Compare commits

...
47 Commits
Author SHA1 Message Date
lzstealth ca9f38f3b9 Release v2.10.4
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-29 12:27:01 +01:00
lzstealth 3f4f57020a Release v2.10.3
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m13s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 31s
2026-08-29 01:56:45 +01:00
lzstealth 30814f3f46 Align environment documentation order 2026-08-28 20:24:10 +01:00
lzstealth dc47948513 Update deployment and schema documentation 2026-08-28 20:22:58 +01:00
lzstealth c95ddb3de8 Organize Docker environment examples 2026-08-28 20:20:30 +01:00
lzstealth 7dc895172c Release 2.10.2
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-28 20:17:45 +01:00
lzstealth f252562103 Fix weather creation route error handling
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m15s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-28 20:12:34 +01:00
lzstealth 3960931ebe Add onboarding weather and template gradients
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m53s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 34s
2026-08-28 20:05:23 +01:00
lzstealth aa07a78912 Fix timetable timezone tests 2026-08-28 02:56:48 +01:00
lzstealth 3de0e89e94 Release 2.9.0 2026-08-28 02:53:59 +01:00
lzstealth 9097d45d6a Improve announcement rendering and theme assets 2026-08-26 01:08:59 +01:00
lzstealth a7d867dd6f Adjust API source response header spacing
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m15s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-22 01:39:35 +01:00
lzstealth 196c640f9b Release 2.8.7
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m47s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 31s
2026-08-22 01:33:35 +01:00
lzstealth 7bd4a792ee Merge remote-tracking branch 'Gitea_SSH/main'
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m50s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
# Conflicts:
#	CHANGELOG.md
#	build/package.player.json
#	build/package.web.json
#	package-lock.json
#	package.json
2026-08-18 02:25:15 +01:00
lzstealth e1e759f64e Release 2.8.6 2026-08-18 02:23:42 +01:00
lzstealth f071c21219 Release 2.8.5
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m15s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 02:15:18 +01:00
lzstealth e984f36875 Release 2.8.5
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m53s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 02:07:48 +01:00
lzstealth bbd517abbb Fix scheduled task run notification
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 00:54:13 +01:00
lzstealth 403a928b9e Release 2.8.4
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 35s
2026-08-17 00:46:07 +01:00
lzstealth 7bb34f40fe Release 2.8.3
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m14s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-17 00:08:05 +01:00
lzstealth ea72747822 Release 2.8.2
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m12s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 34s
2026-08-16 22:41:39 +01:00
lzstealth a5bf8e6f7f Release 2.8.1
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m16s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-16 22:08:32 +01:00
lzstealth 203d0bfc01 Release 2.8.0
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m49s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
2026-08-16 17:15:31 +01:00
lzstealth 1bdc122995 Target Node 26
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m17s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 33s
2026-08-15 15:02:28 +01:00
lzstealth 2d748458d0 Remove GHCR publish path 2026-08-15 14:21:54 +01:00
lzstealth bb8cd98e61 Publish Docker images to both registries
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile, web, pulse-signage-web) (push) Successful in 1m25s
Publish Docker Image / build-and-push-existing-registry (./build/Dockerfile.player, player, pulse-signage-player) (push) Successful in 32s
Publish Docker Image / build-and-push-ghcr (./build/Dockerfile, web, pulse-signage-web) (push) Failing after 1m8s
Publish Docker Image / build-and-push-ghcr (./build/Dockerfile.player, player, pulse-signage-player) (push) Failing after 31s
2026-08-15 14:13:49 +01:00
lzstealth aafe112c36 Release 2.7.5
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m18s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 13:06:46 +01:00
lzstealth 1f1ad5d61f Release 2.7.4
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m15s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 12:30:31 +01:00
lzstealth f0177e6628 Release 2.7.3
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m15s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-15 11:43:07 +01:00
lzstealth 15dc6eb7f2 Release 2.7.2
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m16s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 23:51:38 +01:00
lzstealth 75b5cb5a6b Add player keyboard controls and release 2.7.1
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m17s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 13:50:40 +01:00
lzstealth e7ec276317 Release v2.7.0
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m18s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 33s
2026-08-14 13:36:47 +01:00
lzstealth 30f5ed11b8 Format scheduled task intervals
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m25s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 32s
2026-08-14 00:20:48 +01:00
lzstealth d6a8b45357 Fresh initial commit
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m12s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 30s
2026-08-12 02:41:31 +01:00
lzstealth f9425fc640 Release 2.6.25
Publish Docker Image / build-and-push (./build/Dockerfile, git.lzstealth.com/lzstealth/pulse-signage-web, web) (push) Successful in 1m12s
Publish Docker Image / build-and-push (./build/Dockerfile.player, git.lzstealth.com/lzstealth/pulse-signage-player, player) (push) Successful in 30s
2026-08-10 01:04:49 +01:00
lzstealth 4491c15215 Release 2.6.24 2026-08-10 00:32:28 +01:00
lzstealth 08b06941a4 Adjust dashboard card spacing 2026-08-09 13:53:38 +01:00
lzstealth c0c05f76e3 Make API and RSS refresh notifications change-only 2026-08-09 13:44:17 +01:00
lzstealth 78a34e4105 Release 2.6.23 2026-08-09 13:38:30 +01:00
lzstealth 3c3864e6ac Sync build package versions 2026-08-09 13:06:55 +01:00
lzstealth 6d8bf0f5f0 Release v2.6.22 2026-08-09 13:06:02 +01:00
lzstealth c36b9122c9 Release v2.6.21 2026-08-09 12:30:22 +01:00
lzstealth 39f2098ffe Release v2.6.20 2026-08-09 12:18:44 +01:00
lzstealth 459f84ed94 Release v2.6.19 2026-08-09 11:57:40 +01:00
lzstealth 49c72923b4 Release 2.6.15 2026-08-08 23:15:04 +01:00
lzstealth 6c28a1c028 Release 2.6.14 2026-08-08 21:49:22 +01:00
lzstealth c5172af62d Release 2.6.13 2026-08-08 21:11:34 +01:00
292 changed files with 27807 additions and 3801 deletions
+1
View File
@@ -1,5 +1,6 @@
* *
!package.json !package.json
!package-lock.json
!build/ !build/
!build/** !build/**
!src/ !src/
+3
View File
@@ -3,6 +3,9 @@
## Versioning and releases ## Versioning and releases
- Treat `package.json` as the source of truth for the application version. - Treat `package.json` as the source of truth for the application version.
- Keep `package.json`, `build/package.player.json`, and `build/package.web.json` on the same version number.
- Keep dependency versions and package metadata in `package.json`, `package-lock.json`, `build/package.player.json`, and `build/package.web.json` aligned unless a dependency is intentionally omitted from a specific bundle.
- When changing bundled library versions, update the About page source data from the same package metadata or vendored asset banner rather than hardcoding a fresh literal.
- When the app version changes, update `CHANGELOG.md` in the same change. - When the app version changes, update `CHANGELOG.md` in the same change.
- Keep database migration versions aligned with the release they actually belong to. - Keep database migration versions aligned with the release they actually belong to.
- If only part of a migration batch belongs to a newer release, split that batch into a separate migration entry instead of relabeling the earlier release. - If only part of a migration batch belongs to a newer release, split that batch into a separate migration entry instead of relabeling the earlier release.
+7 -5
View File
@@ -7,17 +7,18 @@ on:
workflow_dispatch: workflow_dispatch:
jobs: jobs:
build-and-push: build-and-push-existing-registry:
runs-on: ubuntu-latest runs-on: ubuntu-latest
strategy: strategy:
fail-fast: false
matrix: matrix:
include: include:
- name: web - name: web
image: git.lzstealth.com/lzstealth/pulse-signage-web repository: pulse-signage-web
dockerfile: ./build/Dockerfile dockerfile: ./build/Dockerfile
- name: player - name: player
image: git.lzstealth.com/lzstealth/pulse-signage-player repository: pulse-signage-player
dockerfile: ./build/Dockerfile.player dockerfile: ./build/Dockerfile.player
steps: steps:
@@ -27,7 +28,7 @@ jobs:
- name: Set up Docker Buildx - name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3 uses: docker/setup-buildx-action@v3
- name: Log in to container registry - name: Log in to existing package registry
uses: docker/login-action@v3 uses: docker/login-action@v3
with: with:
registry: git.lzstealth.com registry: git.lzstealth.com
@@ -38,7 +39,8 @@ jobs:
id: meta id: meta
uses: docker/metadata-action@v5 uses: docker/metadata-action@v5
with: with:
images: ${{ matrix.image }} images: |
git.lzstealth.com/lzstealth/${{ matrix.repository }}
tags: | tags: |
type=raw,value=latest type=raw,value=latest
type=ref,event=tag type=ref,event=tag
+378
View File
@@ -2,6 +2,384 @@
All notable changes to this project will be documented in this file. All notable changes to this project will be documented in this file.
## 2.10.4 - 2026-08-29
### Fixed
- Fixed remote client move commands so they route through the player bridge to the correct browser tab using the physical player identity and connection ID.
- Removed the obsolete `PLAYER_BASE_URL` configuration fallback; command routing uses `PLAYER_INTERNAL_URL` locally or the player bridge remotely, while `PLAYER_PUBLIC_URL` remains available for kiosk launcher and direct player access.
- Removed the player URL list from screen-group add/edit pages and expanded the remaining form card to full width.
## 2.10.3 - 2026-08-28
### Fixed
- Fixed the weather edit preview so the daily forecast is shown initially, the 24-hour forecast is hidden until selected, and the redundant hourly heading is removed.
- Fixed onboarding cleanup so incomplete pairings are retained for the 15-minute pairing-code lifetime while inactive completed bindings are pruned after 24 hours.
- Fixed client-name handling so offline names can be reused, active collisions receive numeric suffixes, and reconnecting players resolve duplicate names consistently.
- Fixed an internal server error when renaming clients by forwarding the available-name resolver to the client command routes.
- Fixed remote client moves to resolve the paired browser client binding before changing its target screen.
- Fixed remote player heartbeats to update the central onboarding bindings for active browser clients without treating the physical player registry ID as a client binding.
- Fixed targeted commands after browser reconnects by falling back to the stable client ID when a transient connection ID is stale.
- Fixed stale browser command connections remaining active indefinitely when the physical player heartbeat was still healthy.
- Added periodic playlist polling so remote screens recover from missed refresh commands after bridge reconnects.
- Added cached playlist snapshots so screens can continue displaying their last known playlist while the bridge or web service is temporarily unavailable.
- Fixed media synchronization so generated player caches are excluded while remote image caches remain available to players.
- Fixed weather screen notifications so changes in the fetched data or the current forecast hour trigger a refresh.
- Fixed player runtime script loading and slide rendering so region modules, transitions, and cached playlists initialize consistently.
- Fixed command delivery reporting to require acknowledgement from the receiving browser tab.
- Fixed playlist refresh notifications to target the physical player hosting each screen instead of always targeting the local player.
## 2.10.2 - 2026-08-28
### Fixed
- Fixed the weather forecast preview to show only its first-fetch message until a successful forecast is available.
- Added persisted onboarding client heartbeats so records inactive for 24 hours can be pruned without relying on player connectivity after the fact.
## 2.10.1 - 2026-08-28
### Added
- Added linear gradient backgrounds to templates, including multiple colours and angle control.
- Added a visual gradient stop editor with draggable stops, click-to-add support, and stop reordering.
## 2.10.0 - 2026-08-28
### Added
- Added secure kiosk onboarding with QR-first and manual pairing flows.
- Added browser-specific pairing sessions with expiring pairing codes.
- Added circular QR presentation and a compatible QR scanner with decoder fallbacks.
- Added responsive player onboarding and a post-pair option to connect another player.
- Added stable player identity bindings for paired players and moved-client aliases.
- Added per-tab client identities backed by browser session storage for commands, pairing, and screen moves.
- Added RBAC protection for player pairing through the `pairing.allow` permission.
- Added a dedicated web onboarding workflow for pairing and managing player setup.
### Changed
- Restricted direct screen URLs to the player configured for the requested screen.
- Added pairing entry points to the dashboard and connected clients workflows.
- Made pairing QR codes easier to scan by encoding only the short pairing code.
- Added a mobile-friendly connected clients link after successful pairing.
- Made connected-client controls and player pairing UI render independently according to their permissions.
- Added player keyboard feedback for slide navigation, plus `P` pause/unpause and `B` blackout toggles.
- Removed client identities from onboarding and screen-move URLs; authorized player data now loads after the tab identity handshake.
- Updated connected-client commands and screen moves to resolve tab and registered-player identities reliably.
## 2.9.0 - 2026-08-28
### Added
- API sources, RSS feeds, and weather locations can be enabled or disabled without deleting their cached data.
- Added Weather slide regions with current, daily, and hourly placeholders, date/time transforms, and Bootstrap weather icon transforms.
- Added multiple saved weather locations with provider, coordinate, unit, and refresh settings.
- Added separate Allow permissions for manually refreshing API sources, RSS feeds, and weather locations.
### Changed
- API, RSS, and Weather refresh jobs now skip disabled sources across scheduled, startup, queued, and manual refresh paths, while re-enabling a source resumes refresh scheduling.
- Weather placeholders now show all current fields, or all fields for the first daily/hourly entry before the remaining entries in a Show more section.
- Weather previews, player playback, and slide thumbnails now use cached Weather data and consistent text/icon sizing.
- API, RSS, and Weather lists now show enabled status and their forms provide action-oriented Enable/Disable controls.
- Enable/Disable actions on API, RSS, and Weather forms now run asynchronously without reloading unsaved form changes.
- Weather locations can now be duplicated from the weather list.
- Startup data-source refreshes now respect each API, RSS, and weather source's configured repull interval.
- RSS feeds now persist their last collection timestamp.
- Refreshed the vendored AdminLTE assets to 4.8.5.
- Added AdminLTE extended palette colours to announcement colour choices and player rendering.
- Removed Digital Signage Subheading and top padding.
- API and RSS source saves now preserve cached data without pulling; added explicit manual refresh actions.
## 2.8.7 - 2026-08-22
### Added
- Added configurable JSON POST requests and two-step login-then-token authentication for API sources.
## 2.8.6 - 2026-08-18
### Fixed
- Added live URL validation with inline feedback and explicit HTTP or HTTPS scheme enforcement for URL fields.
- Prevented Enter in slide editor inputs from implicitly saving the slide.
- Collapsed nested API response JSON sections by default while keeping the root response visible.
## 2.8.5 - 2026-08-17
### Fixed
- Fixed thumbnail capture timing so video assets are ready before the preview canvas is captured.
- Replaced unavailable webpage thumbnails with a subdued placeholder while keeping live webpage previews intact.
## 2.8.4 - 2026-08-17
### Added
- Added local caching for API and RSS image placeholders under `player-cache/remote-images` for offline player playback.
- Added reconciliation of cached remote images so files no longer referenced by slides are removed.
### Fixed
- Fixed popup preview authentication for background thumbnail capture.
- Fixed thumbnails so they use the same popup-preview canvas and resolve API/RSS placeholders, fonts, styles, and cached images correctly.
- Fixed manual scheduled-task run notifications so they use task-neutral wording.
## 2.8.3 - 2026-08-17
### Added
- Added API, RSS, Timetable, and Time / Date placeholder help panels with shared transform and date-token documentation.
- Added render-time API and RSS image placeholders with proportional sizing and preview-only bounding boxes.
### Changed
- API and RSS regions now preserve authored content when no data source is selected and remain blank when a selected source has no authored content.
- Normal WYSIWYG image insertion remains upload-backed and separate from image placeholder transforms.
## 2.8.2 - 2026-08-16
### Changed
- Standardized update audit events on from/to changes and added readable table diffs for nested JSON, arrays, null values, and empty strings.
- Standardized internal `src/data` imports on the `#src` alias.
## 2.8.1 - 2026-08-16
### Fixed
- Prevented startup and runtime duplicate-key writes from consuming auto-increment values in permission, player, onboarding, settings, and relationship tables.
- Prevented partial timetable schemas from being incorrectly treated as fully migrated during schema version detection.
### Changed
- Renamed the built-in administrator role key to `super-admin`, while allowing its display name and description to be edited without being overwritten on restart.
## 2.8.0 - 2026-08-16
### Added
- Filtered audit-log CSV export with a dedicated `audit-log.export` permission.
- Canvas Sizes as an individual Content audit category.
- Audit events for slide, template, playlist, and screen changes.
- Audit events for System Settings changes.
- Administration audit events for user and role management.
- Audit logging enablement, category selection, and request metadata controls.
- The extensible audit event storage, retention setting, dedicated audit-log permission, and paginated viewer foundation.
- A Defaults settings section for player and announcement defaults.
- A configurable maximum active session limit that removes the oldest sessions first.
- IP address and user-agent metadata to active sessions.
- The option for users to sign out their other active sessions from My Account.
- Persistent administrator-controlled account locking and unlocking.
- Database-backed login rate limiting with configurable attempts, lockout duration, and tracking scope.
- A permissions-gated System Settings page for announcement icon suggestions, media upload limits and MIME types, session lifetime, and password-change policies.
- Configurable forced password changes for newly created users and administrator password resets.
- The database foundation for key-based application settings, including typed defaults and validation.
### Changed
- Updated the API and database documentation and added the Docker publish status badge to the project README.
- Renamed the audit export permission to `audit-log.allow`.
- Made Content and Data Sources audit categories opt-in and excluded automatic data-source refreshes from audit logging.
- Split Content audit logging into individual Slides, Templates, Playlists, Screens, and Announcements categories.
- Renamed the System Settings audit category key from `settings` to `system-settings`.
- Split audit administration events into separate Users and Roles categories.
- Split RSS and API data-source refresh defaults.
- Made the default announcement duration use a value and unit selector, matching announcement forms.
- Replaced password strength presets with customizable length, category, and character requirements.
- Session expiration now uses the configured system setting, and user and role administration is grouped under the Settings area.
- Renamed the system settings permissions to the `system-settings.*` namespace and migrated existing role assignments.
- Added numeric auto-increment identifiers to every table and retained natural or relationship keys as unique constraints.
## 2.7.6 - 2026-08-15
### Changed
- The announcement icon picker now supports searching the full Bootstrap Icons catalog while still showing the curated suggestion set by default.
### Fixed
- The announcement Play/Stop button now refreshes after saving screen-group changes, so Play stays disabled until the announcement actually has targets again.
## 2.7.5 - 2026-08-15
### Changed
- The About page now reads bundled library versions from package metadata and the vendored AdminLTE stylesheet.
- AdminLTE is now reported as 4.3.1.
- Animate.css is now reported as 4.1.1.
- Bootstrap Icons is now reported as 1.13.1.
- Cropper.js is now reported as 1.6.2.
- Express is now reported as 5.2.1.
- Handlebars is now reported as 4.7.8.
- hls.js is now reported as 1.7.0.
- Multer is now reported as 2.2.0.
- MySQL2 is now reported as 3.23.3.
- Sharp is now reported as 0.35.3.
- TinyMCE is now reported from the vendored package metadata.
- ws is now reported as 8.21.3.
- The runtime and container images now target Node.js 26.
## 2.7.4 - 2026-08-15
### Added
- A new About page.
### Changed
- Refreshed the vendored AdminLTE assets to 4.3.1.
## 2.7.3 - 2026-08-15
### Changed
- The slide image cropper now warns that SVG and GIF files will be rasterized if they are edited, and it keeps the original file only when the full image remains selected.
- The slide image upload flow now accepts PNG, JPG, GIF, WebP, and SVG images, while the WYSIWYG image uploader now matches that same allowlist.
- TIFF is no longer accepted by the WYSIWYG image uploader.
### Fixed
- The player now preserves quoted custom font-family values from rich text content, so fonts with spaces such as Old London render correctly on screens.
## 2.7.2 - 2026-08-14
### Fixed
- HTML and webpage region previews now normalize object-shaped content before rendering, so the player, thumbnails, and popup preview show the intended iframe content instead of leaking raw objects.
- HTML and webpage preview iframes now size explicitly to the full region bounds in the player, thumbnails, and popup preview.
## 2.7.1 - 2026-08-14
### Changed
- The player page now supports keyboard navigation with arrow keys to move between slides.
## 2.7.0 - 2026-08-14
### Added
- The WYSIWYG editor now supports adding small images.
### Changed
- The WYSIWYG image insertion flow also received a small code cleanup to simplify the related helper logic.
- The default table formatting has been applied.
- Timetable regions now use the renamed helpers end to end in the editor and player, including timezone-aware rendering for timetable entry placeholders.
## 2.6.27 - 2026-08-14
### Fixed
- Scheduled task intervals now display the most appropriate exact unit, such as seconds, minutes, hours, or days, while keeping the sort order numeric.
## 2.6.26 - 2026-08-10
### Changed
- API sources and RSS feeds now accept hours as an update interval unit, and the list and background task scheduling paths now format and convert that unit correctly.
## 2.6.25 - 2026-08-10
### Fixed
- Screen group edit now keeps the slug locked after creation, so existing screen group URLs remain stable.
## 2.6.24 - 2026-08-10
### Fixed
- Deferred playlist updates now keep the current slide index when the next playlist snapshot is applied, so playback no longer jumps back to the first slide mid-cycle.
## 2.6.23 - 2026-08-09
### Fixed
- Dashboard quick-action and kiosk-launcher cards now use row spacing instead of extra card padding, so the layout stays consistent at large widths.
- API and RSS refresh jobs now notify affected player screens only when the refreshed data actually changes, so unchanged polls no longer trigger redundant player refreshes.
## 2.6.22 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether pending migrations exist.
### Fixed
- Direct-to-URL player sessions now generate and persist a stable onboarding device id in session storage, so connected screens can still be moved and renamed independently without going through the onboarding flow first.
- The connected-clients move action now tolerates rows that only have a live connection id, which keeps move operations working for screens that skipped onboarding.
## 2.6.21 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether migrations are required.
- The schema documentation now reflects the timetable table rename, the new `o_app_state` table, and startup version tracking.
- Timetable timezone placeholders now use `tz` for the short zone name and `tz_long` for the full IANA zone.
## 2.6.20 - 2026-08-09
### Changed
- Startup now logs the previously detected schema version, the current app version, and whether migrations are required.
## 2.6.19 - 2026-08-09
### Changed
- Timetable editor helpers, routes, and table layout now use timetable-specific naming and tighter card/table styling.
- Connected clients now sort by client identity fields instead of the old IP-based ordering assumption.
## 2.6.18 - 2026-08-09
### Changed
- Timetable tables were renamed from the old `schedule` names to `timetable` names, and existing databases now rename those tables during migration.
- The timetable group editor now uses timetable-specific naming in its shared helpers and keeps the entries table aligned with the standard admin card/table layout.
## 2.6.17 - 2026-08-09
### Changed
- Existing timetable groups and entries are now migrated to Europe/London, and timetable dates are rewritten to UTC using that source timezone so the wall-clock meaning stays intact.
### Fixed
- New timetable groups now default to Europe/London so the timetable editor and saved data start from the same timezone assumption as the migrated rows.
## 2.6.16 - 2026-08-09
### Changed
- Timetable groups now store an IANA time zone and render their entry datetimes in that timetable time zone, so schedules keep the same wall-clock meaning when they are edited from another country.
### Fixed
- Timetable entry date inputs now round-trip through the timetable time zone instead of the browser locale, so saving from Florida while targeting Germany keeps the intended local times.
## 2.6.15 - 2026-08-08
### Fixed
- Slide update media sync on the player now removes uploads that were removed from the slide, so player storage stays aligned with the current slide content.
- Routine player and player-bridge media upload/delete logs were removed to keep remote player and bridge operation quieter.
- Background task descriptions no longer repeat the player slug when the task key already ends with that player name.
## 2.6.14 - 2026-08-08
### Fixed
- Slide updates and template deletes now fan out media sync work across all live players instead of targeting only one player.
## 2.6.13 - 2026-08-08
### Fixed
- The player bundle now keeps the browser-only QR export dependencies lazy-loaded, so the remote player image no longer needs `puppeteer-core` or `@sparticuz/chromium` at startup.
- Remote player startup sync now falls back to `WEB_INTERNAL_URL` when it is configured, which avoids 404s when the bridge is not the correct sync target.
- The player startup sync and media-write info logs were removed to keep normal remote-player operation quieter.
## 2.6.12 - 2026-08-08 ## 2.6.12 - 2026-08-08
### Fixed ### Fixed
+2
View File
@@ -1,5 +1,7 @@
# Pulse Signage # Pulse Signage
[![Publish Docker Image](https://git.lzstealth.com/lzstealth/pulse-signage/actions/workflows/docker-publish.yml/badge.svg?branch=main)](https://git.lzstealth.com/lzstealth/pulse-signage/actions?workflow=docker-publish.yml)
Pulse Signage is a self-hosted digital signage platform for teams that want clear, reliable control over the content on every screen. Pulse Signage is a self-hosted digital signage platform for teams that want clear, reliable control over the content on every screen.
It gives you one place to publish playlists, slides, announcements, and live updates without handing the workflow to a third-party service. It gives you one place to publish playlists, slides, announcements, and live updates without handing the workflow to a third-party service.
+2 -1
View File
@@ -1,4 +1,4 @@
FROM node:24-alpine FROM node:26-alpine
WORKDIR /app WORKDIR /app
@@ -6,6 +6,7 @@ RUN apk add --no-cache chromium nss freetype harfbuzz ttf-freefont
COPY build/package.web.json ./package.json COPY build/package.web.json ./package.json
RUN npm install --omit=dev --no-audit --no-fund RUN npm install --omit=dev --no-audit --no-fund
COPY package-lock.json ./package-lock.json
COPY src ./src COPY src ./src
COPY scripts ./scripts COPY scripts ./scripts
+2 -1
View File
@@ -1,4 +1,4 @@
FROM node:24-alpine FROM node:26-alpine
WORKDIR /app WORKDIR /app
@@ -6,6 +6,7 @@ RUN apk add --no-cache ffmpeg
COPY build/package.player.json ./package.json COPY build/package.player.json ./package.json
RUN npm install --omit=dev --no-audit --no-fund RUN npm install --omit=dev --no-audit --no-fund
COPY package-lock.json ./package-lock.json
COPY src ./src COPY src ./src
COPY scripts ./scripts COPY scripts ./scripts
+8 -5
View File
@@ -1,8 +1,11 @@
{ {
"name": "pulse-signage-player", "name": "pulse-signage-player",
"version": "2.6.12", "version": "2.10.4",
"private": false, "private": false,
"description": "Pulse Signage player application bundle", "description": "Pulse Signage player application bundle",
"engines": {
"node": ">=26.0.0"
},
"main": "src/common.js", "main": "src/common.js",
"scripts": { "scripts": {
"start": "node -r dotenv/config src/player.js", "start": "node -r dotenv/config src/player.js",
@@ -10,10 +13,10 @@
}, },
"dependencies": { "dependencies": {
"dotenv": "^17.4.2", "dotenv": "^17.4.2",
"express": "^4.21.2", "express": "^5.2.1",
"handlebars": "^4.7.8", "handlebars": "^4.7.8",
"hls.js": "^1.5.15", "hls.js": "^1.7.0",
"mysql2": "^3.14.3", "mysql2": "^3.23.3",
"ws": "^8.21.0" "ws": "^8.21.3"
} }
} }
+10 -6
View File
@@ -1,22 +1,26 @@
{ {
"name": "pulse-signage-web", "name": "pulse-signage-web",
"version": "2.6.12", "version": "2.10.4",
"private": false, "private": false,
"description": "Pulse Signage web and bridge application bundle", "description": "Pulse Signage web and bridge application bundle",
"engines": {
"node": ">=26.0.0"
},
"main": "src/common.js", "main": "src/common.js",
"scripts": { "scripts": {
"start": "node -r dotenv/config src/web.js", "start": "node -r dotenv/config src/web.js",
"start:web": "node -r dotenv/config src/web.js" "start:web": "node -r dotenv/config src/web.js"
}, },
"dependencies": { "dependencies": {
"@sparticuz/chromium": "^137.0.0", "@sparticuz/chromium": "^149.0.0",
"dotenv": "^17.4.2", "dotenv": "^17.4.2",
"express": "^4.21.2", "express": "^5.2.1",
"handlebars": "^4.7.8", "handlebars": "^4.7.8",
"multer": "^2.2.0", "multer": "^2.2.0",
"mysql2": "^3.14.3", "mysql2": "^3.23.3",
"puppeteer-core": "^24.16.0", "puppeteer-core": "^25.7.0",
"sharp": "^0.35.3", "sharp": "^0.35.3",
"ws": "^8.21.0" "jsqr": "^1.4.0",
"ws": "^8.21.3"
} }
} }
+14 -10
View File
@@ -1,9 +1,11 @@
# Shared application settings # Container images
PULSE_SIGNAGE_WEB_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-web:latest" PULSE_SIGNAGE_WEB_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-web:latest"
PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest" PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest"
# Shared security
PULSE_SIGNAGE_SHARED_SECRET="" PULSE_SIGNAGE_SHARED_SECRET=""
# Database settings for the web, player, and bridge services # Database
DB_HOST="mysql" DB_HOST="mysql"
DB_PORT=3306 DB_PORT=3306
DB_NAME="pulse-signage" DB_NAME="pulse-signage"
@@ -11,17 +13,19 @@ DB_USER="pulse-signage"
DB_PASSWORD="signage_password" DB_PASSWORD="signage_password"
MYSQL_ROOT_PASSWORD="root_password" MYSQL_ROOT_PASSWORD="root_password"
# Player settings # Web application
WEB_PUBLIC_URL="http://localhost:8080"
WEB_INTERNAL_URL="http://web:8080"
# Player
PLAYER_IDENTIFIER="player-local" PLAYER_IDENTIFIER="player-local"
PLAYER_PUBLIC_URL="http://localhost:8081" PLAYER_PUBLIC_URL="http://localhost:8081"
PLAYER_INTERNAL_URL="http://player:8081" PLAYER_INTERNAL_URL="http://player:8081"
# Web app bootstrap settings # Player bridge
SESSION_MAX_AGE_DAYS=14 BRIDGE_INTERNAL_URL="http://player-bridge:8090"
# First-run administrator
DEFAULT_ADMIN_USERNAME="admin" DEFAULT_ADMIN_USERNAME="admin"
DEFAULT_ADMIN_NAME="Admin" DEFAULT_ADMIN_NAME="Admin"
DEFAULT_ADMIN_PASSWORD="password123" DEFAULT_ADMIN_PASSWORD="password123!"
# Bridge settings for the player-bridge service
WEB_INTERNAL_URL="http://web:8080"
BRIDGE_INTERNAL_URL="http://player-bridge:8090"
+9 -4
View File
@@ -1,11 +1,16 @@
# Shared application settings # Container image
PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest" PULSE_SIGNAGE_PLAYER_IMAGE="git.lzstealth.com/lzstealth/pulse-signage-player:latest"
# Shared security
PULSE_SIGNAGE_SHARED_SECRET="" PULSE_SIGNAGE_SHARED_SECRET=""
# Player settings # Remote player
PLAYER_IDENTIFIER="player-remote" PLAYER_IDENTIFIER="player-remote"
PLAYER_PUBLIC_URL="http://localhost:8081"
# Optional URL used by the kiosk launcher when the remote player is directly reachable
# PLAYER_PUBLIC_URL="http://remote-player.example.com:8081"
PLAYER_AGENT_RECONNECT_DELAY_MS=5000 PLAYER_AGENT_RECONNECT_DELAY_MS=5000
# Remote player connectivity settings # Remote bridge connectivity
BRIDGE_PUBLIC_URL="http://player-bridge.example.com:8090" BRIDGE_PUBLIC_URL="http://player-bridge.example.com:8090"
+21 -27
View File
@@ -6,7 +6,7 @@ This folder contains the Docker Compose definitions for Pulse Signage, including
- [docker-compose.yml](docker-compose.yml) - full public stack with web, player, player bridge, and MySQL. - [docker-compose.yml](docker-compose.yml) - full public stack with web, player, player bridge, and MySQL.
- [.env.example](.env.example) - sample environment values for the public stack. - [.env.example](.env.example) - sample environment values for the public stack.
- [docker-compose.remote.yml](docker-compose.remote.yml) - remote player-only stack for machines that sit behind the player bridge. - [docker-compose.remote.yml](docker-compose.remote.yml) - remote player-only stack using a published player image.
- [.env.remote.example](.env.remote.example) - sample environment values for the remote stack. - [.env.remote.example](.env.remote.example) - sample environment values for the remote stack.
## Stack Overview ## Stack Overview
@@ -45,11 +45,9 @@ Key configuration:
- `DB_HOST`, `DB_PORT`, `DB_NAME`, `DB_USER`, `DB_PASSWORD` - `DB_HOST`, `DB_PORT`, `DB_NAME`, `DB_USER`, `DB_PASSWORD`
- `PULSE_SIGNAGE_SHARED_SECRET` - `PULSE_SIGNAGE_SHARED_SECRET`
- `SESSION_MAX_AGE_DAYS`
- `DEFAULT_ADMIN_USERNAME` - `DEFAULT_ADMIN_USERNAME`
- `DEFAULT_ADMIN_NAME` - `DEFAULT_ADMIN_NAME`
- `DEFAULT_ADMIN_PASSWORD` - `DEFAULT_ADMIN_PASSWORD`
- `PASSWORD_HASH_ITERATIONS`
### `player` ### `player`
@@ -58,15 +56,13 @@ The screen runtime that renders playlists and receives commands.
Responsibilities: Responsibilities:
- serves the player UI on port `8081` - serves the player UI on port `8081`
- connects to MySQL in local mode - connects to MySQL in the public stack
- connects to the bridge in remote mode through `BRIDGE_PUBLIC_URL` - connects to the bridge in remote mode through `BRIDGE_PUBLIC_URL`
- registers live connections and accepts control commands - registers live connections and accepts control commands
Key configuration: Key configuration:
- `PLAYER_PUBLIC_URL`
- `PLAYER_INTERNAL_URL` - `PLAYER_INTERNAL_URL`
- `BRIDGE_INTERNAL_URL`
- `PLAYER_IDENTIFIER` - `PLAYER_IDENTIFIER`
- `BRIDGE_PUBLIC_URL` in remote mode - `BRIDGE_PUBLIC_URL` in remote mode
- `PULSE_SIGNAGE_SHARED_SECRET` - `PULSE_SIGNAGE_SHARED_SECRET`
@@ -116,16 +112,15 @@ Important values:
- `PULSE_SIGNAGE_WEB_IMAGE` - image to run for the web app and bridge services, typically `.../pulse-signage-web:latest` - `PULSE_SIGNAGE_WEB_IMAGE` - image to run for the web app and bridge services, typically `.../pulse-signage-web:latest`
- `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run for the player services, typically `.../pulse-signage-player:latest` - `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run for the player services, typically `.../pulse-signage-player:latest`
- `PULSE_SIGNAGE_SHARED_SECRET` - long random secret shared by the web, player, and bridge services for authenticated requests - `PULSE_SIGNAGE_SHARED_SECRET` - long random secret shared by the web, player, and bridge services for authenticated requests
- `PLAYER_IDENTIFIER` - unique local player identifier
- `DB_*` - MySQL credentials and database name for the stack - `DB_*` - MySQL credentials and database name for the stack
- `PLAYER_PUBLIC_URL` - public URL the player advertises - `MYSQL_ROOT_PASSWORD` - root password for the local MySQL container
- `WEB_PUBLIC_URL` - public URL of the web application
- `WEB_INTERNAL_URL` - internal URL the bridge uses to call the web app directly
- `PLAYER_IDENTIFIER` - unique local player identifier
- `PLAYER_PUBLIC_URL` - URL used by the kiosk launcher and direct player access
- `PLAYER_INTERNAL_URL` - internal URL the web app uses for local player calls - `PLAYER_INTERNAL_URL` - internal URL the web app uses for local player calls
- `BRIDGE_INTERNAL_URL` - bridge URL the web app uses for player snapshot and command forwarding - `BRIDGE_INTERNAL_URL` - bridge URL the web app uses for player snapshot and command forwarding
- `WEB_INTERNAL_URL` - internal URL the bridge uses to call the web app directly
- `SESSION_MAX_AGE_DAYS` - dashboard session lifetime
- `DEFAULT_ADMIN_*` - bootstrap admin account values - `DEFAULT_ADMIN_*` - bootstrap admin account values
- `PASSWORD_HASH_ITERATIONS` - password hashing cost
- `MYSQL_ROOT_PASSWORD` - root password for the local MySQL container
### `.env.remote.example` ### `.env.remote.example`
@@ -136,7 +131,7 @@ Important values:
- `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run on the device, typically `.../pulse-signage-player:latest` - `PULSE_SIGNAGE_PLAYER_IMAGE` - image to run on the device, typically `.../pulse-signage-player:latest`
- `PULSE_SIGNAGE_SHARED_SECRET` - must match the public stack and should be the same long random value used everywhere in the deployment - `PULSE_SIGNAGE_SHARED_SECRET` - must match the public stack and should be the same long random value used everywhere in the deployment
- `PLAYER_IDENTIFIER` - unique remote player identifier - `PLAYER_IDENTIFIER` - unique remote player identifier
- `PLAYER_PUBLIC_URL` - public URL for the remote player - `PLAYER_PUBLIC_URL` - optional URL used by the kiosk launcher when the remote player is directly reachable
- `BRIDGE_PUBLIC_URL` - bridge URL the player connects back to - `BRIDGE_PUBLIC_URL` - bridge URL the player connects back to
- `PLAYER_AGENT_RECONNECT_DELAY_MS` - reconnect delay for the player agent - `PLAYER_AGENT_RECONNECT_DELAY_MS` - reconnect delay for the player agent
@@ -167,21 +162,20 @@ Leave it blank only if you intentionally want to run without request signing in
| `DB_USER` | web, player, bridge, mysql | Database user. | | `DB_USER` | web, player, bridge, mysql | Database user. |
| `DB_PASSWORD` | web, player, bridge, mysql | Database password. | | `DB_PASSWORD` | web, player, bridge, mysql | Database password. |
| `MYSQL_ROOT_PASSWORD` | mysql | Root password for the local MySQL container. | | `MYSQL_ROOT_PASSWORD` | mysql | Root password for the local MySQL container. |
| `SESSION_MAX_AGE_DAYS` | web | Session cookie lifetime. |
| `DEFAULT_ADMIN_USERNAME` | web | Bootstrap admin username. |
| `DEFAULT_ADMIN_NAME` | web | Bootstrap admin display name. |
| `DEFAULT_ADMIN_PASSWORD` | web | Bootstrap admin password. |
| `PASSWORD_HASH_ITERATIONS` | web | Password hashing cost. |
| `PLAYER_INTERNAL_URL` | web, player | Internal player URL used by the dashboard and player runtime. |
| `BRIDGE_INTERNAL_URL` | web | Bridge URL used by the web app for player snapshot and command forwarding. |
| `WEB_INTERNAL_URL` | player-bridge | Internal web URL used by the bridge to call the dashboard app directly. |
| `PLAYER_PUBLIC_URL` | player, remote player | Public URL advertised by the player. |
| `BRIDGE_PUBLIC_URL` | player, remote player | URL of the bridge service. |
| `PLAYER_IDENTIFIER` | player | Stable player identifier. |
| `PLAYER_AGENT_RECONNECT_DELAY_MS` | remote player | Delay before reconnecting to the bridge. |
| `MYSQL_DATABASE` | mysql | Database name used by the local MySQL container. | | `MYSQL_DATABASE` | mysql | Database name used by the local MySQL container. |
| `MYSQL_USER` | mysql | Database user used by the local MySQL container. | | `MYSQL_USER` | mysql | Database user used by the local MySQL container. |
| `MYSQL_PASSWORD` | mysql | Database password used by the local MySQL container. | | `MYSQL_PASSWORD` | mysql | Database password used by the local MySQL container. |
| `WEB_PUBLIC_URL` | web, player-bridge | Public URL of the web application. |
| `WEB_INTERNAL_URL` | player-bridge | Internal web URL used by the bridge to call the dashboard app directly. |
| `PLAYER_IDENTIFIER` | player | Stable player identifier. |
| `PLAYER_PUBLIC_URL` | player, remote player | URL used by the kiosk launcher and direct player access; optional for bridge-only remote players. |
| `PLAYER_INTERNAL_URL` | web, player | Internal player URL used by the dashboard and player runtime. |
| `BRIDGE_INTERNAL_URL` | web | Bridge URL used by the web app for player snapshot and command forwarding. |
| `DEFAULT_ADMIN_USERNAME` | web | Bootstrap admin username. |
| `DEFAULT_ADMIN_NAME` | web | Bootstrap admin display name. |
| `DEFAULT_ADMIN_PASSWORD` | web | Bootstrap admin password. |
| `BRIDGE_PUBLIC_URL` | remote player | URL of the bridge service. |
| `PLAYER_AGENT_RECONNECT_DELAY_MS` | remote player | Delay before reconnecting to the bridge. |
## Ports ## Ports
@@ -212,7 +206,7 @@ Remote stack ports:
Each compose file creates its own named network: Each compose file creates its own named network:
- `pulse-signage` for the public stack - `pulse-signage` for the public stack
- `pulse-signage-remote` for remote player deployment. - `pulse-signage-remote` for the remote player deployment.
## Notes ## Notes
@@ -220,7 +214,7 @@ Each compose file creates its own named network:
- A remote player must use the same `PULSE_SIGNAGE_SHARED_SECRET` as the bridge it connects to. - A remote player must use the same `PULSE_SIGNAGE_SHARED_SECRET` as the bridge it connects to.
- The bridge service is the dashboard-facing command path for connected remote players. - The bridge service is the dashboard-facing command path for connected remote players.
- The remote player should point `BRIDGE_PUBLIC_URL` at the bridge, not at the public web endpoint. - The remote player should point `BRIDGE_PUBLIC_URL` at the bridge, not at the public web endpoint.
- The `PULSE_SIGNAGE_WEB_IMAGE` and `PULSE_SIGNAGE_PLAYER_IMAGE` tags default to the published `pulse-signage-web` and `pulse-signage-player` repositories with `latest` and `v1.2.3` style tags, but they can be overridden for local builds or custom releases. - The `PULSE_SIGNAGE_WEB_IMAGE` and `PULSE_SIGNAGE_PLAYER_IMAGE` tags default to the published `pulse-signage-web` and `pulse-signage-player` repositories with `latest` tags, but they can be overridden for custom releases.
## Recommended Setup ## Recommended Setup
+2 -2
View File
@@ -11,8 +11,8 @@ services:
- "8081:8081" - "8081:8081"
environment: environment:
PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-remote} PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-remote}
PLAYER_PUBLIC_URL: ${PLAYER_PUBLIC_URL:-http://localhost:8081} PLAYER_PUBLIC_URL: ${PLAYER_PUBLIC_URL:-}
BRIDGE_PUBLIC_URL: ${BRIDGE_PUBLIC_URL:-} BRIDGE_PUBLIC_URL: ${BRIDGE_PUBLIC_URL:?BRIDGE_PUBLIC_URL must be set to a routable bridge URL}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-} PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
PLAYER_AGENT_RECONNECT_DELAY_MS: ${PLAYER_AGENT_RECONNECT_DELAY_MS:-5000} PLAYER_AGENT_RECONNECT_DELAY_MS: ${PLAYER_AGENT_RECONNECT_DELAY_MS:-5000}
volumes: volumes:
+3 -1
View File
@@ -15,8 +15,8 @@ services:
DB_USER: ${DB_USER:-pulse-signage} DB_USER: ${DB_USER:-pulse-signage}
DB_PASSWORD: ${DB_PASSWORD:-signage_password} DB_PASSWORD: ${DB_PASSWORD:-signage_password}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-} PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
WEB_PUBLIC_URL: ${WEB_PUBLIC_URL:-http://localhost:8080}
BRIDGE_INTERNAL_URL: ${BRIDGE_INTERNAL_URL:-http://player-bridge:8090} BRIDGE_INTERNAL_URL: ${BRIDGE_INTERNAL_URL:-http://player-bridge:8090}
SESSION_MAX_AGE_DAYS: ${SESSION_MAX_AGE_DAYS:-14}
DEFAULT_ADMIN_USERNAME: ${DEFAULT_ADMIN_USERNAME:-admin} DEFAULT_ADMIN_USERNAME: ${DEFAULT_ADMIN_USERNAME:-admin}
DEFAULT_ADMIN_NAME: ${DEFAULT_ADMIN_NAME:-Admin} DEFAULT_ADMIN_NAME: ${DEFAULT_ADMIN_NAME:-Admin}
DEFAULT_ADMIN_PASSWORD: ${DEFAULT_ADMIN_PASSWORD:-password123} DEFAULT_ADMIN_PASSWORD: ${DEFAULT_ADMIN_PASSWORD:-password123}
@@ -39,6 +39,7 @@ services:
PLAYER_INTERNAL_URL: ${PLAYER_INTERNAL_URL:-http://player:8081} PLAYER_INTERNAL_URL: ${PLAYER_INTERNAL_URL:-http://player:8081}
PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-local} PLAYER_IDENTIFIER: ${PLAYER_IDENTIFIER:-player-local}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-} PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
WEB_PUBLIC_URL: ${WEB_PUBLIC_URL:-http://localhost:8080}
DB_HOST: ${DB_HOST:-mysql} DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306} DB_PORT: ${DB_PORT:-3306}
DB_NAME: ${DB_NAME:-pulse-signage} DB_NAME: ${DB_NAME:-pulse-signage}
@@ -60,6 +61,7 @@ services:
- "8090:8090" - "8090:8090"
environment: environment:
WEB_INTERNAL_URL: ${WEB_INTERNAL_URL:-http://web:8080} WEB_INTERNAL_URL: ${WEB_INTERNAL_URL:-http://web:8080}
WEB_PUBLIC_URL: ${WEB_PUBLIC_URL:-http://localhost:8080}
PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-} PULSE_SIGNAGE_SHARED_SECRET: ${PULSE_SIGNAGE_SHARED_SECRET:-}
DB_HOST: ${DB_HOST:-mysql} DB_HOST: ${DB_HOST:-mysql}
DB_PORT: ${DB_PORT:-3306} DB_PORT: ${DB_PORT:-3306}
+10 -11
View File
@@ -6,7 +6,7 @@ Player service base URL: `http://localhost:8081`
This document covers the player HTTP surface only. The admin dashboard exposes its own routes for screen commands and onboarding management. This document covers the player HTTP surface only. The admin dashboard exposes its own routes for screen commands and onboarding management.
Access note: most player endpoints are unauthenticated because they are meant to run inside a trusted deployment network. Anything that mutates state or writes files should be treated as internal-only unless you add your own auth layer in front of it. Access note: most player endpoints are unauthenticated because they are meant to run inside a trusted deployment network. Anything that mutates state or writes files should be treated as internal-only unless you add your own auth layer in front of it. Pairing uses a short-lived random PIN displayed by the kiosk; the PIN is accepted only through the authenticated Web UI pairing flow.
When `PULSE_SIGNAGE_SHARED_SECRET` is set, the player pages sign same-origin API fetches with `x-pulse-page-auth`, and the web app signs server-to-player requests with `x-pulse-request-timestamp` plus `x-pulse-request-signature`. Page tokens auto-renew before expiry while the page stays active, and signed server requests are only accepted when their timestamp is fresh. If the secret is unset, those checks stay disabled for compatibility. When `PULSE_SIGNAGE_SHARED_SECRET` is set, the player pages sign same-origin API fetches with `x-pulse-page-auth`, and the web app signs server-to-player requests with `x-pulse-request-timestamp` plus `x-pulse-request-signature`. Page tokens auto-renew before expiry while the page stays active, and signed server requests are only accepted when their timestamp is fresh. If the secret is unset, those checks stay disabled for compatibility.
@@ -17,12 +17,12 @@ Returns the player onboarding landing page.
Access: public within the trusted player deployment. Access: public within the trusted player deployment.
### `GET /onboard` ### `GET /onboard`
Returns the onboarding form page. Redirects to the authenticated Web UI pairing page for compatibility with older QR codes.
Access: public within the trusted player deployment. Access: the Web UI pairing page requires a logged-in Web UI session.
### `GET /screen/{slug}` ### `GET /screen/{slug}`
Returns the rendered player page for a screen. Returns the rendered player page for a screen.
Access: public within the trusted player deployment. Access: the configured player may load only its persisted paired screen. An unpaired player is redirected to `/`; a different screen slug is rejected. The route is public within the trusted player deployment, but it no longer changes the player's binding.
### `GET /api/onboarding/status` ### `GET /api/onboarding/status`
Returns the persisted onboarding status for a device. Returns the persisted onboarding status for a device.
@@ -56,7 +56,7 @@ Response fields:
### `POST /api/onboarding` ### `POST /api/onboarding`
Binds a device to a screen and client name. Binds a device to a screen and client name.
Access: internal-only. Protect this endpoint if the player service is reachable outside your trusted network. Access: internal-only. Browser submissions must go through the authenticated Web UI pairing page. The Web UI resolves the short-lived kiosk PIN to a device ID before forwarding the signed request. Protect this endpoint if the player service is reachable outside your trusted network.
Accepted request fields: Accepted request fields:
@@ -286,6 +286,8 @@ Response fields:
- `id` - `id`
- `name` - `name`
- `fade_between_slides` - `fade_between_slides`
- `skip_unavailable_rtmp`
- `canvas_id`
### Slide ### Slide
@@ -293,12 +295,9 @@ Response fields:
- `title` - `title`
- `body` - `body`
- `duration_seconds` - `duration_seconds`
- `schedule_mode` - `use_video_duration`
- `schedule_start_datetime` - `disable_audio`
- `schedule_end_datetime` - `scheduleRules`
- `schedule_start_time`
- `schedule_end_time`
- `schedule_days_json`
- `media_url` - `media_url`
- `media_type` - `media_type`
- `kind` - `kind`
+67 -33
View File
@@ -3,7 +3,7 @@
This app creates and maintains its schema at startup through `src/db/index.js`. This app creates and maintains its schema at startup through `src/db/index.js`.
The sections below summarize the current tables and their purpose. The sections below summarize the current tables and their purpose.
Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_at` and `modified_at` when a table supports auditing. Tables generally use a numeric auto-increment `id` primary key. The relationship table `d_announcement_screens` intentionally uses the composite `(announcement_id, screen_id)` primary key instead. Natural and relationship keys remain as unique constraints where needed. Timestamps are stored as `created_at` and `modified_at` when a table supports auditing.
## Admin ## Admin
@@ -16,7 +16,7 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `a_users` ### `a_users`
- `id`, `name`, `username`, `password_hash`, `password_salt`, `password_iterations`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `name`, `username`, `password_hash`, `password_salt`, `password_iterations`, `must_change_password`, `account_locked`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `username` is unique. - `username` is unique.
### `a_roles` ### `a_roles`
@@ -32,24 +32,24 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `a_role_permissions` ### `a_role_permissions`
- `role_id`, `permission_id`, `created_at`, `modified_at` - `id`, `role_id`, `permission_id`, `created_at`, `modified_at`
- Foreign keys: - Foreign keys:
- `role_id` -> `a_roles.id` - `role_id` -> `a_roles.id`
- `permission_id` -> `a_permissions.id` - `permission_id` -> `a_permissions.id`
- Composite primary key: `(role_id, permission_id)` - Unique key: `(role_id, permission_id)`
### `a_user_roles` ### `a_user_roles`
- `user_id`, `role_id`, `created_at`, `modified_at` - `id`, `user_id`, `role_id`, `created_at`, `modified_at`
- Foreign keys: - Foreign keys:
- `user_id` -> `a_users.id` - `user_id` -> `a_users.id`
- `role_id` -> `a_roles.id` - `role_id` -> `a_roles.id`
- Composite primary key: `(user_id, role_id)` - Unique key: `(user_id, role_id)`
### `a_sessions` ### `a_sessions`
- `session_hash`, `user_id`, `expires_at`, `created_at`, `created_by`, `last_used_at`, `modified_by` - `id`, `session_hash`, `user_id`, `ip_address`, `user_agent`, `expires_at`, `created_at`, `created_by`, `last_used_at`, `modified_by`
- `session_hash` is the primary key. - `session_hash` is unique.
- Foreign key: - Foreign key:
- `user_id` -> `a_users.id` - `user_id` -> `a_users.id`
@@ -76,7 +76,8 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `c_templates` ### `c_templates`
- `id`, `name`, `canvas_size_id`, `background_image_path`, `background_color`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `name`, `canvas_size_id`, `background_image_path`, `background_color`, `background_gradient`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `background_gradient` stores normalized linear gradient settings as JSON text, including angle and colour stops.
- Foreign key: - Foreign key:
- `canvas_size_id` -> `c_canvas_sizes.id` with `ON DELETE SET NULL` - `canvas_size_id` -> `c_canvas_sizes.id` with `ON DELETE SET NULL`
@@ -116,11 +117,6 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
- `d_screens` - screen records and playlist assignment. - `d_screens` - screen records and playlist assignment.
- `d_onboarding_devices` - device-to-screen bindings and onboarded client names. - `d_onboarding_devices` - device-to-screen bindings and onboarded client names.
## Announcements
- `d_announcements` - announcement content and display metadata.
- `d_announcement_screens` - announcement-to-screen assignments.
### `d_players` ### `d_players`
- `id`, `identifier`, `public_base_url`, `internal_base_url`, `last_seen_at`, `created_at`, `modified_at` - `id`, `identifier`, `public_base_url`, `internal_base_url`, `last_seen_at`, `created_at`, `modified_at`
@@ -138,11 +134,20 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `d_onboarding_devices` ### `d_onboarding_devices`
- `device_id`, `client_name`, `screen_id`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `device_id`, `client_name`, `screen_id`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `device_id` is the primary key. - `device_id` is unique.
- Foreign key: - Foreign key:
- `screen_id` -> `d_screens.id` with `ON DELETE SET NULL` - `screen_id` -> `d_screens.id` with `ON DELETE SET NULL`
## Onboarding
- The onboarding flow uses `d_onboarding_devices` to bind a device to a screen and persist the client name.
## Announcements
- `d_announcements` - announcement content and display metadata.
- `d_announcement_screens` - announcement-to-screen assignments.
### `d_announcements` ### `d_announcements`
- `id`, `message`, `short_label`, `announcement_type`, `color_key`, `icon_key`, `duration_seconds`, `expires_at`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `message`, `short_label`, `announcement_type`, `color_key`, `icon_key`, `duration_seconds`, `expires_at`, `created_at`, `created_by`, `modified_at`, `modified_by`
@@ -154,23 +159,19 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
- Foreign keys: - Foreign keys:
- `announcement_id` -> `d_announcements.id` with `ON DELETE CASCADE` - `announcement_id` -> `d_announcements.id` with `ON DELETE CASCADE`
- `screen_id` -> `d_screens.id` with `ON DELETE CASCADE` - `screen_id` -> `d_screens.id` with `ON DELETE CASCADE`
- Composite primary key: `(announcement_id, screen_id)` - Unique key: `(announcement_id, screen_id)`
## Onboarding
- The onboarding flow uses `d_onboarding_devices` to bind a device to a screen and persist the client name.
## Integrations ## Integrations
- `i_rss_feeds` - RSS feed definitions and refresh cadence. - `i_rss_feeds` - RSS feed definitions and refresh cadence.
- `i_rss_feed_items` - cached RSS feed items. - `i_rss_feed_items` - cached RSS feed items.
- `i_api_sources` - API source definitions and last response snapshot. - `i_api_sources` - API source definitions and last response snapshot.
- `i_schedule_groups` - grouped schedule definitions used by the schedule region. - `i_timetable_groups` - grouped timetable definitions used by the timetable region.
- `i_schedule_entries` - dated entries that belong to a schedule group. - `i_timetable_entries` - dated entries that belong to a timetable group.
### `i_rss_feeds` ### `i_rss_feeds`
- `id`, `name`, `feed_url`, `update_interval_value`, `update_interval_unit`, `item_limit`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `name`, `feed_url`, `update_interval_value`, `update_interval_unit`, `item_limit`, `enabled`, `last_pulled_at`, `created_at`, `created_by`, `modified_at`, `modified_by`
### `i_rss_feed_items` ### `i_rss_feed_items`
@@ -182,34 +183,60 @@ Primary keys are `id` unless noted otherwise. Timestamps are stored as `created_
### `i_api_sources` ### `i_api_sources`
- `id`, `name`, `api_url`, `auth_method`, `auth_username`, `auth_password`, `auth_bearer_token`, `auth_header_name`, `auth_header_value`, `items_path`, `update_interval_value`, `update_interval_unit`, `last_pulled_at`, `last_pull_error`, `last_response_status`, `last_response_content_type`, `last_response_json`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `name`, `api_url`, `auth_method`, `auth_username`, `auth_password`, `auth_bearer_token`, `auth_header_name`, `auth_header_value`, `items_path`, `update_interval_value`, `update_interval_unit`, `enabled`, `last_pulled_at`, `last_pull_error`, `last_response_status`, `last_response_content_type`, `last_response_json`, `created_at`, `created_by`, `modified_at`, `modified_by`
### `i_schedule_groups` ### `i_weather_locations`
- `id`, `name`, `short_description`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `name`, `location_label`, `latitude`, `longitude`, `timezone`, `provider`, `temperature_unit`, `wind_unit`, `precipitation_unit`, `update_interval_value`, `update_interval_unit`, `enabled`, `last_pulled_at`, `last_pull_error`, `last_response_json`, `created_at`, `created_by`, `modified_at`, `modified_by`
- Stores configured weather locations and the most recent provider response used for forecast previews and weather regions.
### `i_schedule_entries` ### `i_timetable_groups`
- `id`, `name`, `short_description`, `timezone`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `timezone` defaults to `Europe/London`.
### `i_timetable_entries`
- `id`, `schedule_group_id`, `title`, `short_description`, `start_datetime`, `end_datetime`, `created_at`, `created_by`, `modified_at`, `modified_by` - `id`, `schedule_group_id`, `title`, `short_description`, `start_datetime`, `end_datetime`, `created_at`, `created_by`, `modified_at`, `modified_by`
- Foreign key: - Foreign key:
- `schedule_group_id` -> `i_schedule_groups.id` with `ON DELETE CASCADE` - `schedule_group_id` -> `i_timetable_groups.id` with `ON DELETE CASCADE`
- Index: - Index:
- `(schedule_group_id, start_datetime)` - `(schedule_group_id, start_datetime)`
## Operations ## Operations
- `o_background_tasks` - queue and history for background jobs. - `o_background_tasks` - queue and history for background jobs.
- `o_app_state` - generic app state and version markers stored as key/value pairs.
- `o_app_settings` - administrator-configurable application settings stored by key.
- `o_audit_events` - retained audit events for administrator activity and system changes.
### `o_background_tasks` ### `o_background_tasks`
- `id`, `task_key`, `task_type`, `title`, `category`, `status`, `payload_json`, `metadata_json`, `attempts`, `created_at`, `created_by`, `started_at`, `finished_at`, `error_message` - `id`, `task_key`, `task_type`, `title`, `category`, `status`, `payload_json`, `metadata_json`, `attempts`, `created_at`, `created_by`, `started_at`, `finished_at`, `error_message`
- Indexed by `status`, `task_key`, and `task_type`. - Indexed by `status`, `task_key`, and `task_type`.
### `o_app_state`
- `id`, `state_key`, `state_value`, `created_at`, `modified_at`
- `state_key` is unique.
- `schema_version` is stored here so startup can detect the previously recorded schema version before deciding whether migrations need to run.
### `o_app_settings`
- `id`, `setting_key`, `setting_value`, `created_at`, `created_by`, `modified_at`, `modified_by`
- `setting_key` is unique.
- Values are stored as JSON and validated against the application setting definitions in `src/data/app-settings.js`.
### `o_audit_events`
- `id`, `occurred_at`, `category`, `event_type`, `actor_user_id`, `target_type`, `target_id`, `target_label`, `ip_address`, `user_agent`, `details_json`
- Indexed by occurrence time, category and event type, actor, and target.
## Notes ## Notes
- The schema is initialized with `CREATE TABLE IF NOT EXISTS`, so new installs can start from an empty database. - The schema is initialized with `CREATE TABLE IF NOT EXISTS`, so new installs can start from an empty database.
- `src/db/bootstrap.js` seeds the canvas size defaults, default permissions, and the default administrator role. - `src/db/bootstrap.js` seeds the canvas size defaults, default permissions, and the default administrator role.
- The migration module stays in place for future releases, but this version treats the current schema as the install baseline. - `src/db/migrations.js` records the current schema version in `o_app_state` during startup so later launches can tell whether an update is happening.
