node without the old `qrcode` or `qrcode-generator` packages.
- The onboarding QR endpoint now generates the styled QR at request time, and the player onboarding page requests it only after confirming the player is not already onboarded.
- Playlist QR preview backfill now uses the same styled QR helper as onboarding, so playlist snapshots and generated previews stay consistent.
- The onboarding QR layout now keeps the code inset within its frame so the corners have more breathing room.
## 2.5.5 - 2026-08-04
### Added
- A shared Dupe flow was added to most admin create pages and list views, including roles, users, playlists, slides, templates, canvas sizes, announcements, and supported data sources.
### Changed
- RBAC roles now include a Dupe action that opens a copy-on-create flow with the selected permissions already populated.
- Users now include a Dupe action that opens the add-user form with the copied name and roles, while leaving the username blank for a new login.
- User usernames are now editable from the admin users section, while the personal account password page remains unchanged.
- The users form now allows creating an account without assigning any roles.
- Save and New on the users form now returns to the blank create page instead of falling back to the list.
- Password updates now accept a slightly lighter policy of 10 characters with 3 of 4 character classes, and the account and user password forms now describe the updated requirement.
- The slide rich-text editor now groups underline, strikethrough, subscript, and superscript into a single split-button control, with the main button using the underline icon and the dropdown exposing the other text-format actions.
- Chip formatting in the slide rich-text editor now uses a reusable inline-format helper so the chip action continues to sync and mark the editor as edited when applied.
- RSS, API, and timetable placeholder help text now uses the same transform examples, spacing, and typography as the timetable version, with the hint shown after the visible placeholders and before any overflow disclosure.
### Fixed
- Cells and inputs now enforce route-specific character limits on the form itself and on the matching save paths, so overlong values no longer fail at submit time.
- Playlist rows now use a grip drag handle with separate up/down move controls, and the drag grip cursor now changes to grab and grabbing on hover and drag.
- Playlist duration inputs now respect a min-only limit correctly, so the shared limiter no longer coerces values down to 0 when no max attribute is present.
- Playlist row video and mute toggles now use the correct filled/outline Bootstrap button styles for their current state without relying on the `active` class.
- Slides table search now only matches slide titles and template names, and no longer searches within slide content.
- Banner marquee text now measures its real cycle width so top-banner and lower-third announcements loop continuously instead of resetting from a fixed start position.
- Slide editor template selection now stays editable on blank slides until the user makes a real content edit, so TinyMCE hydration no longer locks the canvas immediately.
- Slide editor region cards now share a common header shell, so the image and video chips stay aligned with the other region types on the Video Webpage and HTML RTMP pages.
- Firefox preview popup now centers the preview canvas in normal layout flow and scales from the center, so the popup preview lines up correctly in Chrome and Firefox.
- Canvas size edits now keep the width and height fields locked while the size is in use, and oversized canvas dimensions are rejected at 16384 instead of reaching the save path.
- Schedule rules now start collapsed by default, use the built-in card collapse behavior, and keep validation messages visible without re-highlighting empty paired inputs.
- Timetable group deletes now scan slide content for the actual `timetable_group_id` field, so groups that are still referenced by slides stay protected from deletion.
- Timetable add and edit pages now keep cancel confirmation tied to timetable entry edits, so changes inside the entries table are treated as unsaved form changes.
- Screen add and edit pages now keep the Player URL box in a stable two-column layout, so switching between the forms no longer causes the page to jump or shift.
- Screen add pages now show the secondary Save and Close / Save and New actions, and screen edit delete actions now prompt for confirmation before removing the screen.
- Admin user password resets now keep the selected user in view by returning to that user's edit page after saving.
- Account password saves now refresh the page after the success toast is queued so the confirmation message stays visible.
- Shared toast handling now preserves a pending success message across the redirect so refreshes do not drop the confirmation banner.
- Announcement create and edit pages now keep the save action buttons visible, and the edit-page delete action now prompts for confirmation before deleting.
- Active announcements are now blocked from deletion with a clearer edit-page message that explains why.
- Slide template create now shows the background image remove button and clear flag, matching the edit page behavior.
- Template create now exposes Save & Close and Save & New actions, and template edit delete actions now use the shared action-button helper with a confirmation prompt instead of a separate hidden form.
- The advanced animation modal now shows intro, outro, and loop durations as 1-200% fields, with 100% saving back as 1000ms.
- The advanced animation modal now hard-limits repeat counts to 999 so attention-seeker animations cannot be configured with unbounded loops.
- Template editor region boxes now rerender when the canvas or stage resizes, and region width/height changes now keep the lock ratio, stay within the canvas, and shift back on-canvas instead of spilling over.
- Background tasks and scheduled tasks now render timestamps in 24-hour format, and the background task queue keeps a confirmation prompt before clearing finished items.
## 2.5.4 - 2026-08-03
### Changed
- The API source bearer token field now uses a password input with a right-side toggle to show or hide the token.
### Fixed
- QR code regions now render at the correct size in the slide editor preview, and the QR chip header now matches the other region cards.
- The dashboard onboarding link now uses the player public base URL stored in the database instead of a `/screen/...` URL.
## 2.5.3 - 2026-08-03
### Changed
- The user edit page delete action now shows a confirmation prompt before removing an account.
### Fixed
- Schedule modal cancel now restores the original rule set instead of keeping edits made after the modal opened.
## 2.5.2 - 2026-08-03
### Changed
-19
View File
@@ -1,19 +0,0 @@
FROM node:24-alpine
WORKDIR /app
RUN apk add --no-cache ffmpeg chromium nss freetype harfbuzz ttf-freefont
COPY package*.json ./
RUN npm install --omit=dev --no-audit --no-fund
COPY src ./src
RUN mkdir -p /app/src/web/public/vendor/animate.css && cp /app/node_modules/animate.css/animate.min.css /app/src/web/public/vendor/animate.css/animate.min.css
RUN mkdir -p /app/src/player/public/vendor/animate.css && cp /app/node_modules/animate.css/animate.min.css /app/src/player/public/vendor/animate.css/animate.min.css
RUN mkdir -p /app/media
EXPOSE 3000
CMD ["npm", "run", "start:web"]
+26 -66
View File
@@ -1,81 +1,41 @@
# Pulse Signage
Pulse Signage is a self-hosted digital signage platform built for teams that want clear, flexible control over what appears on every screen.
[![Publish Docker Image](https://git.lzstealth.com/lzstealth/pulse-signage/actions/workflows/docker-publish.yml/badge.svg?branch=main)](https://git.lzstealth.com/lzstealth/pulse-signage/actions?workflow=docker-publish.yml)
It gives you one place to manage playlists, slides, templates, screen assignments, announcements, data-driven content, and live player control without handing that workflow to a third-party service.
Pulse Signage is a self-hosted digital signage platform for teams that want clear, reliable control over the content on every screen.
## Why It Stands Out
It gives you one place to publish playlists, slides, announcements, and live updates without handing the workflow to a third-party service.
- Keep signage under your own control.
- Build polished screen experiences with reusable templates and playlists.
- Push announcements, schedules, RSS feeds, API content, and other dynamic content to screens.
- See what is live, what is queued, and what needs attention from a single admin dashboard.
- Use the same system for everyday signage, timed messages, and more structured information displays.
## What It Can Do
## What It Handles
- Run polished screen experiences with playlists, slides, and reusable templates.
- Keep announcements, schedules, RSS feeds, API content, and other live data in sync.
- Manage many screens from a single dashboard.
- Support everyday signage, event messages, lobbies, dashboards, and other always-on displays.
- Keep the player, dashboard, and bridge connected so updates move quickly and consistently.
- Screens and playlist assignments.
- Slides, templates, and canvas sizes.
- Announcements and screen-specific targeting.
- RSS feeds, API sources, and schedule-based content.
- Roles and permissions for admin access.
- Background tasks and scheduled refresh jobs.
- Player onboarding and live playback control.
## Why It Fits
## Simple Deployment
- It keeps signage under your own control.
- It is built for teams that need screens to stay current without extra manual work.
- It works well for offices, venues, campuses, and operations teams.
- It stays focused on display management instead of trying to be a general-purpose CMS.
Pulse Signage ships with a Docker Compose stack for the published image:
## Deploying
- Published-image stack: `docker compose -f docker-compose.yml up -d`
Docker Compose is the recommended way to deploy Pulse Signage. It keeps the web app, player, bridge, and database together in a predictable setup.
Use this stack when you want to run the tagged image instead of building from source.
If you want the details, start with the [Compose guide](docker-compose/README.md).
## Environment File
## Docs
The compose files read from a root `.env` file. Start by copying `.env.example` to `.env`, then adjust the values for your setup.
- [Documentation home](docs/README.md) - the technical reference index.
- [API reference](docs/api.md) - the player HTTP surface and onboarding endpoints.
- [Database schema](docs/schema.md) - the tables and data model the app maintains.
- [WebSocket reference](docs/websocket.md) - the live player and snapshot channels.
- [Compose guide](docker-compose/README.md) - deployment options and service layout.
- [Changelog](CHANGELOG.md) - release history and notable changes.
The variables are split by who uses them:
## Explore The Docs
Shared across the stack:
- `PULSE_SIGNAGE_IMAGE`
- `PULSE_SIGNAGE_SHARED_SECRET`
Web container:
- `SESSION_MAX_AGE_DAYS`
- `DEFAULT_ADMIN_USERNAME`
- `DEFAULT_ADMIN_NAME`
- `DEFAULT_ADMIN_PASSWORD`
- `PASSWORD_HASH_ITERATIONS`
Player container:
- `PLAYER_PUBLIC_BASE_URL`
- `PLAYER_INTERNAL_BASE_URL`
MySQL container:
- `DB_HOST`
- `DB_PORT`
- `DB_NAME`
- `DB_USER`
- `DB_PASSWORD`
- `MYSQL_ROOT_PASSWORD`
`DB_HOST`, `DB_PORT`, `DB_NAME`, `DB_USER`, and `DB_PASSWORD` are shared in practice because both app containers talk to the same database service.
`PLAYER_INTERNAL_BASE_URL` is used by the web side for server-to-player calls, while `PLAYER_PUBLIC_BASE_URL` is used for browser-facing player links.
## First-Time Use
The first startup seeds a default admin account if the database is empty.
- Username: `admin`
- Password: `admin`
## In Practice
Pulse Signage is designed to feel focused and reliable rather than heavy or noisy. It works well when you want a clean internal signage system for offices, venues, dashboards, or any environment where screens need to stay up to date without a lot of manual effort.
The player and admin pieces stay linked, so changes made in the dashboard can flow out to screens quickly and consistently.
The project includes a dashboard for managing content, a player runtime for rendering screens, an onboarding flow for connecting devices, and a bridge layer for remote screens. If you want to understand how the pieces fit together, the docs above cover the technical details without repeating the project overview.
+18
View File
@@ -0,0 +1,18 @@
FROM node:26-alpine
WORKDIR /app
RUN apk add --no-cache chromium nss freetype harfbuzz ttf-freefont
COPY build/package.web.json ./package.json
RUN npm install --omit=dev --no-audit --no-fund
COPY package-lock.json ./package-lock.json
COPY src ./src
COPY scripts ./scripts
RUN mkdir -p /app/media
EXPOSE 3000
CMD ["npm", "run", "start:web"]
+18
View File
@@ -0,0 +1,18 @@
FROM node:26-alpine
WORKDIR /app
RUN apk add --no-cache ffmpeg
COPY build/package.player.json ./package.json
RUN npm install --omit=dev --no-audit --no-fund
COPY package-lock.json ./package-lock.json
COPY src ./src
COPY scripts ./scripts
RUN mkdir -p /app/media
EXPOSE 3000
CMD ["npm", "run", "start:player"]
+22
View File
@@ -0,0 +1,22 @@
{
"name": "pulse-signage-player",
"version": "2.8.7",
"private": false,
"description": "Pulse Signage player application bundle",
"engines": {
"node": ">=26.0.0"
},
"main": "src/common.js",
"scripts": {
"start": "node -r dotenv/config src/player.js",
"start:player": "node -r dotenv/config src/player.js"
},
"dependencies": {
"dotenv": "^17.4.2",
"express": "^5.2.1",
"handlebars": "^4.7.8",
"hls.js": "^1.7.0",
"mysql2": "^3.23.3",
"ws": "^8.21.3"
}
}
+25
View File
@@ -0,0 +1,25 @@
{
"name": "pulse-signage-web",
"version": "2.8.7",
"private": false,
"description": "Pulse Signage web and bridge application bundle",
"engines": {
"node": ">=26.0.0"
},
"main": "src/common.js",
"scripts": {
"start": "node -r dotenv/config src/web.js",
"start:web": "node -r dotenv/config src/web.js"
},
"dependencies": {
"@sparticuz/chromium": "^149.0.0",
"dotenv": "^17.4.2",
"express": "^5.2.1",
"handlebars": "^4.7.8",
"multer": "^2.2.0",
"mysql2": "^3.23.3",
"puppeteer-core": "^25.7.0",
"sharp": "^0.35.3",
"ws": "^8.21.3"
}
}
-80
View File
@@ -1,80 +0,0 @@
services:
web:
image: ${PULSE_SIGNAGE_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage:latest}
restart: unless-stopped
ports:
- "8080:8080"
environment:
DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-signage}
DB_USER: ${DB_USER:-signage_user}
DB_PASSWORD: ${DB_PASSWORD:-signage_password}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
SESSION_MAX_AGE_DAYS: ${SESSION_MAX_AGE_DAYS:-14}
DASHBOARD_REFRESH_INTERVAL_MS: ${DASHBOARD_REFRESH_INTERVAL_MS:-2000}
DEFAULT_ADMIN_USERNAME: ${DEFAULT_ADMIN_USERNAME:-admin}
DEFAULT_ADMIN_NAME: ${DEFAULT_ADMIN_NAME:-Admin}
DEFAULT_ADMIN_PASSWORD: ${DEFAULT_ADMIN_PASSWORD:-admin}
PASSWORD_HASH_ITERATIONS: ${PASSWORD_HASH_ITERATIONS:-310000}
volumes:
- media:/app/media
command: ["node", "src/web.js"]
depends_on:
mysql:
condition: service_healthy
networks:
- pulse_signage
player:
image: ${PULSE_SIGNAGE_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage:latest}
restart: unless-stopped
ports:
- "8081:8081"
environment:
PLAYER_PUBLIC_BASE_URL: ${PLAYER_PUBLIC_BASE_URL:-http://localhost:8081}
PLAYER_INTERNAL_BASE_URL: ${PLAYER_INTERNAL_BASE_URL:-http://player:8081}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-signage}
DB_USER: ${DB_USER:-signage_user}
DB_PASSWORD: ${DB_PASSWORD:-signage_password}
volumes:
- media:/app/media
command: ["node", "src/player.js"]
depends_on:
mysql:
condition: service_healthy
networks:
- pulse_signage
mysql:
image: mysql:8.4
restart: unless-stopped
environment:
MYSQL_DATABASE: ${DB_NAME:-signage}
MYSQL_USER: ${DB_USER:-signage_user}
MYSQL_PASSWORD: ${DB_PASSWORD:-signage_password}
MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD:-root_password}
command:
- --character-set-server=utf8mb4
- --collation-server=utf8mb4_unicode_ci
volumes:
- mysql_data:/var/lib/mysql
healthcheck:
test: ["CMD-SHELL", "mysqladmin ping -h localhost -uroot -p$$MYSQL_ROOT_PASSWORD"]
interval: 10s
timeout: 5s
retries: 10
networks:
- pulse_signage
volumes:
mysql_data:
media:
networks:
pulse_signage:
name: pulse_signage
external: false
+26
View File
@@ -0,0 +1,26 @@
# Shared application settings
PULSE_SIGNAGE_WEB_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-web:latest"
PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest"
PULSE_SIGNAGE_SHARED_SECRET=""
# Database settings for the web, player, and bridge services
DB_HOST="mysql"
DB_PORT=3306
DB_NAME="pulse-signage"
DB_USER="pulse-signage"
DB_PASSWORD="signage_password"
MYSQL_ROOT_PASSWORD="root_password"
# Player settings
PLAYER_IDENTIFIER="player-local"
PLAYER_PUBLIC_URL="http://localhost:8081"
PLAYER_INTERNAL_URL="http://player:8081"
# Web app bootstrap settings
DEFAULT_ADMIN_USERNAME="admin"
DEFAULT_ADMIN_NAME="Admin"
DEFAULT_ADMIN_PASSWORD="password123!"
# Bridge settings for the player-bridge service
WEB_INTERNAL_URL="http://web:8080"
BRIDGE_INTERNAL_URL="http://player-bridge:8090"
+11
View File
@@ -0,0 +1,11 @@
# Shared application settings
PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest"
PULSE_SIGNAGE_SHARED_SECRET=""
# Player settings
PLAYER_IDENTIFIER="player-remote"
PLAYER_PUBLIC_URL="http://localhost:8081"
PLAYER_AGENT_RECONNECT_DELAY_MS=5000
# Remote player connectivity settings
BRIDGE_PUBLIC_URL="http://player-bridge.example.com:8090"
+228
View File
@@ -0,0 +1,228 @@
# Docker Compose Setup
This folder contains the Docker Compose definitions for Pulse Signage, including the public stack and the remote player stack.
## Files
- [docker-compose.yml](docker-compose.yml) - full public stack with web, player, player bridge, and MySQL.
- [.env.example](.env.example) - sample environment values for the public stack.
- [docker-compose.remote.yml](docker-compose.remote.yml) - remote player-only stack for machines that sit behind the player bridge.
- [.env.remote.example](.env.remote.example) - sample environment values for the remote stack.
## Stack Overview
### Public stack
The main compose stack is the most complete setup. It runs:
- `web` - the dashboard and admin app.
- `player` - the local screen player.
- `player-bridge` - the bridge service that proxies dashboard commands and player communication.
- `mysql` - the database used by the web, player, and bridge services.
This is the stack to use when you want the full app running on one machine.
### Remote player
The remote stack runs only the `player` service.
Use it when the player is installed on a remote device and connects back through the player bridge instead of running the full app separately.
## Services
### `web`
The dashboard and admin application.
Responsibilities:
- serves the web UI on port `8080`
- reads and writes application data from MySQL
- forwards player actions through the configured bridge base URL
- renders connected clients, dashboard pages, and admin workflows
Key configuration:
- `DB_HOST`, `DB_PORT`, `DB_NAME`, `DB_USER`, `DB_PASSWORD`
- `PULSE_SIGNAGE_SHARED_SECRET`
- `DEFAULT_ADMIN_USERNAME`
- `DEFAULT_ADMIN_NAME`
- `DEFAULT_ADMIN_PASSWORD`
- `PASSWORD_HASH_ITERATIONS`
### `player`
The screen runtime that renders playlists and receives commands.
Responsibilities:
- serves the player UI on port `8081`
- connects to MySQL in local mode
- connects to the bridge in remote mode through `BRIDGE_PUBLIC_URL`
- registers live connections and accepts control commands
Key configuration:
- `PLAYER_PUBLIC_URL`
- `PLAYER_INTERNAL_URL`
- `BRIDGE_INTERNAL_URL`
- `PLAYER_IDENTIFIER`
- `BRIDGE_PUBLIC_URL` in remote mode
- `PULSE_SIGNAGE_SHARED_SECRET`
- database settings in local mode
### `player-bridge`
The bridge layer that connects the dashboard to the player network.
Responsibilities:
- serves the bridge API on port `8090`
- forwards authenticated dashboard commands to registered players
- exposes screen connection snapshots and player registration data
- proxies command traffic between the web app and remote players
Key configuration:
- `PULSE_SIGNAGE_SHARED_SECRET`
- `WEB_INTERNAL_URL` for the bridge when it should call the web app directly instead of inferring from request headers
- `DB_HOST`, `DB_PORT`, `DB_NAME`, `DB_USER`, `DB_PASSWORD`
### `mysql`
The MySQL 8.4 database used by the public stack.
Responsibilities:
- stores application data, screen state, onboarding state, and registry records
- provides persistent storage through `mysql_data`
Key configuration:
- `MYSQL_DATABASE`
- `MYSQL_USER`
- `MYSQL_PASSWORD`
- `MYSQL_ROOT_PASSWORD`
## Environment Files
### `.env.example`
Use this file as a starting point for the public compose stack.
Important values:
- `PULSE_SIGNAGE_WEB_IMAGE` - image to run for the web app and bridge services, typically `.../pulse-signage-web:latest`
- `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run for the player services, typically `.../pulse-signage-player:latest`
- `PULSE_SIGNAGE_SHARED_SECRET` - long random secret shared by the web, player, and bridge services for authenticated requests
- `PLAYER_IDENTIFIER` - unique local player identifier
- `DB_*` - MySQL credentials and database name for the stack
- `PLAYER_PUBLIC_URL` - public URL the player advertises
- `PLAYER_INTERNAL_URL` - internal URL the web app uses for local player calls
- `BRIDGE_INTERNAL_URL` - bridge URL the web app uses for player snapshot and command forwarding
- `WEB_INTERNAL_URL` - internal URL the bridge uses to call the web app directly
- `DEFAULT_ADMIN_*` - bootstrap admin account values
- `PASSWORD_HASH_ITERATIONS` - password hashing cost
- `MYSQL_ROOT_PASSWORD` - root password for the local MySQL container
### `.env.remote.example`
Use this file on a remote player device.
Important values:
- `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run on the device, typically `.../pulse-signage-player:latest`
- `PULSE_SIGNAGE_SHARED_SECRET` - must match the public stack and should be the same long random value used everywhere in the deployment
- `PLAYER_IDENTIFIER` - unique remote player identifier
- `PLAYER_PUBLIC_URL` - public URL for the remote player
- `BRIDGE_PUBLIC_URL` - bridge URL the player connects back to
- `PLAYER_AGENT_RECONNECT_DELAY_MS` - reconnect delay for the player agent
### `PULSE_SIGNAGE_SHARED_SECRET`
This secret is the shared signing key for requests between the services. Use a single value for every service that needs to talk to the same stack, including the web app, player, bridge, and any remote player that connects back to that bridge.
Recommended shape:
- at least 32 random bytes
- ideally 64 hex characters, or another equally long cryptographically random string
- not a password, phrase, or anything human-readable
If you want a quick local value, generate one with a password manager or a command such as `openssl rand -hex 32`.
Leave it blank only if you intentionally want to run without request signing in a throwaway local setup.
## Main Configuration Variables
| Variable | Used By | Purpose |
| --- | --- | --- |
| `PULSE_SIGNAGE_WEB_IMAGE` | web, bridge | Docker image to run for the web app and bridge services. |
| `PULSE_SIGNAGE_PLAYER_IMAGE` | player, remote player | Docker image to run for the player services. |
| `PULSE_SIGNAGE_SHARED_SECRET` | web, player, bridge, remote player | Shared secret for authenticated requests between services. |
| `DB_HOST` | web, player, bridge | Database host name. |
| `DB_PORT` | web, player, bridge | Database port. |
| `DB_NAME` | web, player, bridge, mysql | Database name. |
| `DB_USER` | web, player, bridge, mysql | Database user. |
| `DB_PASSWORD` | web, player, bridge, mysql | Database password. |
| `MYSQL_ROOT_PASSWORD` | mysql | Root password for the local MySQL container. |
| `DEFAULT_ADMIN_USERNAME` | web | Bootstrap admin username. |
| `DEFAULT_ADMIN_NAME` | web | Bootstrap admin display name. |
| `DEFAULT_ADMIN_PASSWORD` | web | Bootstrap admin password. |
| `PASSWORD_HASH_ITERATIONS` | web | Password hashing cost. |
| `PLAYER_INTERNAL_URL` | web, player | Internal player URL used by the dashboard and player runtime. |
| `BRIDGE_INTERNAL_URL` | web | Bridge URL used by the web app for player snapshot and command forwarding. |
| `WEB_INTERNAL_URL` | player-bridge | Internal web URL used by the bridge to call the dashboard app directly. |
| `PLAYER_PUBLIC_URL` | player, remote player | Public URL advertised by the player. |
| `BRIDGE_PUBLIC_URL` | player, remote player | URL of the bridge service. |
| `PLAYER_IDENTIFIER` | player | Stable player identifier. |
| `PLAYER_AGENT_RECONNECT_DELAY_MS` | remote player | Delay before reconnecting to the bridge. |
| `MYSQL_DATABASE` | mysql | Database name used by the local MySQL container. |
| `MYSQL_USER` | mysql | Database user used by the local MySQL container. |
| `MYSQL_PASSWORD` | mysql | Database password used by the local MySQL container. |
## Ports
Public stack ports:
- `8080` - web dashboard
- `8081` - player
- `8090` - player bridge
- `3306` - MySQL
Remote stack ports:
- `8081` - player only
## Volumes
### Public stack
- `mysql_data` - persistent MySQL data.
- `pulse-signage` - shared media and cache volume for the app services.
### Remote stack
- `pulse-signage` - shared media and cache volume for the remote player.
## Networks
Each compose file creates its own named network:
- `pulse-signage` for the public stack
- `pulse-signage-remote` for remote player deployment.
## Notes
- The public stack expects the app services and MySQL to share the same `PULSE_SIGNAGE_SHARED_SECRET`.
- A remote player must use the same `PULSE_SIGNAGE_SHARED_SECRET` as the bridge it connects to.
- The bridge service is the dashboard-facing command path for connected remote players.
- The remote player should point `BRIDGE_PUBLIC_URL` at the bridge, not at the public web endpoint.
- The `PULSE_SIGNAGE_WEB_IMAGE` and `PULSE_SIGNAGE_PLAYER_IMAGE` tags default to the published `pulse-signage-web` and `pulse-signage-player` repositories with `latest` and `v1.2.3` style tags, but they can be overridden for local builds or custom releases.
## Recommended Setup
1. Copy `.env.example` to a local `.env` file for the public stack.
2. Copy `.env.remote.example` to a device-specific `.env` file for the remote player.
3. Make sure `PULSE_SIGNAGE_SHARED_SECRET` matches everywhere.
4. Start the public stack first, then start the remote player after the bridge is reachable.
5. Verify that the player appears in Connected clients before testing screen commands.
+28
View File
@@ -0,0 +1,28 @@
name: pulse-signage-remote
services:
player:
image: ${PULSE_SIGNAGE_PLAYER_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage-player:latest}
restart: unless-stopped
networks:
- pulse_signage
ports:
- "8081:8081"
environment:
PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-remote}
PLAYER_PUBLIC_URL: ${PLAYER_PUBLIC_URL:-http://localhost:8081}
BRIDGE_PUBLIC_URL: ${BRIDGE_PUBLIC_URL:-}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
PLAYER_AGENT_RECONNECT_DELAY_MS: ${PLAYER_AGENT_RECONNECT_DELAY_MS:-5000}
volumes:
- pulse-signage:/app/media
command: ["node", "src/player.js"]
volumes:
pulse-signage:
networks:
pulse_signage:
name: pulse-signage-remote
external: false
+103
View File
@@ -0,0 +1,103 @@
name: pulse-signage
services:
web:
image: ${PULSE_SIGNAGE_WEB_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage-web:latest}
restart: unless-stopped
networks:
- pulse_signage
ports:
- "8080:8080"
environment:
DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-pulse-signage}
DB_USER: ${DB_USER:-pulse-signage}
DB_PASSWORD: ${DB_PASSWORD:-signage_password}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
BRIDGE_INTERNAL_URL: ${BRIDGE_INTERNAL_URL:-http://player-bridge:8090}
DEFAULT_ADMIN_USERNAME: ${DEFAULT_ADMIN_USERNAME:-admin}
DEFAULT_ADMIN_NAME: ${DEFAULT_ADMIN_NAME:-Admin}
DEFAULT_ADMIN_PASSWORD: ${DEFAULT_ADMIN_PASSWORD:-password123}
volumes:
- pulse-signage:/app/media
command: ["node", "src/web.js"]
depends_on:
mysql:
condition: service_healthy
player:
image: ${PULSE_SIGNAGE_PLAYER_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage-player:latest}
restart: unless-stopped
networks:
- pulse_signage
ports:
- "8081:8081"
environment:
PLAYER_PUBLIC_URL: ${PLAYER_PUBLIC_URL:-http://localhost:8081}
PLAYER_INTERNAL_URL: ${PLAYER_INTERNAL_URL:-http://player:8081}
PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-local}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-pulse-signage}
DB_USER: ${DB_USER:-pulse-signage}
DB_PASSWORD: ${DB_PASSWORD:-signage_password}
volumes:
- pulse-signage:/app/media
command: ["node", "src/player.js"]
depends_on:
mysql:
condition: service_healthy
player-bridge:
image: ${PULSE_SIGNAGE_WEB_IMAGE:-git.lzstealth.com/lzstealth/pulse-signage-web:latest}
restart: unless-stopped
networks:
- pulse_signage
ports:
- "8090:8090"
environment:
WEB_INTERNAL_URL: ${WEB_INTERNAL_URL:-http://web:8080}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-pulse-signage}
DB_USER: ${DB_USER:-pulse-signage}
DB_PASSWORD: ${DB_PASSWORD:-signage_password}
command: ["node", "src/player-bridge/index.js"]
depends_on:
mysql:
condition: service_healthy
mysql:
image: mysql:8.4
restart: unless-stopped
ports:
- "3306:3306"
environment:
MYSQL_DATABASE: ${DB_NAME:-pulse-signage}
MYSQL_USER: ${DB_USER:-pulse-signage}
MYSQL_PASSWORD: ${DB_PASSWORD:-signage_password}
MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD:-root_password}
command:
- --character-set-server=utf8mb4
- --collation-server=utf8mb4_unicode_ci
volumes:
- mysql_data:/var/lib/mysql
healthcheck:
test: ["CMD-SHELL", "mysqladmin ping -h localhost -uroot -p$$MYSQL_ROOT_PASSWORD"]
interval: 10s
timeout: 5s
retries: 10
networks:
- pulse_signage
volumes:
mysql_data:
pulse-signage:
networks:
pulse_signage:
name: pulse-signage
external: false
+13
View File
@@ -0,0 +1,13 @@
# Documentation
This folder contains the technical reference material for Pulse Signage.
## Whats Here
- [API reference](api.md) - the player HTTP surface and onboarding endpoints.
- [Database schema](schema.md) - the tables and data model used by the app.
- [WebSocket reference](websocket.md) - the live player and snapshot channels.
## How To Read It
If you want the big picture first, start with the main [project README](../README.md). It gives a plain overview of what Pulse Signage does, while the pages in this folder explain how the pieces work.
+22 -6
View File
@@ -78,6 +78,11 @@ Response fields:
Returns the upload directory configured for the player service.
Access: internal-only.
Response fields:
- `mediaDir`
- `uploadDir`
### `PUT /api/media/{filename}`
Writes an uploaded file into the player upload directory.
Access: internal-only and write-protected behind your deployment boundary.
@@ -95,6 +100,14 @@ Query fields:
- `source` required
- `disableAudio` optional
Response fields:
- `key`
- `playlistUrl`
- `disableAudio`
- `ready`
- `live`
### `GET /api/rtmp/streams/{key}/index.m3u8`
Returns the RTMP session HLS manifest.
Access: internal-only.
@@ -114,6 +127,7 @@ Response fields:
- `slides`
- `rssFeeds`
- `apiSources`
- `timetableGroups`
- `revision`
### `GET /api/screens/{slug}/connections`
@@ -198,6 +212,7 @@ Response fields:
`GET /api/media/config` returns an object with:
- `mediaDir`
- `uploadDir`
### RTMP Session Response
@@ -208,6 +223,7 @@ Response fields:
- `playlistUrl`
- `disableAudio`
- `ready`
- `live`
### Onboarding Write Response
@@ -230,6 +246,7 @@ Response fields:
- `slides`
- `rssFeeds`
- `apiSources`
- `timetableGroups`
- `revision`
### Connections Response
@@ -269,6 +286,8 @@ Response fields:
- `id`
- `name`
- `fade_between_slides`
- `skip_unavailable_rtmp`
- `canvas_id`
### Slide
@@ -276,12 +295,9 @@ Response fields:
- `title`
- `body`
- `duration_seconds`
- `schedule_mode`
- `schedule_start_datetime`
- `schedule_end_datetime`
- `schedule_start_time`
- `schedule_end_time`
- `schedule_days_json`
- `use_video_duration`
- `disable_audio`
- `scheduleRules`
- `media_url`
- `media_type`
- `kind`
+77 -49
View File
@@ -3,7 +3,7 @@
This app creates and maintains its schema at startup through `src/db/index.js`.
The sections below summarize the current tables and their purpose.
Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_at` and `modified_at` when a table supports auditing.
Tables generally use a numeric auto-increment `id` primary key. The relationship table `d_announcement_screens` intentionally uses the composite `(announcement_id, screen_id)` primary key instead. Natural and relationship keys remain as unique constraints where needed. Timestamps are stored as `created_at` and `modified_at` when a table supports auditing.
## Admin
@@ -16,12 +16,13 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `a_users`
- `id`, `name`, `username`, `password_hash`, `password_salt`, `password_iterations`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `id`, `name`, `username`, `password_hash`, `password_salt`, `password_iterations`, `must_change_password`, `account_locked`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `username` is unique.
### `a_roles`
- `id`, `name`, `description`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `id`, `role_key`, `name`, `description`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `role_key` is unique.
- `name` is unique.
### `a_permissions`
@@ -31,24 +32,24 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `a_role_permissions`
- `role_id`, `permission_id`, `created_at`, `modified_at`
- `id`, `role_id`, `permission_id`, `created_at`, `modified_at`
- Foreign keys:
- `role_id` -> `a_roles.id`
- `permission_id` -> `a_permissions.id`
- Composite primary key: `(role_id, permission_id)`
- Unique key: `(role_id, permission_id)`
### `a_user_roles`
- `user_id`, `role_id`, `created_at`, `modified_at`
- `id`, `user_id`, `role_id`, `created_at`, `modified_at`
- Foreign keys:
- `user_id` -> `a_users.id`
- `role_id` -> `a_roles.id`
- Composite primary key: `(user_id, role_id)`
- Unique key: `(user_id, role_id)`
### `a_sessions`
- `session_hash`, `user_id`, `expires_at`, `created_at`, `created_by`, `last_used_at`, `modified_by`
- `session_hash` is the primary key.
- `id`, `session_hash`, `user_id`, `ip_address`, `user_agent`, `expires_at`, `created_at`, `created_by`, `last_used_at`, `modified_by`
- `session_hash` is unique.
- Foreign key:
- `user_id` -> `a_users.id`
@@ -93,7 +94,7 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `c_playlist_slides`
- `id`, `playlist_id`, `slide_id`, `position`, `duration_seconds`, `use_video_duration`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `id`, `playlist_id`, `slide_id`, `position`, `duration_seconds`, `use_video_duration`, `disable_audio`, `created_at`, `created_by`, `modified_at`, `modified_by`
- Foreign keys:
- `playlist_id` -> `c_playlists.id` with `ON DELETE CASCADE`
- `slide_id` -> `c_slides.id` with `ON DELETE CASCADE`
@@ -112,36 +113,40 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
## Devices
- `d_players` - player registry and connection metadata.
- `d_screens` - screen records and playlist/player assignment.
- `d_screens` - screen records and playlist assignment.
- `d_onboarding_devices` - device-to-screen bindings and onboarded client names.
### `d_players`
- `id`, `identifier`, `public_base_url`, `internal_base_url`, `last_seen_at`, `created_at`, `modified_at`
- `id` is the primary key.
- `identifier` is unique and is the stable player identity used by the app.
### `d_screens`
- `id`, `name`, `slug`, `playlist_id`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `slug` is unique.
- Foreign keys:
- `playlist_id` -> `c_playlists.id` with `ON DELETE SET NULL`
- Screens are no longer tied to a player foreign key directly; player registration and live connection metadata are tracked separately in `d_players`.
### `d_onboarding_devices`
- `id`, `device_id`, `client_name`, `screen_id`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `device_id` is unique.
- Foreign key:
- `screen_id` -> `d_screens.id` with `ON DELETE SET NULL`
## Onboarding
- The onboarding flow uses `d_onboarding_devices` to bind a device to a screen and persist the client name.
## Announcements
- `d_announcements` - announcement content and display metadata.
- `d_announcement_screens` - announcement-to-screen assignments.
### `d_players`
- `device_id`, `public_base_url`, `internal_base_url`, `last_seen_at`, `created_at`, `modified_at`
- `device_id` is the primary key.
### `d_screens`
- `id`, `name`, `slug`, `playlist_id`, `player_id`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `slug` is unique.
- Foreign keys:
- `playlist_id` -> `c_playlists.id` with `ON DELETE SET NULL`
- `player_id` -> `d_players.id` with `ON DELETE RESTRICT`
- `player_id` is required and defaults to `'1'` for the current singleton-player model.
### `d_onboarding_devices`
- `device_id`, `client_name`, `screen_id`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `device_id` is the primary key.
- Foreign key:
- `screen_id` -> `d_screens.id` with `ON DELETE SET NULL`
### `d_announcements`
- `id`, `message`, `short_label`, `announcement_type`, `color_key`, `icon_key`, `duration_seconds`, `expires_at`, `created_at`, `created_by`, `modified_at`, `modified_by`
@@ -153,19 +158,15 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
- Foreign keys:
- `announcement_id` -> `d_announcements.id` with `ON DELETE CASCADE`
- `screen_id` -> `d_screens.id` with `ON DELETE CASCADE`
- Composite primary key: `(announcement_id, screen_id)`
## Onboarding
- The onboarding flow uses `d_onboarding_devices` to bind a device to a screen and persist the client name.
- Unique key: `(announcement_id, screen_id)`
## Integrations
- `i_rss_feeds` - RSS feed definitions and refresh cadence.
- `i_rss_feed_items` - cached RSS feed items.
- `i_api_sources` - API source definitions and last response snapshot.
- `i_schedule_groups` - grouped schedule definitions used by the schedule region.
- `i_schedule_entries` - dated entries that belong to a schedule group.
- `i_timetable_groups` - grouped timetable definitions used by the timetable region.
- `i_timetable_entries` - dated entries that belong to a timetable group.
### `i_rss_feeds`
@@ -183,32 +184,53 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
- `id`, `name`, `api_url`, `auth_method`, `auth_username`, `auth_password`, `auth_bearer_token`, `auth_header_name`, `auth_header_value`, `items_path`, `update_interval_value`, `update_interval_unit`, `last_pulled_at`, `last_pull_error`, `last_response_status`, `last_response_content_type`, `last_response_json`, `created_at`, `created_by`, `modified_at`, `modified_by`
### `i_schedule_groups`
### `i_timetable_groups`
- `id`, `name`, `short_description`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `id`, `name`, `short_description`, `timezone`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `timezone` defaults to `Europe/London`.
### `i_schedule_entries`
### `i_timetable_entries`
- `id`, `schedule_group_id`, `title`, `short_description`, `start_datetime`, `end_datetime`, `created_at`, `created_by`, `modified_at`, `modified_by`
- Foreign key:
- `schedule_group_id` -> `i_schedule_groups.id` with `ON DELETE CASCADE`
- `schedule_group_id` -> `i_timetable_groups.id` with `ON DELETE CASCADE`
- Index:
- `(schedule_group_id, start_datetime)`
## Operations
- `o_background_tasks` - queue and history for background jobs.
- `o_app_state` - generic app state and version markers stored as key/value pairs.
- `o_app_settings` - administrator-configurable application settings stored by key.
- `o_audit_events` - retained audit events for administrator activity and system changes.
### `o_background_tasks`
- `id`, `task_key`, `task_type`, `title`, `category`, `status`, `payload_json`, `metadata_json`, `attempts`, `created_at`, `created_by`, `started_at`, `finished_at`, `error_message`
- Indexed by `status`, `task_key`, and `task_type`.
### `o_app_state`
- `id`, `state_key`, `state_value`, `created_at`, `modified_at`
- `state_key` is unique.
- `schema_version` is stored here so startup can detect the previously recorded schema version before deciding whether migrations need to run.
### `o_app_settings`
- `id`, `setting_key`, `setting_value`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `setting_key` is unique.
- Values are stored as JSON and validated against the application setting definitions in `src/data/app-settings.js`.
### `o_audit_events`
- `id`, `occurred_at`, `category`, `event_type`, `actor_user_id`, `target_type`, `target_id`, `target_label`, `ip_address`, `user_agent`, `details_json`
- Indexed by occurrence time, category and event type, actor, and target.
## Notes
- The schema is initialized with `CREATE TABLE IF NOT EXISTS`, so new installs can start from an empty database.
- `src/db/bootstrap.js` seeds the canvas size defaults, default permissions, and the default administrator role.
- The migration module stays in place for future releases, but this version treats the current schema as the install baseline.
- `src/db/migrations.js` records the current schema version in `o_app_state` during startup so later launches can tell whether an update is happening.
```mermaid
erDiagram
@@ -254,18 +276,25 @@ erDiagram
}
I_API_SOURCES {
}
I_SCHEDULE_GROUPS {
I_TIMETABLE_GROUPS {
}
I_SCHEDULE_ENTRIES {
I_TIMETABLE_ENTRIES {
}
O_APP_STATE {
}
O_APP_SETTINGS {
}
O_BACKGROUND_TASKS {
}
O_AUDIT_EVENTS {
}
A_USERS ||--o{ A_USER_ROLES : has
A_ROLES ||--o{ A_USER_ROLES : assigned_to
A_ROLES ||--o{ A_ROLE_PERMISSIONS : has
A_PERMISSIONS ||--o{ A_ROLE_PERMISSIONS : granted_to
A_USERS ||--o{ A_SESSIONS : owns
A_USERS ||--o{ O_AUDIT_EVENTS : acts
C_CANVAS_SIZES ||--o{ C_TEMPLATES : used_by
C_CANVAS_SIZES ||--o{ C_PLAYLISTS : used_by
@@ -275,12 +304,11 @@ erDiagram
C_SLIDES ||--o{ C_PLAYLIST_SLIDES : included_in
C_PLAYLIST_SLIDES ||--o{ C_PLAYLIST_SLIDE_SCHEDULE_RULES : has_rules
D_PLAYERS ||--o{ D_SCREENS : assigned_to
C_PLAYLISTS ||--o{ D_SCREENS : uses
D_SCREENS ||--o{ D_ONBOARDING_DEVICES : binds
D_ANNOUNCEMENTS ||--o{ D_ANNOUNCEMENT_SCREENS : targets
D_SCREENS ||--o{ D_ANNOUNCEMENT_SCREENS : receives
I_RSS_FEEDS ||--o{ I_RSS_FEED_ITEMS : caches
I_SCHEDULE_GROUPS ||--o{ I_SCHEDULE_ENTRIES : contains
I_TIMETABLE_GROUPS ||--o{ I_TIMETABLE_ENTRIES : contains
```
+550 -1169
View File
File diff suppressed because it is too large Load Diff
+11 -9
View File
@@ -1,8 +1,11 @@
{
"name": "pulse-signage",
"version": "2.5.2",
"version": "2.8.7",
"private": false,
"description": "Pulse Signage application with MySQL and media storage",
"engines": {
"node": ">=26.0.0"
},
"repository": {
"type": "git",
"url": "https://git.lzstealth.com/LZStealth/pulse-signage.git"
@@ -17,20 +20,19 @@
"test": "node --test"
},
"dependencies": {
"@sparticuz/chromium": "^137.0.0",
"@sparticuz/chromium": "^149.0.0",
"animate.css": "^4.1.1",
"bootstrap-icons": "1.11.3",
"bootstrap-icons": "1.13.1",
"cropperjs": "^1.6.2",
"dotenv": "^17.4.2",
"express": "^4.21.2",
"express": "^5.2.1",
"handlebars": "^4.7.8",
"hls.js": "^1.5.15",
"hls.js": "^1.7.0",
"multer": "^2.2.0",
"mysql2": "^3.14.3",
"puppeteer-core": "^24.16.0",
"qrcode": "^1.5.4",
"mysql2": "^3.23.3",
"puppeteer-core": "^25.7.0",
"sharp": "^0.35.3",
"ws": "^8.21.0"
"ws": "^8.21.3"
},
"devDependencies": {
"nodemon": "^3.1.10"
+61
View File
@@ -0,0 +1,61 @@
@echo off
setlocal EnableExtensions EnableDelayedExpansion
set "TARGET_URL=%~1"
if not defined TARGET_URL set "TARGET_URL=http://localhost:8081"
set "BROWSER_PATH="
set "BROWSER_KIND="
for %%B in (chrome.exe msedge.exe firefox.exe) do if not defined BROWSER_PATH (
for /f "delims=" %%I in ('where %%B 2^>nul') do if not defined BROWSER_PATH (
set "BROWSER_PATH=%%I"
set "BROWSER_KIND=%%~nB"
)
)
if not defined BROWSER_PATH if not defined BROWSER_KIND (
for %%P in (
"%ProgramFiles%\Google\Chrome\Application\chrome.exe"
"%ProgramFiles(x86)%\Google\Chrome\Application\chrome.exe"
"%LocalAppData%\Google\Chrome\Application\chrome.exe"
) do if not defined BROWSER_PATH if exist "%%~fP" (
set "BROWSER_PATH=%%~fP"
set "BROWSER_KIND=chrome"
)
)
if not defined BROWSER_PATH if not defined BROWSER_KIND (
for %%P in (
"%ProgramFiles%\Microsoft\Edge\Application\msedge.exe"
"%ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe"
"%LocalAppData%\Microsoft\Edge\Application\msedge.exe"
) do if not defined BROWSER_PATH if exist "%%~fP" (
set "BROWSER_PATH=%%~fP"
set "BROWSER_KIND=edge"
)
)
if not defined BROWSER_PATH if not defined BROWSER_KIND (
for %%P in (
"%ProgramFiles%\Mozilla Firefox\firefox.exe"
"%ProgramFiles(x86)%\Mozilla Firefox\firefox.exe"
"%LocalAppData%\Mozilla Firefox\firefox.exe"
) do if not defined BROWSER_PATH if exist "%%~fP" (
set "BROWSER_PATH=%%~fP"
set "BROWSER_KIND=firefox"
)
)
if not defined BROWSER_PATH (
echo No supported browser was found.
echo Tried Chrome, Edge, and Firefox in PATH and common install locations.
exit /b 1
)
echo Launching !BROWSER_KIND! in kiosk mode: !TARGET_URL!
if /I "!BROWSER_KIND!"=="firefox" (
start "" "!BROWSER_PATH!" -kiosk "!TARGET_URL!"
) else (
start "" "!BROWSER_PATH!" --disable-notifications --kiosk "!TARGET_URL!"