```mermaid ```mermaid
erDiagram erDiagram
@@ -255,18 +282,25 @@ erDiagram
} }
I_API_SOURCES { I_API_SOURCES {
} }
I_SCHEDULE_GROUPS { I_TIMETABLE_GROUPS {
} }
I_SCHEDULE_ENTRIES { I_TIMETABLE_ENTRIES {
}
O_APP_STATE {
}
O_APP_SETTINGS {
} }
O_BACKGROUND_TASKS { O_BACKGROUND_TASKS {
} }
O_AUDIT_EVENTS {
}
A_USERS ||--o{ A_USER_ROLES : has A_USERS ||--o{ A_USER_ROLES : has
A_ROLES ||--o{ A_USER_ROLES : assigned_to A_ROLES ||--o{ A_USER_ROLES : assigned_to
A_ROLES ||--o{ A_ROLE_PERMISSIONS : has A_ROLES ||--o{ A_ROLE_PERMISSIONS : has
A_PERMISSIONS ||--o{ A_ROLE_PERMISSIONS : granted_to A_PERMISSIONS ||--o{ A_ROLE_PERMISSIONS : granted_to
A_USERS ||--o{ A_SESSIONS : owns A_USERS ||--o{ A_SESSIONS : owns
A_USERS ||--o{ O_AUDIT_EVENTS : acts
C_CANVAS_SIZES ||--o{ C_TEMPLATES : used_by C_CANVAS_SIZES ||--o{ C_TEMPLATES : used_by
C_CANVAS_SIZES ||--o{ C_PLAYLISTS : used_by C_CANVAS_SIZES ||--o{ C_PLAYLISTS : used_by
@@ -282,5 +316,5 @@ erDiagram
D_SCREENS ||--o{ D_ANNOUNCEMENT_SCREENS : receives D_SCREENS ||--o{ D_ANNOUNCEMENT_SCREENS : receives
I_RSS_FEEDS ||--o{ I_RSS_FEED_ITEMS : caches I_RSS_FEEDS ||--o{ I_RSS_FEED_ITEMS : caches
I_SCHEDULE_GROUPS ||--o{ I_SCHEDULE_ENTRIES : contains I_TIMETABLE_GROUPS ||--o{ I_TIMETABLE_ENTRIES : contains
``` ```
+580 -984
View File
File diff suppressed because it is too large Load Diff
+12 -8
View File
@@ -1,8 +1,11 @@
{ {
"name": "pulse-signage", "name": "pulse-signage",
"version": "2.6.12", "version": "2.10.4",
"private": false, "private": false,
"description": "Pulse Signage application with MySQL and media storage", "description": "Pulse Signage application with MySQL and media storage",
"engines": {
"node": ">=26.0.0"
},
"repository": { "repository": {
"type": "git", "type": "git",
"url": "https://git.lzstealth.com/LZStealth/pulse-signage.git" "url": "https://git.lzstealth.com/LZStealth/pulse-signage.git"
@@ -17,19 +20,20 @@
"test": "node --test" "test": "node --test"
}, },
"dependencies": { "dependencies": {
"@sparticuz/chromium": "^137.0.0", "@sparticuz/chromium": "^149.0.0",
"animate.css": "^4.1.1", "animate.css": "^4.1.1",
"bootstrap-icons": "1.11.3", "bootstrap-icons": "1.13.1",
"cropperjs": "^1.6.2", "cropperjs": "^1.6.2",
"dotenv": "^17.4.2", "dotenv": "^17.4.2",
"express": "^4.21.2", "express": "^5.2.1",
"handlebars": "^4.7.8", "handlebars": "^4.7.8",
"hls.js": "^1.5.15", "hls.js": "^1.7.0",
"jsqr": "^1.4.0",
"multer": "^2.2.0", "multer": "^2.2.0",
"mysql2": "^3.14.3", "mysql2": "^3.23.3",
"puppeteer-core": "^24.16.0", "puppeteer-core": "^25.7.0",
"sharp": "^0.35.3", "sharp": "^0.35.3",
"ws": "^8.21.0" "ws": "^8.21.3"
}, },
"devDependencies": { "devDependencies": {
"nodemon": "^3.1.10" "nodemon": "^3.1.10"
+5 -2
View File
@@ -53,9 +53,12 @@ if not defined BROWSER_PATH (
exit /b 1 exit /b 1
) )
set "KIOSK_PROFILE=%LocalAppData%\PulseSignage\kiosk-browser-profile"
if not exist "!KIOSK_PROFILE!" mkdir "!KIOSK_PROFILE!"
echo Launching !BROWSER_KIND! in kiosk mode: !TARGET_URL! echo Launching !BROWSER_KIND! in kiosk mode: !TARGET_URL!
if /I "!BROWSER_KIND!"=="firefox" ( if /I "!BROWSER_KIND!"=="firefox" (
start "" "!BROWSER_PATH!" -kiosk "!TARGET_URL!" start "" "!BROWSER_PATH!" -no-remote -profile "!KIOSK_PROFILE!" -new-window -kiosk "!TARGET_URL!"
) else ( ) else (
start "" "!BROWSER_PATH!" --disable-notifications --kiosk "!TARGET_URL!" start "" "!BROWSER_PATH!" --disable-notifications --no-first-run --no-default-browser-check --new-window --kiosk --user-data-dir="!KIOSK_PROFILE!" "!TARGET_URL!"
) )
+5 -2
View File
@@ -35,13 +35,16 @@ else
exit 1 exit 1
fi fi
kiosk_profile="${XDG_DATA_HOME:-$HOME/.local/share}/pulse-signage/kiosk-browser-profile"
mkdir -p "$kiosk_profile"
echo "Launching ${browser_kind} in kiosk mode: ${target_url}" echo "Launching ${browser_kind} in kiosk mode: ${target_url}"
case "$browser_kind" in case "$browser_kind" in
firefox) firefox)
exec "$browser" -kiosk "$target_url" exec "$browser" -no-remote -profile "$kiosk_profile" -new-window -kiosk "$target_url"
;; ;;
edge|chrome) edge|chrome)
exec "$browser" --disable-notifications --kiosk "$target_url" exec "$browser" --disable-notifications --no-first-run --no-default-browser-check --new-window --kiosk --user-data-dir="$kiosk_profile" "$target_url"
;; ;;
esac esac
+37 -3
View File
@@ -7,21 +7,55 @@ const PASSWORD_KEY_LENGTH = 32;
const PASSWORD_DIGEST = 'sha256'; const PASSWORD_DIGEST = 'sha256';
const SESSION_BYTES = 32; const SESSION_BYTES = 32;
function validatePasswordStrength(password) { function validatePasswordStrength(password, options) {
const value = String(password || ''); const value = String(password || '');
const requirements = options && options.policy
? getPasswordPolicyPreset(options.policy)
: {
minimumLength: Number(options && options.minimumLength) || 10,
minimumCategories: Number(options && options.minimumCategories) || 3,
requireLowercase: Boolean(options && options.requireLowercase),
requireUppercase: Boolean(options && options.requireUppercase),
requireNumber: Boolean(options && options.requireNumber),
requireSymbol: Boolean(options && options.requireSymbol)
};
const hasLowercase = /[a-z]/.test(value); const hasLowercase = /[a-z]/.test(value);
const hasUppercase = /[A-Z]/.test(value); const hasUppercase = /[A-Z]/.test(value);
const hasNumber = /[0-9]/.test(value); const hasNumber = /[0-9]/.test(value);
const hasSymbol = /[^A-Za-z0-9]/.test(value); const hasSymbol = /[^A-Za-z0-9]/.test(value);
const categoryCount = [hasLowercase, hasUppercase, hasNumber, hasSymbol].filter(Boolean).length; const categoryCount = [hasLowercase, hasUppercase, hasNumber, hasSymbol].filter(Boolean).length;
if (value.length < 10 || categoryCount < 3) { const missingRequiredCategory = requirements.requireLowercase && !hasLowercase
return 'Password must be at least 10 characters and include 3 of: uppercase, lowercase, number, and symbol.'; || requirements.requireUppercase && !hasUppercase
|| requirements.requireNumber && !hasNumber
|| requirements.requireSymbol && !hasSymbol;
if (value.length < requirements.minimumLength || categoryCount < requirements.minimumCategories || missingRequiredCategory) {
if (missingRequiredCategory) {
const requiredCategories = [];
if (requirements.requireLowercase) requiredCategories.push('lowercase');
if (requirements.requireUppercase) requiredCategories.push('uppercase');
if (requirements.requireNumber) requiredCategories.push('number');
if (requirements.requireSymbol) requiredCategories.push('symbol');
return `Password must be at least ${requirements.minimumLength} characters and include ${requiredCategories.join(', ')}.`;
}
if (requirements.minimumCategories === 4) {
return `Password must be at least ${requirements.minimumLength} characters and include uppercase, lowercase, number, and symbol.`;
}
return `Password must be at least ${requirements.minimumLength} characters and include ${requirements.minimumCategories} of: uppercase, lowercase, number, and symbol.`;
} }
return ''; return '';
} }
function getPasswordPolicyPreset(policy) {
const normalizedPolicy = String(policy || 'standard').trim().toLowerCase();
return normalizedPolicy === 'strict'
? { minimumLength: 14, minimumCategories: 4 }
: normalizedPolicy === 'strong'
? { minimumLength: 12, minimumCategories: 3 }
: { minimumLength: 10, minimumCategories: 3 };
}
function hashPassword(password, salt) { function hashPassword(password, salt) {
const safePassword = String(password || ''); const safePassword = String(password || '');
const safeSalt = salt || crypto.randomBytes(16).toString('hex'); const safeSalt = salt || crypto.randomBytes(16).toString('hex');
+10 -2
View File
@@ -27,11 +27,14 @@ const dbBootstrap = require('#src/db/bootstrap');
const data = require('#src/data'); const data = require('#src/data');
const player = require('#src/player/render'); const player = require('#src/player/render');
const listQuery = require('#src/web/lib/list-query'); const listQuery = require('#src/web/lib/list-query');
const { fetchPlaylistCanvasId, fetchPlaylistCanvasSignature } = require('#src/web/lib/helpers'); const { fetchPlaylistCanvasId } = require('#src/web/lib/helpers');
const { findAvailableClientName } = require('#src/data/client-name-check');
module.exports = { module.exports = {
createPool: dbCommon.createPool, createPool: dbCommon.createPool,
pruneStaleOnboardingDevices: dbCommon.pruneStaleOnboardingDevices, pruneStaleOnboardingDevices: dbCommon.pruneStaleOnboardingDevices,
touchOnboardingDeviceLastSeen: dbCommon.touchOnboardingDeviceLastSeen,
findAvailableClientName: findAvailableClientName,
ensureSchema: db.ensureSchema, ensureSchema: db.ensureSchema,
bootstrapDatabase: dbBootstrap.bootstrapDatabase, bootstrapDatabase: dbBootstrap.bootstrapDatabase,
slugify: data.slugify, slugify: data.slugify,
@@ -63,7 +66,6 @@ module.exports = {
getSortDirectionQuery: listQuery.getSortDirectionQuery, getSortDirectionQuery: listQuery.getSortDirectionQuery,
fetchPlaylistById: data.fetchPlaylistById, fetchPlaylistById: data.fetchPlaylistById,
fetchPlaylistCanvasId: fetchPlaylistCanvasId, fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasSignature,
normalizeDisplayMode: data.normalizeDisplayMode, normalizeDisplayMode: data.normalizeDisplayMode,
fetchTimetablesData: data.fetchTimetablesData, fetchTimetablesData: data.fetchTimetablesData,
fetchTimetableGroupsPage: data.fetchTimetableGroupsPage, fetchTimetableGroupsPage: data.fetchTimetableGroupsPage,
@@ -83,6 +85,12 @@ module.exports = {
buildRssFeedPayload: data.buildRssFeedPayload, buildRssFeedPayload: data.buildRssFeedPayload,
fetchRssFeedItems: data.fetchRssFeedItems, fetchRssFeedItems: data.fetchRssFeedItems,
replaceRssFeedItems: data.replaceRssFeedItems, replaceRssFeedItems: data.replaceRssFeedItems,
fetchWeatherLocationsData: data.fetchWeatherLocationsData,
fetchWeatherLocationsPage: data.fetchWeatherLocationsPage,
fetchWeatherLocationById: data.fetchWeatherLocationById,
fetchWeatherLocationSuggestions: data.fetchWeatherLocationSuggestions,
fetchWeatherLocationForecast: data.fetchWeatherLocationForecast,
buildWeatherLocationPayload: data.buildWeatherLocationPayload,
fetchScreenById: data.fetchScreenById, fetchScreenById: data.fetchScreenById,
fetchScreenEditData: data.fetchScreenEditData, fetchScreenEditData: data.fetchScreenEditData,
fetchScreenPlayerUrls: data.fetchScreenPlayerUrls, fetchScreenPlayerUrls: data.fetchScreenPlayerUrls,
+2 -2
View File
@@ -6,7 +6,7 @@ async function fetchAdminData(pool) {
const [playlists] = await pool.query('SELECT id, name, fade_between_slides, skip_unavailable_rtmp, created_at, modified_at, created_by, modified_by FROM c_playlists ORDER BY id DESC'); const [playlists] = await pool.query('SELECT id, name, fade_between_slides, skip_unavailable_rtmp, created_at, modified_at, created_by, modified_by FROM c_playlists ORDER BY id DESC');
const [canvasSizes] = await pool.query('SELECT id, name, width, height, created_at, modified_at, created_by, modified_by FROM c_canvas_sizes ORDER BY width ASC, height ASC, name ASC'); const [canvasSizes] = await pool.query('SELECT id, name, width, height, created_at, modified_at, created_by, modified_by FROM c_canvas_sizes ORDER BY width ASC, height ASC, name ASC');
const [templates] = await pool.query(` const [templates] = await pool.query(`
SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.created_at, st.modified_at, SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.background_gradient, st.created_at, st.modified_at,
cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height
FROM c_templates st FROM c_templates st
LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id
@@ -112,7 +112,7 @@ async function fetchSlidesPage(pool, page, pageSize, searchTerm, sortKey, sortDi
async function fetchTemplatesPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) { async function fetchTemplatesPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, { const paged = await fetchPagedRows(pool, {
selectSql: `SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.created_at, st.modified_at, selectSql: `SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.background_gradient, st.created_at, st.modified_at,
cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height, cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height,
(SELECT COUNT(*) FROM c_template_regions str WHERE str.template_id = st.id) AS region_count, (SELECT COUNT(*) FROM c_template_regions str WHERE str.template_id = st.id) AS region_count,
(SELECT COUNT(*) FROM c_slides s WHERE s.template_id = st.id) AS slide_count (SELECT COUNT(*) FROM c_slides s WHERE s.template_id = st.id) AS slide_count
+77 -51
View File
@@ -1,55 +1,71 @@
const ANNOUNCEMENT_ICON_OPTIONS = [ // Load and expose the announcement icon catalog used by the editor and player.
{ value: 'megaphone-fill', label: 'Megaphone' },
{ value: 'megaphone', label: 'Megaphone outline' }, const fs = require('fs');
{ value: 'bell-fill', label: 'Bell' }, const path = require('path');
{ value: 'bell', label: 'Bell outline' },
{ value: 'exclamation-triangle-fill', label: 'Warning' }, const BOOTSTRAP_ICON_CSS_PATH = path.join(__dirname, '..', 'web', 'public', 'adminlte', 'bootstrap-icons', 'css', 'bootstrap-icons.min.css');
{ value: 'exclamation-triangle', label: 'Warning outline' },
{ value: 'info-circle-fill', label: 'Info' }, const DEFAULT_ANNOUNCEMENT_ICON_KEYS = [
{ value: 'info-circle', label: 'Info outline' }, 'megaphone-fill', 'megaphone', 'bell-fill', 'bell',
{ value: 'check-circle-fill', label: 'Success' }, 'exclamation-triangle-fill', 'exclamation-triangle', 'info-circle-fill', 'info-circle',
{ value: 'check-circle', label: 'Success outline' }, 'check-circle-fill', 'check-circle', 'lightbulb-fill', 'lightbulb',
{ value: 'lightbulb-fill', label: 'Idea' }, 'calendar-event-fill', 'calendar-event', 'clock-fill', 'clock',
{ value: 'lightbulb', label: 'Idea outline' }, 'wifi-off', 'wifi', 'hdd-network', 'hdd-network-fill',
{ value: 'calendar-event-fill', label: 'Calendar' }, 'speaker-fill', 'speaker', 'shield-fill', 'shield',
{ value: 'calendar-event', label: 'Calendar outline' }, 'collection-play-fill', 'collection-play', 'broadcast', 'broadcast-pin',
{ value: 'clock-fill', label: 'Clock' }, 'plug-fill', 'plug', 'lightning-charge-fill', 'lightning-charge',
{ value: 'clock', label: 'Clock outline' }, 'car-front-fill', 'car-front', 'lamp-fill', 'lamp',
{ value: 'wifi-off', label: 'Wi-Fi Offline' }, 'envelope-fill', 'envelope', 'people-fill', 'people',
{ value: 'wifi', label: 'Wi-Fi' }, 'browser-chrome', 'browser-edge', 'browser-firefox', 'browser-safari',
{ value: 'hdd-network', label: 'Network' }, 'cone', 'cone-striped', 'cup-straw', 'fire'
{ value: 'hdd-network-fill', label: 'Network fill' },
{ value: 'speaker-fill', label: 'Speaker' },
{ value: 'speaker', label: 'Speaker outline' },
{ value: 'shield-fill', label: 'Shield' },
{ value: 'shield', label: 'Shield outline' },
{ value: 'collection-play-fill', label: 'Playlist' },
{ value: 'collection-play', label: 'Playlist outline' },
{ value: 'broadcast', label: 'Broadcast' },
{ value: 'broadcast-pin', label: 'Broadcast pin' },
{ value: 'plug-fill', label: 'Plug' },
{ value: 'plug', label: 'Plug outline' },
{ value: 'lightning-charge-fill', label: 'Urgent' },
{ value: 'lightning-charge', label: 'Urgent outline' },
{ value: 'car-front-fill', label: 'Car Front' },
{ value: 'car-front', label: 'Car Front outline' },
{ value: 'lamp-fill', label: 'Lamp' },
{ value: 'lamp', label: 'Lamp outline' },
{ value: 'envelope-fill', label: 'Message' },
{ value: 'envelope', label: 'Message outline' },
{ value: 'people-fill', label: 'Audience' },
{ value: 'people', label: 'Audience outline' },
{ value: 'browser-chrome', label: 'Browser Chrome' },
{ value: 'browser-edge', label: 'Browser Edge' },
{ value: 'browser-firefox', label: 'Browser Firefox' },
{ value: 'browser-safari', label: 'Browser Safari' },
{ value: 'cone', label: 'Cone' },
{ value: 'cone-striped', label: 'Cone striped' },
{ value: 'cup-straw', label: 'Cup straw' },
{ value: 'fire', label: 'Fire' }
]; ];
const ANNOUNCEMENT_ICON_KEYS = ANNOUNCEMENT_ICON_OPTIONS.map(function (option) { function humanizeBootstrapIconLabel(iconKey) {
return String(iconKey || '')
.trim()
.replace(/[-_]+/g, ' ')
.replace(/\b\w/g, function (character) {
return character.toUpperCase();
});
}
function loadBootstrapIconCatalog() {
try {
const css = fs.readFileSync(BOOTSTRAP_ICON_CSS_PATH, 'utf8');
const keys = Array.from(new Set((css.match(/\.bi-([a-z0-9-]+)::?before/g) || []).map(function (match) {
return String(match || '')
.replace(/^\.bi-/, '')
.replace(/::?before$/, '')
.trim()
.toLowerCase();
}).filter(Boolean)));
return keys.map(function (value) {
return {
value: value,
label: humanizeBootstrapIconLabel(value)
};
}).sort(function (left, right) {
return left.value.localeCompare(right.value);
});
} catch (_error) {
return DEFAULT_ANNOUNCEMENT_ICON_KEYS.map(function (value) {
return { value: value, label: humanizeBootstrapIconLabel(value) };
});
}
}
const ANNOUNCEMENT_ICON_CATALOG = loadBootstrapIconCatalog();
const ANNOUNCEMENT_ICON_OPTIONS = DEFAULT_ANNOUNCEMENT_ICON_KEYS.map(function (value) {
const catalogOption = ANNOUNCEMENT_ICON_CATALOG.find(function (option) {
return option.value === value;
});
return catalogOption || { value: value, label: humanizeBootstrapIconLabel(value) };
});
const ANNOUNCEMENT_ICON_KEYS = DEFAULT_ANNOUNCEMENT_ICON_KEYS.slice();
const ANNOUNCEMENT_ICON_CATALOG_KEYS = ANNOUNCEMENT_ICON_CATALOG.map(function (option) {
return option.value; return option.value;
}); });
@@ -58,17 +74,27 @@ const ANNOUNCEMENT_ICON_LABELS = ANNOUNCEMENT_ICON_OPTIONS.reduce(function (labe
return labels; return labels;
}, Object.create(null)); }, Object.create(null));
ANNOUNCEMENT_ICON_CATALOG.forEach(function (option) {
if (!Object.prototype.hasOwnProperty.call(ANNOUNCEMENT_ICON_LABELS, option.value)) {
ANNOUNCEMENT_ICON_LABELS[option.value] = option.label;
}
});
const DEFAULT_ANNOUNCEMENT_ICON = 'megaphone-fill'; const DEFAULT_ANNOUNCEMENT_ICON = 'megaphone-fill';
function normalizeAnnouncementIcon(value) { function normalizeAnnouncementIcon(value) {
const normalized = String(value || '').trim().toLowerCase(); const normalized = String(value || '').trim().toLowerCase();
return ANNOUNCEMENT_ICON_KEYS.includes(normalized) ? normalized : DEFAULT_ANNOUNCEMENT_ICON; return ANNOUNCEMENT_ICON_CATALOG_KEYS.includes(normalized) ? normalized : DEFAULT_ANNOUNCEMENT_ICON;
} }
module.exports = { module.exports = {
DEFAULT_ANNOUNCEMENT_ICON_KEYS,
ANNOUNCEMENT_ICON_OPTIONS, ANNOUNCEMENT_ICON_OPTIONS,
ANNOUNCEMENT_ICON_KEYS, ANNOUNCEMENT_ICON_KEYS,
ANNOUNCEMENT_ICON_CATALOG,
ANNOUNCEMENT_ICON_CATALOG_KEYS,
ANNOUNCEMENT_ICON_LABELS, ANNOUNCEMENT_ICON_LABELS,
DEFAULT_ANNOUNCEMENT_ICON, DEFAULT_ANNOUNCEMENT_ICON,
humanizeBootstrapIconLabel,
normalizeAnnouncementIcon normalizeAnnouncementIcon
}; };
+5 -1
View File
@@ -11,7 +11,11 @@ const { validateMaxLength } = require('./utils');
const SHORT_LABEL_MAX_LENGTH = 255; const SHORT_LABEL_MAX_LENGTH = 255;
const ANNOUNCEMENT_TYPES = ['lower-third', 'fullscreen', 'top-banner']; const ANNOUNCEMENT_TYPES = ['lower-third', 'fullscreen', 'top-banner'];
const ANNOUNCEMENT_COLORS = ['primary', 'secondary', 'success', 'info', 'warning', 'danger', 'dark', 'light']; const ANNOUNCEMENT_COLORS = [
'primary', 'secondary', 'success', 'info', 'warning', 'danger', 'dark', 'light',
'orange', 'amber', 'olive', 'teal', 'sky', 'indigo', 'violet', 'fuchsia', 'pink',
'navy', 'steel', 'slate', 'graphite', 'midnight'
];
function normalizeAnnouncementType(value) { function normalizeAnnouncementType(value) {
const normalized = String(value || '').trim().toLowerCase(); const normalized = String(value || '').trim().toLowerCase();
+183 -22
View File
@@ -8,19 +8,27 @@ const NAME_MAX_LENGTH = 255;
const URL_MAX_LENGTH = 1024; const URL_MAX_LENGTH = 1024;
const AUTH_MAX_LENGTH = 255; const AUTH_MAX_LENGTH = 255;
const ITEMS_PATH_MAX_LENGTH = 255; const ITEMS_PATH_MAX_LENGTH = 255;
const REQUEST_BODY_MAX_LENGTH = 1000000;
const TOKEN_URL_MAX_LENGTH = 1024;
const TOKEN_RESPONSE_PATH_MAX_LENGTH = 255;
const TOKEN_HEADER_PREFIX_MAX_LENGTH = 64;
const tokenCache = new Map();
function normalizeUpdateIntervalUnit(value) { function normalizeUpdateIntervalUnit(value) {
const unit = String(value || '').trim().toLowerCase(); const unit = String(value || '').trim().toLowerCase();
return unit === 'seconds' ? 'seconds' : 'minutes'; if (unit === 'seconds' || unit === 'minutes' || unit === 'hours') {
return unit;
}
return 'minutes';
} }
function normalizeAuthMethod(value) { function normalizeAuthMethod(value) {
const method = String(value || '').trim().toLowerCase(); const method = String(value || '').trim().toLowerCase();
return ['basic', 'bearer', 'api_key_header'].includes(method) ? method : 'none'; return ['basic', 'bearer', 'api_key_header', 'token_login'].includes(method) ? method : 'none';
} }
function getItemsPath(source) { function normalizeRequestMethod(value) {
return String(source && (source.items_path || source.itemsPath) || '').trim(); return String(value || '').trim().toUpperCase() === 'POST' ? 'POST' : 'GET';
} }
function buildAuthHeaders(source) { function buildAuthHeaders(source) {
@@ -51,7 +59,7 @@ function buildAuthHeaders(source) {
async function fetchApiSourcesData(pool) { async function fetchApiSourcesData(pool) {
const [apiSources] = await pool.query( const [apiSources] = await pool.query(
'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC' 'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC'
); );
return { apiSources: apiSources }; return { apiSources: apiSources };
@@ -59,7 +67,7 @@ async function fetchApiSourcesData(pool) {
async function fetchApiSourcesPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) { async function fetchApiSourcesPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, { const paged = await fetchPagedRows(pool, {
selectSql: 'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC', selectSql: 'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources ORDER BY modified_at DESC, id DESC',
countSql: 'SELECT COUNT(*) AS count FROM i_api_sources', countSql: 'SELECT COUNT(*) AS count FROM i_api_sources',
searchColumns: ['name', 'api_url', 'last_pull_error'], searchColumns: ['name', 'api_url', 'last_pull_error'],
searchTerm: searchTerm, searchTerm: searchTerm,
@@ -83,7 +91,7 @@ async function fetchApiSourcesPage(pool, page, pageSize, searchTerm, sortKey, so
async function fetchApiSourceById(pool, id) { async function fetchApiSourceById(pool, id) {
const [rows] = await pool.query( const [rows] = await pool.query(
'SELECT id, name, api_url, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, items_path, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources WHERE id = ?', 'SELECT id, name, api_url, request_method, request_body_json, auth_method, auth_username, auth_password, auth_bearer_token, auth_header_name, auth_header_value, token_url, token_request_body_json, token_response_path, token_header_name, token_header_prefix, items_path, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_status, last_response_content_type, last_response_json, created_at, modified_at, created_by, modified_by FROM i_api_sources WHERE id = ?',
[id] [id]
); );
@@ -92,13 +100,18 @@ async function fetchApiSourceById(pool, id) {
async function loadUrlText(urlValue, requestOptions) { async function loadUrlText(urlValue, requestOptions) {
const extraHeaders = requestOptions && requestOptions.headers ? requestOptions.headers : {}; const extraHeaders = requestOptions && requestOptions.headers ? requestOptions.headers : {};
const method = String(requestOptions && requestOptions.method || 'GET').toUpperCase();
const body = requestOptions && requestOptions.body !== undefined ? requestOptions.body : undefined;
const headers = Object.assign({
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8',
'User-Agent': 'Pulse Signage API Reader'
}, extraHeaders);
if (typeof fetch === 'function') { if (typeof fetch === 'function') {
const response = await fetch(urlValue, { const fetchOptions = { method: method, headers: headers };
headers: Object.assign({ if (body !== undefined && method !== 'GET' && method !== 'HEAD') {
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8', fetchOptions.body = body;
'User-Agent': 'Pulse Signage API Reader' }
}, extraHeaders) const response = await fetch(urlValue, fetchOptions);
});
return { return {
statusCode: response.status, statusCode: response.status,
@@ -111,12 +124,9 @@ async function loadUrlText(urlValue, requestOptions) {
return await new Promise(function (resolve, reject) { return await new Promise(function (resolve, reject) {
const url = new URL(urlValue); const url = new URL(urlValue);
const transport = url.protocol === 'https:' ? https : http; const transport = url.protocol === 'https:' ? https : http;
const requestHeaders = Object.assign({ const request = transport.request(url, Object.assign({}, requestOptions || {}, {
Accept: 'application/json, text/plain;q=0.9, */*;q=0.8', method: method,
'User-Agent': 'Pulse Signage API Reader' headers: headers
}, extraHeaders);
const request = transport.get(url, Object.assign({}, requestOptions || {}, {
headers: requestHeaders
}), function (response) { }), function (response) {
response.setEncoding('utf8'); response.setEncoding('utf8');
let body = ''; let body = '';
@@ -134,15 +144,126 @@ async function loadUrlText(urlValue, requestOptions) {
response.on('error', reject); response.on('error', reject);
}); });
if (body !== undefined && method !== 'GET' && method !== 'HEAD') {
request.write(body);
}
request.end();
request.on('error', reject); request.on('error', reject);
}); });
} }
function parseJsonRequestBody(value, fieldName) {
const text = String(value || '').trim();
if (!text) {
return undefined;
}
try {
return JSON.parse(text);
} catch (_error) {
const error = new Error(fieldName + ' must contain valid JSON.');
error.statusCode = 400;
throw error;
}
}
function resolveResponsePath(value, responsePath) {
let current = value;
String(responsePath || '').split('.').forEach(function (segment) {
if (current === undefined || current === null) {
current = undefined;
return;
}
current = current[segment];
});
return current;
}
function getTokenCacheKey(source) {
return JSON.stringify([
source && source.id || '',
source && (source.token_url || source.tokenUrl) || '',
source && (source.token_request_body_json || source.tokenRequestBodyJson) || '',
source && (source.token_response_path || source.tokenResponsePath) || 'access_token',
source && (source.token_header_name || source.tokenHeaderName) || 'Authorization',
source && (source.token_header_prefix || source.tokenHeaderPrefix) || 'Bearer'
]);
}
function clearCachedToken(source) {
tokenCache.delete(getTokenCacheKey(source));
}
async function fetchLoginToken(source) {
const cacheKey = getTokenCacheKey(source);
const cached = tokenCache.get(cacheKey);
if (cached && cached.expiresAt > Date.now()) {
return cached.value;
}
const tokenUrl = source.token_url || source.tokenUrl;
const tokenBody = parseJsonRequestBody(source.token_request_body_json || source.tokenRequestBodyJson, 'Login request body');
const tokenHeaders = { 'Content-Type': 'application/json' };
const response = await loadUrlText(tokenUrl, {
method: 'POST',
headers: tokenHeaders,
body: tokenBody === undefined ? undefined : JSON.stringify(tokenBody)
});
if (!response.ok) {
throw new Error(`Unable to obtain API token (${response.statusCode}).`);
}
let parsed;
try {
parsed = JSON.parse(String(response.bodyText || '').trim());
} catch (_error) {
throw new Error('Token response was not valid JSON.');
}
const tokenPath = source.token_response_path || source.tokenResponsePath || 'access_token';
const token = resolveResponsePath(parsed, tokenPath);
if (token === undefined || token === null || String(token).trim() === '') {
throw new Error('Token response did not contain a token at the configured path.');
}
const expiresIn = Number(parsed && (parsed.expires_in || parsed.expiresIn));
const lifetimeMs = Number.isFinite(expiresIn) && expiresIn > 0
? Math.max(30000, expiresIn * 1000 - 60000)
: 300000;
tokenCache.set(cacheKey, { value: String(token), expiresAt: Date.now() + lifetimeMs });
return String(token);
}
async function buildRequestHeaders(source) {
const method = normalizeAuthMethod(source && (source.auth_method || source.authMethod));
if (method !== 'token_login') {
return buildAuthHeaders(source);
}
const token = await fetchLoginToken(source);
const headerName = String(source.token_header_name || source.tokenHeaderName || 'Authorization').trim() || 'Authorization';
const prefix = String(source.token_header_prefix || source.tokenHeaderPrefix || 'Bearer').trim();
return { [headerName]: prefix ? prefix + ' ' + token : token };
}
async function fetchApiSourceResponse(apiSource) { async function fetchApiSourceResponse(apiSource) {
const source = apiSource && typeof apiSource === 'object' ? apiSource : { api_url: apiSource }; const source = apiSource && typeof apiSource === 'object' ? apiSource : { api_url: apiSource };
const response = await loadUrlText(source.api_url, { const requestMethod = normalizeRequestMethod(source.request_method || source.requestMethod);
headers: buildAuthHeaders(source) const requestBody = parseJsonRequestBody(source.request_body_json || source.requestBodyJson, 'API request body');
}); let response;
let tokenRetry = false;
do {
response = await loadUrlText(source.api_url || source.apiUrl, {
method: requestMethod,
headers: Object.assign({}, await buildRequestHeaders(source), requestBody === undefined ? {} : { 'Content-Type': 'application/json' }),
body: requestBody === undefined ? undefined : JSON.stringify(requestBody)
});
if (response.statusCode === 401 && normalizeAuthMethod(source.auth_method || source.authMethod) === 'token_login' && !tokenRetry) {
clearCachedToken(source);
tokenRetry = true;
} else {
break;
}
} while (true);
if (!response.ok) { if (!response.ok) {
throw new Error(`Unable to load API response (${response.statusCode}).`); throw new Error(`Unable to load API response (${response.statusCode}).`);
} }
@@ -179,11 +300,18 @@ function buildApiSourcePayload(req, existingApiSource) {
const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'API source name'); const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'API source name');
const apiUrl = validateMaxLength(req.body.api_url || req.body.apiUrl || fallback.api_url || '', URL_MAX_LENGTH, 'API source URL'); const apiUrl = validateMaxLength(req.body.api_url || req.body.apiUrl || fallback.api_url || '', URL_MAX_LENGTH, 'API source URL');
const authMethod = normalizeAuthMethod(readBodyValue('auth_method', readBodyValue('authMethod', fallback.auth_method || 'none'))); const authMethod = normalizeAuthMethod(readBodyValue('auth_method', readBodyValue('authMethod', fallback.auth_method || 'none')));
const requestMethod = normalizeRequestMethod(readBodyValue('request_method', readBodyValue('requestMethod', fallback.request_method || 'GET')));
const requestBodyJson = validateMaxLength(readBodyValue('request_body_json', readBodyValue('requestBodyJson', fallback.request_body_json || '')) || '', REQUEST_BODY_MAX_LENGTH, 'API request body');
const authUsername = validateMaxLength(readBodyValue('auth_username', readBodyValue('authUsername', fallback.auth_username || '')) || '', AUTH_MAX_LENGTH, 'API source username'); const authUsername = validateMaxLength(readBodyValue('auth_username', readBodyValue('authUsername', fallback.auth_username || '')) || '', AUTH_MAX_LENGTH, 'API source username');
const authPassword = validateMaxLength(readBodyValue('auth_password', readBodyValue('authPassword', fallback.auth_password || '')) || '', AUTH_MAX_LENGTH, 'API source password'); const authPassword = validateMaxLength(readBodyValue('auth_password', readBodyValue('authPassword', fallback.auth_password || '')) || '', AUTH_MAX_LENGTH, 'API source password');
const authBearerToken = validateMaxLength(readBodyValue('auth_bearer_token', readBodyValue('authBearerToken', fallback.auth_bearer_token || '')) || '', AUTH_MAX_LENGTH, 'API source bearer token'); const authBearerToken = validateMaxLength(readBodyValue('auth_bearer_token', readBodyValue('authBearerToken', fallback.auth_bearer_token || '')) || '', AUTH_MAX_LENGTH, 'API source bearer token');
const authHeaderName = validateMaxLength(readBodyValue('auth_header_name', readBodyValue('authHeaderName', fallback.auth_header_name || 'X-API-Key')) || 'X-API-Key', AUTH_MAX_LENGTH, 'API source header name') || 'X-API-Key'; const authHeaderName = validateMaxLength(readBodyValue('auth_header_name', readBodyValue('authHeaderName', fallback.auth_header_name || 'X-API-Key')) || 'X-API-Key', AUTH_MAX_LENGTH, 'API source header name') || 'X-API-Key';
const authHeaderValue = validateMaxLength(readBodyValue('auth_header_value', readBodyValue('authHeaderValue', fallback.auth_header_value || '')) || '', AUTH_MAX_LENGTH, 'API source header value'); const authHeaderValue = validateMaxLength(readBodyValue('auth_header_value', readBodyValue('authHeaderValue', fallback.auth_header_value || '')) || '', AUTH_MAX_LENGTH, 'API source header value');
const tokenUrl = validateMaxLength(readBodyValue('token_url', readBodyValue('tokenUrl', fallback.token_url || '')) || '', TOKEN_URL_MAX_LENGTH, 'API token URL');
const tokenRequestBodyJson = validateMaxLength(readBodyValue('token_request_body_json', readBodyValue('tokenRequestBodyJson', fallback.token_request_body_json || '')) || '', REQUEST_BODY_MAX_LENGTH, 'Login request body');
const tokenResponsePath = validateMaxLength(readBodyValue('token_response_path', readBodyValue('tokenResponsePath', fallback.token_response_path || 'access_token')) || 'access_token', TOKEN_RESPONSE_PATH_MAX_LENGTH, 'Token response path');
const tokenHeaderName = validateMaxLength(readBodyValue('token_header_name', readBodyValue('tokenHeaderName', fallback.token_header_name || 'Authorization')) || 'Authorization', AUTH_MAX_LENGTH, 'Token header name');
const tokenHeaderPrefix = validateMaxLength(readBodyValue('token_header_prefix', readBodyValue('tokenHeaderPrefix', fallback.token_header_prefix || 'Bearer')) || '', TOKEN_HEADER_PREFIX_MAX_LENGTH, 'Token prefix');
const itemsPath = validateMaxLength(readBodyValue('items_path', readBodyValue('itemsPath', fallback.items_path || '')) || '', ITEMS_PATH_MAX_LENGTH, 'API source items path'); const itemsPath = validateMaxLength(readBodyValue('items_path', readBodyValue('itemsPath', fallback.items_path || '')) || '', ITEMS_PATH_MAX_LENGTH, 'API source items path');
const updateIntervalValue = Math.max(1, Number(req.body.update_interval_value || req.body.updateIntervalValue || fallback.update_interval_value || 60)); const updateIntervalValue = Math.max(1, Number(req.body.update_interval_value || req.body.updateIntervalValue || fallback.update_interval_value || 60));
const updateIntervalUnit = normalizeUpdateIntervalUnit(req.body.update_interval_unit || req.body.updateIntervalUnit || fallback.update_interval_unit || 'minutes'); const updateIntervalUnit = normalizeUpdateIntervalUnit(req.body.update_interval_unit || req.body.updateIntervalUnit || fallback.update_interval_unit || 'minutes');
@@ -239,15 +367,48 @@ function buildApiSourcePayload(req, existingApiSource) {
throw error; throw error;
} }
parseJsonRequestBody(requestBodyJson, 'API request body');
parseJsonRequestBody(tokenRequestBodyJson, 'Login request body');
if (authMethod === 'token_login') {
if (!tokenUrl) {
const error = new Error('Token login requires a login URL.');
error.statusCode = 400;
throw error;
}
try {
const tokenParsedUrl = new URL(tokenUrl);
if (tokenParsedUrl.protocol !== 'http:' && tokenParsedUrl.protocol !== 'https:') {
throw new Error('invalid protocol');
}
} catch (_error) {
const error = new Error('Enter a valid API token URL.');
error.statusCode = 400;
throw error;
}
if (!tokenRequestBodyJson) {
const error = new Error('Token login requires a JSON request body.');
error.statusCode = 400;
throw error;
}
}
return { return {
name: name, name: name,
apiUrl: parsedUrl.toString(), apiUrl: parsedUrl.toString(),
requestMethod: requestMethod,
requestBodyJson: requestBodyJson,
authMethod: authMethod, authMethod: authMethod,
authUsername: authUsername, authUsername: authUsername,
authPassword: authPassword, authPassword: authPassword,
authBearerToken: authBearerToken, authBearerToken: authBearerToken,
authHeaderName: authHeaderName, authHeaderName: authHeaderName,
authHeaderValue: authHeaderValue, authHeaderValue: authHeaderValue,
tokenUrl: tokenUrl,
tokenRequestBodyJson: tokenRequestBodyJson,
tokenResponsePath: tokenResponsePath,
tokenHeaderName: tokenHeaderName,
tokenHeaderPrefix: tokenHeaderPrefix,
itemsPath: itemsPath, itemsPath: itemsPath,
updateIntervalValue: Math.floor(updateIntervalValue), updateIntervalValue: Math.floor(updateIntervalValue),
updateIntervalUnit: updateIntervalUnit updateIntervalUnit: updateIntervalUnit
+211
View File
@@ -0,0 +1,211 @@
// Application-wide settings defaults and persistence helpers.
const { DEFAULT_ANNOUNCEMENT_ICON_KEYS } = require('./announcement-icons');
const SETTING_DEFINITIONS = [
{ key: 'app.name', type: 'string', defaultValue: 'Pulse Signage' },
{ key: 'locale.timezone', type: 'string', defaultValue: 'Europe/London' },
{ key: 'locale.language', type: 'string', defaultValue: 'en' },
{ key: 'ui.theme', type: 'enum', values: ['dark', 'light', 'auto'], defaultValue: 'dark' },
{ key: 'security.session_lifetime_days', type: 'integer', min: 1, defaultValue: 14 },
{ key: 'security.allow_user_session_revocation', type: 'boolean', defaultValue: true },
{ key: 'security.max_active_sessions', type: 'integer', min: 0, defaultValue: 0 },
{ key: 'security.password_min_length', type: 'integer', min: 8, defaultValue: 10 },
{ key: 'security.password_min_categories', type: 'integer', min: 1, defaultValue: 3 },
{ key: 'security.password_require_lowercase', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_uppercase', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_number', type: 'boolean', defaultValue: false },
{ key: 'security.password_require_symbol', type: 'boolean', defaultValue: false },
{ key: 'security.require_password_change_for_new_users', type: 'boolean', defaultValue: true },
{ key: 'security.require_password_change_after_admin_reset', type: 'boolean', defaultValue: true },
{ key: 'security.login_max_attempts', type: 'integer', min: 1, defaultValue: 5 },
{ key: 'security.login_lockout_minutes', type: 'integer', min: 1, defaultValue: 15 },
{ key: 'security.login_rate_limit_scope', type: 'enum', values: ['both', 'username', 'ip'], defaultValue: 'both' },
{ key: 'audit.enabled', type: 'boolean', defaultValue: true },
{ key: 'audit.categories', type: 'string_array', defaultValue: ['authentication', 'security', 'sessions', 'users', 'roles', 'system-settings'] },
{ key: 'audit.include_request_metadata', type: 'boolean', defaultValue: true },
{ key: 'audit.retention_days', type: 'integer', min: 0, defaultValue: 180 },
{ key: 'uploads.image_max_bytes', type: 'integer', min: 1, defaultValue: 100 * 1024 * 1024 },
{ key: 'uploads.video_max_bytes', type: 'integer', min: 1, defaultValue: 1024 * 1024 * 1024 },
{ key: 'uploads.wysiwyg_image_max_bytes', type: 'integer', min: 1, defaultValue: 2 * 1024 * 1024 },
{ key: 'uploads.allowed_mime_types', type: 'string_array', defaultValue: ['image/png', 'image/jpeg', 'image/gif', 'image/webp', 'image/svg+xml', 'video/mp4', 'video/webm', 'video/ogg'] },
{ key: 'uploads.cleanup_days', type: 'integer', min: 0, defaultValue: 30 },
{ key: 'uploads.optimize_images', type: 'boolean', defaultValue: true },
{ key: 'announcements.default_icon', type: 'string', defaultValue: 'megaphone-fill' },
{ key: 'announcements.default_duration_value', type: 'integer', min: 1, defaultValue: 10 },
{ key: 'announcements.default_duration_unit', type: 'enum', values: ['seconds', 'minutes'], defaultValue: 'seconds' },
{ key: 'announcements.suggested_icons', type: 'string_array', defaultValue: DEFAULT_ANNOUNCEMENT_ICON_KEYS.slice() },
{ key: 'player.default_slide_duration_seconds', type: 'integer', min: 1, defaultValue: 10 },
{ key: 'player.default_fade_between_slides', type: 'boolean', defaultValue: true },
{ key: 'player.skip_unavailable_rtmp', type: 'boolean', defaultValue: true },
{ key: 'data-sources.rss_default_interval_value', type: 'integer', min: 1, defaultValue: 60 },
{ key: 'data-sources.rss_default_interval_unit', type: 'enum', values: ['seconds', 'minutes', 'hours'], defaultValue: 'minutes' },
{ key: 'data-sources.api_default_interval_value', type: 'integer', min: 1, defaultValue: 60 },
{ key: 'data-sources.api_default_interval_unit', type: 'enum', values: ['seconds', 'minutes', 'hours'], defaultValue: 'minutes' },
{ key: 'weather.open_meteo_api_key', type: 'string', defaultValue: '' },
{ key: 'weather.pirate_weather_api_key', type: 'string', defaultValue: '' }
];
const DEFINITIONS_BY_KEY = new Map(SETTING_DEFINITIONS.map(function (definition) {
return [definition.key, definition];
}));
function cloneValue(value) {
if (Array.isArray(value)) {
return value.slice();
}
return value;
}
function getAppSettingDefinitions() {
return SETTING_DEFINITIONS.map(function (definition) {
return Object.assign({}, definition, {
values: definition.values ? definition.values.slice() : undefined,
defaultValue: cloneValue(definition.defaultValue)
});
});
}
function getDefaultAppSettings() {
return SETTING_DEFINITIONS.reduce(function (settings, definition) {
settings[definition.key] = cloneValue(definition.defaultValue);
return settings;
}, {});
}
function normalizeSettingValue(key, value) {
const definition = DEFINITIONS_BY_KEY.get(String(key || '').trim());
if (!definition) {
throw new Error('Unknown application setting: ' + key);
}
if (definition.type === 'string') {
return String(value == null ? '' : value).trim();
}
if (definition.type === 'integer') {
const normalized = Number(value);
if (!Number.isInteger(normalized) || normalized < definition.min) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return normalized;
}
if (definition.type === 'boolean') {
if (value === true || value === 1 || value === '1' || value === 'true') {
return true;
}
if (value === false || value === 0 || value === '0' || value === 'false') {
return false;
}
throw new Error('Invalid value for application setting: ' + definition.key);
}
if (definition.type === 'enum') {
const normalized = String(value == null ? '' : value).trim();
if (!definition.values.includes(normalized)) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return normalized;
}
if (definition.type === 'string_array') {
if (!Array.isArray(value)) {
throw new Error('Invalid value for application setting: ' + definition.key);
}
return Array.from(new Set(value.map(function (item) {
return String(item || '').trim();
}).filter(Boolean)));
}
throw new Error('Unsupported application setting type: ' + definition.type);
}
function normalizeAppSettings(settings) {
const input = settings && typeof settings === 'object' ? settings : {};
return SETTING_DEFINITIONS.reduce(function (normalized, definition) {
const value = Object.prototype.hasOwnProperty.call(input, definition.key)
? input[definition.key]
: definition.defaultValue;
normalized[definition.key] = normalizeSettingValue(definition.key, value);
return normalized;
}, {});
}
function parseStoredValue(value) {
if (typeof value !== 'string') {
return value;
}
try {
return JSON.parse(value);
} catch (_error) {
return value;
}
}
async function fetchAppSettings(pool) {
const [rows] = await pool.query('SELECT id, setting_key, setting_value FROM o_app_settings ORDER BY setting_key');
const storedSettings = {};
(rows || []).forEach(function (row) {
const key = String(row && row.setting_key || '').trim();
if (DEFINITIONS_BY_KEY.has(key)) {
storedSettings[key] = parseStoredValue(row.setting_value);
}
});
return normalizeAppSettings(Object.assign({}, getDefaultAppSettings(), storedSettings));
}
async function saveAppSettings(pool, settings, modifiedBy) {
const inputSettings = settings && typeof settings === 'object' ? settings : {};
const normalizedSettings = normalizeAppSettings(inputSettings);
const connection = typeof pool.getConnection === 'function' ? await pool.getConnection() : pool;
const shouldRelease = connection !== pool;
try {
if (typeof connection.beginTransaction === 'function') {
await connection.beginTransaction();
}
for (const definition of SETTING_DEFINITIONS) {
if (!Object.prototype.hasOwnProperty.call(inputSettings, definition.key)) {
continue;
}
await connection.query(
`UPDATE o_app_settings
SET setting_value = ?, modified_by = ?
WHERE setting_key = ?`,
[JSON.stringify(normalizedSettings[definition.key]), modifiedBy || null, definition.key]
);
await connection.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM o_app_settings WHERE setting_key = ?
)`,
[definition.key, JSON.stringify(normalizedSettings[definition.key]), modifiedBy || null, modifiedBy || null, definition.key]
);
}
if (typeof connection.commit === 'function') {
await connection.commit();
}
} catch (error) {
if (typeof connection.rollback === 'function') {
await connection.rollback();
}
throw error;
} finally {
if (shouldRelease && typeof connection.release === 'function') {
connection.release();
}
}
return normalizedSettings;
}
module.exports = {
getAppSettingDefinitions,
getDefaultAppSettings,
normalizeSettingValue,
normalizeAppSettings,
fetchAppSettings,
saveAppSettings
};
+120
View File
@@ -0,0 +1,120 @@
// Audit event definitions and data access helpers for administrative activity.
const AUDIT_EVENT_CATEGORIES = Object.freeze({
AUTHENTICATION: 'authentication',
SECURITY: 'security',
SESSIONS: 'sessions',
USERS: 'users',
ROLES: 'roles',
SETTINGS: 'system-settings',
SLIDES: 'slides',
TEMPLATES: 'templates',
PLAYLISTS: 'playlists',
SCREENS: 'screens',
ANNOUNCEMENTS: 'announcements',
CANVAS_SIZES: 'canvas-sizes',
API_SOURCES: 'api-sources',
RSS_FEEDS: 'rss-feeds',
TIMETABLES: 'timetables'
});
const AUDIT_CATEGORY_KEYS = Object.freeze(Object.values(AUDIT_EVENT_CATEGORIES));
const AUDIT_CATEGORY_LABELS = Object.freeze({
authentication: 'Authentication',
security: 'Security',
sessions: 'Sessions',
users: 'Users',
roles: 'Roles',
'system-settings': 'System Settings',
slides: 'Slides',
templates: 'Templates',
playlists: 'Playlists',
screens: 'Screens',
announcements: 'Announcements',
'canvas-sizes': 'Canvas Sizes',
'api-sources': 'API Sources',
'rss-feeds': 'RSS Feeds',
timetables: 'Timetables'
});
const { fetchAppSettings } = require('./app-settings');
function normalizeDetails(details) {
if (details === undefined || details === null) {
return null;
}
return JSON.stringify(details);
}
function buildAuditChanges(previousValues, nextValues) {
const previous = previousValues && typeof previousValues === 'object' ? previousValues : {};
const next = nextValues && typeof nextValues === 'object' ? nextValues : {};
const changes = {};
const keys = new Set(Object.keys(previous).concat(Object.keys(next)));
keys.forEach(function (key) {
if (JSON.stringify(previous[key]) !== JSON.stringify(next[key])) {
changes[key] = { from: previous[key], to: next[key] };
}
});
return changes;
}
function getRequestMetadata(req) {
const forwardedAddress = String(req && req.headers && req.headers['x-forwarded-for'] || '').split(',')[0].trim();
return {
ipAddress: forwardedAddress || String(req && req.ip || req && req.socket && req.socket.remoteAddress || '').trim() || null,
userAgent: String(req && req.headers && req.headers['user-agent'] || '').trim() || null
};
}
async function recordAuditEvent(pool, event) {
const input = event && typeof event === 'object' ? event : {};
const category = String(input.category || '').trim().toLowerCase();
const eventType = String(input.eventType || '').trim().toLowerCase();
if (!category || !eventType) {
throw new Error('Audit events require a category and event type.');
}
await pool.query(
`INSERT INTO o_audit_events
(category, event_type, actor_user_id, target_type, target_id, target_label, ip_address, user_agent, details_json)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?)`,
[
category,
eventType,
Number.isInteger(Number(input.actorUserId)) && Number(input.actorUserId) > 0 ? Number(input.actorUserId) : null,
String(input.targetType || '').trim() || null,
String(input.targetId || '').trim() || null,
String(input.targetLabel || '').trim() || null,
String(input.ipAddress || '').trim() || null,
String(input.userAgent || '').trim() || null,
normalizeDetails(input.details)
]
);
}
async function recordRequestAuditEvent(pool, req, event) {
try {
const settings = await fetchAppSettings(pool);
const category = String(event && event.category || '').trim().toLowerCase();
const enabledCategories = Array.isArray(settings['audit.categories']) ? settings['audit.categories'] : AUDIT_CATEGORY_KEYS;
if (!settings['audit.enabled'] || !enabledCategories.includes(category)) {
return;
}
const metadata = settings['audit.include_request_metadata'] ? getRequestMetadata(req) : {};
await recordAuditEvent(pool, Object.assign({}, event, metadata));
} catch (error) {
// Auditing must not turn a successful login or administration action into a failed request.
console.error('Unable to record audit event:', error.message);
}
}
module.exports = {
AUDIT_EVENT_CATEGORIES,
AUDIT_CATEGORY_KEYS,
AUDIT_CATEGORY_LABELS,
getRequestMetadata,
buildAuditChanges,
recordAuditEvent,
recordRequestAuditEvent
};
+24 -3
View File
@@ -23,6 +23,9 @@ async function isClientNameAvailable(pool, clientName, excludeDeviceId, liveConn
const normalizedDeviceId = normalizeDeviceId(excludeDeviceId); const normalizedDeviceId = normalizeDeviceId(excludeDeviceId);
const live = collectLiveConnections(liveConnections); const live = collectLiveConnections(liveConnections);
const lowerName = normalizedName.toLowerCase(); const lowerName = normalizedName.toLowerCase();
const liveDeviceIds = new Set(live.map(function (connection) {
return normalizeDeviceId(connection && (connection.deviceId || connection.clientId));
}).filter(Boolean));
try { try {
if (pool) { if (pool) {
@@ -32,12 +35,13 @@ async function isClientNameAvailable(pool, clientName, excludeDeviceId, liveConn
WHERE client_name IS NOT NULL WHERE client_name IS NOT NULL
AND TRIM(client_name) <> '' AND TRIM(client_name) <> ''
AND LOWER(TRIM(client_name)) = LOWER(TRIM(?)) AND LOWER(TRIM(client_name)) = LOWER(TRIM(?))