)
+47
View File
@@ -0,0 +1,47 @@
#!/usr/bin/env bash
set -euo pipefail
target_url="${1:-http://localhost:8081}"
find_browser() {
local candidate
for candidate in "$@"; do
if command -v "$candidate" >/dev/null 2>&1; then
printf '%s' "$candidate"
return 0
fi
done
return 1
}
browser=""
browser_kind=""
if browser="$(find_browser google-chrome-stable google-chrome chromium chromium-browser msedge microsoft-edge firefox)"; then
case "$browser" in
firefox)
browser_kind="firefox"
;;
msedge|microsoft-edge)
browser_kind="edge"
;;
*)
browser_kind="chrome"
;;
esac
else
echo "No supported browser was found."
echo "Tried Chrome, Chromium, Edge, and Firefox in PATH."
exit 1
fi
echo "Launching ${browser_kind} in kiosk mode: ${target_url}"
case "$browser_kind" in
firefox)
exec "$browser" -kiosk "$target_url"
;;
edge|chrome)
exec "$browser" --disable-notifications --kiosk "$target_url"
;;
esac
+50
View File
@@ -7,6 +7,55 @@ const PASSWORD_KEY_LENGTH = 32;
const PASSWORD_DIGEST = 'sha256';
const SESSION_BYTES = 32;
function validatePasswordStrength(password, options) {
const value = String(password || '');
const requirements = options && options.policy
? getPasswordPolicyPreset(options.policy)
: {
minimumLength: Number(options && options.minimumLength) || 10,
minimumCategories: Number(options && options.minimumCategories) || 3,
requireLowercase: Boolean(options && options.requireLowercase),
requireUppercase: Boolean(options && options.requireUppercase),
requireNumber: Boolean(options && options.requireNumber),
requireSymbol: Boolean(options && options.requireSymbol)
};
const hasLowercase = /[a-z]/.test(value);
const hasUppercase = /[A-Z]/.test(value);
const hasNumber = /[0-9]/.test(value);
const hasSymbol = /[^A-Za-z0-9]/.test(value);
const categoryCount = [hasLowercase, hasUppercase, hasNumber, hasSymbol].filter(Boolean).length;
const missingRequiredCategory = requirements.requireLowercase && !hasLowercase
|| requirements.requireUppercase && !hasUppercase
|| requirements.requireNumber && !hasNumber
|| requirements.requireSymbol && !hasSymbol;
if (value.length < requirements.minimumLength || categoryCount < requirements.minimumCategories || missingRequiredCategory) {
if (missingRequiredCategory) {
const requiredCategories = [];
if (requirements.requireLowercase) requiredCategories.push('lowercase');
if (requirements.requireUppercase) requiredCategories.push('uppercase');
if (requirements.requireNumber) requiredCategories.push('number');
if (requirements.requireSymbol) requiredCategories.push('symbol');
return `Password must be at least ${requirements.minimumLength} characters and include ${requiredCategories.join(', ')}.`;
}
if (requirements.minimumCategories === 4) {
return `Password must be at least ${requirements.minimumLength} characters and include uppercase, lowercase, number, and symbol.`;
}
return `Password must be at least ${requirements.minimumLength} characters and include ${requirements.minimumCategories} of: uppercase, lowercase, number, and symbol.`;
}
return '';
}
function getPasswordPolicyPreset(policy) {
const normalizedPolicy = String(policy || 'standard').trim().toLowerCase();
return normalizedPolicy === 'strict'
? { minimumLength: 14, minimumCategories: 4 }
: normalizedPolicy === 'strong'
? { minimumLength: 12, minimumCategories: 3 }
: { minimumLength: 10, minimumCategories: 3 };
}
function hashPassword(password, salt) {
const safePassword = String(password || '');
const safeSalt = salt || crypto.randomBytes(16).toString('hex');
@@ -40,6 +89,7 @@ function hashSessionToken(token) {
module.exports = {
hashPassword,
verifyPassword,
validatePasswordStrength,
createSessionToken,
hashSessionToken
};
+6 -2
View File
@@ -27,7 +27,7 @@ const dbBootstrap = require('#src/db/bootstrap');
const data = require('#src/data');
const player = require('#src/player/render');
const listQuery = require('#src/web/lib/list-query');
const { fetchPlaylistCanvasId, fetchPlaylistCanvasSignature } = require('#src/web/lib/helpers');
const { fetchPlaylistCanvasId } = require('#src/web/lib/helpers');
module.exports = {
createPool: dbCommon.createPool,
@@ -37,6 +37,8 @@ module.exports = {
slugify: data.slugify,
uniqueScreenSlug: data.uniqueScreenSlug,
parseJsonSafe: data.parseJsonSafe,
validateMaxLength: data.validateMaxLength,
truncateToMaxLength: data.truncateToMaxLength,
fetchAdminData: data.fetchAdminData,
fetchPlaylistsPage: data.fetchPlaylistsPage,
fetchSlidesPage: data.fetchSlidesPage,
@@ -61,7 +63,6 @@ module.exports = {
getSortDirectionQuery: listQuery.getSortDirectionQuery,
fetchPlaylistById: data.fetchPlaylistById,
fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasSignature,
normalizeDisplayMode: data.normalizeDisplayMode,
fetchTimetablesData: data.fetchTimetablesData,
fetchTimetableGroupsPage: data.fetchTimetableGroupsPage,
@@ -84,13 +85,16 @@ module.exports = {
fetchScreenById: data.fetchScreenById,
fetchScreenEditData: data.fetchScreenEditData,
fetchScreenPlayerUrls: data.fetchScreenPlayerUrls,
fetchPlayerPublicBaseUrl: data.fetchPlayerPublicBaseUrl,
fetchScreenPlayerRecord: data.fetchScreenPlayerRecord,
fetchTemplateById: data.fetchTemplateById,
fetchPlayerRegistrations: data.fetchPlayerRegistrations,
fetchSlideById: data.fetchSlideById,
fetchTemplatesData: data.fetchTemplatesData,
fetchCanvasSizesData: data.fetchCanvasSizesData,
fetchCanvasSizeById: data.fetchCanvasSizeById,
buildCanvasSizePayload: data.buildCanvasSizePayload,
MAX_CANVAS_SIZE_DIMENSION: data.MAX_CANVAS_SIZE_DIMENSION,
buildSlidePayload: data.buildSlidePayload,
extractTemplateRegions: data.extractTemplateRegions,
buildTemplatePayload: data.buildTemplatePayload,
+1 -1
View File
@@ -93,7 +93,7 @@ async function fetchSlidesPage(pool, page, pageSize, searchTerm, sortKey, sortDi
LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id
ORDER BY s.id DESC`,
countSql: 'SELECT COUNT(*) AS count FROM c_slides',
searchColumns: ['s.title', 'st.name', 's.content_json'],
searchColumns: ['s.title', 'st.name'],
searchTerm: searchTerm,
sortColumns: {
title: 's.title',
+75 -51
View File
@@ -1,55 +1,69 @@
const ANNOUNCEMENT_ICON_OPTIONS = [
{ value: 'megaphone-fill', label: 'Megaphone' },
{ value: 'megaphone', label: 'Megaphone outline' },
{ value: 'bell-fill', label: 'Bell' },
{ value: 'bell', label: 'Bell outline' },
{ value: 'exclamation-triangle-fill', label: 'Warning' },
{ value: 'exclamation-triangle', label: 'Warning outline' },
{ value: 'info-circle-fill', label: 'Info' },
{ value: 'info-circle', label: 'Info outline' },
{ value: 'check-circle-fill', label: 'Success' },
{ value: 'check-circle', label: 'Success outline' },
{ value: 'lightbulb-fill', label: 'Idea' },
{ value: 'lightbulb', label: 'Idea outline' },
{ value: 'calendar-event-fill', label: 'Calendar' },
{ value: 'calendar-event', label: 'Calendar outline' },
{ value: 'clock-fill', label: 'Clock' },
{ value: 'clock', label: 'Clock outline' },
{ value: 'wifi-off', label: 'Wi-Fi Offline' },
{ value: 'wifi', label: 'Wi-Fi' },
{ value: 'hdd-network', label: 'Network' },
{ value: 'hdd-network-fill', label: 'Network fill' },
{ value: 'speaker-fill', label: 'Speaker' },
{ value: 'speaker', label: 'Speaker outline' },
{ value: 'shield-fill', label: 'Shield' },
{ value: 'shield', label: 'Shield outline' },
{ value: 'collection-play-fill', label: 'Playlist' },
{ value: 'collection-play', label: 'Playlist outline' },
{ value: 'broadcast', label: 'Broadcast' },
{ value: 'broadcast-pin', label: 'Broadcast pin' },
{ value: 'plug-fill', label: 'Plug' },
{ value: 'plug', label: 'Plug outline' },
{ value: 'lightning-charge-fill', label: 'Urgent' },
{ value: 'lightning-charge', label: 'Urgent outline' },
{ value: 'car-front-fill', label: 'Car Front' },
{ value: 'car-front', label: 'Car Front outline' },
{ value: 'lamp-fill', label: 'Lamp' },
{ value: 'lamp', label: 'Lamp outline' },
{ value: 'envelope-fill', label: 'Message' },
{ value: 'envelope', label: 'Message outline' },
{ value: 'people-fill', label: 'Audience' },
{ value: 'people', label: 'Audience outline' },
{ value: 'browser-chrome', label: 'Browser Chrome' },
{ value: 'browser-edge', label: 'Browser Edge' },
{ value: 'browser-firefox', label: 'Browser Firefox' },
{ value: 'browser-safari', label: 'Browser Safari' },
{ value: 'cone', label: 'Cone' },
{ value: 'cone-striped', label: 'Cone striped' },
{ value: 'cup-straw', label: 'Cup straw' },
{ value: 'fire', label: 'Fire' }
const fs = require('fs');
const path = require('path');
const BOOTSTRAP_ICON_CSS_PATH = path.join(__dirname, '..', 'web', 'public', 'adminlte', 'bootstrap-icons', 'css', 'bootstrap-icons.min.css');
const DEFAULT_ANNOUNCEMENT_ICON_KEYS = [
'megaphone-fill', 'megaphone', 'bell-fill', 'bell',
'exclamation-triangle-fill', 'exclamation-triangle', 'info-circle-fill', 'info-circle',
'check-circle-fill', 'check-circle', 'lightbulb-fill', 'lightbulb',
'calendar-event-fill', 'calendar-event', 'clock-fill', 'clock',
'wifi-off', 'wifi', 'hdd-network', 'hdd-network-fill',
'speaker-fill', 'speaker', 'shield-fill', 'shield',
'collection-play-fill', 'collection-play', 'broadcast', 'broadcast-pin',
'plug-fill', 'plug', 'lightning-charge-fill', 'lightning-charge',
'car-front-fill', 'car-front', 'lamp-fill', 'lamp',
'envelope-fill', 'envelope', 'people-fill', 'people',
'browser-chrome', 'browser-edge', 'browser-firefox', 'browser-safari',
'cone', 'cone-striped', 'cup-straw', 'fire'
];
const ANNOUNCEMENT_ICON_KEYS = ANNOUNCEMENT_ICON_OPTIONS.map(function (option) {
function humanizeBootstrapIconLabel(iconKey) {
return String(iconKey || '')
.trim()
.replace(/[-_]+/g, ' ')
.replace(/\b\w/g, function (character) {
return character.toUpperCase();
});
}
function loadBootstrapIconCatalog() {
try {
const css = fs.readFileSync(BOOTSTRAP_ICON_CSS_PATH, 'utf8');
const keys = Array.from(new Set((css.match(/\.bi-([a-z0-9-]+)::?before/g) || []).map(function (match) {
return String(match || '')
.replace(/^\.bi-/, '')
.replace(/::?before$/, '')
.trim()
.toLowerCase();
}).filter(Boolean)));
return keys.map(function (value) {
return {
value: value,
label: humanizeBootstrapIconLabel(value)
};
}).sort(function (left, right) {
return left.value.localeCompare(right.value);
});
} catch (_error) {
return DEFAULT_ANNOUNCEMENT_ICON_KEYS.map(function (value) {
return { value: value, label: humanizeBootstrapIconLabel(value) };
});
}
}
const ANNOUNCEMENT_ICON_CATALOG = loadBootstrapIconCatalog();
const ANNOUNCEMENT_ICON_OPTIONS = DEFAULT_ANNOUNCEMENT_ICON_KEYS.map(function (value) {
const catalogOption = ANNOUNCEMENT_ICON_CATALOG.find(function (option) {
return option.value === value;
});
return catalogOption || { value: value, label: humanizeBootstrapIconLabel(value) };
});
const ANNOUNCEMENT_ICON_KEYS = DEFAULT_ANNOUNCEMENT_ICON_KEYS.slice();
const ANNOUNCEMENT_ICON_CATALOG_KEYS = ANNOUNCEMENT_ICON_CATALOG.map(function (option) {
return option.value;
});
@@ -58,17 +72,27 @@ const ANNOUNCEMENT_ICON_LABELS = ANNOUNCEMENT_ICON_OPTIONS.reduce(function (labe
return labels;
}, Object.create(null));
ANNOUNCEMENT_ICON_CATALOG.forEach(function (option) {
if (!Object.prototype.hasOwnProperty.call(ANNOUNCEMENT_ICON_LABELS, option.value)) {
ANNOUNCEMENT_ICON_LABELS[option.value] = option.label;
}
});
const DEFAULT_ANNOUNCEMENT_ICON = 'megaphone-fill';
function normalizeAnnouncementIcon(value) {
const normalized = String(value || '').trim().toLowerCase();
return ANNOUNCEMENT_ICON_KEYS.includes(normalized) ? normalized : DEFAULT_ANNOUNCEMENT_ICON;
return ANNOUNCEMENT_ICON_CATALOG_KEYS.includes(normalized) ? normalized : DEFAULT_ANNOUNCEMENT_ICON;
}
module.exports = {
DEFAULT_ANNOUNCEMENT_ICON_KEYS,
ANNOUNCEMENT_ICON_OPTIONS,
ANNOUNCEMENT_ICON_KEYS,
ANNOUNCEMENT_ICON_CATALOG,
ANNOUNCEMENT_ICON_CATALOG_KEYS,
ANNOUNCEMENT_ICON_LABELS,
DEFAULT_ANNOUNCEMENT_ICON,
humanizeBootstrapIconLabel,
normalizeAnnouncementIcon
};
+4 -1
View File
@@ -6,6 +6,9 @@ const {
DEFAULT_ANNOUNCEMENT_ICON,
normalizeAnnouncementIcon: normalizeAnnouncementIconFromConfig
} = require('./announcement-icons');
const { validateMaxLength } = require('./utils');
const SHORT_LABEL_MAX_LENGTH = 255;
const ANNOUNCEMENT_TYPES = ['lower-third', 'fullscreen', 'top-banner'];
const ANNOUNCEMENT_COLORS = ['primary', 'secondary', 'success', 'info', 'warning', 'danger', 'dark', 'light'];
@@ -57,7 +60,7 @@ function normalizeAnnouncementScreenIds(value) {
function buildAnnouncementPayload(input) {
const message = normalizeAnnouncementMessage(input && input.message);
const shortLabel = normalizeAnnouncementShortLabel(input && input.short_label);
const shortLabel = validateMaxLength(normalizeAnnouncementShortLabel(input && input.short_label), SHORT_LABEL_MAX_LENGTH, 'Announcement short description');
const announcementType = normalizeAnnouncementType(input && input.announcement_type);
const colorKey = normalizeAnnouncementColor(input && input.color_key);
const iconKey = normalizeAnnouncementIconFromConfig(input && input.icon_key);
+197 -31
View File
@@ -2,20 +2,33 @@
const http = require('http');
const https = require('https');
const { fetchPagedRows } = require('./utils');
const { fetchPagedRows, validateMaxLength } = require('./utils');
const NAME_MAX_LENGTH = 255;
const URL_MAX_LENGTH = 1024;
const AUTH_MAX_LENGTH = 255;
const ITEMS_PATH_MAX_LENGTH = 255;
const REQUEST_BODY_MAX_LENGTH = 1000000;
const TOKEN_URL_MAX_LENGTH = 1024;
const TOKEN_RESPONSE_PATH_MAX_LENGTH = 255;
const TOKEN_HEADER_PREFIX_MAX_LENGTH = 64;
const tokenCache = new Map();
function normalizeUpdateIntervalUnit(value) {
const unit = String(value || '').trim().toLowerCase();
return unit === 'seconds' ? 'seconds' : 'minutes';
if (unit === 'seconds' || unit === 'minutes' || unit === 'hours') {
return unit;
}
return 'minutes';
}
function normalizeAuthMethod(value) {
const method = String(value || '').trim().toLowerCase();
return ['basic', 'bearer', 'api_key_header'].includes(method) ? method : 'none';
return ['basic', 'bearer', 'api_key_header', 'token_login'].includes(method) ? method : 'none';
}
function getItemsPath(source) {
return String(source && (source.items_path || source.itemsPath) || '').trim();
function normalizeRequestMethod(value) {
return String(value || '').trim().toUpperCase() === 'POST' ? 'POST' : 'GET';
}
function buildAuthHeaders(source) {
@@ -46,7 +59,7 @@ function buildAuthHeaders(source) {
async function fetchApiSourcesData(pool) {
const [apiSources] = await pool.query(
'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC'
'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC'
);
return { apiSources: apiSources };
@@ -54,7 +67,7 @@ async function fetchApiSourcesData(pool) {
async function fetchApiSourcesPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, {
selectSql: 'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC',
selectSql: 'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC',
countSql: 'SELECT COUNT(*) AS count FROM i_api_sources',
searchColumns: ['name', 'api_url', 'last_pull_error'],
searchTerm: searchTerm,
@@ -78,7 +91,7 @@ async function fetchApiSourcesPage(pool, page, pageSize, searchTerm, sortKey, so
async function fetchApiSourceById(pool, id) {
const [rows] = await pool.query(
'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources WHERE id = ?',
'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources WHERE id = ?',
[id]
);
@@ -87,13 +100,18 @@ async function fetchApiSourceById(pool, id) {
async function loadUrlText(urlValue, requestOptions) {
const extraHeaders = requestOptions && requestOptions.headers ? requestOptions.headers : {};
const method = String(requestOptions && requestOptions.method || 'GET').toUpperCase();
const body = requestOptions && requestOptions.body !== undefined ? requestOptions.body : undefined;
const headers = Object.assign({
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8',
'User-Agent': 'Pulse Signage API Reader'
}, extraHeaders);
if (typeof fetch === 'function') {
const response = await fetch(urlValue, {
headers: Object.assign({
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8',
'User-Agent': 'Pulse Signage API Reader'
}, extraHeaders)
});
const fetchOptions = { method: method, headers: headers };
if (body !== undefined && method !== 'GET' && method !== 'HEAD') {
fetchOptions.body = body;
}
const response = await fetch(urlValue, fetchOptions);
return {
statusCode: response.status,
@@ -106,12 +124,9 @@ async function loadUrlText(urlValue, requestOptions) {
return await new Promise(function (resolve, reject) {
const url = new URL(urlValue);
const transport = url.protocol === 'https:' ? https : http;
const requestHeaders = Object.assign({
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8',
'User-Agent': 'Pulse Signage API Reader'
}, extraHeaders);
const request = transport.get(url, Object.assign({}, requestOptions || {}, {
headers: requestHeaders
const request = transport.request(url, Object.assign({}, requestOptions || {}, {
method: method,
headers: headers
}), function (response) {
response.setEncoding('utf8');
let body = '';
@@ -129,15 +144,126 @@ async function loadUrlText(urlValue, requestOptions) {
response.on('error', reject);
});
if (body !== undefined && method !== 'GET' && method !== 'HEAD') {
request.write(body);
}
request.end();
request.on('error', reject);
});
}
function parseJsonRequestBody(value, fieldName) {
const text = String(value || '').trim();
if (!text) {
return undefined;
}
try {
return JSON.parse(text);
} catch (_error) {
const error = new Error(fieldName + ' must contain valid JSON.');
error.statusCode = 400;
throw error;
}
}
function resolveResponsePath(value, responsePath) {
let current = value;
String(responsePath || '').split('.').forEach(function (segment) {
if (current === undefined || current === null) {
current = undefined;
return;
}
current = current[segment];
});
return current;
}
function getTokenCacheKey(source) {
return JSON.stringify([
source && source.id || '',
source && (source.token_url || source.tokenUrl) || '',
source && (source.token_request_body_json || source.tokenRequestBodyJson) || '',
source && (source.token_response_path || source.tokenResponsePath) || 'access_token',
source && (source.token_header_name || source.tokenHeaderName) || 'Authorization',
source && (source.token_header_prefix || source.tokenHeaderPrefix) || 'Bearer'
]);
}
function clearCachedToken(source) {
tokenCache.delete(getTokenCacheKey(source));
}
async function fetchLoginToken(source) {
const cacheKey = getTokenCacheKey(source);
const cached = tokenCache.get(cacheKey);
if (cached && cached.expiresAt > Date.now()) {
return cached.value;
}
const tokenUrl = source.token_url || source.tokenUrl;
const tokenBody = parseJsonRequestBody(source.token_request_body_json || source.tokenRequestBodyJson, 'Login request body');
const tokenHeaders = { 'Content-Type': 'application/json' };
const response = await loadUrlText(tokenUrl, {
method: 'POST',
headers: tokenHeaders,
body: tokenBody === undefined ? undefined : JSON.stringify(tokenBody)
});
if (!response.ok) {
throw new Error(`Unable to obtain API token (${response.statusCode}).`);
}
let parsed;
try {
parsed = JSON.parse(String(response.bodyText || '').trim());
} catch (_error) {
throw new Error('Token response was not valid JSON.');
}
const tokenPath = source.token_response_path || source.tokenResponsePath || 'access_token';
const token = resolveResponsePath(parsed, tokenPath);
if (token === undefined || token === null || String(token).trim() === '') {
throw new Error('Token response did not contain a token at the configured path.');
}
const expiresIn = Number(parsed && (parsed.expires_in || parsed.expiresIn));
const lifetimeMs = Number.isFinite(expiresIn) && expiresIn > 0
? Math.max(30000, expiresIn * 1000 - 60000)
: 300000;
tokenCache.set(cacheKey, { value: String(token), expiresAt: Date.now() + lifetimeMs });
return String(token);
}
async function buildRequestHeaders(source) {
const method = normalizeAuthMethod(source && (source.auth_method || source.authMethod));
if (method !== 'token_login') {
return buildAuthHeaders(source);
}
const token = await fetchLoginToken(source);
const headerName = String(source.token_header_name || source.tokenHeaderName || 'Authorization').trim() || 'Authorization';
const prefix = String(source.token_header_prefix || source.tokenHeaderPrefix || 'Bearer').trim();
return { [headerName]: prefix ? prefix + ' ' + token : token };
}
async function fetchApiSourceResponse(apiSource) {
const source = apiSource && typeof apiSource === 'object' ? apiSource : { api_url: apiSource };
const response = await loadUrlText(source.api_url, {
headers: buildAuthHeaders(source)
});
const requestMethod = normalizeRequestMethod(source.request_method || source.requestMethod);
const requestBody = parseJsonRequestBody(source.request_body_json || source.requestBodyJson, 'API request body');
let response;
let tokenRetry = false;
do {
response = await loadUrlText(source.api_url || source.apiUrl, {
method: requestMethod,
headers: Object.assign({}, await buildRequestHeaders(source), requestBody === undefined ? {} : { 'Content-Type': 'application/json' }),
body: requestBody === undefined ? undefined : JSON.stringify(requestBody)
});
if (response.statusCode === 401 && normalizeAuthMethod(source.auth_method || source.authMethod) === 'token_login' && !tokenRetry) {
clearCachedToken(source);
tokenRetry = true;
} else {
break;
}
} while (true);
if (!response.ok) {
throw new Error(`Unable to load API response (${response.statusCode}).`);
}
@@ -171,15 +297,22 @@ function buildApiSourcePayload(req, existingApiSource) {
return fallbackValue;
}
const name = String(req.body.name || fallback.name || '').trim();
const apiUrl = String(req.body.api_url || req.body.apiUrl || fallback.api_url || '').trim();
const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'API source name');
const apiUrl = validateMaxLength(req.body.api_url || req.body.apiUrl || fallback.api_url || '', URL_MAX_LENGTH, 'API source URL');
const authMethod = normalizeAuthMethod(readBodyValue('auth_method', readBodyValue('authMethod', fallback.auth_method || 'none')));
const authUsername = String(readBodyValue('auth_username', readBodyValue('authUsername', fallback.auth_username || '')) || '').trim();
const authPassword = String(readBodyValue('auth_password', readBodyValue('authPassword', fallback.auth_password || '')) || '');
const authBearerToken = String(readBodyValue('auth_bearer_token', readBodyValue('authBearerToken', fallback.auth_bearer_token || '')) || '').trim();
const authHeaderName = String(readBodyValue('auth_header_name', readBodyValue('authHeaderName', fallback.auth_header_name || 'X-API-Key')) || 'X-API-Key').trim() || 'X-API-Key';
const authHeaderValue = String(readBodyValue('auth_header_value', readBodyValue('authHeaderValue', fallback.auth_header_value || '')) || '').trim();
const itemsPath = String(readBodyValue('items_path', readBodyValue('itemsPath', fallback.items_path || '')) || '').trim();
const requestMethod = normalizeRequestMethod(readBodyValue('request_method', readBodyValue('requestMethod', fallback.request_method || 'GET')));
const requestBodyJson = validateMaxLength(readBodyValue('request_body_json', readBodyValue('requestBodyJson', fallback.request_body_json || '')) || '', REQUEST_BODY_MAX_LENGTH, 'API request body');
const authUsername = validateMaxLength(readBodyValue('auth_username', readBodyValue('authUsername', fallback.auth_username || '')) || '', AUTH_MAX_LENGTH, 'API source username');
const authPassword = validateMaxLength(readBodyValue('auth_password', readBodyValue('authPassword', fallback.auth_password || '')) || '', AUTH_MAX_LENGTH, 'API source password');
const authBearerToken = validateMaxLength(readBodyValue('auth_bearer_token', readBodyValue('authBearerToken', fallback.auth_bearer_token || '')) || '', AUTH_MAX_LENGTH, 'API source bearer token');
const authHeaderName = validateMaxLength(readBodyValue('auth_header_name', readBodyValue('authHeaderName', fallback.auth_header_name || 'X-API-Key')) || 'X-API-Key', AUTH_MAX_LENGTH, 'API source header name') || 'X-API-Key';
const authHeaderValue = validateMaxLength(readBodyValue('auth_header_value', readBodyValue('authHeaderValue', fallback.auth_header_value || '')) || '', AUTH_MAX_LENGTH, 'API source header value');
const tokenUrl = validateMaxLength(readBodyValue('token_url', readBodyValue('tokenUrl', fallback.token_url || '')) || '', TOKEN_URL_MAX_LENGTH, 'API token URL');
const tokenRequestBodyJson = validateMaxLength(readBodyValue('token_request_body_json', readBodyValue('tokenRequestBodyJson', fallback.token_request_body_json || '')) || '', REQUEST_BODY_MAX_LENGTH, 'Login request body');
const tokenResponsePath = validateMaxLength(readBodyValue('token_response_path', readBodyValue('tokenResponsePath', fallback.token_response_path || 'access_token')) || 'access_token', TOKEN_RESPONSE_PATH_MAX_LENGTH, 'Token response path');
const tokenHeaderName = validateMaxLength(readBodyValue('token_header_name', readBodyValue('tokenHeaderName', fallback.token_header_name || 'Authorization')) || 'Authorization', AUTH_MAX_LENGTH, 'Token header name');
const tokenHeaderPrefix = validateMaxLength(readBodyValue('token_header_prefix', readBodyValue('tokenHeaderPrefix', fallback.token_header_prefix || 'Bearer')) || '', TOKEN_HEADER_PREFIX_MAX_LENGTH, 'Token prefix');
const itemsPath = validateMaxLength(readBodyValue('items_path', readBodyValue('itemsPath', fallback.items_path || '')) || '', ITEMS_PATH_MAX_LENGTH, 'API source items path');
const updateIntervalValue = Math.max(1, Number(req.body.update_interval_value || req.body.updateIntervalValue || fallback.update_interval_value || 60));
const updateIntervalUnit = normalizeUpdateIntervalUnit(req.body.update_interval_unit || req.body.updateIntervalUnit || fallback.update_interval_unit || 'minutes');
@@ -234,15 +367,48 @@ function buildApiSourcePayload(req, existingApiSource) {
throw error;
}
parseJsonRequestBody(requestBodyJson, 'API request body');
parseJsonRequestBody(tokenRequestBodyJson, 'Login request body');
if (authMethod === 'token_login') {
if (!tokenUrl) {
const error = new Error('Token login requires a login URL.');
error.statusCode = 400;
throw error;
}
try {
const tokenParsedUrl = new URL(tokenUrl);
if (tokenParsedUrl.protocol !== 'http:' && tokenParsedUrl.protocol !== 'https:') {
throw new Error('invalid protocol');
}
} catch (_error) {
const error = new Error('Enter a valid API token URL.');
error.statusCode = 400;
throw error;
}
if (!tokenRequestBodyJson) {
const error = new Error('Token login requires a JSON request body.');
error.statusCode = 400;
throw error;
}
}
return {
name: name,
apiUrl: parsedUrl.toString(),
requestMethod: requestMethod,
requestBodyJson: requestBodyJson,
authMethod: authMethod,
authUsername: authUsername,
authPassword: authPassword,
authBearerToken: authBearerToken,
authHeaderName: authHeaderName,
authHeaderValue: authHeaderValue,
tokenUrl: tokenUrl,
tokenRequestBodyJson: tokenRequestBodyJson,
tokenResponsePath: tokenResponsePath,
tokenHeaderName: tokenHeaderName,
tokenHeaderPrefix: tokenHeaderPrefix,
itemsPath: itemsPath,
updateIntervalValue: Math.floor(updateIntervalValue),
updateIntervalUnit: updateIntervalUnit
+207
View File
@@ -0,0 +1,207 @@
const { DEFAULT_ANNOUNCEMENT_ICON_KEYS } = require('./announcement-icons');
const SETTING_DEFINITIONS = [
{ key: 'app.name', type: 'string', defaultValue: 'Pulse Signage' },
{ key: 'locale.timezone', type: 'string', defaultValue: 'Europe/London' },
{ key: 'locale.language', type: 'string', defaultValue: 'en' },
{ key: 'ui.theme', type: 'enum', values: ['dark', 'light', 'auto'], defaultValue: 'dark' },
{ key: 'security.session_lifetime_days', type: 'integer', min: 1, defaultValue: 14 },
{ key: 'security.allow_user_session_revocation', type: 'boolean', defaultValue: true },
{ key: 'security.max_active_sessions', type: 'integer', min: 0, defaultValue: 0 },
{ key: 'security.password_min_length', type: 'integer', min: 8, defaultValue: 10 },
{ key: 'security.password_min_categories', type: 'integer', min: 1, defaultValue: 3 },
{ key: 'security.password_require_lowercase', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_uppercase', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_number', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_symbol', type: 'boolean', defaultValue: false },
{ key: 'security.require_password_change_for_new_users', type: 'boolean', defaultValue: true },
{ key: 'security.require_password_change_after_admin_reset', type: 'boolean', defaultValue: true },
{ key: 'security.login_max_attempts', type: 'integer', min: 1, defaultValue: 5 },
{ key: 'security.login_lockout_minutes', type: 'integer', min: 1, defaultValue: 15 },
{ key: 'security.login_rate_limit_scope', type: 'enum', values: ['both', 'username', 'ip'], defaultValue: 'both' },
{ key: 'audit.enabled', type: 'boolean', defaultValue: true },
{ key: 'audit.categories', type: 'string_array', defaultValue: ['authentication', 'security', 'sessions', 'users', 'roles', 'system-settings'] },
{ key: 'audit.include_request_metadata', type: 'boolean', defaultValue: true },
{ key: 'audit.retention_days', type: 'integer', min: 0, defaultValue: 180 },
{ key: 'uploads.image_max_bytes', type: 'integer', min: 1, defaultValue: 100 * 1024 * 1024 },
{ key: 'uploads.video_max_bytes', type: 'integer', min: 1, defaultValue: 1024 * 1024 * 1024 },
{ key: 'uploads.wysiwyg_image_max_bytes', type: 'integer', min: 1, defaultValue: 2 * 1024 * 1024 },
{ key: 'uploads.allowed_mime_types', type: 'string_array', defaultValue: ['image/png', 'image/jpeg', 'image/gif', 'image/webp', 'image/svg+xml', 'video/mp4', 'video/webm', 'video/ogg'] },
{ key: 'uploads.cleanup_days', type: 'integer', min: 0, defaultValue: 30 },
{ key: 'uploads.optimize_images', type: 'boolean', defaultValue: true },
{ key: 'announcements.default_icon', type: 'string', defaultValue: 'megaphone-fill' },
{ key: 'announcements.default_duration_value', type: 'integer', min: 1, defaultValue: 10 },
{ key: 'announcements.default_duration_unit', type: 'enum', values: ['seconds', 'minutes'], defaultValue: 'seconds' },
{ key: 'announcements.suggested_icons', type: 'string_array', defaultValue: DEFAULT_ANNOUNCEMENT_ICON_KEYS.slice() },
{ key: 'player.default_slide_duration_seconds', type: 'integer', min: 1, defaultValue: 10 },
{ key: 'player.default_fade_between_slides', type: 'boolean', defaultValue: true },
{ key: 'player.skip_unavailable_rtmp', type: 'boolean', defaultValue: true }
,{ key: 'data-sources.rss_default_interval_value', type: 'integer', min: 1, defaultValue: 60 }
,{ key: 'data-sources.rss_default_interval_unit', type: 'enum', values: ['seconds', 'minutes', 'hours'], defaultValue: 'minutes' }
,{ key: 'data-sources.api_default_interval_value', type: 'integer', min: 1, defaultValue: 60 }
,{ key: 'data-sources.api_default_interval_unit', type: 'enum', values: ['seconds', 'minutes', 'hours'], defaultValue: 'minutes' }
];
const DEFINITIONS_BY_KEY = new Map(SETTING_DEFINITIONS.map(function (definition) {
return [definition.key, definition];
}));
function cloneValue(value) {
if (Array.isArray(value)) {
return value.slice();
}
return value;
}
function getAppSettingDefinitions() {
return SETTING_DEFINITIONS.map(function (definition) {
return Object.assign({}, definition, {
values: definition.values ? definition.values.slice() : undefined,
defaultValue: cloneValue(definition.defaultValue)
});
});
}
function getDefaultAppSettings() {
return SETTING_DEFINITIONS.reduce(function (settings, definition) {
settings[definition.key] = cloneValue(definition.defaultValue);
return settings;
}, {});
}
function normalizeSettingValue(key, value) {
const definition = DEFINITIONS_BY_KEY.get(String(key || '').trim());
if (!definition) {
throw new Error('Unknown application setting: ' + key);
}
if (definition.type === 'string') {
return String(value == null ? '' : value).trim();
}
if (definition.type === 'integer') {
const normalized = Number(value);
if (!Number.isInteger(normalized) || normalized < definition.min) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return normalized;
}
if (definition.type === 'boolean') {
if (value === true || value === 1 || value === '1' || value === 'true') {
return true;
}
if (value === false || value === 0 || value === '0' || value === 'false') {
return false;
}
throw new Error('Invalid value for application setting: ' + definition.key);
}
if (definition.type === 'enum') {
const normalized = String(value == null ? '' : value).trim();
if (!definition.values.includes(normalized)) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return normalized;
}
if (definition.type === 'string_array') {
if (!Array.isArray(value)) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return Array.from(new Set(value.map(function (item) {
return String(item || '').trim();
}).filter(Boolean)));
}
throw new Error('Unsupported application setting type: ' + definition.type);
}
function normalizeAppSettings(settings) {
const input = settings && typeof settings === 'object' ? settings : {};
return SETTING_DEFINITIONS.reduce(function (normalized, definition) {
const value = Object.prototype.hasOwnProperty.call(input, definition.key)
? input[definition.key]
: definition.defaultValue;
normalized[definition.key] = normalizeSettingValue(definition.key, value);
return normalized;
}, {});
}
function parseStoredValue(value) {
if (typeof value !== 'string') {
return value;
}
try {
return JSON.parse(value);
} catch (_error) {
return value;
}
}
async function fetchAppSettings(pool) {
const [rows] = await pool.query('SELECT id, setting_key, setting_value FROM o_app_settings ORDER BY setting_key');
const storedSettings = {};
(rows || []).forEach(function (row) {
const key = String(row && row.setting_key || '').trim();
if (DEFINITIONS_BY_KEY.has(key)) {
storedSettings[key] = parseStoredValue(row.setting_value);
}
});
return normalizeAppSettings(Object.assign({}, getDefaultAppSettings(), storedSettings));
}
async function saveAppSettings(pool, settings, modifiedBy) {
const inputSettings = settings && typeof settings === 'object' ? settings : {};
const normalizedSettings = normalizeAppSettings(inputSettings);
const connection = typeof pool.getConnection === 'function' ? await pool.getConnection() : pool;
const shouldRelease = connection !== pool;
try {
if (typeof connection.beginTransaction === 'function') {
await connection.beginTransaction();
}
for (const definition of SETTING_DEFINITIONS) {
if (!Object.prototype.hasOwnProperty.call(inputSettings, definition.key)) {
continue;
}
await connection.query(
`UPDATE o_app_settings
SET setting_value = ?, modified_by = ?
WHERE setting_key = ?`,
[JSON.stringify(normalizedSettings[definition.key]), modifiedBy || null, definition.key]
);
await connection.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM o_app_settings WHERE setting_key = ?
)`,
[definition.key, JSON.stringify(normalizedSettings[definition.key]), modifiedBy || null, modifiedBy || null, definition.key]
);
}
if (typeof connection.commit === 'function') {
await connection.commit();
}
} catch (error) {
if (typeof connection.rollback === 'function') {
await connection.rollback();
}
throw error;
} finally {
if (shouldRelease && typeof connection.release === 'function') {
connection.release();
}
}
return normalizedSettings;
}
module.exports = {
getAppSettingDefinitions,
getDefaultAppSettings,
normalizeSettingValue,
normalizeAppSettings,
fetchAppSettings,
saveAppSettings
};
+118
View File
@@ -0,0 +1,118 @@
const AUDIT_EVENT_CATEGORIES = Object.freeze({
AUTHENTICATION: 'authentication',
SECURITY: 'security',
SESSIONS: 'sessions',
USERS: 'users',
ROLES: 'roles',
SETTINGS: 'system-settings',
SLIDES: 'slides',
TEMPLATES: 'templates',
PLAYLISTS: 'playlists',
SCREENS: 'screens',
ANNOUNCEMENTS: 'announcements',
CANVAS_SIZES: 'canvas-sizes',
API_SOURCES: 'api-sources',
RSS_FEEDS: 'rss-feeds',
TIMETABLES: 'timetables'
});
const AUDIT_CATEGORY_KEYS = Object.freeze(Object.values(AUDIT_EVENT_CATEGORIES));
const AUDIT_CATEGORY_LABELS = Object.freeze({
authentication: 'Authentication',
security: 'Security',
sessions: 'Sessions',
users: 'Users',
roles: 'Roles',
'system-settings': 'System Settings',
slides: 'Slides',
templates: 'Templates',
playlists: 'Playlists',
screens: 'Screens',
announcements: 'Announcements',
'canvas-sizes': 'Canvas Sizes',
'api-sources': 'API Sources',
'rss-feeds': 'RSS Feeds',
timetables: 'Timetables'
});
const { fetchAppSettings } = require('./app-settings');
function normalizeDetails(details) {
if (details === undefined || details === null) {
return null;
}
return JSON.stringify(details);
}
function buildAuditChanges(previousValues, nextValues) {
const previous = previousValues && typeof previousValues === 'object' ? previousValues : {};
const next = nextValues && typeof nextValues === 'object' ? nextValues : {};
const changes = {};
const keys = new Set(Object.keys(previous).concat(Object.keys(next)));
keys.forEach(function (key) {
if (JSON.stringify(previous[key]) !== JSON.stringify(next[key])) {
changes[key] = { from: previous[key], to: next[key] };
}
});
return changes;
}
function getRequestMetadata(req) {
const forwardedAddress = String(req && req.headers && req.headers['x-forwarded-for'] || '').split(',')[0].trim();
return {
ipAddress: forwardedAddress || String(req && req.ip || req && req.socket && req.socket.remoteAddress || '').trim() || null,
userAgent: String(req && req.headers && req.headers['user-agent'] || '').trim() || null
};
}
async function recordAuditEvent(pool, event) {
const input = event && typeof event === 'object' ? event : {};
const category = String(input.category || '').trim().toLowerCase();
const eventType = String(input.eventType || '').trim().toLowerCase();
if (!category || !eventType) {
throw new Error('Audit events require a category and event type.');
}
await pool.query(
`INSERT INTO o_audit_events
(category, event_type, actor_user_id, target_type, target_id, target_label, ip_address, user_agent, details_json)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)`,
[
category,
eventType,
Number.isInteger(Number(input.actorUserId)) && Number(input.actorUserId) > 0 ? Number(input.actorUserId) : null,
String(input.targetType || '').trim() || null,
String(input.targetId || '').trim() || null,
String(input.targetLabel || '').trim() || null,
String(input.ipAddress || '').trim() || null,
String(input.userAgent || '').trim() || null,
normalizeDetails(input.details)
]
);
}
async function recordRequestAuditEvent(pool, req, event) {
try {
const settings = await fetchAppSettings(pool);
const category = String(event && event.category || '').trim().toLowerCase();
const enabledCategories = Array.isArray(settings['audit.categories']) ? settings['audit.categories'] : AUDIT_CATEGORY_KEYS;
if (!settings['audit.enabled'] || !enabledCategories.includes(category)) {
return;
}
const metadata = settings['audit.include_request_metadata'] ? getRequestMetadata(req) : {};
await recordAuditEvent(pool, Object.assign({}, event, metadata));
} catch (error) {
// Auditing must not turn a successful login or administration action into a failed request.
console.error('Unable to record audit event:', error.message);
}
}
module.exports = {
AUDIT_EVENT_CATEGORIES,
AUDIT_CATEGORY_KEYS,
AUDIT_CATEGORY_LABELS,
getRequestMetadata,
buildAuditChanges,
recordAuditEvent,
recordRequestAuditEvent
};
+26 -3
View File
@@ -1,6 +1,7 @@
// Canvas size data access and pagination helpers.
const { fetchPagedRows } = require('./utils');
const MAX_CANVAS_SIZE_DIMENSION = 16384;
async function fetchCanvasSizesData(pool) {
const [canvasSizes] = await pool.query('SELECT id, name, width, height, created_at, modified_at, created_by, modified_by FROM c_canvas_sizes ORDER BY width ASC, height ASC, name ASC');
@@ -33,10 +34,31 @@ async function fetchCanvasSizeById(pool, id) {
return rows[0] || null;
}
function readCanvasDimension(rawValue, fallbackValue, fieldName) {
const sourceValue = rawValue !== undefined && rawValue !== null && String(rawValue).trim() !== ''
? rawValue
: fallbackValue;
const numericValue = Number(sourceValue);
if (!Number.isFinite(numericValue)) {
const error = new Error('Canvas size ' + fieldName + ' must be a number.');
error.statusCode = 400;
throw error;
}
if (numericValue > MAX_CANVAS_SIZE_DIMENSION) {
const error = new Error('Canvas size dimensions must be 16384 or less.');
error.statusCode = 400;
throw error;
}
return Math.max(1, numericValue);
}
function buildCanvasSizePayload(req, existingCanvasSize) {
const name = String(req.body.name || '').trim();
const width = Math.max(1, Number(req.body.width || (existingCanvasSize && existingCanvasSize.width) || 0));
const height = Math.max(1, Number(req.body.height || (existingCanvasSize && existingCanvasSize.height) || 0));
const width = readCanvasDimension(req.body.width, existingCanvasSize && existingCanvasSize.width, 'width');
const height = readCanvasDimension(req.body.height, existingCanvasSize && existingCanvasSize.height, 'height');
if (!name) {
const error = new Error('Canvas size name is required.');
@@ -55,5 +77,6 @@ module.exports = {
fetchCanvasSizesData,
fetchCanvasSizesPage,
fetchCanvasSizeById,
buildCanvasSizePayload
buildCanvasSizePayload,
MAX_CANVAS_SIZE_DIMENSION
};
+11 -4
View File
@@ -4,19 +4,22 @@ const { fetchAdminData, fetchPlaylistsPage, fetchSlidesPage, fetchTemplatesPage,
const { ANNOUNCEMENT_TYPES, ANNOUNCEMENT_COLORS, ANNOUNCEMENT_ICONS, DEFAULT_ANNOUNCEMENT_ICON, normalizeAnnouncementType, normalizeAnnouncementColor, normalizeAnnouncementIcon, fetchAnnouncementsPage, fetchAnnouncementById, fetchActiveAnnouncement, buildAnnouncementPayload } = require('./announcements');
const { ANNOUNCEMENT_ICON_OPTIONS, ANNOUNCEMENT_ICON_LABELS } = require('./announcement-icons');
const { fetchPlaylistById } = require('./playlists');
const { normalizeDisplayMode, fetchTimetablesData, fetchTimetableGroupsPage, fetchTimetableGroupById, fetchTimetableEntriesByGroupId, buildTimetableGroupPayload } = require('./schedules');
const { normalizeDisplayMode, fetchTimetablesData, fetchTimetableGroupsPage, fetchTimetableGroupById, fetchTimetableEntriesByGroupId, buildTimetableGroupPayload } = require('./timetables');
const { fetchApiSourcesData, fetchApiSourcesPage, fetchApiSourceById, fetchApiSourceResponse, buildApiSourcePayload } = require('./api-sources');
const { fetchRssFeedsData, fetchRssFeedsPage, fetchRssFeedById, fetchRssFeedItemsByFeedId, normalizeRssFeedItem, buildRssFeedPayload, fetchRssFeedItems, replaceRssFeedItems } = require('./rss-feeds');
const { slugify, uniqueScreenSlug, fetchScreenById, fetchScreenEditData, fetchScreenPlayerUrls, fetchScreenPlayerRecord } = require('./screens');
const { slugify, uniqueScreenSlug, fetchScreenById, fetchScreenEditData, fetchScreenPlayerUrls, fetchPlayerPublicBaseUrl, fetchScreenPlayerRecord, fetchPlayerRecordByIdentifier } = require('./screens');
const { fetchPlayerRegistrations } = require('./player-registry');
const { fetchTemplateById, fetchTemplatesData, extractTemplateRegions, buildTemplatePayload } = require('./templates');
const { fetchCanvasSizesData, fetchCanvasSizeById, buildCanvasSizePayload } = require('./canvas-sizes');
const { fetchCanvasSizesData, fetchCanvasSizeById, buildCanvasSizePayload, MAX_CANVAS_SIZE_DIMENSION } = require('./canvas-sizes');
const { fetchSlideById, buildSlidePayload } = require('./slides');
const { parseJsonSafe, fetchDuplicateName } = require('./utils');
const { parseJsonSafe, fetchDuplicateName, validateMaxLength, truncateToMaxLength } = require('./utils');
module.exports = {
slugify,
uniqueScreenSlug,
parseJsonSafe,
validateMaxLength,
truncateToMaxLength,
fetchAdminData,
fetchPlaylistsPage,
fetchSlidesPage,
@@ -59,13 +62,17 @@ module.exports = {
fetchScreenById,
fetchScreenEditData,
fetchScreenPlayerUrls,
fetchPlayerPublicBaseUrl,
fetchScreenPlayerRecord,
fetchPlayerRecordByIdentifier,
fetchPlayerRegistrations,
fetchTemplateById,
fetchSlideById,
fetchTemplatesData,
fetchCanvasSizesData,
fetchCanvasSizeById,
buildCanvasSizePayload,
MAX_CANVAS_SIZE_DIMENSION,
buildSlidePayload,
extractTemplateRegions,
buildTemplatePayload,
+151
View File
@@ -0,0 +1,151 @@
function normalizeDeviceId(value) {
return String(value || '')
.trim()
.replace(/[^a-zA-Z0-9_-]/g, '')
.slice(0, 128);
}
function normalizeBaseUrl(value) {
return String(value || '').trim().replace(/\/$/, '');
}
function normalizeIdentifier(value) {
return String(value || '').trim().slice(0, 255);
}
async function columnExists(pool, tableName, columnName) {
const [rows] = await pool.query(
`SELECT COUNT(*) AS column_count
FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = ?