AND device_id <> ? AND device_id <> ?`,
LIMIT 1`,
[normalizedName, normalizedDeviceId] [normalizedName, normalizedDeviceId]
); );
if (deviceRows.length) { if ((deviceRows || []).some(function (row) {
return liveDeviceIds.has(normalizeDeviceId(row && row.device_id));
})) {
return false; return false;
} }
} }
@@ -72,6 +76,22 @@ async function isClientNameAvailable(pool, clientName, excludeDeviceId, liveConn
} }
} }
async function findAvailableClientName(pool, clientName, excludeDeviceId, liveConnections) {
const normalizedName = normalizeClientName(clientName);
if (!normalizedName) {
return '';
}
for (let suffix = 0; suffix < 1000; suffix += 1) {
const candidate = suffix === 0 ? normalizedName : `${normalizedName} (${suffix})`;
if (await isClientNameAvailable(pool, candidate, excludeDeviceId, liveConnections)) {
return candidate;
}
}
return '';
}
function buildClientNameLockName(clientName) { function buildClientNameLockName(clientName) {
return `ps_client_name_${crypto.createHash('sha1').update(String(clientName || '').trim().toLowerCase()).digest('hex')}`; return `ps_client_name_${crypto.createHash('sha1').update(String(clientName || '').trim().toLowerCase()).digest('hex')}`;
} }
@@ -116,5 +136,6 @@ module.exports = {
normalizeDeviceId: normalizeDeviceId, normalizeDeviceId: normalizeDeviceId,
collectLiveConnections: collectLiveConnections, collectLiveConnections: collectLiveConnections,
isClientNameAvailable: isClientNameAvailable, isClientNameAvailable: isClientNameAvailable,
findAvailableClientName: findAvailableClientName,
withClientNameReservation: withClientNameReservation withClientNameReservation: withClientNameReservation
}; };
+8 -1
View File
@@ -4,9 +4,10 @@ const { fetchAdminData, fetchPlaylistsPage, fetchSlidesPage, fetchTemplatesPage,
const { ANNOUNCEMENT_TYPES, ANNOUNCEMENT_COLORS, ANNOUNCEMENT_ICONS, DEFAULT_ANNOUNCEMENT_ICON, normalizeAnnouncementType, normalizeAnnouncementColor, normalizeAnnouncementIcon, fetchAnnouncementsPage, fetchAnnouncementById, fetchActiveAnnouncement, buildAnnouncementPayload } = require('./announcements'); const { ANNOUNCEMENT_TYPES, ANNOUNCEMENT_COLORS, ANNOUNCEMENT_ICONS, DEFAULT_ANNOUNCEMENT_ICON, normalizeAnnouncementType, normalizeAnnouncementColor, normalizeAnnouncementIcon, fetchAnnouncementsPage, fetchAnnouncementById, fetchActiveAnnouncement, buildAnnouncementPayload } = require('./announcements');
const { ANNOUNCEMENT_ICON_OPTIONS, ANNOUNCEMENT_ICON_LABELS } = require('./announcement-icons'); const { ANNOUNCEMENT_ICON_OPTIONS, ANNOUNCEMENT_ICON_LABELS } = require('./announcement-icons');
const { fetchPlaylistById } = require('./playlists'); const { fetchPlaylistById } = require('./playlists');
const { normalizeDisplayMode, fetchTimetablesData, fetchTimetableGroupsPage, fetchTimetableGroupById, fetchTimetableEntriesByGroupId, buildTimetableGroupPayload } = require('./schedules'); const { normalizeDisplayMode, fetchTimetablesData, fetchTimetableGroupsPage, fetchTimetableGroupById, fetchTimetableEntriesByGroupId, buildTimetableGroupPayload } = require('./timetables');
const { fetchApiSourcesData, fetchApiSourcesPage, fetchApiSourceById, fetchApiSourceResponse, buildApiSourcePayload } = require('./api-sources'); const { fetchApiSourcesData, fetchApiSourcesPage, fetchApiSourceById, fetchApiSourceResponse, buildApiSourcePayload } = require('./api-sources');
const { fetchRssFeedsData, fetchRssFeedsPage, fetchRssFeedById, fetchRssFeedItemsByFeedId, normalizeRssFeedItem, buildRssFeedPayload, fetchRssFeedItems, replaceRssFeedItems } = require('./rss-feeds'); const { fetchRssFeedsData, fetchRssFeedsPage, fetchRssFeedById, fetchRssFeedItemsByFeedId, normalizeRssFeedItem, buildRssFeedPayload, fetchRssFeedItems, replaceRssFeedItems } = require('./rss-feeds');
const { fetchWeatherLocationsData, fetchWeatherLocationsPage, fetchWeatherLocationById, fetchWeatherLocationSuggestions, fetchWeatherLocationForecast, buildWeatherLocationPayload } = require('./weather');
const { slugify, uniqueScreenSlug, fetchScreenById, fetchScreenEditData, fetchScreenPlayerUrls, fetchPlayerPublicBaseUrl, fetchScreenPlayerRecord, fetchPlayerRecordByIdentifier } = require('./screens'); const { slugify, uniqueScreenSlug, fetchScreenById, fetchScreenEditData, fetchScreenPlayerUrls, fetchPlayerPublicBaseUrl, fetchScreenPlayerRecord, fetchPlayerRecordByIdentifier } = require('./screens');
const { fetchPlayerRegistrations } = require('./player-registry'); const { fetchPlayerRegistrations } = require('./player-registry');
const { fetchTemplateById, fetchTemplatesData, extractTemplateRegions, buildTemplatePayload } = require('./templates'); const { fetchTemplateById, fetchTemplatesData, extractTemplateRegions, buildTemplatePayload } = require('./templates');
@@ -59,6 +60,12 @@ module.exports = {
buildRssFeedPayload, buildRssFeedPayload,
fetchRssFeedItems, fetchRssFeedItems,
replaceRssFeedItems, replaceRssFeedItems,
fetchWeatherLocationsData,
fetchWeatherLocationsPage,
fetchWeatherLocationById,
fetchWeatherLocationSuggestions,
fetchWeatherLocationForecast,
buildWeatherLocationPayload,
fetchScreenById, fetchScreenById,
fetchScreenEditData, fetchScreenEditData,
fetchScreenPlayerUrls, fetchScreenPlayerUrls,
+27 -14
View File
@@ -1,3 +1,5 @@
// Persistent player registration and heartbeat helpers shared by the web app and bridge.
function normalizeDeviceId(value) { function normalizeDeviceId(value) {
return String(value || '') return String(value || '')
.trim() .trim()
@@ -92,15 +94,19 @@ async function upsertPlayerRegistration(pool, options) {
return null; return null;
} }
await pool.query(
`UPDATE d_players
SET public_base_url = ?, internal_base_url = ?, last_seen_at = CURRENT_TIMESTAMP, modified_at = CURRENT_TIMESTAMP
WHERE identifier = ?`,
[publicBaseUrl || null, internalBaseUrl || null, identifier]
);
await pool.query( await pool.query(
`INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at) `INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at)
VALUES (?, ?, ?, CURRENT_TIMESTAMP) SELECT ?, ?, ?, CURRENT_TIMESTAMP
ON DUPLICATE KEY UPDATE WHERE NOT EXISTS (
public_base_url = VALUES(public_base_url), SELECT 1 FROM d_players WHERE identifier = ?
internal_base_url = VALUES(internal_base_url), )`,
last_seen_at = CURRENT_TIMESTAMP, [identifier, publicBaseUrl || null, internalBaseUrl || null, identifier]
modified_at = CURRENT_TIMESTAMP`,
[identifier, publicBaseUrl || null, internalBaseUrl || null]
); );
return resolvePlayerRegistration(pool, identifier); return resolvePlayerRegistration(pool, identifier);
@@ -115,15 +121,22 @@ async function recordPlayerHeartbeat(pool, options) {
return null; return null;
} }
await pool.query(
`UPDATE d_players
SET public_base_url = COALESCE(?, public_base_url),
internal_base_url = COALESCE(?, internal_base_url),
last_seen_at = CURRENT_TIMESTAMP,
modified_at = CURRENT_TIMESTAMP
WHERE identifier = ?`,
[publicBaseUrl || null, internalBaseUrl || null, identifier]
);
await pool.query( await pool.query(
`INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at) `INSERT INTO d_players (identifier, public_base_url, internal_base_url, last_seen_at)
VALUES (?, ?, ?, CURRENT_TIMESTAMP) SELECT ?, ?, ?, CURRENT_TIMESTAMP
ON DUPLICATE KEY UPDATE WHERE NOT EXISTS (
public_base_url = COALESCE(VALUES(public_base_url), public_base_url), SELECT 1 FROM d_players WHERE identifier = ?
internal_base_url = COALESCE(VALUES(internal_base_url), internal_base_url), )`,
last_seen_at = CURRENT_TIMESTAMP, [identifier, publicBaseUrl || null, internalBaseUrl || null, identifier]
modified_at = CURRENT_TIMESTAMP`,
[identifier, publicBaseUrl || null, internalBaseUrl || null]
); );
return resolvePlayerRegistration(pool, identifier); return resolvePlayerRegistration(pool, identifier);
+2 -90
View File
@@ -1,24 +1,8 @@
const fs = require('fs'); // QR code generation helpers for player onboarding and administrative links.
const path = require('path'); const path = require('path');
const QRCodeStyling = require(path.join(__dirname, '..', 'web', 'public', 'vendor', 'qr-code-styling', 'qr-code-styling.js')); const QRCodeStyling = require(path.join(__dirname, '..', 'web', 'public', 'vendor', 'qr-code-styling', 'qr-code-styling.js'));
const puppeteer = require('puppeteer-core');
const chromiumModule = require('@sparticuz/chromium');
const QR_PNG_WIDTH = 2048; const QR_PNG_WIDTH = 2048;
const QR_STYLING_SCRIPT_PATH = path.join(__dirname, '..', 'web', 'public', 'vendor', 'qr-code-styling', 'qr-code-styling.js');
const SYSTEM_CHROMIUM_PATHS = [
process.env.PUPPETEER_EXECUTABLE_PATH,
process.env.CHROMIUM_PATH,
'/usr/bin/chromium',
'/usr/bin/chromium-browser',
'/usr/local/bin/chromium',
'/snap/bin/chromium'
].filter(Boolean);
const chromium = chromiumModule && typeof chromiumModule.executablePath === 'function'
? chromiumModule
: chromiumModule && chromiumModule.default && typeof chromiumModule.default.executablePath === 'function'
? chromiumModule.default
: chromiumModule;
let qrBrowserPromise = null;
function escapeXml(value) { function escapeXml(value) {
return String(value === undefined || value === null ? '' : value).replace(/[&<>"']/g, function (character) { return String(value === undefined || value === null ? '' : value).replace(/[&<>"']/g, function (character) {
@@ -347,74 +331,6 @@ function buildQrStylingOptions(source) {
}; };
} }
function getQrBrowser() {
if (qrBrowserPromise) {
return qrBrowserPromise;
}
qrBrowserPromise = (async function () {
let executablePath = SYSTEM_CHROMIUM_PATHS.find(function (candidate) {
return fs.existsSync(candidate);
}) || '';
const usingSystemChromium = Boolean(executablePath);
if (!executablePath && chromium && typeof chromium.executablePath === 'function') {
executablePath = await chromium.executablePath();
}
if (!executablePath || !fs.existsSync(executablePath)) {
throw new Error('Chromium executable was not found.');
}
return puppeteer.launch({
args: usingSystemChromium
? [
'--no-sandbox',
'--disable-setuid-sandbox',
'--disable-dev-shm-usage',
'--disable-gpu'
]
: puppeteer.defaultArgs({
args: chromium && chromium.args ? chromium.args : [],
headless: 'shell'
}),
defaultViewport: usingSystemChromium
? { width: QR_PNG_WIDTH, height: QR_PNG_WIDTH, deviceScaleFactor: 1 }
: chromium && chromium.defaultViewport ? chromium.defaultViewport : null,
executablePath: executablePath,
headless: usingSystemChromium ? true : 'shell'
});
})();
return qrBrowserPromise;
}
async function blobToDataUrl(blob) {
if (!blob) {
return '';
}
if (typeof blob === 'string') {
return blob;
}
if (typeof blob.arrayBuffer === 'function') {
const buffer = await blob.arrayBuffer();
const bytes = new Uint8Array(buffer);
let binary = '';
for (let index = 0; index < bytes.length; index += 1) {
binary += String.fromCharCode(bytes[index]);
}
return 'data:' + String(blob.type || 'image/png') + ';base64,' + Buffer.from(binary, 'binary').toString('base64');
}
if (typeof blob.text === 'function') {
return blob.text();
}
return '';
}
async function createStyledQrCodeDataUrl(value) { async function createStyledQrCodeDataUrl(value) {
const source = value && typeof value === 'object' ? value : { value: value }; const source = value && typeof value === 'object' ? value : { value: value };
const options = buildQrStylingOptions(source); const options = buildQrStylingOptions(source);
@@ -435,10 +351,6 @@ async function createStyledQrCodeSvg(value) {
return renderStyledQrRawData(options, 'svg'); return renderStyledQrRawData(options, 'svg');
} }
async function createQrCodeDataUrlPlain(value) {
return createStyledQrCodeDataUrl(value);
}
async function createQrCodeSvg(value) { async function createQrCodeSvg(value) {
return createStyledQrCodeSvg(value); return createStyledQrCodeSvg(value);
} }
+7 -4
View File
@@ -9,12 +9,15 @@ const URL_MAX_LENGTH = 1024;
function normalizeUpdateIntervalUnit(value) { function normalizeUpdateIntervalUnit(value) {
const unit = String(value || '').trim().toLowerCase(); const unit = String(value || '').trim().toLowerCase();
return unit === 'seconds' ? 'seconds' : 'minutes'; if (unit === 'seconds' || unit === 'minutes' || unit === 'hours') {
return unit;
}
return 'minutes';
} }
async function fetchRssFeedsData(pool) { async function fetchRssFeedsData(pool) {
const [rssFeeds] = await pool.query( const [rssFeeds] = await pool.query(
'SELECT id, name, feed_url, update_interval_value, update_interval_unit, item_limit, created_at, modified_at, created_by, modified_by FROM i_rss_feeds ORDER BY modified_at DESC, id DESC' 'SELECT id, name, feed_url, enabled, update_interval_value, update_interval_unit, item_limit, last_pulled_at, created_at, modified_at, created_by, modified_by FROM i_rss_feeds ORDER BY modified_at DESC, id DESC'
); );
return { rssFeeds: rssFeeds }; return { rssFeeds: rssFeeds };
@@ -22,7 +25,7 @@ async function fetchRssFeedsData(pool) {
async function fetchRssFeedsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) { async function fetchRssFeedsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, { const paged = await fetchPagedRows(pool, {
selectSql: 'SELECT id, name, feed_url, update_interval_value, update_interval_unit, item_limit, created_at, modified_at, created_by, modified_by FROM i_rss_feeds ORDER BY modified_at DESC, id DESC', selectSql: 'SELECT id, name, feed_url, enabled, update_interval_value, update_interval_unit, item_limit, last_pulled_at, created_at, modified_at, created_by, modified_by FROM i_rss_feeds ORDER BY modified_at DESC, id DESC',
countSql: 'SELECT COUNT(*) AS count FROM i_rss_feeds', countSql: 'SELECT COUNT(*) AS count FROM i_rss_feeds',
searchColumns: ['name', 'feed_url'], searchColumns: ['name', 'feed_url'],
searchTerm: searchTerm, searchTerm: searchTerm,
@@ -45,7 +48,7 @@ async function fetchRssFeedsPage(pool, page, pageSize, searchTerm, sortKey, sort
async function fetchRssFeedById(pool, id) { async function fetchRssFeedById(pool, id) {
const [rows] = await pool.query( const [rows] = await pool.query(
'SELECT id, name, feed_url, update_interval_value, update_interval_unit, item_limit, created_at, modified_at, created_by, modified_by FROM i_rss_feeds WHERE id = ?', 'SELECT id, name, feed_url, enabled, update_interval_value, update_interval_unit, item_limit, last_pulled_at, created_at, modified_at, created_by, modified_by FROM i_rss_feeds WHERE id = ?',
[id] [id]
); );
+130 -17
View File
@@ -6,38 +6,93 @@ const { parseJsonSafe, validateMaxLength } = require('./utils');
const TITLE_MAX_LENGTH = 255; const TITLE_MAX_LENGTH = 255;
const { buildQrCodeContent } = require('./qr-code'); const { buildQrCodeContent } = require('./qr-code');
const ALLOWED_RICH_TEXT_TAGS = ['b', 'strong', 'i', 'em', 'u', 'br', 'p', 'div', 'ul', 'ol', 'li'];
const DEFAULT_FONT_SIZE = 32; const DEFAULT_FONT_SIZE = 32;
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'],
blockquote: ['class', 'style'],
div: ['class', 'style'],
figure: ['class', 'style'],
figcaption: ['class', 'style'],
h1: ['class', 'style'],
h2: ['class', 'style'],
h3: ['class', 'style'],
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
pre: ['class', 'style'],
span: ['class', 'style'],
table: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
tr: ['class', 'style'],
ul: ['class', 'style']
};
const allowed = allowedAttributes[tagName] || [];
if (!allowed.length) {
return '';
}
const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase();
if (!allowed.includes(lowerKey)) {
return '';
}
const value = doubleQuoted !== undefined ? doubleQuoted : singleQuoted !== undefined ? singleQuoted : bareValue !== undefined ? bareValue : '';
if (lowerKey === 'href' && /^(?:\s*javascript:|\s*data:)/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'style' && /(?:expression\s*\(|javascript:|url\s*\()/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'target') {
const targetValue = String(value || '').trim();
if (targetValue === '_blank') {
attrs.push(' target="_blank"');
if (!attrs.includes(' rel="noreferrer noopener"')) {
attrs.push(' rel="noreferrer noopener"');
}
return '';
}
}
attrs.push(' ' + lowerKey + '="' + String(value || '').replace(/&/g, '&amp;').replace(/</g, '&lt;').replace(/>/g, '&gt;').replace(/"/g, '&quot;').replace(/'/g, '&#39;') + '"');
return '';
});
return attrs.join('');
}
function sanitizeRichText(html) { function sanitizeRichText(html) {
let output = String(html || ''); let output = String(html || '');
output = output.replace(/<script[\s\S]*?<\/script>/gi, ''); output = output.replace(/<script[\s\S]*?<\/script>/gi, '');
output = output.replace(/<style[\s\S]*?<\/style>/gi, ''); output = output.replace(/<style[\s\S]*?<\/style>/gi, '');
return output.replace(/<[^>]+>/g, (tag) => { return output.replace(/<[^>]+>/g, (tag) => {
const match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)(?:\s[^>]*)?>$/i); const match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)([\s\S]*?)(\/?)>$/i);
if (!match) { if (!match) {
return ''; return '';
} }
const closing = Boolean(match[1]); const closing = Boolean(match[1]);
const name = String(match[2] || '').toLowerCase(); const name = String(match[2] || '').toLowerCase();
const attrText = String(match[3] || '');
if (!ALLOWED_RICH_TEXT_TAGS.includes(name)) { if (!ALLOWED_RICH_TEXT_TAGS.includes(name)) {
return ''; return '';
} }
if (name === 'br') { if (closing) {
return '<br>'; return `</${name}>`;
} }
return closing ? `</${name}>` : `<${name}>`; return `<${name}${sanitizeRichTextAttributes(name, attrText)}>`;
}); });
} }
function normalizePlainText(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/<\s*br\s*\/?\s*>/gi, '\n')
.replace(/<[^>]*>/g, '')
.replace(/&nbsp;/gi, ' ')
.trim();
}
function stripEditorOnlyMarkup(value) { function stripEditorOnlyMarkup(value) {
return String(value || '') return String(value || '')
.replace(/<pre[^>]*class="[^"]*api-region-sample-preview[^"]*"[^>]*>[\s\S]*?<\/pre>/gi, '') .replace(/<pre[^>]*class="[^"]*api-region-sample-preview[^"]*"[^>]*>[\s\S]*?<\/pre>/gi, '')
@@ -308,6 +363,49 @@ async function buildTemplateContent(pool, template, body, filesByField, existing
value: submitted === undefined ? String(current.value !== undefined ? current.value : current.text !== undefined ? current.text : '') : String(submitted || ''), value: submitted === undefined ? String(current.value !== undefined ? current.value : current.text !== undefined ? current.text : '') : String(submitted || ''),
timezone: timezoneValue === undefined || timezoneValue === null ? String(current.timezone || current.time_zone || '') : String(timezoneValue || '').trim() timezone: timezoneValue === undefined || timezoneValue === null ? String(current.timezone || current.time_zone || '') : String(timezoneValue || '').trim()
}; };
} else if (region.region_type === 'timetable') {
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id;
const generic = {};
const submittedText = body[`region_text_${region.id}`];
const normalizedText = submittedText === undefined ? String(current.text !== undefined ? current.text : current.value !== undefined ? current.value : '') : String(submittedText || '');
Object.keys(body || {}).forEach((key) => {
if (!key.startsWith('region_') || !key.endsWith(suffix)) {
return;
}
const field = key.slice('region_'.length, -suffix.length);
if (!field || field === 'type' || field === 'key' || field === 'name' || field === 'label') {
return;
}
generic[field] = body[key];
});
if (Object.prototype.hasOwnProperty.call(generic, 'timetable_display_mode')) {
generic.display_mode = generic.timetable_display_mode;
delete generic.timetable_display_mode;
}
if (Object.prototype.hasOwnProperty.call(generic, 'timetable_max_items')) {
generic.max_items = generic.timetable_max_items;
delete generic.timetable_max_items;
}
Object.keys(current).forEach((key) => {
if (generic[key] === undefined) {
generic[key] = current[key];
}
});
delete generic.timetable_display_mode;
delete generic.timetable_max_items;
generic.text = normalizedText;
generic.value = normalizedText;
generic.type = region.region_type;
content[region.region_key] = generic;
} else if (region.region_type === 'rss') { } else if (region.region_type === 'rss') {
const submitted = body[`region_text_${region.id}`]; const submitted = body[`region_text_${region.id}`];
const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {}; const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
@@ -320,7 +418,7 @@ async function buildTemplateContent(pool, template, body, filesByField, existing
content[region.region_key] = { content[region.region_key] = {
type: 'rss', type: 'rss',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))), value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))),
feed_id: feedId === undefined || feedId === null || feedId === '' ? (current.feed_id || null) : Number(feedId), feed_id: feedId === undefined || feedId === null ? (current.feed_id || null) : (feedId === '' ? null : Number(feedId)),
item_number: Math.min(itemCount, Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1), item_number: Math.min(itemCount, Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1),
variable_name: 'item', variable_name: 'item',
font_family: style.font_family, font_family: style.font_family,
@@ -338,7 +436,7 @@ async function buildTemplateContent(pool, template, body, filesByField, existing
content[region.region_key] = { content[region.region_key] = {
type: 'api', type: 'api',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))), value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? String(current.value || '') : String(submitted || ''))),
source_id: sourceId === undefined || sourceId === null || sourceId === '' ? (current.source_id || null) : Number(sourceId), source_id: sourceId === undefined || sourceId === null ? (current.source_id || null) : (sourceId === '' ? null : Number(sourceId)),
item_number: Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1, item_number: Number.isFinite(parsedItemNumber) && parsedItemNumber > 0 ? parsedItemNumber : 1,
items_path: itemsPath === undefined || itemsPath === null ? (current.items_path === undefined || current.items_path === null ? '' : String(current.items_path)) : String(itemsPath || '').trim(), items_path: itemsPath === undefined || itemsPath === null ? (current.items_path === undefined || current.items_path === null ? '' : String(current.items_path)) : String(itemsPath || '').trim(),
variable_name: 'item', variable_name: 'item',
@@ -346,7 +444,22 @@ async function buildTemplateContent(pool, template, body, filesByField, existing
font_size: style.font_size, font_size: style.font_size,
font_color: style.font_color font_color: style.font_color
}; };
} else if (!['text', 'image', 'video', 'webpage', 'qr-code', 'html', 'rtmp', 'rss', 'api'].includes(String(region.region_type || '').trim())) { } else if (region.region_type === 'weather') {
const current = existingContent && existingContent[region.region_key] ? existingContent[region.region_key] : {};
const locationId = body[`region_weather_location_id_${region.id}`];
const submittedForecastMode = body[`region_weather_forecast_mode_${region.id}`];
const forecastMode = ['current', 'hourly'].includes(submittedForecastMode) ? submittedForecastMode : 'daily';
const style = getTextRegionStyle(body, region, existingContent);
content[region.region_key] = {
type: 'weather',
value: body[`region_text_${region.id}`] !== undefined ? String(body[`region_text_${region.id}`] || '') : String(current.value || ''),
weather_location_id: locationId === undefined || locationId === null ? (current.weather_location_id || null) : (locationId === '' ? null : Number(locationId)),
forecast_mode: body[`region_weather_forecast_mode_${region.id}`] === undefined ? (['current', 'hourly'].includes(current.forecast_mode) ? current.forecast_mode : 'daily') : forecastMode,
font_family: style.font_family,
font_size: style.font_size,
font_color: style.font_color
};
} else if (!['text', 'image', 'video', 'webpage', 'qr-code', 'html', 'rtmp', 'rss', 'api', 'weather'].includes(String(region.region_type || '').trim())) {
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {}; const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id; const suffix = '_' + region.id;
const generic = {}; const generic = {};
@@ -387,7 +500,7 @@ async function buildTemplateContent(pool, template, body, filesByField, existing
const style = getTextRegionStyle(body, region, existingContent); const style = getTextRegionStyle(body, region, existingContent);
content[region.region_key] = { content[region.region_key] = {
type: 'text', type: 'text',
value: stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? current : String(submitted || ''))), value: sanitizeRichText(stripEditorOnlyMarkup(normalizeEditorMarkup(submitted === undefined ? current : String(submitted || '')))),
font_family: style.font_family, font_family: style.font_family,
font_size: style.font_size, font_size: style.font_size,
font_color: style.font_color font_color: style.font_color
+41 -39
View File
@@ -14,6 +14,39 @@ function sanitizeBackgroundColor(value) {
return '#111111'; return '#111111';
} }
function normalizeBackgroundGradient(value) {
let gradient = value;
if (typeof gradient === 'string') {
try {
gradient = JSON.parse(gradient);
} catch (_error) {
gradient = null;
}
}
if (!gradient || typeof gradient !== 'object' || Array.isArray(gradient)) {
return null;
}
const sourceStops = Array.isArray(gradient.stops) && gradient.stops.length
? gradient.stops
: (Array.isArray(gradient.colors) ? gradient.colors.map((color, index, colors) => ({
color,
position: colors.length > 1 ? Math.round((index / (colors.length - 1)) * 100) : 0
})) : []);
const stops = sourceStops.slice(0, 12).map((stop) => ({
color: sanitizeBackgroundColor(stop && stop.color),
position: Math.max(0, Math.min(100, Number.isFinite(Number(stop && stop.position)) ? Number(stop.position) : 0))
}));
if (stops.length < 2) {
return null;
}
const angle = Number(gradient.angle);
return JSON.stringify({
type: 'linear',
stops,
angle: Number.isFinite(angle) ? Math.max(0, Math.min(360, angle)) : 90
});
}
function normalizeTemplateRegionType(value) { function normalizeTemplateRegionType(value) {
const rawType = String(value || 'text').trim(); const rawType = String(value || 'text').trim();
return rawType || 'text'; return rawType || 'text';
@@ -106,7 +139,7 @@ function ensureUniqueTemplateRegionNames(regions) {
async function fetchTemplateById(pool, id) { async function fetchTemplateById(pool, id) {
const [templates] = await pool.query(` const [templates] = await pool.query(`
SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.created_at, st.modified_at, SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.background_gradient, st.created_at, st.modified_at,
cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height
FROM c_templates st FROM c_templates st
LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id
@@ -123,7 +156,7 @@ async function fetchTemplateById(pool, id) {
async function fetchTemplatesData(pool) { async function fetchTemplatesData(pool) {
const [templates] = await pool.query(` const [templates] = await pool.query(`
SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.created_at, st.modified_at, SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.background_gradient, st.created_at, st.modified_at,
cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height
FROM c_templates st FROM c_templates st
LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id
@@ -194,43 +227,6 @@ function extractTemplateRegions(body) {
return regions; return regions;
} }
function extractGenericRegionContent(region, body, filesByField, existingContent) {
const content = {};
const current = existingContent && existingContent[region.region_key] && typeof existingContent[region.region_key] === 'object' ? existingContent[region.region_key] : {};
const suffix = '_' + region.id;
Object.keys(body || {}).forEach((key) => {
if (!key.startsWith('region_') || !key.endsWith(suffix)) {
return;
}
const field = key.slice('region_'.length, -suffix.length);
if (!field || field === 'type' || field === 'key' || field === 'name' || field === 'label') {
return;
}
content[field] = body[key];
});
Object.keys(filesByField || {}).forEach((fieldName) => {
if (!fieldName.startsWith('region_') || !fieldName.endsWith(suffix)) {
return;
}
const field = fieldName.slice('region_'.length, -suffix.length);
if (!field) {
return;
}
content[field] = `/media/uploads/${filesByField[fieldName].filename}`;
});
Object.keys(current).forEach((key) => {
if (content[key] === undefined) {
content[key] = current[key];
}
});
content.type = region.region_type;
return content;
}
function getFilesByField(files) { function getFilesByField(files) {
const map = {}; const map = {};
(files || []).forEach((file) => { (files || []).forEach((file) => {
@@ -249,6 +245,10 @@ async function buildTemplatePayload(pool, req, existingTemplate) {
const backgroundImage = filesByField.background_image; const backgroundImage = filesByField.background_image;
const removeBackgroundImage = Boolean(req.body.remove_background_image); const removeBackgroundImage = Boolean(req.body.remove_background_image);
const backgroundColor = sanitizeBackgroundColor(req.body.background_color || (existingTemplate && existingTemplate.background_color)); const backgroundColor = sanitizeBackgroundColor(req.body.background_color || (existingTemplate && existingTemplate.background_color));
const submittedBackgroundGradient = Object.prototype.hasOwnProperty.call(req.body, 'background_gradient')
? req.body.background_gradient
: existingTemplate && existingTemplate.background_gradient;
const backgroundGradient = normalizeBackgroundGradient(submittedBackgroundGradient);
const backgroundImagePath = backgroundImage const backgroundImagePath = backgroundImage
? `/media/uploads/${backgroundImage.filename}` ? `/media/uploads/${backgroundImage.filename}`
: removeBackgroundImage : removeBackgroundImage
@@ -293,6 +293,7 @@ async function buildTemplatePayload(pool, req, existingTemplate) {
canvasSizeHeight: canvasHeight, canvasSizeHeight: canvasHeight,
backgroundImagePath, backgroundImagePath,
backgroundColor, backgroundColor,
backgroundGradient,
regions regions
}; };
} }
@@ -302,5 +303,6 @@ module.exports = {
fetchTemplatesData, fetchTemplatesData,
extractTemplateRegions, extractTemplateRegions,
buildTemplatePayload, buildTemplatePayload,
normalizeBackgroundGradient,
parseJsonSafe parseJsonSafe
}; };
@@ -4,6 +4,23 @@ const { fetchPagedRows, validateMaxLength } = require('./utils');
const NAME_MAX_LENGTH = 255; const NAME_MAX_LENGTH = 255;
const DESCRIPTION_MAX_LENGTH = 255; const DESCRIPTION_MAX_LENGTH = 255;
const DEFAULT_TIME_ZONE = 'Europe/London';
function normalizeTimeZone(value, fallback) {
const raw = String(value || '').trim();
if (!raw) {
return String(fallback || DEFAULT_TIME_ZONE).trim() || DEFAULT_TIME_ZONE;
}
try {
new Intl.DateTimeFormat('en-GB', { timeZone: raw }).format(new Date());
return raw;
} catch (_error) {
const error = new Error('Timetable time zone is invalid.');
error.statusCode = 400;
throw error;
}
}
function normalizeDisplayMode(value) { function normalizeDisplayMode(value) {
const mode = String(value || 'upcoming').trim().toLowerCase(); const mode = String(value || 'upcoming').trim().toLowerCase();
@@ -15,15 +32,15 @@ function normalizeDisplayMode(value) {
async function fetchTimetablesData(pool) { async function fetchTimetablesData(pool) {
const [timetableGroups] = await pool.query(` const [timetableGroups] = await pool.query(`
SELECT g.id, g.name, g.short_description, g.created_at, g.modified_at, g.created_by, g.modified_by, SELECT g.id, g.name, g.short_description, g.timezone, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id) AS entry_count, (SELECT COUNT(*) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime (SELECT MIN(e.start_datetime) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_schedule_groups g FROM i_timetable_groups g
ORDER BY g.modified_at DESC, g.id DESC ORDER BY g.modified_at DESC, g.id DESC
`); `);
const [timetableEntries] = await pool.query(` const [timetableEntries] = await pool.query(`
SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by
FROM i_schedule_entries FROM i_timetable_entries
ORDER BY schedule_group_id ASC, start_datetime ASC, id ASC ORDER BY schedule_group_id ASC, start_datetime ASC, id ASC
`); `);
@@ -50,17 +67,18 @@ async function fetchTimetablesData(pool) {
async function fetchTimetableGroupsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) { async function fetchTimetableGroupsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, { const paged = await fetchPagedRows(pool, {
selectSql: `SELECT g.id, g.name, g.short_description, g.created_at, g.modified_at, g.created_by, g.modified_by, selectSql: `SELECT g.id, g.name, g.short_description, g.timezone, g.created_at, g.modified_at, g.created_by, g.modified_by,
(SELECT COUNT(*) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id) AS entry_count, (SELECT COUNT(*) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id) AS entry_count,
(SELECT MIN(e.start_datetime) FROM i_schedule_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime (SELECT MIN(e.start_datetime) FROM i_timetable_entries e WHERE e.schedule_group_id = g.id AND e.start_datetime IS NOT NULL) AS next_start_datetime
FROM i_schedule_groups g FROM i_timetable_groups g
ORDER BY g.modified_at DESC, g.id DESC`, ORDER BY g.modified_at DESC, g.id DESC`,
countSql: 'SELECT COUNT(*) AS count FROM i_schedule_groups', countSql: 'SELECT COUNT(*) AS count FROM i_timetable_groups',
searchColumns: ['g.name', 'g.short_description'], searchColumns: ['g.name', 'g.short_description'],
searchTerm: searchTerm, searchTerm: searchTerm,
sortColumns: { sortColumns: {
name: 'g.name', name: 'g.name',
description: 'g.short_description', description: 'g.short_description',
timezone: 'g.timezone',
entries: 'entry_count', entries: 'entry_count',
next_start: 'next_start_datetime', next_start: 'next_start_datetime',
created: 'g.created_at', created: 'g.created_at',
@@ -77,7 +95,7 @@ async function fetchTimetableGroupsPage(pool, page, pageSize, searchTerm, sortKe
async function fetchTimetableGroupById(pool, id) { async function fetchTimetableGroupById(pool, id) {
const [rows] = await pool.query( const [rows] = await pool.query(
'SELECT id, name, short_description, created_at, modified_at, created_by, modified_by FROM i_schedule_groups WHERE id = ?', 'SELECT id, name, short_description, timezone, created_at, modified_at, created_by, modified_by FROM i_timetable_groups WHERE id = ?',
[id] [id]
); );
@@ -87,7 +105,7 @@ async function fetchTimetableGroupById(pool, id) {
async function fetchTimetableEntriesByGroupId(pool, timetableGroupId) { async function fetchTimetableEntriesByGroupId(pool, timetableGroupId) {
const [rows] = await pool.query( const [rows] = await pool.query(
`SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by `SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, modified_at, created_by, modified_by
FROM i_schedule_entries FROM i_timetable_entries
WHERE schedule_group_id = ? WHERE schedule_group_id = ?
ORDER BY start_datetime ASC, id ASC`, ORDER BY start_datetime ASC, id ASC`,
[timetableGroupId] [timetableGroupId]
@@ -100,6 +118,7 @@ function buildTimetableGroupPayload(req, existingTimetableGroup) {
const fallback = existingTimetableGroup || {}; const fallback = existingTimetableGroup || {};
const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'Timetable group name'); const name = validateMaxLength(req.body.name || fallback.name || '', NAME_MAX_LENGTH, 'Timetable group name');
const shortDescription = validateMaxLength(req.body.short_description || req.body.shortDescription || fallback.short_description || '', DESCRIPTION_MAX_LENGTH, 'Timetable group description'); const shortDescription = validateMaxLength(req.body.short_description || req.body.shortDescription || fallback.short_description || '', DESCRIPTION_MAX_LENGTH, 'Timetable group description');
const timezone = normalizeTimeZone(req.body.timezone || req.body.time_zone || fallback.timezone || DEFAULT_TIME_ZONE, fallback.timezone || DEFAULT_TIME_ZONE);
if (!name) { if (!name) {
const error = new Error('Timetable group name is required.'); const error = new Error('Timetable group name is required.');
@@ -109,7 +128,8 @@ function buildTimetableGroupPayload(req, existingTimetableGroup) {
return { return {
name: name, name: name,
shortDescription: shortDescription shortDescription: shortDescription,
timezone: timezone
}; };
} }
@@ -119,5 +139,6 @@ module.exports = {
fetchTimetableGroupsPage, fetchTimetableGroupsPage,
fetchTimetableGroupById, fetchTimetableGroupById,
fetchTimetableEntriesByGroupId, fetchTimetableEntriesByGroupId,
buildTimetableGroupPayload buildTimetableGroupPayload,
normalizeTimeZone
}; };
+67
View File
@@ -0,0 +1,67 @@
// Convert cached weather snapshots for display without refetching.
function convertTemperature(value, fromUnit, toUnit) {
const number = Number(value);
if (!Number.isFinite(number) || fromUnit === toUnit) return value;
const converted = toUnit === 'fahrenheit' ? number * 9 / 5 + 32 : (number - 32) * 5 / 9;
return Math.round(converted * 10) / 10;
}
function convertWind(value, fromUnit, toUnit) {
const number = Number(value);
if (!Number.isFinite(number) || fromUnit === toUnit) return value;
const metresPerSecond = fromUnit === 'mph' ? number * 0.44704 : fromUnit === 'kmh' ? number / 3.6 : number;
const converted = toUnit === 'mph' ? metresPerSecond / 0.44704 : toUnit === 'kmh' ? metresPerSecond * 3.6 : metresPerSecond;
return Math.round(converted * 10) / 10;
}
function convertPrecipitation(value, fromUnit, toUnit) {
const number = Number(value);
if (!Number.isFinite(number) || fromUnit === toUnit) return value;
const converted = toUnit === 'inch' ? number / 25.4 : number * 25.4;
return Math.round(converted * 100) / 100;
}
function temperatureUnitFromLabel(label) {
return /f/i.test(String(label || '')) ? 'fahrenheit' : 'celsius';
}
function windUnitFromLabel(label) {
const value = String(label || '').toLowerCase();
return value.includes('mph') ? 'mph' : value.includes('m/s') ? 'ms' : 'kmh';
}
function precipitationUnitFromLabel(label) {
return /in/i.test(String(label || '')) ? 'inch' : 'mm';
}
function convertField(data, fields, converter, fromUnit, toUnit) {
fields.forEach(function (field) {
if (data[field] === undefined || data[field] === null) return;
data[field] = Array.isArray(data[field])
? data[field].map(function (value) { return converter(value, fromUnit, toUnit); })
: converter(data[field], fromUnit, toUnit);
});
}
function convertWeatherSnapshot(snapshot, targetUnits) {
const source = snapshot && typeof snapshot === 'object' ? snapshot : {};
const target = Object.assign({ temperature: 'celsius', wind: 'kmh', precipitation: 'mm' }, targetUnits || {});
const result = JSON.parse(JSON.stringify(source));
const currentUnits = source.current_units || {};
const hourlyUnits = source.hourly_units || currentUnits;
const dailyUnits = source.daily_units || currentUnits;
convertField(result.current || {}, ['temperature_2m', 'apparent_temperature'], convertTemperature, temperatureUnitFromLabel(currentUnits.temperature_2m), target.temperature);
convertField(result.current || {}, ['wind_speed_10m'], convertWind, windUnitFromLabel(currentUnits.wind_speed_10m), target.wind);
convertField(result.current || {}, ['precipitation', 'rain'], convertPrecipitation, precipitationUnitFromLabel(currentUnits.precipitation), target.precipitation);
convertField(result.hourly || {}, ['temperature_2m'], convertTemperature, temperatureUnitFromLabel(hourlyUnits.temperature_2m), target.temperature);
convertField(result.hourly || {}, ['wind_speed_10m'], convertWind, windUnitFromLabel(hourlyUnits.wind_speed_10m), target.wind);
convertField(result.hourly || {}, ['precipitation'], convertPrecipitation, precipitationUnitFromLabel(hourlyUnits.precipitation), target.precipitation);
convertField(result.daily || {}, ['temperature_2m_max', 'temperature_2m_min'], convertTemperature, temperatureUnitFromLabel(dailyUnits.temperature_2m_max), target.temperature);
convertField(result.daily || {}, ['wind_speed_10m_max'], convertWind, windUnitFromLabel(dailyUnits.wind_speed_10m_max), target.wind);
convertField(result.daily || {}, ['precipitation_sum'], convertPrecipitation, precipitationUnitFromLabel(dailyUnits.precipitation_sum), target.precipitation);
return result;
}
module.exports = { convertWeatherSnapshot };
+138
View File
@@ -0,0 +1,138 @@
// Weather location data access and form normalization.
const { fetchPagedRows, validateMaxLength } = require('./utils');
const { fetchAppSettings } = require('./app-settings');
const NAME_MAX_LENGTH = 255;
const LOCATION_MAX_LENGTH = 255;
const TIMEZONE_MAX_LENGTH = 128;
const PROVIDERS = ['open-meteo', 'pirate-weather'];
const TEMPERATURE_UNITS = ['celsius', 'fahrenheit'];
const WIND_UNITS = ['kmh', 'mph', 'ms'];
const PRECIPITATION_UNITS = ['mm', 'inch'];
async function fetchWeatherLocationSuggestions(query) {
const search = validateMaxLength(query, LOCATION_MAX_LENGTH, 'Location search');
if (!search) {
return [];
}
const response = await fetch('https://geocoding-api.open-meteo.com/v1/search?name=' + encodeURIComponent(search) + '&count=8&language=en&format=json', {
headers: { Accept: 'application/json', 'User-Agent': 'Pulse Signage weather location lookup' }
});
if (!response.ok) {
throw new Error('Weather location lookup failed.');
}
const data = await response.json();
return (Array.isArray(data.results) ? data.results : []).map(function (result) {
return {
label: [result.name, result.admin1, result.country].filter(Boolean).join(', '),
latitude: Number(result.latitude),
longitude: Number(result.longitude),
timezone: String(result.timezone || '')
};
}).filter(function (result) {
return result.label && Number.isFinite(result.latitude) && Number.isFinite(result.longitude) && result.timezone;
});
}
function normalizeChoice(value, choices, fallback) {
const normalized = String(value || '').trim().toLowerCase();
return choices.includes(normalized) ? normalized : fallback;
}
async function fetchWeatherLocationsPage(pool, page, pageSize, searchTerm, sortKey, sortDirection) {
const paged = await fetchPagedRows(pool, {
selectSql: 'SELECT id, name, location_label, latitude, longitude, timezone, provider, temperature_unit, wind_unit, precipitation_unit, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, created_at, modified_at FROM i_weather_locations ORDER BY modified_at DESC, id DESC',
countSql: 'SELECT COUNT(*) AS count FROM i_weather_locations',
searchColumns: ['name', 'location_label', 'timezone', 'provider'],
searchTerm: searchTerm,
sortColumns: {
name: 'name',
location: 'location_label',
provider: 'provider',
interval: ['update_interval_value', 'update_interval_unit'],
last_pulled: 'last_pulled_at',
modified: 'modified_at'
},
sortKey: sortKey,
sortDirection: sortDirection,
page: page,
pageSize: pageSize
});
return Object.assign({ weatherLocations: paged.rows }, paged);
}
async function fetchWeatherLocationsData(pool) {
const [rows] = await pool.query('SELECT id, name, location_label, latitude, longitude, timezone, provider, temperature_unit, wind_unit, precipitation_unit, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_json, created_at, modified_at FROM i_weather_locations ORDER BY modified_at DESC, id DESC');
return { weatherLocations: rows };
}
async function fetchWeatherLocationById(pool, id) {
const [rows] = await pool.query('SELECT id, name, location_label, latitude, longitude, timezone, provider, temperature_unit, wind_unit, precipitation_unit, enabled, update_interval_value, update_interval_unit, last_pulled_at, last_pull_error, last_response_json, created_at, modified_at, created_by, modified_by FROM i_weather_locations WHERE id = ?', [id]);
return rows[0] || null;
}
async function fetchWeatherLocationForecast(pool, location) {
const source = location || {};
const settings = await fetchAppSettings(pool);
const latitude = Number(source.latitude);
const longitude = Number(source.longitude);
const temperatureUnit = source.temperature_unit === 'fahrenheit' ? 'fahrenheit' : 'celsius';
const windUnit = source.wind_unit === 'mph' ? 'mph' : source.wind_unit === 'ms' ? 'ms' : 'kmh';
const precipitationUnit = source.precipitation_unit === 'inch' ? 'inch' : 'mm';
let url;
let headers = { Accept: 'application/json', 'User-Agent': 'Pulse Signage weather reader' };
if (source.provider === 'pirate-weather') {
const apiKey = String(settings['weather.pirate_weather_api_key'] || '').trim();
if (!apiKey) throw new Error('Pirate Weather API key is not configured.');
url = 'https://api.pirateweather.net/forecast/' + encodeURIComponent(apiKey) + '/' + latitude + ',' + longitude + '?units=' + (temperatureUnit === 'fahrenheit' ? 'us' : 'si');
} else {
const params = new URLSearchParams({ latitude: String(latitude), longitude: String(longitude), timezone: String(source.timezone || 'auto'), forecast_days: '7', forecast_hours: '24', current: 'temperature_2m,relative_humidity_2m,apparent_temperature,is_day,precipitation,rain,weather_code,wind_speed_10m,wind_direction_10m,uv_index,cloud_cover', hourly: 'temperature_2m,precipitation_probability,precipitation,weather_code,wind_speed_10m,uv_index,cloud_cover', daily: 'weather_code,temperature_2m_max,temperature_2m_min,sunrise,sunset,precipitation_probability_max,precipitation_sum,wind_speed_10m_max,uv_index_max,cloud_cover_mean', temperature_unit: temperatureUnit, wind_speed_unit: windUnit, precipitation_unit: precipitationUnit });
const apiKey = String(settings['weather.open_meteo_api_key'] || '').trim();
if (apiKey) params.set('apikey', apiKey);
url = 'https://api.open-meteo.com/v1/forecast?' + params.toString();
}
const response = await fetch(url, { headers: headers });
if (!response.ok) throw new Error('Weather provider returned HTTP ' + response.status + '.');
const snapshot = await response.json();
return { snapshot: snapshot, responseJson: JSON.stringify(snapshot), fetchedAt: new Date() };
}
function buildWeatherLocationPayload(req, existingLocation) {
const body = req && req.body ? req.body : {};
const fallback = existingLocation || {};
const name = validateMaxLength(body.name || fallback.name || '', NAME_MAX_LENGTH, 'Weather location name');
const locationLabel = validateMaxLength(body.location_label || fallback.location_label || '', LOCATION_MAX_LENGTH, 'Location label');
const latitude = Number(body.latitude !== undefined ? body.latitude : fallback.latitude);
const longitude = Number(body.longitude !== undefined ? body.longitude : fallback.longitude);
const timezone = validateMaxLength(body.timezone || fallback.timezone || '', TIMEZONE_MAX_LENGTH, 'Timezone');
const provider = normalizeChoice(body.provider || fallback.provider, PROVIDERS, 'open-meteo');
const temperatureUnit = normalizeChoice(body.temperature_unit || fallback.temperature_unit, TEMPERATURE_UNITS, 'celsius');
const windUnit = normalizeChoice(body.wind_unit || fallback.wind_unit, WIND_UNITS, 'kmh');
const precipitationUnit = normalizeChoice(body.precipitation_unit || fallback.precipitation_unit, PRECIPITATION_UNITS, 'mm');
const updateIntervalValue = Number(body.update_interval_value || fallback.update_interval_value || 30);
const updateIntervalUnit = normalizeChoice(body.update_interval_unit || fallback.update_interval_unit, ['minutes', 'hours'], 'minutes');
if (!name || !locationLabel || !timezone) {
const error = new Error('Name, location label, and timezone are required.');
error.statusCode = 400;
throw error;
}
if (!Number.isFinite(latitude) || latitude < -90 || latitude > 90 || !Number.isFinite(longitude) || longitude < -180 || longitude > 180) {
const error = new Error('Latitude must be between -90 and 90, and longitude must be between -180 and 180.');
error.statusCode = 400;
throw error;
}
if (!Number.isInteger(updateIntervalValue) || updateIntervalValue < 1 || updateIntervalValue > 1440) {
const error = new Error('Update interval must be a whole number between 1 and 1440.');
error.statusCode = 400;
throw error;
}
return { name, locationLabel, latitude, longitude, timezone, provider, temperatureUnit, windUnit, precipitationUnit, updateIntervalValue, updateIntervalUnit };
}
module.exports = { fetchWeatherLocationsData, fetchWeatherLocationsPage, fetchWeatherLocationById, fetchWeatherLocationSuggestions, fetchWeatherLocationForecast, buildWeatherLocationPayload, PROVIDERS, TEMPERATURE_UNITS, WIND_UNITS, PRECIPITATION_UNITS };
+33 -10
View File
@@ -15,11 +15,19 @@ async function bootstrapDatabase(pool) {
} }
for (const permission of PERMISSIONS) { for (const permission of PERMISSIONS) {
await pool.query(
`UPDATE a_permissions
SET name = ?, section_name = ?, description = ?, modified_by = ?
WHERE permission_key = ?`,
[permission.name, permission.sectionName, permission.description || null, null, permission.key]
);
await pool.query( await pool.query(
`INSERT INTO a_permissions (permission_key, name, section_name, description, created_by, modified_by) `INSERT INTO a_permissions (permission_key, name, section_name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, ?, ?) SELECT ?, ?, ?, ?, ?, ?
ON DUPLICATE KEY UPDATE name = VALUES(name), section_name = VALUES(section_name), description = VALUES(description), modified_by = VALUES(modified_by)` , WHERE NOT EXISTS (
[permission.key, permission.name, permission.sectionName, permission.description || null, null, null] SELECT 1 FROM a_permissions WHERE permission_key = ?
)`,
[permission.key, permission.name, permission.sectionName, permission.description || null, null, null, permission.key]
); );
} }
@@ -35,22 +43,37 @@ async function bootstrapDatabase(pool) {
); );
} }
await pool.query('UPDATE a_users SET name = username WHERE name IS NULL OR name = ""'); const [legacyRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', ['administrators']);
const [currentRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', [DEFAULT_ROLE.key]);
if (legacyRoleRows.length && !currentRoleRows.length) {
await pool.query(
`UPDATE a_roles
SET role_key = ?, name = ?, description = ?, modified_by = ?
WHERE role_key = ?`,
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, 'administrators']
);
}
await pool.query( await pool.query(
`INSERT INTO a_roles (role_key, name, description, created_by, modified_by) `INSERT INTO a_roles (role_key, name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, ?) SELECT ?, ?, ?, ?, ?
ON DUPLICATE KEY UPDATE name = VALUES(name), description = VALUES(description), modified_by = VALUES(modified_by)`, WHERE NOT EXISTS (
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, null] SELECT 1 FROM a_roles WHERE role_key = ?
)`,
[DEFAULT_ROLE.key, DEFAULT_ROLE.name, DEFAULT_ROLE.description || null, null, null, DEFAULT_ROLE.key]
); );
const [defaultRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', [DEFAULT_ROLE.key]); const [defaultRoleRows] = await pool.query('SELECT id FROM a_roles WHERE role_key = ? LIMIT 1', [DEFAULT_ROLE.key]);
const defaultRoleId = defaultRoleRows.length ? Number(defaultRoleRows[0].id) : null; const defaultRoleId = defaultRoleRows.length ? Number(defaultRoleRows[0].id) : null;
if (defaultRoleId) { if (defaultRoleId) {
await pool.query( await pool.query(
`INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by) `INSERT INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT ?, id, NULL, NULL FROM a_permissions`, SELECT ?, permissions.id, NULL, NULL
[defaultRoleId] FROM a_permissions permissions
LEFT JOIN a_role_permissions existing
ON existing.role_id = ? AND existing.permission_id = permissions.id
WHERE existing.id IS NULL`,
[defaultRoleId, defaultRoleId]
); );
} }
+25 -2
View File
@@ -1,3 +1,5 @@
// Database pool setup and lifecycle maintenance for persisted onboarding devices.
const mysql = require('mysql2/promise'); const mysql = require('mysql2/promise');
function createPool() { function createPool() {
@@ -15,13 +17,34 @@ function createPool() {
} }
async function pruneStaleOnboardingDevices(pool) { async function pruneStaleOnboardingDevices(pool) {
// Uncompleted pairings expire quickly; completed bindings use their persisted heartbeat instead.
await pool.query( await pool.query(
`DELETE FROM d_onboarding_devices `DELETE FROM d_onboarding_devices
WHERE modified_at < (CURRENT_TIMESTAMP - INTERVAL 1 MINUTE)` WHERE (screen_id IS NULL
AND modified_at < (CURRENT_TIMESTAMP - INTERVAL 15 MINUTE))
OR (last_seen_at IS NOT NULL
AND last_seen_at < (CURRENT_TIMESTAMP - INTERVAL 24 HOUR))`
);
}
async function touchOnboardingDeviceLastSeen(pool, deviceId) {
const deviceIds = (Array.isArray(deviceId) ? deviceId : [deviceId])
.map(function (value) { return String(value || '').trim(); })
.filter(Boolean);
if (!deviceIds.length) {
return;
}
await pool.query(
`UPDATE d_onboarding_devices
SET last_seen_at = CURRENT_TIMESTAMP
WHERE device_id IN (${deviceIds.map(function () { return '?'; }).join(', ')})`,
deviceIds
); );
} }
module.exports = { module.exports = {
createPool, createPool,
pruneStaleOnboardingDevices pruneStaleOnboardingDevices,
touchOnboardingDeviceLastSeen
}; };
+101 -11
View File
@@ -1,3 +1,8 @@
// Schema initialization, migration execution, and database bootstrap helpers.
const { version: appVersion } = require('#root/package.json');
const { compareVersions, detectSchemaVersion, getPendingMigrations, recordSchemaVersion, runMigrations } = require('./migrations');
// Snapshot only: keep this file aligned with the current schema state. // Snapshot only: keep this file aligned with the current schema state.
async function ensureSchema(pool, options) { async function ensureSchema(pool, options) {
const schemaLockName = 'pulse_signage_schema_lock'; const schemaLockName = 'pulse_signage_schema_lock';
@@ -12,6 +17,12 @@ async function ensureSchema(pool, options) {
} }
try { try {
const currentVersion = await detectSchemaVersion(pool);
const pendingMigrations = await getPendingMigrations(pool, { currentVersion: currentVersion });
const updateRequired = pendingMigrations.length > 0;
console.info('[schema] previous=' + currentVersion + ' current=' + appVersion + ' update=' + (updateRequired ? 'yes' : 'no'));
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS c_canvas_sizes ( CREATE TABLE IF NOT EXISTS c_canvas_sizes (
id INT AUTO_INCREMENT PRIMARY KEY, id INT AUTO_INCREMENT PRIMARY KEY,
@@ -48,6 +59,7 @@ async function ensureSchema(pool, options) {
canvas_size_id INT NULL, canvas_size_id INT NULL,
background_image_path VARCHAR(512) NULL, background_image_path VARCHAR(512) NULL,
background_color VARCHAR(32) NULL, background_color VARCHAR(32) NULL,
background_gradient LONGTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -175,13 +187,14 @@ async function ensureSchema(pool, options) {
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS d_announcement_screens ( CREATE TABLE IF NOT EXISTS d_announcement_screens (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
announcement_id INT NOT NULL, announcement_id INT NOT NULL,
screen_id INT NOT NULL, screen_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL, modified_by INT NULL,
PRIMARY KEY (announcement_id, screen_id), UNIQUE KEY uq_announcement_screens_pair (announcement_id, screen_id),
INDEX idx_announcement_screens_screen_id (screen_id), INDEX idx_announcement_screens_screen_id (screen_id),
CONSTRAINT fk_announcement_screens_announcement FOREIGN KEY (announcement_id) REFERENCES d_announcements(id) ON DELETE CASCADE, CONSTRAINT fk_announcement_screens_announcement FOREIGN KEY (announcement_id) REFERENCES d_announcements(id) ON DELETE CASCADE,
CONSTRAINT fk_announcement_screens_screen FOREIGN KEY (screen_id) REFERENCES d_screens(id) ON DELETE CASCADE CONSTRAINT fk_announcement_screens_screen FOREIGN KEY (screen_id) REFERENCES d_screens(id) ON DELETE CASCADE
@@ -193,9 +206,11 @@ async function ensureSchema(pool, options) {
id INT AUTO_INCREMENT PRIMARY KEY, id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL, name VARCHAR(255) NOT NULL,
feed_url VARCHAR(1024) NOT NULL, feed_url VARCHAR(1024) NOT NULL,
enabled TINYINT(1) NOT NULL DEFAULT 1,
update_interval_value INT NOT NULL DEFAULT 60, update_interval_value INT NOT NULL DEFAULT 60,
update_interval_unit VARCHAR(10) NOT NULL DEFAULT 'minutes', update_interval_unit VARCHAR(10) NOT NULL DEFAULT 'minutes',
item_limit INT NOT NULL DEFAULT 1, item_limit INT NOT NULL DEFAULT 1,
last_pulled_at DATETIME NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -223,6 +238,21 @@ async function ensureSchema(pool, options) {
id INT AUTO_INCREMENT PRIMARY KEY, id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL, name VARCHAR(255) NOT NULL,
api_url VARCHAR(1024) NOT NULL, api_url VARCHAR(1024) NOT NULL,
request_method VARCHAR(10) NOT NULL DEFAULT 'GET',
request_body_json MEDIUMTEXT NULL,
auth_method VARCHAR(32) NOT NULL DEFAULT 'none',
auth_username VARCHAR(255) NULL,
auth_password MEDIUMTEXT NULL,
auth_bearer_token MEDIUMTEXT NULL,
auth_header_name VARCHAR(255) NULL,
auth_header_value MEDIUMTEXT NULL,
token_url VARCHAR(1024) NULL,
token_request_body_json MEDIUMTEXT NULL,
token_response_path VARCHAR(255) NULL DEFAULT 'access_token',
token_header_name VARCHAR(255) NULL DEFAULT 'Authorization',
token_header_prefix VARCHAR(64) NULL DEFAULT 'Bearer',
items_path VARCHAR(255) NULL,
enabled TINYINT(1) NOT NULL DEFAULT 1,
update_interval_value INT NOT NULL DEFAULT 60, update_interval_value INT NOT NULL DEFAULT 60,
update_interval_unit VARCHAR(10) NOT NULL DEFAULT 'minutes', update_interval_unit VARCHAR(10) NOT NULL DEFAULT 'minutes',
last_pulled_at TIMESTAMP NULL, last_pulled_at TIMESTAMP NULL,
@@ -238,10 +268,37 @@ async function ensureSchema(pool, options) {
`); `);
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS i_schedule_groups ( CREATE TABLE IF NOT EXISTS i_weather_locations (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL UNIQUE,
location_label VARCHAR(255) NOT NULL,
latitude DECIMAL(9,6) NOT NULL,
longitude DECIMAL(9,6) NOT NULL,
timezone VARCHAR(128) NOT NULL,
provider VARCHAR(32) NOT NULL DEFAULT 'open-meteo',
temperature_unit VARCHAR(16) NOT NULL DEFAULT 'celsius',
wind_unit VARCHAR(16) NOT NULL DEFAULT 'kmh',
precipitation_unit VARCHAR(16) NOT NULL DEFAULT 'mm',
enabled TINYINT(1) NOT NULL DEFAULT 1,
update_interval_value INT NOT NULL DEFAULT 30,
update_interval_unit VARCHAR(16) NOT NULL DEFAULT 'minutes',
last_pulled_at DATETIME NULL,
last_pull_error VARCHAR(1024) NULL,
last_response_json MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
INDEX idx_weather_locations_modified_at (modified_at)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS i_timetable_groups (
id INT AUTO_INCREMENT PRIMARY KEY, id INT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL, name VARCHAR(255) NOT NULL,
short_description VARCHAR(255) NULL, short_description VARCHAR(255) NULL,
timezone VARCHAR(64) NOT NULL DEFAULT 'Europe/London',
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -250,7 +307,7 @@ async function ensureSchema(pool, options) {
`); `);
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS i_schedule_entries ( CREATE TABLE IF NOT EXISTS i_timetable_entries (
id INT AUTO_INCREMENT PRIMARY KEY, id INT AUTO_INCREMENT PRIMARY KEY,
schedule_group_id INT NOT NULL, schedule_group_id INT NOT NULL,
title VARCHAR(255) NOT NULL, title VARCHAR(255) NOT NULL,
@@ -261,20 +318,22 @@ async function ensureSchema(pool, options) {
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL, modified_by INT NULL,
CONSTRAINT fk_schedule_entries_group FOREIGN KEY (schedule_group_id) REFERENCES i_schedule_groups(id) ON DELETE CASCADE, CONSTRAINT fk_timetable_entries_group FOREIGN KEY (schedule_group_id) REFERENCES i_timetable_groups(id) ON DELETE CASCADE,
INDEX idx_schedule_entries_group_start (schedule_group_id, start_datetime) INDEX idx_timetable_entries_group_start (schedule_group_id, start_datetime)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`); `);
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS d_onboarding_devices ( CREATE TABLE IF NOT EXISTS d_onboarding_devices (
device_id VARCHAR(128) PRIMARY KEY, id BIGINT AUTO_INCREMENT PRIMARY KEY,
device_id VARCHAR(128) NOT NULL UNIQUE,
client_name VARCHAR(255) NULL, client_name VARCHAR(255) NULL,
screen_id INT NULL, screen_id INT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL, modified_by INT NULL,
last_seen_at TIMESTAMP NULL,
CONSTRAINT fk_player_onboarding_devices_screen FOREIGN KEY (screen_id) REFERENCES d_screens(id) ON DELETE SET NULL CONSTRAINT fk_player_onboarding_devices_screen FOREIGN KEY (screen_id) REFERENCES d_screens(id) ON DELETE SET NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`); `);
@@ -287,6 +346,8 @@ async function ensureSchema(pool, options) {
password_hash CHAR(64) NOT NULL, password_hash CHAR(64) NOT NULL,
password_salt VARCHAR(64) NOT NULL, password_salt VARCHAR(64) NOT NULL,
password_iterations INT NOT NULL, password_iterations INT NOT NULL,
must_change_password TINYINT(1) NOT NULL DEFAULT 0,
account_locked TINYINT(1) NOT NULL DEFAULT 0,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
@@ -323,13 +384,14 @@ async function ensureSchema(pool, options) {
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS a_role_permissions ( CREATE TABLE IF NOT EXISTS a_role_permissions (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
role_id INT NOT NULL, role_id INT NOT NULL,
permission_id INT NOT NULL, permission_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL, modified_by INT NULL,
PRIMARY KEY (role_id, permission_id), UNIQUE KEY uq_role_permissions_pair (role_id, permission_id),
CONSTRAINT fk_role_permissions_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE, CONSTRAINT fk_role_permissions_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE,
CONSTRAINT fk_role_permissions_permission FOREIGN KEY (permission_id) REFERENCES a_permissions(id) ON DELETE CASCADE CONSTRAINT fk_role_permissions_permission FOREIGN KEY (permission_id) REFERENCES a_permissions(id) ON DELETE CASCADE
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
@@ -337,13 +399,14 @@ async function ensureSchema(pool, options) {
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS a_user_roles ( CREATE TABLE IF NOT EXISTS a_user_roles (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
user_id INT NOT NULL, user_id INT NOT NULL,
role_id INT NOT NULL, role_id INT NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP, modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL, modified_by INT NULL,
PRIMARY KEY (user_id, role_id), UNIQUE KEY uq_user_roles_pair (user_id, role_id),
CONSTRAINT fk_user_roles_user FOREIGN KEY (user_id) REFERENCES a_users(id) ON DELETE CASCADE, CONSTRAINT fk_user_roles_user FOREIGN KEY (user_id) REFERENCES a_users(id) ON DELETE CASCADE,
CONSTRAINT fk_user_roles_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE CONSTRAINT fk_user_roles_role FOREIGN KEY (role_id) REFERENCES a_roles(id) ON DELETE CASCADE
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
@@ -351,8 +414,11 @@ async function ensureSchema(pool, options) {
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS a_sessions ( CREATE TABLE IF NOT EXISTS a_sessions (
session_hash CHAR(64) PRIMARY KEY, id BIGINT AUTO_INCREMENT PRIMARY KEY,
session_hash CHAR(64) NOT NULL UNIQUE,
user_id INT NOT NULL, user_id INT NOT NULL,
ip_address VARCHAR(255) NULL,
user_agent VARCHAR(512) NULL,
expires_at DATETIME NOT NULL, expires_at DATETIME NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP, created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL, created_by INT NULL,
@@ -362,6 +428,18 @@ async function ensureSchema(pool, options) {
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`); `);
await pool.query(`
CREATE TABLE IF NOT EXISTS a_login_attempts (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
rate_key VARCHAR(600) NOT NULL UNIQUE,
failed_count INT NOT NULL DEFAULT 0,
last_failed_at DATETIME NULL,
locked_until DATETIME NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(` await pool.query(`
CREATE TABLE IF NOT EXISTS o_background_tasks ( CREATE TABLE IF NOT EXISTS o_background_tasks (
id BIGINT AUTO_INCREMENT PRIMARY KEY, id BIGINT AUTO_INCREMENT PRIMARY KEY,
@@ -383,8 +461,20 @@ async function ensureSchema(pool, options) {
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci ) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`); `);
const { runMigrations } = require('./migrations'); await pool.query(`
await runMigrations(pool, options); CREATE TABLE IF NOT EXISTS o_app_settings (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
setting_key VARCHAR(191) NOT NULL UNIQUE,
setting_value JSON NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await runMigrations(pool, Object.assign({}, options, { currentVersion: currentVersion }));
await recordSchemaVersion(pool, appVersion);
} finally { } finally {
await pool.query('SELECT RELEASE_LOCK(?)', [schemaLockName]).catch(function () { await pool.query('SELECT RELEASE_LOCK(?)', [schemaLockName]).catch(function () {
}); });
+472 -30
View File
@@ -1,4 +1,9 @@
// Ordered database migrations kept independent from the application version.
const { version: appVersion } = require('#root/package.json'); const { version: appVersion } = require('#root/package.json');
const TIMETABLE_TIME_ZONE = 'Europe/London';
const APP_STATE_TABLE = 'o_app_state';
const APP_STATE_SCHEMA_VERSION_KEY = 'schema_version';
const VERSIONED_MIGRATIONS = [ const VERSIONED_MIGRATIONS = [
{ {
@@ -22,32 +27,32 @@ const VERSIONED_MIGRATIONS = [
// Store the player pointer on screens so we can resolve the player without needing a player-side screen_id. // Store the player pointer on screens so we can resolve the player without needing a player-side screen_id.