AND COLUMN_NAME = ?`,
[tableName, columnName]
);
return Number(rows && rows[0] && rows[0].column_count) > 0;
}
async function fetchPlayerRegistrations(pool) {
if (!pool) {
return [];
}
const [rows] = await pool.query(
`SELECT id, identifier, public_base_url, internal_base_url, last_seen_at, modified_at
FROM d_players
ORDER BY modified_at DESC, identifier ASC`
);
return rows;
}
function getConfiguredPlayerIdentifier() {
return normalizeDeviceId(process.env.PLAYER_IDENTIFIER || process.env.PLAYER_DEVICE_ID || '');
}
async function resolvePlayerRegistration(pool, identifier) {
const normalizedIdentifier = normalizeDeviceId(identifier);
if (!pool || !normalizedIdentifier) {
return null;
}
const hasIdentifierColumn = await columnExists(pool, 'd_players', 'identifier');
const hasDeviceIdColumn = await columnExists(pool, 'd_players', 'device_id');
const identifierColumn = hasIdentifierColumn ? 'identifier' : (hasDeviceIdColumn ? 'device_id' : '');
if (!identifierColumn) {
return null;
}
const selectIdExpression = hasIdentifierColumn ? 'id' : 'NULL AS id';
const selectIdentifierExpression = hasIdentifierColumn ? 'identifier' : 'device_id AS identifier';
const orderByExpression = hasIdentifierColumn ? 'modified_at DESC, id DESC' : 'modified_at DESC';
const [rows] = await pool.query(
`SELECT ${selectIdExpression}, ${selectIdentifierExpression}, public_base_url, internal_base_url, last_seen_at
FROM d_players
WHERE ${identifierColumn} = ?
LIMIT 1`,
[normalizedIdentifier]
);
if (rows[0]) {
return rows[0];
}
const [fallbackRows] = await pool.query(
`SELECT ${selectIdExpression}, ${selectIdentifierExpression}, public_base_url, internal_base_url, last_seen_at
FROM d_players
ORDER BY ${orderByExpression}
LIMIT 1`
);
return fallbackRows[0] || null;
}
async function upsertPlayerRegistration(pool, options) {
const identifier = normalizeDeviceId(options && (options.identifier || options.deviceId));
const publicBaseUrl = normalizeBaseUrl(options && options.publicBaseUrl);
const internalBaseUrl = normalizeBaseUrl(options && options.internalBaseUrl);
if (!pool || !identifier) {
return null;
}
await pool.query(
`UPDATE d_players
SET public_base_url = ?, internal_base_url = ?, last_seen_at = CURRENT_TIMESTAMP, modified_at = CURRENT_TIMESTAMP
WHERE identifier = ?`,
[publicBaseUrl || null, internalBaseUrl || null, identifier]
);
await pool.query(
`INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at)
SELECT ?, ?, ?, CURRENT_TIMESTAMP
WHERE NOT EXISTS (
SELECT 1 FROM d_players WHERE identifier = ?
)`,
[identifier, publicBaseUrl || null, internalBaseUrl || null, identifier]
);
return resolvePlayerRegistration(pool, identifier);
}
async function recordPlayerHeartbeat(pool, options) {
const identifier = normalizeDeviceId(options && (options.identifier || options.deviceId));
const publicBaseUrl = normalizeBaseUrl(options && options.publicBaseUrl);
const internalBaseUrl = normalizeBaseUrl(options && options.internalBaseUrl);
if (!pool || !identifier) {
return null;
}
await pool.query(
`UPDATE d_players
SET public_base_url = COALESCE(?, public_base_url),
internal_base_url = COALESCE(?, internal_base_url),
last_seen_at = CURRENT_TIMESTAMP,
modified_at = CURRENT_TIMESTAMP
WHERE identifier = ?`,
[publicBaseUrl || null, internalBaseUrl || null, identifier]
);
await pool.query(
`INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at)
SELECT ?, ?, ?, CURRENT_TIMESTAMP
WHERE NOT EXISTS (
SELECT 1 FROM d_players WHERE identifier = ?
)`,
[identifier, publicBaseUrl || null, internalBaseUrl || null, identifier]
);
return resolvePlayerRegistration(pool, identifier);
}
module.exports = {
normalizeDeviceId: normalizeDeviceId,
normalizeIdentifier: normalizeIdentifier,
getConfiguredPlayerIdentifier: getConfiguredPlayerIdentifier,
fetchPlayerRegistrations: fetchPlayerRegistrations,
resolvePlayerRegistration: resolvePlayerRegistration,
upsertPlayerRegistration: upsertPlayerRegistration,
recordPlayerHeartbeat: recordPlayerHeartbeat
};
+472
View File
@@ -0,0 +1,472 @@
const path = require('path');
const QRCodeStyling = require(path.join(__dirname, '..', 'web', 'public', 'vendor', 'qr-code-styling', 'qr-code-styling.js'));
const QR_PNG_WIDTH = 2048;
function escapeXml(value) {
return String(value === undefined || value === null ? '' : value).replace(/[&<>"']/g, function (character) {
return {
'&': '&amp;',
'<': '&lt;',
'>': '&gt;',
'"': '&quot;',
"'": '&apos;'
}[character];
});
}
function serializeNode(node) {
if (!node) {
return '';
}
if (node.nodeType === 3) {
return escapeXml(node.textContent || '');
}
const attributeEntries = Object.keys(node.attributes || {}).map(function (name) {
return name + '="' + escapeXml(node.attributes[name]) + '"';
});
if (node.tagName === 'svg' && node.namespaceURI === 'http://www.w3.org/2000/svg' && !Object.prototype.hasOwnProperty.call(node.attributes || {}, 'xmlns')) {
attributeEntries.unshift('xmlns="http://www.w3.org/2000/svg"');
}
const attributes = attributeEntries.join(' ');
const children = (node.childNodes || []).map(serializeNode).join('') + escapeXml(node.textContent || '');
return '<' + node.tagName + (attributes ? ' ' + attributes : '') + '>' + children + '</' + node.tagName + '>';
}
function createDomNode(tagName, namespaceUri) {
return {
tagName: tagName,
namespaceURI: namespaceUri || null,
attributes: {},
childNodes: [],
parentNode: null,
nodeType: 1,
textContent: '',
style: {},
setAttribute: function (name, value) {
this.attributes[name] = String(value);
},
appendChild: function (child) {
if (child) {
this.childNodes.push(child);
child.parentNode = this;
}
return child;
},
removeChild: function (child) {
this.childNodes = this.childNodes.filter(function (node) { return node !== child; });
return child;
},
get firstChild() {
return this.childNodes[0] || null;
},
get outerHTML() {
return serializeNode(this);
}
};
}
function createCanvasContext() {
return {
fillStyle: '#000000',
strokeStyle: '#000000',
lineWidth: 1,
beginPath: function () {},
closePath: function () {},
clearRect: function () {},
fillRect: function () {},
strokeRect: function () {},
moveTo: function () {},
lineTo: function () {},
arc: function () {},
rect: function () {},
fill: function () {},
stroke: function () {},
save: function () {},
restore: function () {},
translate: function () {},
rotate: function () {},
scale: function () {},
setTransform: function () {},
transform: function () {},
drawImage: function () {},
measureText: function (text) {
return { width: String(text === undefined || text === null ? '' : text).length * 8 };
},
createLinearGradient: function () {
return { addColorStop: function () {} };
},
createRadialGradient: function () {
return { addColorStop: function () {} };
},
createPattern: function () {
return null;
},
getImageData: function () {
return { data: [] };
},
putImageData: function () {},
clip: function () {}
};
}
function createCanvasNode() {
const node = createDomNode('canvas', 'http://www.w3.org/1999/xhtml');
node.width = 0;
node.height = 0;
node.getContext = function () {
return createCanvasContext();
};
node.toDataURL = function () {
return '';
};
node.toBlob = function (callback) {
if (typeof callback === 'function') {
callback(null);
}
};
return node;
}
function createQrStylingWindow() {
const document = {
createElement: function (tagName) {
if (String(tagName || '').toLowerCase() === 'canvas') {
return createCanvasNode();
}
return createDomNode(tagName, 'http://www.w3.org/1999/xhtml');
},
createElementNS: function (namespaceUri, tagName) {
return createDomNode(tagName, namespaceUri);
},
createTextNode: function (text) {
return {
nodeType: 3,
textContent: String(text === undefined || text === null ? '' : text),
parentNode: null
};
},
body: createDomNode('body', 'http://www.w3.org/1999/xhtml'),
head: createDomNode('head', 'http://www.w3.org/1999/xhtml')
};
const window = {
document: document,
navigator: { userAgent: 'node' },
URL: {
createObjectURL: function () { return ''; },
revokeObjectURL: function () {}
}
};
window.window = window;
window.self = window;
window.Image = class {
constructor() {
this.onload = null;
this.onerror = null;
this.width = 1;
this.height = 1;
this.naturalWidth = 1;
this.naturalHeight = 1;
this._src = '';
}
set src(value) {
this._src = String(value === undefined || value === null ? '' : value);
if (typeof this.onload === 'function') {
setTimeout(() => this.onload(), 0);
}
}
get src() {
return this._src;
}
};
window.HTMLImageElement = window.Image;
window.XMLSerializer = class {
serializeToString(node) {
return serializeNode(node);
}
};
return { window: window, document: document };
}
async function renderStyledQrRawData(options, format) {
const previousWindow = global.window;
const previousDocument = global.document;
const previousXMLSerializer = global.XMLSerializer;
const dom = createQrStylingWindow();
global.window = dom.window;
global.document = dom.document;
global.XMLSerializer = dom.window.XMLSerializer;
try {
const qrCode = new QRCodeStyling(options);
const blob = await qrCode.getRawData(format);
if (!blob) {
return '';
}
if (typeof blob === 'string') {
return blob;
}
if (typeof blob.text === 'function') {
return blob.text();
}
if (typeof blob.arrayBuffer === 'function') {
const buffer = await blob.arrayBuffer();
const bytes = new Uint8Array(buffer);
let binary = '';
for (let index = 0; index < bytes.length; index += 1) {
binary += String.fromCharCode(bytes[index]);
}
return binary;
}
return '';
} finally {
global.window = previousWindow;
global.document = previousDocument;
global.XMLSerializer = previousXMLSerializer;
}
}
function svgToDataUrl(svg) {
const markup = String(svg === undefined || svg === null ? '' : svg).trim();
if (!markup) {
return '';
}
return 'data:image/svg+xml;charset=utf-8,' + encodeURIComponent(markup);
}
function normalizeQrStyleColor(value, fallback) {
const raw = String(value === undefined || value === null ? '' : value).trim();
return raw || fallback;
}
function normalizeQrStyleNumber(value, fallback, min, max) {
const parsed = Number(value);
if (!Number.isFinite(parsed)) {
return fallback;
}
let next = parsed;
if (typeof min === 'number') {
next = Math.max(min, next);
}
if (typeof max === 'number') {
next = Math.min(max, next);
}
return next;
}
function buildQrStylingOptions(source) {
const text = String(source && source.value === undefined ? '' : source && source.value === null ? '' : source.value || '').trim();
const qrStyle = source && typeof source === 'object' ? source : {};
const dotsGradient = qrStyle.qr_dots_color_mode === 'gradient' ? {
type: String(qrStyle.qr_dots_gradient_type || 'linear').trim() || 'linear',
rotation: normalizeQrStyleNumber(qrStyle.qr_dots_gradient_rotation, 0, undefined, undefined),
colorStops: [
{ offset: 0, color: normalizeQrStyleColor(qrStyle.qr_dots_gradient_color_1, normalizeQrStyleColor(qrStyle.qr_dots_color, '#000000')) },
{ offset: 1, color: normalizeQrStyleColor(qrStyle.qr_dots_gradient_color_2, '#ffffff') }
]
} : null;
const cornersSquareGradient = qrStyle.qr_corners_square_color_mode === 'gradient' ? {
type: String(qrStyle.qr_corners_square_gradient_type || 'linear').trim() || 'linear',
rotation: normalizeQrStyleNumber(qrStyle.qr_corners_square_gradient_rotation, 0, undefined, undefined),
colorStops: [
{ offset: 0, color: normalizeQrStyleColor(qrStyle.qr_corners_square_gradient_color_1, normalizeQrStyleColor(qrStyle.qr_corners_square_color, '#000000')) },
{ offset: 1, color: normalizeQrStyleColor(qrStyle.qr_corners_square_gradient_color_2, '#ffffff') }
]
} : null;
const cornersDotGradient = qrStyle.qr_corners_dot_color_mode === 'gradient' ? {
type: String(qrStyle.qr_corners_dot_gradient_type || 'linear').trim() || 'linear',
rotation: normalizeQrStyleNumber(qrStyle.qr_corners_dot_gradient_rotation, 0, undefined, undefined),
colorStops: [
{ offset: 0, color: normalizeQrStyleColor(qrStyle.qr_corners_dot_gradient_color_1, normalizeQrStyleColor(qrStyle.qr_corners_dot_color, '#000000')) },
{ offset: 1, color: normalizeQrStyleColor(qrStyle.qr_corners_dot_gradient_color_2, '#ffffff') }
]
} : null;
return {
width: QR_PNG_WIDTH,
height: QR_PNG_WIDTH,
type: 'canvas',
data: text,
margin: normalizeQrStyleNumber(qrStyle.qr_margin, 10, 0, undefined),
qrOptions: {},
dotsOptions: {
type: String(qrStyle.qr_dots_type || 'square').trim() || 'square',
color: normalizeQrStyleColor(qrStyle.qr_dots_color, '#000000'),
gradient: dotsGradient || undefined
},
cornersSquareOptions: {
type: String(qrStyle.qr_corners_square_type || 'square').trim() || 'square',
color: normalizeQrStyleColor(qrStyle.qr_corners_square_color, '#000000'),
gradient: cornersSquareGradient || undefined
},
cornersDotOptions: {
type: String(qrStyle.qr_corners_dot_type || 'square').trim() || 'square',
color: normalizeQrStyleColor(qrStyle.qr_corners_dot_color, '#000000'),
gradient: cornersDotGradient || undefined
},
backgroundOptions: {
color: qrStyle.qr_background_transparent ? 'transparent' : normalizeQrStyleColor(qrStyle.qr_background_color, '#ffffff')
},
image: String(qrStyle.qr_image || '').trim() || undefined,
imageOptions: {
hideBackgroundDots: Boolean(qrStyle.qr_image_hide_background_dots),
imageSize: normalizeQrStyleNumber(qrStyle.qr_image_size, 0.4, 0, 1),
margin: normalizeQrStyleNumber(qrStyle.qr_image_margin, 5, 0, undefined)
}
};
}
async function createStyledQrCodeDataUrl(value) {
const source = value && typeof value === 'object' ? value : { value: value };
const options = buildQrStylingOptions(source);
if (!options.data) {
return '';
}
return svgToDataUrl(await createStyledQrCodeSvg(options.data));
}
async function createStyledQrCodeSvg(value) {
const source = value && typeof value === 'object' ? value : { value: value };
const options = buildQrStylingOptions(source);
if (!options.data) {
return '';
}
return renderStyledQrRawData(options, 'svg');
}
async function createQrCodeSvg(value) {
return createStyledQrCodeSvg(value);
}
async function createQrCodeDataUrl(value) {
return createStyledQrCodeDataUrl(value);
}
async function buildQrCodeContent(value, options) {
const source = value && typeof value === 'object' ? value : { value: value };
const forcePreviewRefresh = Boolean(options && options.forcePreviewRefresh);
const text = String(source.value === undefined || source.value === null ? '' : source.value).trim();
const hasBooleanField = function (key) {
return Object.prototype.hasOwnProperty.call(source, key);
};
const margin = Number(source.qr_margin);
const normalizeHex = function (value) {
const raw = String(value === undefined || value === null ? '' : value).trim();
return raw || undefined;
};
const normalizeNumber = function (value, min, max, round) {
const parsed = Number(value);
if (!Number.isFinite(parsed)) {
return undefined;
}
let next = parsed;
if (round) {
next = Math.round(next);
}
if (typeof min === 'number') {
next = Math.max(min, next);
}
if (typeof max === 'number') {
next = Math.min(max, next);
}
return next;
};
const style = {
qr_margin: Number.isFinite(margin) && margin >= 0 ? Math.round(margin) : undefined,
qr_border_radius: Number.isFinite(Number(source.qr_border_radius)) ? Math.max(0, Math.round(Number(source.qr_border_radius))) : undefined,
qr_background_color: String(source.qr_background_color === undefined || source.qr_background_color === null ? '' : source.qr_background_color).trim() || undefined,
qr_background_transparent: hasBooleanField('qr_background_transparent') ? Boolean(source.qr_background_transparent) : undefined,
qr_background_color_mode: 'single',
qr_background_gradient_type: String(source.qr_background_gradient_type === undefined || source.qr_background_gradient_type === null ? '' : source.qr_background_gradient_type).trim() || undefined,
qr_background_gradient_rotation: normalizeNumber(source.qr_background_gradient_rotation),
qr_background_gradient_color_1: normalizeHex(source.qr_background_gradient_color_1),
qr_background_gradient_color_2: normalizeHex(source.qr_background_gradient_color_2),
qr_dots_color: String(source.qr_dots_color === undefined || source.qr_dots_color === null ? '' : source.qr_dots_color).trim() || undefined,
qr_dots_type: String(source.qr_dots_type === undefined || source.qr_dots_type === null ? '' : source.qr_dots_type).trim() || undefined,
qr_dots_color_mode: String(source.qr_dots_color_mode === undefined || source.qr_dots_color_mode === null ? '' : source.qr_dots_color_mode).trim() || undefined,
qr_dots_gradient_type: String(source.qr_dots_gradient_type === undefined || source.qr_dots_gradient_type === null ? '' : source.qr_dots_gradient_type).trim() || undefined,
qr_dots_gradient_rotation: normalizeNumber(source.qr_dots_gradient_rotation),
qr_dots_gradient_color_1: normalizeHex(source.qr_dots_gradient_color_1),
qr_dots_gradient_color_2: normalizeHex(source.qr_dots_gradient_color_2),
qr_corners_square_color: String(source.qr_corners_square_color === undefined || source.qr_corners_square_color === null ? '' : source.qr_corners_square_color).trim() || undefined,
qr_corners_square_type: String(source.qr_corners_square_type === undefined || source.qr_corners_square_type === null ? '' : source.qr_corners_square_type).trim() || undefined,
qr_corners_square_color_mode: String(source.qr_corners_square_color_mode === undefined || source.qr_corners_square_color_mode === null ? '' : source.qr_corners_square_color_mode).trim() || undefined,
qr_corners_square_gradient_type: String(source.qr_corners_square_gradient_type === undefined || source.qr_corners_square_gradient_type === null ? '' : source.qr_corners_square_gradient_type).trim() || undefined,
qr_corners_square_gradient_rotation: normalizeNumber(source.qr_corners_square_gradient_rotation),
qr_corners_square_gradient_color_1: normalizeHex(source.qr_corners_square_gradient_color_1),
qr_corners_square_gradient_color_2: normalizeHex(source.qr_corners_square_gradient_color_2),
qr_corners_dot_color: String(source.qr_corners_dot_color === undefined || source.qr_corners_dot_color === null ? '' : source.qr_corners_dot_color).trim() || undefined,
qr_corners_dot_type: String(source.qr_corners_dot_type === undefined || source.qr_corners_dot_type === null ? '' : source.qr_corners_dot_type).trim() || undefined,
qr_corners_dot_color_mode: String(source.qr_corners_dot_color_mode === undefined || source.qr_corners_dot_color_mode === null ? '' : source.qr_corners_dot_color_mode).trim() || undefined,
qr_corners_dot_gradient_type: String(source.qr_corners_dot_gradient_type === undefined || source.qr_corners_dot_gradient_type === null ? '' : source.qr_corners_dot_gradient_type).trim() || undefined,
qr_corners_dot_gradient_rotation: normalizeNumber(source.qr_corners_dot_gradient_rotation),
qr_corners_dot_gradient_color_1: normalizeHex(source.qr_corners_dot_gradient_color_1),
qr_corners_dot_gradient_color_2: normalizeHex(source.qr_corners_dot_gradient_color_2),
qr_image: String(source.qr_image === undefined || source.qr_image === null ? '' : source.qr_image).trim() || undefined,
qr_image_size: Number.isFinite(Number(source.qr_image_size)) ? Math.max(0, Math.min(1, Number(source.qr_image_size))) : undefined,
qr_image_margin: Number.isFinite(Number(source.qr_image_margin)) ? Math.max(0, Math.round(Number(source.qr_image_margin))) : undefined,
qr_image_hide_background_dots: hasBooleanField('qr_image_hide_background_dots') ? Boolean(source.qr_image_hide_background_dots) : undefined
};
const content = {
type: 'qr-code',
value: text
};
Object.keys(style).forEach((key) => {
if (style[key] !== undefined) {
content[key] = style[key];
}
});
content.qr_background_use_gradient = false;
content.qr_dots_use_gradient = content.qr_dots_gradient_type && content.qr_dots_gradient_type !== 'none';
content.qr_corners_square_use_gradient = content.qr_corners_square_gradient_type && content.qr_corners_square_gradient_type !== 'none';
content.qr_corners_dot_use_gradient = content.qr_corners_dot_gradient_type && content.qr_corners_dot_gradient_type !== 'none';
const svg = String(source.qr_svg === undefined || source.qr_svg === null ? '' : source.qr_svg).trim();
if (svg) {
content.qr_svg = svg;
}
const preview = forcePreviewRefresh ? '' : String(source.qr_preview === undefined || source.qr_preview === null ? '' : source.qr_preview).trim();
if (preview) {
content.qr_preview = preview;
}
if (text && !content.qr_preview) {
const generatedSvg = await createQrCodeSvg(text);
if (generatedSvg) {
content.qr_svg = generatedSvg;
}
const generatedDataUrl = await createStyledQrCodeDataUrl(content);
if (generatedDataUrl) {
content.qr_preview = generatedDataUrl;
}
}
return content;
}
module.exports = {
createQrCodeSvg,
createStyledQrCodeSvg,
createStyledQrCodeDataUrl,
createQrCodeDataUrl,
buildQrCodeContent
};
+10 -4
View File
@@ -2,11 +2,17 @@
const http = require('http');
const https = require('https');
const { fetchPagedRows } = require('./utils');
const { fetchPagedRows, validateMaxLength } = require('./utils');
const NAME_MAX_LENGTH = 255;
const URL_MAX_LENGTH = 1024;
function normalizeUpdateIntervalUnit(value) {
const unit = String(value || '').trim().toLowerCase();
return unit === 'seconds' ? 'seconds' : 'minutes';
if (unit === 'seconds' || unit === 'minutes' || unit === 'hours') {
return unit;
}
return 'minutes';
}
async function fetchRssFeedsData(pool) {
@@ -255,8 +261,8 @@ async function replaceRssFeedItems(connection, rssFeedId, items) {
function buildRssFeedPayload(req, existingRssFeed) {
const fallback = existingRssFeed || {};
const name = String(req.body.name || fallback.name || '').trim();
const feedUrl = String(req.body.feed_url || req.body.feedUrl || fallback.feed_url || '').trim();
const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'RSS feed name');
const feedUrl = validateMaxLength(req.body.feed_url || req.body.feedUrl || fallback.feed_url || '', URL_MAX_LENGTH, 'RSS feed URL');
const updateIntervalValue = Math.max(1, Number(req.body.update_interval_value || req.body.updateIntervalValue || fallback.update_interval_value || 60));
const updateIntervalUnit = normalizeUpdateIntervalUnit(req.body.update_interval_unit || req.body.updateIntervalUnit || fallback.update_interval_unit || 'minutes');
const itemLimit = Math.max(1, Number(req.body.item_limit || req.body.itemLimit || fallback.item_limit || 1));
+57 -16
View File
@@ -13,6 +13,27 @@ function normalizePlayerBaseUrl(value) {
return String(value || '').trim().replace(/\/$/, '');
}
function getConfiguredPlayerIdentifier() {
return String(process.env.PLAYER_IDENTIFIER || process.env.PLAYER_DEVICE_ID || '').trim() || null;
}
async function fetchPlayerRecordByIdentifier(pool, identifier) {
const normalizedIdentifier = String(identifier || '').trim();
if (!normalizedIdentifier) {
return null;
}
const [rows] = await pool.query(
`SELECT id, identifier, public_base_url, internal_base_url, last_seen_at
FROM d_players
WHERE identifier = ?
LIMIT 1`,
[normalizedIdentifier]
);
return rows[0] || null;
}
function buildScreenPlayerUrl(screen, fallbackBaseUrl) {
const slug = String(screen && screen.slug || '').trim();
if (!slug) {
@@ -28,20 +49,21 @@ function buildScreenPlayerUrl(screen, fallbackBaseUrl) {
}
async function fetchScreenPlayerUrls(pool) {
const playerBaseUrl = await fetchPlayerPublicBaseUrl(pool);
if (!playerBaseUrl) {
return {};
}
const [rows] = await pool.query(`
SELECT s.slug, p.public_base_url
FROM d_screens s
LEFT JOIN d_players p ON p.device_id = s.player_id
WHERE p.public_base_url IS NOT NULL
AND TRIM(p.public_base_url) <> ''
ORDER BY p.modified_at DESC, s.slug ASC
SELECT slug
FROM d_screens
ORDER BY slug ASC
`);
const playerUrls = {};
rows.forEach(function (row) {
const slug = String(row && row.slug || '').trim();
const publicBaseUrl = normalizePlayerBaseUrl(row && row.public_base_url);
const playerUrl = buildScreenPlayerUrl({ slug: slug }, publicBaseUrl);
const playerUrl = buildScreenPlayerUrl({ slug: slug }, playerBaseUrl);
if (slug && playerUrl && !playerUrls[slug]) {
playerUrls[slug] = playerUrl;
}
@@ -50,17 +72,33 @@ async function fetchScreenPlayerUrls(pool) {
return playerUrls;
}
async function fetchScreenPlayerRecord(pool, slug) {
async function fetchPlayerPublicBaseUrl(pool) {
const configuredPlayerIdentifier = getConfiguredPlayerIdentifier();
const [rows] = await pool.query(`
SELECT p.device_id, p.public_base_url, p.internal_base_url, p.last_seen_at
FROM d_screens s
JOIN d_players p ON p.device_id = s.player_id
WHERE s.slug = ?
ORDER BY p.modified_at DESC, p.device_id ASC
SELECT public_base_url
FROM d_players
WHERE identifier = ?
LIMIT 1
`, [slug]);
`, [configuredPlayerIdentifier]);
return rows[0] || null;
return normalizePlayerBaseUrl(rows[0] && rows[0].public_base_url) || null;
}
async function fetchScreenPlayerRecord(pool, slug) {
if (slug) {
const [rows] = await pool.query(
`SELECT slug
FROM d_screens
WHERE slug = ?
LIMIT 1`,
[slug]
);
if (!rows.length) {
return null;
}
}
return fetchPlayerRecordByIdentifier(pool, getConfiguredPlayerIdentifier());
}
async function uniqueScreenSlug(pool, baseSlug, excludeId) {
@@ -101,8 +139,11 @@ async function fetchScreenEditData(pool) {
module.exports = {
slugify,
normalizePlayerBaseUrl,
getConfiguredPlayerIdentifier,
fetchPlayerRecordByIdentifier,
buildScreenPlayerUrl,
fetchScreenPlayerUrls,
fetchPlayerPublicBaseUrl,
fetchScreenPlayerRecord,
uniqueScreenSlug,
fetchScreenById,
+278 -24
View File
@@ -1,40 +1,98 @@
// Slide data access helpers, including rich-text normalization and payload building.
const { fetchTemplateById } = require('./templates');
const { parseJsonSafe } = require('./utils');
const { parseJsonSafe, validateMaxLength } = require('./utils');
const TITLE_MAX_LENGTH = 255;
const { buildQrCodeContent } = require('./qr-code');
const ALLOWED_RICH_TEXT_TAGS = ['b', 'strong', 'i', 'em', 'u', 'br', 'p', 'div', 'ul', 'ol', 'li'];
const DEFAULT_FONT_SIZE = 32;
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'],
blockquote: ['class', 'style'],
div: ['class', 'style'],
figure: ['class', 'style'],
figcaption: ['class', 'style'],
h1: ['class', 'style'],
h2: ['class', 'style'],
h3: ['class', 'style'],
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
pre: ['class', 'style'],
span: ['class', 'style'],
table: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
tr: ['class', 'style'],
ul: ['class', 'style']
};
const allowed = allowedAttributes[tagName] || [];
if (!allowed.length) {
return '';
}
const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase();
if (!allowed.includes(lowerKey)) {
return '';
}
const value = doubleQuoted !== undefined ? doubleQuoted : singleQuoted !== undefined ? singleQuoted : bareValue !== undefined ? bareValue : '';
if (lowerKey === 'href' && /^(?:\s*javascript:|\s*data:)/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'style' && /(?:expression\s*\(|javascript:|url\s*\()/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'target') {
const targetValue = String(value || '').trim();
if (targetValue === '_blank') {
attrs.push(' target="_blank"');
if (!attrs.includes(' rel="noreferrer noopener"')) {
attrs.push(' rel="noreferrer noopener"');
}
return '';
}
}
attrs.push(' ' + lowerKey + '="' + String(value || '').replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;').replace(/'/g, '&#39;') + '"');
return '';
});
return attrs.join('');
}
function sanitizeRichText(html) {
let output = String(html || '');
output = output.replace(/<script[\s\S]*?<\/script>/gi, '');
output = output.replace(/<style[\s\S]*?<\/style>/gi, '');
return output.replace(/<[^>]+>/g, (tag) => {
const match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)(?:\s[^>]*)?>$/i);
const match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)([\s\S]*?)(\/?)>$/i);
if (!match) {
return '';
}
const closing = Boolean(match[1]);
const name = String(match[2] || '').toLowerCase();
const attrText = String(match[3] || '');
if (!ALLOWED_RICH_TEXT_TAGS.includes(name)) {
return '';
}
if (name === 'br') {
return '<br>';
if (closing) {
return `</${name}>`;
}
return closing ? `</${name}>` : `<${name}>`;
return `<${name}${sanitizeRichTextAttributes(name, attrText)}>`;
});
}
function normalizePlainText(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/<\s*br\s*\/?\s*>/gi, '\n')
.replace(/<[^>]*>/g, '')
.replace(/&nbsp;/gi, ' ')
.trim();
}
function stripEditorOnlyMarkup(value) {
return String(value || '')
.replace(/<pre[^>]*class="[^"]*api-region-sample-preview[^"]*"[^>]*>[\s\S]*?<\/pre>/gi, '')
@@ -111,9 +169,130 @@ function getTextRegionStyle(body, region, existingContent) {
};
}
function buildTemplateContent(template, body, filesByField, existingContent) {
function getQrRegionStyle(body, region, existingContent) {
const existing = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
const styleKeys = [
'qr_margin',
'qr_background_color',
'qr_background_transparent',
'qr_background_color_mode',
'qr_background_gradient_type',
'qr_background_gradient_rotation',
'qr_background_gradient_color_1',
'qr_background_gradient_color_2',
'qr_dots_color',
'qr_dots_type',
'qr_dots_color_mode',
'qr_dots_gradient_type',
'qr_dots_gradient_rotation',
'qr_dots_gradient_color_1',
'qr_dots_gradient_color_2',
'qr_corners_square_color',
'qr_corners_square_type',
'qr_corners_square_color_mode',
'qr_corners_square_gradient_type',
'qr_corners_square_gradient_rotation',
'qr_corners_square_gradient_color_1',
'qr_corners_square_gradient_color_2',
'qr_corners_dot_color',
'qr_corners_dot_type',
'qr_corners_dot_color_mode',
'qr_corners_dot_gradient_type',
'qr_corners_dot_gradient_rotation',
'qr_corners_dot_gradient_color_1',
'qr_corners_dot_gradient_color_2',
'qr_image',
'qr_image_size',
'qr_image_margin',
'qr_image_hide_background_dots',
'qr_border_radius'
];
const style = {};
styleKeys.forEach((key) => {
const fieldNames = [`region_${key}_${region.id}`, `${key}_${region.id}`];
let fieldName = fieldNames[0];
let hasSubmittedValue = false;
let submitted;
for (let index = 0; index < fieldNames.length; index += 1) {
const candidate = fieldNames[index];
if (Object.prototype.hasOwnProperty.call(body || {}, candidate)) {
fieldName = candidate;
hasSubmittedValue = true;
submitted = body[candidate];
break;
}
}
const value = String(submitted || '').trim();
if (key === 'qr_background_transparent' || key === 'qr_image_hide_background_dots') {
style[key] = hasSubmittedValue;
return;
}
if (key === 'qr_background_color_mode' || key === 'qr_dots_color_mode' || key === 'qr_corners_square_color_mode' || key === 'qr_corners_dot_color_mode' || key === 'qr_background_gradient_type' || key === 'qr_dots_gradient_type' || key === 'qr_corners_square_gradient_type' || key === 'qr_corners_dot_gradient_type') {
style[key] = value === 'none' ? 'none' : value;
return;
}
if (key === 'qr_image') {
style[key] = value;
return;
}
if (submitted === undefined) {
if (existing[key] !== undefined && existing[key] !== null && String(existing[key]).trim() !== '') {
style[key] = existing[key];
}
return;
}
if (value !== '') {
if (key === 'qr_margin') {
const parsedMargin = Number(value);
if (Number.isFinite(parsedMargin)) {
style[key] = Math.max(0, Math.round(parsedMargin));
}
return;
}
if (key === 'qr_image_size') {
const parsedSize = Number(value);
if (Number.isFinite(parsedSize)) {
style[key] = Math.max(0, Math.min(1, parsedSize));
}
return;
}
if (key === 'qr_image_margin' || key === 'qr_border_radius') {
const parsedImageMargin = Number(value);
if (Number.isFinite(parsedImageMargin)) {
style[key] = Math.max(0, Math.round(parsedImageMargin));
}
return;
}
style[key] = value;
}
});
return style;
}
async function getRssFeedItemCount(pool, feedId) {
const [rows] = await pool.query(
'SELECT COUNT(*) AS count FROM i_rss_feed_items WHERE rss_feed_id = ?',
[feedId]
);
return Number(rows && rows[0] && rows[0].count) || 0;
}
async function buildTemplateContent(pool, template, body, filesByField, existingContent) {
const content = {};
template.regions.forEach((region) => {
for (const region of template.regions) {
if (region.region_type === 'image') {
const uploaded = filesByField[`region_image_${region.id}`];
const existing = body[`existing_region_image_${region.id}`];
@@ -142,6 +321,24 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
type: 'webpage',
value: submitted === undefined ? current : String(submitted || '').trim()
};
} else if (region.region_type === 'qr-code') {
const uploadedImage = filesByField[`region_qr_image_${region.id}`];
const submitted = body[`region_qr_code_${region.id}`];
const submittedSvg = body[`region_qr_svg_${region.id}`];
const submittedPreview = body[`region_qr_preview_${region.id}`];
const existingImage = body[`existing_region_qr_image_${region.id}`];
const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
const nextValue = submitted === undefined ? String(current.value !== undefined ? current.value : current.qr_code || '').trim() : String(submitted || '').trim();
const qrStyle = getQrRegionStyle(body, region, existingContent);
delete qrStyle.qr_image;
content[region.region_key] = {
type: 'qr-code',
value: nextValue,
qr_svg: submittedSvg === undefined ? String(current.qr_svg || '').trim() : String(submittedSvg || '').trim(),
qr_preview: submittedPreview === undefined ? String(current.qr_preview || '').trim() : String(submittedPreview || '').trim(),
qr_image: uploadedImage ? `/media/uploads/${uploadedImage.filename}` : String(existingImage === undefined ? String(current.qr_image || '').trim() : String(existingImage || '').trim()),
...qrStyle
};
} else if (region.region_type === 'rtmp') {
const submitted = body[`region_rtmp_${region.id}`];
const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
@@ -166,6 +363,49 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
value: submitted === undefined ? String(current.value !== undefined ? current.value : current.text !== undefined ? current.text : '') : String(submitted || ''),
timezone: timezoneValue === undefined || timezoneValue === null ? String(current.timezone || current.time_zone || '') : String(timezoneValue || '').trim()
};
} else if (region.region_type === 'timetable') {
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id;
const generic = {};
const submittedText = body[`region_text_${region.id}`];
const normalizedText = submittedText === undefined ? String(current.text !== undefined ? current.text : current.value !== undefined ? current.value : '') : String(submittedText || '');
Object.keys(body || {}).forEach((key) => {
if (!key.startsWith('region_') || !key.endsWith(suffix)) {
return;
}
const field = key.slice('region_'.length, -suffix.length);
if (!field || field === 'type' || field === 'key' || field === 'name' || field === 'label') {
return;
}
generic[field] = body[key];
});
if (Object.prototype.hasOwnProperty.call(generic, 'timetable_display_mode')) {
generic.display_mode = generic.timetable_display_mode;
delete generic.timetable_display_mode;
}
if (Object.prototype.hasOwnProperty.call(generic, 'timetable_max_items')) {
generic.max_items = generic.timetable_max_items;
delete generic.timetable_max_items;
}
Object.keys(current).forEach((key) => {
if (generic[key] === undefined) {
generic[key] = current[key];
}
});
delete generic.timetable_display_mode;
delete generic.timetable_max_items;
generic.text = normalizedText;
generic.value = normalizedText;
generic.type = region.region_type;
content[region.region_key] = generic;
} else if (region.region_type === 'rss') {
const submitted = body[`region_text_${region.id}`];
const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
@@ -173,11 +413,13 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
const feedId = body[`region_rss_feed_id_${region.id}`];
const itemNumber = body[`region_rss_item_number_${region.id}`];
const parsedItemNumber = Math.max(1, Number(itemNumber || current.item_number || 1));
const normalizedFeedId = feedId === undefined || feedId === null || feedId === '' ? Number(current.feed_id || 0) : Number(feedId);
const itemCount = normalizedFeedId > 0 ? Math.max(1, await getRssFeedItemCount(pool, normalizedFeedId) || 1) : 1;
content[region.region_key] = {
type: 'rss',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))),
feed_id: feedId === undefined || feedId === null || feedId === '' ? (current.feed_id || null) : Number(feedId),
item_number: Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1,
feed_id: feedId === undefined || feedId === null ? (current.feed_id || null) : (feedId === '' ? null : Number(feedId)),
item_number: Math.min(itemCount, Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1),
variable_name: 'item',
font_family: style.font_family,
font_size: style.font_size,
@@ -194,7 +436,7 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
content[region.region_key] = {
type: 'api',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))),
source_id: sourceId === undefined || sourceId === null || sourceId === '' ? (current.source_id || null) : Number(sourceId),
source_id: sourceId === undefined || sourceId === null ? (current.source_id || null) : (sourceId === '' ? null : Number(sourceId)),
item_number: Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1,
items_path: itemsPath === undefined || itemsPath === null ? (current.items_path === undefined || current.items_path === null ? '' : String(current.items_path)) : String(itemsPath || '').trim(),
variable_name: 'item',
@@ -202,7 +444,7 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
font_size: style.font_size,
font_color: style.font_color
};
} else if (!['text', 'image', 'video', 'webpage', 'html', 'rtmp', 'rss', 'api'].includes(String(region.region_type || '').trim())) {
} else if (!['text', 'image', 'video', 'webpage', 'qr-code', 'html', 'rtmp', 'rss', 'api'].includes(String(region.region_type || '').trim())) {
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id;
const generic = {};
@@ -243,18 +485,18 @@ function buildTemplateContent(template, body, filesByField, existingContent) {
const style = getTextRegionStyle(body, region, existingContent);
content[region.region_key] = {
type: 'text',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? current : String(submitted || ''))),
value: sanitizeRichText(stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? current : String(submitted || '')))),
font_family: style.font_family,
font_size: style.font_size,
font_color: style.font_color
};
}
});
}
return content;
}
async function buildSlidePayload(pool, req, existingSlide) {
const title = String(req.body.title || '').trim();
const title = validateMaxLength(req.body.title || '', TITLE_MAX_LENGTH, 'Slide title');
const templateId = req.body.template_id ? Number(req.body.template_id) : null;
const filesByField = getFilesByField(req.files || []);
const template = templateId ? await fetchTemplateById(pool, templateId) : null;
@@ -273,10 +515,22 @@ async function buildSlidePayload(pool, req, existingSlide) {
}
if (template) {
const content = await buildTemplateContent(pool, template, req.body, filesByField, existingContent);
await Promise.all(Object.keys(content).map(async function (regionKey) {
const region = template.regions.find(function (item) {
return String(item.region_key || '').trim() === regionKey;
});
if (!region || region.region_type !== 'qr-code') {
return;
}
content[regionKey] = await buildQrCodeContent(content[regionKey]);
}));
return {
title,
templateId: template.id,
contentJson: JSON.stringify(buildTemplateContent(template, req.body, filesByField, existingContent))
contentJson: JSON.stringify(content)
};
}
+9 -42
View File
@@ -1,8 +1,11 @@
// Template data access helpers and region normalization logic.
const { parseJsonSafe, readFormArray } = require('./utils');
const { parseJsonSafe, readFormArray, validateMaxLength } = require('./utils');
const animationPresets = require('../web/public/js/templates/animation-presets');
const TEMPLATE_NAME_MAX_LENGTH = 255;
const REGION_NAME_MAX_LENGTH = 255;
function sanitizeBackgroundColor(value) {
const raw = String(value || '').trim();
if (/^#[0-9a-fA-F]{6}$/.test(raw) || /^#[0-9a-fA-F]{3}$/.test(raw)) {
@@ -137,10 +140,11 @@ function extractTemplateRegions(body) {
if (Array.isArray(parsed)) {
return parsed.map((region) => {
const regionType = normalizeTemplateRegionType(region.region_type);
const regionName = validateMaxLength(region.region_name || region.region_key || region.label || '', REGION_NAME_MAX_LENGTH, 'Region name');
return {
region_key: String(region.region_name || region.region_key || region.label || '').trim(),
region_key: regionName,
region_type: regionType,
label: String(region.region_name || region.label || region.region_key || '').trim(),
label: regionName,
lock_ratio: normalizeTemplateRegionLockRatio(region.lock_ratio),
animation_json: normalizeTemplateRegionAnimationConfig(region.animation_json),
x: Number(region.x || 0),
@@ -167,7 +171,7 @@ function extractTemplateRegions(body) {
const regions = [];
for (let i = 0; i < keys.length; i += 1) {
const name = String(names[i] || keys[i] || labels[i] || '').trim();
const name = validateMaxLength(names[i] || keys[i] || labels[i] || '', REGION_NAME_MAX_LENGTH, 'Region name');
const rawType = String(types[i] || 'text').trim();
const regionType = normalizeTemplateRegionType(rawType);
if (!name) {
@@ -190,43 +194,6 @@ function extractTemplateRegions(body) {
return regions;
}
function extractGenericRegionContent(region, body, filesByField, existingContent) {
const content = {};
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id;
Object.keys(body || {}).forEach((key) => {
if (!key.startsWith('region_') || !key.endsWith(suffix)) {
return;
}
const field = key.slice('region_'.length, -suffix.length);
if (!field || field === 'type' || field === 'key' || field === 'name' || field === 'label') {
return;
}
content[field] = body[key];
});
Object.keys(filesByField || {}).forEach((fieldName) => {
if (!fieldName.startsWith('region_') || !fieldName.endsWith(suffix)) {
return;
}
const field = fieldName.slice('region_'.length, -suffix.length);
if (!field) {
return;
}
content[field] = `/media/uploads/${filesByField[fieldName].filename}`;
});
Object.keys(current).forEach((key) => {
if (content[key] === undefined) {
content[key] = current[key];
}
});
content.type = region.region_type;
return content;
}
function getFilesByField(files) {
const map = {};
(files || []).forEach((file) => {
@@ -236,7 +203,7 @@ function getFilesByField(files) {
}
async function buildTemplatePayload(pool, req, existingTemplate) {
const name = String(req.body.name || '').trim();
const name = validateMaxLength(req.body.name || '', TEMPLATE_NAME_MAX_LENGTH, 'Template name');
const canvasSizeId = req.body.canvas_size_id ? Number(req.body.canvas_size_id) : null;
let canvasWidth = Math.max(1, Number((existingTemplate && existingTemplate.canvas_size_width) || 1920));
let canvasHeight = Math.max(1, Number((existingTemplate && existingTemplate.canvas_size_height) || 1080));
@@ -1,6 +1,26 @@
// Timetable group and entry data access helpers.
const { fetchPagedRows } = require('./utils');
const { fetchPagedRows, validateMaxLength } = require('./utils');
const NAME_MAX_LENGTH = 255;
const DESCRIPTION_MAX_LENGTH = 255;
const DEFAULT_TIME_ZONE = 'Europe/London';
function normalizeTimeZone(value, fallback) {
const raw = String(value || '').trim();
if (!raw) {
return String(fallback || DEFAULT_TIME_ZONE).trim() || DEFAULT_TIME_ZONE;
}
try {
new Intl.DateTimeFormat('en-GB', { timeZone: raw }).format(new Date());
return raw;
} catch (_error) {
const error = new Error('Timetable time zone is invalid.');
error.statusCode = 400;
throw error;
}
}
function normalizeDisplayMode(value) {
const mode = String(value || 'upcoming').trim().toLowerCase();
@@ -12,15 +32,15 @@ function normalizeDisplayMode(value) {
async function fetchTimetablesData(pool) {
const [timetableGroups] = await pool.query(`
SELECT g.id, g.name, g.short_description, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_schedule_groups g
SELECT g.id, g.name, g.short_description, g.timezone, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_timetable_groups g
ORDER BY g.modified_at DESC, g.id DESC
`);
const [timetableEntries] = await pool.query(`
SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by
FROM i_schedule_entries
FROM i_timetable_entries
ORDER BY schedule_group_id ASC, start_datetime ASC, id ASC
`);
@@ -47,17 +67,18 @@ async function fetchTimetablesData(pool) {
async function fetchTimetableGroupsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, {
selectSql: `SELECT g.id, g.name, g.short_description, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_schedule_groups g
selectSql: `SELECT g.id, g.name, g.short_description, g.timezone, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_timetable_groups g
ORDER BY g.modified_at DESC, g.id DESC`,
countSql: 'SELECT COUNT(*) AS count FROM i_schedule_groups',
countSql: 'SELECT COUNT(*) AS count FROM i_timetable_groups',
searchColumns: ['g.name', 'g.short_description'],
searchTerm: searchTerm,
sortColumns: {
name: 'g.name',
description: 'g.short_description',
timezone: 'g.timezone',
entries: 'entry_count',
next_start: 'next_start_datetime',
created: 'g.created_at',
@@ -74,7 +95,7 @@ async function fetchTimetableGroupsPage(pool, page, pageSize, searchTerm, sortKe
async function fetchTimetableGroupById(pool, id) {
const [rows] = await pool.query(
'SELECT id, name, short_description, created_at, modified_at, created_by, modified_by FROM i_schedule_groups WHERE id = ?',
'SELECT id, name, short_description, timezone, created_at, modified_at, created_by, modified_by FROM i_timetable_groups WHERE id = ?',
[id]
);
@@ -84,7 +105,7 @@ async function fetchTimetableGroupById(pool, id) {
async function fetchTimetableEntriesByGroupId(pool, timetableGroupId) {
const [rows] = await pool.query(
`SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by
FROM i_schedule_entries
FROM i_timetable_entries
WHERE schedule_group_id = ?