// This is the singleton-player shortcut; a multi-player model should make this relational instead of hardcoded to '1'. // This is the singleton-player shortcut; a multi-player model should make this relational instead of hardcoded to '1'.
if (!(await columnExists(pool, 'd_screens', 'player_id'))) { if (!(await columnExists(pool, 'd_screens', 'player_id'))) {
await pool.query("ALTER TABLE d_screens ADD COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id"); await pool.query("ALTER TABLE d_screens ADD COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
} else { } else {
await pool.query("UPDATE d_screens SET player_id = '1' WHERE player_id IS NULL OR player_id <> '1'"); await pool.query("UPDATE d_screens SET player_id = '1' WHERE player_id IS NULL OR player_id <> '1'");
const [playerColumnNullableRows] = await pool.query( const [playerColumnNullableRows] = await pool.query(
`SELECT COUNT(*) AS nullable_count `SELECT COUNT(*) AS nullable_count
FROM information_schema.COLUMNS FROM information_schema.COLUMNS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens'
AND COLUMN_NAME = 'player_id'
AND IS_NULLABLE = 'YES'`
);
if (Number(playerColumnNullableRows && playerColumnNullableRows[0] && playerColumnNullableRows[0].nullable_count) > 0) {
await pool.query("ALTER TABLE d_screens MODIFY COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
}
}
const [screenPlayerUniqueRows] = await pool.query(
`SELECT COUNT(*) AS index_count
FROM information_schema.STATISTICS
WHERE TABLE_SCHEMA = DATABASE() WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens' AND TABLE_NAME = 'd_screens'
AND INDEX_NAME = 'uq_screens_player_id'` AND COLUMN_NAME = 'player_id'
AND IS_NULLABLE = 'YES'`
); );
if (Number(screenPlayerUniqueRows && screenPlayerUniqueRows[0] && screenPlayerUniqueRows[0].index_count) > 0) { if (Number(playerColumnNullableRows && playerColumnNullableRows[0] && playerColumnNullableRows[0].nullable_count) > 0) {
await pool.query('ALTER TABLE d_screens DROP INDEX uq_screens_player_id'); await pool.query("ALTER TABLE d_screens MODIFY COLUMN player_id VARCHAR(128) NOT NULL DEFAULT '1' AFTER playlist_id");
}
}
const [screenPlayerUniqueRows] = await pool.query(
`SELECT COUNT(*) AS index_count
FROM information_schema.STATISTICS
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = 'd_screens'
AND INDEX_NAME = 'uq_screens_player_id'`
);
if (Number(screenPlayerUniqueRows && screenPlayerUniqueRows[0] && screenPlayerUniqueRows[0].index_count) > 0) {
await pool.query('ALTER TABLE d_screens DROP INDEX uq_screens_player_id');
} }
// Recreate the screen-to-player foreign key after the column exists and legacy data is copied over. // Recreate the screen-to-player foreign key after the column exists and legacy data is copied over.
@@ -56,7 +61,6 @@ const VERSIONED_MIGRATIONS = [
if (await columnExists(pool, 'c_template_regions', 'font_family')) { if (await columnExists(pool, 'c_template_regions', 'font_family')) {
await pool.query('ALTER TABLE c_template_regions DROP COLUMN font_family'); await pool.query('ALTER TABLE c_template_regions DROP COLUMN font_family');
} }
} }
}, },
{ {
@@ -276,6 +280,7 @@ const VERSIONED_MIGRATIONS = [
await pool.query('RENAME TABLE d_players_rebuild TO d_players'); await pool.query('RENAME TABLE d_players_rebuild TO d_players');
await pool.query('ALTER TABLE d_screens MODIFY COLUMN player_id INT NULL AFTER playlist_id'); await pool.query('ALTER TABLE d_screens MODIFY COLUMN player_id INT NULL AFTER playlist_id');
return;
} }
}, },
{ {
@@ -295,6 +300,267 @@ const VERSIONED_MIGRATIONS = [
await dropForeignKeyIfExists(pool, 'd_screens', 'player_id'); await dropForeignKeyIfExists(pool, 'd_screens', 'player_id');
await dropColumnIfExists(pool, 'd_screens', 'player_id'); await dropColumnIfExists(pool, 'd_screens', 'player_id');
} }
},
{
version: '2.6.16',
label: 'v2.6.16 timetable timezone schema',
run: async function (pool) {
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const tableName = timetableGroupsExists ? 'i_timetable_groups' : scheduleGroupsExists ? 'i_schedule_groups' : null;
if (!tableName) {
return;
}
await ensureColumn(pool, tableName, 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
}
},
{
version: '2.6.17',
label: 'v2.6.17 timetable europe/london conversion',
run: async function (pool) {
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const timetableEntriesExists = await tableExists(pool, 'i_timetable_entries');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const scheduleEntriesExists = await tableExists(pool, 'i_schedule_entries');
const groupTableName = timetableGroupsExists ? 'i_timetable_groups' : scheduleGroupsExists ? 'i_schedule_groups' : null;
const entryTableName = timetableEntriesExists ? 'i_timetable_entries' : scheduleEntriesExists ? 'i_schedule_entries' : null;
if (!groupTableName || !entryTableName) {
return;
}
await ensureColumn(pool, groupTableName, 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
await pool.query('UPDATE ' + groupTableName + ' SET timezone = ?', [TIMETABLE_TIME_ZONE]);
const [rows] = await pool.query('SELECT id, start_datetime, end_datetime FROM ' + entryTableName + ' ORDER BY id ASC');
for (const row of rows) {
const startDate = convertMigrationDateTimeFromTimeZone(row.start_datetime, TIMETABLE_TIME_ZONE);
const endDate = row.end_datetime ? convertMigrationDateTimeFromTimeZone(row.end_datetime, TIMETABLE_TIME_ZONE) : null;
await pool.query(
'UPDATE ' + entryTableName + ' SET start_datetime = ?, end_datetime = ? WHERE id = ?',
[formatMigrationDateTimeUtc(startDate), endDate ? formatMigrationDateTimeUtc(endDate) : null, row.id]
);
}
}
},
{
version: '2.6.18',
label: 'v2.6.18 timetable table rename',
run: async function (pool) {
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
if (scheduleGroupsExists) {
if (!timetableGroupsExists) {
await pool.query('RENAME TABLE i_schedule_groups TO i_timetable_groups, i_schedule_entries TO i_timetable_entries');
await ensureColumn(pool, 'i_timetable_groups', 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
return;
}
await ensureColumn(pool, 'i_timetable_groups', 'timezone', "VARCHAR(64) NOT NULL DEFAULT 'Europe/London'", 'short_description');
await pool.query(`
INSERT IGNORE INTO i_timetable_groups (id, name, short_description, timezone, created_at, created_by, modified_at, modified_by)
SELECT id, name, short_description, 'Europe/London' AS timezone, created_at, created_by, modified_at, modified_by
FROM i_schedule_groups
ORDER BY id ASC
`);
await pool.query(`
INSERT IGNORE INTO i_timetable_entries (id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, created_by, modified_at, modified_by)
SELECT id, schedule_group_id, title, short_description, start_datetime, end_datetime, created_at, created_by, modified_at, modified_by
FROM i_schedule_entries
ORDER BY schedule_group_id ASC, start_datetime ASC, id ASC
`);
const [groupRows] = await pool.query('SELECT COALESCE(MAX(id), 0) AS max_id FROM i_timetable_groups');
const [entryRows] = await pool.query('SELECT COALESCE(MAX(id), 0) AS max_id FROM i_timetable_entries');
const nextGroupId = Number(groupRows && groupRows[0] && groupRows[0].max_id) + 1;
const nextEntryId = Number(entryRows && entryRows[0] && entryRows[0].max_id) + 1;
await pool.query('ALTER TABLE i_timetable_groups AUTO_INCREMENT = ' + nextGroupId);
await pool.query('ALTER TABLE i_timetable_entries AUTO_INCREMENT = ' + nextEntryId);
await pool.query('DROP TABLE i_schedule_entries');
await pool.query('DROP TABLE i_schedule_groups');
}
}
},
{
version: '2.8.0',
label: 'v2.8.0 combined application schema',
run: async function (pool) {
await pool.query(`
CREATE TABLE IF NOT EXISTS o_app_settings (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
setting_key VARCHAR(191) NOT NULL UNIQUE,
setting_value JSON NOT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(`
CREATE TABLE IF NOT EXISTS o_app_state (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
state_key VARCHAR(191) NOT NULL UNIQUE,
state_value MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
const numericIdTables = [
['d_announcement_screens', 'uq_announcement_screens_pair', '(announcement_id, screen_id)'],
['d_onboarding_devices', 'uq_onboarding_devices_device_id', '(device_id)'],
['a_role_permissions', 'uq_role_permissions_pair', '(role_id, permission_id)'],
['a_user_roles', 'uq_user_roles_pair', '(user_id, role_id)'],
['a_sessions', 'uq_sessions_hash', '(session_hash)'],
['o_app_state', 'uq_app_state_key', '(state_key)']
];
for (const [tableName, uniqueKeyName, uniqueColumns] of numericIdTables) {
if (!(await tableExists(pool, tableName)) || await columnExists(pool, tableName, 'id')) {
continue;
}
await pool.query('ALTER TABLE ' + tableName + ' DROP PRIMARY KEY, ADD COLUMN id BIGINT NOT NULL AUTO_INCREMENT PRIMARY KEY FIRST, ADD UNIQUE KEY ' + uniqueKeyName + ' ' + uniqueColumns);
}
await ensureColumn(pool, 'a_users', 'must_change_password', 'TINYINT(1) NOT NULL DEFAULT 0', 'password_iterations');
await pool.query(`
CREATE TABLE IF NOT EXISTS a_login_attempts (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
rate_key VARCHAR(600) NOT NULL UNIQUE,
failed_count INT NOT NULL DEFAULT 0,
last_failed_at DATETIME NULL,
locked_until DATETIME NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await ensureColumn(pool, 'a_users', 'account_locked', 'TINYINT(1) NOT NULL DEFAULT 0', 'must_change_password');
await ensureColumn(pool, 'a_sessions', 'ip_address', 'VARCHAR(255) NULL', 'user_id');
await ensureColumn(pool, 'a_sessions', 'user_agent', 'VARCHAR(512) NULL', 'ip_address');
await pool.query(`
CREATE TABLE IF NOT EXISTS o_audit_events (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
occurred_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
category VARCHAR(64) NOT NULL,
event_type VARCHAR(128) NOT NULL,
actor_user_id INT NULL,
target_type VARCHAR(64) NULL,
target_id VARCHAR(191) NULL,
target_label VARCHAR(255) NULL,
ip_address VARCHAR(255) NULL,
user_agent VARCHAR(512) NULL,
details_json JSON NULL,
INDEX idx_audit_events_occurred_at (occurred_at),
INDEX idx_audit_events_category_type (category, event_type),
INDEX idx_audit_events_actor (actor_user_id),
INDEX idx_audit_events_target (target_type, target_id)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await pool.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
VALUES (?, ?, NULL, NULL) ON DUPLICATE KEY UPDATE setting_value = VALUES(setting_value)`,
['audit.retention_days', JSON.stringify(30)]
);
const settings = [
['audit.enabled', true],
['audit.categories', ['authentication', 'security', 'sessions', 'users', 'roles', 'system-settings']],
['audit.include_request_metadata', true]
];
for (const [key, value] of settings) {
await pool.query(
`INSERT INTO o_app_settings (setting_key, setting_value, created_by, modified_by)
VALUES (?, ?, NULL, NULL) ON DUPLICATE KEY UPDATE setting_value = VALUES(setting_value)`,
[key, JSON.stringify(value)]
);
}
await pool.query(
`INSERT IGNORE INTO a_permissions
(permission_key, name, section_name, description, created_by, modified_by)
VALUES (?, ?, ?, ?, NULL, NULL)`,
['audit-log.allow', 'Audit log', 'Settings', 'Download filtered audit events.']
);
await pool.query(
`INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT roles.id, permissions.id, NULL, NULL
FROM a_roles roles
CROSS JOIN a_permissions permissions
WHERE roles.role_key = 'administrators'
AND permissions.permission_key = 'audit-log.allow'`
);
}
},
{
version: '2.8.7',
label: 'v2.8.7 API request and token authentication schema',
run: async function (pool) {
await ensureColumn(pool, 'i_api_sources', 'request_method', "VARCHAR(10) NOT NULL DEFAULT 'GET'", 'api_url');
await ensureColumn(pool, 'i_api_sources', 'request_body_json', 'MEDIUMTEXT NULL', 'request_method');
await ensureColumn(pool, 'i_api_sources', 'token_url', 'VARCHAR(1024) NULL', 'auth_header_value');
await ensureColumn(pool, 'i_api_sources', 'token_request_body_json', 'MEDIUMTEXT NULL', 'token_url');
await ensureColumn(pool, 'i_api_sources', 'token_response_path', "VARCHAR(255) NULL DEFAULT 'access_token'", 'token_request_body_json');
await ensureColumn(pool, 'i_api_sources', 'token_header_name', "VARCHAR(255) NULL DEFAULT 'Authorization'", 'token_response_path');
await ensureColumn(pool, 'i_api_sources', 'token_header_prefix', "VARCHAR(64) NULL DEFAULT 'Bearer'", 'token_header_name');
}
},
{
version: '2.8.8',
label: 'v2.8.8 weather locations and RSS collection timestamps schema',
run: async function (pool) {
await pool.query(`
CREATE TABLE IF NOT EXISTS i_weather_locations (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
name VARCHAR(255) NOT NULL UNIQUE,
location_label VARCHAR(255) NOT NULL,
latitude DECIMAL(9,6) NOT NULL,
longitude DECIMAL(9,6) NOT NULL,
timezone VARCHAR(128) NOT NULL,
provider VARCHAR(32) NOT NULL DEFAULT 'open-meteo',
temperature_unit VARCHAR(16) NOT NULL DEFAULT 'celsius',
wind_unit VARCHAR(16) NOT NULL DEFAULT 'kmh',
precipitation_unit VARCHAR(16) NOT NULL DEFAULT 'mm',
update_interval_value INT NOT NULL DEFAULT 30,
update_interval_unit VARCHAR(16) NOT NULL DEFAULT 'minutes',
last_pulled_at DATETIME NULL,
last_pull_error VARCHAR(1024) NULL,
last_response_json MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
created_by INT NULL,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP,
modified_by INT NULL,
INDEX idx_weather_locations_modified_at (modified_at)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci
`);
await ensureColumn(pool, 'i_rss_feeds', 'last_pulled_at', 'DATETIME NULL', 'item_limit');
}
},
{
version: '2.8.9',
label: 'v2.8.9 data source enablement schema',
run: async function (pool) {
await ensureColumn(pool, 'i_api_sources', 'enabled', 'TINYINT(1) NOT NULL DEFAULT 1', 'api_url');
await ensureColumn(pool, 'i_rss_feeds', 'enabled', 'TINYINT(1) NOT NULL DEFAULT 1', 'feed_url');
await ensureColumn(pool, 'i_weather_locations', 'enabled', 'TINYINT(1) NOT NULL DEFAULT 1', 'precipitation_unit');
}
},
{
version: '2.10.1',
label: 'v2.10.1 template background gradient schema',
run: async function (pool) {
await ensureColumn(pool, 'c_templates', 'background_gradient', 'LONGTEXT NULL', 'background_color');
}
},
{
version: '2.10.2',
label: 'v2.10.2 onboarding client last-seen schema',
run: async function (pool) {
await ensureColumn(pool, 'd_onboarding_devices', 'last_seen_at', 'TIMESTAMP NULL', 'screen_id');
}
} }
]; ];
@@ -311,6 +577,65 @@ async function columnExists(pool, tableName, columnName) {
return Number(rows && rows[0] && rows[0].column_count) > 0; return Number(rows && rows[0] && rows[0].column_count) > 0;
} }
async function tableExists(pool, tableName) {
const [rows] = await pool.query(
`SELECT COUNT(*) AS table_count
FROM information_schema.TABLES
WHERE TABLE_SCHEMA = DATABASE()
AND TABLE_NAME = ?`,
[tableName]
);
return Number(rows && rows[0] && rows[0].table_count) > 0;
}
async function detectSchemaVersion(pool) {
if (await tableExists(pool, APP_STATE_TABLE)) {
const [rows] = await pool.query(
'SELECT state_value FROM ' + APP_STATE_TABLE + ' WHERE state_key = ? LIMIT 1',
[APP_STATE_SCHEMA_VERSION_KEY]
);
const storedVersion = String(rows && rows[0] && rows[0].state_value || '').trim();
if (storedVersion) {
return storedVersion;
}
}
const timetableGroupsExists = await tableExists(pool, 'i_timetable_groups');
const timetableEntriesExists = await tableExists(pool, 'i_timetable_entries');
const scheduleGroupsExists = await tableExists(pool, 'i_schedule_groups');
const scheduleEntriesExists = await tableExists(pool, 'i_schedule_entries');
if (timetableGroupsExists && timetableEntriesExists && !scheduleGroupsExists && !scheduleEntriesExists) {
return '2.6.18';
}
return '0.0.0';
}
async function recordSchemaVersion(pool, version) {
await pool.query(
`CREATE TABLE IF NOT EXISTS ${APP_STATE_TABLE} (
id BIGINT AUTO_INCREMENT PRIMARY KEY,
state_key VARCHAR(191) NOT NULL UNIQUE,
state_value MEDIUMTEXT NULL,
created_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP,
modified_at TIMESTAMP NOT NULL DEFAULT CURRENT_TIMESTAMP ON UPDATE CURRENT_TIMESTAMP
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci`
);
const stateValue = String(version || appVersion || '0.0.0').trim();
await pool.query(
'UPDATE ' + APP_STATE_TABLE + ' SET state_value = ? WHERE state_key = ?',
[stateValue, APP_STATE_SCHEMA_VERSION_KEY]
);
await pool.query(
'INSERT INTO ' + APP_STATE_TABLE + ' (state_key, state_value) SELECT ?, ? WHERE NOT EXISTS (SELECT 1 FROM ' + APP_STATE_TABLE + ' WHERE state_key = ?)',
[APP_STATE_SCHEMA_VERSION_KEY, stateValue, APP_STATE_SCHEMA_VERSION_KEY]
);
}
async function columnIsAutoIncrement(pool, tableName, columnName) { async function columnIsAutoIncrement(pool, tableName, columnName) {
const [rows] = await pool.query( const [rows] = await pool.query(
`SELECT COUNT(*) AS auto_increment_count `SELECT COUNT(*) AS auto_increment_count
@@ -512,6 +837,107 @@ function formatMigrationDateTime(value) {
return year + '-' + month + '-' + day + 'T' + hours + ':' + minutes; return year + '-' + month + '-' + day + 'T' + hours + ':' + minutes;
} }
function parseMigrationDateTimeParts(value) {
if (!value) {
return null;
}
if (value instanceof Date) {
if (Number.isNaN(value.getTime())) {
return null;
}
return {
year: value.getUTCFullYear(),
month: value.getUTCMonth() + 1,
day: value.getUTCDate(),
hour: value.getUTCHours(),
minute: value.getUTCMinutes(),
second: value.getUTCSeconds()
};
}
const raw = String(value || '').trim();
const match = raw.match(/^(\d{4})-(\d{2})-(\d{2})(?:[ T](\d{2}):(\d{2})(?::(\d{2}))?)?$/);
if (!match) {
return null;
}
return {
year: Number(match[1]),
month: Number(match[2]),
day: Number(match[3]),
hour: Number(match[4] || 0),
minute: Number(match[5] || 0),
second: Number(match[6] || 0)
};
}
function getMigrationTimeZoneOffsetMillis(date, timeZone) {
if (!(date instanceof Date) || Number.isNaN(date.getTime())) {
return 0;
}
const parts = new Intl.DateTimeFormat('en-GB', {
timeZone: timeZone,
hour12: false,
year: 'numeric',
month: '2-digit',
day: '2-digit',
hour: '2-digit',
minute: '2-digit',
second: '2-digit'
}).formatToParts(date).reduce(function (acc, part) {
if (part && part.type && part.type !== 'literal') {
acc[part.type] = part.value;
}
return acc;
}, Object.create(null));
const localAsUtc = Date.UTC(
Number(parts.year) || 0,
(Number(parts.month) || 1) - 1,
Number(parts.day) || 1,
Number(parts.hour) || 0,
Number(parts.minute) || 0,
Number(parts.second) || 0,
0
);
return localAsUtc - date.getTime();
}
function convertMigrationDateTimeFromTimeZone(value, timeZone) {
const parts = parseMigrationDateTimeParts(value);
if (!parts) {
return null;
}
const utcMillis = Date.UTC(parts.year, parts.month - 1, parts.day, parts.hour, parts.minute, parts.second, 0);
let adjusted = new Date(utcMillis - getMigrationTimeZoneOffsetMillis(new Date(utcMillis), timeZone));
const adjustedOffset = getMigrationTimeZoneOffsetMillis(adjusted, timeZone);
if (adjustedOffset !== getMigrationTimeZoneOffsetMillis(new Date(utcMillis), timeZone)) {
adjusted = new Date(utcMillis - adjustedOffset);
}
return adjusted;
}
function formatMigrationDateTimeUtc(value) {
if (!(value instanceof Date) || Number.isNaN(value.getTime())) {
return null;
}
const year = value.getUTCFullYear();
const month = String(value.getUTCMonth() + 1).padStart(2, '0');
const day = String(value.getUTCDate()).padStart(2, '0');
const hours = String(value.getUTCHours()).padStart(2, '0');
const minutes = String(value.getUTCMinutes()).padStart(2, '0');
const seconds = String(value.getUTCSeconds()).padStart(2, '0');
return year + '-' + month + '-' + day + ' ' + hours + ':' + minutes + ':' + seconds;
}
function formatMigrationTime(value) { function formatMigrationTime(value) {
if (!value) { if (!value) {
return null; return null;
@@ -562,12 +988,13 @@ function compareVersions(leftVersion, rightVersion) {
return 0; return 0;
} }
async function runMigrations(pool, options) { async function getPendingMigrations(pool, options) {
// Only run migrations that are newer than the installed schema version and not beyond the app version.
const targetVersion = String(appVersion || '0.0.0').trim(); const targetVersion = String(appVersion || '0.0.0').trim();
const currentVersion = String(options && options.currentVersion || '0.0.0').trim(); const currentVersion = String(options && options.currentVersion || '0.0.0').trim();
const legacyPlayerSchemaPresent = await columnExists(pool, 'd_players', 'device_id'); const legacyPlayerSchemaPresent = await columnExists(pool, 'd_players', 'device_id');
const screenPlayerColumnPresent = await columnExists(pool, 'd_screens', 'player_id'); const screenPlayerColumnPresent = await columnExists(pool, 'd_screens', 'player_id');
const legacyTimetableGroupsPresent = await tableExists(pool, 'i_schedule_groups');
const legacyTimetableEntriesPresent = await tableExists(pool, 'i_schedule_entries');
let effectiveCurrentVersion = currentVersion; let effectiveCurrentVersion = currentVersion;
if (!legacyPlayerSchemaPresent && compareVersions(effectiveCurrentVersion, '2.1.0') < 0) { if (!legacyPlayerSchemaPresent && compareVersions(effectiveCurrentVersion, '2.1.0') < 0) {
@@ -578,14 +1005,29 @@ async function runMigrations(pool, options) {
effectiveCurrentVersion = '2.6.3'; effectiveCurrentVersion = '2.6.3';
} }
for (const migration of VERSIONED_MIGRATIONS) { if (legacyTimetableGroupsPresent || legacyTimetableEntriesPresent) {
if (compareVersions(migration.version, effectiveCurrentVersion) > 0 && compareVersions(migration.version, targetVersion) <= 0) { effectiveCurrentVersion = compareVersions(effectiveCurrentVersion, '2.6.18') < 0 ? '2.6.17' : '2.6.17';
await migration.run(pool); }
}
return VERSIONED_MIGRATIONS.filter(function (migration) {
return compareVersions(migration.version, effectiveCurrentVersion) > 0 && compareVersions(migration.version, targetVersion) <= 0;
});
}
async function runMigrations(pool, options) {
// Only run migrations that are newer than the installed schema version and not beyond the app version.
const pendingMigrations = await getPendingMigrations(pool, options);
for (const migration of pendingMigrations) {
await migration.run(pool);
} }
} }
module.exports = { module.exports = {
appVersion: appVersion, appVersion: appVersion,
runMigrations: runMigrations getPendingMigrations: getPendingMigrations,
runMigrations: runMigrations,
detectSchemaVersion: detectSchemaVersion,
recordSchemaVersion: recordSchemaVersion,
compareVersions: compareVersions
}; };
+224 -94
View File
@@ -1,3 +1,5 @@
// Thin-client bridge for player registration, snapshots, commands, and heartbeats.
const express = require('express'); const express = require('express');
const crypto = require('crypto'); const crypto = require('crypto');
const fs = require('fs'); const fs = require('fs');
@@ -8,11 +10,11 @@ const common = require('../common');
const { verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth'); const { verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth');
const { normalizeDeviceId, upsertPlayerRegistration, recordPlayerHeartbeat } = require('#src/data/player-registry'); const { normalizeDeviceId, upsertPlayerRegistration, recordPlayerHeartbeat } = require('#src/data/player-registry');
const { createPlayerPlaylistService } = require('../player/playlist'); const { createPlayerPlaylistService } = require('../player/playlist');
const { buildThumbnailPreviewData } = require('../player/thumbnail-preview');
const { commitDeviceBinding, bindPlayerToScreen, getOnboardingStatus, getPlayerPublicBaseUrl } = require('../player/onboarding'); const { commitDeviceBinding, bindPlayerToScreen, getOnboardingStatus, getPlayerPublicBaseUrl } = require('../player/onboarding');
const { createStyledQrCodeSvg } = require('../data/qr-code'); const { createStyledQrCodeSvg } = require('../data/qr-code');
const { verifyPageAuthToken } = require('#src/request-auth'); const { verifyPageAuthToken } = require('#src/request-auth');
function createThinClientConfig() { function createThinClientConfig() {
return { return {
port: Number(process.env.THIN_CLIENT_PORT || 8090), port: Number(process.env.THIN_CLIENT_PORT || 8090),
@@ -187,6 +189,7 @@ async function start() {
const playerPlaylistService = createPlayerPlaylistService({ const playerPlaylistService = createPlayerPlaylistService({
pool: pool, pool: pool,
common: common, common: common,
mediaDir: config.mediaDir,
snapshotDir: path.join(config.mediaDir, 'player-cache', 'screen-playlists') snapshotDir: path.join(config.mediaDir, 'player-cache', 'screen-playlists')
}); });
app.use(express.json()); app.use(express.json());
@@ -353,6 +356,27 @@ async function start() {
return socket && socket.playerDeviceId ? String(socket.playerDeviceId).trim() : ''; return socket && socket.playerDeviceId ? String(socket.playerDeviceId).trim() : '';
} }
function findPlayerByPairingCode(pairingCode) {
const normalizedCode = String(pairingCode || '').trim().toUpperCase();
if (!normalizedCode) {
return null;
}
for (const [deviceId, socket] of playerSockets.entries()) {
const pairingCodes = socket && Array.isArray(socket.pairingSessions)
? socket.pairingSessions.map(function (entry) { return entry.code; })
: (socket && Array.isArray(socket.pairingCodes) ? socket.pairingCodes : [socket && socket.pairingCode]);
if (socket && pairingCodes.some(function (code) {
return String(code || '').trim().toUpperCase() === normalizedCode;
})) {
const session = socket.pairingSessions && socket.pairingSessions.find(function (entry) {
return String(entry.code || '').trim().toUpperCase() === normalizedCode;
});
return { deviceId: deviceId, socket: socket, clientId: session && session.clientId ? session.clientId : null, code: normalizedCode };
}
}
return null;
}
function removeConnectedPlayerSocket(socket) { function removeConnectedPlayerSocket(socket) {
if (!socket || !socket.playerDeviceId) { if (!socket || !socket.playerDeviceId) {
return false; return false;
@@ -435,7 +459,21 @@ async function start() {
function storeScreenSnapshot(slug, connections, deviceIds) { function storeScreenSnapshot(slug, connections, deviceIds) {
const key = String(slug || '').trim(); const key = String(slug || '').trim();
const normalizedConnections = Array.isArray(connections) ? connections : []; const normalizedConnections = [];
const connectionIndexes = new Map();
(Array.isArray(connections) ? connections : []).forEach(function (connection) {
const identity = connection && typeof connection === 'object'
? [String(connection.deviceId || '').trim(), String(connection.clientId || '').trim()].join('|')
: '';
if (!identity || !connectionIndexes.has(identity)) {
if (identity) {
connectionIndexes.set(identity, normalizedConnections.length);
}
normalizedConnections.push(connection);
return;
}
normalizedConnections[connectionIndexes.get(identity)] = connection;
});
const normalizedDeviceIds = Array.isArray(deviceIds) ? deviceIds.map(function (value) { const normalizedDeviceIds = Array.isArray(deviceIds) ? deviceIds.map(function (value) {
return normalizeDeviceId(value); return normalizeDeviceId(value);
}).filter(Boolean) : []; }).filter(Boolean) : [];
@@ -513,6 +551,21 @@ async function start() {
}; };
} }
function requireOnboardingAuth(req, res, next) {
const token = String(req.headers['x-pulse-page-auth'] || '').trim();
const payload = verifyPageAuthToken(token);
if (payload && ['onboarding', 'player'].indexOf(String(payload.scope || '').trim()) !== -1) {
req.playerPageAuth = payload;
return next();
}
if (verifyRequestAuth(req)) {
return next();
}
return res.status(401).json({ error: 'Onboarding authentication required.' });
}
app.get('/api/media/config', requireRequestAuth, function (_req, res) { app.get('/api/media/config', requireRequestAuth, function (_req, res) {
res.json({ res.json({
mediaDir: config.mediaDir, mediaDir: config.mediaDir,
@@ -532,12 +585,6 @@ async function start() {
return res.status(400).json({ error: 'Device ID is required.' }); return res.status(400).json({ error: 'Device ID is required.' });
} }
logBridge('Forwarding media upload to player', {
deviceId: deviceId,
relativePath: relativePath,
contentLength: Buffer.isBuffer(req.body) ? req.body.length : 0
});
const bodyBuffer = Buffer.isBuffer(req.body) ? req.body : Buffer.from(req.body || ''); const bodyBuffer = Buffer.isBuffer(req.body) ? req.body : Buffer.from(req.body || '');
const response = await sendPlayerCommand({ const response = await sendPlayerCommand({
command: 'media-put', command: 'media-put',
@@ -545,13 +592,6 @@ async function start() {
bodyBase64: bodyBuffer.toString('base64') bodyBase64: bodyBuffer.toString('base64')
}, deviceId); }, deviceId);
logBridge('Player media upload completed', {
deviceId: deviceId,
relativePath: relativePath,
ok: Boolean(response && response.ok),
status: response && response.status ? response.status : null
});
res.status(response.status || (response.ok ? 200 : 502)).json(response); res.status(response.status || (response.ok ? 200 : 502)).json(response);
} catch (error) { } catch (error) {
logBridge('Player media upload failed', { logBridge('Player media upload failed', {
@@ -574,23 +614,11 @@ async function start() {
return res.status(400).json({ error: 'Device ID is required.' }); return res.status(400).json({ error: 'Device ID is required.' });
} }
logBridge('Forwarding media delete to player', {
deviceId: deviceId,
relativePath: relativePath
});
const response = await sendPlayerCommand({ const response = await sendPlayerCommand({
command: 'media-delete', command: 'media-delete',
relativePath: relativePath relativePath: relativePath
}, deviceId); }, deviceId);
logBridge('Player media delete completed', {
deviceId: deviceId,
relativePath: relativePath,
ok: Boolean(response && response.ok),
status: response && response.status ? response.status : null
});
res.status(response.status || (response.ok ? 200 : 502)).json(response); res.status(response.status || (response.ok ? 200 : 502)).json(response);
} catch (error) { } catch (error) {
logBridge('Player media delete failed', { logBridge('Player media delete failed', {
@@ -641,6 +669,16 @@ async function start() {
}, response && typeof response === 'object' ? response : {}); }, response && typeof response === 'object' ? response : {});
})); }));
logBridge('Screen command result', {
screenSlug: slug,
command: command,
connectionId: connectionId || null,
targets: targetPlayers.map(function (target) { return target.deviceId; }),
results: results.map(function (result) {
return { playerIdentifier: result.playerIdentifier, ok: result.ok, status: result.status, error: result.error || null };
})
});
res.json({ res.json({
ok: true, ok: true,
screenSlug: slug, screenSlug: slug,
@@ -654,12 +692,45 @@ async function start() {
} }
}); });
app.post('/api/screens/:slug/announcements/refresh', requireRequestAuth, function (req, res) {
const slug = String(req.params.slug || '').trim();
if (!slug) {
return res.status(400).json({ error: 'Screen slug is required.' });
}
const targetPlayers = Array.from(playerSockets.values()).filter(function (socket) {
return socket && socket.readyState === WebSocket.OPEN;
}).map(function (socket) {
return { socket: socket };
});
let sent = 0;
targetPlayers.forEach(function (target) {
if (!target || !target.socket || target.socket.readyState !== WebSocket.OPEN) {
return;
}
try {
target.socket.send(JSON.stringify({
type: 'command',
command: 'announcement-refresh',
screenSlug: slug,
sentAt: new Date().toISOString()
}));
sent += 1;
} catch (_error) {
}
});
return res.json({ ok: true, screenSlug: slug, sent: sent });
});
app.get('/api/onboarding/status', async function (req, res, next) { app.get('/api/onboarding/status', async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.query.deviceId) || getConnectedPlayerDeviceId(); const requestedDeviceId = normalizeDeviceId(req.query.deviceId);
const deviceId = requestedDeviceId;
const status = await getOnboardingStatus(pool, deviceId); const status = await getOnboardingStatus(pool, deviceId);
res.json({ res.json({
deviceId: normalizeDeviceId(deviceId), deviceId: requestedDeviceId,
onboarded: Boolean(status && status.screen_id), onboarded: Boolean(status && status.screen_id),
clientName: status ? status.client_name : null, clientName: status ? status.client_name : null,
screenId: status ? status.screen_id : null, screenId: status ? status.screen_id : null,
@@ -672,6 +743,58 @@ async function start() {
} }
}); });
app.get('/api/onboarding/resolve', requireRequestAuth, function (req, res) {
const pairing = findPlayerByPairingCode(req.query.pairingCode);
if (!pairing) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
}
res.json({
deviceId: pairing.deviceId,
clientId: pairing.clientId || null,
});
});
app.get('/api/onboarding/url', requireRequestAuth, function (req, res) {
const pairing = findPlayerByPairingCode(req.query.pairingCode);
if (!pairing) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
}
const webBaseUrl = String(process.env.WEB_PUBLIC_URL || '').trim().replace(/\/$/, '');
if (!webBaseUrl) {
return res.status(503).json({ error: 'WEB_PUBLIC_URL is not configured on the bridge.' });
}
res.json({ url: `${webBaseUrl}/pairing?code=${encodeURIComponent(pairing.code)}` });
});
app.get('/api/onboarding/qr', requireRequestAuth, async function (req, res, next) {
try {
const pairing = findPlayerByPairingCode(req.query.pairingCode);
if (!pairing) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
}
const webBaseUrl = String(process.env.WEB_PUBLIC_URL || '').trim().replace(/\/$/, '');
if (!webBaseUrl) {
return res.status(503).json({ error: 'WEB_PUBLIC_URL is not configured on the bridge.' });
}
const svg = await createStyledQrCodeSvg({
value: `${webBaseUrl}/pairing?code=${encodeURIComponent(pairing.code)}`,
qr_margin: 20,
qr_dots_type: 'dots',
qr_dots_color: '#f4f8f5',
qr_corners_square_type: 'dot',
qr_corners_square_color: '#f4f8f5',
qr_corners_dot_type: 'dot',
qr_corners_dot_color: '#f0bd70',
qr_background_transparent: true
});
res.set('Content-Type', 'image/svg+xml; charset=utf-8');
res.set('Cache-Control', 'no-store');
res.send(svg);
} catch (error) {
next(error);
}
});
app.get('/api/onboarding/screens', requirePageAuth(['onboarding', 'player']), async function (_req, res, next) { app.get('/api/onboarding/screens', requirePageAuth(['onboarding', 'player']), async function (_req, res, next) {
try { try {
const [rows] = await pool.query('SELECT id, name, slug FROM d_screens ORDER BY name ASC, id ASC'); const [rows] = await pool.query('SELECT id, name, slug FROM d_screens ORDER BY name ASC, id ASC');
@@ -681,25 +804,18 @@ async function start() {
} }
}); });
app.get('/api/onboarding/qr', async function (req, res, next) { app.post('/api/onboarding', express.json(), requireOnboardingAuth, async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.query.deviceId) || getConnectedPlayerDeviceId(); const pairingCode = String(req.body && req.body.pairingCode || '').trim().toUpperCase();
if (!deviceId) { const pairing = findPlayerByPairingCode(pairingCode);
return res.status(400).json({ error: 'Device ID is required' }); const clientId = normalizeDeviceId(req.body && req.body.clientId);
if (!pairing) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
} }
const onboardingUrl = `${getPlayerPublicBaseUrl(req)}/onboard?deviceId=${encodeURIComponent(deviceId)}`; if (!clientId) {
const svg = await createStyledQrCodeSvg({ value: onboardingUrl, qr_margin: 20 }); return res.status(400).json({ error: 'Client ID is required.' });
res.set('Content-Type', 'image/svg+xml; charset=utf-8'); }
res.set('Cache-Control', 'no-store'); const deviceId = pairing.deviceId;
res.send(svg);
} catch (error) {
next(error);
}
});
app.post('/api/onboarding', requirePageAuth(['onboarding', 'player']), express.json(), async function (req, res, next) {
try {
const deviceId = normalizeDeviceId(req.body && req.body.deviceId) || getConnectedPlayerDeviceId();
const clientName = String((req.body && req.body.clientName) || '').trim(); const clientName = String((req.body && req.body.clientName) || '').trim();
const screenSlug = String((req.body && req.body.screenSlug) || '').trim(); const screenSlug = String((req.body && req.body.screenSlug) || '').trim();
if (!deviceId) { if (!deviceId) {
@@ -712,8 +828,13 @@ async function start() {
return res.status(400).json({ error: 'Screen is required' }); return res.status(400).json({ error: 'Screen is required' });
} }
const status = await commitDeviceBinding(pool, deviceId, clientName, screenSlug, null, []); const status = await commitDeviceBinding(pool, clientId, clientName, screenSlug, null, []);
await bindPlayerToScreen(pool, deviceId, screenSlug); await bindPlayerToScreen(pool, deviceId, screenSlug);
await sendPlayerCommandToSocket(pairing.socket, {
command: 'redirect',
url: `${String(pairing.socket.publicBaseUrl || getPlayerPublicBaseUrl(req)).replace(/\/$/, '')}/screen/${encodeURIComponent(screenSlug)}`,
clientId: clientId
});
res.json({ res.json({
deviceId: deviceId, deviceId: deviceId,
clientName: status ? status.client_name : clientName, clientName: status ? status.client_name : clientName,
@@ -733,6 +854,11 @@ async function start() {
app.get('/api/screens/:slug/playlist', requirePageAuth(['player']), async function (req, res, next) { app.get('/api/screens/:slug/playlist', requirePageAuth(['player']), async function (req, res, next) {
try { try {
const clientId = String(req.headers['x-pulse-client-id'] || '').trim();
const status = await getOnboardingStatus(pool, clientId);
if (!clientId || !status || String(status.screen_slug || '').trim() !== String(req.params.slug || '').trim()) {
return res.status(403).json({ error: 'This browser tab is not authorized for this screen.' });
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
const data = await playerPlaylistService.buildScreenPlaylist(req.params.slug); const data = await playerPlaylistService.buildScreenPlaylist(req.params.slug);
if (!data.screen) { if (!data.screen) {
@@ -753,6 +879,11 @@ async function start() {
app.get('/api/screens/:slug/announcement', requirePageAuth(['player']), async function (req, res, next) { app.get('/api/screens/:slug/announcement', requirePageAuth(['player']), async function (req, res, next) {
try { try {
const clientId = String(req.headers['x-pulse-client-id'] || '').trim();
const status = await getOnboardingStatus(pool, clientId);
if (!clientId || !status || String(status.screen_slug || '').trim() !== String(req.params.slug || '').trim()) {
return res.status(403).json({ error: 'This browser tab is not authorized for this screen.' });
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
const announcement = typeof common.fetchActiveAnnouncement === 'function' const announcement = typeof common.fetchActiveAnnouncement === 'function'
? await common.fetchActiveAnnouncement(pool, req.params.slug) ? await common.fetchActiveAnnouncement(pool, req.params.slug)
@@ -776,48 +907,6 @@ async function start() {
} }
}); });
app.get('/api/internal/slide-thumbnails/:id/preview', requireRequestAuth, async function (req, res, next) {
try {
const slide = await common.fetchSlideById(pool, Number(req.params.id));
if (!slide) {
return res.status(404).send('Slide not found');
}
const data = buildThumbnailPreviewData(slide);
if (typeof common.fetchRssFeedsData === 'function' && typeof common.fetchRssFeedItemsByFeedId === 'function') {
const rssData = await common.fetchRssFeedsData(pool);
data.rssFeeds = await Promise.all((rssData.rssFeeds || []).map(async function (feed) {
const items = await common.fetchRssFeedItemsByFeedId(pool, feed.id);
return Object.assign({}, feed, {
items: items.map(function (item) {
return typeof common.normalizeRssFeedItem === 'function' ? common.normalizeRssFeedItem(item) : item;
})
});
}));
}
if (typeof common.fetchApiSourcesData === 'function') {
const apiData = await common.fetchApiSourcesData(pool);
data.apiSources = (apiData.apiSources || []).map(function (source) {
return Object.assign({}, source, {
responseJson: typeof common.parseJsonSafe === 'function' ? common.parseJsonSafe(source.last_response_json) : null
});
});
}
if (typeof common.fetchTimetablesData === 'function') {
const timetableData = await common.fetchTimetablesData(pool);
data.timetableGroups = Array.isArray(timetableData && timetableData.timetableGroups) ? timetableData.timetableGroups : [];
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.send(common.renderPlayerPage('slide-thumbnail-preview-' + slide.id, data));
} catch (error) {
next(error);
}
});
app.post('/api/players/:deviceId/commands', requireRequestAuth, async function (req, res, next) { app.post('/api/players/:deviceId/commands', requireRequestAuth, async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.params.deviceId); const deviceId = normalizeDeviceId(req.params.deviceId);
@@ -827,8 +916,11 @@ async function start() {
return res.status(404).json({ ok: false, error: 'Player is not connected.' }); return res.status(404).json({ ok: false, error: 'Player is not connected.' });
} }
socket.send(JSON.stringify(payload)); const response = await sendPlayerCommandToSocket(socket, payload);
res.json({ ok: true, deviceId: deviceId, sent: true }); res.status(response && response.ok ? 200 : (response && response.status || 502)).json(Object.assign({
deviceId: deviceId,
connectionId: payload.connectionId || null
}, response && typeof response === 'object' ? response : { ok: false }));
} catch (error) { } catch (error) {
next(error); next(error);
} }
@@ -865,6 +957,17 @@ async function start() {
} }
socket.playerDeviceId = deviceId; socket.playerDeviceId = deviceId;
socket.pairingSessions = Array.isArray(payload.pairingSessions) ? payload.pairingSessions.map(function (entry) {
return {
deviceId: normalizeDeviceId(entry && entry.deviceId),
clientId: normalizeDeviceId(entry && entry.clientId),
code: String(entry && entry.code || '').trim().toUpperCase()
};
}).filter(function (entry) { return entry.deviceId && entry.code; }) : [];
socket.pairingCodes = Array.from(new Set((Array.isArray(payload.pairingCodes) ? payload.pairingCodes : [payload.pairingCode]).map(function (value) {
return String(value || '').trim().toUpperCase();
}).filter(Boolean)));
socket.pairingCode = socket.pairingCodes[0] || '';
if (messageType === 'snapshot') { if (messageType === 'snapshot') {
const slug = String(payload.slug || '').trim(); const slug = String(payload.slug || '').trim();
@@ -872,29 +975,56 @@ async function start() {
return; return;
} }
setScreenSnapshotSource(slug, deviceId, Array.isArray(payload.connections) ? payload.connections : []); const snapshotPlayerPublicBaseUrl = String(payload.playerPublicBaseUrl || socket.publicBaseUrl || '').trim().replace(/\/$/, '');
const connections = Array.isArray(payload.connections) ? payload.connections.map(function (connection) {
if (!connection || typeof connection !== 'object' || !snapshotPlayerPublicBaseUrl) {
return connection && typeof connection === 'object'
? Object.assign({}, connection, { playerDeviceId: deviceId })
: connection;
}
return Object.assign({}, connection, {
playerDeviceId: deviceId,
playerPublicBaseUrl: snapshotPlayerPublicBaseUrl
});
}) : [];
setScreenSnapshotSource(slug, deviceId, connections);
return; return;
} }
if (messageType === 'register') { if (messageType === 'register') {
socket.publicBaseUrl = String(payload.publicBaseUrl || '').trim().replace(/\/$/, '');
const player = await upsertPlayerRegistration(pool, { const player = await upsertPlayerRegistration(pool, {
deviceId: deviceId, deviceId: deviceId,
publicBaseUrl: payload.publicBaseUrl, publicBaseUrl: payload.publicBaseUrl,
internalBaseUrl: payload.internalBaseUrl internalBaseUrl: payload.internalBaseUrl
}); });
const previousSocket = playerSockets.get(deviceId);
playerSockets.set(deviceId, socket); playerSockets.set(deviceId, socket);
if (previousSocket && previousSocket !== socket && previousSocket.readyState !== WebSocket.CLOSED) {
try {
previousSocket.close(1000, 'Replaced by a newer player connection.');
} catch (_error) {
}
}
logBridge(`Player ${formatPlayerConnectionLabel(deviceId)} has connected`); logBridge(`Player ${formatPlayerConnectionLabel(deviceId)} has connected`);
socket.send(JSON.stringify({ type: 'registered', ok: true, player: player })); socket.send(JSON.stringify({ type: 'registered', ok: true, player: player }));
return; return;
} }
if (messageType === 'heartbeat') { if (messageType === 'heartbeat') {
socket.publicBaseUrl = String(payload.publicBaseUrl || socket.publicBaseUrl || '').trim().replace(/\/$/, '');
const player = await recordPlayerHeartbeat(pool, { const player = await recordPlayerHeartbeat(pool, {
deviceId: deviceId, deviceId: deviceId,
publicBaseUrl: payload.publicBaseUrl, publicBaseUrl: payload.publicBaseUrl,
internalBaseUrl: payload.internalBaseUrl internalBaseUrl: payload.internalBaseUrl
}); });
if (typeof common.touchOnboardingDeviceLastSeen === 'function') {
const onboardingClientIds = (Array.isArray(payload.connections) ? payload.connections : []).map(function (connection) {
return connection && connection.clientId;
});
await common.touchOnboardingDeviceLastSeen(pool, onboardingClientIds);
}
socket.send(JSON.stringify({ type: 'heartbeat-ack', ok: true, player: player })); socket.send(JSON.stringify({ type: 'heartbeat-ack', ok: true, player: player }));
return; return;
@@ -952,15 +1082,15 @@ async function start() {
}); });
socket.on('close', function () { socket.on('close', function () {
clearPlayerSnapshotSources(socket.playerDeviceId);
if (removeConnectedPlayerSocket(socket)) { if (removeConnectedPlayerSocket(socket)) {
clearPlayerSnapshotSources(socket.playerDeviceId);
logPlayerDisconnect(socket); logPlayerDisconnect(socket);
} }
}); });
socket.on('error', function () { socket.on('error', function () {
clearPlayerSnapshotSources(socket.playerDeviceId);
if (removeConnectedPlayerSocket(socket)) { if (removeConnectedPlayerSocket(socket)) {
clearPlayerSnapshotSources(socket.playerDeviceId);
logPlayerDisconnect(socket); logPlayerDisconnect(socket);
} }
}); });
+65 -52
View File
@@ -1,3 +1,5 @@
// Player application bootstrap, media routes, websocket runtime, and onboarding wiring.
const express = require('express'); const express = require('express');
const fs = require('fs'); const fs = require('fs');
const http = require('http'); const http = require('http');
@@ -10,8 +12,10 @@ const { createRtmpStreamService } = require('./player/modules/rtmp-streams');
const { normalizeDeviceId, registerPlayerOnboardingRoutes, commitDeviceBinding } = require('./player/onboarding'); const { normalizeDeviceId, registerPlayerOnboardingRoutes, commitDeviceBinding } = require('./player/onboarding');
const { createOnboardingStore } = require('./player/onboarding/store'); const { createOnboardingStore } = require('./player/onboarding/store');
const { registerPlayerRoutes } = require('./player/routes'); const { registerPlayerRoutes } = require('./player/routes');
const { getPlayerRuntimeScripts } = require('./player/render-helpers');
const { ensureFontLibrary } = require('#src/web/lib/media/font-library'); const { ensureFontLibrary } = require('#src/web/lib/media/font-library');
const { createRequestAuthHeaders } = require('#src/request-auth'); const { createRequestAuthHeaders } = require('#src/request-auth');
const { withClientNameReservation } = require('#src/data/client-name-check');
const { getConfiguredPlayerIdentifier, recordPlayerHeartbeat } = require('#src/data/player-registry'); const { getConfiguredPlayerIdentifier, recordPlayerHeartbeat } = require('#src/data/player-registry');
@@ -20,10 +24,11 @@ async function start() {
const app = express(); const app = express();
const pool = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '') ? null : common.createPool(); const pool = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '') ? null : common.createPool();
const PORT = Number(process.env.PLAYER_PORT || 8081); const PORT = Number(process.env.PLAYER_PORT || 8081);
const PLAYER_PUBLIC_URL = String(process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, ''); const PLAYER_PUBLIC_URL = String(process.env.PLAYER_PUBLIC_URL || '').trim().replace(/\/$/, '');
const BRIDGE_PUBLIC_URL = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, ''); const BRIDGE_PUBLIC_URL = String(process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const WEB_INTERNAL_URL = String(process.env.WEB_INTERNAL_URL || '').trim().replace(/\/$/, '');
const isRemotePlayer = Boolean(BRIDGE_PUBLIC_URL); const isRemotePlayer = Boolean(BRIDGE_PUBLIC_URL);
const PLAYER_INTERNAL_URL = String(isRemotePlayer ? BRIDGE_PUBLIC_URL : (process.env.PLAYER_INTERNAL_URL || PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '')).trim().replace(/\/$/, ''); const PLAYER_INTERNAL_URL = String(isRemotePlayer ? BRIDGE_PUBLIC_URL : (process.env.PLAYER_INTERNAL_URL || '')).trim().replace(/\/$/, '');
const PLAYER_DEVICE_ID = getConfiguredPlayerIdentifier(); const PLAYER_DEVICE_ID = getConfiguredPlayerIdentifier();
const PLAYER_AGENT_RECONNECT_DELAY_MS = Number(process.env.PLAYER_AGENT_RECONNECT_DELAY_MS || 5000); const PLAYER_AGENT_RECONNECT_DELAY_MS = Number(process.env.PLAYER_AGENT_RECONNECT_DELAY_MS || 5000);
const ASSET_DIR = path.join(__dirname, 'player', 'public'); const ASSET_DIR = path.join(__dirname, 'player', 'public');
@@ -36,6 +41,9 @@ async function start() {
let lastDisconnectAt = 0; let lastDisconnectAt = 0;
let playerPublicBaseUrl = PLAYER_PUBLIC_URL || null; let playerPublicBaseUrl = PLAYER_PUBLIC_URL || null;
let refreshThinClientRegistration = null; let refreshThinClientRegistration = null;
let activePairingCode = '';
let activePairingCodes = [];
let activePairingSessions = [];
const playerRuntime = createPlayerRuntime({ const playerRuntime = createPlayerRuntime({
pool: pool, pool: pool,
normalizeDeviceId: normalizeDeviceId, normalizeDeviceId: normalizeDeviceId,
@@ -48,11 +56,28 @@ async function start() {
thinClientSocket.send(JSON.stringify({ thinClientSocket.send(JSON.stringify({
type: 'snapshot', type: 'snapshot',
deviceId: PLAYER_DEVICE_ID, deviceId: PLAYER_DEVICE_ID,
playerPublicBaseUrl: getPlayerPublicBaseUrl(),
slug: snapshot && snapshot.slug ? String(snapshot.slug).trim() : '', slug: snapshot && snapshot.slug ? String(snapshot.slug).trim() : '',
connections: Array.isArray(snapshot && snapshot.connections) ? snapshot.connections : [] connections: Array.isArray(snapshot && snapshot.connections) ? snapshot.connections : []
})); }));
} catch (_error) { } catch (_error) {
} }
},
persistClientName: async function (deviceId, clientName) {
if (!pool || !deviceId || !clientName) {
return;
}
await withClientNameReservation(pool, clientName, async function () {
await pool.query(
`UPDATE d_onboarding_devices
SET client_name = ?, modified_at = CURRENT_TIMESTAMP
WHERE device_id = ?`,
[clientName, deviceId]
);
});
},
touchClientLastSeen: async function (deviceId) {
await common.touchOnboardingDeviceLastSeen(pool, deviceId);
} }
}); });
const playerPlaylistService = isRemotePlayer const playerPlaylistService = isRemotePlayer
@@ -60,6 +85,7 @@ async function start() {
: createPlayerPlaylistService({ : createPlayerPlaylistService({
pool: pool, pool: pool,
common: common, common: common,
mediaDir: MEDIA_DIR,
snapshotDir: path.join(MEDIA_DIR, 'player-cache', 'screen-playlists') snapshotDir: path.join(MEDIA_DIR, 'player-cache', 'screen-playlists')
}); });
const rtmpStreamService = createRtmpStreamService({ const rtmpStreamService = createRtmpStreamService({
@@ -133,7 +159,8 @@ async function start() {
} }
async function triggerWebMediaSync() { async function triggerWebMediaSync() {
if (!isRemotePlayer || !BRIDGE_PUBLIC_URL) { const syncBaseUrl = WEB_INTERNAL_URL || BRIDGE_PUBLIC_URL;
if (!isRemotePlayer || !syncBaseUrl) {
return false; return false;
} }
@@ -144,16 +171,12 @@ async function start() {
}; };
try { try {
console.info('[player] Triggering startup media sync', {
playerIdentifier: PLAYER_DEVICE_ID,
bridgeBaseUrl: BRIDGE_PUBLIC_URL
});
const authHeaders = createRequestAuthHeaders({ const authHeaders = createRequestAuthHeaders({
method: 'POST', method: 'POST',
pathname: '/api/internal/sync/player-media', pathname: '/api/internal/sync/player-media',
body: requestBody body: requestBody
}); });
const response = await fetch(`${BRIDGE_PUBLIC_URL}/api/internal/sync/player-media`, { const response = await fetch(`${syncBaseUrl}/api/internal/sync/player-media`, {
method: 'POST', method: 'POST',
headers: Object.assign({ headers: Object.assign({
Accept: 'application/json', Accept: 'application/json',
@@ -162,11 +185,6 @@ async function start() {
body: JSON.stringify(requestBody) body: JSON.stringify(requestBody)
}); });
console.info('[player] Startup media sync response', {
ok: Boolean(response && response.ok),
status: response && response.status ? response.status : null
});
return Boolean(response && response.ok); return Boolean(response && response.ok);
} catch (_error) { } catch (_error) {
console.warn('[player] Startup media sync failed'); console.warn('[player] Startup media sync failed');
@@ -175,7 +193,8 @@ async function start() {
} }
async function triggerWebFontSync() { async function triggerWebFontSync() {
if (!isRemotePlayer || !BRIDGE_PUBLIC_URL) { const syncBaseUrl = WEB_INTERNAL_URL || BRIDGE_PUBLIC_URL;
if (!isRemotePlayer || !syncBaseUrl) {
return false; return false;
} }
@@ -186,16 +205,12 @@ async function start() {
}; };
try { try {
console.info('[player] Triggering startup font sync', {
playerIdentifier: PLAYER_DEVICE_ID,
bridgeBaseUrl: BRIDGE_PUBLIC_URL
});
const authHeaders = createRequestAuthHeaders({ const authHeaders = createRequestAuthHeaders({
method: 'POST', method: 'POST',
pathname: '/api/internal/sync/player-font', pathname: '/api/internal/sync/player-font',
body: requestBody body: requestBody
}); });
const response = await fetch(`${BRIDGE_PUBLIC_URL}/api/internal/sync/player-font`, { const response = await fetch(`${syncBaseUrl}/api/internal/sync/player-font`, {
method: 'POST', method: 'POST',
headers: Object.assign({ headers: Object.assign({
Accept: 'application/json', Accept: 'application/json',
@@ -204,11 +219,6 @@ async function start() {
body: JSON.stringify(requestBody) body: JSON.stringify(requestBody)
}); });
console.info('[player] Startup font sync response', {
ok: Boolean(response && response.ok),
status: response && response.status ? response.status : null
});
return Boolean(response && response.ok); return Boolean(response && response.ok);
} catch (_error) { } catch (_error) {
console.warn('[player] Startup font sync failed'); console.warn('[player] Startup font sync failed');
@@ -257,18 +267,9 @@ async function start() {
response.error = 'Invalid media payload.'; response.error = 'Invalid media payload.';
} else { } else {
const bodyBuffer = Buffer.from(bodyBase64, 'base64'); const bodyBuffer = Buffer.from(bodyBase64, 'base64');
console.info('[player] Writing media file', {
relativePath: relativePath,
filePath: filePath,
bytes: bodyBuffer.length
});
await fs.promises.mkdir(path.dirname(filePath), { recursive: true }); await fs.promises.mkdir(path.dirname(filePath), { recursive: true });
await fs.promises.writeFile(filePath, bodyBuffer); await fs.promises.writeFile(filePath, bodyBuffer);
response.ok = true; response.ok = true;
console.info('[player] Media file written', {
relativePath: relativePath,
filePath: filePath
});
} }
} else if (command === 'media-delete') { } else if (command === 'media-delete') {
const relativePath = String(payload.relativePath || payload.filename || '').trim(); const relativePath = String(payload.relativePath || payload.filename || '').trim();
@@ -276,10 +277,6 @@ async function start() {
if (!filePath) { if (!filePath) {
response.error = 'Invalid media path.'; response.error = 'Invalid media path.';
} else { } else {
console.info('[player] Removing media file', {
relativePath: relativePath,
filePath: filePath
});
try { try {
await fs.promises.unlink(filePath); await fs.promises.unlink(filePath);
} catch (error) { } catch (error) {
@@ -288,12 +285,8 @@ async function start() {
} }
} }
response.ok = true; response.ok = true;
console.info('[player] Media file removed', {
relativePath: relativePath,
filePath: filePath
});
} }
} else if (['refresh', 'reload', 'redirect', 'pause', 'blackout', 'previous', 'next', 'setclientname'].indexOf(command) !== -1) { } else if (['refresh', 'reload', 'redirect', 'pause', 'blackout', 'previous', 'next', 'setclientname', 'announcement-refresh'].indexOf(command) !== -1) {
const screenSlug = String(payload.screenSlug || payload.slug || '').trim(); const screenSlug = String(payload.screenSlug || payload.slug || '').trim();
if (!screenSlug) { if (!screenSlug) {
response.error = 'Screen slug is required.'; response.error = 'Screen slug is required.';
@@ -336,7 +329,25 @@ async function start() {
playerPublicBaseUrl: getPlayerPublicBaseUrl(), playerPublicBaseUrl: getPlayerPublicBaseUrl(),
playerInternalBaseUrl: PLAYER_INTERNAL_URL, playerInternalBaseUrl: PLAYER_INTERNAL_URL,
bridgeBaseUrl: BRIDGE_PUBLIC_URL, bridgeBaseUrl: BRIDGE_PUBLIC_URL,
playerDeviceId: PLAYER_DEVICE_ID playerDeviceId: PLAYER_DEVICE_ID,
onPairingCode: function (code, codes) {
activePairingCode = String(code || '').trim().toUpperCase();
activePairingSessions = Array.isArray(codes) ? codes.map(function (entry) {
return { deviceId: String(entry && entry.deviceId || '').trim(), clientId: String(entry && entry.clientId || '').trim(), code: String(entry && entry.code || '').trim().toUpperCase() };
}).filter(function (entry) { return entry.deviceId && entry.code; }) : [];
activePairingCodes = activePairingSessions.map(function (entry) { return entry.code; });
if (typeof refreshThinClientRegistration === 'function') {
refreshThinClientRegistration();
}
}
});
app.get('/assets/player-script/:name.js', function (req, res) {
const script = getPlayerRuntimeScripts().find(function (entry) { return entry[0] === req.params.name; });
if (!script) {
return res.sendStatus(404);
}
res.set('Cache-Control', 'no-cache');
return res.type('application/javascript').send(script[1]);
}); });
registerPlayerRoutes(app, { registerPlayerRoutes(app, {
pool: pool, pool: pool,
@@ -346,6 +357,7 @@ async function start() {
playerRuntime: playerRuntime, playerRuntime: playerRuntime,
playerPlaylistService: playerPlaylistService, playerPlaylistService: playerPlaylistService,
rtmpStreamService: rtmpStreamService, rtmpStreamService: rtmpStreamService,
snapshotDir: path.join(MEDIA_DIR, 'player-cache', 'screen-playlists'),
playerInternalBaseUrl: PLAYER_INTERNAL_URL, playerInternalBaseUrl: PLAYER_INTERNAL_URL,
bridgeBaseUrl: BRIDGE_PUBLIC_URL, bridgeBaseUrl: BRIDGE_PUBLIC_URL,
playerDeviceId: PLAYER_DEVICE_ID, playerDeviceId: PLAYER_DEVICE_ID,
@@ -406,7 +418,11 @@ async function start() {
type: 'heartbeat', type: 'heartbeat',
deviceId: PLAYER_DEVICE_ID, deviceId: PLAYER_DEVICE_ID,
publicBaseUrl: getPlayerPublicBaseUrl(), publicBaseUrl: getPlayerPublicBaseUrl(),
internalBaseUrl: PLAYER_INTERNAL_URL internalBaseUrl: PLAYER_INTERNAL_URL,
pairingCode: activePairingCode,
pairingCodes: activePairingCodes,
pairingSessions: activePairingSessions,
connections: playerRuntime.snapshotAllConnections()
})); }));
} }
@@ -454,6 +470,7 @@ async function start() {
socket.send(JSON.stringify({ socket.send(JSON.stringify({
type: 'snapshot', type: 'snapshot',
deviceId: PLAYER_DEVICE_ID, deviceId: PLAYER_DEVICE_ID,
playerPublicBaseUrl: getPlayerPublicBaseUrl(),
slug: String(slug || '').trim(), slug: String(slug || '').trim(),
connections: playerRuntime.snapshotConnections(slug) connections: playerRuntime.snapshotConnections(slug)
})); }));
@@ -470,7 +487,10 @@ async function start() {
type: 'register', type: 'register',
deviceId: PLAYER_DEVICE_ID, deviceId: PLAYER_DEVICE_ID,
publicBaseUrl: getPlayerPublicBaseUrl(), publicBaseUrl: getPlayerPublicBaseUrl(),
internalBaseUrl: PLAYER_INTERNAL_URL internalBaseUrl: PLAYER_INTERNAL_URL,
pairingCode: activePairingCode,
pairingCodes: activePairingCodes,
pairingSessions: activePairingSessions
})); }));
playerRuntime.snapshotSlugs().forEach(function (slug) { playerRuntime.snapshotSlugs().forEach(function (slug) {
@@ -491,9 +511,6 @@ async function start() {
} }
if (parsedMessage && String(parsedMessage.type || '').trim() === 'registered') { if (parsedMessage && String(parsedMessage.type || '').trim() === 'registered') {
console.info('[player] Bridge registration acknowledged', {
playerIdentifier: PLAYER_DEVICE_ID
});
sendHeartbeat(); sendHeartbeat();
return; return;
} }
@@ -580,10 +597,6 @@ async function start() {
console.error(error); console.error(error);
}); });
if (playerRuntime.snapshotAllConnections().length > 0) {
await common.pruneStaleOnboardingDevices(pool);
}
await onboardingStore.flushBindings(function (entry) { await onboardingStore.flushBindings(function (entry) {
return commitDeviceBinding( return commitDeviceBinding(
pool, pool,
+205 -20
View File
@@ -1,20 +1,44 @@
// Player onboarding routes and signup flow helpers. // Player onboarding routes and signup flow helpers.