ORDER BY start_datetime ASC, id ASC`,
[timetableGroupId]
@@ -95,8 +116,9 @@ async function fetchTimetableEntriesByGroupId(pool, timetableGroupId) {
function buildTimetableGroupPayload(req, existingTimetableGroup) {
const fallback = existingTimetableGroup || {};
const name = String(req.body.name || fallback.name || '').trim();
const shortDescription = String(req.body.short_description || req.body.shortDescription || fallback.short_description || '').trim();
const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'Timetable group name');
const shortDescription = validateMaxLength(req.body.short_description || req.body.shortDescription || fallback.short_description || '', DESCRIPTION_MAX_LENGTH, 'Timetable group description');
const timezone = normalizeTimeZone(req.body.timezone || req.body.time_zone || fallback.timezone || DEFAULT_TIME_ZONE, fallback.timezone || DEFAULT_TIME_ZONE);
if (!name) {
const error = new Error('Timetable group name is required.');
@@ -106,7 +128,8 @@ function buildTimetableGroupPayload(req, existingTimetableGroup) {
return {
name: name,
shortDescription: shortDescription
shortDescription: shortDescription,
timezone: timezone
};
}
@@ -116,5 +139,6 @@ module.exports = {
fetchTimetableGroupsPage,
fetchTimetableGroupById,
fetchTimetableEntriesByGroupId,
buildTimetableGroupPayload
buildTimetableGroupPayload,
normalizeTimeZone
};
+100 -1
View File
@@ -24,6 +24,26 @@ function readFormArray(body, key) {
return [body[key]];
}
function validateMaxLength(value, maxLength, fieldName) {
const text = String(value || '').trim();
const limit = Number(maxLength);
if (Number.isFinite(limit) && limit > 0 && text.length > limit) {
const error = new Error(fieldName + ' must be ' + limit + ' characters or fewer.');
error.statusCode = 400;
throw error;
}
return text;
}
function truncateToMaxLength(value, maxLength) {
const text = String(value || '').trim();
const limit = Number(maxLength);
if (!Number.isFinite(limit) || limit <= 0 || text.length <= limit) {
return text;
}
return text.slice(0, limit);
}
function normalizePageNumber(value) {
const pageNumber = Math.floor(Number(value) || 1);
return Math.max(1, pageNumber);
@@ -201,6 +221,75 @@ function findTopLevelWhereIndex(sql) {
return lastWhereIndex;
}
function findTopLevelGroupByIndex(sql) {
const text = String(sql || '');
let depth = 0;
let inSingleQuote = false;
let inDoubleQuote = false;
let inBacktick = false;
let lastGroupByIndex = -1;
for (let index = 0; index < text.length; index += 1) {
const character = text[index];
const previousCharacter = index > 0 ? text[index - 1] : '';
if (inSingleQuote) {
if (character === '\'' && previousCharacter !== '\\') {
inSingleQuote = false;
}
continue;
}
if (inDoubleQuote) {
if (character === '"' && previousCharacter !== '\\') {
inDoubleQuote = false;
}
continue;
}
if (inBacktick) {
if (character === '`') {
inBacktick = false;
}
continue;
}
if (character === '\'') {
inSingleQuote = true;
continue;
}
if (character === '"') {
inDoubleQuote = true;
continue;
}
if (character === '`') {
inBacktick = true;
continue;
}
if (character === '(') {
depth += 1;
continue;
}
if (character === ')' && depth > 0) {
depth -= 1;
continue;
}
if (depth === 0 && /[gG]/.test(character)) {
const remaining = text.slice(index);
if (/^group\s+by\b/i.test(remaining)) {
lastGroupByIndex = index;
}
}
}
return lastGroupByIndex;
}
function buildSearchFilter(searchColumns, searchTerm) {
const columns = Array.isArray(searchColumns) ? searchColumns.map(function (column) {
return String(column || '').trim();
@@ -238,17 +327,24 @@ async function fetchPagedRows(pool, options) {
throw new Error('fetchPagedRows requires selectSql and countSql.');
}
const orderByIndex = findTopLevelOrderByIndex(selectSql);
const groupByIndex = findTopLevelGroupByIndex(selectSql);
let baseSelectSql = selectSql;
let orderBySql = '';
let groupBySql = '';
if (orderByIndex >= 0) {
baseSelectSql = selectSql.slice(0, orderByIndex).trim();
orderBySql = selectSql.slice(orderByIndex).trim();
}
if (groupByIndex >= 0 && (orderByIndex < 0 || groupByIndex < orderByIndex)) {
baseSelectSql = selectSql.slice(0, groupByIndex).trim();
groupBySql = selectSql.slice(groupByIndex, orderByIndex >= 0 ? orderByIndex : selectSql.length).trim();
}
const hasTopLevelWhere = findTopLevelWhereIndex(baseSelectSql) >= 0;
const searchClause = searchFilter.clause ? (hasTopLevelWhere ? searchFilter.clause.replace(/^\s*WHERE\s+/i, ' AND ') : searchFilter.clause) : '';
const filteredSelectSql = `${baseSelectSql}${searchClause}`;
const filteredSelectSql = `${baseSelectSql}${searchClause}${groupBySql ? ' ' + groupBySql : ''}`;
const countQuery = searchFilter.clause
? `SELECT COUNT(*) AS count FROM (${filteredSelectSql}) AS filtered_rows`
: countSql;
@@ -294,10 +390,13 @@ async function fetchDuplicateName(pool, tableName, name, excludeId, columnName)
module.exports = {
parseJsonSafe,
readFormArray,
validateMaxLength,
truncateToMaxLength,
normalizePageNumber,
normalizeSortDirection,
buildSortOrderClause,
findTopLevelOrderByIndex,
findTopLevelGroupByIndex,
buildSearchFilter,
fetchPagedRows,
fetchDuplicateName
+33 -10
View File
@@ -15,11 +15,19 @@ async function bootstrapDatabase(pool) {
}
for (const permission of PERMISSIONS) {
await pool.query(
`UPDATE a_permissions
SET name = ?, section_name = ?, description = ?, modified_by = ?
WHERE permission_key = ?`,
[permission.name, permission.sectionName, permission.description || null, null, permission.key]
);
await pool.query(
`INSERT INTO a_permissions (permission_key, name, section_name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, ?, ?)
ON DUPLICATE KEY UPDATE name = VALUES(name), section_name = VALUES(section_name), description = VALUES(description), modified_by = VALUES(modified_by)` ,
[permission.key, permission.name, permission.sectionName, permission.description || null, null, null]
SELECT ?, ?, ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_permissions WHERE permission_key = ?
)`,
[permission.key, permission.name, permission.sectionName, permission.description || null, null, null, permission.key]
);
}
@@ -35,22 +43,37 @@ async function bootstrapDatabase(pool) {
);
}
await pool.query('UPDATE a_users SET name = username WHERE name IS NULL OR name = ""');
const [legacyRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', ['administrators']);
const [currentRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', [DEFAULT_ROLE.key]);
if (legacyRoleRows.length && !currentRoleRows.length) {
await pool.query(
`UPDATE a_roles
SET role_key = ?, name = ?, description = ?, modified_by = ?
WHERE role_key = ?`,
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, 'administrators']
);
}
await pool.query(
`INSERT INTO a_roles (role_key, name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, ?)
ON DUPLICATE KEY UPDATE name = VALUES(name), description = VALUES(description), modified_by = VALUES(modified_by)`,
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, null]
SELECT ?, ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_roles WHERE role_key = ?
)`,
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, null, DEFAULT_ROLE.key]
);
const [defaultRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', [DEFAULT_ROLE.key]);
const defaultRoleId = defaultRoleRows.length ? Number(defaultRoleRows[0].id) : null;
if (defaultRoleId) {
await pool.query(
`INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT ?, id, NULL, NULL FROM a_permissions`,
[defaultRoleId]
`INSERT INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT ?, permissions.id, NULL, NULL
FROM a_permissions permissions
LEFT JOIN a_role_permissions existing
ON existing.role_id = ? AND existing.permission_id = permissions.id
WHERE existing.id IS NULL`,
[defaultRoleId, defaultRoleId]
);
}
+100 -13
View File
@@ -1,6 +1,27 @@
const { version: appVersion } = require('#root/package.json');
const { compareVersions, detectSchemaVersion, getPendingMigrations, recordSchemaVersion, runMigrations } = require('./migrations');
// Snapshot only: keep this file aligned with the current schema state.
async function ensureSchema(pool, options) {
await pool.query(`
const schemaLockName = 'pulse_signage_schema_lock';
const schemaConnection = await pool.getConnection();
try {
pool = schemaConnection;
const [lockRows] = await pool.query('SELECT GET_LOCK(?, 120) AS lock_acquired', [schemaLockName]);
if (!Number(lockRows && lockRows[0] && lockRows[0].lock_acquired)) {
throw new Error('Unable to acquire the schema migration lock.');
}
try {
const currentVersion = await detectSchemaVersion(pool);
const pendingMigrations = await getPendingMigrations(pool, { currentVersion: currentVersion });
const updateRequired = pendingMigrations.length > 0;
console.info('[schema] previous=' + currentVersion + ' current=' + appVersion + ' update=' + (updateRequired ? 'yes' : 'no'));
await pool.query(`
CREATE TABLE IF NOT EXISTS c_canvas_sizes (
id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL,
@@ -116,13 +137,24 @@ async function ensureSchema(pool, options) {
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS d_players (
id INT AUTO_INCREMENT PRIMARY KEY,
identifier VARCHAR(128) NOT NULL UNIQUE,
public_base_url VARCHAR(512) NULL,
internal_base_url VARCHAR(512) NULL,
last_seen_at TIMESTAMP NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS d_screens (
id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL,
slug VARCHAR(255) NOT NULL UNIQUE,
playlist_id INT NULL,
player_id INT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -152,13 +184,14 @@ async function ensureSchema(pool, options) {
await pool.query(`
CREATE TABLE IF NOT EXISTS d_announcement_screens (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
announcement_id INT NOT NULL,
screen_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
PRIMARY KEY (announcement_id, screen_id),
UNIQUE KEY uq_announcement_screens_pair (announcement_id, screen_id),
INDEX idx_announcement_screens_screen_id (screen_id),
CONSTRAINT fk_announcement_screens_announcement FOREIGN KEY (announcement_id) REFERENCES d_announcements(id) ON DELETE CASCADE,
CONSTRAINT fk_announcement_screens_screen FOREIGN KEY (screen_id) REFERENCES d_screens(id) ON DELETE CASCADE
@@ -200,6 +233,20 @@ async function ensureSchema(pool, options) {
id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL,
api_url VARCHAR(1024) NOT NULL,
request_method VARCHAR(10) NOT NULL DEFAULT 'GET',
request_body_json MEDIUMTEXT NULL,
auth_method VARCHAR(32) NOT NULL DEFAULT 'none',
auth_username VARCHAR(255) NULL,
auth_password MEDIUMTEXT NULL,
auth_bearer_token MEDIUMTEXT NULL,
auth_header_name VARCHAR(255) NULL,
auth_header_value MEDIUMTEXT NULL,
token_url VARCHAR(1024) NULL,
token_request_body_json MEDIUMTEXT NULL,
token_response_path VARCHAR(255) NULL DEFAULT 'access_token',
token_header_name VARCHAR(255) NULL DEFAULT 'Authorization',
token_header_prefix VARCHAR(64) NULL DEFAULT 'Bearer',
items_path VARCHAR(255) NULL,
update_interval_value INT NOT NULL DEFAULT 60,
update_interval_unit VARCHAR(10) NOT NULL DEFAULT 'minutes',
last_pulled_at TIMESTAMP NULL,
@@ -215,10 +262,11 @@ async function ensureSchema(pool, options) {
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS i_schedule_groups (
CREATE TABLE IF NOT EXISTS i_timetable_groups (
id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL,
short_description VARCHAR(255) NULL,
timezone VARCHAR(64) NOT NULL DEFAULT 'Europe/London',
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -227,7 +275,7 @@ async function ensureSchema(pool, options) {
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS i_schedule_entries (
CREATE TABLE IF NOT EXISTS i_timetable_entries (
id INT AUTO_INCREMENT PRIMARY KEY,
schedule_group_id INT NOT NULL,
title VARCHAR(255) NOT NULL,
@@ -238,14 +286,15 @@ async function ensureSchema(pool, options) {
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
CONSTRAINT fk_schedule_entries_group FOREIGN KEY (schedule_group_id) REFERENCES i_schedule_groups(id) ON DELETE CASCADE,
INDEX idx_schedule_entries_group_start (schedule_group_id, start_datetime)
CONSTRAINT fk_timetable_entries_group FOREIGN KEY (schedule_group_id) REFERENCES i_timetable_groups(id) ON DELETE CASCADE,
INDEX idx_timetable_entries_group_start (schedule_group_id, start_datetime)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS d_onboarding_devices (
device_id VARCHAR(128) PRIMARY KEY,
id BIGINT AUTO_INCREMENT PRIMARY KEY,
device_id VARCHAR(128) NOT NULL UNIQUE,
client_name VARCHAR(255) NULL,
screen_id INT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
@@ -264,6 +313,8 @@ async function ensureSchema(pool, options) {
password_hash CHAR(64) NOT NULL,
password_salt VARCHAR(64) NOT NULL,
password_iterations INT NOT NULL,
must_change_password TINYINT(1) NOT NULL DEFAULT 0,
account_locked TINYINT(1) NOT NULL DEFAULT 0,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -300,13 +351,14 @@ async function ensureSchema(pool, options) {
await pool.query(`
CREATE TABLE IF NOT EXISTS a_role_permissions (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
role_id INT NOT NULL,
permission_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
PRIMARY KEY (role_id, permission_id),
UNIQUE KEY uq_role_permissions_pair (role_id, permission_id),
CONSTRAINT fk_role_permissions_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE,
CONSTRAINT fk_role_permissions_permission FOREIGN KEY (permission_id) REFERENCES a_permissions(id) ON DELETE CASCADE
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
@@ -314,13 +366,14 @@ async function ensureSchema(pool, options) {
await pool.query(`
CREATE TABLE IF NOT EXISTS a_user_roles (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
user_id INT NOT NULL,
role_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
PRIMARY KEY (user_id, role_id),
UNIQUE KEY uq_user_roles_pair (user_id, role_id),
CONSTRAINT fk_user_roles_user FOREIGN KEY (user_id) REFERENCES a_users(id) ON DELETE CASCADE,
CONSTRAINT fk_user_roles_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
@@ -328,8 +381,11 @@ async function ensureSchema(pool, options) {
await pool.query(`
CREATE TABLE IF NOT EXISTS a_sessions (
session_hash CHAR(64) PRIMARY KEY,
id BIGINT AUTO_INCREMENT PRIMARY KEY,
session_hash CHAR(64) NOT NULL UNIQUE,
user_id INT NOT NULL,
ip_address VARCHAR(255) NULL,
user_agent VARCHAR(512) NULL,
expires_at DATETIME NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
@@ -339,6 +395,18 @@ async function ensureSchema(pool, options) {
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS a_login_attempts (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
rate_key VARCHAR(600) NOT NULL UNIQUE,
failed_count INT NOT NULL DEFAULT 0,
last_failed_at DATETIME NULL,
locked_until DATETIME NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS o_background_tasks (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
@@ -360,8 +428,27 @@ async function ensureSchema(pool, options) {
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
const { runMigrations } = require('./migrations');
await runMigrations(pool, options);
await pool.query(`
CREATE TABLE IF NOT EXISTS o_app_settings (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
setting_key VARCHAR(191) NOT NULL UNIQUE,
setting_value JSON NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await runMigrations(pool, Object.assign({}, options, { currentVersion: currentVersion }));
await recordSchemaVersion(pool, appVersion);
} finally {
await pool.query('SELECT RELEASE_LOCK(?)', [schemaLockName]).catch(function () {
});
}
} finally {
schemaConnection.release();
}
}
module.exports = {
+555 -35
View File
@@ -1,4 +1,7 @@
const { version: appVersion } = require('#root/package.json');
const TIMETABLE_TIME_ZONE = 'Europe/London';
const APP_STATE_TABLE = 'o_app_state';
const APP_STATE_SCHEMA_VERSION_KEY = 'schema_version';
const VERSIONED_MIGRATIONS = [
{
@@ -19,39 +22,35 @@ const VERSIONED_MIGRATIONS = [
`);
}
// Seed the singleton player row used by the current one-player model.
// For multi-player support, this seed and the hardcoded screen_id/player_id mapping will need to be replaced.
await pool.query(`INSERT IGNORE INTO d_players (device_id) VALUES ('1')`);
// Store the player pointer on screens so we can resolve the player without needing a player-side screen_id.
// This is the singleton-player shortcut; a multi-player model should make this relational instead of hardcoded to '1'.
if (!(await columnExists(pool, 'd_screens', 'player_id'))) {
await pool.query("ALTER TABLE d_screens ADD COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
} else {
await pool.query("UPDATE d_screens SET player_id = '1' WHERE player_id IS NULL OR player_id <> '1'");
await pool.query("ALTER TABLE d_screens ADD COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
} else {
await pool.query("UPDATE d_screens SET player_id = '1' WHERE player_id IS NULL OR player_id <> '1'");
const [playerColumnNullableRows] = await pool.query(
`SELECT COUNT(*) AS nullable_count
FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens'
AND COLUMN_NAME = 'player_id'
AND IS_NULLABLE = 'YES'`
);
if (Number(playerColumnNullableRows && playerColumnNullableRows[0] && playerColumnNullableRows[0].nullable_count) > 0) {
await pool.query("ALTER TABLE d_screens MODIFY COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
}
}
const [screenPlayerUniqueRows] = await pool.query(
`SELECT COUNT(*) AS index_count
FROM information_schema.STATISTICS
const [playerColumnNullableRows] = await pool.query(
`SELECT COUNT(*) AS nullable_count
FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens'
AND INDEX_NAME = 'uq_screens_player_id'`
AND COLUMN_NAME = 'player_id'
AND IS_NULLABLE = 'YES'`
);
if (Number(screenPlayerUniqueRows && screenPlayerUniqueRows[0] && screenPlayerUniqueRows[0].index_count) > 0) {
await pool.query('ALTER TABLE d_screens DROP INDEX uq_screens_player_id');
if (Number(playerColumnNullableRows && playerColumnNullableRows[0] && playerColumnNullableRows[0].nullable_count) > 0) {
await pool.query("ALTER TABLE d_screens MODIFY COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
}
}
const [screenPlayerUniqueRows] = await pool.query(
`SELECT COUNT(*) AS index_count
FROM information_schema.STATISTICS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens'
AND INDEX_NAME = 'uq_screens_player_id'`
);
if (Number(screenPlayerUniqueRows && screenPlayerUniqueRows[0] && screenPlayerUniqueRows[0].index_count) > 0) {
await pool.query('ALTER TABLE d_screens DROP INDEX uq_screens_player_id');
}
// Recreate the screen-to-player foreign key after the column exists and legacy data is copied over.
@@ -60,7 +59,6 @@ const VERSIONED_MIGRATIONS = [
if (await columnExists(pool, 'c_template_regions', 'font_family')) {
await pool.query('ALTER TABLE c_template_regions DROP COLUMN font_family');
}
}
},
{
@@ -212,6 +210,301 @@ const VERSIONED_MIGRATIONS = [
run: async function (pool) {
await ensureColumn(pool, 'c_template_regions', 'animation_json', 'JSON NULL', 'lock_ratio');
}
},
{
version: '2.6.2',
label: 'v2.6.2 player identity schema',
run: async function (pool) {
if (!(await columnExists(pool, 'd_players', 'device_id'))) {
await dropForeignKeyIfExists(pool, 'd_screens', 'player_id');
if (!(await columnExists(pool, 'd_players', 'identifier'))) {
await ensureColumn(pool, 'd_players', 'identifier', 'VARCHAR(128) NOT NULL UNIQUE', 'id');
}
if (!(await columnExists(pool, 'd_players', 'id'))) {
await ensureColumn(pool, 'd_players', 'id', 'INT NOT NULL AUTO_INCREMENT', null);
await pool.query('ALTER TABLE d_players ADD PRIMARY KEY (id)');
} else if (!(await columnIsAutoIncrement(pool, 'd_players', 'id'))) {
await pool.query('ALTER TABLE d_players MODIFY COLUMN id INT NOT NULL AUTO_INCREMENT');
}
await pool.query('ALTER TABLE d_screens MODIFY COLUMN player_id INT NULL AFTER playlist_id');
return;
}
await dropForeignKeyIfExists(pool, 'd_screens', 'player_id');
await pool.query('DROP TABLE IF EXISTS d_players_rebuild');
await pool.query(`
CREATE TABLE d_players_rebuild (
id INT NOT NULL AUTO_INCREMENT PRIMARY KEY,
identifier VARCHAR(128) NOT NULL UNIQUE,
public_base_url VARCHAR(512) NULL,
internal_base_url VARCHAR(512) NULL,
last_seen_at TIMESTAMP NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
INSERT INTO d_players_rebuild (identifier, public_base_url, internal_base_url, last_seen_at, created_at, modified_at)
SELECT DISTINCT
device_id AS identifier,
public_base_url,
internal_base_url,
last_seen_at,
created_at,
modified_at
FROM d_players
ORDER BY COALESCE(created_at, modified_at, device_id), device_id
`);
await pool.query('DROP TEMPORARY TABLE IF EXISTS d_player_id_map');
await pool.query(`
CREATE TEMPORARY TABLE d_player_id_map AS
SELECT old_players.device_id AS old_device_id, rebuilt_players.id AS new_player_id
FROM d_players old_players
JOIN d_players_rebuild rebuilt_players ON rebuilt_players.identifier = old_players.device_id
`);
await pool.query(
`UPDATE d_screens s
JOIN d_player_id_map m ON m.old_device_id = CAST(s.player_id AS CHAR)
SET s.player_id = m.new_player_id
WHERE s.player_id IS NOT NULL`
);
await pool.query('DROP TABLE d_players');
await pool.query('RENAME TABLE d_players_rebuild TO d_players');
await pool.query('ALTER TABLE d_screens MODIFY COLUMN player_id INT NULL AFTER playlist_id');
return;
}
},
{
version: '2.6.3',
label: 'v2.6.3 screen-player fk removal',
run: async function (pool) {
await dropForeignKeyIfExists(pool, 'd_screens', 'player_id');
if (await columnExists(pool, 'd_screens', 'player_id')) {
await pool.query('ALTER TABLE d_screens MODIFY COLUMN player_id INT NULL AFTER playlist_id');
}
}
},
{
version: '2.6.4',
label: 'v2.6.4 drop screen player id',
run: async function (pool) {
await dropForeignKeyIfExists(pool, 'd_screens', 'player_id');
await dropColumnIfExists(pool, 'd_screens', 'player_id');
}
},
{
version: '2.6.16',
label: 'v2.6.16 timetable timezone schema',
run: async function (pool) {
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const tableName = timetableGroupsExists ? 'i_timetable_groups' : scheduleGroupsExists ? 'i_schedule_groups' : null;
if (!tableName) {
return;
}
await ensureColumn(pool, tableName, 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
}
},
{
version: '2.6.17',
label: 'v2.6.17 timetable europe/london conversion',
run: async function (pool) {
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const timetableEntriesExists = await tableExists(pool, 'i_timetable_entries');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const scheduleEntriesExists = await tableExists(pool, 'i_schedule_entries');
const groupTableName = timetableGroupsExists ? 'i_timetable_groups' : scheduleGroupsExists ? 'i_schedule_groups' : null;
const entryTableName = timetableEntriesExists ? 'i_timetable_entries' : scheduleEntriesExists ? 'i_schedule_entries' : null;
if (!groupTableName || !entryTableName) {
return;
}
await ensureColumn(pool, groupTableName, 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
await pool.query('UPDATE ' + groupTableName + ' SET timezone = ?', [TIMETABLE_TIME_ZONE]);
const [rows] = await pool.query('SELECT id, start_datetime, end_datetime FROM ' + entryTableName + ' ORDER BY id ASC');
for (const row of rows) {
const startDate = convertMigrationDateTimeFromTimeZone(row.start_datetime, TIMETABLE_TIME_ZONE);
const endDate = row.end_datetime ? convertMigrationDateTimeFromTimeZone(row.end_datetime, TIMETABLE_TIME_ZONE) : null;
await pool.query(
'UPDATE ' + entryTableName + ' SET start_datetime = ?, end_datetime = ? WHERE id = ?',
[formatMigrationDateTimeUtc(startDate), endDate ? formatMigrationDateTimeUtc(endDate) : null, row.id]
);
}
}
},
{
version: '2.6.18',
label: 'v2.6.18 timetable table rename',
run: async function (pool) {
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
if (scheduleGroupsExists) {
if (!timetableGroupsExists) {
await pool.query('RENAME TABLE i_schedule_groups TO i_timetable_groups, i_schedule_entries TO i_timetable_entries');
await ensureColumn(pool, 'i_timetable_groups', 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
return;
}
await ensureColumn(pool, 'i_timetable_groups', 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
await pool.query(`
INSERT IGNORE INTO i_timetable_groups (id, name, short_description, timezone, created_at, created_by, modified_at, modified_by)
SELECT id, name, short_description, 'Europe/London' AS timezone, created_at, created_by, modified_at, modified_by
FROM i_schedule_groups
ORDER BY id ASC
`);
await pool.query(`
INSERT IGNORE INTO i_timetable_entries (id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, created_by, modified_at, modified_by)
SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, created_by, modified_at, modified_by
FROM i_schedule_entries
ORDER BY schedule_group_id ASC, start_datetime ASC, id ASC
`);
const [groupRows] = await pool.query('SELECT COALESCE(MAX(id), 0) AS max_id FROM i_timetable_groups');
const [entryRows] = await pool.query('SELECT COALESCE(MAX(id), 0) AS max_id FROM i_timetable_entries');
const nextGroupId = Number(groupRows && groupRows[0] && groupRows[0].max_id) + 1;
const nextEntryId = Number(entryRows && entryRows[0] && entryRows[0].max_id) + 1;
await pool.query('ALTER TABLE i_timetable_groups AUTO_INCREMENT = ' + nextGroupId);
await pool.query('ALTER TABLE i_timetable_entries AUTO_INCREMENT = ' + nextEntryId);
await pool.query('DROP TABLE i_schedule_entries');
await pool.query('DROP TABLE i_schedule_groups');
}
}
},
{
version: '2.8.0',
label: 'v2.8.0 combined application schema',
run: async function (pool) {
await pool.query(`
CREATE TABLE IF NOT EXISTS o_app_settings (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
setting_key VARCHAR(191) NOT NULL UNIQUE,
setting_value JSON NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS o_app_state (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
state_key VARCHAR(191) NOT NULL UNIQUE,
state_value MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
const numericIdTables = [
['d_announcement_screens', 'uq_announcement_screens_pair', '(announcement_id, screen_id)'],
['d_onboarding_devices', 'uq_onboarding_devices_device_id', '(device_id)'],
['a_role_permissions', 'uq_role_permissions_pair', '(role_id, permission_id)'],
['a_user_roles', 'uq_user_roles_pair', '(user_id, role_id)'],
['a_sessions', 'uq_sessions_hash', '(session_hash)'],
['o_app_state', 'uq_app_state_key', '(state_key)']
];
for (const [tableName, uniqueKeyName, uniqueColumns] of numericIdTables) {
if (!(await tableExists(pool, tableName)) || await columnExists(pool, tableName, 'id')) {
continue;
}
await pool.query('ALTER TABLE ' + tableName + ' DROP PRIMARY KEY, ADD COLUMN id BIGINT NOT NULL AUTO_INCREMENT PRIMARY KEY FIRST, ADD UNIQUE KEY ' + uniqueKeyName + ' ' + uniqueColumns);
}
await ensureColumn(pool, 'a_users', 'must_change_password', 'TINYINT(1) NOT NULL DEFAULT 0', 'password_iterations');
await pool.query(`
CREATE TABLE IF NOT EXISTS a_login_attempts (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
rate_key VARCHAR(600) NOT NULL UNIQUE,
failed_count INT NOT NULL DEFAULT 0,
last_failed_at DATETIME NULL,
locked_until DATETIME NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await ensureColumn(pool, 'a_users', 'account_locked', 'TINYINT(1) NOT NULL DEFAULT 0', 'must_change_password');
await ensureColumn(pool, 'a_sessions', 'ip_address', 'VARCHAR(255) NULL', 'user_id');
await ensureColumn(pool, 'a_sessions', 'user_agent', 'VARCHAR(512) NULL', 'ip_address');
await pool.query(`
CREATE TABLE IF NOT EXISTS o_audit_events (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
occurred_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
category VARCHAR(64) NOT NULL,
event_type VARCHAR(128) NOT NULL,
actor_user_id INT NULL,
target_type VARCHAR(64) NULL,
target_id VARCHAR(191) NULL,
target_label VARCHAR(255) NULL,
ip_address VARCHAR(255) NULL,
user_agent VARCHAR(512) NULL,
details_json JSON NULL,
INDEX idx_audit_events_occurred_at (occurred_at),
INDEX idx_audit_events_category_type (category, event_type),
INDEX idx_audit_events_actor (actor_user_id),
INDEX idx_audit_events_target (target_type, target_id)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
VALUES (?, ?, NULL, NULL) ON DUPLICATE KEY UPDATE setting_value = VALUES(setting_value)`,
['audit.retention_days', JSON.stringify(30)]
);
const settings = [
['audit.enabled', true],
['audit.categories', ['authentication', 'security', 'sessions', 'users', 'roles', 'system-settings']],
['audit.include_request_metadata', true]
];
for (const [key, value] of settings) {
await pool.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
VALUES (?, ?, NULL, NULL) ON DUPLICATE KEY UPDATE setting_value = VALUES(setting_value)`,
[key, JSON.stringify(value)]
);
}
await pool.query(
`INSERT IGNORE INTO a_permissions
(permission_key, name, section_name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, NULL, NULL)`,
['audit-log.allow', 'Audit log', 'Settings', 'Download filtered audit events.']
);
await pool.query(
`INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT roles.id, permissions.id, NULL, NULL
FROM a_roles roles
CROSS JOIN a_permissions permissions
WHERE roles.role_key = 'administrators'
AND permissions.permission_key = 'audit-log.allow'`
);
}
},
{
version: '2.8.7',
label: 'v2.8.7 API request and token authentication schema',
run: async function (pool) {
await ensureColumn(pool, 'i_api_sources', 'request_method', "VARCHAR(10) NOT NULL DEFAULT 'GET'", 'api_url');
await ensureColumn(pool, 'i_api_sources', 'request_body_json', 'MEDIUMTEXT NULL', 'request_method');
await ensureColumn(pool, 'i_api_sources', 'token_url', 'VARCHAR(1024) NULL', 'auth_header_value');
await ensureColumn(pool, 'i_api_sources', 'token_request_body_json', 'MEDIUMTEXT NULL', 'token_url');
await ensureColumn(pool, 'i_api_sources', 'token_response_path', "VARCHAR(255) NULL DEFAULT 'access_token'", 'token_request_body_json');
await ensureColumn(pool, 'i_api_sources', 'token_header_name', "VARCHAR(255) NULL DEFAULT 'Authorization'", 'token_response_path');
await ensureColumn(pool, 'i_api_sources', 'token_header_prefix', "VARCHAR(64) NULL DEFAULT 'Bearer'", 'token_header_name');
}
}
];
@@ -228,6 +521,79 @@ async function columnExists(pool, tableName, columnName) {
return Number(rows && rows[0] && rows[0].column_count) > 0;
}
async function tableExists(pool, tableName) {
const [rows] = await pool.query(
`SELECT COUNT(*) AS table_count
FROM information_schema.TABLES
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = ?`,
[tableName]
);
return Number(rows && rows[0] && rows[0].table_count) > 0;
}
async function detectSchemaVersion(pool) {
if (await tableExists(pool, APP_STATE_TABLE)) {
const [rows] = await pool.query(
'SELECT state_value FROM ' + APP_STATE_TABLE + ' WHERE state_key = ? LIMIT 1',
[APP_STATE_SCHEMA_VERSION_KEY]
);
const storedVersion = String(rows && rows[0] && rows[0].state_value || '').trim();
if (storedVersion) {
return storedVersion;
}
}
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const timetableEntriesExists = await tableExists(pool, 'i_timetable_entries');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const scheduleEntriesExists = await tableExists(pool, 'i_schedule_entries');
if (timetableGroupsExists && timetableEntriesExists && !scheduleGroupsExists && !scheduleEntriesExists) {
return '2.6.18';
}
return '0.0.0';
}
async function recordSchemaVersion(pool, version) {
await pool.query(
`CREATE TABLE IF NOT EXISTS ${APP_STATE_TABLE} (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
state_key VARCHAR(191) NOT NULL UNIQUE,
state_value MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci`
);
const stateValue = String(version || appVersion || '0.0.0').trim();
await pool.query(
'UPDATE ' + APP_STATE_TABLE + ' SET state_value = ? WHERE state_key = ?',
[stateValue, APP_STATE_SCHEMA_VERSION_KEY]
);
await pool.query(
'INSERT INTO ' + APP_STATE_TABLE + ' (state_key, state_value) SELECT ?, ? WHERE NOT EXISTS (SELECT 1 FROM ' + APP_STATE_TABLE + ' WHERE state_key = ?)',
[APP_STATE_SCHEMA_VERSION_KEY, stateValue, APP_STATE_SCHEMA_VERSION_KEY]
);
}
async function columnIsAutoIncrement(pool, tableName, columnName) {
const [rows] = await pool.query(
`SELECT COUNT(*) AS auto_increment_count
FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = ?
AND COLUMN_NAME = ?
AND EXTRA LIKE '%auto_increment%'`,
[tableName, columnName]
);
return Number(rows && rows[0] && rows[0].auto_increment_count) > 0;
}
async function ensureColumn(pool, tableName, columnName, columnDefinition, afterColumn) {
if (await columnExists(pool, tableName, columnName)) {
return;
@@ -282,13 +648,39 @@ async function ensureForeignKey(pool, tableName, constraintName, columnName, ref
await pool.query('ALTER TABLE ' + tableName + ' ADD CONSTRAINT ' + candidateName + ' FOREIGN KEY (' + columnName + ') REFERENCES ' + referencedTable + '(' + referencedColumn + ') ON DELETE ' + onDeleteAction);
return;
} catch (error) {
if (!error || (error.code !== 'ER_FK_DUP_NAME' && error.errno !== 1826)) {
if (!error || (error.code !== 'ER_FK_DUP_NAME' && error.errno !== 1826 && error.errno !== 121)) {
throw error;
}
}
}
}
async function dropForeignKeyIfExists(pool, tableName, columnName) {
const [rows] = await pool.query(
`SELECT CONSTRAINT_NAME AS constraint_name
FROM information_schema.KEY_COLUMN_USAGE
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = ?
AND COLUMN_NAME = ?
AND REFERENCED_TABLE_NAME IS NOT NULL
LIMIT 1`,
[tableName, columnName]
);
const constraintName = String(rows && rows[0] && rows[0].constraint_name || '').trim();
if (!constraintName) {
return;
}
try {
await pool.query('ALTER TABLE ' + tableName + ' DROP FOREIGN KEY ' + constraintName);
} catch (error) {
if (!error || (error.code !== 'ER_CANT_DROP_FIELD_OR_KEY' && error.errno !== 1091)) {
throw error;
}
}
}
async function dropColumnIfExists(pool, tableName, columnName) {
if (await columnExists(pool, tableName, columnName)) {
try {
@@ -389,6 +781,107 @@ function formatMigrationDateTime(value) {
return year + '-' + month + '-' + day + 'T' + hours + ':' + minutes;
}
function parseMigrationDateTimeParts(value) {
if (!value) {
return null;
}
if (value instanceof Date) {
if (Number.isNaN(value.getTime())) {
return null;
}
return {
year: value.getUTCFullYear(),
month: value.getUTCMonth() + 1,
day: value.getUTCDate(),
hour: value.getUTCHours(),
minute: value.getUTCMinutes(),
second: value.getUTCSeconds()
};
}
const raw = String(value || '').trim();
const match = raw.match(/^(\d{4})-(\d{2})-(\d{2})(?:[ T](\d{2}):(\d{2})(?::(\d{2}))?)?$/);
if (!match) {
return null;
}
return {
year: Number(match[1]),
month: Number(match[2]),
day: Number(match[3]),
hour: Number(match[4] || 0),
minute: Number(match[5] || 0),
second: Number(match[6] || 0)
};
}
function getMigrationTimeZoneOffsetMillis(date, timeZone) {
if (!(date instanceof Date) || Number.isNaN(date.getTime())) {
return 0;
}
const parts = new Intl.DateTimeFormat('en-GB', {
timeZone: timeZone,
hour12: false,
year: 'numeric',
month: '2-digit',
day: '2-digit',
hour: '2-digit',
minute: '2-digit',
second: '2-digit'
}).formatToParts(date).reduce(function (acc, part) {
if (part && part.type && part.type !== 'literal') {
acc[part.type] = part.value;
}
return acc;
}, Object.create(null));
const localAsUtc = Date.UTC(
Number(parts.year) || 0,
(Number(parts.month) || 1) - 1,
Number(parts.day) || 1,
Number(parts.hour) || 0,
Number(parts.minute) || 0,
Number(parts.second) || 0,
0
);
return localAsUtc - date.getTime();
}
function convertMigrationDateTimeFromTimeZone(value, timeZone) {
const parts = parseMigrationDateTimeParts(value);
if (!parts) {
return null;
}
const utcMillis = Date.UTC(parts.year, parts.month - 1, parts.day, parts.hour, parts.minute, parts.second, 0);
let adjusted = new Date(utcMillis - getMigrationTimeZoneOffsetMillis(new Date(utcMillis), timeZone));
const adjustedOffset = getMigrationTimeZoneOffsetMillis(adjusted, timeZone);
if (adjustedOffset !== getMigrationTimeZoneOffsetMillis(new Date(utcMillis), timeZone)) {
adjusted = new Date(utcMillis - adjustedOffset);
}
return adjusted;
}
function formatMigrationDateTimeUtc(value) {
if (!(value instanceof Date) || Number.isNaN(value.getTime())) {
return null;
}
const year = value.getUTCFullYear();
const month = String(value.getUTCMonth() + 1).padStart(2, '0');
const day = String(value.getUTCDate()).padStart(2, '0');
const hours = String(value.getUTCHours()).padStart(2, '0');
const minutes = String(value.getUTCMinutes()).padStart(2, '0');
const seconds = String(value.getUTCSeconds()).padStart(2, '0');
return year + '-' + month + '-' + day + ' ' + hours + ':' + minutes + ':' + seconds;
}
function formatMigrationTime(value) {
if (!value) {
return null;
@@ -439,19 +932,46 @@ function compareVersions(leftVersion, rightVersion) {
return 0;
}
async function runMigrations(pool, options) {
// Only run migrations that are newer than the installed schema version and not beyond the app version.
async function getPendingMigrations(pool, options) {
const targetVersion = String(appVersion || '0.0.0').trim();
const currentVersion = String(options && options.currentVersion || '0.0.0').trim();
const legacyPlayerSchemaPresent = await columnExists(pool, 'd_players', 'device_id');
const screenPlayerColumnPresent = await columnExists(pool, 'd_screens', 'player_id');
const legacyTimetableGroupsPresent = await tableExists(pool, 'i_schedule_groups');
const legacyTimetableEntriesPresent = await tableExists(pool, 'i_schedule_entries');
let effectiveCurrentVersion = currentVersion;
for (const migration of VERSIONED_MIGRATIONS) {
if (compareVersions(migration.version, currentVersion) > 0 && compareVersions(migration.version, targetVersion) <= 0) {
await migration.run(pool);
}
if (!legacyPlayerSchemaPresent && compareVersions(effectiveCurrentVersion, '2.1.0') < 0) {
effectiveCurrentVersion = '2.1.0';
}
if (!screenPlayerColumnPresent && compareVersions(effectiveCurrentVersion, '2.6.3') < 0) {
effectiveCurrentVersion = '2.6.3';
}
if (legacyTimetableGroupsPresent || legacyTimetableEntriesPresent) {
effectiveCurrentVersion = compareVersions(effectiveCurrentVersion, '2.6.18') < 0 ? '2.6.17' : '2.6.17';
}
return VERSIONED_MIGRATIONS.filter(function (migration) {
return compareVersions(migration.version, effectiveCurrentVersion) > 0 && compareVersions(migration.version, targetVersion) <= 0;
});
}
async function runMigrations(pool, options) {
// Only run migrations that are newer than the installed schema version and not beyond the app version.
const pendingMigrations = await getPendingMigrations(pool, options);
for (const migration of pendingMigrations) {
await migration.run(pool);
}
}
module.exports = {
appVersion: appVersion,
runMigrations: runMigrations
getPendingMigrations: getPendingMigrations,
runMigrations: runMigrations,
detectSchemaVersion: detectSchemaVersion,
recordSchemaVersion: recordSchemaVersion,
compareVersions: compareVersions
};
File diff suppressed because it is too large Load Diff
+504 -26
View File
@@ -2,6 +2,7 @@ const express = require('express');
const fs = require('fs');
const http = require('http');
const path = require('path');
const { WebSocket } = require('ws');
const common = require('./common');
const { createPlayerRuntime } = require('./player/runtime');
const { createPlayerPlaylistService } = require('./player/playlist');
@@ -10,44 +11,301 @@ const { normalizeDeviceId, registerPlayerOnboardingRoutes, commitDeviceBinding }
const { createOnboardingStore } = require('./player/onboarding/store');
const { registerPlayerRoutes } = require('./player/routes');
const { ensureFontLibrary } = require('#src/web/lib/media/font-library');
const { createRequestAuthHeaders } = require('#src/request-auth');
const { getConfiguredPlayerIdentifier, recordPlayerHeartbeat } = require('#src/data/player-registry');
// Player runtime, media API, and websocket wiring.
async function start() {
const app = express();
const pool = common.createPool();
const pool = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '') ? null : common.createPool();
const PORT = Number(process.env.PLAYER_PORT || 8081);
const PLAYER_PUBLIC_BASE_URL = String(process.env.PLAYER_PUBLIC_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const PLAYER_INTERNAL_BASE_URL = String(process.env.PLAYER_INTERNAL_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const PLAYER_IDENTIFIER = '1';
const PLAYER_PUBLIC_URL = String(process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const BRIDGE_PUBLIC_URL = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const WEB_INTERNAL_URL = String(process.env.WEB_INTERNAL_URL || '').trim().replace(/\/$/, '');
const isRemotePlayer = Boolean(BRIDGE_PUBLIC_URL);
const PLAYER_INTERNAL_URL = String(isRemotePlayer ? BRIDGE_PUBLIC_URL : (process.env.PLAYER_INTERNAL_URL || PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '')).trim().replace(/\/$/, '');
const PLAYER_DEVICE_ID = getConfiguredPlayerIdentifier();
const PLAYER_AGENT_RECONNECT_DELAY_MS = Number(process.env.PLAYER_AGENT_RECONNECT_DELAY_MS || 5000);
const ASSET_DIR = path.join(__dirname, 'player', 'public');
const MEDIA_DIR = path.join(__dirname, '..', 'media');
const ONBOARDING_QUEUE_FILE = path.join(MEDIA_DIR, 'player-onboarding-queue.json');
const DB_SYNC_INTERVAL_MS = Number(process.env.PLAYER_DB_SYNC_INTERVAL_MS || 15000);
const RECONNECT_SYNC_STALE_MS = 60 * 1000;
const onboardingStore = createOnboardingStore(ONBOARDING_QUEUE_FILE);
let thinClientSocket = null;
let lastDisconnectAt = 0;
let playerPublicBaseUrl = PLAYER_PUBLIC_URL || null;
let refreshThinClientRegistration = null;
const playerRuntime = createPlayerRuntime({
pool: pool,
normalizeDeviceId: normalizeDeviceId
});
const playerPlaylistService = createPlayerPlaylistService({
pool: pool,
common: common,
snapshotDir: path.join(MEDIA_DIR, 'player-cache', 'screen-playlists')
normalizeDeviceId: normalizeDeviceId,
notifySnapshot: function (snapshot) {
if (!thinClientSocket || thinClientSocket.readyState !== WebSocket.OPEN) {
return;
}
try {
thinClientSocket.send(JSON.stringify({
type: 'snapshot',
deviceId: PLAYER_DEVICE_ID,
slug: snapshot && snapshot.slug ? String(snapshot.slug).trim() : '',
connections: Array.isArray(snapshot && snapshot.connections) ? snapshot.connections : []
}));
} catch (_error) {
}
}
});
const playerPlaylistService = isRemotePlayer
? null
: createPlayerPlaylistService({
pool: pool,
common: common,
mediaDir: MEDIA_DIR,
snapshotDir: path.join(MEDIA_DIR, 'player-cache', 'screen-playlists')
});
const rtmpStreamService = createRtmpStreamService({
mediaDir: MEDIA_DIR
});
const server = http.createServer(app);
playerRuntime.installWebsocket(server);
app.use(express.json());
let hasLoggedPlayerStartup = false;
function normalizePlayerPublicBaseUrl(value) {
const normalized = String(value || '').trim().replace(/\/$/, '');
if (!normalized) {
return null;
}
try {
return new URL(normalized).origin.replace(/\/$/, '');
} catch (_error) {
return normalized;
}
}
function setPlayerPublicBaseUrl(value) {
const nextBaseUrl = normalizePlayerPublicBaseUrl(value);
if (!nextBaseUrl || nextBaseUrl === playerPublicBaseUrl) {
return;
}
playerPublicBaseUrl = nextBaseUrl;
if (typeof refreshThinClientRegistration === 'function') {
refreshThinClientRegistration();
}
}
function getPlayerPublicBaseUrl() {
return playerPublicBaseUrl;
}
function logPlayerStartup(connectionState) {
if (hasLoggedPlayerStartup) {
return;
}
hasLoggedPlayerStartup = true;
console.info('[player] startup', {
mode: isRemotePlayer ? 'bridge client' : 'local',
connected: connectionState && typeof connectionState.connected === 'boolean' ? connectionState.connected : false,
publicBaseUrl: getPlayerPublicBaseUrl(),
bridgeBaseUrl: PLAYER_INTERNAL_URL || null,
bridgeWebSocketUrl: BRIDGE_PUBLIC_URL ? createThinClientWebSocketUrl() : null
});
}
fs.mkdirSync(MEDIA_DIR, { recursive: true });
function resolveLocalMediaFilePath(fileName) {
const relativePath = path.normalize(String(fileName || '').trim()).replace(/^([\\/])+/, '');
if (!relativePath || relativePath === '.' || relativePath.startsWith('..') || path.isAbsolute(relativePath)) {
return null;
}
const resolvedMediaDir = path.resolve(MEDIA_DIR);
const resolvedFilePath = path.resolve(MEDIA_DIR, relativePath);
if (resolvedFilePath !== resolvedMediaDir && !resolvedFilePath.startsWith(resolvedMediaDir + path.sep)) {
return null;
}
return resolvedFilePath;
}
async function triggerWebMediaSync() {
const syncBaseUrl = WEB_INTERNAL_URL || BRIDGE_PUBLIC_URL;
if (!isRemotePlayer || !syncBaseUrl) {
return false;
}
const requestBody = {
playerIdentifier: PLAYER_DEVICE_ID,
playerPublicBaseUrl: getPlayerPublicBaseUrl(),
playerInternalBaseUrl: PLAYER_INTERNAL_URL
};
try {
const authHeaders = createRequestAuthHeaders({
method: 'POST',
pathname: '/api/internal/sync/player-media',
body: requestBody
});
const response = await fetch(`${syncBaseUrl}/api/internal/sync/player-media`, {
method: 'POST',
headers: Object.assign({
Accept: 'application/json',
'Content-Type': 'application/json'
}, authHeaders),
body: JSON.stringify(requestBody)
});
return Boolean(response && response.ok);
} catch (_error) {
console.warn('[player] Startup media sync failed');
return false;
}
}
async function triggerWebFontSync() {
const syncBaseUrl = WEB_INTERNAL_URL || BRIDGE_PUBLIC_URL;
if (!isRemotePlayer || !syncBaseUrl) {
return false;
}
const requestBody = {
playerIdentifier: PLAYER_DEVICE_ID,
playerPublicBaseUrl: getPlayerPublicBaseUrl(),
playerInternalBaseUrl: PLAYER_INTERNAL_URL
};
try {
const authHeaders = createRequestAuthHeaders({
method: 'POST',
pathname: '/api/internal/sync/player-font',
body: requestBody
});
const response = await fetch(`${syncBaseUrl}/api/internal/sync/player-font`, {
method: 'POST',
headers: Object.assign({
Accept: 'application/json',
'Content-Type': 'application/json'
}, authHeaders),
body: JSON.stringify(requestBody)
});
return Boolean(response && response.ok);
} catch (_error) {
console.warn('[player] Startup font sync failed');
return false;
}
}
let webMediaSyncCompleted = false;
let webFontSyncCompleted = false;
let webFontSyncTriggered = false;
function shouldTriggerReconnectSync() {
if (!lastDisconnectAt) {
return true;
}
return Date.now() - lastDisconnectAt >= RECONNECT_SYNC_STALE_MS;
}
async function handleThinClientCommand(socket, rawMessage) {
let payload = null;
try {
payload = JSON.parse(String(rawMessage || ''));
} catch (_error) {
return;
}
if (!payload || typeof payload !== 'object' || Array.isArray(payload) || String(payload.type || '').trim() !== 'command') {
return;
}
const requestId = String(payload.requestId || '').trim() || null;
const command = String(payload.command || '').trim().toLowerCase();
const response = {
type: 'command-response',
requestId: requestId,
ok: false
};
try {
if (command === 'media-put') {
const relativePath = String(payload.relativePath || payload.filename || '').trim();
const filePath = resolveLocalMediaFilePath(relativePath);
const bodyBase64 = String(payload.bodyBase64 || '').trim();
if (!filePath || !bodyBase64) {
response.error = 'Invalid media payload.';
} else {
const bodyBuffer = Buffer.from(bodyBase64, 'base64');
await fs.promises.mkdir(path.dirname(filePath), { recursive: true });
await fs.promises.writeFile(filePath, bodyBuffer);
response.ok = true;
}
} else if (command === 'media-delete') {
const relativePath = String(payload.relativePath || payload.filename || '').trim();
const filePath = resolveLocalMediaFilePath(relativePath);
if (!filePath) {
response.error = 'Invalid media path.';
} else {
try {
await fs.promises.unlink(filePath);
} catch (error) {
if (!error || error.code !== 'ENOENT') {
throw error;
}
}
response.ok = true;
}
} else if (['refresh', 'reload', 'redirect', 'pause', 'blackout', 'previous', 'next', 'setclientname'].indexOf(command) !== -1) {
const screenSlug = String(payload.screenSlug || payload.slug || '').trim();
if (!screenSlug) {
response.error = 'Screen slug is required.';
} else if (payload.connectionId) {
const sent = await playerRuntime.sendCommandToConnection(screenSlug, String(payload.connectionId || '').trim(), payload);
response.ok = sent > 0;
if (!response.ok) {
response.error = 'Player is not connected.';
}
} else {
const sent = await playerRuntime.broadcastCommand(screenSlug, payload);
response.ok = sent > 0;
if (!response.ok) {
response.error = 'Player is not connected.';
}
}
} else {
response.error = 'Unsupported command.';
}
} catch (error) {
response.error = error && error.message ? error.message : 'Command failed.';
}
if (socket && socket.readyState === WebSocket.OPEN) {
socket.send(JSON.stringify(response));
}
}
app.use(function (error, _req, res, _next) {
console.error(error);
res.status(error.statusCode || 500).send(error.statusCode ? error.message : 'Internal server error');
});
await ensureFontLibrary(MEDIA_DIR);
registerPlayerOnboardingRoutes(app, {
pool: pool,
common: common,
playerRuntime: playerRuntime,
onboardingStore: onboardingStore,
playerPublicBaseUrl: PLAYER_PUBLIC_BASE_URL,
playerInternalBaseUrl: PLAYER_INTERNAL_BASE_URL,
QRCode: require('qrcode')
playerPublicBaseUrl: getPlayerPublicBaseUrl(),
playerInternalBaseUrl: PLAYER_INTERNAL_URL,
bridgeBaseUrl: BRIDGE_PUBLIC_URL,
playerDeviceId: PLAYER_DEVICE_ID
});
registerPlayerRoutes(app, {
pool: pool,
@@ -57,27 +315,236 @@ async function start() {
playerRuntime: playerRuntime,
playerPlaylistService: playerPlaylistService,
rtmpStreamService: rtmpStreamService,
playerPublicBaseUrl: PLAYER_PUBLIC_BASE_URL,
playerInternalBaseUrl: PLAYER_INTERNAL_BASE_URL,
playerIdentifier: PLAYER_IDENTIFIER
playerInternalBaseUrl: PLAYER_INTERNAL_URL,
bridgeBaseUrl: BRIDGE_PUBLIC_URL,
playerDeviceId: PLAYER_DEVICE_ID,
onPlayerPublicBaseUrl: setPlayerPublicBaseUrl
});
app.use(function (error, _req, res, _next) {
console.error(error);
res.status(error.statusCode || 500).send(error.statusCode ? error.message : 'Internal server error');
});
function createThinClientWebSocketUrl() {
if (!BRIDGE_PUBLIC_URL) {
return null;
}
fs.mkdirSync(MEDIA_DIR, { recursive: true });
await ensureFontLibrary(MEDIA_DIR);
return BRIDGE_PUBLIC_URL.replace(/^http:/i, 'ws:').replace(/^https:/i, 'wss:') + '/ws/players';
}
function startThinClientRegistration() {
const thinClientUrl = createThinClientWebSocketUrl();
if (!thinClientUrl) {
return null;
}
let socket = null;
let reconnectTimer = null;
let heartbeatTimer = null;
function clearTimers() {
if (reconnectTimer) {
clearTimeout(reconnectTimer);
reconnectTimer = null;
}
if (heartbeatTimer) {
clearInterval(heartbeatTimer);
heartbeatTimer = null;
}
}
function connect() {
clearTimers();
const timestamp = String(Date.now());
const authHeaders = createRequestAuthHeaders({
method: 'GET',
pathname: '/ws/players',
timestamp: timestamp
});
let webMediaSyncTriggered = false;
socket = new WebSocket(thinClientUrl, {
headers: Object.assign({
'x-pulse-request-timestamp': timestamp
}, authHeaders)
});
thinClientSocket = socket;
function sendHeartbeat() {
if (!socket || socket.readyState !== WebSocket.OPEN) {
return;
}
socket.send(JSON.stringify({
type: 'heartbeat',
deviceId: PLAYER_DEVICE_ID,
publicBaseUrl: getPlayerPublicBaseUrl(),
internalBaseUrl: PLAYER_INTERNAL_URL
}));
}
refreshThinClientRegistration = sendHeartbeat;
function triggerMediaSyncIfNeeded() {
if (webMediaSyncTriggered || webMediaSyncCompleted) {
return;
}
webMediaSyncTriggered = true;
triggerWebMediaSync().then(function (success) {
webMediaSyncCompleted = Boolean(success) || webMediaSyncCompleted;
if (!success) {
webMediaSyncTriggered = false;
}
}).catch(function () {
webMediaSyncTriggered = false;
});
}
function triggerFontSyncIfNeeded() {
if (webFontSyncTriggered || webFontSyncCompleted) {
return;
}
webFontSyncTriggered = true;
triggerWebFontSync().then(function (success) {
webFontSyncCompleted = Boolean(success) || webFontSyncCompleted;
if (!success) {
webFontSyncTriggered = false;
}
}).catch(function () {
webFontSyncTriggered = false;
webFontSyncCompleted = false;
});
}
function sendSnapshot(slug) {
if (!socket || socket.readyState !== WebSocket.OPEN) {
return;
}
try {
socket.send(JSON.stringify({
type: 'snapshot',
deviceId: PLAYER_DEVICE_ID,
slug: String(slug || '').trim(),
connections: playerRuntime.snapshotConnections(slug)
}));
} catch (_error) {
}
}
socket.on('open', function () {
logPlayerStartup({
connected: true
});
socket.send(JSON.stringify({
type: 'register',
deviceId: PLAYER_DEVICE_ID,
publicBaseUrl: getPlayerPublicBaseUrl(),
internalBaseUrl: PLAYER_INTERNAL_URL
}));
playerRuntime.snapshotSlugs().forEach(function (slug) {
sendSnapshot(slug);
});
heartbeatTimer = setInterval(function () {
sendHeartbeat();
}, DB_SYNC_INTERVAL_MS);
});
socket.on('message', function (rawMessage) {
let parsedMessage = null;
try {
parsedMessage = JSON.parse(String(rawMessage || '{}'));
} catch (_error) {
parsedMessage = null;
}
if (parsedMessage && String(parsedMessage.type || '').trim() === 'registered') {
sendHeartbeat();
return;
}
if (parsedMessage && String(parsedMessage.type || '').trim() === 'heartbeat-ack') {
if (shouldTriggerReconnectSync()) {
triggerMediaSyncIfNeeded();
triggerFontSyncIfNeeded();
}
return;
}
handleThinClientCommand(socket, rawMessage).catch(function (error) {
try {
socket.send(JSON.stringify({
type: 'command-response',
requestId: null,
ok: false,
error: error && error.message ? error.message : 'Command failed.'
}));
} catch (_sendError) {
// ignore send errors
}
});
});
socket.on('close', function () {
lastDisconnectAt = Date.now();
webFontSyncTriggered = false;
webFontSyncCompleted = false;
webMediaSyncCompleted = false;
clearTimers();
thinClientSocket = null;
refreshThinClientRegistration = null;
reconnectTimer = setTimeout(connect, PLAYER_AGENT_RECONNECT_DELAY_MS);
});
socket.on('error', function () {
try {
socket.close();
} catch (_error) {
// ignore reconnect noise
}
});
}
connect();
return function stop() {
clearTimers();
if (socket) {
try {
socket.close();
} catch (_error) {
// ignore close errors
}
socket = null;
}
};
}
if (!isRemotePlayer) {
logPlayerStartup({
connected: false
});
}
const stopThinClientRegistration = startThinClientRegistration();
server.listen(PORT, function () {
console.log(`Pulse Signage app listening on port ${PORT}`);
});
async function syncDatabaseState() {
if (isRemotePlayer) {
return;
}
try {
await common.ensureSchema(pool, { mediaDir: MEDIA_DIR });
await common.bootstrapDatabase(pool);
await recordPlayerHeartbeat(pool, {
deviceId: PLAYER_DEVICE_ID,
publicBaseUrl: getPlayerPublicBaseUrl(),
internalBaseUrl: PLAYER_INTERNAL_URL
}).catch(function (error) {
console.error(error);
});
if (playerRuntime.snapshotAllConnections().length > 0) {
await common.pruneStaleOnboardingDevices(pool);
@@ -100,16 +567,27 @@ async function start() {
await syncDatabaseState();
if (PLAYER_IDENTIFIER) {
if (PLAYER_DEVICE_ID && !isRemotePlayer) {
const { upsertPlayerRegistration } = require('./player/onboarding');
await upsertPlayerRegistration(pool, PLAYER_IDENTIFIER, PLAYER_PUBLIC_BASE_URL, PLAYER_INTERNAL_BASE_URL, null);
await upsertPlayerRegistration(pool, PLAYER_DEVICE_ID, getPlayerPublicBaseUrl(), PLAYER_INTERNAL_URL).catch(function (error) {
console.error(error);
});
}
setInterval(function () {
if (isRemotePlayer) {
return;
}
syncDatabaseState().catch(function (error) {
console.error(error);
});
}, DB_SYNC_INTERVAL_MS);
process.on('exit', function () {
if (typeof stopThinClientRegistration === 'function') {
stopThinClientRegistration();
}
});
}
module.exports = { start };
@@ -99,7 +99,6 @@
display: inline-flex;
align-items: center;
gap: 2.5rem;
min-width: 100%;
width: max-content;
backface-visibility: hidden;
will-change: transform;
@@ -148,7 +147,7 @@
transform: translate3d(0, 0, 0);
}
to {
transform: translate3d(-50%, 0, 0);
transform: translate3d(calc(-1 * var(--announcement-scroll-distance, 0px)), 0, 0);
}
}
</style>
@@ -178,21 +177,10 @@
}
var track = root.querySelector('.player-announcement__message-track');
if (!track) {
if (!track || typeof window.initPlayerAnnouncementMarquee !== 'function') {
return;
}
if (track.dataset.marqueeMeasured === 'true') {
return;
}
var rate = Number(track.getAttribute('data-announcement-marquee-rate') || 44) || 44;
var singlePassWidth = Math.max(1, track.scrollWidth / 2);
var durationSeconds = Math.max(8, singlePassWidth / rate);
var durationValue = durationSeconds.toFixed(2) + 's';
track.dataset.marqueeMeasured = 'true';
track.style.setProperty('--announcement-scroll-duration', durationValue);
track.style.animationDuration = durationValue;
window.initPlayerAnnouncementMarquee(track, { container: root.querySelector('.player-announcement__message') || root });
}());
</script>
@@ -101,7 +101,6 @@
display: inline-flex;
align-items: center;
gap: 2.5rem;
min-width: 100%;
width: max-content;
backface-visibility: hidden;
will-change: transform;
@@ -150,7 +149,7 @@
transform: translate3d(0, 0, 0);
}
to {
transform: translate3d(-50%, 0, 0);
transform: translate3d(calc(-1 * var(--announcement-scroll-distance, 0px)), 0, 0);
}
}
</style>
@@ -180,21 +179,10 @@
}
var track = root.querySelector('.player-announcement__message-track');
if (!track) {
if (!track || typeof window.initPlayerAnnouncementMarquee !== 'function') {
return;
}
if (track.dataset.marqueeMeasured === 'true') {
return;
}
var rate = Number(track.getAttribute('data-announcement-marquee-rate') || 44) || 44;
var singlePassWidth = Math.max(1, track.scrollWidth / 2);
var durationSeconds = Math.max(8, singlePassWidth / rate);
var durationValue = durationSeconds.toFixed(2) + 's';
track.dataset.marqueeMeasured = 'true';
track.style.setProperty('--announcement-scroll-duration', durationValue);
track.style.animationDuration = durationValue;
window.initPlayerAnnouncementMarquee(track, { container: root.querySelector('.player-announcement__message') || root });
}());
</script>
+151 -54
View File
@@ -1,7 +1,10 @@
// Player onboarding routes and signup flow helpers.
const express = require('express');
const { isClientNameAvailable, withClientNameReservation } = require('#src/data/client-name-check');
const { getSharedSecret, verifyPageAuthToken } = require('#src/request-auth');
const { createStyledQrCodeSvg } = require('#src/data/qr-code');
const { getSharedSecret, verifyPageAuthToken, createRequestAuthHeaders } = require('#src/request-auth');
const { resolvePlayerRegistration, upsertPlayerRegistration: upsertPlayerRegistrationRecord } = require('#src/data/player-registry');
const { isTransientDbError } = require('./store');
const ONBOARDING_SIGNUP_LIMIT_WINDOW_MS = 5 * 60 * 1000;
@@ -13,15 +16,16 @@ function normalizeDeviceId(value) {
}
function getPublicBaseUrl(req, configuredUrl) {
const configured = String(configuredUrl || process.env.PLAYER_PUBLIC_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
if (configured) {
return configured;
}
const forwardedProto = String(req.headers['x-forwarded-proto'] || '').trim().split(',')[0];
const protocol = forwardedProto || (req.socket && req.socket.encrypted ? 'https' : 'http');
const forwardedHost = String(req.headers['x-forwarded-host'] || '').trim().split(',')[0];
const host = forwardedHost || String(req.headers.host || '').trim();
return `${protocol}://${host}`.replace(/\/$/, '');
if (host) {
return `${protocol}://${host}`.replace(/\/$/, '');
}
const configured = String(configuredUrl || process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
return configured || null;
}
function getRequestIp(req) {
@@ -47,7 +51,7 @@ function getPlayerPublicBaseUrl(req, configuredUrl) {
}
function getPlayerInternalBaseUrl(configuredUrl) {
const configured = String(configuredUrl || process.env.PLAYER_INTERNAL_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const configured = String(configuredUrl || process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
return configured || null;
}
@@ -124,15 +128,25 @@ async function commitDeviceBinding(pool, deviceId, clientName, screenSlug, isNam
}
await pool.query(
'INSERT INTO d_onboarding_devices (device_id, client_name, screen_id) VALUES (?, ?, ?) ON DUPLICATE KEY UPDATE client_name = VALUES(client_name), screen_id = VALUES(screen_id), modified_at = CURRENT_TIMESTAMP',
[normalizedDeviceId, normalizedClientName, screen.id]
`UPDATE d_onboarding_devices
SET client_name = ?, screen_id = ?, modified_at = CURRENT_TIMESTAMP
WHERE device_id = ?`,
[normalizedClientName, screen.id, normalizedDeviceId]
);
await pool.query(
`INSERT INTO d_onboarding_devices (device_id, client_name, screen_id)
SELECT ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM d_onboarding_devices WHERE device_id = ?
)`,
[normalizedDeviceId, normalizedClientName, screen.id, normalizedDeviceId]
);
return getOnboardingStatus(pool, normalizedDeviceId);
});
}
async function upsertPlayerRegistration(pool, deviceId, publicBaseUrl, internalBaseUrl, screenSlug) {
async function upsertPlayerRegistration(pool, deviceId, publicBaseUrl, internalBaseUrl) {
const normalizedDeviceId = normalizeDeviceId(deviceId);
const normalizedPublicBaseUrl = String(publicBaseUrl || '').trim().replace(/\/$/, '');
const normalizedInternalBaseUrl = String(internalBaseUrl || '').trim().replace(/\/$/, '');
@@ -140,18 +154,11 @@ async function upsertPlayerRegistration(pool, deviceId, publicBaseUrl, internalB
return null;
}
await pool.query(
`INSERT INTO d_players (device_id, public_base_url, internal_base_url, last_seen_at)
VALUES (?, ?, ?, CURRENT_TIMESTAMP)
ON DUPLICATE KEY UPDATE public_base_url = VALUES(public_base_url), internal_base_url = VALUES(internal_base_url), last_seen_at = CURRENT_TIMESTAMP, modified_at = CURRENT_TIMESTAMP`,
[normalizedDeviceId, normalizedPublicBaseUrl || null, normalizedInternalBaseUrl || null]
);
return {
device_id: normalizedDeviceId,
public_base_url: normalizedPublicBaseUrl || null,
internal_base_url: normalizedInternalBaseUrl || null
};
return upsertPlayerRegistrationRecord(pool, {
identifier: normalizedDeviceId,
publicBaseUrl: normalizedPublicBaseUrl || null,
internalBaseUrl: normalizedInternalBaseUrl || null
});
}
async function bindPlayerToScreen(pool, deviceId, screenSlug) {
@@ -166,25 +173,9 @@ async function bindPlayerToScreen(pool, deviceId, screenSlug) {
return null;
}
const screenId = Number(screenRows[0].id);
const connection = await pool.getConnection();
try {
await connection.beginTransaction();
// Current model: every screen binds to the shared player row '1'.
// If we introduce multiple players, resolve the correct player row here instead of hardcoding it.
await connection.query("UPDATE d_screens SET player_id = '1', modified_at = CURRENT_TIMESTAMP WHERE id = ?", [screenId]);
await connection.commit();
} catch (error) {
await connection.rollback();
throw error;
} finally {
connection.release();
}
return {
screen_id: screenId,
screen_slug: normalizedScreenSlug,
player_id: '1'
screen_id: Number(screenRows[0].id),
screen_slug: normalizedScreenSlug
};
}
@@ -222,15 +213,67 @@ function registerPlayerOnboardingRoutes(app, options) {
const pool = options && options.pool ? options.pool : null;
const common = options && options.common ? options.common : null;
const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null;
const QRCode = options && options.QRCode ? options.QRCode : null;
const onboardingStore = options && options.onboardingStore ? options.onboardingStore : null;
const playerPublicUrl = String(options && options.playerPublicBaseUrl || process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const playerDeviceId = normalizeDeviceId(options && options.playerDeviceId);
if (!app || !pool || !common || !playerRuntime || !QRCode) {
throw new Error('registerPlayerOnboardingRoutes requires app, pool, common, playerRuntime, and QRCode.');
if (!app || !common) {
throw new Error('registerPlayerOnboardingRoutes requires app and common.');
}
if (!bridgeBaseUrl && (!pool || !playerRuntime)) {
throw new Error('registerPlayerOnboardingRoutes requires pool and playerRuntime unless bridgeBaseUrl is configured.');
}
const sharedSecret = getSharedSecret();
async function fetchThinClient(req, pathname, options) {
if (!bridgeBaseUrl) {
return null;
}
const requestOptions = options && typeof options === 'object' ? options : {};
const method = String(requestOptions.method || req.method || 'GET').trim().toUpperCase();
const body = Object.prototype.hasOwnProperty.call(requestOptions, 'body') ? requestOptions.body : undefined;
const requestPathname = String(pathname || '').split('?')[0];
const headers = Object.assign({}, requestOptions.headers || {}, createRequestAuthHeaders({
method: method,
pathname: requestPathname,
body: body
}));
if (req.headers['x-pulse-page-auth']) {
headers['x-pulse-page-auth'] = String(req.headers['x-pulse-page-auth']).trim();
}
if (requestOptions.contentType) {
headers['content-type'] = requestOptions.contentType;
}
return fetch(new URL(pathname, bridgeBaseUrl).toString(), {
method: method,
headers: headers,
body: body === undefined || body === null || method === 'GET' || method === 'HEAD' ? undefined : body
});
}
async function readJsonResponse(response) {
if (!response) {
return null;
}
const contentType = String(response.headers && typeof response.headers.get === 'function' ? response.headers.get('content-type') : '').toLowerCase();
if (contentType.indexOf('application/json') === -1 && contentType.indexOf('+json') === -1) {
return null;
}
try {
return await response.json();
} catch (_error) {
return null;
}
}
function requireOnboardingPageAuth(req, res, next) {
if (!sharedSecret) {
return next();
@@ -254,7 +297,7 @@ function registerPlayerOnboardingRoutes(app, options) {
app.get('/onboard', async function (req, res, next) {
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
try {
res.send(common.renderPlayerOnboardingFormPage(String(req.query.deviceId || '').trim()));
res.send(common.renderPlayerOnboardingFormPage(String(req.query.deviceId || playerDeviceId || '').trim()));
} catch (error) {
next(error);
}
@@ -272,15 +315,32 @@ function registerPlayerOnboardingRoutes(app, options) {
next();
}, async function (req, res, next) {
try {
const status = await getOnboardingStatus(pool, req.query.deviceId);
const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId;
if (bridgeBaseUrl) {
const response = await fetchThinClient(req, '/api/onboarding/status?deviceId=' + encodeURIComponent(deviceId || ''), {
method: 'GET'
});
if (!response) {
return res.status(502).json({ error: 'Player bridge unavailable.' });
}
res.status(response.status);
const payload = await readJsonResponse(response);
if (!payload) {
return res.status(502).json({ error: 'Player bridge returned an invalid response.' });
}
payload.playerUrl = payload && payload.screenSlug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(payload.screenSlug)}` : null;
return res.json(payload);
}
const status = await getOnboardingStatus(pool, deviceId);
res.json({
deviceId: normalizeDeviceId(req.query.deviceId),
deviceId: normalizeDeviceId(deviceId),
onboarded: Boolean(status && status.screen_id),
clientName: status ? status.client_name : null,
screenId: status ? status.screen_id : null,
screenSlug: status ? status.screen_slug : null,
screenName: status ? status.screen_name : null,
playerUrl: status && status.screen_slug ? `${getPublicBaseUrl(req)}/screen/${encodeURIComponent(status.screen_slug)}` : null
playerUrl: status && status.screen_slug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(status.screen_slug)}` : null
});
} catch (error) {
next(error);
@@ -289,6 +349,16 @@ function registerPlayerOnboardingRoutes(app, options) {
app.get('/api/onboarding/screens', requireOnboardingPageAuth, async function (_req, res, next) {
try {
if (bridgeBaseUrl) {
const response = await fetchThinClient(_req, '/api/onboarding/screens', {
method: 'GET'
});
res.status(response.status);
const text = await response.text();
res.type(response.headers.get('content-type') || 'application/json');
return res.send(text);
}
const [rows] = await pool.query('SELECT id, name, slug FROM d_screens ORDER BY name ASC, id ASC');
res.json({ screens: rows });
} catch (error) {
@@ -298,12 +368,12 @@ function registerPlayerOnboardingRoutes(app, options) {
app.get('/api/onboarding/qr', async function (req, res, next) {
try {
const deviceId = normalizeDeviceId(req.query.deviceId);
const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId;
if (!deviceId) {
return res.status(400).json({ error: 'Device ID is required' });
}
const onboardingUrl = `${getPublicBaseUrl(req, options && options.playerPublicBaseUrl)}/onboard?deviceId=${encodeURIComponent(deviceId)}`;
const svg = await QRCode.toString(onboardingUrl, { type: 'svg', margin: 1, errorCorrectionLevel: 'M' });
const onboardingUrl = `${getPublicBaseUrl(req, playerPublicUrl)}/onboard?deviceId=${encodeURIComponent(deviceId)}`;
const svg = await createStyledQrCodeSvg({ value: onboardingUrl, qr_margin: 20 });
res.set('Content-Type', 'image/svg+xml; charset=utf-8');
res.set('Cache-Control', 'no-store');
res.send(svg);
@@ -312,9 +382,9 @@ function registerPlayerOnboardingRoutes(app, options) {
}
});
app.post('/api/onboarding', requireOnboardingPageAuth, async function (req, res, next) {
app.post('/api/onboarding', requireOnboardingPageAuth, express.json(), async function (req, res, next) {
try {
const deviceId = normalizeDeviceId(req.body && req.body.deviceId);
const deviceId = normalizeDeviceId(req.body && req.body.deviceId) || playerDeviceId;
const clientName = String((req.body && req.body.clientName) || '').trim();
const screenSlug = String((req.body && req.body.screenSlug) || '').trim();
const retryAfterSeconds = isOnboardingSignupRateLimited(req, deviceId);
@@ -322,6 +392,30 @@ function registerPlayerOnboardingRoutes(app, options) {
res.set('Retry-After', String(retryAfterSeconds));
return res.status(429).json({ error: 'Too many onboarding attempts. Please try again later.' });
}
if (bridgeBaseUrl) {
const forwardedBody = Object.assign({}, req.body || {}, {
deviceId: deviceId
});
const response = await fetch(new URL('/api/onboarding', bridgeBaseUrl).toString(), {
method: 'POST',
headers: Object.assign({
'content-type': 'application/json'
}, createRequestAuthHeaders({
method: 'POST',
pathname: '/api/onboarding',
body: forwardedBody
}), req.headers['x-pulse-page-auth'] ? { 'x-pulse-page-auth': String(req.headers['x-pulse-page-auth']).trim() } : {}),
body: JSON.stringify(forwardedBody)
});
res.status(response.status);
const payload = await readJsonResponse(response);
if (!payload) {
return res.status(502).json({ error: 'Player bridge returned an invalid response.' });
}
payload.playerUrl = payload && payload.screenSlug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(payload.screenSlug)}` : `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(screenSlug)}`;
return res.json(payload);
}
if (!deviceId) {
return res.status(400).json({ error: 'Device ID is required' });
}
@@ -340,11 +434,14 @@ function registerPlayerOnboardingRoutes(app, options) {
screenId: status && status.screen_id ? status.screen_id : null,
screenSlug: status ? status.screen_slug : screenSlug,
screenName: status && status.screen_name ? status.screen_name : null,
playerUrl: status && status.screen_slug ? `${getPublicBaseUrl(req)}/screen/${encodeURIComponent(status.screen_slug)}` : `${getPublicBaseUrl(req)}/screen/${encodeURIComponent(screenSlug)}`,
playerUrl: status && status.screen_slug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(status.screen_slug)}` : `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(screenSlug)}`,
queued: Boolean(status && status.queued)
});
} catch (error) {
next(error);
const statusCode = Number(error && error.statusCode || error && error.status || 500);
res.status(Number.isFinite(statusCode) && statusCode >= 400 ? statusCode : 500).json({
error: error && error.message ? error.message : 'Onboarding failed.'
});
}
});
}
@@ -7,6 +7,12 @@
var form = document.getElementById("onboarding-form");
var message = document.getElementById("onboarding-message");
var screenSelect = document.getElementById("onboarding-screen-select");
function getSessionStorageItem(key) {
try { return window.sessionStorage.getItem(key) || ""; } catch (_error) { return ""; }
}
function setSessionStorageItem(key, value) {
try { window.sessionStorage.setItem(key, value); } catch (_error) {}
}
function setMessage(value) { if (message) { message.textContent = value || ""; } }
function parseResponseError(response) {
return response.text().then(function (text) {
@@ -39,15 +45,19 @@
return screens;
});
}
if (!deviceId) { setMessage("Missing device id. Scan the QR code from the player screen again."); return; }
try { window.localStorage.setItem(deviceKey, deviceId); } catch (_error) {}
try {
if (!deviceId) {
deviceId = window.sessionStorage.getItem(deviceKey) || "";
}
if (deviceId) {
window.sessionStorage.setItem(deviceKey, deviceId);
}
} catch (_error) {}
loadScreens().then(function () {
try {
var storedClientName = window.localStorage.getItem(clientNameKey) || "";
var storedScreenSlug = window.localStorage.getItem(screenKey) || "";
var storedClientName = getSessionStorageItem(clientNameKey) || "";
var clientNameInput = form.querySelector("input[name=\"clientName\"]");
if (clientNameInput && storedClientName) { clientNameInput.value = storedClientName; }
if (screenSelect && storedScreenSlug) { screenSelect.value = storedScreenSlug; }
} catch (_error) {}
});
form.addEventListener("submit", function (event) {
@@ -58,10 +68,14 @@
if (!clientName) { setMessage("Client name is required."); return; }
if (!screenSlug) { setMessage("Screen is required."); return; }
setMessage("Saving client...");
var payload = { clientName: clientName, screenSlug: screenSlug };
if (deviceId) {
payload.deviceId = deviceId;
}
fetch("/api/onboarding", {
method: "POST",
headers: { "Content-Type": "application/json", Accept: "application/json" },
body: JSON.stringify({ deviceId: deviceId, clientName: clientName, screenSlug: screenSlug })
body: JSON.stringify(payload)
})
.then(function (response) {
if (response.ok) {
@@ -73,7 +87,7 @@
})
.then(function (payload) {
if (!payload || !payload.screenSlug) { throw new Error("Unable to save onboarding."); }
if (payload.clientName) { try { window.localStorage.setItem(clientNameKey, payload.clientName); } catch (_error) {} }
if (payload.clientName) { setSessionStorageItem(clientNameKey, payload.clientName); }
try { window.localStorage.setItem(screenKey, payload.screenSlug); } catch (_error) {}
setMessage("Onboarding complete.");
if (form) {
@@ -2,6 +2,12 @@
(function () {
var deviceKey = "pulse-signage-player-device-id";
var clientNameKey = "pulse-signage-player-client-name";
function getSessionStorageItem(key) {
try { return window.sessionStorage.getItem(key) || ""; } catch (_error) { return ""; }
}
function setSessionStorageItem(key, value) {
try { window.sessionStorage.setItem(key, value); } catch (_error) {}
}
function getClientNameStorageKey(_screenSlug) {
return clientNameKey;
}
@@ -11,6 +17,7 @@
var localForm = document.getElementById("onboarding-local-form");
var localMessage = document.getElementById("onboarding-message");
var localScreenSelect = document.getElementById("onboarding-screen-select");
var qrPlaceholderSrc = "data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E";
function parseResponseError(response) {
return response.text().then(function (text) {
var fallbackMessage = text && text.trim() ? text.trim() : "Unable to save onboarding.";
@@ -24,10 +31,10 @@
}
function getDeviceId() {
var stored = "";
try { stored = window.localStorage.getItem(deviceKey) || ""; } catch (_error) { stored = ""; }
try { stored = window.sessionStorage.getItem(deviceKey) || ""; } catch (_error) { stored = ""; }
if (stored) { return stored; }
var next = (window.crypto && window.crypto.randomUUID ? window.crypto.randomUUID() : "device-" + Date.now() + "-" + Math.random().toString(16).slice(2));
try { window.localStorage.setItem(deviceKey, next); } catch (_error2) {}
try { window.sessionStorage.setItem(deviceKey, next); } catch (_error2) {}
return next;
}
function setStatus(message) { if (status) { status.textContent = message; } }
@@ -60,7 +67,11 @@
.catch(function () { setSelectOptions(localScreenSelect, [], selectedSlug); return []; });
}
function loadQr(deviceId) {
if (qr) { qr.src = "/api/onboarding/qr?deviceId=" + encodeURIComponent(deviceId); }
if (!qr) { return; }
qr.onerror = function () {
qr.src = qrPlaceholderSrc;
};
qr.src = "/api/onboarding/qr?deviceId=" + encodeURIComponent(deviceId);
}
function submitOnboarding(deviceId, clientName, screenSlug) {
return fetch("/api/onboarding", {
@@ -78,8 +89,8 @@
})
.then(function (payload) {
if (!payload || !payload.screenSlug) { throw new Error("Unable to save onboarding."); }
if (payload.clientName) { try { window.localStorage.setItem(clientNameKey, payload.clientName); } catch (_error) {} }
if (payload.clientName && payload.screenSlug) { try { window.localStorage.setItem(getClientNameStorageKey(payload.screenSlug), payload.clientName); } catch (_error2) {} }
if (payload.clientName) { setSessionStorageItem(clientNameKey, payload.clientName); }
if (payload.clientName && payload.screenSlug) { setSessionStorageItem(getClientNameStorageKey(payload.screenSlug), payload.clientName); }
try { window.localStorage.setItem(screenKey, payload.screenSlug); } catch (_error) {}
setLocalMessage("Onboarding complete.");
if (localForm) {
@@ -94,8 +105,8 @@
.then(function (response) { return response.ok ? response.json() : null; })
.then(function (payload) {
if (payload && payload.onboarded && payload.screenSlug) {
if (payload.clientName) { try { window.localStorage.setItem(clientNameKey, payload.clientName); } catch (_error) {} }
if (payload.clientName && payload.screenSlug) { try { window.localStorage.setItem(getClientNameStorageKey(payload.screenSlug), payload.clientName); } catch (_error2) {} }
if (payload.clientName) { setSessionStorageItem(clientNameKey, payload.clientName); }
if (payload.clientName && payload.screenSlug) { setSessionStorageItem(getClientNameStorageKey(payload.screenSlug), payload.clientName); }
try { window.localStorage.setItem(screenKey, payload.screenSlug); } catch (_error) {}
window.location.replace("/screen/" + encodeURIComponent(payload.screenSlug));
return true;
@@ -121,18 +132,18 @@
}
loadScreens().then(function () {
try {
var storedScreenSlug = window.localStorage.getItem(screenKey) || "";
var storedClientName = window.localStorage.getItem(clientNameKey) || "";
if (!storedClientName && storedScreenSlug) { storedClientName = window.localStorage.getItem(getClientNameStorageKey(storedScreenSlug)) || ""; }
var storedClientName = getSessionStorageItem(clientNameKey) || "";
if (storedClientName && localForm) {
var clientNameInput = localForm.querySelector("input[name=\"clientName\"]");
if (clientNameInput && !clientNameInput.value) { clientNameInput.value = storedClientName; }
if (clientNameInput) { clientNameInput.value = storedClientName; }
}
if (storedScreenSlug && localScreenSelect) { localScreenSelect.value = storedScreenSlug; }
} catch (_error) {}
});
redirectIfOnboarded(deviceId).then(function (redirected) {
if (redirected) { return; }
if (qr && !qr.getAttribute("src")) {
qr.src = qrPlaceholderSrc;
}
loadQr(deviceId);
setStatus("Waiting for onboarding to finish.");
window.setInterval(function () { redirectIfOnboarded(deviceId); }, 2000);
+27 -20
View File
@@ -4,10 +4,31 @@
const onboardingClientNameStorageKey = 'pulse-signage-player-client-name';
const onboardingDeviceIdStorageKey = 'pulse-signage-player-device-id';
function getSessionStorageItem(key) {
try {
return window.sessionStorage.getItem(key) || '';
} catch (_error) {
return '';
}
}
function setSessionStorageItem(key, value) {
try {
window.sessionStorage.setItem(key, value);
} catch (_error) {
// ignore storage errors
}
}
function getOnboardingDeviceId() {
try {
var storedDeviceId = window.localStorage.getItem(onboardingDeviceIdStorageKey) || '';
return String(storedDeviceId || '').trim();
var storedDeviceId = getSessionStorageItem(onboardingDeviceIdStorageKey);
if (storedDeviceId) {
return String(storedDeviceId || '').trim();
}
var nextDeviceId = window.crypto && window.crypto.randomUUID ? window.crypto.randomUUID() : 'device-' + Date.now() + '-' + Math.random().toString(16).slice(2);
setSessionStorageItem(onboardingDeviceIdStorageKey, nextDeviceId);
return String(nextDeviceId || '').trim();
} catch (_error) {
return '';
}
@@ -19,24 +40,14 @@
return onboardingClientName;
}
try {
var storedClientName = window.localStorage.getItem(onboardingClientNameStorageKey);
var storedClientName = getSessionStorageItem(onboardingClientNameStorageKey);
if (storedClientName) {
onboardingClientName = storedClientName;
try {
window.localStorage.setItem('pulse-signage-player-client-name', storedClientName);
} catch (_mirrorError) {
// ignore storage errors
}
return onboardingClientName;
}
var genericClientName = window.localStorage.getItem('pulse-signage-player-client-name');
var genericClientName = getSessionStorageItem('pulse-signage-player-client-name');
if (genericClientName) {
onboardingClientName = genericClientName;
try {
window.localStorage.setItem(onboardingClientNameStorageKey, genericClientName);
} catch (_error) {
// ignore storage errors
}
return onboardingClientName;
}
} catch (_error) {
@@ -51,12 +62,8 @@
return;
}
onboardingClientName = normalizedName;
try {
window.localStorage.setItem('pulse-signage-player-client-name', normalizedName);
window.localStorage.setItem(onboardingClientNameStorageKey, normalizedName);
} catch (_error) {
// ignore storage errors
}
setSessionStorageItem('pulse-signage-player-client-name', normalizedName);
setSessionStorageItem(onboardingClientNameStorageKey, normalizedName);
if (socket && socket.readyState === WebSocket.OPEN) {
sendCommandState(socket);
}
+1 -1
View File
@@ -7,7 +7,7 @@
<link rel="icon" type="image/png" href="/assets/favicon.png" />
<link rel="stylesheet" href="/assets/adminlte/bootstrap-icons/css/bootstrap-icons.min.css" />
<link rel="stylesheet" href="/assets/vendor/animate.css/animate.min.css" />
<link rel="stylesheet" href="/assets/css/player.css?v=36" />
<link rel="stylesheet" href="/assets/css/player.css?v=37" />
{{{STYLESHEETS}}}
</head>
<body class="{{BODY_CLASS}}">
+137 -4
View File
@@ -3,11 +3,14 @@
const crypto = require('crypto');
const fs = require('fs');
const path = require('path');
const { createStyledQrCodeDataUrl } = require('../data/qr-code');
function createPlayerPlaylistService(options) {
const pool = options && options.pool ? options.pool : null;
const common = options && options.common ? options.common : null;
const snapshotDir = options && options.snapshotDir ? options.snapshotDir : null;
const mediaDir = options && options.mediaDir ? path.resolve(String(options.mediaDir)) : null;
const remoteImageCacheDir = mediaDir ? path.join(mediaDir, 'player-cache', 'remote-images') : null;
if (!pool) {
throw new Error('pool is required');
@@ -56,6 +59,109 @@ function createPlayerPlaylistService(options) {
await fs.promises.writeFile(filePath, JSON.stringify(payload, null, 2), 'utf8');
}
async function createQrPreviewDataUrl(value) {
return createStyledQrCodeDataUrl(value);
}
function getPlaceholderImageExpressions(value, output) {
const expressions = output || [];
const source = String(value || '');
const pattern = /\{\{\s*([^{}]*?\.image\s*\([^{}]*\)[^{}]*?)\s*\}\}/gi;
let match = null;
while ((match = pattern.exec(source))) {
expressions.push(String(match[1] || '').trim());
}
return expressions;
}
function resolvePathValue(value, expression) {
const parsed = String(expression || '').replace(/\.image\s*\([^)]*\)\s*$/i, '').trim();
return parsed.split('.').reduce(function (current, segment) {
return current === undefined || current === null ? '' : current[segment];
}, value);
}
function getApiItems(responseJson, itemsPath) {
let current = responseJson;
const pathValue = String(itemsPath || '').trim();
if (pathValue) {
pathValue.split('.').forEach(function (segment) {
current = current === undefined || current === null ? '' : current[segment];
});
return Array.isArray(current) ? current : [];
}
if (Array.isArray(responseJson)) return responseJson;
if (responseJson && Array.isArray(responseJson.items)) return responseJson.items;
if (responseJson && Array.isArray(responseJson.results)) return responseJson.results;
if (responseJson && Array.isArray(responseJson.data)) return responseJson.data;
return responseJson ? [responseJson] : [];
}
async function cacheRemoteImage(url) {
const remoteUrl = String(url || '').trim();
if (!remoteImageCacheDir || !/^https?:\/\//i.test(remoteUrl)) return '';
const hash = crypto.createHash('sha256').update(remoteUrl).digest('hex');
await fs.promises.mkdir(remoteImageCacheDir, { recursive: true });
const existing = (await fs.promises.readdir(remoteImageCacheDir)).find(function (name) { return name.startsWith(hash + '.'); });
if (existing) return '/media/player-cache/remote-images/' + existing;
try {
const response = await fetch(remoteUrl, { signal: AbortSignal.timeout(15000) });
if (!response.ok || !String(response.headers.get('content-type') || '').toLowerCase().startsWith('image/')) return '';
const bytes = Buffer.from(await response.arrayBuffer());
if (bytes.length > 10 * 1024 * 1024) return '';
const contentType = String(response.headers.get('content-type') || '').toLowerCase();
const extension = contentType.includes('svg') ? '.svg' : contentType.includes('png') ? '.png' : contentType.includes('webp') ? '.webp' : contentType.includes('gif') ? '.gif' : '.jpg';
const fileName = hash + extension;
const filePath = path.join(remoteImageCacheDir, fileName);
await fs.promises.writeFile(filePath, bytes);
return '/media/player-cache/remote-images/' + fileName;
} catch (_error) {
return '';
}
}
async function cachePlaceholderImages(slides, rssFeeds, apiSources) {
if (!remoteImageCacheDir) return;
const usedPaths = new Set();
const allSlideRows = await pool.query('SELECT content_json FROM c_slides').then(function (result) { return result[0] || []; });
const allContents = allSlideRows.map(function (row) { return common.parseJsonSafe(row.content_json) || {}; });
const sourceContent = allContents.concat((slides || []).map(function (slide) { return slide.content || {}; }));
const cacheSource = async function (source, item, expressions) {
if (!source || !item) return;
for (const expression of expressions) {
const remoteUrl = String(resolvePathValue(item, expression) || '').trim();
const localPath = await cacheRemoteImage(remoteUrl);
if (localPath) {
source.imageCache = source.imageCache || {};
source.imageCache[remoteUrl] = localPath;
usedPaths.add(localPath);
}
}
};
for (const content of sourceContent) {
for (const key of Object.keys(content || {})) {
const region = content[key];
if (!region || typeof region !== 'object') continue;
const expressions = getPlaceholderImageExpressions(region.value, []);
if (!expressions.length) continue;
const itemNumber = Math.max(1, Number(region.item_number || 1)) - 1;
if (String(region.type || '').toLowerCase() === 'api') {
const source = (apiSources || []).find(function (entry) { return Number(entry.id) === Number(region.source_id); });
const items = source ? getApiItems(source.responseJson, region.items_path) : [];
await cacheSource(source, items[itemNumber], expressions);
}
if (String(region.type || '').toLowerCase() === 'rss') {
const feed = (rssFeeds || []).find(function (entry) { return Number(entry.id) === Number(region.feed_id); });
await cacheSource(feed, feed && feed.items && feed.items[itemNumber], expressions);
}
}
}
const files = await fs.promises.readdir(remoteImageCacheDir).catch(function () { return []; });
await Promise.all(files.filter(function (file) { return !usedPaths.has('/media/player-cache/remote-images/' + file); }).map(function (file) {
return fs.promises.unlink(path.join(remoteImageCacheDir, file)).catch(function () {});
}));
}
async function buildScreenPlaylist(slug) {
try {
const [screenRows] = await pool.query('SELECT id, name, slug, playlist_id, created_at, modified_at, created_by, modified_by FROM d_screens WHERE slug = ?', [slug]);
@@ -139,23 +245,27 @@ function createPlayerPlaylistService(options) {
return null;
}
const videoRegion = Object.keys(parsed).map(function (key) { return parsed[key]; }).find(function (region) {
const videoRegions = Object.keys(parsed).map(function (key) { return parsed[key]; }).filter(function (region) {
return region && typeof region === 'object' && String(region.type || '').trim().toLowerCase() === 'video' && Number(region.duration_seconds || 0) > 0;
});
const duration = Math.round(Number(videoRegion && videoRegion.duration_seconds || 0) * 1000) / 1000;
const duration = videoRegions.reduce(function (longest, region) {
const regionDuration = Math.round(Number(region.duration_seconds || 0) * 1000) / 1000;
return regionDuration > longest ? regionDuration : longest;
}, 0);
return Number.isFinite(duration) && duration > 0 ? duration : null;
} catch (_error) {
return null;
}
}
const slides = slideRows.map(function (slide) {
const slides = await Promise.all(slideRows.map(async function (slide) {
const storedDuration = Number(slide.duration_seconds || 0);
const videoDuration = slide.use_video_duration ? getVideoRegionDurationSeconds(slide.content_json) : null;
const disableAudio = slide.disable_audio === undefined || slide.disable_audio === null ? true : Boolean(slide.disable_audio);
const videoCacheBust = String(slide.modified_at || slide.content_json || slide.id || '');
const content = common.parseJsonSafe(slide.content_json) || {};
const qrBackfillTasks = [];
Object.keys(content).forEach(function (key) {
const region = content[key];
if (region && typeof region === 'object') {
@@ -168,6 +278,27 @@ function createPlayerPlaylistService(options) {
region.cache_bust = videoCacheBust;
}
});
Object.keys(content).forEach(function (key) {
const region = content[key];
if (!region || typeof region !== 'object' || String(region.type || '').trim().toLowerCase() !== 'qr-code') {
return;
}
if (region.qr_preview && /^data:image\//i.test(String(region.qr_preview || '').trim())) {
return;
}
qrBackfillTasks.push(createQrPreviewDataUrl(region.value).then(function (preview) {
if (preview) {
region.qr_preview = preview;
}
return null;
}).catch(function () {
return null;
}));
});
await Promise.all(qrBackfillTasks);
return {
id: slide.id,
title: slide.title,
@@ -180,7 +311,7 @@ function createPlayerPlaylistService(options) {
template: slide.template_id ? templatesById[slide.template_id] || null : null,
content: content
};
});
}));
let rssFeeds = [];
if (typeof common.fetchRssFeedsData === 'function' && typeof common.fetchRssFeedItemsByFeedId === 'function') {
@@ -211,6 +342,8 @@ function createPlayerPlaylistService(options) {
timetableGroups = Array.isArray(timetableData && timetableData.timetableGroups) ? timetableData.timetableGroups : [];
}
await cachePlaceholderImages(slides, rssFeeds, apiSources);
const revision = getPlaylistRevision(screen, playlist, slideRows, scheduleRuleRows, templateRows, regionRows, rssFeeds, apiSources, timetableGroups);
const payload = { screen: screen, playlist: playlist, slides: slides, rssFeeds: rssFeeds, apiSources: apiSources, timetableGroups: timetableGroups, revision: revision };
await writeSnapshot(slug, payload);
+12 -23
View File
@@ -4,7 +4,7 @@ body {
width: 100%;
height: 100%;
overflow: hidden;
background: #111;
background: #0a0a0a;
color: #fff;
font-family: Arial, sans-serif;
}
@@ -43,7 +43,7 @@ body.thumbnail-preview .player-offline-banner {
display: flex;
align-items: center;
justify-content: center;
background: #111;
background: #0a0a0a;
position: relative;
}
@@ -116,6 +116,8 @@ body.thumbnail-preview .player-offline-banner {
display: block;
background: #fff;
border-radius: 18px;
padding: 16px;
box-sizing: border-box;
}
.onboarding-form {
@@ -292,15 +294,6 @@ body.screen-blackout #app {
display: block;
}
.slide img,
.slide video,
.slide iframe {
width: 100%;
height: 100%;
object-fit: contain;
border: 0;
}
.body {
position: absolute;
left: 5%;
@@ -393,18 +386,6 @@ body.screen-blackout #app {
white-space: pre-wrap;
}
.template-region.text > *,
.template-region.api > *,
.template-region.rss > * {
margin: 0;
}
.template-region.text > * + *,
.template-region.api > * + *,
.template-region.rss > * + * {
margin-top: 0.5em;
}
.template-region.text ul,
.template-region.text ol,
.template-region.api ul,
@@ -443,6 +424,14 @@ body.screen-blackout #app {
overflow: hidden;
}
.template-region.qr-code img {
width: 100%;
height: 100%;
object-fit: contain;
display: block;
background: #fff;
}
.template-region.html iframe {
width: 100%;
height: 100%;
@@ -54,12 +54,68 @@
});
}
function getComputedGapWidth(track) {
if (!track || !window.getComputedStyle) {
return 0;
}
var computedStyle = window.getComputedStyle(track);
var gapValue = String(computedStyle.columnGap || computedStyle.gap || '0').trim();
var gap = Number.parseFloat(gapValue);
return Number.isFinite(gap) ? gap : 0;
}
function getElementWidth(element) {
if (!element || !element.getBoundingClientRect) {
return 0;
}
return Math.max(0, element.getBoundingClientRect().width || 0);
}
function initPlayerAnnouncementMarquee(track, options) {
if (!track || track.dataset.marqueeMeasured === 'true') {
return;
}
var settings = options || {};
var rate = Number(settings.rate || track.getAttribute('data-announcement-marquee-rate') || 44) || 44;
var textSelector = String(settings.textSelector || '.player-announcement__message-text').trim() || '.player-announcement__message-text';
var textNodes = Array.prototype.slice.call(track.querySelectorAll(textSelector));
if (!textNodes.length) {
return;
}
var container = settings.container || track.parentElement || track;
var containerWidth = Math.max(1, getElementWidth(container) || 0);
var gapWidth = getComputedGapWidth(track);
var firstItemWidth = Math.max(1, getElementWidth(textNodes[0]) || 0);
var cycleWidth = Math.max(1, firstItemWidth + gapWidth);
var minimumTrackWidth = Math.max(containerWidth + cycleWidth, cycleWidth * 2);
var cloneIndex = 0;
while (getElementWidth(track) < minimumTrackWidth && cloneIndex < 8) {
var clone = textNodes[cloneIndex % textNodes.length].cloneNode(true);
clone.setAttribute('aria-hidden', 'true');
track.appendChild(clone);
cloneIndex += 1;
}
var durationSeconds = Math.max(8, cycleWidth / rate);
var durationValue = durationSeconds.toFixed(2) + 's';
track.dataset.marqueeMeasured = 'true';
track.style.setProperty('--announcement-scroll-distance', cycleWidth.toFixed(2) + 'px');
track.style.setProperty('--announcement-scroll-duration', durationValue);
track.style.animationDuration = durationValue;
}
function renderPlayerAnnouncementMarkup(announcement) {
var normalizedType = normalizeAnnouncementType(announcement && announcement.announcement_type);
var colorKey = normalizeAnnouncementColor(announcement && announcement.color_key);
var colorTokens = getAnnouncementColorTokens(colorKey);
var iconKey = normalizeAnnouncementIcon(announcement && announcement.icon_key);
var text = escapeHtml(String(announcement && announcement.message || '').trim()).replace(/\n/g, '<br />');
var text = escapeHtml(String(announcement && announcement.message || '').trim()).replace(/[\r\n]+/g, ' ');
var titleText = escapeHtml(String(announcement && announcement.short_label || 'Announcement').trim() || 'Announcement');
var templates = window.playerAnnouncementTemplates || {};
var templateName = normalizedType === 'fullscreen' ? 'fullscreen' : normalizedType === 'top-banner' ? 'topBanner' : 'lowerThird';
@@ -77,4 +133,5 @@
}
window.renderPlayerAnnouncementMarkup = renderPlayerAnnouncementMarkup;
window.initPlayerAnnouncementMarquee = initPlayerAnnouncementMarquee;
})();
+65 -31
View File
@@ -130,9 +130,10 @@ function scheduleSlideAdvance(delayMs) {
slideExpiresAt = null;
pausedRemainingMs = null;
clearSlideOutroTimer();
applyPendingPlaylistUpdate();
const activeSlides = getCurrentActiveSlides();
if (activeSlides.length < 2) {
refresh();
showCurrent();
return;
}
if (index >= activeSlides.length) {
@@ -262,20 +263,33 @@ function renderSlideMarkup(markup, shouldFade) {
});
}
function schedulePostRenderSetup(root, delayMs) {
if (!root) {
return;
}
if (root.isConnected === false) {
return;
}
if (typeof syncRtmpRegions === 'function') {
syncRtmpRegions(root);
}
if (!isThumbnailPreview()) {
initializeRegionInstances(root);
}
initializeRenderedVideoPlayback(root, delayMs);
if (typeof playRegionAnimations === 'function') {
playRegionAnimations(root, 'intro');
}
}
if (!shouldFade) {
app.innerHTML = markup;
if (typeof syncRtmpRegions === 'function') {
syncRtmpRegions(app);
}
if (!isThumbnailPreview()) {
initializeRegionInstances(app);
}
initializeRenderedVideoPlayback(app);
if (typeof playRegionAnimations === 'function') {
window.requestAnimationFrame(function () {
playRegionAnimations(app, 'intro');
});
}
schedulePostRenderSetup(app, 0);
return app.firstElementChild;
}
@@ -324,11 +338,7 @@ function renderSlideMarkup(markup, shouldFade) {
app.innerHTML = '';
nextShell.style.opacity = '1';
app.appendChild(nextShell);
if (typeof syncRtmpRegions === 'function') {
syncRtmpRegions(nextShell);
}
initializeRegionInstances(nextShell);
initializeRenderedVideoPlayback(nextShell, slideFadeDurationMs / 2);
schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2);
return nextShell;
}
@@ -339,24 +349,12 @@ function renderSlideMarkup(markup, shouldFade) {
pauseRenderedVideoPlayback(previousShell, slideFadeDurationMs / 2);
app.appendChild(nextShell);
void nextShell.offsetHeight;
window.requestAnimationFrame(function () {
nextShell.style.opacity = '1';
previousShell.style.opacity = '0';
if (typeof playRegionAnimations === 'function') {
playRegionAnimations(nextShell, 'intro');
}
schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2);
});
if (typeof syncRtmpRegions === 'function') {
syncRtmpRegions(nextShell);
}
if (!isThumbnailPreview()) {
initializeRegionInstances(nextShell);
}
initializeRenderedVideoPlayback(nextShell, slideFadeDurationMs / 2);
slideTransitionTimer = window.setTimeout(function () {
if (previousShell && previousShell.parentNode) {
previousShell.parentNode.removeChild(previousShell);
@@ -429,6 +427,42 @@ function normalizeBoolean(value) {
return null;
}
function isEditableTarget(target) {
if (!target) {
return false;
}
if (target.isContentEditable) {
return true;
}
var tagName = String(target.tagName || '').toUpperCase();
return ['INPUT', 'TEXTAREA', 'SELECT', 'OPTION'].indexOf(tagName) !== -1;
}
function handlePlayerKeydown(event) {
if (!event || event.defaultPrevented || event.altKey || event.ctrlKey || event.metaKey) {
return;
}
if (isEditableTarget(event.target)) {
return;
}
if (event.key === 'ArrowLeft') {
event.preventDefault();
navigateSlides(-1);
return;
}
if (event.key === 'ArrowRight') {
event.preventDefault();
navigateSlides(1);
}
}
window.addEventListener('keydown', handlePlayerKeydown);
// Move to the previous or next active slide.