const express = require('express'); const express = require('express');
const { isClientNameAvailable, withClientNameReservation } = require('#src/data/client-name-check'); const crypto = require('crypto');
const { findAvailableClientName, withClientNameReservation } = require('#src/data/client-name-check');
const { createStyledQrCodeSvg } = require('#src/data/qr-code'); const { createStyledQrCodeSvg } = require('#src/data/qr-code');
const { getSharedSecret, verifyPageAuthToken, createRequestAuthHeaders } = require('#src/request-auth'); const { getSharedSecret, verifyPageAuthToken, verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth');
const { resolvePlayerRegistration, upsertPlayerRegistration: upsertPlayerRegistrationRecord } = require('#src/data/player-registry'); const { resolvePlayerRegistration, upsertPlayerRegistration: upsertPlayerRegistrationRecord } = require('#src/data/player-registry');
const { isTransientDbError } = require('./store'); const { isTransientDbError } = require('./store');
const ONBOARDING_SIGNUP_LIMIT_WINDOW_MS = 5 * 60 * 1000; const ONBOARDING_SIGNUP_LIMIT_WINDOW_MS = 5 * 60 * 1000;
const ONBOARDING_SIGNUP_LIMIT_MAX_ATTEMPTS = 8; const ONBOARDING_SIGNUP_LIMIT_MAX_ATTEMPTS = 8;
const PAIRING_CODE_LENGTH = 6;
const PAIRING_CODE_TTL_MS = 15 * 60 * 1000;
const PAIRING_CODE_ALPHABET = 'ABCDEFGHJKLMNPQRSTUVWXYZ23456789';
const onboardingSignupAttempts = new Map(); const onboardingSignupAttempts = new Map();
function normalizeDeviceId(value) { function normalizeDeviceId(value) {
return String(value || '').trim().replace(/[^a-zA-Z0-9_-]/g, '').slice(0, 128); return String(value || '').trim().replace(/[^a-zA-Z0-9_-]/g, '').slice(0, 128);
} }
function createPairingCode() {
const bytes = crypto.randomBytes(PAIRING_CODE_LENGTH);
let code = '';
for (let index = 0; index < PAIRING_CODE_LENGTH; index += 1) {
code += PAIRING_CODE_ALPHABET[bytes[index] % PAIRING_CODE_ALPHABET.length];
}
return code;
}
function createPairingSession(deviceId, clientId) {
return { deviceId: normalizeDeviceId(deviceId), clientId: normalizeDeviceId(clientId), code: createPairingCode(), expiresAt: Date.now() + PAIRING_CODE_TTL_MS };
}
function isValidOnboardingPairingCode(pairingSession, pairingCode, now) {
const suppliedCode = Buffer.from(String(pairingCode || '').trim().toUpperCase());
const expectedCode = Buffer.from(String(pairingSession && pairingSession.code || '').trim());
const currentTime = Number(now || Date.now());
return Boolean(pairingSession && pairingSession.deviceId && pairingSession.expiresAt > currentTime && suppliedCode.length === expectedCode.length && suppliedCode.length > 0 && crypto.timingSafeEqual(suppliedCode, expectedCode));
}
function getPublicBaseUrl(req, configuredUrl) { function getPublicBaseUrl(req, configuredUrl) {
const forwardedProto = String(req.headers['x-forwarded-proto'] || '').trim().split(',')[0]; const forwardedProto = String(req.headers['x-forwarded-proto'] || '').trim().split(',')[0];
const protocol = forwardedProto || (req.socket && req.socket.encrypted ? 'https' : 'http'); const protocol = forwardedProto || (req.socket && req.socket.encrypted ? 'https' : 'http');
@@ -24,7 +48,7 @@ function getPublicBaseUrl(req, configuredUrl) {
return `${protocol}://${host}`.replace(/\/$/, ''); return `${protocol}://${host}`.replace(/\/$/, '');
} }
const configured = String(configuredUrl || process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, ''); const configured = String(configuredUrl || process.env.PLAYER_PUBLIC_URL || '').trim().replace(/\/$/, '');
return configured || null; return configured || null;
} }
@@ -51,7 +75,7 @@ function getPlayerPublicBaseUrl(req, configuredUrl) {
} }
function getPlayerInternalBaseUrl(configuredUrl) { function getPlayerInternalBaseUrl(configuredUrl) {
const configured = String(configuredUrl || process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, ''); const configured = String(configuredUrl || process.env.PLAYER_INTERNAL_URL || '').trim().replace(/\/$/, '');
return configured || null; return configured || null;
} }
@@ -120,16 +144,26 @@ async function commitDeviceBinding(pool, deviceId, clientName, screenSlug, isNam
} }
const screen = screenRows[0]; const screen = screenRows[0];
const available = await isClientNameAvailable(pool, normalizedClientName, normalizedDeviceId, liveConnections); const selectedClientName = await findAvailableClientName(pool, normalizedClientName, normalizedDeviceId, liveConnections);
if (!available) { if (!selectedClientName) {
const error = new Error('Client name already exists.'); const error = new Error('Client name already exists.');
error.statusCode = 400; error.statusCode = 400;
throw error; throw error;
} }
await pool.query( await pool.query(
'INSERT INTO d_onboarding_devices (device_id, client_name, screen_id) VALUES (?, ?, ?) ON DUPLICATE KEY UPDATE client_name = VALUES(client_name), screen_id = VALUES(screen_id), modified_at = CURRENT_TIMESTAMP', `UPDATE d_onboarding_devices
[normalizedDeviceId, normalizedClientName, screen.id] SET client_name = ?, screen_id = ?, last_seen_at = CURRENT_TIMESTAMP, modified_at = CURRENT_TIMESTAMP
WHERE device_id = ?`,
[selectedClientName, screen.id, normalizedDeviceId]
);
await pool.query(
`INSERT INTO d_onboarding_devices (device_id, client_name, screen_id)
SELECT ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM d_onboarding_devices WHERE device_id = ?
)`,
[normalizedDeviceId, selectedClientName, screen.id, normalizedDeviceId]
); );
return getOnboardingStatus(pool, normalizedDeviceId); return getOnboardingStatus(pool, normalizedDeviceId);
@@ -204,9 +238,41 @@ function registerPlayerOnboardingRoutes(app, options) {
const common = options && options.common ? options.common : null; const common = options && options.common ? options.common : null;
const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null; const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null;
const onboardingStore = options && options.onboardingStore ? options.onboardingStore : null; const onboardingStore = options && options.onboardingStore ? options.onboardingStore : null;
const playerPublicUrl = String(options && options.playerPublicBaseUrl || process.env.PLAYER_PUBLIC_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, ''); const playerPublicUrl = String(options && options.playerPublicBaseUrl || process.env.PLAYER_PUBLIC_URL || '').trim().replace(/\/$/, '');
const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, ''); const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const playerDeviceId = normalizeDeviceId(options && options.playerDeviceId); const playerDeviceId = normalizeDeviceId(options && options.playerDeviceId);
const onPairingCode = options && typeof options.onPairingCode === 'function' ? options.onPairingCode : null;
const pairingSessions = new Map();
function getPairingSession(deviceId, clientId) {
const normalizedDeviceId = normalizeDeviceId(deviceId) || playerDeviceId;
if (!normalizedDeviceId) {
return null;
}
const sessionKey = `${normalizedDeviceId}:${normalizeDeviceId(clientId) || 'default'}`;
let pairingSession = pairingSessions.get(sessionKey);
if (!isValidOnboardingPairingCode(pairingSession, pairingSession && pairingSession.code)) {
pairingSession = createPairingSession(normalizedDeviceId, clientId);
pairingSessions.set(sessionKey, pairingSession);
}
if (onPairingCode) {
onPairingCode(pairingSession.code, Array.from(pairingSessions.entries()).filter(function (entry) {
return isValidOnboardingPairingCode(entry[1], entry[1] && entry[1].code);
}).map(function (entry) {
return { deviceId: entry[1].deviceId, clientId: entry[1].clientId || null, code: entry[1].code };
}));
}
return pairingSession;
}
function findPairingSession(pairingCode) {
for (const [deviceId, pairingSession] of pairingSessions.entries()) {
if (isValidOnboardingPairingCode(pairingSession, pairingCode)) {
return { deviceId: pairingSession.deviceId, session: pairingSession };
}
}
return null;
}
if (!app || !common) { if (!app || !common) {
throw new Error('registerPlayerOnboardingRoutes requires app and common.'); throw new Error('registerPlayerOnboardingRoutes requires app and common.');
@@ -279,15 +345,71 @@ function registerPlayerOnboardingRoutes(app, options) {
next(); next();
} }
app.get('/', function (_req, res) { function requireOnboardingAuth(req, res, next) {
if (!sharedSecret) {
return next();
}
const pageToken = String(req.headers['x-pulse-page-auth'] || '').trim();
const pagePayload = verifyPageAuthToken(pageToken);
if (pagePayload && String(pagePayload.scope || '').trim() === 'onboarding') {
req.playerPageAuth = pagePayload;
return next();
}
if (verifyRequestAuth(req)) {
return next();
}
return res.status(401).json({ error: 'Onboarding authentication required.' });
}
app.get('/', async function (req, res, next) {
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.send(common.renderPlayerOnboardingLandingPage()); try {
const deviceId = normalizeDeviceId(req.query && req.query.clientId);
let status = null;
if (deviceId) {
if (bridgeBaseUrl) {
const response = await fetchThinClient(req, '/api/onboarding/status?deviceId=' + encodeURIComponent(deviceId), {
method: 'GET'
});
status = await readJsonResponse(response);
} else {
status = await getOnboardingStatus(pool, deviceId);
}
}
const screenId = status && (status.screen_id || status.screenId);
const screenSlug = status && (status.screen_slug || status.screenSlug);
if (screenId && screenSlug) {
return res.redirect('/screen/' + encodeURIComponent(screenSlug));
}
res.send(common.renderPlayerOnboardingLandingPage({ pairingCode: '' }));
} catch (error) {
next(error);
}
}); });
app.get('/onboard', async function (req, res, next) { app.get('/onboard', async function (req, res, next) {
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
try { try {
res.send(common.renderPlayerOnboardingFormPage(String(req.query.deviceId || playerDeviceId || '').trim())); const deviceId = playerDeviceId;
const onboardingBaseUrl = String(process.env.WEB_PUBLIC_URL || '').trim().replace(/\/$/, '') || getPublicBaseUrl(req, playerPublicUrl);
const clientId = normalizeDeviceId(req.query.clientId);
const pairingSession = getPairingSession(deviceId, clientId);
const pairingParams = [];
if (pairingSession && pairingSession.code) {
pairingParams.push(`code=${encodeURIComponent(pairingSession.code)}`);
}
const pairingQuery = pairingParams.length ? `?${pairingParams.join('&')}` : '';
if (bridgeBaseUrl && pairingSession && pairingSession.code) {
const response = await fetchThinClient(req, `/api/onboarding/url?pairingCode=${encodeURIComponent(pairingSession.code)}`);
const payload = await readJsonResponse(response);
if (payload && payload.url) {
return res.redirect(String(payload.url));
}
}
return res.redirect(`${onboardingBaseUrl}/pairing${pairingQuery}`);
} catch (error) { } catch (error) {
next(error); next(error);
} }
@@ -305,7 +427,7 @@ function registerPlayerOnboardingRoutes(app, options) {
next(); next();
}, async function (req, res, next) { }, async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId; const deviceId = normalizeDeviceId(req.query.deviceId || req.query.clientId);
if (bridgeBaseUrl) { if (bridgeBaseUrl) {
const response = await fetchThinClient(req, '/api/onboarding/status?deviceId=' + encodeURIComponent(deviceId || ''), { const response = await fetchThinClient(req, '/api/onboarding/status?deviceId=' + encodeURIComponent(deviceId || ''), {
method: 'GET' method: 'GET'
@@ -337,6 +459,26 @@ function registerPlayerOnboardingRoutes(app, options) {
} }
}); });
app.get('/api/onboarding/resolve', requireOnboardingAuth, function (req, res) {
const pairingCode = String(req.query.pairingCode || '').trim();
const pairing = findPairingSession(pairingCode);
if (!pairing) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
}
res.json({ deviceId: pairing.deviceId, clientId: pairing.session.clientId || null });
});
app.get('/api/onboarding/session', requireOnboardingPageAuth, function (req, res) {
const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId;
const clientId = normalizeDeviceId(req.query.clientId);
const pairingSession = getPairingSession(deviceId, clientId);
if (!pairingSession) {
return res.status(503).json({ error: 'Player identity is unavailable.' });
}
res.set('Cache-Control', 'no-store');
res.json({ deviceId: deviceId, pairingCode: pairingSession.code });
});
app.get('/api/onboarding/screens', requireOnboardingPageAuth, async function (_req, res, next) { app.get('/api/onboarding/screens', requireOnboardingPageAuth, async function (_req, res, next) {
try { try {
if (bridgeBaseUrl) { if (bridgeBaseUrl) {
@@ -356,14 +498,40 @@ function registerPlayerOnboardingRoutes(app, options) {
} }
}); });
app.get('/api/onboarding/qr', async function (req, res, next) { app.get('/api/onboarding/qr', async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId; const deviceId = normalizeDeviceId(req.query.deviceId) || playerDeviceId;
const clientId = normalizeDeviceId(req.query.clientId);
if (!deviceId) { if (!deviceId) {
return res.status(400).json({ error: 'Device ID is required' }); return res.status(400).json({ error: 'Device ID is required' });
} }
const onboardingUrl = `${getPublicBaseUrl(req, playerPublicUrl)}/onboard?deviceId=${encodeURIComponent(deviceId)}`; const pairingSession = getPairingSession(deviceId, clientId);
const svg = await createStyledQrCodeSvg({ value: onboardingUrl, qr_margin: 20 }); if (!pairingSession) {
return res.status(503).json({ error: 'Pairing session is unavailable.' });
}
if (bridgeBaseUrl) {
const response = await fetchThinClient(req, `/api/onboarding/qr?pairingCode=${encodeURIComponent(pairingSession.code)}`);
if (response && response.ok) {
const svg = await response.text();
res.set('Content-Type', response.headers.get('content-type') || 'image/svg+xml; charset=utf-8');
res.set('Cache-Control', 'no-store');
return res.send(svg);
}
}
const onboardingBaseUrl = String(process.env.WEB_PUBLIC_URL || '').trim().replace(/\/$/, '') || getPublicBaseUrl(req, playerPublicUrl);
const onboardingUrl = `${onboardingBaseUrl}/pairing?code=${encodeURIComponent(pairingSession.code)}`;
const svg = await createStyledQrCodeSvg({
value: onboardingUrl,
qr_margin: 20,
qr_dots_type: 'dots',
qr_dots_color: '#f4f8f5',
qr_corners_square_type: 'dot',
qr_corners_square_color: '#f4f8f5',
qr_corners_dot_type: 'dot',
qr_corners_dot_color: '#f0bd70',
qr_background_transparent: true
});
res.set('Content-Type', 'image/svg+xml; charset=utf-8'); res.set('Content-Type', 'image/svg+xml; charset=utf-8');
res.set('Cache-Control', 'no-store'); res.set('Cache-Control', 'no-store');
res.send(svg); res.send(svg);
@@ -372,20 +540,28 @@ function registerPlayerOnboardingRoutes(app, options) {
} }
}); });
app.post('/api/onboarding', requireOnboardingPageAuth, express.json(), async function (req, res, next) { app.post('/api/onboarding', express.json(), requireOnboardingAuth, async function (req, res, next) {
try { try {
const deviceId = normalizeDeviceId(req.body && req.body.deviceId) || playerDeviceId; const deviceId = playerDeviceId;
const clientName = String((req.body && req.body.clientName) || '').trim(); const clientName = String((req.body && req.body.clientName) || '').trim();
const screenSlug = String((req.body && req.body.screenSlug) || '').trim(); const screenSlug = String((req.body && req.body.screenSlug) || '').trim();
const pairingCode = String((req.body && req.body.pairingCode) || '').trim();
const clientId = normalizeDeviceId(req.body && req.body.clientId);
const retryAfterSeconds = isOnboardingSignupRateLimited(req, deviceId); const retryAfterSeconds = isOnboardingSignupRateLimited(req, deviceId);
if (retryAfterSeconds) { if (retryAfterSeconds) {
res.set('Retry-After', String(retryAfterSeconds)); res.set('Retry-After', String(retryAfterSeconds));
return res.status(429).json({ error: 'Too many onboarding attempts. Please try again later.' }); return res.status(429).json({ error: 'Too many onboarding attempts. Please try again later.' });
} }
const pairing = findPairingSession(pairingCode);
const pairingSession = pairing && pairing.session;
if (!isValidOnboardingPairingCode(pairingSession, pairingCode)) {
return res.status(401).json({ error: 'A valid kiosk pairing code is required.' });
}
if (bridgeBaseUrl) { if (bridgeBaseUrl) {
const forwardedBody = Object.assign({}, req.body || {}, { const forwardedBody = Object.assign({}, req.body || {}, {
deviceId: deviceId clientId: clientId || null
}); });
const response = await fetch(new URL('/api/onboarding', bridgeBaseUrl).toString(), { const response = await fetch(new URL('/api/onboarding', bridgeBaseUrl).toString(), {
method: 'POST', method: 'POST',
@@ -403,6 +579,10 @@ function registerPlayerOnboardingRoutes(app, options) {
if (!payload) { if (!payload) {
return res.status(502).json({ error: 'Player bridge returned an invalid response.' }); return res.status(502).json({ error: 'Player bridge returned an invalid response.' });
} }
if (response.ok) {
pairingSessions.delete(deviceId);
res.cookie('pulse-player-client-id', clientId, { path: '/', sameSite: 'lax' });
}
payload.playerUrl = payload && payload.screenSlug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(payload.screenSlug)}` : `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(screenSlug)}`; payload.playerUrl = payload && payload.screenSlug ? `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(payload.screenSlug)}` : `${getPublicBaseUrl(req, playerPublicUrl)}/screen/${encodeURIComponent(screenSlug)}`;
return res.json(payload); return res.json(payload);
} }
@@ -416,8 +596,12 @@ function registerPlayerOnboardingRoutes(app, options) {
return res.status(400).json({ error: 'Screen is required' }); return res.status(400).json({ error: 'Screen is required' });
} }
const status = await bindDeviceToScreen(pool, deviceId, clientName, screenSlug, playerRuntime.isClientNameAvailableOnScreen, playerRuntime, onboardingStore); if (!clientId) {
await bindPlayerToScreen(pool, deviceId, screenSlug); return res.status(400).json({ error: 'Client ID is required' });
}
const status = await bindDeviceToScreen(pool, clientId, clientName, screenSlug, playerRuntime.isClientNameAvailableOnScreen, playerRuntime, onboardingStore);
pairingSessions.delete(deviceId);
res.cookie('pulse-player-client-id', clientId, { path: '/', sameSite: 'lax' });
res.json({ res.json({
deviceId: deviceId, deviceId: deviceId,
clientName: status ? status.client_name : clientName, clientName: status ? status.client_name : clientName,
@@ -446,5 +630,6 @@ module.exports = {
upsertPlayerRegistration: upsertPlayerRegistration, upsertPlayerRegistration: upsertPlayerRegistration,
bindPlayerToScreen: bindPlayerToScreen, bindPlayerToScreen: bindPlayerToScreen,
bindDeviceToScreen: bindDeviceToScreen, bindDeviceToScreen: bindDeviceToScreen,
isValidOnboardingPairingCode: isValidOnboardingPairingCode,
registerPlayerOnboardingRoutes: registerPlayerOnboardingRoutes registerPlayerOnboardingRoutes: registerPlayerOnboardingRoutes
}; };
@@ -65,10 +65,11 @@
var formData = new FormData(form); var formData = new FormData(form);
var clientName = String(formData.get("clientName") || "").trim(); var clientName = String(formData.get("clientName") || "").trim();
var screenSlug = String(formData.get("screenSlug") || "").trim(); var screenSlug = String(formData.get("screenSlug") || "").trim();
var pairingCode = String(formData.get("pairingCode") || "").trim();
if (!clientName) { setMessage("Client name is required."); return; } if (!clientName) { setMessage("Client name is required."); return; }
if (!screenSlug) { setMessage("Screen is required."); return; } if (!screenSlug) { setMessage("Screen is required."); return; }
setMessage("Saving client..."); setMessage("Saving client...");
var payload = { clientName: clientName, screenSlug: screenSlug }; var payload = { clientName: clientName, screenSlug: screenSlug, pairingCode: pairingCode };
if (deviceId) { if (deviceId) {
payload.deviceId = deviceId; payload.deviceId = deviceId;
} }
@@ -13,23 +13,12 @@
} }
var screenKey = "pulse-signage-player-screen-slug"; var screenKey = "pulse-signage-player-screen-slug";
var qr = document.getElementById("onboarding-qr"); var qr = document.getElementById("onboarding-qr");
var status = document.getElementById("onboarding-status"); var pairingCodeElement = document.getElementById("onboarding-pairing-code");
var localForm = document.getElementById("onboarding-local-form");
var localMessage = document.getElementById("onboarding-message");
var localScreenSelect = document.getElementById("onboarding-screen-select");
var qrPlaceholderSrc = "data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E"; var qrPlaceholderSrc = "data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E";
function parseResponseError(response) {
return response.text().then(function (text) {
var fallbackMessage = text && text.trim() ? text.trim() : "Unable to save onboarding.";
try {
var payload = JSON.parse(text);
return payload && payload.error ? payload.error : fallbackMessage;
} catch (_error) {
return fallbackMessage;
}
});
}
function getDeviceId() { function getDeviceId() {
var configuredDeviceId = document.getElementById("onboarding-shell");
configuredDeviceId = configuredDeviceId ? String(configuredDeviceId.getAttribute("data-player-device-id") || "").trim() : "";
if (configuredDeviceId) { return configuredDeviceId; }
var stored = ""; var stored = "";
try { stored = window.sessionStorage.getItem(deviceKey) || ""; } catch (_error) { stored = ""; } try { stored = window.sessionStorage.getItem(deviceKey) || ""; } catch (_error) { stored = ""; }
if (stored) { return stored; } if (stored) { return stored; }
@@ -37,71 +26,34 @@
try { window.sessionStorage.setItem(deviceKey, next); } catch (_error2) {} try { window.sessionStorage.setItem(deviceKey, next); } catch (_error2) {}
return next; return next;
} }
function setStatus(message) { if (status) { status.textContent = message; } } function loadQr(deviceId, clientId) {
function setLocalMessage(message) { if (localMessage) { localMessage.textContent = message || ""; } }
function setSelectOptions(select, screens, selectedSlug) {
if (!select) { return; }
while (select.firstChild) { select.removeChild(select.firstChild); }
var placeholder = document.createElement("option");
placeholder.value = "";
placeholder.textContent = "Select a screen";
select.appendChild(placeholder);
(Array.isArray(screens) ? screens : []).forEach(function (screen) {
var option = document.createElement("option");
option.value = String(screen && screen.slug ? screen.slug : "");
option.textContent = String(screen && (screen.name || screen.slug) ? (screen.name || screen.slug) : "Screen");
if (selectedSlug && String(option.value) === String(selectedSlug)) {
option.selected = true;
}
select.appendChild(option);
});
}
function loadScreens(selectedSlug) {
return fetch("/api/onboarding/screens", { cache: "no-store" })
.then(function (response) { return response.ok ? response.json() : null; })
.then(function (payload) {
var screens = payload && Array.isArray(payload.screens) ? payload.screens : [];
setSelectOptions(localScreenSelect, screens, selectedSlug);
return screens;
})
.catch(function () { setSelectOptions(localScreenSelect, [], selectedSlug); return []; });
}
function loadQr(deviceId) {
if (!qr) { return; } if (!qr) { return; }
qr.onerror = function () { qr.onerror = function () {
qr.src = qrPlaceholderSrc; qr.src = qrPlaceholderSrc;
}; };
qr.src = "/api/onboarding/qr?deviceId=" + encodeURIComponent(deviceId); qr.src = "/api/onboarding/qr?deviceId=" + encodeURIComponent(deviceId) + "&clientId=" + encodeURIComponent(clientId);
} }
function submitOnboarding(deviceId, clientName, screenSlug) { function loadPairingSession(deviceId, clientId) {
return fetch("/api/onboarding", { return fetch("/api/onboarding/session?deviceId=" + encodeURIComponent(deviceId) + "&clientId=" + encodeURIComponent(clientId), { cache: "no-store" })
method: "POST", .then(function (response) { return response.ok ? response.json() : null; })
headers: { "Content-Type": "application/json", Accept: "application/json" },
body: JSON.stringify({ deviceId: deviceId, clientName: clientName, screenSlug: screenSlug })
})
.then(function (response) {
if (response.ok) {
return response.json();
}
return parseResponseError(response).then(function (messageText) {
throw new Error(messageText);
});
})
.then(function (payload) { .then(function (payload) {
if (!payload || !payload.screenSlug) { throw new Error("Unable to save onboarding."); } if (payload && payload.pairingCode && pairingCodeElement) {
if (payload.clientName) { setSessionStorageItem(clientNameKey, payload.clientName); } pairingCodeElement.textContent = payload.pairingCode;
if (payload.clientName && payload.screenSlug) { setSessionStorageItem(getClientNameStorageKey(payload.screenSlug), payload.clientName); }
try { window.localStorage.setItem(screenKey, payload.screenSlug); } catch (_error) {}
setLocalMessage("Onboarding complete.");
if (localForm) {
Array.prototype.slice.call(localForm.querySelectorAll("input, select, button")).forEach(function (control) {
control.disabled = true;
});
} }
}); return payload;
})
.catch(function () { return null; });
}
function getClientId() {
var stored = getSessionStorageItem("pulse-signage-player-client-id");
if (stored) { return stored; }
var next = (window.crypto && window.crypto.randomUUID ? window.crypto.randomUUID() : "client-" + Date.now() + "-" + Math.random().toString(16).slice(2));
setSessionStorageItem("pulse-signage-player-client-id", next);
return next;
} }
function redirectIfOnboarded(deviceId) { function redirectIfOnboarded(deviceId) {
return fetch("/api/onboarding/status?deviceId=" + encodeURIComponent(deviceId), { cache: "no-store" }) var bindingId = getClientId() || deviceId;
return fetch("/api/onboarding/status?deviceId=" + encodeURIComponent(bindingId), { cache: "no-store" })
.then(function (response) { return response.ok ? response.json() : null; }) .then(function (response) { return response.ok ? response.json() : null; })
.then(function (payload) { .then(function (payload) {
if (payload && payload.onboarded && payload.screenSlug) { if (payload && payload.onboarded && payload.screenSlug) {
@@ -115,37 +67,16 @@
}) })
.catch(function () { return false; }); .catch(function () { return false; });
} }
var clientId = getClientId();
var deviceId = getDeviceId(); var deviceId = getDeviceId();
if (localForm) {
localForm.addEventListener("submit", function (event) {
event.preventDefault();
var formData = new FormData(localForm);
var clientName = String(formData.get("clientName") || "").trim();
var screenSlug = String(formData.get("screenSlug") || "").trim();
if (!clientName) { setLocalMessage("Client name is required."); return; }
if (!screenSlug) { setLocalMessage("Screen is required."); return; }
setLocalMessage("Saving client...");
submitOnboarding(deviceId, clientName, screenSlug).catch(function (error) {
setLocalMessage(error && error.message ? error.message : "Unable to save onboarding.");
});
});
}
loadScreens().then(function () {
try {
var storedClientName = getSessionStorageItem(clientNameKey) || "";
if (storedClientName && localForm) {
var clientNameInput = localForm.querySelector("input[name=\"clientName\"]");
if (clientNameInput) { clientNameInput.value = storedClientName; }
}
} catch (_error) {}
});
redirectIfOnboarded(deviceId).then(function (redirected) { redirectIfOnboarded(deviceId).then(function (redirected) {
if (redirected) { return; } if (redirected) { return; }
if (qr && !qr.getAttribute("src")) { if (qr && !qr.getAttribute("src")) {
qr.src = qrPlaceholderSrc; qr.src = qrPlaceholderSrc;
} }
loadQr(deviceId); loadPairingSession(deviceId, clientId).then(function () {
setStatus("Waiting for onboarding to finish."); loadQr(deviceId, clientId);
});
window.setInterval(function () { redirectIfOnboarded(deviceId); }, 2000); window.setInterval(function () { redirectIfOnboarded(deviceId); }, 2000);
}); });
}()); }());
+7 -2
View File
@@ -23,7 +23,12 @@
function getOnboardingDeviceId() { function getOnboardingDeviceId() {
try { try {
var storedDeviceId = getSessionStorageItem(onboardingDeviceIdStorageKey); var storedDeviceId = getSessionStorageItem(onboardingDeviceIdStorageKey);
return String(storedDeviceId || '').trim(); if (storedDeviceId) {
return String(storedDeviceId || '').trim();
}
var nextDeviceId = window.crypto && window.crypto.randomUUID ? window.crypto.randomUUID() : 'device-' + Date.now() + '-' + Math.random().toString(16).slice(2);
setSessionStorageItem(onboardingDeviceIdStorageKey, nextDeviceId);
return String(nextDeviceId || '').trim();
} catch (_error) { } catch (_error) {
return ''; return '';
} }
@@ -85,7 +90,7 @@
}); });
}).then(function (payload) { }).then(function (payload) {
var serverName = payload && payload.clientName ? String(payload.clientName).trim() : ''; var serverName = payload && payload.clientName ? String(payload.clientName).trim() : '';
if (serverName) { if (serverName && !getOnboardingClientName()) {
applyOnboardingClientName(serverName, null); applyOnboardingClientName(serverName, null);
} }
return onboardingClientName || getOnboardingClientName(); return onboardingClientName || getOnboardingClientName();
+3
View File
@@ -131,6 +131,9 @@
if (window.__pulsePageAuthToken) { if (window.__pulsePageAuthToken) {
request.setRequestHeader('x-pulse-page-auth', window.__pulsePageAuthToken); request.setRequestHeader('x-pulse-page-auth', window.__pulsePageAuthToken);
} }
if (typeof getCommandClientId === 'function') {
request.setRequestHeader('x-pulse-client-id', getCommandClientId());
}
if (announcementEtag) { if (announcementEtag) {
request.setRequestHeader('If-None-Match', announcementEtag); request.setRequestHeader('If-None-Match', announcementEtag);
} }
+20 -39
View File
@@ -1,41 +1,11 @@
<!-- Player page bootstrap and browser-side playback lifecycle. -->
<script> <script>
const slug = {{SLUG_JSON}}; const slug = {{SLUG_JSON}};
const initialData = {{INITIAL_DATA_JSON}}; let initialData = {{INITIAL_DATA_JSON}};
window.slug = slug; window.slug = slug;
window.initialData = initialData; window.initialData = initialData;
const app = document.getElementById('app'); const app = document.getElementById('app');
(function () {
var root = window;
var registry = root.pulsePlayerRegionTypes && typeof root.pulsePlayerRegionTypes === 'object' ? root.pulsePlayerRegionTypes : {};
function normalizeType(type) {
return String(type || '').trim().toLowerCase();
}
function register(type, definition) {
registry[normalizeType(type)] = definition || {};
return registry[normalizeType(type)];
}
function get(type) {
return registry[normalizeType(type)] || null;
}
function list() {
return Object.keys(registry).map(function (type) {
return {
type: type,
definition: registry[type] || {}
};
});
}
root.pulsePlayerRegionTypes = {
register: register,
get: get,
list: list
};
}());
let slides = Array.isArray(initialData && initialData.slides) ? initialData.slides.map(normalizeSlide) : []; let slides = Array.isArray(initialData && initialData.slides) ? initialData.slides.map(normalizeSlide) : [];
let currentPlaylistSignature = ''; let currentPlaylistSignature = '';
let currentPlaylistEtag = ''; let currentPlaylistEtag = '';
@@ -61,6 +31,7 @@
let viewportRenderTimer = null; let viewportRenderTimer = null;
let refreshRetryTimer = null; let refreshRetryTimer = null;
let refreshRetryDelayMs = 0; let refreshRetryDelayMs = 0;
let playlistRefreshTimer = null;
let commandClientId = null; let commandClientId = null;
let screenWakeLock = null; let screenWakeLock = null;
let screenWakeLockRequestPromise = null; let screenWakeLockRequestPromise = null;
@@ -73,7 +44,7 @@
let slideExpiresAt = null; let slideExpiresAt = null;
const slideFadeDurationMs = 560; const slideFadeDurationMs = 560;
const commandSocketPath = '/ws/screens/' + encodeURIComponent(slug); const commandSocketPath = '/ws/screens/' + encodeURIComponent(slug);
const commandClientStorageKey = 'pulse-signage-player-client-id:' + slug; const commandClientStorageKey = 'pulse-signage-player-client-id';
const playlistSnapshotStorageKey = 'pulse-signage-player-playlist-snapshot:' + slug; const playlistSnapshotStorageKey = 'pulse-signage-player-playlist-snapshot:' + slug;
const initialPlaylistSnapshot = loadPlaylistSnapshot(); const initialPlaylistSnapshot = loadPlaylistSnapshot();
let offlineBanner = null; let offlineBanner = null;
@@ -102,7 +73,12 @@
// Render the empty-state message into the player root. // Render the empty-state message into the player root.
function renderEmpty(message) { function renderEmpty(message) {
app.innerHTML = '<div class="empty">' + escapeHtml(message) + '</div>'; var markup = '<div class="empty">' + escapeHtml(message) + '</div>';
if (currentPlaylistFadeBetweenSlides && typeof renderSlideMarkup === 'function') {
renderSlideMarkup(markup, true);
return;
}
app.innerHTML = markup;
} }
// Announce the player to the command websocket. // Announce the player to the command websocket.
@@ -181,10 +157,6 @@
releaseScreenWakeLock(); releaseScreenWakeLock();
}); });
if (initialPlaylistSnapshot && initialPlaylistSnapshot.slides.length) {
applyPlaylistSnapshot(initialPlaylistSnapshot);
}
if (slides.length) { if (slides.length) {
if (!currentPlaylistSignature) { if (!currentPlaylistSignature) {
currentPlaylistSignature = getPlaylistRevision(initialData && initialData.slides ? initialData : { slides: slides }); currentPlaylistSignature = getPlaylistRevision(initialData && initialData.slides ? initialData : { slides: slides });
@@ -208,10 +180,19 @@
showCurrent(); showCurrent();
refresh(); refresh();
} else { } else {
if (initialPlaylistSnapshot && applyPlaylistSnapshot(initialPlaylistSnapshot)) {
currentPlaylistSkipUnavailableRtmp = Boolean(initialPlaylistSnapshot.skipUnavailableRtmp);
showCurrent();
}
syncBlackoutState(); syncBlackoutState();
refresh(); refresh();
} }
syncOfflineBanner(); syncOfflineBanner();
syncScreenWakeLock(); syncScreenWakeLock();
playlistRefreshTimer = window.setInterval(function () {
if (document.visibilityState !== 'hidden') {
refresh();
}
}, 60 * 1000);
connectCommandSocket(); connectCommandSocket();
</script> </script>
+1 -1
View File
@@ -7,7 +7,7 @@
<link rel="icon" type="image/png" href="/assets/favicon.png" /> <link rel="icon" type="image/png" href="/assets/favicon.png" />
<link rel="stylesheet" href="/assets/adminlte/bootstrap-icons/css/bootstrap-icons.min.css" /> <link rel="stylesheet" href="/assets/adminlte/bootstrap-icons/css/bootstrap-icons.min.css" />
<link rel="stylesheet" href="/assets/vendor/animate.css/animate.min.css" /> <link rel="stylesheet" href="/assets/vendor/animate.css/animate.min.css" />
<link rel="stylesheet" href="/assets/css/player.css?v=36" /> <link rel="stylesheet" href="/assets/css/player.css?v=37" />
{{{STYLESHEETS}}} {{{STYLESHEETS}}}
</head> </head>
<body class="{{BODY_CLASS}}"> <body class="{{BODY_CLASS}}">
+128 -5
View File
@@ -1,6 +1,7 @@
// Player playlist assembly, snapshot persistence, and playlist revision helpers. // Player playlist assembly, snapshot persistence, and playlist revision helpers.
const crypto = require('crypto'); const crypto = require('crypto');
const { convertWeatherSnapshot } = require('#src/data/weather-units');
const fs = require('fs'); const fs = require('fs');
const path = require('path'); const path = require('path');
const { createStyledQrCodeDataUrl } = require('../data/qr-code'); const { createStyledQrCodeDataUrl } = require('../data/qr-code');
@@ -9,6 +10,8 @@ function createPlayerPlaylistService(options) {
const pool = options && options.pool ? options.pool : null; const pool = options && options.pool ? options.pool : null;
const common = options && options.common ? options.common : null; const common = options && options.common ? options.common : null;
const snapshotDir = options && options.snapshotDir ? options.snapshotDir : null; const snapshotDir = options && options.snapshotDir ? options.snapshotDir : null;
const mediaDir = options && options.mediaDir ? path.resolve(String(options.mediaDir)) : null;
const remoteImageCacheDir = mediaDir ? path.join(mediaDir, 'player-cache', 'remote-images') : null;
if (!pool) { if (!pool) {
throw new Error('pool is required'); throw new Error('pool is required');
@@ -61,11 +64,110 @@ function createPlayerPlaylistService(options) {
return createStyledQrCodeDataUrl(value); return createStyledQrCodeDataUrl(value);
} }
function getPlaceholderImageExpressions(value, output) {
const expressions = output || [];
const source = String(value || '');
const pattern = /\{\{\s*([^{}]*?\.image\s*\([^{}]*\)[^{}]*?)\s*\}\}/gi;
let match = null;
while ((match = pattern.exec(source))) {
expressions.push(String(match[1] || '').trim());
}
return expressions;
}
function resolvePathValue(value, expression) {
const parsed = String(expression || '').replace(/\.image\s*\([^)]*\)\s*$/i, '').trim();
return parsed.split('.').reduce(function (current, segment) {
return current === undefined || current === null ? '' : current[segment];
}, value);
}
function getApiItems(responseJson, itemsPath) {
let current = responseJson;
const pathValue = String(itemsPath || '').trim();
if (pathValue) {
pathValue.split('.').forEach(function (segment) {
current = current === undefined || current === null ? '' : current[segment];
});
return Array.isArray(current) ? current : [];
}
if (Array.isArray(responseJson)) return responseJson;
if (responseJson && Array.isArray(responseJson.items)) return responseJson.items;
if (responseJson && Array.isArray(responseJson.results)) return responseJson.results;
if (responseJson && Array.isArray(responseJson.data)) return responseJson.data;
return responseJson ? [responseJson] : [];
}
async function cacheRemoteImage(url) {
const remoteUrl = String(url || '').trim();
if (!remoteImageCacheDir || !/^https?:\/\//i.test(remoteUrl)) return '';
const hash = crypto.createHash('sha256').update(remoteUrl).digest('hex');
await fs.promises.mkdir(remoteImageCacheDir, { recursive: true });
const existing = (await fs.promises.readdir(remoteImageCacheDir)).find(function (name) { return name.startsWith(hash + '.'); });
if (existing) return '/media/player-cache/remote-images/' + existing;
try {
const response = await fetch(remoteUrl, { signal: AbortSignal.timeout(15000) });
if (!response.ok || !String(response.headers.get('content-type') || '').toLowerCase().startsWith('image/')) return '';
const bytes = Buffer.from(await response.arrayBuffer());
if (bytes.length > 10 * 1024 * 1024) return '';
const contentType = String(response.headers.get('content-type') || '').toLowerCase();
const extension = contentType.includes('svg') ? '.svg' : contentType.includes('png') ? '.png' : contentType.includes('webp') ? '.webp' : contentType.includes('gif') ? '.gif' : '.jpg';
const fileName = hash + extension;
const filePath = path.join(remoteImageCacheDir, fileName);
await fs.promises.writeFile(filePath, bytes);
return '/media/player-cache/remote-images/' + fileName;
} catch (_error) {
return '';
}
}
async function cachePlaceholderImages(slides, rssFeeds, apiSources) {
if (!remoteImageCacheDir) return;
const usedPaths = new Set();
const allSlideRows = await pool.query('SELECT content_json FROM c_slides').then(function (result) { return result[0] || []; });
const allContents = allSlideRows.map(function (row) { return common.parseJsonSafe(row.content_json) || {}; });
const sourceContent = allContents.concat((slides || []).map(function (slide) { return slide.content || {}; }));
const cacheSource = async function (source, item, expressions) {
if (!source || !item) return;
for (const expression of expressions) {
const remoteUrl = String(resolvePathValue(item, expression) || '').trim();
const localPath = await cacheRemoteImage(remoteUrl);
if (localPath) {
source.imageCache = source.imageCache || {};
source.imageCache[remoteUrl] = localPath;
usedPaths.add(localPath);
}
}
};
for (const content of sourceContent) {
for (const key of Object.keys(content || {})) {
const region = content[key];
if (!region || typeof region !== 'object') continue;
const expressions = getPlaceholderImageExpressions(region.value, []);
if (!expressions.length) continue;
const itemNumber = Math.max(1, Number(region.item_number || 1)) - 1;
if (String(region.type || '').toLowerCase() === 'api') {
const source = (apiSources || []).find(function (entry) { return Number(entry.id) === Number(region.source_id); });
const items = source ? getApiItems(source.responseJson, region.items_path) : [];
await cacheSource(source, items[itemNumber], expressions);
}
if (String(region.type || '').toLowerCase() === 'rss') {
const feed = (rssFeeds || []).find(function (entry) { return Number(entry.id) === Number(region.feed_id); });
await cacheSource(feed, feed && feed.items && feed.items[itemNumber], expressions);
}
}
}
const files = await fs.promises.readdir(remoteImageCacheDir).catch(function () { return []; });
await Promise.all(files.filter(function (file) { return !usedPaths.has('/media/player-cache/remote-images/' + file); }).map(function (file) {
return fs.promises.unlink(path.join(remoteImageCacheDir, file)).catch(function () {});
}));
}
async function buildScreenPlaylist(slug) { async function buildScreenPlaylist(slug) {
try { try {
const [screenRows] = await pool.query('SELECT id, name, slug, playlist_id, created_at, modified_at, created_by, modified_by FROM d_screens WHERE slug = ?', [slug]); const [screenRows] = await pool.query('SELECT id, name, slug, playlist_id, created_at, modified_at, created_by, modified_by FROM d_screens WHERE slug = ?', [slug]);
if (!screenRows.length) { if (!screenRows.length) {
return { screen: null, playlist: null, slides: [], rssFeeds: [], apiSources: [], timetableGroups: [] }; return { screen: null, playlist: null, slides: [], rssFeeds: [], apiSources: [], timetableGroups: [], weatherLocations: [] };
} }
const screen = screenRows[0]; const screen = screenRows[0];
@@ -77,6 +179,7 @@ function createPlayerPlaylistService(options) {
rssFeeds: [], rssFeeds: [],
apiSources: [], apiSources: [],
timetableGroups: [], timetableGroups: [],
weatherLocations: [],
revision: getPlaylistRevision(screen, null, [], [], [], [], [], []) revision: getPlaylistRevision(screen, null, [], [], [], [], [], [])
}; };
await writeSnapshot(slug, payloadWithoutPlaylist); await writeSnapshot(slug, payloadWithoutPlaylist);
@@ -120,7 +223,7 @@ function createPlayerPlaylistService(options) {
let regionRows = []; let regionRows = [];
if (templateIds.length) { if (templateIds.length) {
[templateRows] = await pool.query(` [templateRows] = await pool.query(`
SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.created_at, st.modified_at, SELECT st.id, st.name, st.canvas_size_id, st.background_image_path, st.background_color, st.background_gradient, st.created_at, st.modified_at,
cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height, cs.width AS canvas_width, cs.height AS canvas_height cs.name AS canvas_size_name, cs.width AS canvas_size_width, cs.height AS canvas_size_height, cs.width AS canvas_width, cs.height AS canvas_height
FROM c_templates st FROM c_templates st
LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id LEFT JOIN c_canvas_sizes cs ON cs.id = st.canvas_size_id
@@ -241,8 +344,25 @@ function createPlayerPlaylistService(options) {
timetableGroups = Array.isArray(timetableData && timetableData.timetableGroups) ? timetableData.timetableGroups : []; timetableGroups = Array.isArray(timetableData && timetableData.timetableGroups) ? timetableData.timetableGroups : [];
} }
const revision = getPlaylistRevision(screen, playlist, slideRows, scheduleRuleRows, templateRows, regionRows, rssFeeds, apiSources, timetableGroups); let weatherLocations = [];
const payload = { screen: screen, playlist: playlist, slides: slides, rssFeeds: rssFeeds, apiSources: apiSources, timetableGroups: timetableGroups, revision: revision }; if (typeof common.fetchWeatherLocationsData === 'function') {
const weatherData = await common.fetchWeatherLocationsData(pool);
weatherLocations = (weatherData.weatherLocations || []).map(function (location) {
const responseJson = common.parseJsonSafe ? common.parseJsonSafe(location.last_response_json) : null;
return Object.assign({}, location, {
responseJson: convertWeatherSnapshot(responseJson, {
temperature: location.temperature_unit === 'fahrenheit' ? 'fahrenheit' : 'celsius',
wind: location.wind_unit === 'mph' ? 'mph' : location.wind_unit === 'ms' ? 'ms' : 'kmh',
precipitation: location.precipitation_unit === 'inch' ? 'inch' : 'mm'
})
});
});
}
await cachePlaceholderImages(slides, rssFeeds, apiSources);
const revision = getPlaylistRevision(screen, playlist, slideRows, scheduleRuleRows, templateRows, regionRows, rssFeeds, apiSources, timetableGroups, weatherLocations);
const payload = { screen: screen, playlist: playlist, slides: slides, rssFeeds: rssFeeds, apiSources: apiSources, timetableGroups: timetableGroups, weatherLocations: weatherLocations, revision: revision };
await writeSnapshot(slug, payload); await writeSnapshot(slug, payload);
return payload; return payload;
} catch (error) { } catch (error) {
@@ -259,7 +379,7 @@ function createPlayerPlaylistService(options) {
hash.update('\0'); hash.update('\0');
} }
function getPlaylistRevision(screen, playlist, slideRows, scheduleRuleRows, templateRows, regionRows, rssFeeds, apiSources, timetableGroups) { function getPlaylistRevision(screen, playlist, slideRows, scheduleRuleRows, templateRows, regionRows, rssFeeds, apiSources, timetableGroups, weatherLocations) {
const hash = crypto.createHash('sha1'); const hash = crypto.createHash('sha1');
updatePlaylistRevisionHash(hash, screen && screen.id); updatePlaylistRevisionHash(hash, screen && screen.id);
@@ -302,6 +422,8 @@ function createPlayerPlaylistService(options) {
updatePlaylistRevisionHash(hash, template.canvas_size_height); updatePlaylistRevisionHash(hash, template.canvas_size_height);
updatePlaylistRevisionHash(hash, template.background_image_path); updatePlaylistRevisionHash(hash, template.background_image_path);
updatePlaylistRevisionHash(hash, template.background_color); updatePlaylistRevisionHash(hash, template.background_color);
updatePlaylistRevisionHash(hash, template.background_gradient);
updatePlaylistRevisionHash(hash, template.background_gradient);
updatePlaylistRevisionHash(hash, template.modified_at); updatePlaylistRevisionHash(hash, template.modified_at);
}); });
@@ -323,6 +445,7 @@ function createPlayerPlaylistService(options) {
updatePlaylistRevisionHash(hash, JSON.stringify(rssFeeds || [])); updatePlaylistRevisionHash(hash, JSON.stringify(rssFeeds || []));
updatePlaylistRevisionHash(hash, JSON.stringify(apiSources || [])); updatePlaylistRevisionHash(hash, JSON.stringify(apiSources || []));
updatePlaylistRevisionHash(hash, JSON.stringify(timetableGroups || [])); updatePlaylistRevisionHash(hash, JSON.stringify(timetableGroups || []));
updatePlaylistRevisionHash(hash, JSON.stringify(weatherLocations || []));
return hash.digest('hex'); return hash.digest('hex');
} }
+215 -46
View File
@@ -4,16 +4,16 @@ body {
width: 100%; width: 100%;
height: 100%; height: 100%;
overflow: hidden; overflow: hidden;
background: #111; background: #0a0a0a;
color: #fff; color: #fff;
font-family: Arial, sans-serif; font-family: Arial, sans-serif;
} }
body.onboarding-page { body.onboarding-page {
background: background:
radial-gradient(circle at top, rgba(82, 144, 255, 0.28), transparent 32%), radial-gradient(circle at 78% 20%, rgba(55, 195, 178, 0.16), transparent 28%),
radial-gradient(circle at bottom right, rgba(34, 197, 94, 0.18), transparent 26%), radial-gradient(circle at 12% 90%, rgba(237, 177, 89, 0.12), transparent 30%),
linear-gradient(160deg, #09111f 0%, #0b1323 52%, #111827 100%); linear-gradient(145deg, #07131b 0%, #0b2028 58%, #10252a 100%);
overflow-x: hidden; overflow-x: hidden;
overflow-y: auto; overflow-y: auto;
} }
@@ -22,40 +22,54 @@ body.onboarding-page #app {
display: none; display: none;
} }
body.thumbnail-preview *,
body.thumbnail-preview *::before,
body.thumbnail-preview *::after {
animation: none !important;
animation-delay: 0s !important;
animation-duration: 0s !important;
animation-iteration-count: 1 !important;
transition: none !important;
}
body.thumbnail-preview .player-announcement-layer,
body.thumbnail-preview .player-offline-banner {
display: none !important;
}
#app { #app {
width: 100%; width: 100%;
height: 100%; height: 100%;
display: flex; display: flex;
align-items: center; align-items: center;
justify-content: center; justify-content: center;
background: #111; background: #0a0a0a;
position: relative; position: relative;
} }
.onboarding-shell { .onboarding-shell {
min-height: 100vh; min-height: 100%;
display: flex; display: flex;
align-items: center; align-items: center;
justify-content: center; justify-content: center;
padding: clamp(16px, 3vw, 40px); padding: clamp(24px, 5vw, 72px);
box-sizing: border-box; box-sizing: border-box;
} }
.onboarding-stage {
width: min(100%, 1160px);
}
.onboarding-header {
display: flex;
align-items: center;
gap: 14px;
margin-bottom: 10px;
}
.onboarding-brand-mark {
width: 42px;
height: 42px;
display: grid;
place-items: center;
border-radius: 13px;
background: #f0bd70;
color: #10252a;
font-size: 1.45rem;
font-weight: 800;
}
.onboarding-label {
margin: 3px 0 0;
color: #8faeb0;
font-size: 0.88rem;
}
.onboarding-card { .onboarding-card {
width: min(100%, 1040px); width: min(100%, 1040px);
padding: clamp(20px, 3vw, 40px); padding: clamp(20px, 3vw, 40px);
@@ -73,14 +87,35 @@ body.thumbnail-preview .player-offline-banner {
line-height: 1.05; line-height: 1.05;
} }
.onboarding-stage h1 {
max-width: 560px;
font-size: clamp(2.5rem, 5vw, 5rem);
letter-spacing: 0;
}
.onboarding-stage--landing h1 {
max-width: 500px;
font-size: clamp(2.1rem, 3.6vw, 3.4rem);
line-height: 1.08;
}
.onboarding-kicker { .onboarding-kicker {
margin: 0 0 12px; margin: 0 0 12px;
text-transform: uppercase; text-transform: uppercase;
letter-spacing: 0.14em; letter-spacing: 0.14em;
color: #8ab4ff; color: #f0bd70;
font-size: 0.82rem; font-size: 0.82rem;
} }
.onboarding-step {
margin: 0 0 18px;
color: #70d0c2;
font-size: 0.9rem;
font-weight: 700;
letter-spacing: 0.08em;
text-transform: uppercase;
}
.onboarding-copy { .onboarding-copy {
margin: 0 0 28px; margin: 0 0 28px;
color: #cbd5e1; color: #cbd5e1;
@@ -90,36 +125,123 @@ body.thumbnail-preview .player-offline-banner {
.onboarding-layout { .onboarding-layout {
display: grid; display: grid;
grid-template-columns: minmax(280px, 1fr) minmax(320px, 1fr); grid-template-columns: minmax(320px, 0.9fr) minmax(320px, 1.1fr);
gap: clamp(20px, 3vw, 32px); gap: clamp(20px, 3vw, 32px);
align-items: stretch; align-items: stretch;
} }
.onboarding-copy-panel {
display: flex;
grid-column: 1;
grid-row: 1;
flex-direction: column;
justify-content: center;
}
.onboarding-instructions {
display: grid;
gap: 14px;
max-width: 440px;
margin: 18px 0 0;
padding: 0;
list-style: none;
counter-reset: setup-step;
}
.onboarding-instructions li {
display: grid;
grid-template-columns: 24px 1fr;
gap: 10px;
color: #b7cccd;
font-size: 0.96rem;
line-height: 1.35;
counter-increment: setup-step;
}
.onboarding-instructions li::before {
content: counter(setup-step);
width: 22px;
height: 22px;
display: grid;
place-items: center;
border: 1px solid rgba(112, 208, 194, 0.55);
border-radius: 50%;
color: #70d0c2;
font-size: 0.75rem;
font-weight: 700;
}
.onboarding-pin-block {
margin-top: 28px;
}
.onboarding-pin-label {
display: block;
margin-bottom: 10px;
color: #8faeb0;
font-size: 0.92rem;
}
.onboarding-pin-label strong { color: #f0bd70; }
.onboarding-pin {
display: block;
color: #f4f8f5;
font-size: clamp(1.7rem, 3vw, 2.8rem);
font-weight: 800;
letter-spacing: 0.18em;
line-height: 1;
}
.onboarding-qr-pane { .onboarding-qr-pane {
display: grid; display: grid;
gap: 16px; width: min(100%, 420px);
grid-column: 2;
grid-row: 1;
gap: 0;
align-content: start; align-content: start;
justify-self: center;
} }
.onboarding-qr-frame { .onboarding-qr-frame {
display: flex; display: flex;
width: min(100%, 420px);
aspect-ratio: 1;
box-sizing: border-box;
justify-content: center; justify-content: center;
padding: 22px; align-items: center;
border-radius: 26px; justify-self: center;
background: rgba(255, 255, 255, 0.04); padding: 14px;
border: 1px solid rgba(255, 255, 255, 0.08); border-radius: 22px;
background: rgba(7, 19, 27, 0.7);
border: 1px solid rgba(244, 248, 245, 0.42);
box-shadow: 0 24px 64px rgba(0, 0, 0, 0.22);
} }
.onboarding-qr-frame img { .onboarding-qr-frame img {
width: min(100%, 320px); width: min(100%, 390px);
aspect-ratio: 1; aspect-ratio: 1;
display: block; display: block;
background: #fff; background: transparent;
border-radius: 18px; border-radius: 16px;
padding: 16px; padding: 12px;
box-sizing: border-box; box-sizing: border-box;
} }
.onboarding-qr-caption {
margin: 6px 0 0;
color: #8faeb0;
font-size: 0.92rem;
text-align: center;
}
.onboarding-brand-title {
margin-bottom: 10px;
font-size: 1.2rem;
font-weight: 700;
letter-spacing: 0.1em;
}
.onboarding-form { .onboarding-form {
display: grid; display: grid;
gap: 14px; gap: 14px;
@@ -181,14 +303,14 @@ body.thumbnail-preview .player-offline-banner {
} }
.onboarding-status { .onboarding-status {
margin-top: 8px; margin-top: clamp(32px, 6vh, 56px);
min-height: 1.4em; min-height: 1.4em;
color: #cbd5e1; color: #8faeb0;
font-size: 0.96rem; font-size: 0.96rem;
} }
.onboarding-card--landing .onboarding-status { .onboarding-card--landing .onboarding-status {
text-align: center; text-align: left;
} }
@media (max-width: 860px), (orientation: portrait) { @media (max-width: 860px), (orientation: portrait) {
@@ -200,12 +322,45 @@ body.thumbnail-preview .player-offline-banner {
grid-template-columns: 1fr; grid-template-columns: 1fr;
} }
.onboarding-copy-panel,
.onboarding-qr-pane {
grid-column: 1;
}
.onboarding-copy-panel {
grid-row: 1;
}
.onboarding-qr-pane {
grid-row: 2;
}
.onboarding-card { .onboarding-card {
width: 100%; width: 100%;
} }
.onboarding-qr-frame img { .onboarding-qr-frame img {
width: min(100%, 280px); width: min(100%, 390px);
}
.onboarding-qr-frame {
width: min(100%, 420px);
}
.onboarding-qr-pane {
width: min(100%, 420px);
}
.onboarding-stage--landing h1 {
font-size: clamp(2rem, 7vw, 3rem);
}
.onboarding-header {
margin-bottom: 38px;
}
.onboarding-pin {
font-size: clamp(1.7rem, 9vw, 2.8rem);
} }
} }
@@ -239,6 +394,29 @@ body.screen-blackout #app {
opacity: 0; opacity: 0;
} }
.player-keyboard-feedback {
position: fixed;
top: 1.5rem;
left: 50%;
z-index: 10000;
padding: 0.65rem 1rem;
border: 1px solid rgba(255, 255, 255, 0.32);
border-radius: 0.4rem;
background: rgba(15, 23, 42, 0.88);
color: #fff;
font-size: 0.95rem;
font-weight: 700;
opacity: 0;
pointer-events: none;
transform: translate(-50%, -0.5rem);
transition: opacity 120ms ease, transform 120ms ease;
}
.player-keyboard-feedback.is-visible {
opacity: 1;
transform: translate(-50%, 0);
}
.player-announcement-layer { .player-announcement-layer {
position: fixed; position: fixed;
left: 50%; left: 50%;
@@ -294,15 +472,6 @@ body.screen-blackout #app {
display: block; display: block;
} }
.slide img,
.slide video,
.slide iframe {
width: 100%;
height: 100%;
object-fit: contain;
border: 0;
}
.body { .body {
position: absolute; position: absolute;
left: 5%; left: 5%;
@@ -22,7 +22,11 @@
function normalizeAnnouncementColor(value) { function normalizeAnnouncementColor(value) {
var normalized = String(value || '').trim().toLowerCase(); var normalized = String(value || '').trim().toLowerCase();
if (['primary', 'secondary', 'success', 'info', 'warning', 'danger', 'dark', 'light'].indexOf(normalized) !== -1) { if ([
'primary', 'secondary', 'success', 'info', 'warning', 'danger', 'dark', 'light',
'orange', 'amber', 'olive', 'teal', 'sky', 'indigo', 'violet', 'fuchsia', 'pink',
'navy', 'steel', 'slate', 'graphite', 'midnight'
].indexOf(normalized) !== -1) {
return normalized; return normalized;
} }
return 'primary'; return 'primary';
@@ -42,7 +46,21 @@
warning: { accent: '#ffc107', foreground: '#201400', glow: 'rgba(255, 193, 7, 0.30)' }, warning: { accent: '#ffc107', foreground: '#201400', glow: 'rgba(255, 193, 7, 0.30)' },
danger: { accent: '#dc3545', foreground: '#ffffff', glow: 'rgba(220, 53, 69, 0.34)' }, danger: { accent: '#dc3545', foreground: '#ffffff', glow: 'rgba(220, 53, 69, 0.34)' },
dark: { accent: '#212529', foreground: '#ffffff', glow: 'rgba(33, 37, 41, 0.34)' }, dark: { accent: '#212529', foreground: '#ffffff', glow: 'rgba(33, 37, 41, 0.34)' },
light: { accent: '#f8f9fa', foreground: '#1f2937', glow: 'rgba(248, 249, 250, 0.34)' } light: { accent: '#f8f9fa', foreground: '#1f2937', glow: 'rgba(248, 249, 250, 0.34)' },
orange: { accent: '#c84e10', foreground: '#ffffff', glow: 'rgba(200, 78, 16, 0.34)' },
amber: { accent: '#a56710', foreground: '#ffffff', glow: 'rgba(165, 103, 16, 0.34)' },
olive: { accent: '#5f7f0f', foreground: '#ffffff', glow: 'rgba(95, 127, 15, 0.34)' },
teal: { accent: '#12827d', foreground: '#ffffff', glow: 'rgba(18, 130, 125, 0.34)' },
sky: { accent: '#127caf', foreground: '#ffffff', glow: 'rgba(18, 124, 175, 0.34)' },
indigo: { accent: '#6f60ea', foreground: '#ffffff', glow: 'rgba(111, 96, 234, 0.34)' },
violet: { accent: '#9553db', foreground: '#ffffff', glow: 'rgba(149, 83, 219, 0.34)' },
fuchsia: { accent: '#b347be', foreground: '#ffffff', glow: 'rgba(179, 71, 190, 0.34)' },
pink: { accent: '#cd388d', foreground: '#ffffff', glow: 'rgba(205, 56, 141, 0.34)' },
navy: { accent: '#1d2d4c', foreground: '#ffffff', glow: 'rgba(29, 45, 76, 0.34)' },
steel: { accent: '#3a4860', foreground: '#ffffff', glow: 'rgba(58, 72, 96, 0.34)' },
slate: { accent: '#566577', foreground: '#ffffff', glow: 'rgba(86, 101, 119, 0.34)' },
graphite: { accent: '#32363c', foreground: '#ffffff', glow: 'rgba(50, 54, 60, 0.34)' },
midnight: { accent: '#1e1d2d', foreground: '#ffffff', glow: 'rgba(30, 29, 45, 0.34)' }
}; };
return tokens[colorKey] || tokens.primary; return tokens[colorKey] || tokens.primary;
+152 -16
View File
@@ -7,6 +7,7 @@ function getCurrentViewport() {
} }
var slideOutroTimers = []; var slideOutroTimers = [];
var commandHeartbeatTimer = null;
// Command websocket and player-state helpers. // Command websocket and player-state helpers.
// Send the current playback state to the command websocket. // Send the current playback state to the command websocket.
@@ -166,19 +167,11 @@ function getPlayerRegionModules() {
return window.pulsePlayerRegionTypes.list(); return window.pulsePlayerRegionTypes.list();
} }
function isThumbnailPreview() {
return Boolean(window.__pulseThumbnailPreview);
}
function runRegionLifecycle(root, lifecycleName) { function runRegionLifecycle(root, lifecycleName) {
if (!root) { if (!root) {
return; return;
} }
if (isThumbnailPreview() && lifecycleName === 'initRegion') {
return;
}
getPlayerRegionModules().forEach(function (entry) { getPlayerRegionModules().forEach(function (entry) {
var module = entry && entry.definition ? entry.definition : null; var module = entry && entry.definition ? entry.definition : null;
if (!module || typeof module[lifecycleName] !== 'function') { if (!module || typeof module[lifecycleName] !== 'function') {
@@ -276,9 +269,7 @@ function renderSlideMarkup(markup, shouldFade) {
syncRtmpRegions(root); syncRtmpRegions(root);
} }
if (!isThumbnailPreview()) { initializeRegionInstances(root);
initializeRegionInstances(root);
}
initializeRenderedVideoPlayback(root, delayMs); initializeRenderedVideoPlayback(root, delayMs);
@@ -330,13 +321,16 @@ function renderSlideMarkup(markup, shouldFade) {
} }
var nextShell = document.createElement('div'); var nextShell = document.createElement('div');
nextShell.className = 'slide-shell'; nextShell.className = 'slide-shell slide-shell-entering';
nextShell.style.zIndex = '0';
nextShell.style.opacity = '0'; nextShell.style.opacity = '0';
nextShell.innerHTML = markup; nextShell.innerHTML = markup;
if (!previousShell || (previousShell.classList && previousShell.classList.contains('empty'))) { if (!previousShell || (previousShell.classList && previousShell.classList.contains('empty'))) {
app.innerHTML = ''; app.innerHTML = '';
nextShell.style.opacity = '1'; nextShell.style.opacity = '1';
nextShell.classList.remove('slide-shell-entering');
nextShell.classList.add('is-visible');
app.appendChild(nextShell); app.appendChild(nextShell);
schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2); schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2);
return nextShell; return nextShell;
@@ -345,6 +339,9 @@ function renderSlideMarkup(markup, shouldFade) {
if (!previousShell.classList.contains('slide-shell')) { if (!previousShell.classList.contains('slide-shell')) {
previousShell.classList.add('slide-shell'); previousShell.classList.add('slide-shell');
} }
previousShell.classList.remove('is-visible');
previousShell.classList.add('is-exiting');
previousShell.style.zIndex = '1';
previousShell.style.opacity = '1'; previousShell.style.opacity = '1';
pauseRenderedVideoPlayback(previousShell, slideFadeDurationMs / 2); pauseRenderedVideoPlayback(previousShell, slideFadeDurationMs / 2);
@@ -352,6 +349,8 @@ function renderSlideMarkup(markup, shouldFade) {
window.requestAnimationFrame(function () { window.requestAnimationFrame(function () {
nextShell.style.opacity = '1'; nextShell.style.opacity = '1';
previousShell.style.opacity = '0'; previousShell.style.opacity = '0';
nextShell.classList.remove('slide-shell-entering');
nextShell.classList.add('is-visible');
schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2); schedulePostRenderSetup(nextShell, slideFadeDurationMs / 2);
}); });
@@ -360,7 +359,10 @@ function renderSlideMarkup(markup, shouldFade) {
previousShell.parentNode.removeChild(previousShell); previousShell.parentNode.removeChild(previousShell);
} }
if (nextShell) { if (nextShell) {
nextShell.style.zIndex = '1';
nextShell.style.opacity = '1'; nextShell.style.opacity = '1';
nextShell.classList.remove('slide-shell-entering');
nextShell.classList.add('is-visible');
} }
slideTransitionTimer = null; slideTransitionTimer = null;
}, slideFadeDurationMs); }, slideFadeDurationMs);
@@ -427,6 +429,86 @@ function normalizeBoolean(value) {
return null; return null;
} }
function isEditableTarget(target) {
if (!target) {
return false;
}
if (target.isContentEditable) {
return true;
}
var tagName = String(target.tagName || '').toUpperCase();
return ['INPUT', 'TEXTAREA', 'SELECT', 'OPTION'].indexOf(tagName) !== -1;
}
var keyboardFeedbackTimer = null;
function showKeyboardFeedback(message) {
if (typeof document === 'undefined' || !document.body) {
return;
}
var feedback = document.querySelector('.player-keyboard-feedback');
if (!feedback) {
feedback = document.createElement('div');
feedback.className = 'player-keyboard-feedback';
feedback.setAttribute('aria-live', 'polite');
document.body.appendChild(feedback);
}
feedback.textContent = String(message || '');
feedback.classList.remove('is-visible');
void feedback.offsetWidth;
feedback.classList.add('is-visible');
if (keyboardFeedbackTimer) {
window.clearTimeout(keyboardFeedbackTimer);
}
keyboardFeedbackTimer = window.setTimeout(function () {
feedback.classList.remove('is-visible');
keyboardFeedbackTimer = null;
}, 900);
}
function handlePlayerKeydown(event) {
if (!event || event.defaultPrevented || event.altKey || event.ctrlKey || event.metaKey) {
return;
}
if (isEditableTarget(event.target)) {
return;
}
if (event.key === 'ArrowLeft') {
event.preventDefault();
navigateSlides(-1);
showKeyboardFeedback('Previous slide');
return;
}
if (event.key === 'ArrowRight') {
event.preventDefault();
navigateSlides(1);
showKeyboardFeedback('Next slide');
return;
}
if (String(event.key || '').toLowerCase() === 'p') {
event.preventDefault();
setPaused(!isPaused);
showKeyboardFeedback(isPaused ? 'Paused' : 'Playing');
return;
}
if (String(event.key || '').toLowerCase() === 'b') {
event.preventDefault();
setBlackout(!isBlackout);
showKeyboardFeedback(isBlackout ? 'Blackout on' : 'Blackout off');
}
}
window.addEventListener('keydown', handlePlayerKeydown);
// Move to the previous or next active slide. // Move to the previous or next active slide.
function navigateSlides(offset) { function navigateSlides(offset) {
const manualSlides = getCurrentActiveSlides(); const manualSlides = getCurrentActiveSlides();
@@ -453,14 +535,32 @@ function handleCommandMessage(rawMessage) {
} catch (_error) { } catch (_error) {
return; return;
} }
if (payload && payload.type === 'client-id-conflict') {
handleClientIdConflict();
return;
}
if (payload && payload.type === 'client-name-updated') {
if (payload.clientName) {
applyOnboardingClientName(payload.clientName, commandSocket);
}
return;
}
if (!payload || payload.type !== 'command') { if (!payload || payload.type !== 'command') {
return; return;
} }
if (payload.requestId && commandSocket && commandSocket.readyState === WebSocket.OPEN) {
commandSocket.send(JSON.stringify({
type: 'command-ack',
requestId: payload.requestId,
ok: true
}));
}
switch (payload.command) { switch (payload.command) {
case 'refresh': case 'refresh':
refresh(); refresh(true);
return; return;
case 'setclientname': case 'setclientname':
if (payload.clientName) { if (payload.clientName) {
@@ -469,7 +569,17 @@ function handleCommandMessage(rawMessage) {
return; return;
case 'redirect': case 'redirect':
if (payload.url) { if (payload.url) {
window.location.replace(String(payload.url)); var redirectUrl = String(payload.url);
var authorizeMove = payload.moveToken
? fetch('/api/screen-move-authorize', {
method: 'POST',
headers: { 'Content-Type': 'application/json', 'Accept': 'application/json' },
body: JSON.stringify({ moveToken: String(payload.moveToken) })
})
: Promise.resolve();
authorizeMove.finally(function () {
window.location.replace(redirectUrl);
});
} }
return; return;
case 'pause': case 'pause':
@@ -505,6 +615,12 @@ function handleCommandMessage(rawMessage) {
} }
} }
function handleClientIdConflict() {
var replacementClientId = regenerateCommandClientId();
var onboardingUrl = new URL('/', window.location.origin);
window.location.replace(onboardingUrl.toString());
}
// Retry the command websocket after a disconnect. // Retry the command websocket after a disconnect.
function scheduleCommandReconnect() { function scheduleCommandReconnect() {
if (commandReconnectTimer) { if (commandReconnectTimer) {
@@ -528,6 +644,12 @@ function connectCommandSocket() {
commandSocket = socket; commandSocket = socket;
socket.onopen = function () { socket.onopen = function () {
if (commandHeartbeatTimer) {
window.clearInterval(commandHeartbeatTimer);
}
commandHeartbeatTimer = window.setInterval(function () {
sendCommandState(lastRenderedSlide);
}, 60 * 1000);
if (typeof syncOnboardingClientNameFromServer === 'function') { if (typeof syncOnboardingClientNameFromServer === 'function') {
syncOnboardingClientNameFromServer(socket).then(function () { syncOnboardingClientNameFromServer(socket).then(function () {
sendCommandState(socket); sendCommandState(socket);
@@ -541,12 +663,26 @@ function connectCommandSocket() {
handleCommandMessage(event.data); handleCommandMessage(event.data);
}; };
socket.onclose = function () { socket.onclose = function (event) {
if (typeof logDebug === 'function') {
logDebug('Command websocket closed.', 'code=' + String(event && event.code || '') + ' reason=' + String(event && event.reason || ''), 'warn');
}
if (commandHeartbeatTimer) {
window.clearInterval(commandHeartbeatTimer);
commandHeartbeatTimer = null;
}
commandSocket = null; commandSocket = null;
if (event && event.code === 4009) {
handleClientIdConflict();
return;
}
scheduleCommandReconnect(); scheduleCommandReconnect();
}; };
socket.onerror = function () { socket.onerror = function (error) {
if (typeof logDebug === 'function') {
logDebug('Command websocket error.', error && error.message ? String(error.message) : 'Websocket transport error.', 'error');
}
try { try {
socket.close(); socket.close();
} catch (_error) { } catch (_error) {
@@ -1,8 +1,5 @@
// Show or hide the offline status banner. // Show or hide the offline status banner.
function setOfflineBannerVisible(visible, message) { function setOfflineBannerVisible(visible, message) {
if (window.__pulseThumbnailPreview) {
return;
}
var normalizedVisible = Boolean(visible); var normalizedVisible = Boolean(visible);
var bannerMessage = String(message || 'Offline mode: using cached playlist.').trim(); var bannerMessage = String(message || 'Offline mode: using cached playlist.').trim();
if (normalizedVisible) { if (normalizedVisible) {
@@ -41,9 +38,6 @@ function setOfflineBannerVisible(visible, message) {
// Update the offline banner based on connectivity or playlist availability. // Update the offline banner based on connectivity or playlist availability.
function syncOfflineBanner() { function syncOfflineBanner() {
if (window.__pulseThumbnailPreview) {
return;
}
if (!window.navigator.onLine) { if (!window.navigator.onLine) {
setOfflineBannerVisible(true, 'Offline mode: using cached playlist.'); setOfflineBannerVisible(true, 'Offline mode: using cached playlist.');
return; return;
@@ -63,9 +57,6 @@ function clearRefreshRetry() {
// Retry playlist refresh with a short backoff while the player is offline. // Retry playlist refresh with a short backoff while the player is offline.
function scheduleRefreshRetry() { function scheduleRefreshRetry() {
if (window.__pulseThumbnailPreview) {
return;
}
if (refreshRetryTimer) { if (refreshRetryTimer) {
return; return;
} }
+45 -6
View File
@@ -1,5 +1,5 @@
// Render the slide at the requested index within the active set. // Render the slide at the requested index within the active set.
async function renderSlideAtIndex(sourceSlides, targetIndex) { async function renderSlideAtIndex(sourceSlides, targetIndex, options) {
const availableSlides = Array.isArray(sourceSlides) ? sourceSlides : []; const availableSlides = Array.isArray(sourceSlides) ? sourceSlides : [];
if (!availableSlides.length) { if (!availableSlides.length) {
renderEmpty(slides.length ? 'No slides are scheduled for this time.' : 'No slides assigned to this screen yet.'); renderEmpty(slides.length ? 'No slides are scheduled for this time.' : 'No slides assigned to this screen yet.');
@@ -53,7 +53,7 @@ async function renderSlideAtIndex(sourceSlides, targetIndex) {
index = currentIndex; index = currentIndex;
var markup = buildSlideMarkup(slide); var markup = buildSlideMarkup(slide);
renderSlideMarkup(markup, currentPlaylistFadeBetweenSlides); renderSlideMarkup(markup, !(options && options.skipFade) && currentPlaylistFadeBetweenSlides);
if (typeof scheduleSlideMarkupPreload === 'function') { if (typeof scheduleSlideMarkupPreload === 'function') {
scheduleSlideMarkupPreload(availableSlides, currentIndex); scheduleSlideMarkupPreload(availableSlides, currentIndex);
} }
@@ -70,6 +70,7 @@ function applyPendingPlaylistUpdate() {
if (!pendingPlaylistUpdate) { if (!pendingPlaylistUpdate) {
return false; return false;
} }
var nextIndex = Number(index || 0);
slides = pendingPlaylistUpdate.slides; slides = pendingPlaylistUpdate.slides;
currentPlaylistSignature = pendingPlaylistUpdate.signature; currentPlaylistSignature = pendingPlaylistUpdate.signature;
currentPlaylistFadeBetweenSlides = pendingPlaylistUpdate.fadeBetweenSlides; currentPlaylistFadeBetweenSlides = pendingPlaylistUpdate.fadeBetweenSlides;
@@ -80,13 +81,17 @@ function applyPendingPlaylistUpdate() {
templateLayoutCache = Object.create(null); templateLayoutCache = Object.create(null);
templateRenderPlanCache = Object.create(null); templateRenderPlanCache = Object.create(null);
renderCacheViewportKey = window.innerWidth + 'x' + window.innerHeight; renderCacheViewportKey = window.innerWidth + 'x' + window.innerHeight;
index = 0; const activeSlides = getCurrentActiveSlides();
if (!Number.isFinite(nextIndex) || nextIndex < 0) {
nextIndex = 0;
}
index = activeSlides.length ? Math.min(nextIndex, activeSlides.length - 1) : 0;
logDebug('Applied updated playlist on slide transition.'); logDebug('Applied updated playlist on slide transition.');
return true; return true;
} }
// Render the current active slide or the empty state. // Render the current active slide or the empty state.
function showCurrent() { function showCurrent(options) {
clearSlideTimer(); clearSlideTimer();
const activeSlides = getCurrentActiveSlides(); const activeSlides = getCurrentActiveSlides();
syncWebpagePreloads(activeSlides, index); syncWebpagePreloads(activeSlides, index);
@@ -101,7 +106,7 @@ function showCurrent() {
lastRenderedViewKey = getCurrentRenderKey(activeSlides); lastRenderedViewKey = getCurrentRenderKey(activeSlides);
return; return;
} }
void renderSlideAtIndex(activeSlides, index); void renderSlideAtIndex(activeSlides, index, options);
lastRenderedViewKey = getCurrentRenderKey(activeSlides); lastRenderedViewKey = getCurrentRenderKey(activeSlides);
} }
@@ -143,7 +148,7 @@ function handleRtmpPlaybackFailure(message, options) {
} }
// Fetch the latest playlist and queue any updates. // Fetch the latest playlist and queue any updates.
function refresh() { function refresh(applyImmediately) {
var request = new XMLHttpRequest(); var request = new XMLHttpRequest();
var url = window.location.origin + '/api/screens/' + encodeURIComponent(slug) + '/playlist?ts=' + Date.now(); var url = window.location.origin + '/api/screens/' + encodeURIComponent(slug) + '/playlist?ts=' + Date.now();
request.open('GET', url, true); request.open('GET', url, true);
@@ -151,6 +156,9 @@ function refresh() {
if (window.__pulsePageAuthToken) { if (window.__pulsePageAuthToken) {
request.setRequestHeader('x-pulse-page-auth', window.__pulsePageAuthToken); request.setRequestHeader('x-pulse-page-auth', window.__pulsePageAuthToken);
} }
if (typeof getCommandClientId === 'function') {
request.setRequestHeader('x-pulse-client-id', getCommandClientId());
}
if (currentPlaylistEtag) { if (currentPlaylistEtag) {
request.setRequestHeader('If-None-Match', currentPlaylistEtag); request.setRequestHeader('If-None-Match', currentPlaylistEtag);
} }
@@ -159,6 +167,7 @@ function refresh() {
return; return;
} }
if (request.status === 304) { if (request.status === 304) {
logDebug('Playlist refresh completed with no changes.');
markRefreshHealthy(); markRefreshHealthy();
setOfflineBannerVisible(false); setOfflineBannerVisible(false);
if (lastRenderedSlide && getCurrentActiveSlides().length < 2) { if (lastRenderedSlide && getCurrentActiveSlides().length < 2) {
@@ -167,6 +176,10 @@ function refresh() {
return; return;
} }
if (request.status < 200 || request.status >= 300) { if (request.status < 200 || request.status >= 300) {
if (request.status === 401 || request.status === 403) {
window.location.replace('/');
return;
}
setOfflineBannerVisible(true); setOfflineBannerVisible(true);
scheduleRefreshRetry(); scheduleRefreshRetry();
logDebug( logDebug(
@@ -180,10 +193,26 @@ function refresh() {
const responseEtag = String(request.getResponseHeader('ETag') || '').trim(); const responseEtag = String(request.getResponseHeader('ETag') || '').trim();
const data = JSON.parse(request.responseText || '{}'); const data = JSON.parse(request.responseText || '{}');
const nextSignature = getPlaylistRevision(data); const nextSignature = getPlaylistRevision(data);
logDebug('Playlist refresh completed.', 'Revision: ' + nextSignature);
const nextSlides = Array.isArray(data.slides) ? data.slides.map(normalizeSlide) : []; const nextSlides = Array.isArray(data.slides) ? data.slides.map(normalizeSlide) : [];
const nextActiveSlides = getActiveSlidesFrom(nextSlides); const nextActiveSlides = getActiveSlidesFrom(nextSlides);
const nextFadeBetweenSlides = Boolean(data && data.playlist && data.playlist.fade_between_slides); const nextFadeBetweenSlides = Boolean(data && data.playlist && data.playlist.fade_between_slides);
const nextSkipUnavailableRtmp = Boolean(data && data.playlist && data.playlist.skip_unavailable_rtmp); const nextSkipUnavailableRtmp = Boolean(data && data.playlist && data.playlist.skip_unavailable_rtmp);
var refreshedInitialData = Object.assign({},
typeof initialData !== 'undefined' && initialData ? initialData : (window.initialData || {}), {
screen: data.screen || null,
playlist: data.playlist || null,
slides: nextSlides,
rssFeeds: Array.isArray(data.rssFeeds) ? data.rssFeeds : [],
apiSources: Array.isArray(data.apiSources) ? data.apiSources : [],
timetableGroups: Array.isArray(data.timetableGroups) ? data.timetableGroups : [],
weatherLocations: Array.isArray(data.weatherLocations) ? data.weatherLocations : [],
revision: nextSignature
});
if (typeof initialData !== 'undefined') {
initialData = refreshedInitialData;
}
window.initialData = refreshedInitialData;
savePlaylistSnapshot({ savePlaylistSnapshot({
slides: nextSlides, slides: nextSlides,
signature: nextSignature, signature: nextSignature,
@@ -227,6 +256,11 @@ function refresh() {
fadeBetweenSlides: nextFadeBetweenSlides, fadeBetweenSlides: nextFadeBetweenSlides,
skipUnavailableRtmp: nextSkipUnavailableRtmp skipUnavailableRtmp: nextSkipUnavailableRtmp
}; };
if (applyImmediately) {
applyPendingPlaylistUpdate();
showCurrent();
return;
}
if (!isSlideInList(lastRenderedSlide, nextSlides)) { if (!isSlideInList(lastRenderedSlide, nextSlides)) {
applyPendingPlaylistUpdate(); applyPendingPlaylistUpdate();
showCurrent(); showCurrent();
@@ -241,6 +275,11 @@ function refresh() {
fadeBetweenSlides: nextFadeBetweenSlides, fadeBetweenSlides: nextFadeBetweenSlides,
skipUnavailableRtmp: nextSkipUnavailableRtmp skipUnavailableRtmp: nextSkipUnavailableRtmp
}; };
if (applyImmediately) {
applyPendingPlaylistUpdate();
showCurrent();
return;
}
logDebug('Playlist update detected; applying on next slide transition.'); logDebug('Playlist update detected; applying on next slide transition.');
} catch (_error) { } catch (_error) {
logDebug( logDebug(
+11 -4
View File
@@ -129,10 +129,6 @@ function getSlideMarkupPreloadSlides(sourceSlides, targetIndex) {
} }
function scheduleSlideMarkupPreload(sourceSlides, targetIndex) { function scheduleSlideMarkupPreload(sourceSlides, targetIndex) {
if (window.__pulseThumbnailPreview) {
return;
}
const preloadSlides = getSlideMarkupPreloadSlides(sourceSlides, targetIndex); const preloadSlides = getSlideMarkupPreloadSlides(sourceSlides, targetIndex);
if (!preloadSlides.length || typeof primeSlideMarkup !== 'function') { if (!preloadSlides.length || typeof primeSlideMarkup !== 'function') {
return; return;
@@ -211,6 +207,16 @@ function getCommandClientId() {
return commandClientId; return commandClientId;
} }
function regenerateCommandClientId() {
commandClientId = null;
try {
window.sessionStorage.removeItem(commandClientStorageKey);
} catch (_error) {
// ignore storage errors
}
return getCommandClientId();
}
// Load the most recent playlist snapshot from browser storage. // Load the most recent playlist snapshot from browser storage.
function loadPlaylistSnapshot() { function loadPlaylistSnapshot() {
try { try {
@@ -226,6 +232,7 @@ function loadPlaylistSnapshot() {
slides: parsed.slides.map(normalizeSlide), slides: parsed.slides.map(normalizeSlide),
signature: String(parsed.signature || ''), signature: String(parsed.signature || ''),
fadeBetweenSlides: Boolean(parsed.fadeBetweenSlides), fadeBetweenSlides: Boolean(parsed.fadeBetweenSlides),
skipUnavailableRtmp: Boolean(parsed.skipUnavailableRtmp),
etag: String(parsed.etag || '') etag: String(parsed.etag || '')
}; };
} catch (_error) { } catch (_error) {
+48 -11
View File
@@ -4,6 +4,14 @@ function sanitizeFontFamily(value) {
return String(value || '').replace(/[^a-zA-Z0-9 ,\"-]/g, '').trim(); return String(value || '').replace(/[^a-zA-Z0-9 ,\"-]/g, '').trim();
} }
function normalizeStyleAttributeValue(value) {
return String(value || '')
.replace(/&quot;/g, '"')
.replace(/&#39;/g, "'")
.replace(/&amp;quot;/g, '"')
.replace(/&amp;#39;/g, "'");
}
// Clamp font size to the supported range. // Clamp font size to the supported range.
function sanitizeFontSize(value) { function sanitizeFontSize(value) {
return Math.max(8, Number(value || 0) || 24); return Math.max(8, Number(value || 0) || 24);
@@ -219,7 +227,7 @@ function getRegionAnimationPhaseTimingMs(root, phase) {
} }
function getRegionAnimationPhaseTimings(root, phase) { function getRegionAnimationPhaseTimings(root, phase) {
if (!root || isThumbnailPreview()) { if (!root) {
return []; return [];
} }
@@ -258,7 +266,7 @@ function getRegionAnimationPhaseTimings(root, phase) {
} }
function playRegionAnimation(element, phase) { function playRegionAnimation(element, phase) {
if (!element || isThumbnailPreview()) { if (!element) {
return; return;
} }
@@ -308,7 +316,7 @@ function playRegionAnimation(element, phase) {
} }
function playRegionAnimations(root, phase) { function playRegionAnimations(root, phase) {
if (!root || isThumbnailPreview()) { if (!root) {
return; return;
} }
@@ -334,7 +342,7 @@ function setPlayerCanvasDimensions(canvasWidth, canvasHeight) {
document.documentElement.style.setProperty('--player-canvas-height', height + 'px'); document.documentElement.style.setProperty('--player-canvas-height', height + 'px');
} }
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul']; const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) { function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = { const allowedAttributes = {
@@ -349,14 +357,20 @@ function sanitizeRichTextAttributes(tagName, attrText) {
h4: ['class', 'style'], h4: ['class', 'style'],
h5: ['class', 'style'], h5: ['class', 'style'],
h6: ['class', 'style'], h6: ['class', 'style'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
i: ['class', 'style', 'aria-hidden'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
li: ['class', 'style'], li: ['class', 'style'],
ol: ['class', 'style', 'start'], ol: ['class', 'style', 'start'],
p: ['class', 'style'], p: ['class', 'style'],
pre: ['class', 'style'], pre: ['class', 'style'],
span: ['class', 'style'], span: ['class', 'style'],
table: ['class', 'style'], table: ['class', 'style'],
tbody: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'], td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'], th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
thead: ['class', 'style'],
tr: ['class', 'style'], tr: ['class', 'style'],
ul: ['class', 'style'] ul: ['class', 'style']
}; };
@@ -365,6 +379,14 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return ''; return '';
} }
if (tagName === 'img') {
const srcMatch = String(attrText || '').match(/\bsrc\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+))/i);
const srcValue = srcMatch ? String(srcMatch[2] !== undefined ? srcMatch[2] : srcMatch[3] !== undefined ? srcMatch[3] : srcMatch[4] !== undefined ? srcMatch[4] : '').trim() : '';
if (!srcValue || !/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/]|data:image\/)/i.test(srcValue)) {
return '';
}
}
const attrs = []; const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => { String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase(); const lowerKey = String(key || '').toLowerCase();
@@ -388,7 +410,7 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return ''; return '';
} }
} }
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"'); attrs.push(' ' + lowerKey + '="' + escapeHtml(lowerKey === 'style' ? normalizeStyleAttributeValue(value) : value) + '"');
return ''; return '';
}); });
@@ -760,6 +782,7 @@ function getTemplateLayout(template) {
canvasHeight: canvasSize.height, canvasHeight: canvasSize.height,
background: template.background_image_path ? '<img class="template-background" src="' + escapeHtml(template.background_image_path) + '" alt="" />' : '', background: template.background_image_path ? '<img class="template-background" src="' + escapeHtml(template.background_image_path) + '" alt="" />' : '',
backgroundColor: template.background_color || '#111111', backgroundColor: template.background_color || '#111111',
backgroundGradient: template.background_gradient || '',
regions: regions regions: regions
}; };
@@ -768,17 +791,31 @@ function getTemplateLayout(template) {
} }
// Build a dark backdrop style for template and media canvases. // Build a dark backdrop style for template and media canvases.
function buildBackdropStyle(backgroundColor, backgroundImagePath) { function buildBackdropStyle(backgroundColor, backgroundImagePath, backgroundGradient) {
var color = String(backgroundColor || '#111111').trim() || '#111111'; var color = String(backgroundColor || '#111111').trim() || '#111111';
var style = 'background-color:' + escapeHtml(color) + ';'; var style = 'background-color:' + escapeHtml(color) + ';';
var gradient = '';
try {
var gradientData = typeof backgroundGradient === 'string' ? JSON.parse(backgroundGradient) : backgroundGradient;
if (gradientData && gradientData.type === 'linear' && ((Array.isArray(gradientData.stops) && gradientData.stops.length >= 2) || (Array.isArray(gradientData.colors) && gradientData.colors.length >= 2))) {
var stops = Array.isArray(gradientData.stops) ? gradientData.stops : (gradientData.colors || []).map(function (color, index, colors) { return { color: color, position: colors.length > 1 ? Math.round(index * 100 / (colors.length - 1)) : 0 }; });
stops = stops.filter(function (stop) { return stop && /^#[0-9a-fA-F]{3,8}$/.test(String(stop.color || '').trim()); }).slice(0, 12);
if (stops.length >= 2) {
var angle = Number(gradientData.angle);
gradient = 'linear-gradient(' + (Number.isFinite(angle) ? Math.max(0, Math.min(360, angle)) : 90) + 'deg,' + stops.map(function (stop) { return stop.color + ' ' + Math.max(0, Math.min(100, Number(stop.position) || 0)) + '%'; }).join(',') + ')';
}
}
} catch (_error) {
gradient = '';
}
if (backgroundImagePath) { if (backgroundImagePath) {
style += 'background-image:url("' + escapeHtml(backgroundImagePath) + '");'; style += 'background-image:url("' + escapeHtml(backgroundImagePath) + '")' + (gradient ? ',' + gradient : '') + ';';
style += 'background-position:center;background-size:contain;background-repeat:no-repeat;'; style += 'background-position:center,center;background-size:contain,cover;background-repeat:no-repeat,no-repeat;';
return style; return style;
} }
style += 'background-image:none;background-position:center;background-size:cover;background-repeat:no-repeat;'; style += 'background-image:' + (gradient || 'none') + ';background-position:center;background-size:cover;background-repeat:no-repeat;';
return style; return style;
} }
@@ -854,7 +891,7 @@ function renderTemplateSlideMarkup(slide) {
animationConfig: normalizePlayerAnimationConfig(region.animationJson) animationConfig: normalizePlayerAnimationConfig(region.animationJson)
}); });
}).join('') : ''; }).join('') : '';
const stageStyle = layout ? buildBackdropStyle(layout.backgroundColor || '#111111', template.background_image_path) : ''; const stageStyle = layout ? buildBackdropStyle(layout.backgroundColor || '#111111', template.background_image_path, layout.backgroundGradient) : '';
if (layout) { if (layout) {
setPlayerCanvasDimensions(layout.canvasWidth, layout.canvasHeight); setPlayerCanvasDimensions(layout.canvasWidth, layout.canvasHeight);
} }
@@ -938,7 +975,7 @@ function notifyVideoRegionSourceReady() {
} }
slideMarkupCache = Object.create(null); slideMarkupCache = Object.create(null);
if (typeof showCurrent === 'function' && slides && slides.length) { if (typeof showCurrent === 'function' && slides && slides.length) {
showCurrent(); showCurrent({ skipFade: true });
} }
} }
@@ -0,0 +1,34 @@
// Registry used by the player runtime to discover independently loaded region modules.
(function () {
var root = window;
var registry = root.pulsePlayerRegionTypes && typeof root.pulsePlayerRegionTypes === 'object' ? root.pulsePlayerRegionTypes : {};
function normalizeType(type) {
return String(type || '').trim().toLowerCase();
}
function register(type, definition) {
registry[normalizeType(type)] = definition || {};
return registry[normalizeType(type)];
}
function get(type) {
return registry[normalizeType(type)] || null;
}
function list() {
return Object.keys(registry).map(function (type) {
return {
type: type,
definition: registry[type] || {}
};
});
}
root.pulsePlayerRegionTypes = {
register: register,
get: get,
list: list
};
}());
+22 -6
View File
@@ -56,7 +56,7 @@ function getApiItem(sourceId, itemNumber, itemsPathOverride) {
return items[index] || null; return items[index] || null;
} }
function substituteApiVariables(html, item) { function substituteApiVariables(html, item, sourceId) {
var source = String(html || ''); var source = String(html || '');
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) { return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
if (!item || typeof item !== 'object') { if (!item || typeof item !== 'object') {
@@ -67,7 +67,25 @@ function substituteApiVariables(html, item) {
return ''; return '';
} }
return escapeHtml(placeholderUtils.formatPlaceholderValue(placeholderUtils.resolvePlaceholderExpression(item, expression))); var resolved = placeholderUtils.resolvePlaceholderExpression(item, expression);
if (typeof placeholderUtils.isImagePlaceholderExpression === 'function' && placeholderUtils.isImagePlaceholderExpression(expression)) {
var imageSource = placeholderUtils.formatPlaceholderValue(resolved);
var source = getApiSourceById(sourceId);
imageSource = source && source.imageCache && source.imageCache[imageSource] ? source.imageCache[imageSource] : imageSource;
if (!/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/])/i.test(imageSource)) {
return '';
}
var imageConfig = typeof placeholderUtils.getImagePlaceholderConfig === 'function' ? placeholderUtils.getImagePlaceholderConfig(expression) : {};
var hasImageBounds = imageConfig.width && imageConfig.height;
var imageStyle = hasImageBounds
? 'display:block;width:100%;height:100%;object-fit:contain;'
: 'display:block;width:auto;height:auto;' + (imageConfig.width ? 'max-width:' + imageConfig.width + 'px;' : '') + (imageConfig.height ? 'max-height:' + imageConfig.height + 'px;' : '');
var image = '<img src="' + escapeHtml(imageSource) + '" alt="" style="' + imageStyle + '" />';
return hasImageBounds
? '<span style="display:inline-flex;align-items:center;justify-content:center;box-sizing:border-box;width:' + imageConfig.width + 'px;height:' + imageConfig.height + 'px;">' + image + '</span>'
: image;
}
return escapeHtml(placeholderUtils.formatPlaceholderValue(resolved));
}); });
} }
@@ -120,10 +138,8 @@ function renderApiRegion(region, regionContent) {
var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize); var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize);
var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor); var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor);
var item = getApiItem(sourceId, itemNumber, itemsPath); var item = getApiItem(sourceId, itemNumber, itemsPath);
var body = item ? substituteApiVariables(content, item) : ''; var hasSource = String(sourceId === undefined || sourceId === null ? '' : sourceId).trim() !== '';
if (!body && item) { var body = hasSource ? (item ? substituteApiVariables(content, item, sourceId) : '') : content;
body = getApiPreviewFallback(item);
}
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';'; var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
if (!body) { if (!body) {
return ''; return '';
+39 -3
View File
@@ -2,16 +2,52 @@
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function buildHtmlDocument(html) {
var raw = String(html || '').trim();
if (!raw) {
return '';
}
if (/^<!doctype\b/i.test(raw) || /^<html\b/i.test(raw)) {
return raw;
}
return '<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}html,body{background:transparent !important;}</style></head><body>' + raw + '</body></html>';
}
function renderHtmlRegionContent(value) { function renderHtmlRegionContent(value) {
var html = String(value || '').trim(); var html = normalizeRenderableValue(value).trim();
if (!html) { if (!html) {
return ''; return '';
} }
return '<iframe class="template-region-html-frame" sandbox="" scrolling="no" srcdoc="<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + escapeHtml(html) + '</body></html>" title="HTML region" loading="eager"></iframe>'; if (/^<!doctype\b/i.test(html) || /^<html\b/i.test(html)) {
return '<iframe class="template-region-html-frame" sandbox="" allowtransparency="true" scrolling="no" srcdoc="' + escapeHtml(html) + '" title="HTML region" loading="eager" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe>';
}
return '<div class="template-region-html-content" style="width:100%;height:100%;overflow:hidden;background:transparent;">' + html + '</div>';
} }
function renderHtmlRegion(region, regionContent) { function renderHtmlRegion(region, regionContent) {
return '<div class="template-region html" style="' + region.baseStyle + '">' + renderHtmlRegionContent(regionContent.value || '') + '</div>'; return '<div class="template-region html" style="' + region.baseStyle + '">' + renderHtmlRegionContent(regionContent && regionContent.value !== undefined ? regionContent.value : '') + '</div>';
} }
registry.register('html', { registry.register('html', {
+27 -15
View File
@@ -1,6 +1,7 @@
// RSS region helpers for resolving feeds, items, and nested values. // RSS region helpers for resolving feeds, items, and nested values.
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
var placeholderUtils = window.placeholderUtils || {};
function getDefaultStyle() { function getDefaultStyle() {
return { return {
@@ -63,14 +64,34 @@ function resolveRssPath(value, path) {
return current === undefined || current === null ? '' : current; return current === undefined || current === null ? '' : current;
} }
function substituteRssVariables(html, item) { function substituteRssVariables(html, item, feedId) {
var source = String(html || ''); var source = String(html || '');
return source.replace(/\{\{\s*([a-zA-Z0-9_]+)(?:\.([a-zA-Z0-9_.]+))?\s*\}\}/g, function (_match, tokenName, tokenPath) { return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
if (!item || typeof item !== 'object') { if (!item || typeof item !== 'object') {
return ''; return '';
} }
var key = tokenPath ? tokenName + '.' + tokenPath : tokenName; if (typeof placeholderUtils.resolvePlaceholderExpression !== 'function' || typeof placeholderUtils.formatPlaceholderValue !== 'function') {
return escapeHtml(resolveRssPath(item, key || '')); return '';
}
var resolved = placeholderUtils.resolvePlaceholderExpression(item, expression);
if (typeof placeholderUtils.isImagePlaceholderExpression === 'function' && placeholderUtils.isImagePlaceholderExpression(expression)) {
var imageSource = placeholderUtils.formatPlaceholderValue(resolved);
var feed = getRssFeedById(feedId);
imageSource = feed && feed.imageCache && feed.imageCache[imageSource] ? feed.imageCache[imageSource] : imageSource;
if (!/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/])/i.test(imageSource)) {
return '';
}
var imageConfig = typeof placeholderUtils.getImagePlaceholderConfig === 'function' ? placeholderUtils.getImagePlaceholderConfig(expression) : {};
var hasImageBounds = imageConfig.width && imageConfig.height;
var imageStyle = hasImageBounds
? 'display:block;width:100%;height:100%;object-fit:contain;'
: 'display:block;width:auto;height:auto;' + (imageConfig.width ? 'max-width:' + imageConfig.width + 'px;' : '') + (imageConfig.height ? 'max-height:' + imageConfig.height + 'px;' : '');
var image = '<img src="' + escapeHtml(imageSource) + '" alt="" style="' + imageStyle + '" />';
return hasImageBounds
? '<span style="display:inline-flex;align-items:center;justify-content:center;box-sizing:border-box;width:' + imageConfig.width + 'px;height:' + imageConfig.height + 'px;">' + image + '</span>'
: image;
}
return escapeHtml(placeholderUtils.formatPlaceholderValue(resolved));
}); });
} }
@@ -83,17 +104,8 @@ function renderRssRegion(region, regionContent) {
var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize || defaultStyle.font_size); var fontSize = sanitizeFontSize(regionContent.font_size || region.fontSize || defaultStyle.font_size);
var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor || defaultStyle.font_color); var fontColor = sanitizeTextColor(regionContent.font_color || region.fontColor || defaultStyle.font_color);
var item = getRssFeedItem(feedId, itemNumber); var item = getRssFeedItem(feedId, itemNumber);
var body = item ? substituteRssVariables(content, item) : ''; var hasFeed = String(feedId === undefined || feedId === null ? '' : feedId).trim() !== '';
if (!body && item) { var body = hasFeed ? (item ? substituteRssVariables(content, item, feedId) : '') : content;
var summaryParts = [];
if (item.title) {
summaryParts.push('<h3>' + escapeHtml(item.title) + '</h3>');
}
if (item.description) {
summaryParts.push('<div>' + sanitizeRichText(item.description) + '</div>');
}
body = summaryParts.join('');
}
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';'; var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor) + ';';
if (!body) { if (!body) {
return ''; return '';
+2
View File
@@ -1,3 +1,5 @@
// RTMP region markup and playback lifecycle hooks.
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
function renderRtmpRegion(region, regionContent) { function renderRtmpRegion(region, regionContent) {
+21 -28
View File
@@ -1,6 +1,7 @@
// Time/date region rendering and live updates. // Time/date region rendering and live updates.
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
var placeholderUtils = window.placeholderUtils || {};
var DEFAULT_FORMAT = '{{hh}}:{{mm}}'; var DEFAULT_FORMAT = '{{hh}}:{{mm}}';
var DEFAULT_STYLE = { var DEFAULT_STYLE = {
font_family: 'Arial', font_family: 'Arial',
@@ -9,15 +10,6 @@ var DEFAULT_STYLE = {
}; };
var timeDateFormatterCache = Object.create(null); var timeDateFormatterCache = Object.create(null);
function escapeHtml(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
function sanitizeTagAttributes(tagName, attrText) { function sanitizeTagAttributes(tagName, attrText) {
var allowedAttributes = { var allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'], a: ['href', 'title', 'target', 'rel', 'class', 'style'],
@@ -133,7 +125,7 @@ function resolveTimeZone(value) {
} }
} }
function getFormatter(key, options) { function getTimeDateFormatter(key, options) {
if (!timeDateFormatterCache[key]) { if (!timeDateFormatterCache[key]) {
timeDateFormatterCache[key] = new Intl.DateTimeFormat('en-GB', options); timeDateFormatterCache[key] = new Intl.DateTimeFormat('en-GB', options);
} }
@@ -141,10 +133,10 @@ function getFormatter(key, options) {
return timeDateFormatterCache[key]; return timeDateFormatterCache[key];
} }
function getFormattedParts(timeZone, date) { function getTimeDateFormattedParts(timeZone, date) {
var targetDate = date instanceof Date ? date : new Date(); var targetDate = date instanceof Date ? date : new Date();
var resolvedTimeZone = resolveTimeZone(timeZone); var resolvedTimeZone = resolveTimeZone(timeZone);
var numericParts = getFormatter('numeric:' + resolvedTimeZone, { var numericParts = getTimeDateFormatter('numeric:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
hour12: false, hour12: false,
hour: '2-digit', hour: '2-digit',
@@ -154,29 +146,29 @@ function getFormattedParts(timeZone, date) {
month: '2-digit', month: '2-digit',
year: 'numeric' year: 'numeric'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var weekdayLong = getFormatter('weekday-long:' + resolvedTimeZone, { var weekdayLong = getTimeDateFormatter('weekday-long:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
weekday: 'long' weekday: 'long'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var weekdayShort = getFormatter('weekday-short:' + resolvedTimeZone, { var weekdayShort = getTimeDateFormatter('weekday-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
weekday: 'short' weekday: 'short'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var monthLong = getFormatter('month-long:' + resolvedTimeZone, { var monthLong = getTimeDateFormatter('month-long:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
month: 'long' month: 'long'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var monthShort = getFormatter('month-short:' + resolvedTimeZone, { var monthShort = getTimeDateFormatter('month-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
month: 'short' month: 'short'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var ampm = getFormatter('ampm:' + resolvedTimeZone, { var ampm = getTimeDateFormatter('ampm:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
hour12: true, hour12: true,
hour: '2-digit', hour: '2-digit',
minute: '2-digit' minute: '2-digit'
}).formatToParts(targetDate); }).formatToParts(targetDate);
var timezoneShort = getFormatter('tz-short:' + resolvedTimeZone, { var timezoneShort = getTimeDateFormatter('tz-short:' + resolvedTimeZone, {
timeZone: resolvedTimeZone, timeZone: resolvedTimeZone,
timeZoneName: 'short' timeZoneName: 'short'
}).formatToParts(targetDate); }).formatToParts(targetDate);
@@ -213,27 +205,28 @@ function getFormattedParts(timeZone, date) {
MMM: toTitleCase(getPart(monthShort, 'month')), MMM: toTitleCase(getPart(monthShort, 'month')),
MMMM: toTitleCase(getPart(monthLong, 'month')), MMMM: toTitleCase(getPart(monthLong, 'month')),
a: toTitleCase(getPart(ampm, 'dayPeriod')), a: toTitleCase(getPart(ampm, 'dayPeriod')),
tz: resolvedTimeZone, tz: getPart(timezoneShort, 'timeZoneName'),
tz_short: getPart(timezoneShort, 'timeZoneName'), tz_long: resolvedTimeZone,
date: getPart(numericParts, 'year') + '-' + getPart(numericParts, 'month') + '-' + getPart(numericParts, 'day'), date: getPart(numericParts, 'year') + '-' + getPart(numericParts, 'month') + '-' + getPart(numericParts, 'day'),
time: getPart(numericParts, 'hour') + ':' + getPart(numericParts, 'minute') + ':' + getPart(numericParts, 'second') time: getPart(numericParts, 'hour') + ':' + getPart(numericParts, 'minute') + ':' + getPart(numericParts, 'second')
}; };
} }
function resolveTimeDatePlaceholder(values, expression) { function resolveTimeDateTemplatePlaceholder(values, expression) {
if (typeof placeholderUtils.resolvePlaceholderExpression === 'function' && typeof placeholderUtils.formatPlaceholderValue === 'function') { var currentPlaceholderUtils = window.placeholderUtils || placeholderUtils || {};
return placeholderUtils.formatPlaceholderValue(placeholderUtils.resolvePlaceholderExpression(values, expression)); if (typeof currentPlaceholderUtils.resolvePlaceholderExpression === 'function' && typeof currentPlaceholderUtils.formatPlaceholderValue === 'function') {
return currentPlaceholderUtils.formatPlaceholderValue(currentPlaceholderUtils.resolvePlaceholderExpression(values, expression));
} }
var parsed = String(expression || '').trim(); var parsed = String(expression || '').trim();
return Object.prototype.hasOwnProperty.call(values, parsed) ? values[parsed] : ''; return Object.prototype.hasOwnProperty.call(values, parsed) ? values[parsed] : '';
} }
function renderTemplate(format, timeZone, date) { function renderTimeDateTemplate(format, timeZone, date) {
var template = String(format || '').trim() || DEFAULT_FORMAT; var template = String(format || '').trim() || DEFAULT_FORMAT;
var values = getFormattedParts(timeZone, date); var values = getTimeDateFormattedParts(timeZone, date);
return template.replace(/\{\{\s*([a-zA-Z0-9_.()\-]+)\s*\}\}/g, function (_match, key) { return template.replace(/\{\{\s*([a-zA-Z0-9_.()\-]+)\s*\}\}/g, function (_match, key) {
return String(resolveTimeDatePlaceholder(values, key) || ''); return String(resolveTimeDateTemplatePlaceholder(values, key, { timeZone: timeZone }) || '');
}); });
} }
@@ -257,7 +250,7 @@ function renderTimeDateRegion(region, regionContent) {
var fontSize = style.font_size ? 'font-size:' + Math.max(1, Math.round(Number(style.font_size))) + 'px;' : ''; var fontSize = style.font_size ? 'font-size:' + Math.max(1, Math.round(Number(style.font_size))) + 'px;' : '';
var fontColor = style.font_color ? 'color:' + escapeHtml(style.font_color) + ';' : ''; var fontColor = style.font_color ? 'color:' + escapeHtml(style.font_color) + ';' : '';
var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? fontFamily : '') + fontSize + fontColor + 'white-space:pre-wrap;line-height:1.1;'; var contentStyle = 'width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;transform:scale(' + region.canvasScale + ');transform-origin:top left;' + (fontFamily ? fontFamily : '') + fontSize + fontColor + 'white-space:pre-wrap;line-height:1.1;';
var renderedText = renderTemplate(format, timeZone, new Date()); var renderedText = renderTimeDateTemplate(format, timeZone, new Date());
return '<div class="template-region time-date" data-time-date-format="' + escapeHtml(format) + '" data-time-date-timezone="' + escapeHtml(timeZone) + '" style="' + region.baseStyle + '"><div class="template-region-text-scale" style="' + contentStyle + '">' + renderEditorJsContent(renderedText) + '</div></div>'; return '<div class="template-region time-date" data-time-date-format="' + escapeHtml(format) + '" data-time-date-timezone="' + escapeHtml(timeZone) + '" style="' + region.baseStyle + '"><div class="template-region-text-scale" style="' + contentStyle + '">' + renderEditorJsContent(renderedText) + '</div></div>';
} }
@@ -273,7 +266,7 @@ function updateTimeDateRegion(element) {
return; return;
} }
scaleWrapper.innerHTML = renderEditorJsContent(renderTemplate(format, timeZone, new Date())); scaleWrapper.innerHTML = renderEditorJsContent(renderTimeDateTemplate(format, timeZone, new Date()));
} }
function scheduleTimeDateRegionUpdate(element) { function scheduleTimeDateRegionUpdate(element) {
@@ -2,101 +2,6 @@
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
function escapeHtml(value) {
return String(value === undefined || value === null ? '' : value)
.replace(/&/g, '&amp;')
.replace(/</g, '&lt;')
.replace(/>/g, '&gt;')
.replace(/"/g, '&quot;')
.replace(/'/g, '&#39;');
}
function sanitizeRichTextAttributes(tagName, attrText) {
var allowedAttributes = {
a: ['href', 'title', 'target', 'rel', 'class', 'style'],
blockquote: ['class', 'style'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
div: ['class', 'style'],
figure: ['class', 'style'],
figcaption: ['class', 'style'],
h1: ['class', 'style'],
h2: ['class', 'style'],
h3: ['class', 'style'],
h4: ['class', 'style'],
h5: ['class', 'style'],
h6: ['class', 'style'],
li: ['class', 'style'],
ol: ['class', 'style', 'start'],
p: ['class', 'style'],
pre: ['class', 'style'],
span: ['class', 'style'],
table: ['class', 'style'],
tbody: ['class', 'style'],
td: ['class', 'style', 'colspan', 'rowspan'],
th: ['class', 'style', 'colspan', 'rowspan', 'scope'],
thead: ['class', 'style'],
tr: ['class', 'style'],
ul: ['class', 'style']
};
var allowed = allowedAttributes[tagName] || [];
if (!allowed.length) {
return '';
}
var attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, function (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) {
var lowerKey = String(key || '').toLowerCase();
if (allowed.indexOf(lowerKey) === -1) {
return '';
}
var value = doubleQuoted !== undefined ? doubleQuoted : singleQuoted !== undefined ? singleQuoted : bareValue !== undefined ? bareValue : '';
if (lowerKey === 'href' && /^(?:\s*javascript:|\s*data:)/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'style' && /(?:expression\s*\(|javascript:|url\s*\()/i.test(String(value || ''))) {
return '';
}
if (lowerKey === 'target') {
var targetValue = String(value || '').trim();
if (targetValue === '_blank') {
attrs.push(' target="_blank"');
if (attrs.indexOf(' rel="noreferrer noopener"') === -1) {
attrs.push(' rel="noreferrer noopener"');
}
return '';
}
}
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"');
return '';
});
return attrs.join('');
}
function sanitizeRichText(html) {
var output = String(html || '');
output = output.replace(/<script[\s\S]*?<\/script>/gi, '');
output = output.replace(/<style[\s\S]*?<\/style>/gi, '');
return output.replace(/<[^>]+>/g, function (tag) {
var match = tag.match(/^<\s*(\/?)\s*([a-z0-9]+)([\s\S]*?)(\/?)>$/i);
if (!match) {
return '';
}
var closing = Boolean(match[1]);
var name = String(match[2] || '').toLowerCase();
var allowed = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
if (allowed.indexOf(name) === -1) {
return '';
}
if (closing) {
return '</' + name + '>';
}
return '<' + name + sanitizeRichTextAttributes(name, String(match[3] || '')) + '>';
});
}
function substituteTimetableVariables(html, entry) { function substituteTimetableVariables(html, entry) {
var source = String(html || ''); var source = String(html || '');
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) { return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
@@ -228,6 +133,7 @@ function renderRegion(region, regionContent) {
var maxItems = regionContent && regionContent.max_items !== undefined ? regionContent.max_items : 5; var maxItems = regionContent && regionContent.max_items !== undefined ? regionContent.max_items : 5;
var group = getGroupById(groupId, groups); var group = getGroupById(groupId, groups);
var entries = getVisibleEntries(groupId, displayMode, maxItems, groups); var entries = getVisibleEntries(groupId, displayMode, maxItems, groups);
var timeZone = group && (group.timezone || group.time_zone) ? String(group.timezone || group.time_zone) : '';
var width = Math.max(1, Math.round(Number(region && region.pixelWidth ? region.pixelWidth : 0) || 1)); var width = Math.max(1, Math.round(Number(region && region.pixelWidth ? region.pixelWidth : 0) || 1));
var height = Math.max(1, Math.round(Number(region && region.pixelHeight ? region.pixelHeight : 0) || 1)); var height = Math.max(1, Math.round(Number(region && region.pixelHeight ? region.pixelHeight : 0) || 1));
var canvasScale = Number(region && region.canvasScale ? region.canvasScale : 1) || 1; var canvasScale = Number(region && region.canvasScale ? region.canvasScale : 1) || 1;
@@ -241,6 +147,7 @@ function renderRegion(region, regionContent) {
return '<div class="timetable-region-entry" data-timetable-entry-index="' + index + '">' + sanitizeRichText(substituteTimetableVariables(value, Object.assign({}, entry || {}, { return '<div class="timetable-region-entry" data-timetable-entry-index="' + index + '">' + sanitizeRichText(substituteTimetableVariables(value, Object.assign({}, entry || {}, {
start: entry && entry.start_datetime !== undefined ? entry.start_datetime : '', start: entry && entry.start_datetime !== undefined ? entry.start_datetime : '',
end: entry && entry.end_datetime !== undefined ? entry.end_datetime : '', end: entry && entry.end_datetime !== undefined ? entry.end_datetime : '',
timeZone: timeZone,
group: group || {}, group: group || {},
entries: entries, entries: entries,
index: index + 1 index: index + 1
+90
View File
@@ -0,0 +1,90 @@
// Weather region rendering for live playback.