function navigateSlides(offset) {
const manualSlides = getCurrentActiveSlides();
+50 -13
View File
@@ -54,6 +54,9 @@ async function renderSlideAtIndex(sourceSlides, targetIndex) {
index = currentIndex;
var markup = buildSlideMarkup(slide);
renderSlideMarkup(markup, currentPlaylistFadeBetweenSlides);
if (typeof scheduleSlideMarkupPreload === 'function') {
scheduleSlideMarkupPreload(availableSlides, currentIndex);
}
sendCommandState(slide);
if (!isPaused) {
scheduleSlideAdvance(getSlideHoldDelay(Math.max(1, Number(slide.duration_seconds || 10)) * 1000));
@@ -67,6 +70,7 @@ function applyPendingPlaylistUpdate() {
if (!pendingPlaylistUpdate) {
return false;
}
var nextIndex = Number(index || 0);
slides = pendingPlaylistUpdate.slides;
currentPlaylistSignature = pendingPlaylistUpdate.signature;
currentPlaylistFadeBetweenSlides = pendingPlaylistUpdate.fadeBetweenSlides;
@@ -77,7 +81,11 @@ function applyPendingPlaylistUpdate() {
templateLayoutCache = Object.create(null);
templateRenderPlanCache = Object.create(null);
renderCacheViewportKey = window.innerWidth + 'x' + window.innerHeight;
index = 0;
const activeSlides = getCurrentActiveSlides();
if (!Number.isFinite(nextIndex) || nextIndex < 0) {
nextIndex = 0;
}
index = activeSlides.length ? Math.min(nextIndex, activeSlides.length - 1) : 0;
logDebug('Applied updated playlist on slide transition.');
return true;
}
@@ -85,12 +93,14 @@ function applyPendingPlaylistUpdate() {
// Render the current active slide or the empty state.
function showCurrent() {
clearSlideTimer();
applyPendingPlaylistUpdate();
const activeSlides = getCurrentActiveSlides();
syncWebpagePreloads(activeSlides, index);
if (typeof syncRtmpWarmups === 'function') {
syncRtmpWarmups(activeSlides, index);
}
if (typeof scheduleSlideMarkupPreload === 'function') {
scheduleSlideMarkupPreload(activeSlides, index);
}
if (!activeSlides.length) {
renderEmpty(slides.length ? 'No slides are scheduled for this time.' : 'No slides assigned to this screen yet.');
lastRenderedViewKey = getCurrentRenderKey(activeSlides);
@@ -100,6 +110,16 @@ function showCurrent() {
lastRenderedViewKey = getCurrentRenderKey(activeSlides);
}
function isSlideInList(slide, slideList) {
if (!slide || !Array.isArray(slideList)) {
return false;
}
return slideList.some(function (item) {
return item && Number(item.id) === Number(slide.id);
});
}
// Skip the current slide when an RTMP feed is unavailable and the playlist asks for it.
function handleRtmpPlaybackFailure(message, options) {
if (!currentPlaylistSkipUnavailableRtmp) {
@@ -166,8 +186,18 @@ function refresh() {
const data = JSON.parse(request.responseText || '{}');
const nextSignature = getPlaylistRevision(data);
const nextSlides = Array.isArray(data.slides) ? data.slides.map(normalizeSlide) : [];
const nextActiveSlides = getActiveSlidesFrom(nextSlides);
const nextFadeBetweenSlides = Boolean(data && data.playlist && data.playlist.fade_between_slides);
const nextSkipUnavailableRtmp = Boolean(data && data.playlist && data.playlist.skip_unavailable_rtmp);
if (window.initialData && typeof window.initialData === 'object') {
window.initialData.screen = data.screen || window.initialData.screen || null;
window.initialData.playlist = data.playlist || null;
window.initialData.slides = nextSlides;
window.initialData.rssFeeds = Array.isArray(data.rssFeeds) ? data.rssFeeds : [];
window.initialData.apiSources = Array.isArray(data.apiSources) ? data.apiSources : [];
window.initialData.timetableGroups = Array.isArray(data.timetableGroups) ? data.timetableGroups : [];
window.initialData.revision = nextSignature;
}
savePlaylistSnapshot({
slides: nextSlides,
signature: nextSignature,
@@ -197,19 +227,26 @@ function refresh() {
}
return;
}
syncWebpagePreloads(getActiveSlidesFrom(nextSlides), index);
syncWebpagePreloads(nextActiveSlides, index);
if (typeof syncRtmpWarmups === 'function') {
syncRtmpWarmups(getActiveSlidesFrom(nextSlides), index);
syncRtmpWarmups(nextActiveSlides, index);
}
if (currentActiveSlides.length < 2) {
slides = nextSlides;
currentPlaylistSignature = nextSignature;
currentPlaylistFadeBetweenSlides = nextFadeBetweenSlides;
currentPlaylistSkipUnavailableRtmp = nextSkipUnavailableRtmp;
pendingPlaylistUpdate = null;
index = 0;
showCurrent();
sendCommandState(lastRenderedSlide);
if (typeof scheduleSlideMarkupPreload === 'function') {
scheduleSlideMarkupPreload(nextActiveSlides, index);
}
if (nextActiveSlides.length < 2) {
pendingPlaylistUpdate = {
slides: nextSlides,
signature: nextSignature,
fadeBetweenSlides: nextFadeBetweenSlides,
skipUnavailableRtmp: nextSkipUnavailableRtmp
};
if (!isSlideInList(lastRenderedSlide, nextSlides)) {
applyPendingPlaylistUpdate();
showCurrent();
return;
}
logDebug('Playlist update detected; applying on next slide transition.');
return;
}
pendingPlaylistUpdate = {
+61 -9
View File
@@ -84,7 +84,7 @@ function getCurrentRenderKey(activeSlides) {
return [currentPlaylistSignature || '', viewportKey, 'slide', slide && slide.id ? slide.id : ''].join('|');
}
// Pick the current slide and the next slide for webpage preloading.
// Pick the next slide for webpage preloading.
function getWebpagePreloadSlides(sourceSlides, targetIndex) {
const availableSlides = Array.isArray(sourceSlides) ? sourceSlides : [];
if (!availableSlides.length) {
@@ -97,19 +97,71 @@ function getWebpagePreloadSlides(sourceSlides, targetIndex) {
}
const preloadSlides = [];
const currentSlide = availableSlides[normalizedIndex];
const nextSlide = availableSlides[normalizedIndex + 1];
if (currentSlide) {
preloadSlides.push(currentSlide);
}
if (nextSlide && nextSlide !== currentSlide) {
if (nextSlide) {
preloadSlides.push(nextSlide);
}
return preloadSlides;
}
// Pick the next slide to warm its markup before it becomes visible.
function getSlideMarkupPreloadSlides(sourceSlides, targetIndex) {
const availableSlides = Array.isArray(sourceSlides) ? sourceSlides : [];
if (!availableSlides.length) {
return [];
}
let normalizedIndex = Number(targetIndex || 0);
if (!Number.isFinite(normalizedIndex) || normalizedIndex < 0 || normalizedIndex >= availableSlides.length) {
normalizedIndex = 0;
}
const preloadSlides = [];
const nextSlide = availableSlides[normalizedIndex + 1];
if (nextSlide) {
preloadSlides.push(nextSlide);
}
return preloadSlides;
}
function scheduleSlideMarkupPreload(sourceSlides, targetIndex) {
if (window.__pulseThumbnailPreview) {
return;
}
const preloadSlides = getSlideMarkupPreloadSlides(sourceSlides, targetIndex);
if (!preloadSlides.length || typeof primeSlideMarkup !== 'function') {
return;
}
const slide = preloadSlides[0];
const preloadSignature = [
currentPlaylistSignature || '',
slide && slide.id ? slide.id : '',
slide && slide.template_id ? slide.template_id : '',
slide && slide.modified_at ? slide.modified_at : '',
window.innerWidth + 'x' + window.innerHeight,
videoRegionRenderVersion || 0
].join('|');
if (scheduleSlideMarkupPreload.signature === preloadSignature) {
return;
}
scheduleSlideMarkupPreload.signature = preloadSignature;
window.setTimeout(function () {
if (scheduleSlideMarkupPreload.signature !== preloadSignature) {
return;
}
primeSlideMarkup(slide);
}, 0);
}
// Mount hidden iframe preloads for the chosen webpage URLs.
function syncWebpagePreloads(sourceSlides, targetIndex) {
const urls = getWebpageUrls(getWebpagePreloadSlides(sourceSlides, targetIndex));
@@ -136,13 +188,13 @@ function syncWebpagePreloads(sourceSlides, targetIndex) {
preloadSignature = signature;
}
// Return a stable client id for this browser session.
// Return a stable client id for this screen session.
function getCommandClientId() {
if (commandClientId) {
return commandClientId;
}
try {
var storedClientId = window.localStorage.getItem(commandClientStorageKey);
var storedClientId = window.sessionStorage.getItem(commandClientStorageKey);
if (storedClientId) {
commandClientId = storedClientId;
return commandClientId;
@@ -152,7 +204,7 @@ function getCommandClientId() {
}
commandClientId = (window.crypto && window.crypto.randomUUID ? window.crypto.randomUUID() : 'client-' + Date.now() + '-' + Math.random().toString(16).slice(2));
try {
window.localStorage.setItem(commandClientStorageKey, commandClientId);
window.sessionStorage.setItem(commandClientStorageKey, commandClientId);
} catch (_error2) {
// ignore storage errors
}
+72 -5
View File
@@ -4,6 +4,14 @@ function sanitizeFontFamily(value) {
return String(value || '').replace(/[^a-zA-Z0-9 ,\"-]/g, '').trim();
}
function normalizeStyleAttributeValue(value) {
return String(value || '')
.replace(/&quot;/g, '"')
.replace(/&#39;/g, "'")
.replace(/&amp;quot;/g, '"')
.replace(/&amp;#39;/g, "'");
}
// Clamp font size to the supported range.
function sanitizeFontSize(value) {
return Math.max(8, Number(value || 0) || 24);
@@ -334,7 +342,7 @@ function setPlayerCanvasDimensions(canvasWidth, canvasHeight) {
document.documentElement.style.setProperty('--player-canvas-height', height + 'px');
}
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = {
@@ -349,14 +357,19 @@ function sanitizeRichTextAttributes(tagName, attrText) {
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
pre: ['class', 'style'],
span: ['class', 'style'],
table: ['class', 'style'],
tbody: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
thead: ['class', 'style'],
tr: ['class', 'style'],
ul: ['class', 'style']
};
@@ -365,6 +378,14 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return '';
}
if (tagName === 'img') {
const srcMatch = String(attrText || '').match(/\bsrc\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+))/i);
const srcValue = srcMatch ? String(srcMatch[2] !== undefined ? srcMatch[2] : srcMatch[3] !== undefined ? srcMatch[3] : srcMatch[4] !== undefined ? srcMatch[4] : '').trim() : '';
if (!srcValue || !/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/]|data:image\/)/i.test(srcValue)) {
return '';
}
}
const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase();
@@ -388,7 +409,7 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return '';
}
}
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"');
attrs.push(' ' + lowerKey + '="' + escapeHtml(lowerKey === 'style' ? normalizeStyleAttributeValue(value) : value) + '"');
return '';
});
@@ -893,6 +914,45 @@ function getSlideMarkupCacheKey(slide) {
return [currentPlaylistSignature || '', slide && slide.id ? slide.id : '', slide && slide.template_id ? slide.template_id : '', slide && slide.modified_at ? slide.modified_at : '', viewportKey, videoRegionRenderVersion || 0].join('|');
}
function restorePlayerCanvasDimensions(width, height) {
if (!document || !document.documentElement) {
return;
}
var style = document.documentElement.style;
if (width) {
style.setProperty('--player-canvas-width', width);
} else {
style.removeProperty('--player-canvas-width');
}
if (height) {
style.setProperty('--player-canvas-height', height);
} else {
style.removeProperty('--player-canvas-height');
}
}
function primeSlideMarkup(slide) {
if (!slide) {
return '';
}
var cachedMarkup = getCachedSlideMarkup(slide);
if (cachedMarkup) {
return cachedMarkup;
}
var previousWidth = document && document.documentElement && document.documentElement.style ? String(document.documentElement.style.getPropertyValue('--player-canvas-width') || '') : '';
var previousHeight = document && document.documentElement && document.documentElement.style ? String(document.documentElement.style.getPropertyValue('--player-canvas-height') || '') : '';
try {
return buildSlideMarkupForState(slide, false);
} finally {
restorePlayerCanvasDimensions(previousWidth.trim(), previousHeight.trim());
}
}
function notifyVideoRegionSourceReady() {
if (typeof videoRegionRenderVersion === 'number') {
videoRegionRenderVersion += 1;
@@ -919,9 +979,12 @@ function setCachedSlideMarkup(slide, markup) {
// Slide rendering and markup cache helpers.
// Choose the right slide renderer and cache the result.
function buildSlideMarkup(slide) {
lastRenderedSlide = slide || null;
syncBlackoutState();
function buildSlideMarkupForState(slide, updateCurrentState) {
if (updateCurrentState) {
lastRenderedSlide = slide || null;
syncBlackoutState();
}
var cachedMarkup = getCachedSlideMarkup(slide);
if (cachedMarkup) {
return cachedMarkup;
@@ -938,3 +1001,7 @@ function buildSlideMarkup(slide) {
setCachedSlideMarkup(slide, markup);
return markup;
}
function buildSlideMarkup(slide) {
return buildSlideMarkupForState(slide, true);
}
+1 -1
View File
@@ -61,7 +61,7 @@ async function networkFirst(request, cacheName, cacheKeyRequest) {
if (cached) {
return cached;
}
throw _error;
return new Response('', { status: 504, statusText: 'Offline' });
}
}
+22 -6
View File
@@ -56,7 +56,7 @@ function getApiItem(sourceId, itemNumber, itemsPathOverride) {
return items[index] || null;
}
function substituteApiVariables(html, item) {
function substituteApiVariables(html, item, sourceId) {
var source = String(html || '');
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
if (!item || typeof item !== 'object') {
@@ -67,7 +67,25 @@ function substituteApiVariables(html, item) {
return '';
}
return escapeHtml(placeholderUtils.formatPlaceholderValue(placeholderUtils.resolvePlaceholderExpression(item, expression)));
var resolved = placeholderUtils.resolvePlaceholderExpression(item, expression);
if (typeof placeholderUtils.isImagePlaceholderExpression === 'function' && placeholderUtils.isImagePlaceholderExpression(expression)) {
var imageSource = placeholderUtils.formatPlaceholderValue(resolved);
var source = getApiSourceById(sourceId);
imageSource = source && source.imageCache && source.imageCache[imageSource] ? source.imageCache[imageSource] : imageSource;
if (!/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/])/i.test(imageSource)) {
return '';
}
var imageConfig = typeof placeholderUtils.getImagePlaceholderConfig === 'function' ? placeholderUtils.getImagePlaceholderConfig(expression) : {};
var hasImageBounds = imageConfig.width && imageConfig.height;
var imageStyle = hasImageBounds
? 'display:block;width:100%;height:100%;object-fit:contain;'
: 'display:block;width:auto;height:auto;' + (imageConfig.width ? 'max-width:' + imageConfig.width + 'px;' : '') + (imageConfig.height ? 'max-height:' + imageConfig.height + 'px;' : '');
var image = '<img src="' + escapeHtml(imageSource) + '" alt="" style="' + imageStyle + '" />';
return hasImageBounds
? '<span style="display:inline-flex;align-items:center;justify-content:center;box-sizing:border-box;width:' + imageConfig.width + 'px;height:' + imageConfig.height + 'px;">' + image + '</span>'
: image;
}
return escapeHtml(placeholderUtils.formatPlaceholderValue(resolved));
});
}
@@ -120,10 +138,8 @@ function renderApiRegion(region, regionContent) {
var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize);
var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor);
var item = getApiItem(sourceId, itemNumber, itemsPath);
var body = item ? substituteApiVariables(content, item) : '';
if (!body && item) {
body = getApiPreviewFallback(item);
}
var hasSource = String(sourceId === undefined || sourceId === null ? '' : sourceId).trim() !== '';
var body = hasSource ? (item ? substituteApiVariables(content, item, sourceId) : '') : content;
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
if (!body) {
return '';
+39 -3
View File
@@ -2,16 +2,52 @@
var registry = window.pulsePlayerRegionTypes;
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function buildHtmlDocument(html) {
var raw = String(html || '').trim();
if (!raw) {
return '';
}
if (/^<!doctype\b/i.test(raw) || /^<html\b/i.test(raw)) {
return raw;
}
return '<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}html,body{background:transparent !important;}</style></head><body>' + raw + '</body></html>';
}
function renderHtmlRegionContent(value) {
var html = String(value || '').trim();
var html = normalizeRenderableValue(value).trim();
if (!html) {
return '';
}
return '<iframe class="template-region-html-frame" sandbox="" scrolling="no" srcdoc="<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + escapeHtml(html) + '</body></html>" title="HTML region" loading="eager"></iframe>';
if (/^<!doctype\b/i.test(html) || /^<html\b/i.test(html)) {
return '<iframe class="template-region-html-frame" sandbox="" allowtransparency="true" scrolling="no" srcdoc="' + escapeHtml(html) + '" title="HTML region" loading="eager" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe>';
}
return '<div class="template-region-html-content" style="width:100%;height:100%;overflow:hidden;background:transparent;">' + html + '</div>';
}
function renderHtmlRegion(region, regionContent) {
return '<div class="template-region html" style="' + region.baseStyle + '">' + renderHtmlRegionContent(regionContent.value || '') + '</div>';
return '<div class="template-region html" style="' + region.baseStyle + '">' + renderHtmlRegionContent(regionContent && regionContent.value !== undefined ? regionContent.value : '') + '</div>';
}
registry.register('html', {
+20
View File
@@ -0,0 +1,20 @@
// QR code region rendering for embedded URL-to-image output.
var registry = window.pulsePlayerRegionTypes;
function renderQrCodeRegion(region, regionContent) {
var borderRadius = Math.max(0, Math.round(Number(regionContent && regionContent.qr_border_radius || 0)));
var radiusStyle = borderRadius > 0 ? 'border-radius:' + borderRadius + 'px;overflow:hidden;' : '';
var preview = String(regionContent && regionContent.qr_preview || '').trim();
if (!preview) {
return '';
}
return '<div class="template-region qr-code" style="' + region.baseStyle + radiusStyle + '"><img class="template-region-qr-code-image" src="' + escapeHtml(preview) + '" alt="QR code" role="img" draggable="false" style="background:transparent;display:block;width:100%;height:100%;object-fit:contain;' + radiusStyle + '" /></div>';
}
registry.register('qr-code', {
renderRegion: renderQrCodeRegion,
initRegion: function () {}
});
+27 -15
View File
@@ -1,6 +1,7 @@
// RSS region helpers for resolving feeds, items, and nested values.
var registry = window.pulsePlayerRegionTypes;
var placeholderUtils = window.placeholderUtils || {};
function getDefaultStyle() {
return {
@@ -63,14 +64,34 @@ function resolveRssPath(value, path) {
return current === undefined || current === null ? '' : current;
}
function substituteRssVariables(html, item) {
function substituteRssVariables(html, item, feedId) {
var source = String(html || '');
return source.replace(/\{\{\s*([a-zA-Z0-9_]+)(?:\.([a-zA-Z0-9_.]+))?\s*\}\}/g, function (_match, tokenName, tokenPath) {
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
if (!item || typeof item !== 'object') {
return '';
}
var key = tokenPath ? tokenName + '.' + tokenPath : tokenName;
return escapeHtml(resolveRssPath(item, key || ''));
if (typeof placeholderUtils.resolvePlaceholderExpression !== 'function' || typeof placeholderUtils.formatPlaceholderValue !== 'function') {
return '';
}
var resolved = placeholderUtils.resolvePlaceholderExpression(item, expression);
if (typeof placeholderUtils.isImagePlaceholderExpression === 'function' && placeholderUtils.isImagePlaceholderExpression(expression)) {
var imageSource = placeholderUtils.formatPlaceholderValue(resolved);
var feed = getRssFeedById(feedId);
imageSource = feed && feed.imageCache && feed.imageCache[imageSource] ? feed.imageCache[imageSource] : imageSource;
if (!/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/])/i.test(imageSource)) {
return '';
}
var imageConfig = typeof placeholderUtils.getImagePlaceholderConfig === 'function' ? placeholderUtils.getImagePlaceholderConfig(expression) : {};
var hasImageBounds = imageConfig.width && imageConfig.height;
var imageStyle = hasImageBounds
? 'display:block;width:100%;height:100%;object-fit:contain;'
: 'display:block;width:auto;height:auto;' + (imageConfig.width ? 'max-width:' + imageConfig.width + 'px;' : '') + (imageConfig.height ? 'max-height:' + imageConfig.height + 'px;' : '');
var image = '<img src="' + escapeHtml(imageSource) + '" alt="" style="' + imageStyle + '" />';
return hasImageBounds
? '<span style="display:inline-flex;align-items:center;justify-content:center;box-sizing:border-box;width:' + imageConfig.width + 'px;height:' + imageConfig.height + 'px;">' + image + '</span>'
: image;
}
return escapeHtml(placeholderUtils.formatPlaceholderValue(resolved));
});
}
@@ -83,17 +104,8 @@ function renderRssRegion(region, regionContent) {
var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize || defaultStyle.font_size);
var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor || defaultStyle.font_color);
var item = getRssFeedItem(feedId, itemNumber);
var body = item ? substituteRssVariables(content, item) : '';
if (!body && item) {
var summaryParts = [];
if (item.title) {
summaryParts.push('<h3>' + escapeHtml(item.title) + '</h3>');
}
if (item.description) {
summaryParts.push('<div>' + sanitizeRichText(item.description) + '</div>');
}
body = summaryParts.join('');
}
var hasFeed = String(feedId === undefined || feedId === null ? '' : feedId).trim() !== '';
var body = hasFeed ? (item ? substituteRssVariables(content, item, feedId) : '') : content;
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
if (!body) {
return '';
+5 -10
View File
@@ -304,13 +304,9 @@ function getRtmpWarmupSlides(sourceSlides, targetIndex) {
}
var warmupSlides = [];
var currentSlide = availableSlides[normalizedIndex];
var nextSlide = availableSlides[normalizedIndex + 1];
if (currentSlide) {
warmupSlides.push(currentSlide);
}
if (nextSlide && nextSlide !== currentSlide) {
if (nextSlide) {
warmupSlides.push(nextSlide);
}
@@ -693,12 +689,11 @@ function startRtmpPlayback(video, sourceUrl, disableAudio, skipUnavailable, plac
if (window.Hls && window.Hls.isSupported && window.Hls.isSupported()) {
var hls = new window.Hls({
enableWorker: true,
lowLatencyMode: true,
liveSyncDurationCount: 4,
liveMaxLatencyDurationCount: 8,
maxBufferLength: 20,
liveSyncDurationCount: 6,
liveMaxLatencyDurationCount: 12,
maxBufferLength: 30,
maxLiveSyncPlaybackRate: 1,
backBufferLength: 30
backBufferLength: 60
});
video.__rtmpHls = hls;
hls.attachMedia(video);
+1 -1
View File
@@ -40,7 +40,7 @@ function renderTextRegion(region, regionContent) {
var fontFamily = sanitizeFontFamily(regionContent.font_family || region.fontFamily || defaultStyle.font_family);
var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize || defaultStyle.font_size);
var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor || defaultStyle.font_color);
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;line-height:1.5;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
var renderedBody = renderEditorJsContent(rawValue);
return renderedBody ? '<div class="template-region text" style="' + region.baseStyle + '"><div class="template-region-text-scale" style="' + contentStyle + '">' + renderedBody + '</div></div>' : '';
}
+21 -28
View File
@@ -1,6 +1,7 @@
// Time/date region rendering and live updates.