var weatherRegistry = window.pulsePlayerRegionTypes;
var weatherPlaceholderUtils = window.placeholderUtils || {};
function weatherIconForCode(code) {
var value = Number(code);
if (value === 0) return 'bi-sun';
if (value <= 3) return 'bi-cloud-sun';
if (value <= 48) return 'bi-cloud-fog';
if (value <= 67 || value > 77 && value <= 82) return 'bi-cloud-rain';
if (value <= 77) return 'bi-cloud-snow';
return 'bi-cloud-lightning-rain';
}
function getWeatherLocation(locationId) {
var locations = Array.isArray(initialData && initialData.weatherLocations) ? initialData.weatherLocations : [];
return locations.find(function (location) { return Number(location.id) === Number(locationId); }) || null;
}
function normalizeWeatherExpression(expression) {
var value = String(expression || '').trim();
var currentAliases = { temp: 'current.temperature_2m', temp_unit: 'current.temperature_unit', feels_like: 'current.apparent_temperature', humidity: 'current.relative_humidity_2m', code: 'current.weather_code', wind: 'current.wind_speed_10m', wind_unit: 'current.wind_speed_unit', precip: 'current.precipitation', precip_unit: 'current.precipitation_unit', uv_index: 'current.uv_index', cloud_cover: 'current.cloud_cover', icon: 'current.weather_code.icon' };
var globalAliases = { temp_unit: 'temperature_unit', wind_unit: 'wind_speed_unit', precip_unit: 'precipitation_unit' };
if (globalAliases[value]) return globalAliases[value];
var currentField = value.replace(/^current\./, '');
var currentMatch = currentField.match(/^([^.()]+)((?:\(.*\))|(?:\..*))?$/);
if (currentMatch && currentAliases[currentMatch[1]]) return currentAliases[currentMatch[1]] + (currentMatch[2] || '');
var indexed = value.match(/^(daily|hourly)\.(\d+)\.(.+)$/);
if (!indexed) return value;
var fieldMatch = indexed[3].match(/^([^.()]+)((?:\(.*\))|(?:\..*))?$/);
var field = fieldMatch ? fieldMatch[1] : indexed[3];
var aliases = indexed[1] === 'daily' ? { time: 'time', code: 'weather_code', temp_max: 'temperature_2m_max', temp_min: 'temperature_2m_min', precip: 'precipitation_sum', wind: 'wind_speed_10m_max', uv_index: 'uv_index_max', cloud_cover: 'cloud_cover_mean', sunrise: 'sunrise', sunset: 'sunset', icon: 'weather_code' } : { time: 'time', code: 'weather_code', temp: 'temperature_2m', precip: 'precipitation', wind: 'wind_speed_10m', uv_index: 'uv_index', cloud_cover: 'cloud_cover', icon: 'weather_code' };
if (!Object.prototype.hasOwnProperty.call(aliases, field)) return value;
return field === 'icon' ? indexed[1] + '.' + aliases[field] + '.' + indexed[2] + '.icon' + (fieldMatch[2] || '') : indexed[1] + '.' + aliases[field] + '.' + indexed[2] + (fieldMatch[2] || '');
}
function withWeatherUnits(snapshot, location) {
var data = Object.assign({}, snapshot, { location_label: location.location_label || '', name: location.name || '', timezone: location.timezone || '', temp_unit: location.temperature_unit === 'fahrenheit' ? '°F' : '°C', wind_unit: location.wind_unit === 'mph' ? 'mph' : location.wind_unit === 'ms' ? 'm/s' : 'km/h', precip_unit: location.precipitation_unit === 'inch' ? 'in' : 'mm' });
var temperatureUnit = location.temperature_unit === 'fahrenheit' ? '°F' : '°C';
var windUnit = location.wind_unit === 'mph' ? 'mph' : location.wind_unit === 'ms' ? 'm/s' : 'km/h';
var precipitationUnit = location.precipitation_unit === 'inch' ? 'in' : 'mm';
data.current = Object.assign({}, snapshot.current || {}, { temperature_unit: temperatureUnit, wind_speed_unit: windUnit, precipitation_unit: precipitationUnit });
data.daily = Object.assign({}, snapshot.daily || {}, { temperature_unit: temperatureUnit });
data.hourly = Object.assign({}, snapshot.hourly || {}, { temperature_unit: temperatureUnit });
return data;
}
function substituteWeatherVariables(html, value) {
return String(html || '').replace(/\{\{\s*([^{}]+?)\s*\}\}/g, function (_match, expression) {
if (!value || typeof value !== 'object' || typeof weatherPlaceholderUtils.resolvePlaceholderExpression !== 'function' || typeof weatherPlaceholderUtils.formatPlaceholderValue !== 'function') return '';
var rawExpression = String(expression).trim();
var normalizedExpression = normalizeWeatherExpression(rawExpression);
var iconMatch = normalizedExpression.match(/^(?:current\.weather_code|daily\.weather_code\.\d+|hourly\.weather_code\.\d+)\.icon(?:\((\d+)(?:\s*,\s*(\d+))?\))?$/);
if (iconMatch) {
var codeExpression = normalizedExpression.replace(/\.icon(?:\(.*\))?$/, '');
var width = iconMatch[1] ? Math.max(1, Math.min(1000, Number(iconMatch[1]))) : 0;
var height = iconMatch[2] ? Math.max(1, Math.min(1000, Number(iconMatch[2]))) : width;
var style = width ? ' style="display:inline-block;vertical-align:middle;font-size:' + width + 'px;line-height:' + height + 'px;width:' + width + 'px;height:' + height + 'px;"' : '';
var weatherCode = weatherPlaceholderUtils.resolvePlaceholderExpression(value, codeExpression, { timeZone: value.timezone });
var icon = '<i class="bi ' + weatherIconForCode(weatherCode) + '"' + style + ' aria-hidden="true"></i>';
return width ? '<span style="display:inline-flex;align-items:center;justify-content:center;box-sizing:border-box;width:' + width + 'px;height:' + height + 'px;">' + icon + '</span>' : icon;
}
return escapeHtml(weatherPlaceholderUtils.formatPlaceholderValue(weatherPlaceholderUtils.resolvePlaceholderExpression(value, normalizeWeatherExpression(expression), { timeZone: value.timezone })));
});
}
function renderWeatherRegion(region, regionContent) {
var location = getWeatherLocation(regionContent && regionContent.weather_location_id);
var snapshot = location && location.responseJson && typeof location.responseJson === 'object' ? location.responseJson : null;
var width = Math.max(1, Math.round(Number(region && region.pixelWidth) || 1));
var height = Math.max(1, Math.round(Number(region && region.pixelHeight) || 1));
var scale = Number(region && region.canvasScale) || 1;
var style = 'width:' + width + 'px;height:' + height + 'px;transform:scale(' + scale + ');transform-origin:top left;overflow:hidden;';
if (!location || !snapshot) return '<div class="template-region weather" style="' + region.baseStyle + '"><div style="' + style + '"></div></div>';
var current = snapshot.current || {};
var value = String(regionContent && regionContent.value || '');
if (value) {
var weatherData = withWeatherUnits(snapshot, location);
var fontSize = Math.max(8, Number(regionContent && regionContent.font_size || region && (region.font_size || region.fontSize) || 32) || 32);
return '<div class="template-region weather" style="' + region.baseStyle + '"><div style="' + style + 'font-family:Arial,sans-serif;font-size:' + fontSize + 'px;line-height:1.5;">' + renderEditorJsContent(substituteWeatherVariables(value, weatherData)) + '</div></div>';
}
var daily = snapshot.daily || {};
var days = (daily.time || []).slice(0, 7).map(function (day, index) {
return '<div class="weather-region-day"><strong>' + escapeHtml(index === 0 ? 'Today' : String(day).slice(5)) + '</strong><i class="bi ' + weatherIconForCode(daily.weather_code && daily.weather_code[index]) + '"></i><span>' + escapeHtml(daily.temperature_2m_max && daily.temperature_2m_max[index] !== undefined ? daily.temperature_2m_max[index] + '°' : '-') + '</span></div>';
}).join('');
return '<div class="template-region weather" style="' + region.baseStyle + '"><div style="' + style + 'padding:3%;font-family:Arial,sans-serif;"><div style="display:flex;align-items:center;justify-content:space-between;"><div><div style="font-size:.8em;opacity:.72;">' + escapeHtml(location.location_label || location.name) + '</div><strong style="font-size:2em;">' + escapeHtml(current.temperature_2m === undefined ? '-' : current.temperature_2m) + '°</strong></div><i class="bi ' + weatherIconForCode(current.weather_code) + '" style="font-size:3em;"></i></div><div style="display:grid;grid-template-columns:repeat(7,minmax(0,1fr));gap:.35em;margin-top:1em;">' + days + '</div></div></div>';
}
weatherRegistry.register('weather', { renderRegion: renderWeatherRegion });
+28 -2
View File
@@ -2,12 +2,38 @@
var registry = window.pulsePlayerRegionTypes; var registry = window.pulsePlayerRegionTypes;
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.url !== undefined) {
return normalizeRenderableValue(value.url);
}
if (value.href !== undefined) {
return normalizeRenderableValue(value.href);
}
if (value.src !== undefined) {
return normalizeRenderableValue(value.src);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function renderWebpageRegion(region, regionContent) { function renderWebpageRegion(region, regionContent) {
var url = String(regionContent.value || '').trim(); var url = normalizeRenderableValue(regionContent && regionContent.value !== undefined ? regionContent.value : '').trim();
if (!url) { if (!url) {
return ''; return '';
} }
return '<div class="template-region webpage" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(url) + '" title="' + escapeHtml(region.label) + '" loading="eager" referrerpolicy="no-referrer" scrolling="no"></iframe></div>'; return '<div class="template-region webpage" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(url) + '" title="' + escapeHtml(region.label) + '" loading="eager" referrerpolicy="no-referrer" scrolling="no" style="width:100%;height:100%;border:0;display:block;background:#fff;overflow:hidden;"></iframe></div>';
} }
registry.register('webpage', { registry.register('webpage', {
+88 -6
View File
@@ -1,3 +1,5 @@
// Assemble player HTML and inline runtime scripts from the server-side templates.
const fs = require('fs'); const fs = require('fs');
const path = require('path'); const path = require('path');
const announcementIcons = require('#src/data/announcement-icons'); const announcementIcons = require('#src/data/announcement-icons');
@@ -25,6 +27,14 @@ function escapeHtml(value) {
.replace(/'/g, '&#39;'); .replace(/'/g, '&#39;');
} }
function normalizeStyleAttributeValue(value) {
return String(value || '')
.replace(/&quot;/g, '"')
.replace(/&#39;/g, "'")
.replace(/&amp;quot;/g, '"')
.replace(/&amp;#39;/g, "'");
}
function sanitizeFontFamily(value) { function sanitizeFontFamily(value) {
return String(value || '').replace(/[^a-zA-Z0-9 ,"-]/g, '').trim(); return String(value || '').replace(/[^a-zA-Z0-9 ,"-]/g, '').trim();
} }
@@ -41,7 +51,7 @@ function sanitizeTextColor(value, fallback) {
return fallback || '#000000'; return fallback || '#000000';
} }
const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul']; const ALLOWED_RICH_TEXT_TAGS = ['a', 'b', 'blockquote', 'br', 'code', 'col', 'colgroup', 'div', 'em', 'figure', 'figcaption', 'h1', 'h2', 'h3', 'h4', 'h5', 'h6', 'hr', 'i', 'img', 'li', 'ol', 'p', 'pre', 'span', 'strong', 'sub', 'sup', 'table', 'tbody', 'td', 'th', 'thead', 'tr', 'u', 'ul'];
function sanitizeRichTextAttributes(tagName, attrText) { function sanitizeRichTextAttributes(tagName, attrText) {
const allowedAttributes = { const allowedAttributes = {
@@ -56,6 +66,10 @@ function sanitizeRichTextAttributes(tagName, attrText) {
h4: ['class', 'style'], h4: ['class', 'style'],
h5: ['class', 'style'], h5: ['class', 'style'],
h6: ['class', 'style'], h6: ['class', 'style'],
i: ['class', 'style', 'aria-hidden'],
img: ['src', 'alt', 'title', 'width', 'height', 'class', 'style', 'loading', 'decoding'],
col: ['class', 'style', 'span', 'width'],
colgroup: ['class', 'style', 'span'],
li: ['class', 'style'], li: ['class', 'style'],
ol: ['class', 'style', 'start'], ol: ['class', 'style', 'start'],
p: ['class', 'style'], p: ['class', 'style'],
@@ -72,6 +86,14 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return ''; return '';
} }
if (tagName === 'img') {
const srcMatch = String(attrText || '').match(/\bsrc\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+))/i);
const srcValue = srcMatch ? String(srcMatch[2] !== undefined ? srcMatch[2] : srcMatch[3] !== undefined ? srcMatch[3] : srcMatch[4] !== undefined ? srcMatch[4] : '').trim() : '';
if (!srcValue || !/^(?:https?:\/\/|\/media\/|\/assets\/|\/[^/]|data:image\/)/i.test(srcValue)) {
return '';
}
}
const attrs = []; const attrs = [];
String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => { String(attrText || '').replace(/([a-zA-Z0-9:-]+)(?:\s*=\s*("([^"]*)"|'([^']*)'|([^\s"'>/=`]+)))?/g, (_full, key, _valuePart, doubleQuoted, singleQuoted, bareValue) => {
const lowerKey = String(key || '').toLowerCase(); const lowerKey = String(key || '').toLowerCase();
@@ -95,7 +117,7 @@ function sanitizeRichTextAttributes(tagName, attrText) {
return ''; return '';
} }
} }
attrs.push(' ' + lowerKey + '="' + escapeHtml(value) + '"'); attrs.push(' ' + lowerKey + '="' + escapeHtml(lowerKey === 'style' ? normalizeStyleAttributeValue(value) : value) + '"');
return ''; return '';
}); });
@@ -268,12 +290,45 @@ function renderEditorJsContent(value) {
return wrapRichTextParagraph(sanitizeRichText(raw)); return wrapRichTextParagraph(sanitizeRichText(raw));
} }
function buildHtmlDocument(html) {
const raw = String(html || '').trim();
if (!raw) {
return '';
}
if (/^<!doctype\b/i.test(raw) || /^<html\b/i.test(raw)) {
return raw;
}
return '<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + raw + '</body></html>';
}
function renderHtmlRegionContent(value) { function renderHtmlRegionContent(value) {
const html = String(value || '').trim(); const html = normalizeRenderableValue(value).trim();
if (!html) { if (!html) {
return '<div class="template-region-placeholder">HTML</div>'; return '<div class="template-region-placeholder">HTML</div>';
} }
return '<iframe class="template-region-html-frame" sandbox="" srcdoc="' + escapeHtml(html) + '" title="HTML region" loading="eager"></iframe>'; return '<iframe class="template-region-html-frame" sandbox="" srcdoc="' + escapeHtml(buildHtmlDocument(html)) + '" title="HTML region" loading="eager" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe>';
}
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
} }
function fitCanvasSize(canvasWidth, canvasHeight, maxWidth, maxHeight) { function fitCanvasSize(canvasWidth, canvasHeight, maxWidth, maxHeight) {
@@ -374,7 +429,7 @@ function getPlayerAnnouncementTemplatesScript() {
function getAnnouncementIconsDataScript() { function getAnnouncementIconsDataScript() {
return [ return [
'(function () {', '(function () {',
' window.pulseAnnouncementIconKeys = ' + safeJsonForScript(announcementIcons.ANNOUNCEMENT_ICON_KEYS) + ';', ' window.pulseAnnouncementIconKeys = ' + safeJsonForScript(announcementIcons.ANNOUNCEMENT_ICON_CATALOG_KEYS) + ';',
' window.pulseAnnouncementDefaultIconKey = ' + safeJsonForScript(announcementIcons.DEFAULT_ANNOUNCEMENT_ICON) + ';', ' window.pulseAnnouncementDefaultIconKey = ' + safeJsonForScript(announcementIcons.DEFAULT_ANNOUNCEMENT_ICON) + ';',
'}());' '}());'
].join('\n'); ].join('\n');
@@ -470,6 +525,32 @@ function getPlayerOnboardingFormScript() {
return loadTemplate(playerOnboardingFormScriptPath, playerOnboardingFormScriptCache || (playerOnboardingFormScriptCache = {})); return loadTemplate(playerOnboardingFormScriptPath, playerOnboardingFormScriptCache || (playerOnboardingFormScriptCache = {}));
} }
function getPlayerRuntimeScripts() {
function getScriptBody(value) {
return String(value || '')
.replace(/^\s*<script(?:\s[^>]*)?>/i, '')
.replace(/<\/script>\s*$/i, '')
.trim();
}
return [
['region-registry', fs.readFileSync(path.join(__dirname, 'public', 'js', 'player-region-registry.js'), 'utf8').trim()],
['placeholder-utils', fs.readFileSync(path.join(__dirname, '..', 'web', 'public', 'js', 'shared', 'placeholder-utils.js'), 'utf8').trim()],
['qr-code-svg', fs.readFileSync(path.join(__dirname, '..', 'web', 'public', 'js', 'shared', 'qr-code-svg.js'), 'utf8').trim()],
['client-name', getScriptBody(getPlayerClientNameScript()())],
['offline', getScriptBody(getPlayerPageOfflineScript()())],
['playlist', getScriptBody(getPlayerPagePlaylistScript()())],
['commands', getScriptBody(getPlayerPageCommandsScript()())],
['rendering', getScriptBody(getPlayerPageRenderingScript()())],
['playback', getScriptBody(getPlayerPagePlaybackScript()())],
['announcement-icons', getAnnouncementIconsDataScript()],
['announcement-data', getPlayerAnnouncementTemplatesDataScript()],
['announcement-templates', getScriptBody(getPlayerAnnouncementTemplatesScript())]
].concat(getPlayerRegionScriptPaths().map(function (filePath, index) {
return ['region-' + index, fs.readFileSync(filePath, 'utf8').trim()];
})).filter(function (entry) { return entry[1]; });
}
module.exports = { module.exports = {
mediaKind: mediaKind, mediaKind: mediaKind,
escapeHtml: escapeHtml, escapeHtml: escapeHtml,
@@ -503,5 +584,6 @@ module.exports = {
getPlayerPageScript: getPlayerPageScript, getPlayerPageScript: getPlayerPageScript,
getPlayerRegionScripts: getPlayerRegionScripts, getPlayerRegionScripts: getPlayerRegionScripts,
getPlayerOnboardingLandingScript: getPlayerOnboardingLandingScript, getPlayerOnboardingLandingScript: getPlayerOnboardingLandingScript,
getPlayerOnboardingFormScript: getPlayerOnboardingFormScript getPlayerOnboardingFormScript: getPlayerOnboardingFormScript,
getPlayerRuntimeScripts: getPlayerRuntimeScripts
}; };
+32 -36
View File
@@ -2,8 +2,7 @@
const Handlebars = require('handlebars'); const Handlebars = require('handlebars');
const path = require('path'); const path = require('path');
const { mediaKind, safeJsonForScript, getPlayerPageTemplate, getPlayerClientNameScript, getPlayerPageOfflineScript, getPlayerPagePlaylistScript, getPlayerPageCommandsScript, getPlayerPageRenderingScript, getPlayerPagePlaybackScript, getAnnouncementIconsDataScript, getPlayerAnnouncementTemplatesDataScript, getPlayerAnnouncementTemplatesScript, getPlayerPageAnnouncementsScript, getPlayerPageScript, getPlayerRegionScripts, getPlayerOnboardingLandingScript, getPlayerOnboardingFormScript } = require('./render-helpers'); const { mediaKind, safeJsonForScript, getPlayerPageTemplate, getPlayerPageAnnouncementsScript, getPlayerPageScript, getPlayerOnboardingLandingScript, getPlayerOnboardingFormScript, getPlayerRuntimeScripts } = require('./render-helpers');
const { createThumbnailPreviewBootstrapScript } = require('./thumbnail-preview');
const { createPageAuthBundle, createPageFetchAuthScript } = require('#src/request-auth'); const { createPageAuthBundle, createPageFetchAuthScript } = require('#src/request-auth');
const { getFontStylesheetHref } = require('#src/web/lib/media/font-library'); const { getFontStylesheetHref } = require('#src/web/lib/media/font-library');
@@ -36,34 +35,31 @@ function getPlayerServiceWorkerRegistrationScript() {
].join(''); ].join('');
} }
function renderOnboardingLandingBody() { function renderOnboardingLandingBody(options) {
const onboardingCode = String(options && options.pairingCode || '').trim();
const deviceId = String(options && options.deviceId || '').trim();
return [ return [
'<main class="onboarding-shell">', ' <main id="onboarding-shell" class="onboarding-shell">',
' <section class="onboarding-card onboarding-card--landing">', ' <section class="onboarding-stage onboarding-stage--landing">',
' <p class="onboarding-kicker">Pulse Signage</p>',
' <h1>Onboard this player</h1>',
' <p class="onboarding-copy">Choose an existing screen, name the client, and either scan the QR code or finish right here with a keyboard and mouse.</p>',
' <div class="onboarding-layout">', ' <div class="onboarding-layout">',
' <div class="onboarding-qr-pane">', ' <div class="onboarding-qr-pane">',
' <div class="onboarding-qr-frame">', ' <div class="onboarding-qr-frame">',
' <img id="onboarding-qr" alt="Onboarding QR code" src="data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E" />', ' <img id="onboarding-qr" alt="Onboarding QR code" src="data:image/svg+xml;charset=utf-8,%3Csvg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 320 320%22%3E%3Crect width=%22320%22 height=%22320%22 rx=%2224%22 fill=%22%23ffffff%22/%3E%3Crect x=%2230%22 y=%2230%22 width=%22260%22 height=%22260%22 rx=%2218%22 fill=%22%23f8fafc%22 stroke=%22%23cbd5e1%22 stroke-width=%223%22 stroke-dasharray=%2212 10%22/%3E%3Cpath d=%22M106 118h108M106 156h108M106 194h72%22 stroke=%22%2394a3b8%22 stroke-width=%2214%22 stroke-linecap=%22round%22/%3E%3Ccircle cx=%22128%22 cy=%22248%22 r=%2212%22 fill=%22%2394a3b8%22/%3E%3Ctext x=%22160%22 y=%2278%22 text-anchor=%22middle%22 fill=%22%230f172a%22 font-family=%22Arial,sans-serif%22 font-size=%2224%22 font-weight=%22700%22%3EQR code loading%3C/text%3E%3Ctext x=%22160%22 y=%22266%22 text-anchor=%22middle%22 fill=%22%234b5563%22 font-family=%22Arial,sans-serif%22 font-size=%2214%22%3EPlease wait%3C/text%3E%3C/svg%3E" />',
' </div>', ' </div>',
' <div id="onboarding-status" class="onboarding-status">Preparing onboarding link...</div>', ' <p class="onboarding-qr-caption">Scan this QR code with your phone</p>',
' </div>',
' <div class="onboarding-copy-panel">',
' <p class="onboarding-kicker onboarding-brand-title">Pulse Signage</p>',
' <h1>Quickly set up with your phone</h1>',
' <ol class="onboarding-instructions">',
' <li>Open the camera and scan the QR code.</li>',
' <li>Log in to Pulse Signage and choose a screen.</li>',
' </ol>',
' <div class="onboarding-pin-block">',
' <span class="onboarding-pin-label">Pairing Code</span>',
' <strong id="onboarding-pairing-code" class="onboarding-pin">' + Handlebars.escapeExpression(onboardingCode || 'Loading...') + '</strong>',
' </div>',
' </div>', ' </div>',
' <form id="onboarding-local-form" class="onboarding-form onboarding-form--local">',
' <label>',
' <span>Client name</span>',
' <input name="clientName" type="text" maxlength="255" required placeholder="Lobby player" autocomplete="off" />',
' </label>',
' <label>',
' <span>Screen</span>',
' <select name="screenSlug" id="onboarding-screen-select" required>',
' <option value="">Loading screens...</option>',
' </select>',
' </label>',
' <button type="submit">Save client</button>',
' <div id="onboarding-message" class="onboarding-status"></div>',
' </form>',
' </div>', ' </div>',
' </section>', ' </section>',
'</main>' '</main>'
@@ -79,6 +75,10 @@ function renderOnboardingFormBody(deviceId) {
' <p class="onboarding-copy">Pick an existing screen and give this player a friendly name that will persist after refreshes.</p>', ' <p class="onboarding-copy">Pick an existing screen and give this player a friendly name that will persist after refreshes.</p>',
' <form id="onboarding-form" class="onboarding-form">', ' <form id="onboarding-form" class="onboarding-form">',
' <label>', ' <label>',
' <span>Pairing code</span>',
' <input name="pairingCode" type="text" inputmode="numeric" pattern="[0-9]{6}" maxlength="6" required autocomplete="one-time-code" placeholder="Enter the code shown on the kiosk" />',
' </label>',
' <label>',
' <span>Client name</span>', ' <span>Client name</span>',
' <input name="clientName" type="text" maxlength="255" required placeholder="Lobby player" />', ' <input name="clientName" type="text" maxlength="255" required placeholder="Lobby player" />',
' </label>', ' </label>',
@@ -109,40 +109,36 @@ function renderOnboardingFormScript(deviceId) {
} }
function renderPlayerPage(slug, initialData) { function renderPlayerPage(slug, initialData) {
const onboardingScript = getPlayerClientNameScript()();
const offlineScript = getPlayerPageOfflineScript()();
const playlistScript = getPlayerPagePlaylistScript()();
const commandScript = getPlayerPageCommandsScript()();
const renderingScript = getPlayerPageRenderingScript()();
const playbackScript = getPlayerPagePlaybackScript()();
const serviceWorkerScript = getPlayerServiceWorkerRegistrationScript(); const serviceWorkerScript = getPlayerServiceWorkerRegistrationScript();
const template = getPlayerPageTemplate(); const template = getPlayerPageTemplate();
const hlsScriptTag = '<script src="/assets/vendor/hls.min.js"></script>'; const hlsScriptTag = '<script src="/assets/vendor/hls.min.js"></script>';
const pageAuthToken = createPageAuthBundle({ scope: 'player', slug: String(slug || '').trim() }); const pageAuthToken = createPageAuthBundle({ scope: 'player', slug: String(slug || '').trim() });
const fontStylesheetHref = getFontStylesheetHref(PLAYER_MEDIA_DIR); const fontStylesheetHref = getFontStylesheetHref(PLAYER_MEDIA_DIR);
const bodyClass = [initialData && initialData.thumbnailPreview ? 'thumbnail-preview' : '', ''].join(' ').trim(); const bootstrapScript = getPlayerPageScript()({
const script = getPlayerPageScript()({
SLUG_JSON: new Handlebars.SafeString(JSON.stringify(slug)), SLUG_JSON: new Handlebars.SafeString(JSON.stringify(slug)),
INITIAL_DATA_JSON: new Handlebars.SafeString(safeJsonForScript(initialData || null)), INITIAL_DATA_JSON: new Handlebars.SafeString(safeJsonForScript(initialData || null)),
REGION_SCRIPTS: new Handlebars.SafeString(getPlayerRegionScripts()) REGION_SCRIPTS: ''
}); });
const runtimeScriptTags = getPlayerRuntimeScripts().map(function (entry) {
return '<script src="/assets/player-script/' + encodeURIComponent(entry[0]) + '.js"></script>';
}).join('');
return renderPage(template, { return renderPage(template, {
title: 'Screen ' + slug, title: 'Screen ' + slug,
bodyClass: bodyClass, bodyClass: '',
body: '<div id="app"><div class="empty">Loading screen...</div></div>', body: '<div id="app"><div class="empty">Loading screen...</div></div>',
stylesheets: fontStylesheetHref ? [fontStylesheetHref] : [], stylesheets: fontStylesheetHref ? [fontStylesheetHref] : [],
script: createPageFetchAuthScript(pageAuthToken, '/ws/screens/' + encodeURIComponent(slug || '')) + hlsScriptTag + serviceWorkerScript + createThumbnailPreviewBootstrapScript(initialData) + '<script>' + offlineScript + '</script>' + '<script>' + playlistScript + '</script>' + '<script>' + commandScript + '</script>' + '<script>' + renderingScript + '</script>' + '<script>' + playbackScript + '</script>' + '<script>' + getAnnouncementIconsDataScript() + '</script>' + '<script>' + getPlayerAnnouncementTemplatesDataScript() + '</script>' + '<script>' + getPlayerAnnouncementTemplatesScript() + '</script>' + onboardingScript + script + '<script>' + getPlayerPageAnnouncementsScript()() + '</script>' script: createPageFetchAuthScript(pageAuthToken, '/ws/screens/' + encodeURIComponent(slug || '')) + hlsScriptTag + serviceWorkerScript + runtimeScriptTags + bootstrapScript + '<script>' + getPlayerPageAnnouncementsScript()() + '</script>'
}); });
} }
function renderPlayerOnboardingLandingPage() { function renderPlayerOnboardingLandingPage(options) {
const pageAuthToken = createPageAuthBundle({ scope: 'onboarding' }); const pageAuthToken = createPageAuthBundle({ scope: 'onboarding' });
const fontStylesheetHref = getFontStylesheetHref(PLAYER_MEDIA_DIR); const fontStylesheetHref = getFontStylesheetHref(PLAYER_MEDIA_DIR);
return renderPage(getPlayerPageTemplate(), { return renderPage(getPlayerPageTemplate(), {
title: 'Onboard player', title: 'Onboard player',
bodyClass: 'onboarding-page', bodyClass: 'onboarding-page',
body: renderOnboardingLandingBody(), body: renderOnboardingLandingBody(options),
stylesheets: fontStylesheetHref ? [fontStylesheetHref] : [], stylesheets: fontStylesheetHref ? [fontStylesheetHref] : [],
script: createPageFetchAuthScript(pageAuthToken) + getPlayerServiceWorkerRegistrationScript() + renderOnboardingLandingScript() script: createPageFetchAuthScript(pageAuthToken) + getPlayerServiceWorkerRegistrationScript() + renderOnboardingLandingScript()
}); });
+159 -78
View File
@@ -5,7 +5,6 @@ const express = require('express');
const path = require('path'); const path = require('path');
const { getSharedSecret, createPageAuthBundle, verifyPageAuthToken, verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth'); const { getSharedSecret, createPageAuthBundle, verifyPageAuthToken, verifyRequestAuth, createRequestAuthHeaders } = require('#src/request-auth');
const { getPlayerPublicBaseUrl } = require('./onboarding'); const { getPlayerPublicBaseUrl } = require('./onboarding');
const { buildThumbnailPreviewData } = require('./thumbnail-preview');
const TRANSIENT_DB_ERROR_CODES = ['ECONNREFUSED', 'ECONNRESET', 'ETIMEDOUT', 'EPIPE', 'ENOTFOUND', 'PROTOCOL_CONNECTION_LOST', 'POOL_CLOSED', 'ERR_POOL_CLOSED']; const TRANSIENT_DB_ERROR_CODES = ['ECONNREFUSED', 'ECONNRESET', 'ETIMEDOUT', 'EPIPE', 'ENOTFOUND', 'PROTOCOL_CONNECTION_LOST', 'POOL_CLOSED', 'ERR_POOL_CLOSED'];
@@ -24,6 +23,23 @@ function isBridgeFetchError(error) {
)); ));
} }
function getRequestClientId(req) {
const headerClientId = String(req && req.headers && req.headers['x-pulse-client-id'] || '').trim();
if (headerClientId) {
return headerClientId;
}
const queryClientId = String(req && req.query && req.query.clientId || '').trim();
if (queryClientId) {
return queryClientId;
}
const cookieHeader = String(req && req.headers && req.headers.cookie || '');
const cookie = cookieHeader.split(';').map(function (part) {
const separator = part.indexOf('=');
return separator === -1 ? null : [part.slice(0, separator).trim(), part.slice(separator + 1).trim()];
}).filter(Boolean).find(function (entry) { return entry[0] === 'pulse-player-client-id'; });
return cookie ? decodeURIComponent(cookie[1]) : '';
}
function registerPlayerRoutes(app, options) { function registerPlayerRoutes(app, options) {
const pool = options && options.pool ? options.pool : null; const pool = options && options.pool ? options.pool : null;
const common = options && options.common ? options.common : null; const common = options && options.common ? options.common : null;
@@ -32,9 +48,10 @@ function registerPlayerRoutes(app, options) {
const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null; const playerRuntime = options && options.playerRuntime ? options.playerRuntime : null;
const playerPlaylistService = options && options.playerPlaylistService ? options.playerPlaylistService : null; const playerPlaylistService = options && options.playerPlaylistService ? options.playerPlaylistService : null;
const rtmpStreamService = options && options.rtmpStreamService ? options.rtmpStreamService : null; const rtmpStreamService = options && options.rtmpStreamService ? options.rtmpStreamService : null;
const playerInternalUrl = String(options && options.playerInternalBaseUrl || process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || '').trim().replace(/\/$/, ''); const playerInternalUrl = String(options && options.playerInternalBaseUrl || process.env.PLAYER_INTERNAL_URL || '').trim().replace(/\/$/, '');
const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, ''); const bridgeBaseUrl = String(options && options.bridgeBaseUrl || process.env.BRIDGE_PUBLIC_URL || '').trim().replace(/\/$/, '');
const playerDeviceId = String(options && options.playerDeviceId || '').trim() || null; const playerDeviceId = String(options && options.playerDeviceId || '').trim() || null;
const snapshotDir = options && options.snapshotDir ? path.resolve(String(options.snapshotDir)) : null;
const onPlayerPublicBaseUrl = typeof options.onPlayerPublicBaseUrl === 'function' ? options.onPlayerPublicBaseUrl : null; const onPlayerPublicBaseUrl = typeof options.onPlayerPublicBaseUrl === 'function' ? options.onPlayerPublicBaseUrl : null;
if (!app || !common || !mediaDir || !assetDir || !playerRuntime || !rtmpStreamService) { if (!app || !common || !mediaDir || !assetDir || !playerRuntime || !rtmpStreamService) {
@@ -62,11 +79,20 @@ function registerPlayerRoutes(app, options) {
body: body body: body
})); }));
if (req.headers['x-pulse-page-auth']) { const requestHeaders = req && req.headers ? req.headers : {};
headers['x-pulse-page-auth'] = String(req.headers['x-pulse-page-auth']).trim(); if (requestHeaders['x-pulse-page-auth']) {
headers['x-pulse-page-auth'] = String(requestHeaders['x-pulse-page-auth']).trim();
} }
if (req.headers['if-none-match']) { if (requestHeaders['if-none-match']) {
headers['if-none-match'] = String(req.headers['if-none-match']).trim(); headers['if-none-match'] = String(requestHeaders['if-none-match']).trim();
}
if (requestHeaders['x-pulse-client-id']) {
headers['x-pulse-client-id'] = String(requestHeaders['x-pulse-client-id']).trim();
} else {
const clientId = getRequestClientId(req);
if (clientId) {
headers['x-pulse-client-id'] = clientId;
}
} }
if (requestOptions.contentType) { if (requestOptions.contentType) {
headers['content-type'] = requestOptions.contentType; headers['content-type'] = requestOptions.contentType;
@@ -96,6 +122,76 @@ function registerPlayerRoutes(app, options) {
} }
} }
async function getBoundScreenSlug(req) {
if (!playerDeviceId) {
return null;
}
const clientId = String(req.query && req.query.clientId || '').trim();
if (!clientId) {
return null;
}
const bindingId = clientId;
if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/onboarding/status?deviceId=' + encodeURIComponent(bindingId), {
method: 'GET'
});
const status = await readJsonResponse(response);
return status && status.screenSlug ? String(status.screenSlug).trim() : null;
}
const [rows] = await pool.query(
`SELECT s.slug
FROM d_onboarding_devices d
JOIN d_screens s ON s.id = d.screen_id
WHERE d.device_id = ?`,
[bindingId]
);
return rows[0] && rows[0].slug ? String(rows[0].slug).trim() : null;
}
async function isClientAuthorizedForScreen(req, requestedSlug) {
const clientId = getRequestClientId(req);
if (!clientId) {
return false;
}
const boundSlug = await getBoundScreenSlug({ query: { clientId: clientId } });
return boundSlug === String(requestedSlug || '').trim();
}
function isAuthorizedScreenMove(req, requestedSlug) {
const queryToken = String(req.query && req.query.moveToken || '').trim();
const cookieHeader = String(req.headers && req.headers.cookie || '');
const cookieToken = cookieHeader.split(';').map(function (part) {
const separator = part.indexOf('=');
return separator === -1 ? null : [part.slice(0, separator).trim(), part.slice(separator + 1).trim()];
}).filter(Boolean).find(function (entry) { return entry[0] === 'pulse-screen-move'; });
const token = queryToken || (cookieToken ? decodeURIComponent(cookieToken[1]) : '');
if (!token) {
return false;
}
const payload = verifyPageAuthToken(token);
return Boolean(payload
&& String(payload.scope || '').trim() === 'screen-move'
&& String(payload.playerId || '').trim() === String(playerDeviceId || '').trim()
&& String(payload.screenSlug || '').trim() === String(requestedSlug || '').trim());
}
app.post('/api/screen-move-authorize', express.json(), function (req, res) {
const token = String(req.body && req.body.moveToken || '').trim();
const payload = verifyPageAuthToken(token);
if (!payload
|| String(payload.scope || '').trim() !== 'screen-move'
|| String(payload.playerId || '').trim() !== String(playerDeviceId || '').trim()) {
return res.status(401).json({ error: 'Invalid screen move authorization.' });
}
res.setHeader('Set-Cookie', `pulse-screen-move=${encodeURIComponent(token)}; Max-Age=60; Path=/; HttpOnly; SameSite=Lax`);
return res.json({ ok: true });
});
function requirePageAuth(allowedScopes) { function requirePageAuth(allowedScopes) {
return function (req, res, next) { return function (req, res, next) {
if (!sharedSecret) { if (!sharedSecret) {
@@ -145,6 +241,32 @@ function registerPlayerRoutes(app, options) {
return resolvedFilePath; return resolvedFilePath;
} }
function getSnapshotFilePath(slug) {
const normalizedSlug = String(slug || '').trim();
return snapshotDir && normalizedSlug ? path.join(snapshotDir, `${normalizedSlug}.json`) : null;
}
async function readPlaylistSnapshot(slug) {
const filePath = getSnapshotFilePath(slug);
if (!filePath) {
return null;
}
try {
return JSON.parse(await fs.promises.readFile(filePath, 'utf8'));
} catch (_error) {
return null;
}
}
async function writePlaylistSnapshot(slug, payload) {
const filePath = getSnapshotFilePath(slug);
if (!filePath || !payload) {
return;
}
await fs.promises.mkdir(path.dirname(filePath), { recursive: true });
await fs.promises.writeFile(filePath, JSON.stringify(payload, null, 2), 'utf8');
}
app.use('/assets', express.static(assetDir)); app.use('/assets', express.static(assetDir));
app.use('/assets/adminlte/bootstrap-icons', express.static(path.join(__dirname, '..', 'web', 'public', 'adminlte', 'bootstrap-icons'))); app.use('/assets/adminlte/bootstrap-icons', express.static(path.join(__dirname, '..', 'web', 'public', 'adminlte', 'bootstrap-icons')));
app.use('/media', express.static(mediaDir)); app.use('/media', express.static(mediaDir));
@@ -296,8 +418,8 @@ function registerPlayerRoutes(app, options) {
} }
}); });
app.get('/screen/:slug', function (req, res) { app.get('/screen/:slug', async function (req, res, next) {
if (onPlayerPublicBaseUrl) { if (onPlayerPublicBaseUrl && !bridgeBaseUrl) {
try { try {
onPlayerPublicBaseUrl(getPlayerPublicBaseUrl(req, null)); onPlayerPublicBaseUrl(getPlayerPublicBaseUrl(req, null));
} catch (_error) { } catch (_error) {
@@ -313,34 +435,31 @@ function registerPlayerRoutes(app, options) {
headers: pageAuthToken ? { 'x-pulse-page-auth': pageAuthToken } : {} headers: pageAuthToken ? { 'x-pulse-page-auth': pageAuthToken } : {}
}).then(async function (response) { }).then(async function (response) {
if (!response || response.status >= 400) { if (!response || response.status >= 400) {
const snapshot = await readPlaylistSnapshot(req.params.slug);
res.set('X-Player-Offline', '1'); res.set('X-Player-Offline', '1');
return res.send(common.renderPlayerPage(req.params.slug, null)); return res.send(common.renderPlayerPage(req.params.slug, snapshot));
} }
const data = await readJsonResponse(response); const data = await readJsonResponse(response);
if (!data) { if (!data) {
const snapshot = await readPlaylistSnapshot(req.params.slug);
res.set('X-Player-Offline', '1'); res.set('X-Player-Offline', '1');
return res.send(common.renderPlayerPage(req.params.slug, null)); return res.send(common.renderPlayerPage(req.params.slug, snapshot));
} }
res.send(common.renderPlayerPage(req.params.slug, data)); await writePlaylistSnapshot(req.params.slug, data);
}).catch(function (error) { res.send(common.renderPlayerPage(req.params.slug, null));
}).catch(async function (error) {
if (!isBridgeFetchError(error)) { if (!isBridgeFetchError(error)) {
console.error(error); console.error(error);
} }
const snapshot = await readPlaylistSnapshot(req.params.slug);
res.set('X-Player-Offline', '1'); res.set('X-Player-Offline', '1');
res.send(common.renderPlayerPage(req.params.slug, null)); res.send(common.renderPlayerPage(req.params.slug, snapshot));
}); });
return; return;
} }
const { bindPlayerToScreen } = require('./onboarding');
if (playerDeviceId) {
void bindPlayerToScreen(pool, playerDeviceId, req.params.slug)
.catch(function (error) {
console.error(error);
});
}
playerPlaylistService.buildScreenPlaylist(req.params.slug).then(function (data) { playerPlaylistService.buildScreenPlaylist(req.params.slug).then(function (data) {
res.send(common.renderPlayerPage(req.params.slug, data)); res.send(common.renderPlayerPage(req.params.slug, null));
}).catch(function (error) { }).catch(function (error) {
console.error(error); console.error(error);
res.set('X-Player-Offline', '1'); res.set('X-Player-Offline', '1');
@@ -348,69 +467,23 @@ function registerPlayerRoutes(app, options) {
}); });
}); });
app.get('/api/internal/slide-thumbnails/:id/preview', requireRequestAuth, async function (req, res, next) {
try {
if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/internal/slide-thumbnails/' + encodeURIComponent(req.params.id) + '/preview', {
method: 'GET'
});
if (!response) {
return res.status(502).send('Thin client unavailable');
}
res.status(response.status);
res.set('Cache-Control', response.headers.get('cache-control') || 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.type(response.headers.get('content-type') || 'text/html; charset=utf-8');
return res.send(await response.text());
}
const slide = await common.fetchSlideById(pool, Number(req.params.id));
if (!slide) {
return res.status(404).send('Slide not found');
}
const data = buildThumbnailPreviewData(slide);
if (typeof common.fetchRssFeedsData === 'function' && typeof common.fetchRssFeedItemsByFeedId === 'function') {
const rssData = await common.fetchRssFeedsData(pool);
data.rssFeeds = await Promise.all((rssData.rssFeeds || []).map(async function (feed) {
const items = await common.fetchRssFeedItemsByFeedId(pool, feed.id);
return Object.assign({}, feed, {
items: items.map(function (item) {
return typeof common.normalizeRssFeedItem === 'function' ? common.normalizeRssFeedItem(item) : item;
})
});
}));
}
if (typeof common.fetchApiSourcesData === 'function') {
const apiData = await common.fetchApiSourcesData(pool);
data.apiSources = (apiData.apiSources || []).map(function (source) {
return Object.assign({}, source, {
responseJson: typeof common.parseJsonSafe === 'function' ? common.parseJsonSafe(source.last_response_json) : null
});
});
}
if (typeof common.fetchTimetablesData === 'function') {
const timetableData = await common.fetchTimetablesData(pool);
data.timetableGroups = Array.isArray(timetableData && timetableData.timetableGroups) ? timetableData.timetableGroups : [];
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.send(common.renderPlayerPage('slide-thumbnail-preview-' + slide.id, data));
} catch (error) {
next(error);
}
});
app.get('/api/screens/:slug/playlist', requirePageAuth(['player']), async function (req, res, next) { app.get('/api/screens/:slug/playlist', requirePageAuth(['player']), async function (req, res, next) {
try { try {
if (playerDeviceId && !(await isClientAuthorizedForScreen(req, req.params.slug))) {
return res.status(403).json({ error: 'This browser tab is not authorized for this screen.' });
}
if (bridgeBaseUrl) { if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/playlist', { const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/playlist', {
method: 'GET' method: 'GET'
}); });
if (!response) { if (!response) {
return res.status(502).json({ error: 'Thin client unavailable.' }); const snapshot = await readPlaylistSnapshot(req.params.slug);
if (!snapshot) {
return res.status(502).json({ error: 'Thin client unavailable.' });
}
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
res.set('ETag', '"' + String(snapshot.revision || '') + '"');
return res.json(snapshot);
} }
res.status(response.status); res.status(response.status);
const etag = response.headers.get('etag'); const etag = response.headers.get('etag');
@@ -425,7 +498,12 @@ function registerPlayerRoutes(app, options) {
return res.end(); return res.end();
} }
res.type(response.headers.get('content-type') || 'application/json'); res.type(response.headers.get('content-type') || 'application/json');
return res.send(await response.text()); const responseText = await response.text();
try {
await writePlaylistSnapshot(req.params.slug, JSON.parse(responseText));
} catch (_error) {
}
return res.send(responseText);
} }
res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate'); res.set('Cache-Control', 'no-store, no-cache, must-revalidate, proxy-revalidate');
@@ -448,6 +526,9 @@ function registerPlayerRoutes(app, options) {
app.get('/api/screens/:slug/announcement', requirePageAuth(['player']), async function (req, res, next) { app.get('/api/screens/:slug/announcement', requirePageAuth(['player']), async function (req, res, next) {
try { try {
if (playerDeviceId && !(await isClientAuthorizedForScreen(req, req.params.slug))) {
return res.status(403).json({ error: 'This browser tab is not authorized for this screen.' });
}
if (bridgeBaseUrl) { if (bridgeBaseUrl) {
const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/announcement', { const response = await fetchBridge(req, '/api/screens/' + encodeURIComponent(req.params.slug) + '/announcement', {
method: 'GET' method: 'GET'
+151 -6
View File
@@ -2,7 +2,7 @@
const crypto = require('crypto'); const crypto = require('crypto');
const { WebSocketServer, WebSocket } = require('ws'); const { WebSocketServer, WebSocket } = require('ws');
const { isClientNameAvailable } = require('#src/data/client-name-check'); const { findAvailableClientName, isClientNameAvailable } = require('#src/data/client-name-check');
const { verifyPageAuthToken, verifyRequestAuth } = require('#src/request-auth'); const { verifyPageAuthToken, verifyRequestAuth } = require('#src/request-auth');
const PAGE_AUTH_COOKIE_NAME = 'pulse_page_auth'; const PAGE_AUTH_COOKIE_NAME = 'pulse_page_auth';
@@ -22,6 +22,8 @@ function normalizePlayerPublicBaseUrl(pageUrl) {
function createPlayerRuntime(options) { function createPlayerRuntime(options) {
const pool = options && options.pool ? options.pool : null; const pool = options && options.pool ? options.pool : null;
const notifySnapshot = typeof options.notifySnapshot === 'function' ? options.notifySnapshot : null; const notifySnapshot = typeof options.notifySnapshot === 'function' ? options.notifySnapshot : null;
const persistClientName = typeof options.persistClientName === 'function' ? options.persistClientName : null;
const touchClientLastSeen = typeof options.touchClientLastSeen === 'function' ? options.touchClientLastSeen : null;
const normalizeDeviceId = typeof options.normalizeDeviceId === 'function' const normalizeDeviceId = typeof options.normalizeDeviceId === 'function'
? options.normalizeDeviceId ? options.normalizeDeviceId
: function (value) { : function (value) {
@@ -30,7 +32,26 @@ function createPlayerRuntime(options) {
const connectionsBySlug = new Map(); const connectionsBySlug = new Map();
const dashboardListenersBySlug = new Map(); const dashboardListenersBySlug = new Map();
const announcementListenersBySlug = new Map(); const announcementListenersBySlug = new Map();
const pendingCommandAcks = new Map();
const wss = new WebSocketServer({ noServer: true }); const wss = new WebSocketServer({ noServer: true });
const staleConnectionMs = Number(options && options.staleConnectionMs) > 0
? Number(options.staleConnectionMs)
: 3 * 60 * 1000;
function hasActiveClientId(clientId, currentConnection) {
const normalizedClientId = String(clientId || '').trim();
if (!normalizedClientId) {
return false;
}
for (const connections of connectionsBySlug.values()) {
for (const connection of connections.values()) {
if (connection !== currentConnection && String(connection.clientId || '').trim() === normalizedClientId) {
return true;
}
}
}
return false;
}
function normalizeClientIp(value) { function normalizeClientIp(value) {
const ip = String(value || '').trim(); const ip = String(value || '').trim();
@@ -165,6 +186,57 @@ function createPlayerRuntime(options) {
} }
} }
function removeStaleConnections() {
const cutoff = Date.now() - staleConnectionMs;
for (const [slug, bucket] of connectionsBySlug.entries()) {
for (const [connectionId, connection] of bucket.entries()) {
if (connection.lastSeenAt && connection.lastSeenAt.getTime() > cutoff) {
continue;
}
removeConnection(slug, connectionId);
try {
connection.socket.close(1000, 'Connection heartbeat expired.');
} catch (_error) {
}
broadcastConnectionSnapshot(slug);
}
}
}
const staleConnectionSweep = setInterval(removeStaleConnections, Math.min(staleConnectionMs, 60 * 1000));
if (typeof staleConnectionSweep.unref === 'function') {
staleConnectionSweep.unref();
}
function checkWebsocketHealth() {
for (const [slug, bucket] of connectionsBySlug.entries()) {
for (const [connectionId, connection] of bucket.entries()) {
if (!connection.isAlive) {
removeConnection(slug, connectionId);
try {
connection.socket.terminate();
} catch (_error) {
}
broadcastConnectionSnapshot(slug);
continue;
}
connection.isAlive = false;
try {
connection.socket.ping();
} catch (_error) {
removeConnection(slug, connectionId);
broadcastConnectionSnapshot(slug);
}
}
}
}
const websocketHealthCheck = setInterval(checkWebsocketHealth, 30 * 1000);
if (typeof websocketHealthCheck.unref === 'function') {
websocketHealthCheck.unref();
}
function getDashboardListenerBucket(slug) { function getDashboardListenerBucket(slug) {
const key = String(slug || '').trim(); const key = String(slug || '').trim();
if (!key) { if (!key) {
@@ -355,7 +427,10 @@ function createPlayerRuntime(options) {
return 0; return 0;
} }
const target = bucket.get(String(connectionId || '').trim()); const normalizedConnectionId = String(connectionId || '').trim();
const target = bucket.get(normalizedConnectionId) || Array.from(bucket.values()).find(function (connection) {
return String(connection && connection.clientId || '').trim() === normalizedConnectionId;
});
if (!target || target.socket.readyState !== WebSocket.OPEN) { if (!target || target.socket.readyState !== WebSocket.OPEN) {
return 0; return 0;
} }
@@ -367,8 +442,28 @@ function createPlayerRuntime(options) {
payload.targetConnectionId = target.id; payload.targetConnectionId = target.id;
payload.sentAt = new Date().toISOString(); payload.sentAt = new Date().toISOString();
const requestId = String(payload.requestId || '').trim();
if (!requestId) {
target.socket.send(JSON.stringify(payload));
return 1;
}
const acknowledgement = new Promise(function (resolve) {
const timeout = setTimeout(function () {
pendingCommandAcks.delete(requestId);
resolve(0);
}, 5000);
pendingCommandAcks.set(requestId, {
connection: target,
resolve: function (acknowledged) {
clearTimeout(timeout);
pendingCommandAcks.delete(requestId);
resolve(acknowledged ? 1 : 0);
}
});
});
target.socket.send(JSON.stringify(payload)); target.socket.send(JSON.stringify(payload));
return 1; return await acknowledgement;
} }
async function broadcastCommand(slug, commandOrPayload) { async function broadcastCommand(slug, commandOrPayload) {
@@ -512,6 +607,7 @@ function createPlayerRuntime(options) {
connectedAt: new Date(), connectedAt: new Date(),
lastSeenAt: new Date() lastSeenAt: new Date()
}; };
connection.isAlive = true;
const bucket = getConnectionBucket(slug); const bucket = getConnectionBucket(slug);
if (!bucket) { if (!bucket) {
@@ -521,7 +617,11 @@ function createPlayerRuntime(options) {
bucket.set(connectionId, connection); bucket.set(connectionId, connection);
socket.on('message', function (rawMessage) { socket.on('pong', function () {
connection.isAlive = true;
});
socket.on('message', async function (rawMessage) {
connection.lastSeenAt = new Date(); connection.lastSeenAt = new Date();
let payload = null; let payload = null;
try { try {
@@ -531,15 +631,48 @@ function createPlayerRuntime(options) {
} }
if (!payload || payload.type !== 'state') { if (!payload || payload.type !== 'state') {
if (payload && payload.type === 'command-ack') {
const requestId = String(payload.requestId || '').trim();
const pendingAck = pendingCommandAcks.get(requestId);
if (pendingAck && pendingAck.connection === connection) {
pendingAck.resolve(payload.ok !== false);
}
}
return; return;
} }
connection.clientId = payload.clientId ? String(payload.clientId).trim() : connection.clientId; const nextClientId = payload.clientId ? String(payload.clientId).trim() : connection.clientId;
if (nextClientId && hasActiveClientId(nextClientId, connection)) {
socket.send(JSON.stringify({ type: 'client-id-conflict' }));
socket.close(4009, 'Client ID is already in use.');
return;
}
connection.clientId = nextClientId;
connection.clientName = payload.clientName ? String(payload.clientName).trim() : connection.clientName; connection.clientName = payload.clientName ? String(payload.clientName).trim() : connection.clientName;
connection.deviceId = payload.deviceId ? normalizeDeviceId(payload.deviceId) || connection.deviceId : connection.deviceId; connection.deviceId = payload.deviceId ? normalizeDeviceId(payload.deviceId) || connection.deviceId : connection.deviceId;
if (!connection.clientName && connection.clientId) { if (!connection.clientName && connection.clientId) {
connection.clientName = connection.clientId; connection.clientName = connection.clientId;
} }
if (connection.clientName) {
const connectionIdentity = connection.deviceId || connection.clientId;
const selectedClientName = await findAvailableClientName(pool, connection.clientName, connectionIdentity, snapshotAllConnections());
if (selectedClientName && selectedClientName !== connection.clientName) {
connection.clientName = selectedClientName;
if (persistClientName) {
await persistClientName(connection.deviceId, selectedClientName);
}
if (socket.readyState === WebSocket.OPEN) {
socket.send(JSON.stringify({ type: 'client-name-updated', clientName: selectedClientName }));
}
}
}
if (touchClientLastSeen) {
try {
await touchClientLastSeen(connection.clientId);
} catch (_error) {
// A heartbeat failure must not interrupt playback or websocket state.
}
}
connection.userAgent = payload.userAgent ? String(payload.userAgent).trim() : connection.userAgent; connection.userAgent = payload.userAgent ? String(payload.userAgent).trim() : connection.userAgent;
connection.viewport = payload.viewport && typeof payload.viewport === 'object' ? payload.viewport : connection.viewport; connection.viewport = payload.viewport && typeof payload.viewport === 'object' ? payload.viewport : connection.viewport;
connection.page = payload.page ? String(payload.page).trim() : connection.page; connection.page = payload.page ? String(payload.page).trim() : connection.page;
@@ -560,12 +693,24 @@ function createPlayerRuntime(options) {
broadcastConnectionSnapshot(slug); broadcastConnectionSnapshot(slug);
}); });
socket.on('close', function () { socket.on('close', function (code, reason) {
pendingCommandAcks.forEach(function (pendingAck, requestId) {
if (pendingAck.connection === connection) {
pendingAck.resolve(false);
pendingCommandAcks.delete(requestId);
}
});
removeConnection(slug, connectionId); removeConnection(slug, connectionId);
broadcastConnectionSnapshot(slug); broadcastConnectionSnapshot(slug);
}); });
socket.on('error', function () { socket.on('error', function () {
pendingCommandAcks.forEach(function (pendingAck, requestId) {
if (pendingAck.connection === connection) {
pendingAck.resolve(false);
pendingCommandAcks.delete(requestId);
}
});
removeConnection(slug, connectionId); removeConnection(slug, connectionId);
broadcastConnectionSnapshot(slug); broadcastConnectionSnapshot(slug);
}); });
-30
View File
@@ -1,30 +0,0 @@
// Thumbnail preview data and bootstrap script helpers for slide thumbnails.
function buildThumbnailPreviewData(slide) {
return {
thumbnailPreview: true,
screen: {
id: slide.id,
name: slide.title,
slug: 'slide-thumbnail-preview-' + slide.id,
playlist_id: null
},
playlist: {
fade_between_slides: false
},
slides: [slide],
rssFeeds: [],
apiSources: [],
timetableGroups: [],
revision: String(slide.modified_at || slide.id || Date.now())
};
}
function createThumbnailPreviewBootstrapScript(initialData) {
return initialData && initialData.thumbnailPreview ? '<script>window.__pulseThumbnailPreview = true;</script>' : '';
}
module.exports = {
buildThumbnailPreviewData: buildThumbnailPreviewData,
createThumbnailPreviewBootstrapScript: createThumbnailPreviewBootstrapScript
};
+42 -2
View File
@@ -22,6 +22,14 @@ const PERMISSION_SECTIONS = [
{ key: 'read', name: 'Read', description: 'View connected player clients and live status.' }, { key: 'read', name: 'Read', description: 'View connected player clients and live status.' },
{ key: 'allow', name: 'Allow', description: 'Use the connected client command buttons.' } { key: 'allow', name: 'Allow', description: 'Use the connected client command buttons.' }
] ]
},
{
key: 'pairing',
order: 30,
name: 'Player pairing',
permissions: [
{ key: 'allow', name: 'Allow', description: 'Pair players with screen groups.' }
]
} }
] ]
}, },
@@ -109,6 +117,7 @@ const PERMISSION_SECTIONS = [
{ key: 'read', name: 'Read', description: 'View configured RSS feeds.' }, { key: 'read', name: 'Read', description: 'View configured RSS feeds.' },
{ key: 'create', name: 'Create', description: 'Create new RSS feeds.' }, { key: 'create', name: 'Create', description: 'Create new RSS feeds.' },
{ key: 'update', name: 'Update', description: 'Update RSS feeds.' }, { key: 'update', name: 'Update', description: 'Update RSS feeds.' },
{ key: 'allow', name: 'Allow', description: 'Manually refresh RSS feeds.' },
{ key: 'delete', name: 'Delete', description: 'Delete RSS feeds.' } { key: 'delete', name: 'Delete', description: 'Delete RSS feeds.' }
] ]
}, },
@@ -120,6 +129,7 @@ const PERMISSION_SECTIONS = [
{ key: 'read', name: 'Read', description: 'View configured API sources.' }, { key: 'read', name: 'Read', description: 'View configured API sources.' },
{ key: 'create', name: 'Create', description: 'Create new API sources.' }, { key: 'create', name: 'Create', description: 'Create new API sources.' },
{ key: 'update', name: 'Update', description: 'Update API sources.' }, { key: 'update', name: 'Update', description: 'Update API sources.' },
{ key: 'allow', name: 'Allow', description: 'Manually refresh API sources.' },
{ key: 'delete', name: 'Delete', description: 'Delete API sources.' } { key: 'delete', name: 'Delete', description: 'Delete API sources.' }
] ]
}, },
@@ -133,6 +143,18 @@ const PERMISSION_SECTIONS = [
{ key: 'update', name: 'Update', description: 'Update timetable groups and entries.' }, { key: 'update', name: 'Update', description: 'Update timetable groups and entries.' },
{ key: 'delete', name: 'Delete', description: 'Delete timetable groups.' } { key: 'delete', name: 'Delete', description: 'Delete timetable groups.' }
] ]
},
{
key: 'weather',
order: 40,
name: 'Weather locations',
permissions: [
{ key: 'read', name: 'Read', description: 'View configured weather locations.' },
{ key: 'create', name: 'Create', description: 'Create new weather locations.' },
{ key: 'update', name: 'Update', description: 'Update weather locations.' },
{ key: 'allow', name: 'Allow', description: 'Manually refresh weather locations.' },
{ key: 'delete', name: 'Delete', description: 'Delete weather locations.' }
]
} }
] ]
}, },
@@ -140,6 +162,24 @@ const PERMISSION_SECTIONS = [
sectionName: 'Settings', sectionName: 'Settings',
order: 40, order: 40,
permissions: [ permissions: [
{
key: 'system-settings',
order: 70,
name: 'System settings',
permissions: [
{ key: 'read', name: 'Read', description: 'View global application settings.' },
{ key: 'update', name: 'Update', description: 'Update global application settings.' }
]
},
{
key: 'audit-log',
order: 60,
name: 'Audit log',
permissions: [
{ key: 'read', name: 'Read', description: 'View security and session audit events.' },
{ key: 'allow', name: 'Allow', description: 'Download filtered audit events.' }
]
},
{ {
key: 'users', key: 'users',
order: 10, order: 10,
@@ -218,8 +258,8 @@ const PERMISSIONS = PERMISSION_SECTIONS.flatMap(function (section, sectionIndex)
}); });
const DEFAULT_ROLE = { const DEFAULT_ROLE = {
key: 'administrators', key: 'super-admin',
name: 'Administrators', name: 'Super Admin',
description: 'Full access to the admin interface.' description: 'Full access to the admin interface.'