var registry = window.pulsePlayerRegionTypes;
var placeholderUtils = window.placeholderUtils || {};
var DEFAULT_FORMAT = '{{hh}}:{{mm}}';
var DEFAULT_STYLE = {
font_family: 'Arial',
@@ -9,15 +10,6 @@ var DEFAULT_STYLE = {
};
var timeDateFormatterCache = Object.create(null);
function escapeHtml(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
function sanitizeTagAttributes(tagName, attrText) {
var allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'],
@@ -133,7 +125,7 @@ function resolveTimeZone(value) {
}
}
function getFormatter(key, options) {
function getTimeDateFormatter(key, options) {
if (!timeDateFormatterCache[key]) {
timeDateFormatterCache[key] = new Intl.DateTimeFormat('en-GB', options);
}
@@ -141,10 +133,10 @@ function getFormatter(key, options) {
return timeDateFormatterCache[key];
}
function getFormattedParts(timeZone, date) {
function getTimeDateFormattedParts(timeZone, date) {
var targetDate = date instanceof Date ? date : new Date();
var resolvedTimeZone = resolveTimeZone(timeZone);
var numericParts = getFormatter('numeric:' + resolvedTimeZone, {
var numericParts = getTimeDateFormatter('numeric:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
hour12: false,
hour: '2-digit',
@@ -154,29 +146,29 @@ function getFormattedParts(timeZone, date) {
month: '2-digit',
year: 'numeric'
}).formatToParts(targetDate);
var weekdayLong = getFormatter('weekday-long:' + resolvedTimeZone, {
var weekdayLong = getTimeDateFormatter('weekday-long:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
weekday: 'long'
}).formatToParts(targetDate);
var weekdayShort = getFormatter('weekday-short:' + resolvedTimeZone, {
var weekdayShort = getTimeDateFormatter('weekday-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
weekday: 'short'
}).formatToParts(targetDate);
var monthLong = getFormatter('month-long:' + resolvedTimeZone, {
var monthLong = getTimeDateFormatter('month-long:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
month: 'long'
}).formatToParts(targetDate);
var monthShort = getFormatter('month-short:' + resolvedTimeZone, {
var monthShort = getTimeDateFormatter('month-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
month: 'short'
}).formatToParts(targetDate);
var ampm = getFormatter('ampm:' + resolvedTimeZone, {
var ampm = getTimeDateFormatter('ampm:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
hour12: true,
hour: '2-digit',
minute: '2-digit'
}).formatToParts(targetDate);
var timezoneShort = getFormatter('tz-short:' + resolvedTimeZone, {
var timezoneShort = getTimeDateFormatter('tz-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone,
timeZoneName: 'short'
}).formatToParts(targetDate);
@@ -213,27 +205,28 @@ function getFormattedParts(timeZone, date) {
MMM: toTitleCase(getPart(monthShort, 'month')),
MMMM: toTitleCase(getPart(monthLong, 'month')),
a: toTitleCase(getPart(ampm, 'dayPeriod')),
tz: resolvedTimeZone,
tz_short: getPart(timezoneShort, 'timeZoneName'),
tz: getPart(timezoneShort, 'timeZoneName'),
tz_long: resolvedTimeZone,
date: getPart(numericParts, 'year') + '-' + getPart(numericParts, 'month') + '-' + getPart(numericParts, 'day'),
time: getPart(numericParts, 'hour') + ':' + getPart(numericParts, 'minute') + ':' + getPart(numericParts, 'second')
};
}
function resolveTimeDatePlaceholder(values, expression) {
if (typeof placeholderUtils.resolvePlaceholderExpression === 'function' && typeof placeholderUtils.formatPlaceholderValue === 'function') {
return placeholderUtils.formatPlaceholderValue(placeholderUtils.resolvePlaceholderExpression(values, expression));
function resolveTimeDateTemplatePlaceholder(values, expression) {
var currentPlaceholderUtils = window.placeholderUtils || placeholderUtils || {};
if (typeof currentPlaceholderUtils.resolvePlaceholderExpression === 'function' && typeof currentPlaceholderUtils.formatPlaceholderValue === 'function') {
return currentPlaceholderUtils.formatPlaceholderValue(currentPlaceholderUtils.resolvePlaceholderExpression(values, expression));
}
var parsed = String(expression || '').trim();
return Object.prototype.hasOwnProperty.call(values, parsed) ? values[parsed] : '';
}
function renderTemplate(format, timeZone, date) {
function renderTimeDateTemplate(format, timeZone, date) {
var template = String(format || '').trim() || DEFAULT_FORMAT;
var values = getFormattedParts(timeZone, date);
var values = getTimeDateFormattedParts(timeZone, date);
return template.replace(/\{\{\s*([a-zA-Z0-9_.()\-]+)\s*\}\}/g, function (_match, key) {
return String(resolveTimeDatePlaceholder(values, key) || '');
return String(resolveTimeDateTemplatePlaceholder(values, key, { timeZone: timeZone }) || '');
});
}
@@ -257,7 +250,7 @@ function renderTimeDateRegion(region, regionContent) {
var fontSize = style.font_size ? 'font-size:' + Math.max(1, Math.round(Number(style.font_size))) + 'px;' : '';
var fontColor = style.font_color ? 'color:' + escapeHtml(style.font_color) + ';' : '';
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? fontFamily : '') + fontSize + fontColor + 'white-space:pre-wrap;line-height:1.1;';
var renderedText = renderTemplate(format, timeZone, new Date());
var renderedText = renderTimeDateTemplate(format, timeZone, new Date());
return '<div class="template-region time-date" data-time-date-format="' + escapeHtml(format) + '" data-time-date-timezone="' + escapeHtml(timeZone) + '" style="' + region.baseStyle + '"><div class="template-region-text-scale" style="' + contentStyle + '">' + renderEditorJsContent(renderedText) + '</div></div>';
}
@@ -273,7 +266,7 @@ function updateTimeDateRegion(element) {
return;
}
scaleWrapper.innerHTML = renderEditorJsContent(renderTemplate(format, timeZone, new Date()));
scaleWrapper.innerHTML = renderEditorJsContent(renderTimeDateTemplate(format, timeZone, new Date()));
}
function scheduleTimeDateRegionUpdate(element) {
@@ -2,101 +2,6 @@
var registry = window.pulsePlayerRegionTypes;
function escapeHtml(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
function sanitizeRichTextAttributes(tagName, attrText) {
var allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'],
blockquote: ['class', 'style'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
div: ['class', 'style'],
figure: ['class', 'style'],
figcaption: ['class', 'style'],
h1: ['class', 'style'],
h2: ['class', 'style'],
h3: ['class', 'style'],
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
pre: ['class', 'style'],
span: ['class', 'style'],
table: ['class', 'style'],
tbody: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
thead: ['class', 'style'],
tr: ['class', 'style'],
ul: ['class', 'style']
};
var allowed = allowedAttributes[tagName] || [];
if (!allowed.length) {
return '';
}
var attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, function (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) {
var lowerKey = String(key || '').toLowerCase();
if (allowed.indexOf(lowerKey) === -1) {
return '';
}
var value = doubleQuoted !== undefined ? doubleQuoted : singleQuoted !== undefined ? singleQuoted : bareValue !== undefined ? bareValue : '';
if (lowerKey === 'href' && /^(?:\s*javascript:|\s*data:)/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'style' && /(?:expression\s*\(|javascript:|url\s*\()/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'target') {
var targetValue = String(value || '').trim();
if (targetValue === '_blank') {
attrs.push(' target="_blank"');
if (attrs.indexOf(' rel="noreferrer noopener"') === -1) {
attrs.push(' rel="noreferrer noopener"');
}
return '';
}
}
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"');
return '';
});
return attrs.join('');
}
function sanitizeRichText(html) {
var output = String(html || '');
output = output.replace(/<script[\s\S]*?<\/script>/gi, '');
output = output.replace(/<style[\s\S]*?<\/style>/gi, '');
return output.replace(/<[^>]+>/g, function (tag) {
var match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)([\s\S]*?)(\/?)>$/i);
if (!match) {
return '';
}
var closing = Boolean(match[1]);
var name = String(match[2] || '').toLowerCase();
var allowed = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
if (allowed.indexOf(name) === -1) {
return '';
}
if (closing) {
return '</' + name + '>';
}
return '<' + name + sanitizeRichTextAttributes(name, String(match[3] || '')) + '>';
});
}
function substituteTimetableVariables(html, entry) {
var source = String(html || '');
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
@@ -228,6 +133,7 @@ function renderRegion(region, regionContent) {
var maxItems = regionContent && regionContent.max_items !== undefined ? regionContent.max_items : 5;
var group = getGroupById(groupId, groups);
var entries = getVisibleEntries(groupId, displayMode, maxItems, groups);
var timeZone = group && (group.timezone || group.time_zone) ? String(group.timezone || group.time_zone) : '';
var width = Math.max(1, Math.round(Number(region && region.pixelWidth ? region.pixelWidth : 0) || 1));
var height = Math.max(1, Math.round(Number(region && region.pixelHeight ? region.pixelHeight : 0) || 1));
var canvasScale = Number(region && region.canvasScale ? region.canvasScale : 1) || 1;
@@ -241,6 +147,7 @@ function renderRegion(region, regionContent) {
return '<div class="timetable-region-entry" data-timetable-entry-index="' + index + '">' + sanitizeRichText(substituteTimetableVariables(value, Object.assign({}, entry || {}, {
start: entry && entry.start_datetime !== undefined ? entry.start_datetime : '',
end: entry && entry.end_datetime !== undefined ? entry.end_datetime : '',
timeZone: timeZone,
group: group || {},
entries: entries,
index: index + 1
+3 -3
View File
@@ -122,7 +122,7 @@ function renderVideoRegion(region, regionContent) {
videoRegionLastGoodSrcCache[regionKey] = requestedSrc;
}
setVideoSourceAvailability(requestedSrc, true);
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(requestedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})" onloadedmetadata="this.play().catch(function () {})"></video></div>';
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(requestedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})"></video></div>';
}
var requestedState = getVideoSourceAvailability(requestedSrc);
@@ -132,7 +132,7 @@ function renderVideoRegion(region, regionContent) {
if (regionKey) {
videoRegionLastGoodSrcCache[regionKey] = requestedSrc;
}
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(requestedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})" onloadedmetadata="this.play().catch(function () {})"></video></div>';
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(requestedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})"></video></div>';
}
scheduleVideoSourceProbe(regionKey, requestedSrc, false);
@@ -141,7 +141,7 @@ function renderVideoRegion(region, regionContent) {
if (cachedSrc !== requestedSrc) {
logVideoRegionStatus('Keeping the previous playable video until the new mirrored file finishes transferring.', 'region=' + regionKey + ' old=' + cachedSrc + ' new=' + requestedSrc);
}
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(cachedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})" onloadedmetadata="this.play().catch(function () {})"></video></div>';
return '<div class="template-region video" style="' + region.baseStyle + '"><video src="' + escapeHtml(cachedSrcVersioned) + '" title="' + escapeHtml(region.label) + '" data-disable-audio="' + (disableAudio ? '1' : '0') + '" autoplay' + (disableAudio ? ' muted' : '') + ' loop playsinline preload="auto" disablepictureinpicture oncanplay="this.play().catch(function () {})"></video></div>';
}
return '';
+28 -2
View File
@@ -2,12 +2,38 @@
var registry = window.pulsePlayerRegionTypes;
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.url !== undefined) {
return normalizeRenderableValue(value.url);
}
if (value.href !== undefined) {
return normalizeRenderableValue(value.href);
}
if (value.src !== undefined) {
return normalizeRenderableValue(value.src);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function renderWebpageRegion(region, regionContent) {
var url = String(regionContent.value || '').trim();
var url = normalizeRenderableValue(regionContent && regionContent.value !== undefined ? regionContent.value : '').trim();
if (!url) {
return '';
}
return '<div class="template-region webpage" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(url) + '" title="' + escapeHtml(region.label) + '" loading="eager" referrerpolicy="no-referrer" scrolling="no"></iframe></div>';
return '<div class="template-region webpage" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(url) + '" title="' + escapeHtml(region.label) + '" loading="eager" referrerpolicy="no-referrer" scrolling="no" style="width:100%;height:100%;border:0;display:block;background:#fff;overflow:hidden;"></iframe></div>';
}
registry.register('webpage', {
+58 -5
View File
@@ -25,6 +25,14 @@ function escapeHtml(value) {
.replace(/'/g, '&#39;');
}
function normalizeStyleAttributeValue(value) {
return String(value || '')
.replace(/&quot;/g, '"')
.replace(/&#39;/g, "'")
.replace(/&amp;quot;/g, '"')
.replace(/&amp;#39;/g, "'");
}
function sanitizeFontFamily(value) {
return String(value || '').replace(/[^a-zA-Z0-9 ,"-]/g, '').trim();
}
@@ -41,7 +49,7 @@ function sanitizeTextColor(value, fallback) {
return fallback || '#000000';
}
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = {
@@ -56,6 +64,9 @@ function sanitizeRichTextAttributes(tagName, attrText) {
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
@@ -72,6 +83,14 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return '';
}
if (tagName === 'img') {
const srcMatch = String(attrText || '').match(/\bsrc\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+))/i);
const srcValue = srcMatch ? String(srcMatch[2] !== undefined ? srcMatch[2] : srcMatch[3] !== undefined ? srcMatch[3] : srcMatch[4] !== undefined ? srcMatch[4] : '').trim() : '';
if (!srcValue || !/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/]|data:image\/)/i.test(srcValue)) {
return '';
}
}
const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase();
@@ -95,7 +114,7 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return '';
}
}
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"');
attrs.push(' ' + lowerKey + '="' + escapeHtml(lowerKey === 'style' ? normalizeStyleAttributeValue(value) : value) + '"');
return '';
});
@@ -268,12 +287,45 @@ function renderEditorJsContent(value) {
return wrapRichTextParagraph(sanitizeRichText(raw));
}
function buildHtmlDocument(html) {
const raw = String(html || '').trim();
if (!raw) {
return '';
}
if (/^<!doctype\b/i.test(raw) || /^<html\b/i.test(raw)) {
return raw;
}
return '<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + raw + '</body></html>';
}
function renderHtmlRegionContent(value) {
const html = String(value || '').trim();
const html = normalizeRenderableValue(value).trim();
if (!html) {
return '<div class="template-region-placeholder">HTML</div>';
}
return '<iframe class="template-region-html-frame" sandbox="" srcdoc="' + escapeHtml(html) + '" title="HTML region" loading="eager"></iframe>';
return '<iframe class="template-region-html-frame" sandbox="" srcdoc="' + escapeHtml(buildHtmlDocument(html)) + '" title="HTML region" loading="eager" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe>';
}
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function fitCanvasSize(canvasWidth, canvasHeight, maxWidth, maxHeight) {
@@ -442,8 +494,9 @@ function getPlayerRegionScriptPaths() {
function getPlayerRegionScripts() {
const sharedPlaceholderUtilsPath = path.join(__dirname, '..', 'web', 'public', 'js', 'shared', 'placeholder-utils.js');
const sharedQrSvgUtilsPath = path.join(__dirname, '..', 'web', 'public', 'js', 'shared', 'qr-code-svg.js');
const playerRegionScriptPaths = getPlayerRegionScriptPaths();
const scriptPaths = [sharedPlaceholderUtilsPath].concat(playerRegionScriptPaths);
const scriptPaths = [sharedPlaceholderUtilsPath, sharedQrSvgUtilsPath].concat(playerRegionScriptPaths);
const statSignature = scriptPaths.map(function (filePath) {
return fs.statSync(filePath).mtimeMs;
}).join('|');
+1 -1
View File
@@ -46,7 +46,7 @@ function renderOnboardingLandingBody() {
' <div class="onboarding-layout">',
' <div class="onboarding-qr-pane">',
' <div class="onboarding-qr-frame">',
' <img id="onboarding-qr" alt="Onboarding QR code" />',
' <img id="onboarding-qr" alt="Onboarding QR code" src="data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E" />',
' </div>',
' <div id="onboarding-status" class="onboarding-status">Preparing onboarding link...</div>',
' </div>',
+196 -16
View File
@@ -3,7 +3,8 @@
const fs = require('fs');
const express = require('express');
const path = require('path');
const { getSharedSecret, createPageAuthBundle, verifyPageAuthToken, verifyRequestAuth } = require('#src/request-auth');
const { getSharedSecret, createPageAuthBundle, verifyPageAuthToken, verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth');
const { getPlayerPublicBaseUrl } = require('./onboarding');
const { buildThumbnailPreviewData } = require('./thumbnail-preview');
const TRANSIENT_DB_ERROR_CODES = ['ECONNREFUSED', 'ECONNRESET', 'ETIMEDOUT', 'EPIPE', 'ENOTFOUND', 'PROTOCOL_CONNECTION_LOST', 'POOL_CLOSED', 'ERR_POOL_CLOSED'];
@@ -12,6 +13,17 @@ function isTransientDbError(error) {
return Boolean(error && TRANSIENT_DB_ERROR_CODES.indexOf(String(error.code || '').trim()) !== -1);
}
function isBridgeFetchError(error) {
const message = String(error && error.message || '').toLowerCase();
return Boolean(error && (
message.indexOf('fetch failed') !== -1 ||
message.indexOf('network error') !== -1 ||
message.indexOf('econnreset') !== -1 ||
message.indexOf('econnrefused') !== -1 ||
message.indexOf('enotfound') !== -1
));
}
function registerPlayerRoutes(app, options) {
const pool = options && options.pool ? options.pool : null;
const common = options && options.common ? options.common : null;
@@ -20,16 +32,70 @@ function registerPlayerRoutes(app, options) {
const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null;
const playerPlaylistService = options && options.playerPlaylistService ? options.playerPlaylistService : null;
const rtmpStreamService = options && options.rtmpStreamService ? options.rtmpStreamService : null;
const playerPublicBaseUrl = String(options && options.playerPublicBaseUrl || process.env.PLAYER_PUBLIC_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const playerInternalBaseUrl = String(options && options.playerInternalBaseUrl || process.env.PLAYER_INTERNAL_BASE_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const playerIdentifier = String(options && options.playerIdentifier || '1').trim() || '1';
const playerInternalUrl = String(options && options.playerInternalBaseUrl || process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, '');
const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const playerDeviceId = String(options && options.playerDeviceId || '').trim() || null;
const onPlayerPublicBaseUrl = typeof options.onPlayerPublicBaseUrl === 'function' ? options.onPlayerPublicBaseUrl : null;
if (!app || !pool || !common || !mediaDir || !assetDir || !playerRuntime || !playerPlaylistService || !rtmpStreamService) {
throw new Error('registerPlayerRoutes requires app, pool, common, mediaDir, assetDir, playerRuntime, playerPlaylistService, and rtmpStreamService.');
if (!app || !common || !mediaDir || !assetDir || !playerRuntime || !rtmpStreamService) {
throw new Error('registerPlayerRoutes requires app, common, mediaDir, assetDir, playerRuntime, and rtmpStreamService.');
}
if (!bridgeBaseUrl && (!pool || !playerPlaylistService)) {
throw new Error('registerPlayerRoutes requires pool and playerPlaylistService unless bridgeBaseUrl is configured.');
}
const sharedSecret = getSharedSecret();
async function fetchBridge(req, pathname, options) {
if (!bridgeBaseUrl) {
return null;
}
const requestOptions = options && typeof options === 'object' ? options : {};
const method = String(requestOptions.method || req.method || 'GET').trim().toUpperCase();
const body = Object.prototype.hasOwnProperty.call(requestOptions, 'body') ? requestOptions.body : undefined;
const requestPathname = String(pathname || '').split('?')[0];
const headers = Object.assign({}, requestOptions.headers || {}, createRequestAuthHeaders({
method: method,
pathname: requestPathname,
body: body
}));
if (req.headers['x-pulse-page-auth']) {
headers['x-pulse-page-auth'] = String(req.headers['x-pulse-page-auth']).trim();
}
if (req.headers['if-none-match']) {
headers['if-none-match'] = String(req.headers['if-none-match']).trim();
}
if (requestOptions.contentType) {
headers['content-type'] = requestOptions.contentType;
}
return fetch(new URL(pathname, bridgeBaseUrl).toString(), {
method: method,
headers: headers,
body: body === undefined || body === null || method === 'GET' || method === 'HEAD' ? undefined : body
});
}
async function readJsonResponse(response) {
if (!response) {
return null;
}
const contentType = String(response.headers && typeof response.headers.get === 'function' ? response.headers.get('content-type') : '').toLowerCase();
if (contentType.indexOf('application/json') === -1 && contentType.indexOf('+json') === -1) {
return null;
}
try {
return await response.json();
} catch (_error) {
return null;
}
}
function requirePageAuth(allowedScopes) {
return function (req, res, next) {
if (!sharedSecret) {
@@ -114,6 +180,26 @@ function registerPlayerRoutes(app, options) {
});
app.get('/api/media/config', requireRequestAuth, function (_req, res) {
if (bridgeBaseUrl) {
void fetch(new URL('/api/media/config', bridgeBaseUrl).toString(), {
method: 'GET',
headers: createRequestAuthHeaders({
method: 'GET',
pathname: '/api/media/config'
})
}).then(async function (response) {
res.status(response.status);
const contentType = response.headers.get('content-type');
if (contentType) {
res.type(contentType);
}
res.send(await response.text());
}).catch(function (_error) {
res.status(502).json({ error: 'Thin client unavailable.' });
});
return;
}
res.json({
mediaDir: mediaDir,
uploadDir: path.join(mediaDir, 'uploads')
@@ -211,11 +297,44 @@ function registerPlayerRoutes(app, options) {
});
app.get('/screen/:slug', function (req, res) {
if (onPlayerPublicBaseUrl) {
try {
onPlayerPublicBaseUrl(getPlayerPublicBaseUrl(req, null));
} catch (_error) {
}
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.set('Pragma', 'no-cache');
if (bridgeBaseUrl) {
const pageAuthToken = createPageAuthBundle({ scope: 'player', slug: String(req.params.slug || '').trim() }).token;
void fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/playlist?ts=' + Date.now(), {
method: 'GET',
headers: pageAuthToken ? { 'x-pulse-page-auth': pageAuthToken } : {}
}).then(async function (response) {
if (!response || response.status >= 400) {
res.set('X-Player-Offline', '1');
return res.send(common.renderPlayerPage(req.params.slug, null));
}
const data = await readJsonResponse(response);
if (!data) {
res.set('X-Player-Offline', '1');
return res.send(common.renderPlayerPage(req.params.slug, null));
}
res.send(common.renderPlayerPage(req.params.slug, data));
}).catch(function (error) {
if (!isBridgeFetchError(error)) {
console.error(error);
}
res.set('X-Player-Offline', '1');
res.send(common.renderPlayerPage(req.params.slug, null));
});
return;
}
const { bindPlayerToScreen } = require('./onboarding');
if (playerIdentifier) {
void bindPlayerToScreen(pool, playerIdentifier, req.params.slug)
if (playerDeviceId) {
void bindPlayerToScreen(pool, playerDeviceId, req.params.slug)
.catch(function (error) {
console.error(error);
});
@@ -231,6 +350,19 @@ function registerPlayerRoutes(app, options) {
app.get('/api/internal/slide-thumbnails/:id/preview', requireRequestAuth, async function (req, res, next) {
try {
if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/internal/slide-thumbnails/' + encodeURIComponent(req.params.id) + '/preview', {
method: 'GET'
});
if (!response) {
return res.status(502).send('Thin client unavailable');
}
res.status(response.status);
res.set('Cache-Control', response.headers.get('cache-control') || 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.type(response.headers.get('content-type') || 'text/html; charset=utf-8');
return res.send(await response.text());
}
const slide = await common.fetchSlideById(pool, Number(req.params.id));
if (!slide) {
return res.status(404).send('Slide not found');
@@ -273,6 +405,29 @@ function registerPlayerRoutes(app, options) {
app.get('/api/screens/:slug/playlist', requirePageAuth(['player']), async function (req, res, next) {
try {
if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/playlist', {
method: 'GET'
});
if (!response) {
return res.status(502).json({ error: 'Thin client unavailable.' });
}
res.status(response.status);
const etag = response.headers.get('etag');
const cacheControl = response.headers.get('cache-control');
if (etag) {
res.set('ETag', etag);
}
if (cacheControl) {
res.set('Cache-Control', cacheControl);
}
if (response.status === 304) {
return res.end();
}
res.type(response.headers.get('content-type') || 'application/json');
return res.send(await response.text());
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
const data = await playerPlaylistService.buildScreenPlaylist(req.params.slug);
if (!data.screen) {
@@ -293,6 +448,29 @@ function registerPlayerRoutes(app, options) {
app.get('/api/screens/:slug/announcement', requirePageAuth(['player']), async function (req, res, next) {
try {
if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/announcement', {
method: 'GET'
});
if (!response) {
return res.status(502).json({ error: 'Thin client unavailable.' });
}
res.status(response.status);
const etag = response.headers.get('etag');
const cacheControl = response.headers.get('cache-control');
if (etag) {
res.set('ETag', etag);
}
if (cacheControl) {
res.set('Cache-Control', cacheControl);
}
if (response.status === 304) {
return res.end();
}
res.type(response.headers.get('content-type') || 'application/json');
return res.send(await response.text());
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
const announcement = typeof common.fetchActiveAnnouncement === 'function'
? await common.fetchActiveAnnouncement(pool, req.params.slug)
@@ -335,13 +513,15 @@ function registerPlayerRoutes(app, options) {
const connections = playerRuntime.snapshotConnections(req.params.slug);
let screen = null;
let screenLookupFailed = false;
try {
const [screenRows] = await pool.query('SELECT id, name, slug FROM d_screens WHERE slug = ?', [req.params.slug]);
screen = screenRows[0] || null;
} catch (error) {
screenLookupFailed = isTransientDbError(error);
if (!screenLookupFailed) {
throw error;
if (pool && typeof pool.query === 'function') {
try {
const [screenRows] = await pool.query('SELECT id, name, slug FROM d_screens WHERE slug = ?', [req.params.slug]);
screen = screenRows[0] || null;
} catch (error) {
screenLookupFailed = isTransientDbError(error);
if (!screenLookupFailed) {
throw error;
}
}
}
res.json({
@@ -374,7 +554,7 @@ function registerPlayerRoutes(app, options) {
const isRedirectCommand = command === 'redirect';
let screen = null;
let screenLookupFailed = false;
if (!isRedirectCommand) {
if (!isRedirectCommand && pool && typeof pool.query === 'function') {
try {
const [screenRows] = await pool.query('SELECT id, name, slug FROM d_screens WHERE slug = ?', [req.params.slug]);
screen = screenRows[0] || null;
+88 -15
View File
@@ -21,6 +21,7 @@ function normalizePlayerPublicBaseUrl(pageUrl) {
function createPlayerRuntime(options) {
const pool = options && options.pool ? options.pool : null;
const notifySnapshot = typeof options.notifySnapshot === 'function' ? options.notifySnapshot : null;
const normalizeDeviceId = typeof options.normalizeDeviceId === 'function'
? options.normalizeDeviceId
: function (value) {
@@ -44,6 +45,76 @@ function createPlayerRuntime(options) {
return ip;
}
function firstHeaderValue(value) {
return String(value || '').trim().split(',')[0].trim();
}
function isPrivateOrReservedIp(ip) {
const normalized = normalizeClientIp(ip);
if (!normalized) {
return true;
}
const lower = normalized.toLowerCase();
if (lower === 'localhost' || lower === '::1') {
return true;
}
if (/^10\./.test(lower) || /^192\.168\./.test(lower) || /^127\./.test(lower) || /^169\.254\./.test(lower)) {
return true;
}
if (/^172\.(1[6-9]|2\d|3[0-1])\./.test(lower)) {
return true;
}
if (lower.startsWith('fc') || lower.startsWith('fd') || lower.startsWith('fe80:') || lower.startsWith('::ffff:127.')) {
return true;
}
return false;
}
function pickForwardedIp(candidates) {
const normalizedCandidates = Array.isArray(candidates)
? candidates.map(function (candidate) {
return normalizeClientIp(candidate);
}).filter(Boolean)
: [];
const publicCandidate = normalizedCandidates.find(function (candidate) {
return !isPrivateOrReservedIp(candidate);
});
return publicCandidate || normalizedCandidates[0] || null;
}
function resolveRequestIp(request) {
const forwardedFor = String(request && request.headers && request.headers['x-forwarded-for'] || '').split(',');
const forwardedForIp = pickForwardedIp(forwardedFor);
if (forwardedForIp) {
return forwardedForIp;
}
const realIp = pickForwardedIp([firstHeaderValue(request && request.headers && request.headers['x-real-ip'])]);
if (realIp) {
return realIp;
}
const forwarded = firstHeaderValue(request && request.headers && request.headers.forwarded);
if (forwarded) {
const forwardedMatches = Array.from(forwarded.matchAll(/(?:^|,\s*|;\s*)for=(?:"?\[?)([^"\];,\s]+)/gi)).map(function (match) {
return match[1];
});
const forwardedIp = pickForwardedIp(forwardedMatches);
if (forwardedIp) {
return forwardedIp;
}
}
return normalizeClientIp(request && request.socket && request.socket.remoteAddress);
}
function parseCookies(cookieHeader) {
return String(cookieHeader || '').split(/;\s*/).reduce(function (cookies, pair) {
if (!pair) {
@@ -144,7 +215,6 @@ function createPlayerRuntime(options) {
const clientName = String(connection.clientName || '').trim();
const clientId = String(connection.clientId || '').trim();
const userAgent = String(connection.userAgent || '').trim();
const clientIp = String(connection.clientIp || '').trim();
const viewport = connection.viewport && typeof connection.viewport === 'object'
? connection.viewport
: null;
@@ -160,10 +230,6 @@ function createPlayerRuntime(options) {
labelParts.push(`id ${clientId.slice(-6)}`);
}
if (clientIp) {
labelParts.push(clientIp);
}
if (viewport && Number.isFinite(Number(viewport.width)) && Number.isFinite(Number(viewport.height))) {
labelParts.push(`${Number(viewport.width)}x${Number(viewport.height)}`);
}
@@ -197,8 +263,6 @@ function createPlayerRuntime(options) {
blackout: Boolean(connection.blackout),
currentSlideId: connection.currentSlide && connection.currentSlide.id ? connection.currentSlide.id : null,
currentSlideTitle: connection.currentSlide && connection.currentSlide.title ? connection.currentSlide.title : null,
clientIp: connection.clientIp || null,
remoteAddress: connection.remoteAddress || null,
connectedAt: connection.connectedAt ? connection.connectedAt.toISOString() : null,
lastSeenAt: connection.lastSeenAt ? connection.lastSeenAt.toISOString() : null
};
@@ -222,6 +286,10 @@ function createPlayerRuntime(options) {
return allConnections;
}
function snapshotSlugs() {
return Array.from(connectionsBySlug.keys());
}
async function isClientNameAvailableOnScreen(poolArg, clientName, excludeDeviceId) {
return isClientNameAvailable(poolArg || pool, clientName, excludeDeviceId, snapshotAllConnections());
}
@@ -229,6 +297,16 @@ function createPlayerRuntime(options) {
function broadcastConnectionSnapshot(slug) {
const key = String(slug || '').trim();
const bucket = dashboardListenersBySlug.get(key);
const connections = snapshotConnections(slug);
if (notifySnapshot) {
try {
notifySnapshot({
slug: key,
connections: connections
});
} catch (_error) {
}
}
if (!bucket || !bucket.size) {
return;
}
@@ -236,7 +314,7 @@ function createPlayerRuntime(options) {
const payload = JSON.stringify({
type: 'snapshot',
slug: key,
connections: snapshotConnections(slug),
connections: connections,
sentAt: new Date().toISOString()
});
@@ -416,9 +494,6 @@ function createPlayerRuntime(options) {
return;
}
const remoteAddress = request.socket && request.socket.remoteAddress ? request.socket.remoteAddress : null;
const forwardedFor = normalizeClientIp(String(request.headers['x-forwarded-for'] || '').split(',')[0]);
const normalizedRemoteAddress = normalizeClientIp(remoteAddress);
const connectionId = crypto.randomUUID();
const connection = {
id: connectionId,
@@ -433,9 +508,7 @@ function createPlayerRuntime(options) {
paused: false,
blackout: false,
playerPublicBaseUrl: null,
clientIp: forwardedFor || normalizedRemoteAddress,
remoteAddress: normalizedRemoteAddress,
label: forwardedFor || normalizedRemoteAddress || 'connected client',
label: 'connected client',
connectedAt: new Date(),
lastSeenAt: new Date()
};
@@ -476,7 +549,6 @@ function createPlayerRuntime(options) {
}
connection.paused = Boolean(payload.paused);
connection.blackout = Boolean(payload.blackout);
connection.clientIp = payload.clientIp ? normalizeClientIp(payload.clientIp) || connection.clientIp : connection.clientIp;
connection.currentSlide = payload.currentSlide && typeof payload.currentSlide === 'object' ? {
id: payload.currentSlide.id || null,
title: payload.currentSlide.title || '',
@@ -508,6 +580,7 @@ function createPlayerRuntime(options) {
broadcastAnnouncementRefresh: broadcastAnnouncementRefresh,
snapshotConnections: snapshotConnections,
snapshotAllConnections: snapshotAllConnections,
snapshotSlugs: snapshotSlugs,
isClientNameAvailableOnScreen: isClientNameAvailableOnScreen,
sendCommandToConnection: sendCommandToConnection,
broadcastCommand: broadcastCommand
+215 -181
View File
@@ -2,208 +2,242 @@
const PERMISSION_SECTIONS = [
{
key: 'dashboard',
sectionName: 'Main navigation',
order: 10,
name: 'Dashboard',
sectionName: 'Main navigation',
actions: [
{ key: 'read', name: 'Read', description: 'Access the dashboard overview.' },
{ key: 'allow', name: 'Allow', description: 'Send global player commands.' }
permissions: [
{
key: 'dashboard',
order: 10,
name: 'Dashboard',
permissions: [
{ key: 'read', name: 'Read', description: 'Access the dashboard overview.' },
{ key: 'allow', name: 'Allow', description: 'Send global player commands.' }
]
},
{
key: 'clients',
order: 20,
name: 'Connected clients',
permissions: [
{ key: 'read', name: 'Read', description: 'View connected player clients and live status.' },
{ key: 'allow', name: 'Allow', description: 'Use the connected client command buttons.' }
]
}
]
},
{
key: 'clients',
sectionName: 'Content',
order: 20,
name: 'Connected clients',
sectionName: 'Main navigation',
actions: [
{ key: 'read', name: 'Read', description: 'View connected player clients and live status.' },
{ key: 'allow', name: 'Allow', description: 'Use the connected client command buttons.' }
permissions: [
{
key: 'screens',
order: 10,
name: 'Screens',
permissions: [
{ key: 'read', name: 'Read', description: 'View the screen list and open screen details.' },
{ key: 'create', name: 'Create', description: 'Create new screens.' },
{ key: 'update', name: 'Update', description: 'Update screens.' },
{ key: 'delete', name: 'Delete', description: 'Delete screens.' }
]
},
{
key: 'playlists',
order: 20,
name: 'Playlists',
permissions: [
{ key: 'read', name: 'Read', description: 'View playlists and playlist contents.' },
{ key: 'create', name: 'Create', description: 'Create new playlists.' },
{ key: 'update', name: 'Update', description: 'Update playlists and playlist slides.' },
{ key: 'delete', name: 'Delete', description: 'Delete playlists.' }
]
},
{
key: 'slides',
order: 30,
name: 'Slides',
permissions: [
{ key: 'read', name: 'Read', description: 'View slides.' },
{ key: 'create', name: 'Create', description: 'Create new slides.' },
{ key: 'update', name: 'Update', description: 'Update slide content.' },
{ key: 'delete', name: 'Delete', description: 'Delete slides.' }
]
},
{
key: 'templates',
order: 40,
name: 'Slide templates',
permissions: [
{ key: 'read', name: 'Read', description: 'View slide templates.' },
{ key: 'create', name: 'Create', description: 'Create new slide templates.' },
{ key: 'update', name: 'Update', description: 'Update slide templates.' },
{ key: 'delete', name: 'Delete', description: 'Delete slide templates.' }
]
},
{
key: 'canvas-sizes',
order: 50,
name: 'Canvas sizes',
permissions: [
{ key: 'read', name: 'Read', description: 'View canvas sizes.' },
{ key: 'create', name: 'Create', description: 'Create new canvas sizes.' },
{ key: 'update', name: 'Update', description: 'Update canvas sizes.' },
{ key: 'delete', name: 'Delete', description: 'Delete canvas sizes.' }
]
},
{
key: 'announcements',
order: 60,
name: 'Announcements',
permissions: [
{ key: 'read', name: 'Read', description: 'View announcements.' },
{ key: 'create', name: 'Create', description: 'Create new announcements.' },
{ key: 'update', name: 'Update', description: 'Update announcements.' },
{ key: 'delete', name: 'Delete', description: 'Delete announcements.' }
]
}
]
},
{
key: 'screens',
sectionName: 'Data Sources',
order: 30,
name: 'Screens',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View the screen list and open screen details.' },
{ key: 'create', name: 'Create', description: 'Create new screens.' },
{ key: 'update', name: 'Update', description: 'Update screens.' },
{ key: 'delete', name: 'Delete', description: 'Delete screens.' }
permissions: [
{
key: 'rss-feeds',
order: 10,
name: 'RSS feeds',
permissions: [
{ key: 'read', name: 'Read', description: 'View configured RSS feeds.' },
{ key: 'create', name: 'Create', description: 'Create new RSS feeds.' },
{ key: 'update', name: 'Update', description: 'Update RSS feeds.' },
{ key: 'delete', name: 'Delete', description: 'Delete RSS feeds.' }
]
},
{
key: 'api-sources',
order: 20,
name: 'API sources',
permissions: [
{ key: 'read', name: 'Read', description: 'View configured API sources.' },
{ key: 'create', name: 'Create', description: 'Create new API sources.' },
{ key: 'update', name: 'Update', description: 'Update API sources.' },
{ key: 'delete', name: 'Delete', description: 'Delete API sources.' }
]
},
{
key: 'timetables',
order: 30,
name: 'Timetables',
permissions: [
{ key: 'read', name: 'Read', description: 'View configured timetable groups.' },
{ key: 'create', name: 'Create', description: 'Create new timetable groups.' },
{ key: 'update', name: 'Update', description: 'Update timetable groups and entries.' },
{ key: 'delete', name: 'Delete', description: 'Delete timetable groups.' }
]
}
]
},
{
key: 'playlists',
sectionName: 'Settings',
order: 40,
name: 'Playlists',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View playlists and playlist contents.' },
{ key: 'create', name: 'Create', description: 'Create new playlists.' },
{ key: 'update', name: 'Update', description: 'Update playlists and playlist slides.' },
{ key: 'delete', name: 'Delete', description: 'Delete playlists.' }
]
},
{
key: 'slides',
order: 50,
name: 'Slides',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View slides.' },
{ key: 'create', name: 'Create', description: 'Create new slides.' },
{ key: 'update', name: 'Update', description: 'Update slide content.' },
{ key: 'delete', name: 'Delete', description: 'Delete slides.' }
]
},
{
key: 'templates',
order: 60,
name: 'Slide templates',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View slide templates.' },
{ key: 'create', name: 'Create', description: 'Create new slide templates.' },
{ key: 'update', name: 'Update', description: 'Update slide templates.' },
{ key: 'delete', name: 'Delete', description: 'Delete slide templates.' }
]
},
{
key: 'canvas-sizes',
order: 70,
name: 'Canvas sizes',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View canvas sizes.' },
{ key: 'create', name: 'Create', description: 'Create new canvas sizes.' },
{ key: 'update', name: 'Update', description: 'Update canvas sizes.' },
{ key: 'delete', name: 'Delete', description: 'Delete canvas sizes.' }
]
},
{
key: 'announcements',
order: 80,
name: 'Announcements',
sectionName: 'Content',
actions: [
{ key: 'read', name: 'Read', description: 'View announcements.' },
{ key: 'create', name: 'Create', description: 'Create new announcements.' },
{ key: 'update', name: 'Update', description: 'Update announcements.' },
{ key: 'delete', name: 'Delete', description: 'Delete announcements.' }
]
},
{
key: 'rss-feeds',
order: 90,
name: 'RSS feeds',
sectionName: 'Data Sources',
actions: [
{ key: 'read', name: 'Read', description: 'View configured RSS feeds.' },
{ key: 'create', name: 'Create', description: 'Create new RSS feeds.' },
{ key: 'update', name: 'Update', description: 'Update RSS feeds.' },
{ key: 'delete', name: 'Delete', description: 'Delete RSS feeds.' }
]
},
{
key: 'api-sources',
order: 100,
name: 'API sources',
sectionName: 'Data Sources',
actions: [
{ key: 'read', name: 'Read', description: 'View configured API sources.' },
{ key: 'create', name: 'Create', description: 'Create new API sources.' },
{ key: 'update', name: 'Update', description: 'Update API sources.' },
{ key: 'delete', name: 'Delete', description: 'Delete API sources.' }
]
},
{
key: 'timetables',
order: 110,
name: 'Timetables',
sectionName: 'Data Sources',
actions: [
{ key: 'read', name: 'Read', description: 'View configured timetable groups.' },
{ key: 'create', name: 'Create', description: 'Create new timetable groups.' },
{ key: 'update', name: 'Update', description: 'Update timetable groups and entries.' },
{ key: 'delete', name: 'Delete', description: 'Delete timetable groups.' }
]
},
{
key: 'users',
order: 120,
name: 'Users',
sectionName: 'Settings',
actions: [
{ key: 'read', name: 'Read', description: 'View users and role assignments.' },
{ key: 'create', name: 'Create', description: 'Create new users.' },
{ key: 'update', name: 'Update', description: 'Update users, passwords, and role assignments.' },
{ key: 'delete', name: 'Delete', description: 'Delete users.' }
]
},
{
key: 'rbac',
order: 130,
name: 'Roles and permissions',
sectionName: 'Settings',
actions: [
{ key: 'read', name: 'Read', description: 'View roles and permissions.' },
{ key: 'create', name: 'Create', description: 'Create new roles.' },
{ key: 'update', name: 'Update', description: 'Update role details and permissions.' },
{ key: 'delete', name: 'Delete', description: 'Delete roles.' }
]
},
{
key: 'fonts',
order: 140,
name: 'Fonts',
sectionName: 'Settings',
actions: [
{ key: 'read', name: 'Read', description: 'View managed fonts.' },
{ key: 'create', name: 'Create', description: 'Upload managed fonts.' },
{ key: 'delete', name: 'Delete', description: 'Remove managed fonts.' }
]
},
{
key: 'background-tasks',
order: 150,
name: 'Task Queue',
sectionName: 'Settings',
actions: [
{ key: 'read', name: 'Read', description: 'View queued background tasks.' },
{ key: 'allow', name: 'Allow', description: 'Manage queued background tasks and clear finished items.' }
]
},
{
key: 'scheduled-tasks',
order: 160,
name: 'Scheduled tasks',
sectionName: 'Settings',
actions: [
{ key: 'read', name: 'Read', description: 'View scheduled refresh tasks.' },
{ key: 'allow', name: 'Allow', description: 'Run scheduled refreshes manually.' }
permissions: [
{
key: 'system-settings',
order: 70,
name: 'System settings',
permissions: [
{ key: 'read', name: 'Read', description: 'View global application settings.' },
{ key: 'update', name: 'Update', description: 'Update global application settings.' }
]
},
{
key: 'audit-log',
order: 60,
name: 'Audit log',
permissions: [
{ key: 'read', name: 'Read', description: 'View security and session audit events.' },
{ key: 'allow', name: 'Allow', description: 'Download filtered audit events.' }
]
},
{
key: 'users',
order: 10,
name: 'Users',
permissions: [
{ key: 'read', name: 'Read', description: 'View users and role assignments.' },
{ key: 'create', name: 'Create', description: 'Create new users.' },
{ key: 'update', name: 'Update', description: 'Update users, passwords, and role assignments.' },
{ key: 'delete', name: 'Delete', description: 'Delete users.' }
]
},
{
key: 'rbac',
order: 20,
name: 'Roles and permissions',
permissions: [
{ key: 'read', name: 'Read', description: 'View roles and permissions.' },
{ key: 'create', name: 'Create', description: 'Create new roles.' },
{ key: 'update', name: 'Update', description: 'Update role details and permissions.' },
{ key: 'delete', name: 'Delete', description: 'Delete roles.' }
]
},
{
key: 'fonts',
order: 30,
name: 'Fonts',
permissions: [
{ key: 'read', name: 'Read', description: 'View managed fonts.' },
{ key: 'create', name: 'Create', description: 'Upload managed fonts.' },
{ key: 'delete', name: 'Delete', description: 'Remove managed fonts.' }
]
},
{
key: 'background-tasks',
order: 40,
name: 'Task Queue',
permissions: [
{ key: 'read', name: 'Read', description: 'View queued background tasks.' },
{ key: 'allow', name: 'Allow', description: 'Manage queued background tasks and clear finished items.' }
]
},
{
key: 'scheduled-tasks',
order: 50,
name: 'Scheduled tasks',
permissions: [
{ key: 'read', name: 'Read', description: 'View scheduled refresh tasks.' },
{ key: 'allow', name: 'Allow', description: 'Run scheduled refreshes manually.' }
]
}
]
}
];
const PERMISSIONS = PERMISSION_SECTIONS.flatMap(function (section) {
return section.actions.map(function (action) {
return {
key: `${section.key}.${action.key}`,
name: section.name,
sectionOrder: section.order,
actionName: action.name,
sectionName: section.sectionName,
sectionKey: section.key,
actionKey: action.key,
description: action.description
};
const PERMISSIONS = PERMISSION_SECTIONS.flatMap(function (section, sectionIndex) {
return (Array.isArray(section.permissions) ? section.permissions : []).flatMap(function (resource, resourceIndex) {
return (Array.isArray(resource.permissions) ? resource.permissions : []).map(function (action, actionIndex) {
return {
key: `${resource.key}.${action.key}`,
name: resource.name,
sectionOrder: section.order,
sectionIndex: sectionIndex,
actionName: action.name,
permissionOrder: actionIndex + 1,
permissionIndex: actionIndex,
sectionName: section.sectionName,
resourceKey: resource.key,
resourceOrder: resource.order,
resourceIndex: resourceIndex,
resourceName: resource.name,
actionKey: action.key,
description: action.description
};
});
});
});
const DEFAULT_ROLE = {
key: 'administrators',
name: 'Administrators',
key: 'super-admin',
name: 'Super Admin',
description: 'Full access to the admin interface.'
};
+31 -7
View File
@@ -6,9 +6,10 @@ const multer = require('multer');
const fs = require('fs');
const crypto = require('crypto');
const common = require('./common');
const { verifyPassword, createSessionToken, hashSessionToken, hashPassword } = require('#src/auth');
const { verifyPassword, createSessionToken, hashSessionToken, hashPassword, validatePasswordStrength } = require('#src/auth');
const pages = require('#src/web/pages');
const registerMiddleware = require('#src/web/middleware');
const registerNotFoundHandler = require('#src/web/middleware/not-found');
const { createBackgroundTaskQueue } = require('#src/web/lib/background-tasks/queue');
const { initializeBackgroundTasks } = require('#src/web/lib/background-tasks');
const { createDataSourceTaskService } = require('#src/web/lib/background-tasks/tasks-scheduled/data-source-refresh');
@@ -23,6 +24,8 @@ const { rbacData } = require('#src/web/lib/auth');
const { createPlayerActionService } = require('#src/web/lib/player-actions');
const { isClientNameAvailable, withClientNameReservation } = require('#src/data/client-name-check');
const { createSessionService } = require('#src/web/lib/auth');
const { fetchAppSettings } = require('#src/data/app-settings');
const { recordRequestAuditEvent } = require('#src/data/audit-log');
const { hasAnyPermission } = require('#src/rbac');
const { ensureFontLibrary } = require('#src/web/lib/media/font-library');
const {
@@ -34,7 +37,6 @@ const {
getAuditUserId,
getCanvasSignature,
fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature,
fetchScreensByPlaylistId,
fetchScreensBySlideId,
fetchScreensByTemplateId,
@@ -62,7 +64,8 @@ async function start() {
const playerActionService = createPlayerActionService({
pool: pool,
common: common,
playerInternalBaseUrl: webConfig.playerInternalBaseUrl
playerInternalBaseUrl: webConfig.playerInternalUrl,
bridgeInternalBaseUrl: webConfig.bridgeInternalUrl
});
const notifyPlayerScreens = createNotifyPlayerScreens(playerActionService.forwardPlayerCommand);
@@ -70,8 +73,8 @@ async function start() {
const webBootstrap = createWebBootstrap({
pool: pool,
common: common,
playerInternalBaseUrl: webConfig.playerInternalBaseUrl,
playerPublicBaseUrl: webConfig.playerPublicBaseUrl,
playerInternalBaseUrl: webConfig.playerInternalUrl,
bridgeInternalBaseUrl: webConfig.bridgeInternalUrl,
uploadDir: webConfig.uploadsDir,
formatDashboardDate: formatDashboardDate,
notifyPlayerScreens: notifyPlayerScreens,
@@ -91,6 +94,14 @@ async function start() {
const sessionService = createSessionService({
sessionCookieName: webConfig.sessionCookieName,
sessionMaxAgeMs: webConfig.sessionMaxAgeMs,
getConfiguredSessionMaxAgeMs: async function () {
const settings = await fetchAppSettings(pool);
return Number(settings['security.session_lifetime_days']) * 24 * 60 * 60 * 1000;
},
getConfiguredMaxActiveSessions: async function () {
const settings = await fetchAppSettings(pool);
return Number(settings['security.max_active_sessions']);
},
hashSessionToken: hashSessionToken,
createSessionToken: createSessionToken
});
@@ -98,6 +109,7 @@ async function start() {
const createUserSession = sessionService.createUserSession;
const clearSessionCookie = sessionService.clearSessionCookie;
const setSessionCookie = sessionService.setSessionCookie;
const getSessionMaxAgeMs = sessionService.getSessionMaxAgeMs;
const setAuthMessageCookie = sessionService.setAuthMessageCookie;
const consumeAuthMessageCookie = sessionService.consumeAuthMessageCookie;
const loadCurrentUser = sessionService.loadCurrentUser;
@@ -118,9 +130,11 @@ async function start() {
common: common,
pages: pages,
upload: upload,
mediaDir: webConfig.mediaDir,
uploadDir: webConfig.uploadsDir,
createUserSession: createUserSession,
setSessionCookie: setSessionCookie,
getSessionMaxAgeMs: getSessionMaxAgeMs,
clearSessionCookie: clearSessionCookie,
setAuthMessageCookie: setAuthMessageCookie,
consumeAuthMessageCookie: consumeAuthMessageCookie,
@@ -130,7 +144,9 @@ async function start() {
sessionCookieName: webConfig.sessionCookieName,
formatDashboardDate: formatDashboardDate,
getAuditUserId: getAuditUserId,
recordRequestAuditEvent: recordRequestAuditEvent,
hashPassword: hashPassword,
validatePasswordStrength: validatePasswordStrength,
readArrayField: readArrayField,
rbacData: rbacData,
fetchOrderedPlaylistSlides: fetchOrderedPlaylistSlides,
@@ -138,7 +154,6 @@ async function start() {
fetchScreensBySlideId: fetchScreensBySlideId,
fetchScreensByTemplateId: fetchScreensByTemplateId,
fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasSignature,
getCanvasSignature: getCanvasSignature,
normalizeScheduleMode: normalizeScheduleMode,
parseDateTimeLocal: parseDateTimeLocal,
@@ -155,6 +170,7 @@ async function start() {
},
hasAnyPermission: hasAnyPermission,
backgroundTaskQueue: backgroundTaskQueue,
uploadSyncService: webBootstrap.uploadSyncService,
collectUploadReferencesFromSlide: collectUploadReferencesFromSlide,
collectUploadReferencesFromTemplate: collectUploadReferencesFromTemplate,
collectUploadReferencesFromPayload: collectUploadReferencesFromPayload,
@@ -163,9 +179,15 @@ async function start() {
buildDashboardState: webBootstrap.buildDashboardState
});
registerNotFoundHandler(app);
app.use(function (error, req, res, _next) {
console.error(error);
const statusCode = Number(error && (error.statusCode || error.status)) || 500;
if (statusCode >= 500) {
console.error(error);
} else if (statusCode >= 400 && statusCode !== 404) {
console.warn(error && error.message ? error.message : 'Request failed.', { statusCode: statusCode });
}
const isXhr = String(req.get && req.get('X-Requested-With') || '').toLowerCase() === 'xmlhttprequest';
const wantsHtml = !isXhr && !String(req.originalUrl || '').startsWith('/api/') && (!req.accepts || req.accepts('html'));
@@ -203,10 +225,12 @@ async function start() {
mediaDir: webConfig.mediaDir,
backgroundTaskQueue: backgroundTaskQueue,
webBootstrap: webBootstrap,
notifyPlayerScreens: notifyPlayerScreens,
loadCurrentUser: loadCurrentUser,
initializeBackgroundTasks: initializeBackgroundTasks,
captureSlideThumbnail: captureSlideThumbnail,
server: server,
webBaseUrl: webConfig.webInternalUrl,
dataSourceStartupRefreshStaggerMs: webConfig.dataSourceStartupRefreshStaggerMs
});
+57 -64
View File
@@ -8,8 +8,8 @@ const { createRequestAuthHeaders } = require('#src/request-auth');
function createWebBootstrap(options) {
const pool = options && options.pool;
const common = options && options.common;
const configuredPlayerInternalBaseUrl = String(options && options.playerInternalBaseUrl || '').replace(/\/$/, '');
const playerPublicBaseUrl = String(options && options.playerPublicBaseUrl || '').replace(/\/$/, '');
const configuredPlayerInternalUrl = String(options && options.playerInternalBaseUrl || '').replace(/\/$/, '');
const configuredBridgeInternalUrl = String(options && options.bridgeInternalBaseUrl || process.env.BRIDGE_INTERNAL_URL || '').trim().replace(/\/$/, '');
const uploadDir = String(options && options.uploadDir || '').trim();
const dashboardRefreshIntervalMs = 5000;
const formatDashboardDate = options && options.formatDashboardDate;
@@ -22,53 +22,12 @@ function createWebBootstrap(options) {
const dashboardWs = new WebSocketServer({ noServer: true });
const dashboardClients = new Set();
const playerSnapshotCache = new Map();
const playerSnapshotSockets = new Map();
const playerSnapshotCache = options && options.playerSnapshotCache ? options.playerSnapshotCache : new Map();
const playerSnapshotSockets = options && options.playerSnapshotSockets ? options.playerSnapshotSockets : new Map();
let dashboardRefreshInFlight = null;
let broadcastDashboardState = null;
let playerInternalBaseUrl = null;
let playerInternalBaseUrlPromise = null;
async function getPlayerInternalBaseUrl() {
if (playerInternalBaseUrl) {
return playerInternalBaseUrl;
}
if (playerInternalBaseUrlPromise) {
return playerInternalBaseUrlPromise;
}
playerInternalBaseUrlPromise = (async function () {
if (!pool) {
return configuredPlayerInternalBaseUrl || null;
}
try {
const [rows] = await pool.query(
`SELECT internal_base_url
FROM d_players
WHERE device_id = '1'
LIMIT 1`
);
const resolvedBaseUrl = String(rows && rows[0] && rows[0].internal_base_url || '').trim().replace(/\/$/, '');
return resolvedBaseUrl || configuredPlayerInternalBaseUrl || null;
} catch (_error) {
return configuredPlayerInternalBaseUrl || null;
}
})().then(function (baseUrl) {
playerInternalBaseUrl = baseUrl || null;
playerInternalBaseUrlPromise = null;
return playerInternalBaseUrl;
}, function () {
playerInternalBaseUrlPromise = null;
return configuredPlayerInternalBaseUrl || null;
});
return playerInternalBaseUrlPromise;
}
async function getPlayerSnapshotSocketUrl(slug) {
const resolvedPlayerInternalBaseUrl = await getPlayerInternalBaseUrl();
function getPlayerSnapshotSocketUrl(slug) {
const resolvedPlayerInternalBaseUrl = configuredBridgeInternalUrl || configuredPlayerInternalUrl;
if (!resolvedPlayerInternalBaseUrl) {
throw new Error('Unable to resolve the player internal base URL.');
}
@@ -79,34 +38,28 @@ function createWebBootstrap(options) {
return url.toString();
}
function storePlayerSnapshot(slug, connections) {
const normalizedSlug = String(slug || '').trim();
const normalizedConnections = Array.isArray(connections) ? connections : [];
playerSnapshotCache.set(normalizedSlug, {
slug: normalizedSlug,
count: normalizedConnections.length,
connections: normalizedConnections
});
}
function clearPlayerSnapshotSocket(slug) {
const key = String(slug || '').trim();
playerSnapshotSockets.delete(key);
}
function ensurePlayerSnapshotSubscription(slug) {
if (options && typeof options.ensurePlayerSnapshotSubscription === 'function' && options.ensurePlayerSnapshotSubscription !== ensurePlayerSnapshotSubscription) {
return options.ensurePlayerSnapshotSubscription(slug);
}
const key = String(slug || '').trim();
if (!key || playerSnapshotSockets.has(key)) {
return;
}
playerSnapshotSockets.set(key, null);
const socketUrlPromise = getPlayerSnapshotSocketUrl(key);
const authHeaders = createRequestAuthHeaders({
method: 'GET',
pathname: `/ws/screens/${encodeURIComponent(key)}/events`
});
socketUrlPromise.then(function (socketUrl) {
Promise.resolve(getPlayerSnapshotSocketUrl(key)).then(function (socketUrl) {
const socket = new WebSocket(socketUrl, {
headers: authHeaders
});
@@ -118,7 +71,11 @@ function createWebBootstrap(options) {
if (!payload || payload.type !== 'snapshot' || payload.slug !== key) {
return;
}
storePlayerSnapshot(key, payload.connections || []);
playerSnapshotCache.set(key, {
slug: key,
count: Array.isArray(payload.connections) ? payload.connections.length : 0,
connections: Array.isArray(payload.connections) ? payload.connections : []
});
if (broadcastDashboardState) {
broadcastDashboardState().catch(function (error) {
console.error(error);
@@ -152,10 +109,10 @@ function createWebBootstrap(options) {
const dashboardStateService = createDashboardStateService({
pool: pool,
common: common,
thinClientBaseUrl: configuredBridgeInternalUrl,
playerSnapshotCache: playerSnapshotCache,
playerSnapshotSockets: playerSnapshotSockets,
ensurePlayerSnapshotSubscription: ensurePlayerSnapshotSubscription,
playerPublicBaseUrl: playerPublicBaseUrl,
formatDashboardDate: formatDashboardDate
});
const buildDashboardState = dashboardStateService.buildDashboardState;
@@ -163,7 +120,7 @@ function createWebBootstrap(options) {
const uploadSyncService = createUploadSyncService({
pool: pool,
common: common,
playerInternalBaseUrl: configuredPlayerInternalBaseUrl,
playerInternalBaseUrl: configuredPlayerInternalUrl,
playerSnapshotCache: playerSnapshotCache,
notifyPlayerScreens: notifyPlayerScreens,
backgroundTaskQueue: backgroundTaskQueue
@@ -177,12 +134,44 @@ function createWebBootstrap(options) {
const collectUploadPathsFromDirectory = uploadSyncService.collectUploadPathsFromDirectory;
const syncPlaylistUploadsOnChange = uploadSyncService.syncPlaylistUploadsOnChange;
const runMediaSyncTask = uploadSyncService.runMediaSyncTask;
let lastDashboardState = null;
function getFallbackDashboardState() {
return lastDashboardState || {
playlists: [],
screens: [],
clients: [],
kioskPlayers: [],
slides: [],
playerServiceConnected: false,
connectedPlayersCount: 0,
connectedClientsCount: 0
};
}
async function resolveDashboardState() {
try {
const state = await buildDashboardState();
lastDashboardState = state;
return state;
} catch (error) {
if (lastDashboardState) {
console.error(error);
return lastDashboardState;
}
throw error;
}
}
async function sendDashboardStateToSocket(socket) {
if (!socket || socket.readyState !== WebSocket.OPEN) {
return;
}
const state = await buildDashboardState();
const state = await resolveDashboardState().catch(function (error) {
console.error(error);
return getFallbackDashboardState();
});
socket.send(JSON.stringify({ type: 'dashboard-state', state: state }));
}
@@ -192,7 +181,10 @@ function createWebBootstrap(options) {
}
dashboardRefreshInFlight = (async function () {
const state = await buildDashboardState();
const state = await resolveDashboardState().catch(function (error) {
console.error(error);
return getFallbackDashboardState();
});
const payload = JSON.stringify({ type: 'dashboard-state', state: state });
for (const socket of dashboardClients) {
if (socket && socket.readyState === WebSocket.OPEN) {
@@ -261,6 +253,7 @@ function createWebBootstrap(options) {
return {
upload: upload,
uploadSyncService: uploadSyncService,
playerInternalBaseUrl: configuredPlayerInternalUrl || null,
buildDashboardState: buildDashboardState,
collectUploadReferencesFromSlide: collectUploadReferencesFromSlide,
collectUploadReferencesFromTemplate: collectUploadReferencesFromTemplate,
+19 -3
View File
@@ -28,6 +28,15 @@ function registerGeneralHelpers(Handlebars) {
return `${text.slice(0, Math.max(0, limit - 1)).trimEnd()}`;
});
Handlebars.registerHelper('textLengthAttrs', function (maxLength) {
const limit = Number(maxLength);
if (!Number.isFinite(limit) || limit < 1) {
return '';
}
return new Handlebars.SafeString(`maxlength="${Handlebars.escapeExpression(String(Math.floor(limit)))}" data-limit-text-length`);
});
}
// URL helpers for generating links and external URL checks.
@@ -49,7 +58,11 @@ function registerUrlHelpers(Handlebars) {
});
Handlebars.registerHelper('playerUrl', function (slug) {
const base = (process.env.PLAYER_PUBLIC_BASE_URL || process.env.PLAYER_BASE_URL || 'http://localhost:3001').replace(/\/$/, '');
const base = String(arguments[1] || '').trim().replace(/\/$/, '');
if (!base) {
return '';
}
return `${base}/screen/${encodeURIComponent(slug)}`;
});
}
@@ -112,12 +125,14 @@ function registerActionHelpers(Handlebars) {
label: String(hash.deleteLabel || 'Delete'),
className: String(hash.deleteClass || 'btn btn-danger'),
url: String(hash.deleteUrl || '').trim(),
formId: String(hash.deleteFormId || '').trim(),
confirmMessage: String(hash.deleteConfirmMessage || '').trim(),
disabled: hash.deleteDisabled === undefined ? false : String(hash.deleteDisabled).toLowerCase() !== 'false',
title: String(hash.deleteTitle || '')
};
const resolvedDeleteUrl = deleteAction.url || (!deleteAction.disabled && saveUrl ? saveUrl.replace(/\/+$/, '') + '/delete' : '');
const resolvedDeleteFormId = deleteAction.formId || '';
if (!formId) {
return '';
@@ -141,10 +156,11 @@ function registerActionHelpers(Handlebars) {
}
if (showDelete && (deleteAction.disabled || resolvedDeleteUrl)) {
const deleteActionAttr = resolvedDeleteUrl ? ` data-delete-action-url="${escape(resolvedDeleteUrl)}"` : '';
const deleteActionAttr = resolvedDeleteUrl && !resolvedDeleteFormId ? ` data-delete-action-url="${escape(resolvedDeleteUrl)}"` : '';
const deleteFormAttr = resolvedDeleteFormId ? ` form="${escape(resolvedDeleteFormId)}"` : '';
const confirmAttr = deleteAction.confirmMessage ? ` data-confirm-message="${escape(deleteAction.confirmMessage)}"` : '';
const titleAttr = deleteAction.disabled && deleteAction.title ? ` title="${escape(deleteAction.title)}"` : '';
parts.push(`<button type="button" class="${escape(deleteAction.className)}"${deleteActionAttr}${confirmAttr}${deleteAction.disabled ? ' disabled' : ''}${titleAttr}>${escape(deleteAction.label)}</button>`);
parts.push(`<button type="${resolvedDeleteFormId ? 'submit' : 'button'}" class="${escape(deleteAction.className)}"${deleteFormAttr}${deleteActionAttr}${confirmAttr}${deleteAction.disabled ? ' disabled' : ''}${titleAttr}>${escape(deleteAction.label)}</button>`);
}
parts.push('</div>');
+40 -6
View File
@@ -113,7 +113,7 @@ async function fetchRolesForUser(pool, userId) {
async function fetchUsersWithRoles(pool) {
const [rows] = await pool.query(
`SELECT u.id, u.name, u.username, u.created_at, u.modified_at,
`SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u
@@ -142,7 +142,7 @@ async function fetchUsersWithRolesPage(pool, page, pageSize, searchTerm, sortKey
const whereSql = hasExcludedUserId ? 'WHERE u.id <> ?' : '';
const queryArgs = hasExcludedUserId ? [excludedUserId] : [];
const paged = await fetchPagedRows(pool, {
selectSql: `SELECT u.id, u.name, u.username, u.created_at, u.modified_at,
selectSql: `SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u
@@ -189,7 +189,7 @@ async function fetchUsersWithRolesPage(pool, page, pageSize, searchTerm, sortKey
async function fetchUserWithRoles(pool, userId) {
const [rows] = await pool.query(
`SELECT u.id, u.name, u.username, u.created_at, u.modified_at,
`SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u
@@ -216,6 +216,17 @@ async function fetchUserWithRoles(pool, userId) {
});
}
async function fetchActiveUserSessions(pool, userId) {
const [rows] = await pool.query(
`SELECT id, ip_address, user_agent, created_at, last_used_at, expires_at
FROM a_sessions
WHERE user_id = ? AND expires_at > NOW()
ORDER BY last_used_at DESC`,
[userId]
);
return rows || [];
}
async function syncUserRoles(pool, userId, roleIds) {
const uniqueRoleIds = Array.from(new Set((Array.isArray(roleIds) ? roleIds : []).map(function (roleId) {
return Number(roleId);
@@ -225,7 +236,14 @@ async function syncUserRoles(pool, userId, roleIds) {
await pool.query('DELETE FROM a_user_roles WHERE user_id = ?', [userId]);
for (const roleId of uniqueRoleIds) {
await pool.query('INSERT IGNORE INTO a_user_roles (user_id, role_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [userId, roleId, null, null]);
await pool.query(
`INSERT INTO a_user_roles (user_id, role_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_user_roles WHERE user_id = ? AND role_id = ?
)`,
[userId, roleId, null, null, userId, roleId]
);
}
}
@@ -238,7 +256,14 @@ async function syncRoleUsers(pool, roleId, userIds) {
await pool.query('DELETE FROM a_user_roles WHERE role_id = ?', [roleId]);
for (const userId of uniqueUserIds) {
await pool.query('INSERT IGNORE INTO a_user_roles (user_id, role_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [userId, roleId, null, null]);
await pool.query(
`INSERT INTO a_user_roles (user_id, role_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_user_roles WHERE user_id = ? AND role_id = ?
)`,
[userId, roleId, null, null, userId, roleId]
);
}
}
@@ -257,7 +282,15 @@ async function syncRolePermissions(pool, roleId, permissionKeys) {
await pool.query('DELETE FROM a_role_permissions WHERE role_id = ?', [roleId]);
for (const permissionRow of permissionRows) {
await pool.query('INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [roleId, Number(permissionRow.id), null, null]);
const permissionId = Number(permissionRow.id);
await pool.query(
`INSERT INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_role_permissions WHERE role_id = ? AND permission_id = ?
)`,
[roleId, permissionId, null, null, roleId, permissionId]
);
}
}
@@ -273,6 +306,7 @@ module.exports = {
fetchUsersWithRoles,
fetchUsersWithRolesPage,
fetchUserWithRoles,
fetchActiveUserSessions,
syncUserRoles,
syncRoleUsers,
syncRolePermissions
+77 -9
View File
@@ -2,9 +2,40 @@
const { normalizePermissionKeys } = require('#src/rbac');
function getRequestOrigin(req) {
const forwardedProto = String(req && req.headers && req.headers['x-forwarded-proto'] || '').trim().split(',')[0];
const protocol = forwardedProto || (req && req.socket && req.socket.encrypted ? 'https' : 'http');
const forwardedHost = String(req && req.headers && req.headers['x-forwarded-host'] || '').trim().split(',')[0];
const host = forwardedHost || String(req && req.headers && req.headers.host || '').trim();
return host ? `${protocol}://${host}`.replace(/\/$/, '') : 'http://localhost';
}
function normalizeReturnToPath(value, baseUrl) {
const rawValue = String(value || '').trim();
if (!rawValue) {
return '';
}
const normalizedBaseUrl = String(baseUrl || '').trim().replace(/\/$/, '') || 'http://localhost';
try {
const parsed = new URL(rawValue, normalizedBaseUrl);
const baseOrigin = new URL(normalizedBaseUrl).origin;
if (parsed.origin !== baseOrigin) {
return '';
}
return parsed.pathname + parsed.search + parsed.hash;
} catch (_error) {
return rawValue.charAt(0) === '/' ? rawValue : '';
}
}
function createSessionService(options) {
const sessionCookieName = String(options && options.sessionCookieName || '').trim();
const sessionMaxAgeMs = Number(options && options.sessionMaxAgeMs);
const getConfiguredSessionMaxAgeMs = options && options.getConfiguredSessionMaxAgeMs;
const getConfiguredMaxActiveSessions = options && options.getConfiguredMaxActiveSessions;
const hashSessionToken = options && options.hashSessionToken;
const createSessionToken = options && options.createSessionToken;
const authMessageCookieName = 'pulse_auth_message';
@@ -59,7 +90,20 @@ function createSessionService(options) {
}
function setSessionCookie(res, token) {
appendCookieHeader(res, serializeCookie(sessionCookieName, token, { maxAge: sessionMaxAgeMs }));
const hasRequestedMaxAge = arguments.length > 2;
const requestedMaxAgeMs = hasRequestedMaxAge ? Number(arguments[2]) : sessionMaxAgeMs;
const cookieOptions = hasRequestedMaxAge && arguments[2] === null
? {}
: { maxAge: Number.isFinite(requestedMaxAgeMs) && requestedMaxAgeMs > 0 ? requestedMaxAgeMs : sessionMaxAgeMs };
appendCookieHeader(res, serializeCookie(sessionCookieName, token, cookieOptions));
}
async function getSessionMaxAgeMs() {
const configuredValue = typeof getConfiguredSessionMaxAgeMs === 'function'
? await getConfiguredSessionMaxAgeMs()
: sessionMaxAgeMs;
const normalizedValue = Number(configuredValue);
return Number.isFinite(normalizedValue) && normalizedValue > 0 ? normalizedValue : sessionMaxAgeMs;
}
function setAuthMessageCookie(res, message) {
@@ -84,7 +128,7 @@ function createSessionService(options) {
const tokenHash = hashSessionToken(token);
const [rows] = await pool.query(
`SELECT s.user_id, u.id, u.name, u.username
`SELECT s.user_id, u.id, u.name, u.username, u.must_change_password
FROM a_sessions s
JOIN a_users u ON u.id = s.user_id
WHERE s.session_hash = ?
@@ -117,6 +161,7 @@ function createSessionService(options) {
await pool.query('UPDATE a_sessions SET last_used_at = CURRENT_TIMESTAMP, modified_by = ? WHERE session_hash = ?', [rows[0].user_id, tokenHash]);
return Object.assign({}, rows[0], {
mustChangePassword: Boolean(rows[0].must_change_password),
roleKeys: roleRows.map(function (row) {
return String(row.role_key || '').trim();
}).filter(Boolean),
@@ -126,14 +171,34 @@ function createSessionService(options) {
});
}
async function createUserSession(pool, userId) {
async function createUserSession(pool, userId, configuredMaxAgeMs, metadata) {
const token = createSessionToken();
const tokenHash = hashSessionToken(token);
const expiresAt = new Date(Date.now() + sessionMaxAgeMs);
const maxAgeMs = Number.isFinite(Number(configuredMaxAgeMs)) && Number(configuredMaxAgeMs) > 0
? Number(configuredMaxAgeMs)
: await getSessionMaxAgeMs();
const expiresAt = new Date(Date.now() + maxAgeMs);
const sessionMetadata = metadata && typeof metadata === 'object' ? metadata : {};
await pool.query(
'INSERT INTO a_sessions (session_hash, user_id, expires_at, created_by, modified_by) VALUES (?, ?, ?, ?, ?)',
[tokenHash, userId, expiresAt, userId, userId]
'INSERT INTO a_sessions (session_hash, user_id, ip_address, user_agent, expires_at, created_by, modified_by) VALUES (?, ?, ?, ?, ?, ?, ?)',
[tokenHash, userId, String(sessionMetadata.ipAddress || '').slice(0, 255) || null, String(sessionMetadata.userAgent || '').slice(0, 512) || null, expiresAt, userId, userId]
);
if (typeof getConfiguredMaxActiveSessions === 'function') {
const maxActiveSessions = Number(await getConfiguredMaxActiveSessions());
if (Number.isInteger(maxActiveSessions) && maxActiveSessions > 0) {
const [sessionRows] = await pool.query(
'SELECT id, session_hash FROM a_sessions WHERE user_id = ? AND expires_at > NOW() ORDER BY last_used_at ASC, created_at ASC, id ASC',
[userId]
);
const sessionsToRemove = (sessionRows || []).filter(function (session) {
return session.session_hash !== tokenHash;
}).slice(0, Math.max(0, sessionRows.length - maxActiveSessions));
for (const session of sessionsToRemove) {
await pool.query('DELETE FROM a_sessions WHERE id = ? AND user_id = ?', [session.id, userId]);
}
}
}
return token;
}
@@ -142,7 +207,8 @@ function createSessionService(options) {
return next();
}
setAuthMessageCookie(res, 'Please sign in to continue.');
res.redirect('/login');
const returnTo = normalizeReturnToPath(req && (req.originalUrl || req.url || req.path), getRequestOrigin(req));
res.redirect(returnTo ? '/login?returnTo=' + encodeURIComponent(returnTo) : '/login');
}
return {
@@ -154,8 +220,10 @@ function createSessionService(options) {
consumeAuthMessageCookie: consumeAuthMessageCookie,
loadCurrentUser: loadCurrentUser,
createUserSession: createUserSession,
requireAuth: requireAuth
getSessionMaxAgeMs: getSessionMaxAgeMs,
requireAuth: requireAuth,
getRequestOrigin: getRequestOrigin
};
}
module.exports = { createSessionService };
module.exports = { createSessionService, normalizeReturnToPath, getRequestOrigin };
+7 -1
View File
@@ -52,7 +52,13 @@ function registerStartupTasks(options) {
}
async function initialize() {
await loadTaskModules(backgroundTaskDirectory, options);
const startupTaskFile = path.join(backgroundTaskDirectory, 'data-source-refresh.js');
const taskModule = require(startupTaskFile);
const exported = getTaskExport(taskModule);
if (typeof exported === 'function') {
await exported(options);
}
}
return {
+3
View File
@@ -19,6 +19,9 @@ function normalizeIntervalMs(value, unit) {
if (normalizedUnit === 'seconds') {
return numericValue * 1000;
}
if (normalizedUnit === 'hours') {
return numericValue * 60 * 60 * 1000;
}
return numericValue * 60 * 1000;
}
@@ -24,7 +24,7 @@ function registerDataSourceRefreshTask(options) {
if (!apiSource) {
throw new Error('API source not found.');
}
return refreshApiSource(pool, common, apiSource, Number(payload.actorId) || null);
return refreshApiSource(pool, common, apiSource, Number(payload.actorId) || null, options.notifyPlayerScreens);
}
if (sourceType === 'rss-feed') {
@@ -32,7 +32,7 @@ function registerDataSourceRefreshTask(options) {
if (!rssFeed) {
throw new Error('RSS feed not found.');
}
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, Number(payload.actorId) || null);
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, Number(payload.actorId) || null, options.notifyPlayerScreens);
}
throw new Error('Unsupported data source refresh task.');
@@ -9,6 +9,7 @@ function registerFontSyncTask(options) {
backgroundTaskQueue.setTaskHandler('font-sync', async function (task) {
const payload = task && task.payload ? task.payload : task || {};
const uploadDir = String(payload.uploadDir || '').trim();
const playerIdentifier = String(payload.playerIdentifier || payload.deviceId || '').trim();
const operations = Array.isArray(payload.operations)
? payload.operations
: Array.isArray(payload.uploadPaths)
@@ -28,9 +29,9 @@ function registerFontSyncTask(options) {
continue;
}
if (String(operation.type || '').trim().toLowerCase() === 'delete') {
await uploadSyncService.removeUploadFileFromPlayer(uploadPath, uploadDir);
await uploadSyncService.removeUploadFileFromPlayer(uploadPath, uploadDir, undefined, playerIdentifier);
} else {
await uploadSyncService.pushUploadFileToPlayer(uploadPath, uploadDir);
await uploadSyncService.pushUploadFileToPlayer(uploadPath, uploadDir, undefined, playerIdentifier);
}
}
});
@@ -1,16 +1,18 @@
const { resolvePlayerRegistration } = require('#src/data/player-registry');
const TASK = {
taskType: 'slide-thumbnail-refresh'
};
async function fetchPlayerInternalBaseUrl(pool) {
const [rows] = await pool.query(
`SELECT internal_base_url
FROM d_players
WHERE device_id = '1'
LIMIT 1`
);
async function fetchPlayerInternalBaseUrl(pool, configuredPlayerInternalBaseUrl) {
const configured = String(configuredPlayerInternalBaseUrl || '').trim().replace(/\/$/, '');
if (configured) {
return configured;
}
return String(rows && rows[0] && rows[0].internal_base_url || '').trim().replace(/\/$/, '') || null;
const { getConfiguredPlayerIdentifier } = require('#src/data/player-registry');
const player = await resolvePlayerRegistration(pool, getConfiguredPlayerIdentifier());
return String(player && player.internal_base_url || '').trim().replace(/\/$/, '') || null;
}
function registerSlideThumbnailRefreshTask(options) {
@@ -19,6 +21,7 @@ function registerSlideThumbnailRefreshTask(options) {
const pool = options && options.pool;
const common = options && options.common;
const mediaDir = String(options && options.mediaDir || '').trim();
const configuredWebBaseUrl = String(options && options.webBaseUrl || '').trim().replace(/\/$/, '');
if (!backgroundTaskQueue || typeof captureSlideThumbnail !== 'function' || !pool || !common || !mediaDir) {
throw new Error('registerSlideThumbnailRefreshTask requires the slide thumbnail dependencies.');
@@ -32,18 +35,19 @@ function registerSlideThumbnailRefreshTask(options) {
throw new Error('Slide id is required.');
}
const playerInternalBaseUrl = await fetchPlayerInternalBaseUrl(pool);
if (!playerInternalBaseUrl) {
throw new Error('Player internal base URL is required.');
const webBaseUrl = configuredWebBaseUrl || `http://127.0.0.1:${Number(process.env.WEB_PORT || 8080)}`;
if (!webBaseUrl) {
throw new Error('Web base URL is required.');
}
return captureSlideThumbnail({
pool: pool,
common: common,
mediaDir: mediaDir,
baseUrl: playerInternalBaseUrl,
baseUrl: webBaseUrl,
slideId: slideId,
previousThumbnailPath: payload.previousThumbnailPath || null
previousThumbnailPath: payload.previousThumbnailPath || null,
fontStylesheetHref: payload.fontStylesheetHref || ''
});
});
}
@@ -1,16 +1,18 @@
const { resolvePlayerRegistration } = require('#src/data/player-registry');
const TASK = {
taskType: 'template-slide-thumbnail-refresh'
};
async function fetchPlayerInternalBaseUrl(pool) {
const [rows] = await pool.query(
`SELECT internal_base_url
FROM d_players
WHERE device_id = '1'
LIMIT 1`
);
async function fetchPlayerInternalBaseUrl(pool, configuredPlayerInternalBaseUrl) {
const configured = String(configuredPlayerInternalBaseUrl || '').trim().replace(/\/$/, '');
if (configured) {
return configured;
}
return String(rows && rows[0] && rows[0].internal_base_url || '').trim().replace(/\/$/, '') || null;
const { getConfiguredPlayerIdentifier } = require('#src/data/player-registry');
const player = await resolvePlayerRegistration(pool, getConfiguredPlayerIdentifier());
return String(player && player.internal_base_url || '').trim().replace(/\/$/, '') || null;
}
function registerTemplateSlideThumbnailRefreshTask(options) {
@@ -19,6 +21,7 @@ function registerTemplateSlideThumbnailRefreshTask(options) {
const pool = options && options.pool;
const common = options && options.common;
const mediaDir = String(options && options.mediaDir || '').trim();
const configuredWebBaseUrl = String(options && options.webBaseUrl || '').trim().replace(/\/$/, '');
if (!backgroundTaskQueue || typeof captureSlideThumbnail !== 'function' || !pool || !common || !mediaDir) {
throw new Error('registerTemplateSlideThumbnailRefreshTask requires the template thumbnail dependencies.');
@@ -32,9 +35,9 @@ function registerTemplateSlideThumbnailRefreshTask(options) {
throw new Error('Template id is required.');
}
const playerInternalBaseUrl = await fetchPlayerInternalBaseUrl(pool);
if (!playerInternalBaseUrl) {
throw new Error('Player internal base URL is required.');
const webBaseUrl = configuredWebBaseUrl || `http://127.0.0.1:${Number(process.env.WEB_PORT || 8080)}`;
if (!webBaseUrl) {
throw new Error('Web base URL is required.');
}
const [slides] = await pool.query(
@@ -52,7 +55,7 @@ function registerTemplateSlideThumbnailRefreshTask(options) {
pool: pool,
common: common,
mediaDir: mediaDir,
baseUrl: playerInternalBaseUrl,
baseUrl: webBaseUrl,
slideId: slideId,
previousThumbnailPath: slide && slide.thumbnail_path ? slide.thumbnail_path : null
});
@@ -0,0 +1,34 @@
const { fetchAppSettings } = require('#src/data/app-settings');
const TASK = {
key: 'audit-log-sweep',
title: 'Audit log cleanup',
category: 'cleanup',
intervalMs: 24 * 60 * 60 * 1000
};
function registerAuditLogSweepTask(options) {
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const pool = options && options.pool;
if (!backgroundTaskQueue || !pool) {
throw new Error('registerAuditLogSweepTask requires audit cleanup dependencies.');
}
backgroundTaskQueue.registerRecurringTask({
key: TASK.key,
title: TASK.title,
category: TASK.category,
intervalMs: TASK.intervalMs,
metadata: {},
run: async function () {
const settings = await fetchAppSettings(pool);
const retentionDays = Number(settings['audit.retention_days']);
if (!Number.isInteger(retentionDays) || retentionDays <= 0) {
return;
}
const cutoff = new Date(Date.now() - retentionDays * 24 * 60 * 60 * 1000);
await pool.query('DELETE FROM o_audit_events WHERE occurred_at < ?', [cutoff]);
}
});
}
module.exports = { registerAuditLogSweepTask };
@@ -34,7 +34,7 @@ function registerRecurringDataSourceRefreshes(options) {
sourceName: apiSource.name
},
run: function () {
return refreshApiSource(pool, common, apiSource, null);
return refreshApiSource(pool, common, apiSource, null, options.notifyPlayerScreens);
}
});
});
@@ -52,7 +52,7 @@ function registerRecurringDataSourceRefreshes(options) {
sourceName: rssFeed.name
},
run: function () {
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null);
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null, options.notifyPlayerScreens);
}
});
});
@@ -115,11 +115,11 @@ function createDataSourceTaskService(options) {
}
async function refreshApiSourceInBackground(apiSourceId, actorId) {
return refreshApiSource(pool, common, apiSourceId, actorId);
return refreshApiSource(pool, common, apiSourceId, actorId, options.notifyPlayerScreens);
}
async function refreshRssFeedInBackground(rssFeedId, feedUrl, itemLimit, actorId) {
return refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId);
return refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId, options.notifyPlayerScreens);
}
return {
@@ -0,0 +1,31 @@
const TASK = {
key: 'expired-session-sweep',
title: 'Expired session cleanup',
category: 'cleanup',
trigger: 'scheduled recurring task, hourly',
purpose: 'remove expired authentication sessions and their metadata.',
taskType: 'recurring-run',
intervalMs: 60 * 60 * 1000
};
function registerExpiredSessionSweepTask(options) {
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const pool = options && options.pool;
if (!backgroundTaskQueue || !pool) {
throw new Error('registerExpiredSessionSweepTask requires the session cleanup dependencies.');
}
backgroundTaskQueue.registerRecurringTask({
key: TASK.key,
title: TASK.title,
category: TASK.category,
intervalMs: TASK.intervalMs,
metadata: {},
run: async function () {
await pool.query('DELETE FROM a_sessions WHERE expires_at <= NOW()');
}
});
}
module.exports = { registerExpiredSessionSweepTask };
@@ -0,0 +1,32 @@
const TASK = {
key: 'onboarding-device-prune',
title: 'Onboarding device prune',
category: 'cleanup',
trigger: 'scheduled recurring task, hourly',
purpose: 'remove stale onboarding device bindings that have been idle for more than one minute.',
taskType: 'recurring-run',
intervalMs: 60 * 60 * 1000
};
function registerOnboardingDevicePruneTask(options) {
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const pool = options && options.pool;
const common = options && options.common;
if (!backgroundTaskQueue || !pool || !common || typeof common.pruneStaleOnboardingDevices !== 'function') {
throw new Error('registerOnboardingDevicePruneTask requires the onboarding prune dependencies.');
}
backgroundTaskQueue.registerRecurringTask({
key: TASK.key,
title: TASK.title,
category: TASK.category,
intervalMs: TASK.intervalMs,
metadata: {},
run: async function () {
await common.pruneStaleOnboardingDevices(pool);
}
});
}
module.exports = { registerOnboardingDevicePruneTask };
@@ -33,13 +33,13 @@ function scheduleStartupDataSourceRefreshes(options) {
(apiSourcesData.apiSources || []).forEach(function (apiSource) {
startupSources.push(buildStartupSource('api-source', apiSource.id, apiSource.name, function () {
return refreshApiSource(pool, common, apiSource, null);
return refreshApiSource(pool, common, apiSource, null, options.notifyPlayerScreens);
}));
});
(rssFeedsData.rssFeeds || []).forEach(function (rssFeed) {
startupSources.push(buildStartupSource('rss-feed', rssFeed.id, rssFeed.name, function () {
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null);
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null, options.notifyPlayerScreens);
}));
});
@@ -1,29 +1,86 @@
const { collectFontLibrarySyncOperations } = require('../../media/font-library');
const { fetchPlayerRegistrations } = require('#src/data/player-registry');
const TASK = {
key: 'initial-font-sync',
category: 'fonts'
};
function isRecentPlayerRegistration(player, staleSeconds) {
const lastSeenAt = player && player.last_seen_at;
const lastSeenAtValue = lastSeenAt instanceof Date ? lastSeenAt.getTime() : new Date(lastSeenAt).getTime();
const cutoffTime = Date.now() - Math.max(30, Number(staleSeconds || 60)) * 1000;
return Number.isFinite(lastSeenAtValue) && lastSeenAtValue >= cutoffTime;
}
function normalizePlayerMetadata(player) {
const playerIdentifier = String(player && player.identifier || '').trim();
const playerPublicBaseUrl = String(player && player.public_base_url || '').trim();
const playerInternalBaseUrl = String(player && player.internal_base_url || '').trim();
return {
playerIdentifier: playerIdentifier || null,
playerPublicBaseUrl: playerPublicBaseUrl || null,
playerInternalBaseUrl: playerInternalBaseUrl || null,
playerLabel: playerIdentifier || playerPublicBaseUrl || playerInternalBaseUrl || null,
playerActive: true
};
}
function registerInitialFontSyncTask(options) {
const pool = options && options.pool;
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const mediaDir = String(options && options.mediaDir || '').trim();
const uploadSyncService = options && options.uploadSyncService;
if (!backgroundTaskQueue || !mediaDir) {
if (!pool || !backgroundTaskQueue || !mediaDir) {
throw new Error('registerInitialFontSyncTask requires the initial font sync dependencies.');
}
return backgroundTaskQueue.enqueueTask({
key: TASK.key,
title: 'Initial font sync',
category: TASK.category,
taskType: 'font-sync',
payload: {
mode: 'initial',
uploadDir: mediaDir,
operations: collectFontLibrarySyncOperations(mediaDir)
},
persist: true
const metadataPromise = uploadSyncService && typeof uploadSyncService.getPlayerTaskMetadata === 'function'
? uploadSyncService.getPlayerTaskMetadata()
: Promise.resolve({});
return Promise.resolve(metadataPromise).then(async function () {
let players = [];
try {
players = await fetchPlayerRegistrations(pool);
} catch (error) {
console.warn('Unable to fetch player registrations for initial font sync:', error);
return null;
}
const livePlayers = Array.isArray(players)
? players.filter(function (player) {
return isRecentPlayerRegistration(player, 60);
})
: [];
if (!livePlayers.length) {
return null;
}
const operations = collectFontLibrarySyncOperations(mediaDir);
return Promise.all(livePlayers.map(function (player) {
const metadata = normalizePlayerMetadata(player);
return backgroundTaskQueue.enqueueTask({
key: TASK.key,
title: 'Initial font sync',
category: TASK.category,
taskType: 'font-sync',
metadata: metadata,
payload: {
mode: 'initial',
uploadDir: mediaDir,
operations: operations,
playerIdentifier: metadata.playerIdentifier,
playerPublicBaseUrl: metadata.playerPublicBaseUrl,
playerInternalBaseUrl: metadata.playerInternalBaseUrl
},
persist: true
});
}));
}).catch(function (error) {
console.warn('Unable to queue initial font sync:', error);
});
@@ -3,24 +3,81 @@ const TASK = {
category: 'media-sync',
};
const { fetchPlayerRegistrations } = require('#src/data/player-registry');
function isRecentPlayerRegistration(player, staleSeconds) {
const lastSeenAt = player && player.last_seen_at;
const lastSeenAtValue = lastSeenAt instanceof Date ? lastSeenAt.getTime() : new Date(lastSeenAt).getTime();
const cutoffTime = Date.now() - Math.max(30, Number(staleSeconds || 60)) * 1000;
return Number.isFinite(lastSeenAtValue) && lastSeenAtValue >= cutoffTime;
}
function normalizePlayerMetadata(player) {
const playerIdentifier = String(player && player.identifier || '').trim();
const playerPublicBaseUrl = String(player && player.public_base_url || '').trim();
const playerInternalBaseUrl = String(player && player.internal_base_url || '').trim();
return {
playerIdentifier: playerIdentifier || null,
playerPublicBaseUrl: playerPublicBaseUrl || null,
playerInternalBaseUrl: playerInternalBaseUrl || null,
playerLabel: playerIdentifier || playerPublicBaseUrl || playerInternalBaseUrl || null,
playerActive: true
};
}
function registerInitialMediaSyncTask(options) {
const pool = options && options.pool;
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const mediaDir = String(options && options.mediaDir || '').trim();
const uploadSyncService = options && options.uploadSyncService;
if (!backgroundTaskQueue || !mediaDir) {
if (!pool || !backgroundTaskQueue || !mediaDir) {
throw new Error('registerInitialMediaSyncTask requires the initial media sync dependencies.');
}
return backgroundTaskQueue.enqueueTask({
key: TASK.key,
title: 'Initial media sync',
category: TASK.category,
taskType: 'media-sync',
payload: {
mode: 'initial',
uploadDir: mediaDir
},
persist: true
const metadataPromise = uploadSyncService && typeof uploadSyncService.getPlayerTaskMetadata === 'function'
? uploadSyncService.getPlayerTaskMetadata()
: Promise.resolve({});
return Promise.resolve(metadataPromise).then(async function () {
let players = [];
try {
players = await fetchPlayerRegistrations(pool);
} catch (error) {
console.warn('Unable to fetch player registrations for initial media sync:', error);
return null;
}
const livePlayers = Array.isArray(players)
? players.filter(function (player) {
return isRecentPlayerRegistration(player, 60);
})
: [];
if (!livePlayers.length) {
return null;
}
return Promise.all(livePlayers.map(function (player) {
const metadata = normalizePlayerMetadata(player);
return backgroundTaskQueue.enqueueTask({
key: TASK.key,
title: 'Initial media sync',
category: TASK.category,
taskType: 'media-sync',
metadata: metadata,
payload: {
mode: 'initial',
uploadDir: mediaDir,
playerIdentifier: metadata.playerIdentifier,
playerPublicBaseUrl: metadata.playerPublicBaseUrl,
playerInternalBaseUrl: metadata.playerInternalBaseUrl
},
persist: true
});
}));
}).catch(function (error) {
console.warn('Unable to queue initial media sync:', error);
});
+7 -6
View File
@@ -5,11 +5,11 @@ function createWebConfig() {
const uploadsDir = path.join(mediaDir, 'uploads');
const thumbnailsDir = path.join(mediaDir, 'thumbnails');
const assetDir = path.join(__dirname, '..', 'public');
const playerInternalBaseUrl = (process.env.PLAYER_INTERNAL_BASE_URL || process.env.PLAYER_BASE_URL || 'http://player:8081').replace(/\/$/, '');
const playerPublicBaseUrl = (process.env.PLAYER_PUBLIC_BASE_URL || process.env.PLAYER_BASE_URL || 'http://localhost:8081').replace(/\/$/, '');
const playerInternalUrl = (process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || 'http://player:8081').replace(/\/$/, '');
const bridgeInternalUrl = (process.env.BRIDGE_INTERNAL_URL || 'http://player-bridge:8090').replace(/\/$/, '');
const webInternalUrl = (process.env.WEB_INTERNAL_URL || `http://127.0.0.1:${Number(process.env.WEB_PORT || 8080)}`).replace(/\/$/, '');
const sessionCookieName = 'digital_signage_session';
const sessionMaxAgeDays = Number(process.env.SESSION_MAX_AGE_DAYS || 14);
const sessionMaxAgeMs = (Number.isFinite(sessionMaxAgeDays) && sessionMaxAgeDays > 0 ? sessionMaxAgeDays : 14) * 24 * 60 * 60 * 1000;
const sessionMaxAgeMs = 14 * 24 * 60 * 60 * 1000;
const port = Number(process.env.WEB_PORT || 8080);
const dataSourceStartupRefreshStaggerMs = Math.max(100, Number(process.env.DATA_SOURCE_STARTUP_REFRESH_STAGGER_MS || 250));
@@ -19,8 +19,9 @@ function createWebConfig() {
uploadsDir: uploadsDir,
thumbnailsDir: thumbnailsDir,
assetDir: assetDir,
playerInternalBaseUrl: playerInternalBaseUrl,
playerPublicBaseUrl: playerPublicBaseUrl,
playerInternalUrl: playerInternalUrl,
bridgeInternalUrl: bridgeInternalUrl,
webInternalUrl: webInternalUrl,
sessionCookieName: sessionCookieName,
sessionMaxAgeMs: sessionMaxAgeMs,
dataSourceStartupRefreshStaggerMs: dataSourceStartupRefreshStaggerMs
+73 -4
View File
@@ -6,6 +6,10 @@ function normalizeClientName(value) {
return String(value || '').trim();
}
function normalizePlayerBaseUrl(value) {
return String(value || '').trim().replace(/\/$/, '');
}
function enrichScreensWithConnections(screens, connectionsBySlug, onboardingNameBySlug, playerUrlsBySlug) {
return (screens || []).map(function (screen) {
const connectionState = connectionsBySlug[screen.slug] || { count: 0, connections: [] };
@@ -18,11 +22,12 @@ function enrichScreensWithConnections(screens, connectionsBySlug, onboardingName
});
}
function buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, formatDashboardDate) {
function buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, playerIdentifierByBaseUrl, formatDashboardDate) {
return (screens || []).flatMap(function (screen) {
const connectionState = connectionsBySlug[screen.slug] || { count: 0, connections: [] };
return (connectionState.connections || []).map(function (connection) {
const deviceId = String(connection.deviceId || '').trim();
const playerBaseUrl = normalizePlayerBaseUrl(connection.playerPublicBaseUrl);
return Object.assign({}, connection, {
screen_slug: screen.slug,
screen_name: screen.name,
@@ -30,12 +35,55 @@ function buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboa
playlist_name: screen.playlist_name || null,
connectedAtLabel: formatDashboardDate(connection.connectedAt),
lastSeenAtLabel: formatDashboardDate(connection.lastSeenAt),
player_url: screen.player_url || String(connection.page || '').trim() || null
player_identifier: playerIdentifierByBaseUrl && playerBaseUrl ? (playerIdentifierByBaseUrl[playerBaseUrl] || null) : null,
player_url: playerBaseUrl || null
});
});
});
}
function isRecentPlayerRegistration(player, staleSeconds) {
const lastSeenAt = player && player.last_seen_at;
const lastSeenAtValue = lastSeenAt instanceof Date ? lastSeenAt.getTime() : new Date(lastSeenAt).getTime();
const cutoffTime = Date.now() - Math.max(30, Number(staleSeconds || 60)) * 1000;
return Number.isFinite(lastSeenAtValue) && lastSeenAtValue >= cutoffTime;
}
function buildKioskLauncherPlayers(playerRegistrations, staleSeconds) {
return (Array.isArray(playerRegistrations) ? playerRegistrations : [])
.filter(function (player) {
return Boolean(player && String(player.identifier || '').trim() && String(player.public_base_url || '').trim() && isRecentPlayerRegistration(player, staleSeconds));
})
.map(function (player) {
return {
player_identifier: String(player.identifier || '').trim(),
player_url: String(player.public_base_url || '').trim().replace(/\/$/, '')
};
});
}
async function fetchConnectedPlayerCount(pool, connectedPlayerCountStaleSeconds) {
const staleSeconds = Math.max(30, Number(connectedPlayerCountStaleSeconds || 60));
if (!pool || typeof pool.query !== 'function' || !Number.isFinite(staleSeconds)) {
return null;
}
try {
const [rows] = await pool.query(
`SELECT COUNT(*) AS connected_count
FROM d_players
WHERE last_seen_at IS NOT NULL
AND last_seen_at >= DATE_SUB(NOW(), INTERVAL ${staleSeconds} SECOND)`
);
const count = Number(rows && rows[0] && rows[0].connected_count);
return Number.isFinite(count) && count >= 0 ? count : null;
} catch (_error) {
return null;
}
}
function compareScreenNames(left, right) {
const leftName = String(left && left.name || '').trim();
const rightName = String(right && right.name || '').trim();
@@ -51,6 +99,7 @@ function compareScreenNames(left, right) {
function createDashboardStateService(options) {
const pool = options && options.pool;
const common = options && options.common;
const connectedPlayerCountStaleSeconds = options && options.connectedPlayerCountStaleSeconds;
const playerSnapshotCache = options && options.playerSnapshotCache;
const playerSnapshotSockets = options && options.playerSnapshotSockets;
const ensurePlayerSnapshotSubscription = options && options.ensurePlayerSnapshotSubscription;
@@ -63,11 +112,19 @@ function createDashboardStateService(options) {
async function buildDashboardState() {
const data = await common.fetchAdminData(pool);
const screensData = data.screens || [];
const connectedPlayersCount = await fetchConnectedPlayerCount(pool, connectedPlayerCountStaleSeconds);
const playerUrlsBySlug = typeof common.fetchScreenPlayerUrls === 'function'
? await common.fetchScreenPlayerUrls(pool)
: {};
const playerRegistrations = typeof common.fetchPlayerRegistrations === 'function'
? await common.fetchPlayerRegistrations(pool)
: [];
screensData.forEach(function (screen) {
ensurePlayerSnapshotSubscription(screen.slug);
try {
ensurePlayerSnapshotSubscription(screen.slug);
} catch (_error) {
// Keep building dashboard state when one player snapshot subscription fails.
}
});
const [onboardingRows] = await pool.query(
@@ -91,6 +148,15 @@ function createDashboardStateService(options) {
}
});
const playerIdentifierByBaseUrl = {};
(Array.isArray(playerRegistrations) ? playerRegistrations : []).forEach(function (player) {
const baseUrl = normalizePlayerBaseUrl(player && player.public_base_url);
const identifier = normalizeClientName(player && player.identifier);
if (baseUrl && identifier) {
playerIdentifierByBaseUrl[baseUrl] = identifier;
}
});
const connectionsBySlug = {};
screensData.forEach(function (screen) {
const cached = playerSnapshotCache.get(String(screen.slug || '').trim());
@@ -106,7 +172,8 @@ function createDashboardStateService(options) {
});
})
.sort(compareScreenNames);
const clients = buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, formatDashboardDate);
const clients = buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, playerIdentifierByBaseUrl, formatDashboardDate);
const kioskPlayers = buildKioskLauncherPlayers(playerRegistrations, connectedPlayerCountStaleSeconds);
const playerServiceConnected = Array.from(playerSnapshotSockets.values()).some(function (socket) {
return socket && socket.readyState === WebSocket.OPEN;
});
@@ -115,8 +182,10 @@ function createDashboardStateService(options) {
playlists: data.playlists || [],
screens: screens,
clients: clients,
kioskPlayers: kioskPlayers,
slides: data.slides || [],
playerServiceConnected: playerServiceConnected,
connectedPlayersCount: connectedPlayersCount !== null ? connectedPlayersCount : 0,
connectedClientsCount: screens.reduce(function (total, screen) {
return total + Number(screen.player_connection_count || 0);
}, 0)
+127 -2
View File
@@ -1,4 +1,112 @@
async function refreshApiSource(pool, common, apiSourceOrId, actorId) {
async function getAffectedScreenSlugs(connection, common, slideMatchKey, sourceId) {
const [slideRows] = await connection.query('SELECT id, content_json FROM c_slides WHERE content_json IS NOT NULL');
const slideIds = [];
const seenSlideIds = new Set();
slideRows.forEach(function (row) {
const content = typeof common.parseJsonSafe === 'function' ? common.parseJsonSafe(row.content_json) : null;
if (!content || typeof content !== 'object') {
return;
}
const stack = [content];
while (stack.length) {
const value = stack.pop();
if (!value || typeof value !== 'object') {
continue;
}
if (Array.isArray(value)) {
value.forEach(function (item) {
stack.push(item);
});
continue;
}
if (Object.prototype.hasOwnProperty.call(value, slideMatchKey) && Number(value[slideMatchKey]) === Number(sourceId)) {
const slideId = Number(row.id);
if (Number.isFinite(slideId) && slideId > 0 && !seenSlideIds.has(slideId)) {
seenSlideIds.add(slideId);
slideIds.push(slideId);
}
break;
}
Object.keys(value).forEach(function (key) {
stack.push(value[key]);
});
}
});
if (!slideIds.length) {
return [];
}
const [screenRows] = await connection.query(
`SELECT DISTINCT s.slug
FROM d_screens s
JOIN c_playlist_slides ps ON ps.playlist_id = s.playlist_id
WHERE ps.slide_id IN (?)
AND s.slug IS NOT NULL`,
[slideIds]
);
return screenRows.map(function (row) {
return String(row.slug || '').trim();
}).filter(Boolean);
}
async function notifyAffectedScreens(connection, common, notifyPlayerScreens, slideMatchKey, sourceId) {
if (typeof notifyPlayerScreens !== 'function') {
return;
}
const slugs = await getAffectedScreenSlugs(connection, common, slideMatchKey, sourceId);
if (!slugs.length) {
return;
}
await notifyPlayerScreens(slugs, 'refresh');
}
function normalizeSnapshotValue(value) {
return String(value || '').trim();
}
async function hasRssFeedChanged(connection, rssFeedId, items) {
const [rows] = await connection.query(
`SELECT item_json
FROM i_rss_feed_items
WHERE rss_feed_id = ?
ORDER BY position ASC, id ASC`,
[rssFeedId]
);
const currentSnapshots = (rows || []).map(function (row) {
return normalizeSnapshotValue(row && row.item_json);
});
const nextSnapshots = (Array.isArray(items) ? items : []).map(function (item) {
return normalizeSnapshotValue(JSON.stringify(item || {}));
});
if (currentSnapshots.length !== nextSnapshots.length) {
return true;
}
for (let index = 0; index < currentSnapshots.length; index += 1) {
if (currentSnapshots[index] !== nextSnapshots[index]) {
return true;
}
}
return false;
}
function hasApiSourceChanged(apiSource, responseDetails) {
return normalizeSnapshotValue(apiSource && apiSource.last_response_json) !== normalizeSnapshotValue(responseDetails && responseDetails.responseJson);
}
async function refreshApiSource(pool, common, apiSourceOrId, actorId, notifyPlayerScreens) {
const connection = await pool.getConnection();
try {
const apiSource = apiSourceOrId && typeof apiSourceOrId === 'object'
@@ -25,6 +133,14 @@ async function refreshApiSource(pool, common, apiSourceOrId, actorId) {
[new Date(), pullError || null, responseDetails ? responseDetails.responseStatus : null, responseDetails ? responseDetails.responseContentType : null, responseDetails ? responseDetails.responseJson : null, actorId, apiSource.id]
);
await connection.commit();
if (!pullError && hasApiSourceChanged(apiSource, responseDetails)) {
try {
await notifyAffectedScreens(connection, common, notifyPlayerScreens, 'source_id', apiSource.id);
} catch (notifyError) {
console.warn('[data-source-refresh] Unable to notify players after API source refresh ' + apiSource.id + ':', notifyError);
}
}
} catch (error) {
try {
await connection.rollback();
@@ -37,7 +153,7 @@ async function refreshApiSource(pool, common, apiSourceOrId, actorId) {
}
}
async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId) {
async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId, notifyPlayerScreens) {
const connection = await pool.getConnection();
try {
let updatedItems = [];
@@ -50,11 +166,20 @@ async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actor
}
await connection.beginTransaction();
const rssFeedChanged = await hasRssFeedChanged(connection, rssFeedId, updatedItems);
if (typeof common.replaceRssFeedItems === 'function') {
await common.replaceRssFeedItems(connection, rssFeedId, updatedItems);
}
await connection.commit();
if (!pullError && rssFeedChanged) {
try {
await notifyAffectedScreens(connection, common, notifyPlayerScreens, 'feed_id', rssFeedId);
} catch (notifyError) {
console.warn('[data-source-refresh] Unable to notify players after RSS feed refresh ' + rssFeedId + ':', notifyError);
}
}
if (pullError) {
console.error('[data-source-refresh] RSS feed refresh completed with an error for feed ' + rssFeedId + ': ' + pullError);
}
-1
View File
@@ -198,7 +198,6 @@ module.exports = {
getAuditUserId: getAuditUserId,
getCanvasSignature: getCanvasSignature,
fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasId,
fetchScreensByPlaylistId: fetchScreensByPlaylistId,
fetchScreensBySlideId: fetchScreensBySlideId,
fetchScreensByTemplateId: fetchScreensByTemplateId,

Some files were not shown because too many files have changed in this diff Show More