}; };
+31 -5
View File
@@ -9,6 +9,7 @@ const common = require('./common');
const { verifyPassword, createSessionToken, hashSessionToken, hashPassword, validatePasswordStrength } = require('#src/auth'); const { verifyPassword, createSessionToken, hashSessionToken, hashPassword, validatePasswordStrength } = require('#src/auth');
const pages = require('#src/web/pages'); const pages = require('#src/web/pages');
const registerMiddleware = require('#src/web/middleware'); const registerMiddleware = require('#src/web/middleware');
const registerNotFoundHandler = require('#src/web/middleware/not-found');
const { createBackgroundTaskQueue } = require('#src/web/lib/background-tasks/queue'); const { createBackgroundTaskQueue } = require('#src/web/lib/background-tasks/queue');
const { initializeBackgroundTasks } = require('#src/web/lib/background-tasks'); const { initializeBackgroundTasks } = require('#src/web/lib/background-tasks');
const { createDataSourceTaskService } = require('#src/web/lib/background-tasks/tasks-scheduled/data-source-refresh'); const { createDataSourceTaskService } = require('#src/web/lib/background-tasks/tasks-scheduled/data-source-refresh');
@@ -23,6 +24,8 @@ const { rbacData } = require('#src/web/lib/auth');
const { createPlayerActionService } = require('#src/web/lib/player-actions'); const { createPlayerActionService } = require('#src/web/lib/player-actions');
const { isClientNameAvailable, withClientNameReservation } = require('#src/data/client-name-check'); const { isClientNameAvailable, withClientNameReservation } = require('#src/data/client-name-check');
const { createSessionService } = require('#src/web/lib/auth'); const { createSessionService } = require('#src/web/lib/auth');
const { fetchAppSettings } = require('#src/data/app-settings');
const { recordRequestAuditEvent } = require('#src/data/audit-log');
const { hasAnyPermission } = require('#src/rbac'); const { hasAnyPermission } = require('#src/rbac');
const { ensureFontLibrary } = require('#src/web/lib/media/font-library'); const { ensureFontLibrary } = require('#src/web/lib/media/font-library');
const { const {
@@ -34,7 +37,6 @@ const {
getAuditUserId, getAuditUserId,
getCanvasSignature, getCanvasSignature,
fetchPlaylistCanvasId, fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature,
fetchScreensByPlaylistId, fetchScreensByPlaylistId,
fetchScreensBySlideId, fetchScreensBySlideId,
fetchScreensByTemplateId, fetchScreensByTemplateId,
@@ -65,7 +67,12 @@ async function start() {
playerInternalBaseUrl: webConfig.playerInternalUrl, playerInternalBaseUrl: webConfig.playerInternalUrl,
bridgeInternalBaseUrl: webConfig.bridgeInternalUrl bridgeInternalBaseUrl: webConfig.bridgeInternalUrl
}); });
const notifyPlayerScreens = createNotifyPlayerScreens(playerActionService.forwardPlayerCommand); const notifyPlayerScreens = createNotifyPlayerScreens(
playerActionService.forwardPlayerCommand,
playerActionService.getScreenConnections,
playerActionService.forwardPlayerCommandToBaseUrl,
playerActionService.resolvePlayerBaseUrlForPublicUrl
);
// Centralized dashboard/player bootstrap. // Centralized dashboard/player bootstrap.
const webBootstrap = createWebBootstrap({ const webBootstrap = createWebBootstrap({
@@ -92,6 +99,14 @@ async function start() {
const sessionService = createSessionService({ const sessionService = createSessionService({
sessionCookieName: webConfig.sessionCookieName, sessionCookieName: webConfig.sessionCookieName,
sessionMaxAgeMs: webConfig.sessionMaxAgeMs, sessionMaxAgeMs: webConfig.sessionMaxAgeMs,
getConfiguredSessionMaxAgeMs: async function () {
const settings = await fetchAppSettings(pool);
return Number(settings['security.session_lifetime_days']) * 24 * 60 * 60 * 1000;
},
getConfiguredMaxActiveSessions: async function () {
const settings = await fetchAppSettings(pool);
return Number(settings['security.max_active_sessions']);
},
hashSessionToken: hashSessionToken, hashSessionToken: hashSessionToken,
createSessionToken: createSessionToken createSessionToken: createSessionToken
}); });
@@ -99,6 +114,7 @@ async function start() {
const createUserSession = sessionService.createUserSession; const createUserSession = sessionService.createUserSession;
const clearSessionCookie = sessionService.clearSessionCookie; const clearSessionCookie = sessionService.clearSessionCookie;
const setSessionCookie = sessionService.setSessionCookie; const setSessionCookie = sessionService.setSessionCookie;
const getSessionMaxAgeMs = sessionService.getSessionMaxAgeMs;
const setAuthMessageCookie = sessionService.setAuthMessageCookie; const setAuthMessageCookie = sessionService.setAuthMessageCookie;
const consumeAuthMessageCookie = sessionService.consumeAuthMessageCookie; const consumeAuthMessageCookie = sessionService.consumeAuthMessageCookie;
const loadCurrentUser = sessionService.loadCurrentUser; const loadCurrentUser = sessionService.loadCurrentUser;
@@ -119,9 +135,11 @@ async function start() {
common: common, common: common,
pages: pages, pages: pages,
upload: upload, upload: upload,
mediaDir: webConfig.mediaDir,
uploadDir: webConfig.uploadsDir, uploadDir: webConfig.uploadsDir,
createUserSession: createUserSession, createUserSession: createUserSession,
setSessionCookie: setSessionCookie, setSessionCookie: setSessionCookie,
getSessionMaxAgeMs: getSessionMaxAgeMs,
clearSessionCookie: clearSessionCookie, clearSessionCookie: clearSessionCookie,
setAuthMessageCookie: setAuthMessageCookie, setAuthMessageCookie: setAuthMessageCookie,
consumeAuthMessageCookie: consumeAuthMessageCookie, consumeAuthMessageCookie: consumeAuthMessageCookie,
@@ -131,6 +149,7 @@ async function start() {
sessionCookieName: webConfig.sessionCookieName, sessionCookieName: webConfig.sessionCookieName,
formatDashboardDate: formatDashboardDate, formatDashboardDate: formatDashboardDate,
getAuditUserId: getAuditUserId, getAuditUserId: getAuditUserId,
recordRequestAuditEvent: recordRequestAuditEvent,
hashPassword: hashPassword, hashPassword: hashPassword,
validatePasswordStrength: validatePasswordStrength, validatePasswordStrength: validatePasswordStrength,
readArrayField: readArrayField, readArrayField: readArrayField,
@@ -140,7 +159,6 @@ async function start() {
fetchScreensBySlideId: fetchScreensBySlideId, fetchScreensBySlideId: fetchScreensBySlideId,
fetchScreensByTemplateId: fetchScreensByTemplateId, fetchScreensByTemplateId: fetchScreensByTemplateId,
fetchPlaylistCanvasId: fetchPlaylistCanvasId, fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasSignature,
getCanvasSignature: getCanvasSignature, getCanvasSignature: getCanvasSignature,
normalizeScheduleMode: normalizeScheduleMode, normalizeScheduleMode: normalizeScheduleMode,
parseDateTimeLocal: parseDateTimeLocal, parseDateTimeLocal: parseDateTimeLocal,
@@ -150,14 +168,15 @@ async function start() {
broadcastDashboardState: broadcastDashboardState, broadcastDashboardState: broadcastDashboardState,
dataSourceTasks: dataSourceTasks, dataSourceTasks: dataSourceTasks,
playerActionService: playerActionService, playerActionService: playerActionService,
playerInternalBaseUrl: webConfig.playerInternalUrl,
isClientNameAvailable: isClientNameAvailable, isClientNameAvailable: isClientNameAvailable,
findAvailableClientName: common.findAvailableClientName,
withClientNameReservation: withClientNameReservation, withClientNameReservation: withClientNameReservation,
requirePermission: function (permissionKey, options) { requirePermission: function (permissionKey, options) {
return createRequirePermission(permissionKey, Object.assign({ setAuthMessageCookie: setAuthMessageCookie }, options)); return createRequirePermission(permissionKey, Object.assign({ setAuthMessageCookie: setAuthMessageCookie }, options));
}, },
hasAnyPermission: hasAnyPermission, hasAnyPermission: hasAnyPermission,
backgroundTaskQueue: backgroundTaskQueue, backgroundTaskQueue: backgroundTaskQueue,
mediaDir: webConfig.mediaDir,
uploadSyncService: webBootstrap.uploadSyncService, uploadSyncService: webBootstrap.uploadSyncService,
collectUploadReferencesFromSlide: collectUploadReferencesFromSlide, collectUploadReferencesFromSlide: collectUploadReferencesFromSlide,
collectUploadReferencesFromTemplate: collectUploadReferencesFromTemplate, collectUploadReferencesFromTemplate: collectUploadReferencesFromTemplate,
@@ -167,9 +186,15 @@ async function start() {
buildDashboardState: webBootstrap.buildDashboardState buildDashboardState: webBootstrap.buildDashboardState
}); });
registerNotFoundHandler(app);
app.use(function (error, req, res, _next) { app.use(function (error, req, res, _next) {
console.error(error);
const statusCode = Number(error && (error.statusCode || error.status)) || 500; const statusCode = Number(error && (error.statusCode || error.status)) || 500;
if (statusCode >= 500) {
console.error(error);
} else if (statusCode >= 400 && statusCode !== 404) {
console.warn(error && error.message ? error.message : 'Request failed.', { statusCode: statusCode });
}
const isXhr = String(req.get && req.get('X-Requested-With') || '').toLowerCase() === 'xmlhttprequest'; const isXhr = String(req.get && req.get('X-Requested-With') || '').toLowerCase() === 'xmlhttprequest';
const wantsHtml = !isXhr && !String(req.originalUrl || '').startsWith('/api/') && (!req.accepts || req.accepts('html')); const wantsHtml = !isXhr && !String(req.originalUrl || '').startsWith('/api/') && (!req.accepts || req.accepts('html'));
@@ -207,6 +232,7 @@ async function start() {
mediaDir: webConfig.mediaDir, mediaDir: webConfig.mediaDir,
backgroundTaskQueue: backgroundTaskQueue, backgroundTaskQueue: backgroundTaskQueue,
webBootstrap: webBootstrap, webBootstrap: webBootstrap,
notifyPlayerScreens: notifyPlayerScreens,
loadCurrentUser: loadCurrentUser, loadCurrentUser: loadCurrentUser,
initializeBackgroundTasks: initializeBackgroundTasks, initializeBackgroundTasks: initializeBackgroundTasks,
captureSlideThumbnail: captureSlideThumbnail, captureSlideThumbnail: captureSlideThumbnail,
+2
View File
@@ -179,6 +179,8 @@ function registerPartials(Handlebars, viewsRoot) {
Handlebars.registerPartial('signage/templates/animation-advanced-modal', fs.readFileSync(path.join(viewsRoot, 'signage', 'templates', 'animation-advanced-modal.hbs'), 'utf8')); Handlebars.registerPartial('signage/templates/animation-advanced-modal', fs.readFileSync(path.join(viewsRoot, 'signage', 'templates', 'animation-advanced-modal.hbs'), 'utf8'));
Handlebars.registerPartial('data-sources/api-sources/form', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'api-sources', 'form.hbs'), 'utf8')); Handlebars.registerPartial('data-sources/api-sources/form', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'api-sources', 'form.hbs'), 'utf8'));
Handlebars.registerPartial('data-sources/rss-feeds/form', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'rss-feeds', 'form.hbs'), 'utf8')); Handlebars.registerPartial('data-sources/rss-feeds/form', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'rss-feeds', 'form.hbs'), 'utf8'));
Handlebars.registerPartial('data-sources/weather/preview', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'weather', 'preview.hbs'), 'utf8'));
Handlebars.registerPartial('data-sources/weather/forecast-preview', fs.readFileSync(path.join(viewsRoot, 'data-sources', 'weather', 'forecast-preview.hbs'), 'utf8'));
} }
// One entry point keeps Handlebars bootstrap centralized. // One entry point keeps Handlebars bootstrap centralized.
+40 -6
View File
@@ -113,7 +113,7 @@ async function fetchRolesForUser(pool, userId) {
async function fetchUsersWithRoles(pool) { async function fetchUsersWithRoles(pool) {
const [rows] = await pool.query( const [rows] = await pool.query(
`SELECT u.id, u.name, u.username, u.created_at, u.modified_at, `SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names, COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u FROM a_users u
@@ -142,7 +142,7 @@ async function fetchUsersWithRolesPage(pool, page, pageSize, searchTerm, sortKey
const whereSql = hasExcludedUserId ? 'WHERE u.id <> ?' : ''; const whereSql = hasExcludedUserId ? 'WHERE u.id <> ?' : '';
const queryArgs = hasExcludedUserId ? [excludedUserId] : []; const queryArgs = hasExcludedUserId ? [excludedUserId] : [];
const paged = await fetchPagedRows(pool, { const paged = await fetchPagedRows(pool, {
selectSql: `SELECT u.id, u.name, u.username, u.created_at, u.modified_at, selectSql: `SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names, COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u FROM a_users u
@@ -189,7 +189,7 @@ async function fetchUsersWithRolesPage(pool, page, pageSize, searchTerm, sortKey
async function fetchUserWithRoles(pool, userId) { async function fetchUserWithRoles(pool, userId) {
const [rows] = await pool.query( const [rows] = await pool.query(
`SELECT u.id, u.name, u.username, u.created_at, u.modified_at, `SELECT u.id, u.name, u.username, u.account_locked, u.created_at, u.modified_at,
COALESCE(role_data.role_names, '') AS role_names, COALESCE(role_data.role_names, '') AS role_names,
COALESCE(role_data.role_ids_csv, '') AS role_ids_csv COALESCE(role_data.role_ids_csv, '') AS role_ids_csv
FROM a_users u FROM a_users u
@@ -216,6 +216,17 @@ async function fetchUserWithRoles(pool, userId) {
}); });
} }
async function fetchActiveUserSessions(pool, userId) {
const [rows] = await pool.query(
`SELECT id, ip_address, user_agent, created_at, last_used_at, expires_at
FROM a_sessions
WHERE user_id = ? AND expires_at > NOW()
ORDER BY last_used_at DESC`,
[userId]
);
return rows || [];
}
async function syncUserRoles(pool, userId, roleIds) { async function syncUserRoles(pool, userId, roleIds) {
const uniqueRoleIds = Array.from(new Set((Array.isArray(roleIds) ? roleIds : []).map(function (roleId) { const uniqueRoleIds = Array.from(new Set((Array.isArray(roleIds) ? roleIds : []).map(function (roleId) {
return Number(roleId); return Number(roleId);
@@ -225,7 +236,14 @@ async function syncUserRoles(pool, userId, roleIds) {
await pool.query('DELETE FROM a_user_roles WHERE user_id = ?', [userId]); await pool.query('DELETE FROM a_user_roles WHERE user_id = ?', [userId]);
for (const roleId of uniqueRoleIds) { for (const roleId of uniqueRoleIds) {
await pool.query('INSERT IGNORE INTO a_user_roles (user_id, role_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [userId, roleId, null, null]); await pool.query(
`INSERT INTO a_user_roles (user_id, role_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_user_roles WHERE user_id = ? AND role_id = ?
)`,
[userId, roleId, null, null, userId, roleId]
);
} }
} }
@@ -238,7 +256,14 @@ async function syncRoleUsers(pool, roleId, userIds) {
await pool.query('DELETE FROM a_user_roles WHERE role_id = ?', [roleId]); await pool.query('DELETE FROM a_user_roles WHERE role_id = ?', [roleId]);
for (const userId of uniqueUserIds) { for (const userId of uniqueUserIds) {
await pool.query('INSERT IGNORE INTO a_user_roles (user_id, role_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [userId, roleId, null, null]); await pool.query(
`INSERT INTO a_user_roles (user_id, role_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_user_roles WHERE user_id = ? AND role_id = ?
)`,
[userId, roleId, null, null, userId, roleId]
);
} }
} }
@@ -257,7 +282,15 @@ async function syncRolePermissions(pool, roleId, permissionKeys) {
await pool.query('DELETE FROM a_role_permissions WHERE role_id = ?', [roleId]); await pool.query('DELETE FROM a_role_permissions WHERE role_id = ?', [roleId]);
for (const permissionRow of permissionRows) { for (const permissionRow of permissionRows) {
await pool.query('INSERT IGNORE INTO a_role_permissions (role_id, permission_id, created_by, modified_by) VALUES (?, ?, ?, ?)', [roleId, Number(permissionRow.id), null, null]); const permissionId = Number(permissionRow.id);
await pool.query(
`INSERT INTO a_role_permissions (role_id, permission_id, created_by, modified_by)
SELECT ?, ?, ?, ?
WHERE NOT EXISTS (
SELECT 1 FROM a_role_permissions WHERE role_id = ? AND permission_id = ?
)`,
[roleId, permissionId, null, null, roleId, permissionId]
);
} }
} }
@@ -273,6 +306,7 @@ module.exports = {
fetchUsersWithRoles, fetchUsersWithRoles,
fetchUsersWithRolesPage, fetchUsersWithRolesPage,
fetchUserWithRoles, fetchUserWithRoles,
fetchActiveUserSessions,
syncUserRoles, syncUserRoles,
syncRoleUsers, syncRoleUsers,
syncRolePermissions syncRolePermissions
+43 -6
View File
@@ -34,6 +34,8 @@ function normalizeReturnToPath(value, baseUrl) {
function createSessionService(options) { function createSessionService(options) {
const sessionCookieName = String(options && options.sessionCookieName || '').trim(); const sessionCookieName = String(options && options.sessionCookieName || '').trim();
const sessionMaxAgeMs = Number(options && options.sessionMaxAgeMs); const sessionMaxAgeMs = Number(options && options.sessionMaxAgeMs);
const getConfiguredSessionMaxAgeMs = options && options.getConfiguredSessionMaxAgeMs;
const getConfiguredMaxActiveSessions = options && options.getConfiguredMaxActiveSessions;
const hashSessionToken = options && options.hashSessionToken; const hashSessionToken = options && options.hashSessionToken;
const createSessionToken = options && options.createSessionToken; const createSessionToken = options && options.createSessionToken;
const authMessageCookieName = 'pulse_auth_message'; const authMessageCookieName = 'pulse_auth_message';
@@ -88,7 +90,20 @@ function createSessionService(options) {
} }
function setSessionCookie(res, token) { function setSessionCookie(res, token) {
appendCookieHeader(res, serializeCookie(sessionCookieName, token, { maxAge: sessionMaxAgeMs })); const hasRequestedMaxAge = arguments.length > 2;
const requestedMaxAgeMs = hasRequestedMaxAge ? Number(arguments[2]) : sessionMaxAgeMs;
const cookieOptions = hasRequestedMaxAge && arguments[2] === null
? {}
: { maxAge: Number.isFinite(requestedMaxAgeMs) && requestedMaxAgeMs > 0 ? requestedMaxAgeMs : sessionMaxAgeMs };
appendCookieHeader(res, serializeCookie(sessionCookieName, token, cookieOptions));
}
async function getSessionMaxAgeMs() {
const configuredValue = typeof getConfiguredSessionMaxAgeMs === 'function'
? await getConfiguredSessionMaxAgeMs()
: sessionMaxAgeMs;
const normalizedValue = Number(configuredValue);
return Number.isFinite(normalizedValue) && normalizedValue > 0 ? normalizedValue : sessionMaxAgeMs;
} }
function setAuthMessageCookie(res, message) { function setAuthMessageCookie(res, message) {
@@ -113,7 +128,7 @@ function createSessionService(options) {
const tokenHash = hashSessionToken(token); const tokenHash = hashSessionToken(token);
const [rows] = await pool.query( const [rows] = await pool.query(
`SELECT s.user_id, u.id, u.name, u.username `SELECT s.user_id, u.id, u.name, u.username, u.must_change_password
FROM a_sessions s FROM a_sessions s
JOIN a_users u ON u.id = s.user_id JOIN a_users u ON u.id = s.user_id
WHERE s.session_hash = ? WHERE s.session_hash = ?
@@ -146,6 +161,7 @@ function createSessionService(options) {
await pool.query('UPDATE a_sessions SET last_used_at = CURRENT_TIMESTAMP, modified_by = ? WHERE session_hash = ?', [rows[0].user_id, tokenHash]); await pool.query('UPDATE a_sessions SET last_used_at = CURRENT_TIMESTAMP, modified_by = ? WHERE session_hash = ?', [rows[0].user_id, tokenHash]);
return Object.assign({}, rows[0], { return Object.assign({}, rows[0], {
mustChangePassword: Boolean(rows[0].must_change_password),
roleKeys: roleRows.map(function (row) { roleKeys: roleRows.map(function (row) {
return String(row.role_key || '').trim(); return String(row.role_key || '').trim();
}).filter(Boolean), }).filter(Boolean),
@@ -155,14 +171,34 @@ function createSessionService(options) {
}); });
} }
async function createUserSession(pool, userId) { async function createUserSession(pool, userId, configuredMaxAgeMs, metadata) {
const token = createSessionToken(); const token = createSessionToken();
const tokenHash = hashSessionToken(token); const tokenHash = hashSessionToken(token);
const expiresAt = new Date(Date.now() + sessionMaxAgeMs); const maxAgeMs = Number.isFinite(Number(configuredMaxAgeMs)) && Number(configuredMaxAgeMs) > 0
? Number(configuredMaxAgeMs)
: await getSessionMaxAgeMs();
const expiresAt = new Date(Date.now() + maxAgeMs);
const sessionMetadata = metadata && typeof metadata === 'object' ? metadata : {};
await pool.query( await pool.query(
'INSERT INTO a_sessions (session_hash, user_id, expires_at, created_by, modified_by) VALUES (?, ?, ?, ?, ?)', 'INSERT INTO a_sessions (session_hash, user_id, ip_address, user_agent, expires_at, created_by, modified_by) VALUES (?, ?, ?, ?, ?, ?, ?)',
[tokenHash, userId, expiresAt, userId, userId] [tokenHash, userId, String(sessionMetadata.ipAddress || '').slice(0, 255) || null, String(sessionMetadata.userAgent || '').slice(0, 512) || null, expiresAt, userId, userId]
); );
if (typeof getConfiguredMaxActiveSessions === 'function') {
const maxActiveSessions = Number(await getConfiguredMaxActiveSessions());
if (Number.isInteger(maxActiveSessions) && maxActiveSessions > 0) {
const [sessionRows] = await pool.query(
'SELECT id, session_hash FROM a_sessions WHERE user_id = ? AND expires_at > NOW() ORDER BY last_used_at ASC, created_at ASC, id ASC',
[userId]
);
const sessionsToRemove = (sessionRows || []).filter(function (session) {
return session.session_hash !== tokenHash;
}).slice(0, Math.max(0, sessionRows.length - maxActiveSessions));
for (const session of sessionsToRemove) {
await pool.query('DELETE FROM a_sessions WHERE id = ? AND user_id = ?', [session.id, userId]);
}
}
}
return token; return token;
} }
@@ -184,6 +220,7 @@ function createSessionService(options) {
consumeAuthMessageCookie: consumeAuthMessageCookie, consumeAuthMessageCookie: consumeAuthMessageCookie,
loadCurrentUser: loadCurrentUser, loadCurrentUser: loadCurrentUser,
createUserSession: createUserSession, createUserSession: createUserSession,
getSessionMaxAgeMs: getSessionMaxAgeMs,
requireAuth: requireAuth, requireAuth: requireAuth,
getRequestOrigin: getRequestOrigin getRequestOrigin: getRequestOrigin
}; };
+3
View File
@@ -19,6 +19,9 @@ function normalizeIntervalMs(value, unit) {
if (normalizedUnit === 'seconds') { if (normalizedUnit === 'seconds') {
return numericValue * 1000; return numericValue * 1000;
} }
if (normalizedUnit === 'hours') {
return numericValue * 60 * 60 * 1000;
}
return numericValue * 60 * 1000; return numericValue * 60 * 1000;
} }
@@ -1,4 +1,4 @@
const { refreshApiSource, refreshRssFeed } = require('../../data-source-refresh'); const { refreshApiSource, refreshRssFeed, refreshWeatherLocation } = require('../../data-source-refresh');
const TASK = { const TASK = {
taskType: 'data-source-refresh' taskType: 'data-source-refresh'
@@ -24,7 +24,8 @@ function registerDataSourceRefreshTask(options) {
if (!apiSource) { if (!apiSource) {
throw new Error('API source not found.'); throw new Error('API source not found.');
} }
return refreshApiSource(pool, common, apiSource, Number(payload.actorId) || null); if (apiSource.enabled === 0 || apiSource.enabled === false) return { skipped: true, reason: 'disabled' };
return refreshApiSource(pool, common, apiSource, Number(payload.actorId) || null, options.notifyPlayerScreens);
} }
if (sourceType === 'rss-feed') { if (sourceType === 'rss-feed') {
@@ -32,7 +33,17 @@ function registerDataSourceRefreshTask(options) {
if (!rssFeed) { if (!rssFeed) {
throw new Error('RSS feed not found.'); throw new Error('RSS feed not found.');
} }
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, Number(payload.actorId) || null); if (rssFeed.enabled === 0 || rssFeed.enabled === false) return { skipped: true, reason: 'disabled' };
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, Number(payload.actorId) || null, options.notifyPlayerScreens);
}
if (sourceType === 'weather-location') {
const location = await common.fetchWeatherLocationById(pool, sourceId);
if (!location) {
throw new Error('Weather location not found.');
}
if (location.enabled === 0 || location.enabled === false) return { skipped: true, reason: 'disabled' };
return refreshWeatherLocation(pool, common, location, Number(payload.actorId) || null, options.notifyPlayerScreens);
} }
throw new Error('Unsupported data source refresh task.'); throw new Error('Unsupported data source refresh task.');
@@ -0,0 +1,34 @@
const { fetchAppSettings } = require('#src/data/app-settings');
const TASK = {
key: 'audit-log-sweep',
title: 'Audit log cleanup',
category: 'cleanup',
intervalMs: 24 * 60 * 60 * 1000
};
function registerAuditLogSweepTask(options) {
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const pool = options && options.pool;
if (!backgroundTaskQueue || !pool) {
throw new Error('registerAuditLogSweepTask requires audit cleanup dependencies.');
}
backgroundTaskQueue.registerRecurringTask({
key: TASK.key,
title: TASK.title,
category: TASK.category,
intervalMs: TASK.intervalMs,
metadata: {},
run: async function () {
const settings = await fetchAppSettings(pool);
const retentionDays = Number(settings['audit.retention_days']);
if (!Number.isInteger(retentionDays) || retentionDays <= 0) {
return;
}
const cutoff = new Date(Date.now() - retentionDays * 24 * 60 * 60 * 1000);
await pool.query('DELETE FROM o_audit_events WHERE occurred_at < ?', [cutoff]);
}
});
}
module.exports = { registerAuditLogSweepTask };
@@ -9,7 +9,7 @@ const TASK = {
}; };
const { normalizeIntervalMs } = require('../queue'); const { normalizeIntervalMs } = require('../queue');
const { refreshApiSource, refreshRssFeed } = require('../../data-source-refresh'); const { refreshApiSource, refreshRssFeed, refreshWeatherLocation } = require('../../data-source-refresh');
function registerRecurringDataSourceRefreshes(options) { function registerRecurringDataSourceRefreshes(options) {
const pool = options && options.pool; const pool = options && options.pool;
@@ -23,6 +23,7 @@ function registerRecurringDataSourceRefreshes(options) {
return (async function () { return (async function () {
const apiSourcesData = await common.fetchApiSourcesData(pool); const apiSourcesData = await common.fetchApiSourcesData(pool);
(apiSourcesData.apiSources || []).forEach(function (apiSource) { (apiSourcesData.apiSources || []).forEach(function (apiSource) {
if (apiSource.enabled === 0 || apiSource.enabled === false) return;
backgroundTaskQueue.registerRecurringTask({ backgroundTaskQueue.registerRecurringTask({
key: 'api-source-refresh:' + Number(apiSource.id), key: 'api-source-refresh:' + Number(apiSource.id),
title: 'API source refresh', title: 'API source refresh',
@@ -34,13 +35,14 @@ function registerRecurringDataSourceRefreshes(options) {
sourceName: apiSource.name sourceName: apiSource.name
}, },
run: function () { run: function () {
return refreshApiSource(pool, common, apiSource, null); return refreshApiSource(pool, common, apiSource, null, options.notifyPlayerScreens);
} }
}); });
}); });
const rssFeedsData = await common.fetchRssFeedsData(pool); const rssFeedsData = await common.fetchRssFeedsData(pool);
(rssFeedsData.rssFeeds || []).forEach(function (rssFeed) { (rssFeedsData.rssFeeds || []).forEach(function (rssFeed) {
if (rssFeed.enabled === 0 || rssFeed.enabled === false) return;
backgroundTaskQueue.registerRecurringTask({ backgroundTaskQueue.registerRecurringTask({
key: 'rss-feed-refresh:' + Number(rssFeed.id), key: 'rss-feed-refresh:' + Number(rssFeed.id),
title: 'RSS feed refresh', title: 'RSS feed refresh',
@@ -52,10 +54,23 @@ function registerRecurringDataSourceRefreshes(options) {
sourceName: rssFeed.name sourceName: rssFeed.name
}, },
run: function () { run: function () {
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null); return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null, options.notifyPlayerScreens);
} }
}); });
}); });
const weatherLocationsData = await common.fetchWeatherLocationsData(pool);
(weatherLocationsData.weatherLocations || []).forEach(function (location) {
if (location.enabled === 0 || location.enabled === false) return;
backgroundTaskQueue.registerRecurringTask({
key: 'weather-location-refresh:' + Number(location.id),
title: 'Weather location refresh',
category: TASK.category,
intervalMs: normalizeIntervalMs(location.update_interval_value, location.update_interval_unit),
metadata: { sourceType: 'weather-location', sourceId: Number(location.id), sourceName: location.name },
run: function () { return refreshWeatherLocation(pool, common, location.id, null, options.notifyPlayerScreens); }
});
});
})(); })();
} }
@@ -73,7 +88,7 @@ function createDataSourceTaskService(options) {
} }
function buildRecurringTitle(sourceType) { function buildRecurringTitle(sourceType) {
return sourceType === 'rss-feed' ? 'RSS feed refresh' : 'API source refresh'; return sourceType === 'rss-feed' ? 'RSS feed refresh' : sourceType === 'weather-location' ? 'Weather location refresh' : 'API source refresh';
} }
function registerRecurringRefresh(sourceType, id, name, intervalValue, intervalUnit, run) { function registerRecurringRefresh(sourceType, id, name, intervalValue, intervalUnit, run) {
@@ -115,11 +130,15 @@ function createDataSourceTaskService(options) {
} }
async function refreshApiSourceInBackground(apiSourceId, actorId) { async function refreshApiSourceInBackground(apiSourceId, actorId) {
return refreshApiSource(pool, common, apiSourceId, actorId); return refreshApiSource(pool, common, apiSourceId, actorId, options.notifyPlayerScreens);
} }
async function refreshRssFeedInBackground(rssFeedId, feedUrl, itemLimit, actorId) { async function refreshRssFeedInBackground(rssFeedId, feedUrl, itemLimit, actorId) {
return refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId); return refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId, options.notifyPlayerScreens);
}
async function refreshWeatherLocationInBackground(locationId, actorId) {
return refreshWeatherLocation(pool, common, locationId, actorId, options.notifyPlayerScreens);
} }
return { return {
@@ -129,7 +148,8 @@ function createDataSourceTaskService(options) {
removeRecurringRefresh: removeRecurringRefresh, removeRecurringRefresh: removeRecurringRefresh,
getTaskStatusById: getTaskStatusById, getTaskStatusById: getTaskStatusById,
refreshApiSourceInBackground: refreshApiSourceInBackground, refreshApiSourceInBackground: refreshApiSourceInBackground,
refreshRssFeedInBackground: refreshRssFeedInBackground refreshRssFeedInBackground: refreshRssFeedInBackground,
refreshWeatherLocationInBackground: refreshWeatherLocationInBackground
}; };
} }
@@ -0,0 +1,31 @@
const TASK = {
key: 'expired-session-sweep',
title: 'Expired session cleanup',
category: 'cleanup',
trigger: 'scheduled recurring task, hourly',
purpose: 'remove expired authentication sessions and their metadata.',
taskType: 'recurring-run',
intervalMs: 60 * 60 * 1000
};
function registerExpiredSessionSweepTask(options) {
const backgroundTaskQueue = options && options.backgroundTaskQueue;
const pool = options && options.pool;
if (!backgroundTaskQueue || !pool) {
throw new Error('registerExpiredSessionSweepTask requires the session cleanup dependencies.');
}
backgroundTaskQueue.registerRecurringTask({
key: TASK.key,
title: TASK.title,
category: TASK.category,
intervalMs: TASK.intervalMs,
metadata: {},
run: async function () {
await pool.query('DELETE FROM a_sessions WHERE expires_at <= NOW()');
}
});
}
module.exports = { registerExpiredSessionSweepTask };
@@ -3,7 +3,7 @@ const TASK = {
title: 'Onboarding device prune', title: 'Onboarding device prune',
category: 'cleanup', category: 'cleanup',
trigger: 'scheduled recurring task, hourly', trigger: 'scheduled recurring task, hourly',
purpose: 'remove stale onboarding device bindings that have been idle for more than one minute.', purpose: 'remove unbound onboarding devices that have been idle for more than one minute.',
taskType: 'recurring-run', taskType: 'recurring-run',
intervalMs: 60 * 60 * 1000 intervalMs: 60 * 60 * 1000
}; };
@@ -1,4 +1,5 @@
const { refreshApiSource, refreshRssFeed } = require('../../data-source-refresh'); const { refreshApiSource, refreshRssFeed, refreshWeatherLocation } = require('../../data-source-refresh');
const { normalizeIntervalMs } = require('../queue');
const TASK = { const TASK = {
key: 'startup-data-source-refresh', key: 'startup-data-source-refresh',
@@ -26,20 +27,49 @@ function scheduleStartupDataSourceRefreshes(options) {
}; };
} }
function shouldRefreshAtStartup(source) {
const lastPulledAt = source && source.last_pulled_at ? new Date(source.last_pulled_at).getTime() : NaN;
if (!Number.isFinite(lastPulledAt)) {
return true;
}
const intervalMs = normalizeIntervalMs(source.update_interval_value, source.update_interval_unit);
return Date.now() - lastPulledAt >= intervalMs;
}
return (async function () { return (async function () {
const apiSourcesData = await common.fetchApiSourcesData(pool); const apiSourcesData = await common.fetchApiSourcesData(pool);
const rssFeedsData = await common.fetchRssFeedsData(pool); const rssFeedsData = await common.fetchRssFeedsData(pool);
const weatherLocationsData = await common.fetchWeatherLocationsData(pool);
const startupSources = []; const startupSources = [];
(apiSourcesData.apiSources || []).forEach(function (apiSource) { (apiSourcesData.apiSources || []).forEach(function (apiSource) {
if (apiSource.enabled === 0 || apiSource.enabled === false) return;
if (!shouldRefreshAtStartup(apiSource)) {
return;
}
startupSources.push(buildStartupSource('api-source', apiSource.id, apiSource.name, function () { startupSources.push(buildStartupSource('api-source', apiSource.id, apiSource.name, function () {
return refreshApiSource(pool, common, apiSource, null); return refreshApiSource(pool, common, apiSource, null, options.notifyPlayerScreens);
})); }));
}); });
(rssFeedsData.rssFeeds || []).forEach(function (rssFeed) { (rssFeedsData.rssFeeds || []).forEach(function (rssFeed) {
if (rssFeed.enabled === 0 || rssFeed.enabled === false) return;
if (!shouldRefreshAtStartup(rssFeed)) {
return;
}
startupSources.push(buildStartupSource('rss-feed', rssFeed.id, rssFeed.name, function () { startupSources.push(buildStartupSource('rss-feed', rssFeed.id, rssFeed.name, function () {
return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null); return refreshRssFeed(pool, common, rssFeed.id, rssFeed.feed_url, rssFeed.item_limit, null, options.notifyPlayerScreens);
}));
});
(weatherLocationsData.weatherLocations || []).forEach(function (location) {
if (location.enabled === 0 || location.enabled === false) return;
if (!shouldRefreshAtStartup(location)) {
return;
}
startupSources.push(buildStartupSource('weather-location', location.id, location.name, function () {
return refreshWeatherLocation(pool, common, location, null, options.notifyPlayerScreens);
})); }));
}); });
@@ -50,7 +80,7 @@ function scheduleStartupDataSourceRefreshes(options) {
setTimeout(function () { setTimeout(function () {
backgroundTaskQueue.enqueueTask({ backgroundTaskQueue.enqueueTask({
key: TASK.key + ':' + source.type + ':' + source.id + ':' + Date.now(), key: TASK.key + ':' + source.type + ':' + source.id + ':' + Date.now(),
title: source.type === 'rss-feed' ? 'RSS feed refresh' : 'API source refresh', title: source.type === 'rss-feed' ? 'RSS feed refresh' : source.type === 'weather-location' ? 'Weather location refresh' : 'API source refresh',
category: TASK.category, category: TASK.category,
taskType: 'data-source-refresh', taskType: 'data-source-refresh',
metadata: { metadata: {
+2 -3
View File
@@ -5,12 +5,11 @@ function createWebConfig() {
const uploadsDir = path.join(mediaDir, 'uploads'); const uploadsDir = path.join(mediaDir, 'uploads');
const thumbnailsDir = path.join(mediaDir, 'thumbnails'); const thumbnailsDir = path.join(mediaDir, 'thumbnails');
const assetDir = path.join(__dirname, '..', 'public'); const assetDir = path.join(__dirname, '..', 'public');
const playerInternalUrl = (process.env.PLAYER_INTERNAL_URL || process.env.PLAYER_BASE_URL || 'http://player:8081').replace(/\/$/, ''); const playerInternalUrl = (process.env.PLAYER_INTERNAL_URL || 'http://player:8081').replace(/\/$/, '');
const bridgeInternalUrl = (process.env.BRIDGE_INTERNAL_URL || 'http://player-bridge:8090').replace(/\/$/, ''); const bridgeInternalUrl = (process.env.BRIDGE_INTERNAL_URL || 'http://player-bridge:8090').replace(/\/$/, '');
const webInternalUrl = (process.env.WEB_INTERNAL_URL || `http://127.0.0.1:${Number(process.env.WEB_PORT || 8080)}`).replace(/\/$/, ''); const webInternalUrl = (process.env.WEB_INTERNAL_URL || `http://127.0.0.1:${Number(process.env.WEB_PORT || 8080)}`).replace(/\/$/, '');
const sessionCookieName = 'digital_signage_session'; const sessionCookieName = 'digital_signage_session';
const sessionMaxAgeDays = Number(process.env.SESSION_MAX_AGE_DAYS || 14); const sessionMaxAgeMs = 14 * 24 * 60 * 60 * 1000;
const sessionMaxAgeMs = (Number.isFinite(sessionMaxAgeDays) && sessionMaxAgeDays > 0 ? sessionMaxAgeDays : 14) * 24 * 60 * 60 * 1000;
const port = Number(process.env.WEB_PORT || 8080); const port = Number(process.env.WEB_PORT || 8080);
const dataSourceStartupRefreshStaggerMs = Math.max(100, Number(process.env.DATA_SOURCE_STARTUP_REFRESH_STAGGER_MS || 250)); const dataSourceStartupRefreshStaggerMs = Math.max(100, Number(process.env.DATA_SOURCE_STARTUP_REFRESH_STAGGER_MS || 250));
+11 -1
View File
@@ -25,7 +25,17 @@ function enrichScreensWithConnections(screens, connectionsBySlug, onboardingName
function buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, playerIdentifierByBaseUrl, formatDashboardDate) { function buildClientRows(screens, connectionsBySlug, onboardingNameBySlug, onboardingNameByDeviceId, playerIdentifierByBaseUrl, formatDashboardDate) {
return (screens || []).flatMap(function (screen) { return (screens || []).flatMap(function (screen) {
const connectionState = connectionsBySlug[screen.slug] || { count: 0, connections: [] }; const connectionState = connectionsBySlug[screen.slug] || { count: 0, connections: [] };
return (connectionState.connections || []).map(function (connection) { const seenClientKeys = new Set();
return (connectionState.connections || []).filter(function (connection) {
const deviceId = String(connection && connection.deviceId || '').trim();
const clientId = String(connection && connection.clientId || '').trim();
const key = deviceId && clientId ? `${deviceId}:${clientId}` : String(connection && connection.id || '').trim();
if (seenClientKeys.has(key)) {
return false;
}
seenClientKeys.add(key);
return true;
}).map(function (connection) {
const deviceId = String(connection.deviceId || '').trim(); const deviceId = String(connection.deviceId || '').trim();
const playerBaseUrl = normalizePlayerBaseUrl(connection.playerPublicBaseUrl); const playerBaseUrl = normalizePlayerBaseUrl(connection.playerPublicBaseUrl);
return Object.assign({}, connection, { return Object.assign({}, connection, {
+194 -3
View File
@@ -1,4 +1,132 @@
async function refreshApiSource(pool, common, apiSourceOrId, actorId) { // Refresh data sources and notify only the screens whose rendered data changed.
async function getAffectedScreenSlugs(connection, common, slideMatchKey, sourceId) {
const [slideRows] = await connection.query('SELECT id, content_json FROM c_slides WHERE content_json IS NOT NULL');
const slideIds = [];
const seenSlideIds = new Set();
slideRows.forEach(function (row) {
const content = typeof common.parseJsonSafe === 'function' ? common.parseJsonSafe(row.content_json) : null;
if (!content || typeof content !== 'object') {
return;
}
const stack = [content];
while (stack.length) {
const value = stack.pop();
if (!value || typeof value !== 'object') {
continue;
}
if (Array.isArray(value)) {
value.forEach(function (item) {
stack.push(item);
});
continue;
}
if (Object.prototype.hasOwnProperty.call(value, slideMatchKey) && Number(value[slideMatchKey]) === Number(sourceId)) {
const slideId = Number(row.id);
if (Number.isFinite(slideId) && slideId > 0 && !seenSlideIds.has(slideId)) {
seenSlideIds.add(slideId);
slideIds.push(slideId);
}
break;
}
Object.keys(value).forEach(function (key) {
stack.push(value[key]);
});
}
});
if (!slideIds.length) {
return [];
}
const [screenRows] = await connection.query(
`SELECT DISTINCT s.slug
FROM d_screens s
JOIN c_playlist_slides ps ON ps.playlist_id = s.playlist_id
WHERE ps.slide_id IN (?)
AND s.slug IS NOT NULL`,
[slideIds]
);
return screenRows.map(function (row) {
return String(row.slug || '').trim();
}).filter(Boolean);
}
async function notifyAffectedScreens(connection, common, notifyPlayerScreens, slideMatchKey, sourceId) {
if (typeof notifyPlayerScreens !== 'function') {
return;
}
const slugs = await getAffectedScreenSlugs(connection, common, slideMatchKey, sourceId);
if (!slugs.length) {
return;
}
await notifyPlayerScreens(slugs, 'refresh');
}
function normalizeSnapshotValue(value) {
return String(value || '').trim();
}
async function hasRssFeedChanged(connection, rssFeedId, items) {
const [rows] = await connection.query(
`SELECT item_json
FROM i_rss_feed_items
WHERE rss_feed_id = ?
ORDER BY position ASC, id ASC`,
[rssFeedId]
);
const currentSnapshots = (rows || []).map(function (row) {
return normalizeSnapshotValue(row && row.item_json);
});
const nextSnapshots = (Array.isArray(items) ? items : []).map(function (item) {
return normalizeSnapshotValue(JSON.stringify(item || {}));
});
if (currentSnapshots.length !== nextSnapshots.length) {
return true;
}
for (let index = 0; index < currentSnapshots.length; index += 1) {
if (currentSnapshots[index] !== nextSnapshots[index]) {
return true;
}
}
return false;
}
function hasApiSourceChanged(apiSource, responseDetails) {
return normalizeSnapshotValue(apiSource && apiSource.last_response_json) !== normalizeSnapshotValue(responseDetails && responseDetails.responseJson);
}
function isDifferentHour(previousPulledAt, currentPulledAt) {
const previous = new Date(previousPulledAt);
const current = new Date(currentPulledAt);
if (!Number.isFinite(previous.getTime())) {
return false;
}
return previous.getFullYear() !== current.getFullYear()
|| previous.getMonth() !== current.getMonth()
|| previous.getDate() !== current.getDate()
|| previous.getHours() !== current.getHours();
}
function hasWeatherLocationChanged(location, responseDetails, refreshedAt) {
return normalizeSnapshotValue(location && location.last_response_json) !== normalizeSnapshotValue(responseDetails && responseDetails.responseJson)
|| isDifferentHour(location && location.last_pulled_at, refreshedAt);
}
async function refreshApiSource(pool, common, apiSourceOrId, actorId, notifyPlayerScreens) {
const connection = await pool.getConnection(); const connection = await pool.getConnection();
try { try {
const apiSource = apiSourceOrId && typeof apiSourceOrId === 'object' const apiSource = apiSourceOrId && typeof apiSourceOrId === 'object'
@@ -25,6 +153,14 @@ async function refreshApiSource(pool, common, apiSourceOrId, actorId) {
[new Date(), pullError || null, responseDetails ? responseDetails.responseStatus : null, responseDetails ? responseDetails.responseContentType : null, responseDetails ? responseDetails.responseJson : null, actorId, apiSource.id] [new Date(), pullError || null, responseDetails ? responseDetails.responseStatus : null, responseDetails ? responseDetails.responseContentType : null, responseDetails ? responseDetails.responseJson : null, actorId, apiSource.id]
); );
await connection.commit(); await connection.commit();
if (!pullError && hasApiSourceChanged(apiSource, responseDetails)) {
try {
await notifyAffectedScreens(connection, common, notifyPlayerScreens, 'source_id', apiSource.id);
} catch (notifyError) {
console.warn('[data-source-refresh] Unable to notify players after API source refresh ' + apiSource.id + ':', notifyError);
}
}
} catch (error) { } catch (error) {
try { try {
await connection.rollback(); await connection.rollback();
@@ -37,7 +173,48 @@ async function refreshApiSource(pool, common, apiSourceOrId, actorId) {
} }
} }
async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId) { async function refreshWeatherLocation(pool, common, weatherLocationOrId, actorId, notifyPlayerScreens) {
const connection = await pool.getConnection();
try {
const location = weatherLocationOrId && typeof weatherLocationOrId === 'object'
? weatherLocationOrId
: await common.fetchWeatherLocationById(pool, Number(weatherLocationOrId));
if (!location) throw new Error('Weather location not found.');
let result = null;
let pullError = '';
try {
result = await common.fetchWeatherLocationForecast(pool, location);
} catch (error) {
pullError = String(error && error.message ? error.message : 'Unable to load weather forecast.');
}
const refreshedAt = new Date();
await connection.beginTransaction();
await connection.query(
'UPDATE i_weather_locations SET last_pulled_at = ?, last_pull_error = ?, last_response_json = COALESCE(?, last_response_json), modified_by = ? WHERE id = ?',
[refreshedAt, pullError || null, result ? result.responseJson : null, actorId, location.id]
);
await connection.commit();
if (pullError) {
console.error('[data-source-refresh] Weather location refresh completed with an error for location ' + location.id + ': ' + pullError);
} else if (hasWeatherLocationChanged(location, result, refreshedAt) && typeof notifyPlayerScreens === 'function') {
try {
await notifyAffectedScreens(connection, common, notifyPlayerScreens, 'weather_location_id', location.id);
} catch (notifyError) {
console.warn('[data-source-refresh] Unable to notify players after weather refresh ' + location.id + ':', notifyError);
}
}
} catch (error) {
try { await connection.rollback(); } catch (_rollbackError) { }
throw error;
} finally {
connection.release();
}
}
async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actorId, notifyPlayerScreens) {
const connection = await pool.getConnection(); const connection = await pool.getConnection();
try { try {
let updatedItems = []; let updatedItems = [];
@@ -50,11 +227,24 @@ async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actor
} }
await connection.beginTransaction(); await connection.beginTransaction();
const rssFeedChanged = await hasRssFeedChanged(connection, rssFeedId, updatedItems);
if (typeof common.replaceRssFeedItems === 'function') { if (typeof common.replaceRssFeedItems === 'function') {
await common.replaceRssFeedItems(connection, rssFeedId, updatedItems); await common.replaceRssFeedItems(connection, rssFeedId, updatedItems);
} }
await connection.query(
'UPDATE i_rss_feeds SET last_pulled_at = ? WHERE id = ?',
[new Date(), rssFeedId]
);
await connection.commit(); await connection.commit();
if (!pullError && rssFeedChanged) {
try {
await notifyAffectedScreens(connection, common, notifyPlayerScreens, 'feed_id', rssFeedId);
} catch (notifyError) {
console.warn('[data-source-refresh] Unable to notify players after RSS feed refresh ' + rssFeedId + ':', notifyError);
}
}
if (pullError) { if (pullError) {
console.error('[data-source-refresh] RSS feed refresh completed with an error for feed ' + rssFeedId + ': ' + pullError); console.error('[data-source-refresh] RSS feed refresh completed with an error for feed ' + rssFeedId + ': ' + pullError);
} }
@@ -72,5 +262,6 @@ async function refreshRssFeed(pool, common, rssFeedId, feedUrl, itemLimit, actor
module.exports = { module.exports = {
refreshApiSource: refreshApiSource, refreshApiSource: refreshApiSource,
refreshRssFeed: refreshRssFeed refreshRssFeed: refreshRssFeed,
refreshWeatherLocation: refreshWeatherLocation
}; };
-1
View File
@@ -198,7 +198,6 @@ module.exports = {
getAuditUserId: getAuditUserId, getAuditUserId: getAuditUserId,
getCanvasSignature: getCanvasSignature, getCanvasSignature: getCanvasSignature,
fetchPlaylistCanvasId: fetchPlaylistCanvasId, fetchPlaylistCanvasId: fetchPlaylistCanvasId,
fetchPlaylistCanvasSignature: fetchPlaylistCanvasId,
fetchScreensByPlaylistId: fetchScreensByPlaylistId, fetchScreensByPlaylistId: fetchScreensByPlaylistId,
fetchScreensBySlideId: fetchScreensBySlideId, fetchScreensBySlideId: fetchScreensBySlideId,
fetchScreensByTemplateId: fetchScreensByTemplateId, fetchScreensByTemplateId: fetchScreensByTemplateId,
+43 -6
View File
@@ -30,6 +30,43 @@ function normalizeText(value) {
return String(value || '').replace(/\s+/g, ' ').trim(); return String(value || '').replace(/\s+/g, ' ').trim();
} }
function quoteFontFamilyToken(token) {
const normalizedToken = normalizeText(token);
if (!normalizedToken) {
return '';
}
if (normalizedToken === 'inherit' || /^[a-zA-Z0-9_-]+$/.test(normalizedToken)) {
return normalizedToken;
}
return `'${normalizedToken.replace(/\\/g, '\\\\').replace(/'/g, "\\'")}'`;
}
function normalizeFontFamilyFormat(format) {
return String(format || '')
.split(',')
.map(quoteFontFamilyToken)
.filter(Boolean)
.join(',');
}
function normalizeFontFamilyFormatEntry(entry) {
const value = String(entry || '').trim();
if (!value) {
return '';
}
const separatorIndex = value.indexOf('=');
if (separatorIndex === -1) {
return `${value}=${normalizeFontFamilyFormat(value)}`;
}
const label = value.slice(0, separatorIndex).trim();
const format = value.slice(separatorIndex + 1).trim();
return `${label}=${normalizeFontFamilyFormat(format || label)}`;
}
function resolveMediaRoot(mediaRootOrUploadDir) { function resolveMediaRoot(mediaRootOrUploadDir) {
const resolved = path.resolve(String(mediaRootOrUploadDir || '').trim()); const resolved = path.resolve(String(mediaRootOrUploadDir || '').trim());
return path.basename(resolved) === 'uploads' ? path.dirname(resolved) : resolved; return path.basename(resolved) === 'uploads' ? path.dirname(resolved) : resolved;
@@ -119,22 +156,19 @@ function buildFontFaceRule(entry) {
function buildFontStylesheet(fonts) { function buildFontStylesheet(fonts) {
const rules = (Array.isArray(fonts) ? fonts : []) const rules = (Array.isArray(fonts) ? fonts : [])
.filter(function (font) {
return font && font.enabled !== false;
})
.map(buildFontFaceRule) .map(buildFontFaceRule)
.filter(Boolean); .filter(Boolean);
return rules.length ? `/* Managed fonts */\n\n${rules.join('\n\n')}\n` : '/* Managed fonts */\n'; return rules.length ? `/* Managed fonts */\n\n${rules.join('\n\n')}\n` : '/* Managed fonts */\n';
} }
function buildFontFamilyFormats(fonts) { function buildFontFamilyFormats(fonts) {
const formatEntries = Array.from(new Set(DEFAULT_FONT_FAMILY_FORMATS.concat((Array.isArray(fonts) ? fonts : []) const formatEntries = Array.from(new Set(DEFAULT_FONT_FAMILY_FORMATS.map(normalizeFontFamilyFormatEntry).concat((Array.isArray(fonts) ? fonts : [])
.filter(function (font) { .filter(function (font) {
return font && font.enabled !== false && normalizeText(font.family || font.name); return font && font.enabled !== false && normalizeText(font.family || font.name);
}) })
.map(function (font) { .map(function (font) {
const family = normalizeText(font.family || font.name); const family = normalizeText(font.family || font.name);
return `${family}=${family}`; return `${family}=${normalizeFontFamilyFormat(family)}`;
})))) }))))
.sort(function (left, right) { .sort(function (left, right) {
const leftLabel = String(left || '').split('=')[0]; const leftLabel = String(left || '').split('=')[0];
@@ -344,7 +378,7 @@ function collectFontLibrarySyncOperations(mediaRootOrUploadDir) {
} }
operations.push({ operations.push({
type: font.enabled === false ? 'delete' : 'put', type: 'put',
uploadPath: `/media/${FONT_LIBRARY_DIR_NAME}/${font.fileName}` uploadPath: `/media/${FONT_LIBRARY_DIR_NAME}/${font.fileName}`
}); });
}); });
@@ -363,7 +397,10 @@ module.exports = {
collectFontLibraryDirectoryUploadPaths: collectFontLibraryDirectoryUploadPaths, collectFontLibraryDirectoryUploadPaths: collectFontLibraryDirectoryUploadPaths,
collectFontLibrarySyncOperations: collectFontLibrarySyncOperations, collectFontLibrarySyncOperations: collectFontLibrarySyncOperations,
getFontStylesheetHref: getFontStylesheetHref, getFontStylesheetHref: getFontStylesheetHref,
buildFontStylesheet: buildFontStylesheet,
buildFontFamilyFormats: buildFontFamilyFormats, buildFontFamilyFormats: buildFontFamilyFormats,
normalizeFontFamilyFormat: normalizeFontFamilyFormat,
normalizeFontFamilyFormatEntry: normalizeFontFamilyFormatEntry,
isSupportedFontUpload: isSupportedFontUpload, isSupportedFontUpload: isSupportedFontUpload,
getFontLibraryDir: getFontLibraryDir, getFontLibraryDir: getFontLibraryDir,
getFontManifestPath: getFontManifestPath, getFontManifestPath: getFontManifestPath,
+49 -6
View File
@@ -30,6 +30,35 @@ function resolveAssetUrl(baseUrl, value) {
return normalizedBaseUrl + '/' + raw.replace(/^\/+/, ''); return normalizedBaseUrl + '/' + raw.replace(/^\/+/, '');
} }
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.url !== undefined) {
return normalizeRenderableValue(value.url);
}
if (value.href !== undefined) {
return normalizeRenderableValue(value.href);
}
if (value.src !== undefined) {
return normalizeRenderableValue(value.src);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function getThumbnailCanvasSize(slide) { function getThumbnailCanvasSize(slide) {
const template = slide && slide.template ? slide.template : null; const template = slide && slide.template ? slide.template : null;
return { return {
@@ -53,7 +82,16 @@ function buildThumbnailRegionStyle(region, canvasWidth, canvasHeight) {
} }
function hasVisibleContent(html) { function hasVisibleContent(html) {
return Boolean(String(html || '').replace(/<[^>]+>/g, '').trim()); var raw = String(html || '').trim();
if (!raw) {
return false;
}
if (/<img\b/i.test(raw)) {
return true;
}
return Boolean(raw.replace(/<[^>]+>/g, '').trim());
} }
function buildTextRegionMarkup(region, regionContent) { function buildTextRegionMarkup(region, regionContent) {
@@ -70,7 +108,7 @@ function buildTextRegionMarkup(region, regionContent) {
function buildRegionInnerHtml(region, regionContent, baseUrl) { function buildRegionInnerHtml(region, regionContent, baseUrl) {
const regionType = String(regionContent.type || region.region_type || 'text').trim().toLowerCase(); const regionType = String(regionContent.type || region.region_type || 'text').trim().toLowerCase();
const rawValue = regionContent && regionContent.value !== undefined ? regionContent.value : ''; const rawValue = normalizeRenderableValue(regionContent && regionContent.value !== undefined ? regionContent.value : '');
if (regionType === 'image') { if (regionType === 'image') {
const src = resolveAssetUrl(baseUrl, rawValue); const src = resolveAssetUrl(baseUrl, rawValue);
@@ -89,7 +127,7 @@ function buildRegionInnerHtml(region, regionContent, baseUrl) {
if (regionType === 'webpage') { if (regionType === 'webpage') {
const src = resolveAssetUrl(baseUrl, rawValue); const src = resolveAssetUrl(baseUrl, rawValue);
return src return src
? '<div class="slide-preview-region slide-preview-webpage-region" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(src) + '" title="' + escapeHtml(region.label || region.region_key || 'webpage') + '" loading="eager" referrerpolicy="no-referrer" scrolling="no"></iframe></div>' ? '<div class="slide-preview-region slide-preview-webpage-region" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(src) + '" title="' + escapeHtml(region.label || region.region_key || 'webpage') + '" loading="eager" referrerpolicy="no-referrer" scrolling="no" style="width:100%;height:100%;border:0;display:block;background:#fff;overflow:hidden;"></iframe></div>'
: ''; : '';
} }
@@ -104,9 +142,13 @@ function buildRegionInnerHtml(region, regionContent, baseUrl) {
if (regionType === 'html') { if (regionType === 'html') {
const html = String(rawValue || '').trim(); const html = String(rawValue || '').trim();
return html if (!html) {
? '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><iframe sandbox="" srcdoc="<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + escapeHtml(html) + '</body></html>" title="' + escapeHtml(region.label || region.region_key || 'html') + '" loading="eager" scrolling="no"></iframe></div>' return '';
: ''; }
if (/^<!doctype\b/i.test(html) || /^<html\b/i.test(html)) {
return '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><iframe sandbox="" allowtransparency="true" srcdoc="' + escapeHtml(html) + '" title="' + escapeHtml(region.label || region.region_key || 'html') + '" loading="eager" scrolling="no" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe></div>';
}
return '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><div class="slide-preview-html-content" style="width:100%;height:100%;overflow:hidden;background:transparent;">' + html + '</div></div>';
} }
if (regionType === 'rtmp') { if (regionType === 'rtmp') {
@@ -144,6 +186,7 @@ function buildThumbnailPreviewPayload(slide, options) {
canvasWidth: canvasSize.width, canvasWidth: canvasSize.width,
canvasHeight: canvasSize.height, canvasHeight: canvasSize.height,
backgroundColor: template && template.background_color ? String(template.background_color) : '#111111', backgroundColor: template && template.background_color ? String(template.background_color) : '#111111',
backgroundGradient: template && template.background_gradient ? String(template.background_gradient) : '',
backgroundImagePath: template && template.background_image_path ? String(template.background_image_path) : '', backgroundImagePath: template && template.background_image_path ? String(template.background_image_path) : '',
fontStylesheetHref: String(options && options.fontStylesheetHref || '').trim(), fontStylesheetHref: String(options && options.fontStylesheetHref || '').trim(),
html: buildThumbnailPreviewMarkup(slide, options && options.baseUrl) html: buildThumbnailPreviewMarkup(slide, options && options.baseUrl)
+249 -46
View File
@@ -2,6 +2,8 @@
const fs = require('fs'); const fs = require('fs');
const path = require('path'); const path = require('path');
const crypto = require('crypto');
const vm = require('vm');
const { const {
escapeHtml, escapeHtml,
mediaKind, mediaKind,
@@ -10,7 +12,14 @@ const {
sanitizeFontSize, sanitizeFontSize,
sanitizeTextColor sanitizeTextColor
} = require('#src/player/render-helpers'); } = require('#src/player/render-helpers');
const { createRequestAuthHeaders } = require('#src/request-auth'); const { createRequestAuthHeaders, createPageAuthToken } = require('#src/request-auth');
const { convertWeatherSnapshot } = require('#src/data/weather-units');
const placeholderUtils = (() => {
const sandbox = { window: {} };
vm.runInNewContext(fs.readFileSync(path.join(__dirname, '..', '..', 'public', 'js', 'shared', 'placeholder-utils.js'), 'utf8'), sandbox);
return sandbox.window.placeholderUtils || {};
})();
const SYSTEM_CHROMIUM_PATHS = [ const SYSTEM_CHROMIUM_PATHS = [
process.env.PUPPETEER_EXECUTABLE_PATH, process.env.PUPPETEER_EXECUTABLE_PATH,
@@ -52,6 +61,35 @@ function resolveAssetUrl(baseUrl, value) {
return normalizedBaseUrl + '/' + raw.replace(/^\/+/, ''); return normalizedBaseUrl + '/' + raw.replace(/^\/+/, '');
} }
function normalizeRenderableValue(value) {
if (value && typeof value === 'object') {
if (value.value !== undefined) {
return normalizeRenderableValue(value.value);
}
if (value.text !== undefined) {
return normalizeRenderableValue(value.text);
}
if (value.html !== undefined) {
return normalizeRenderableValue(value.html);
}
if (value.url !== undefined) {
return normalizeRenderableValue(value.url);
}
if (value.href !== undefined) {
return normalizeRenderableValue(value.href);
}
if (value.src !== undefined) {
return normalizeRenderableValue(value.src);
}
if (value.content !== undefined) {
return normalizeRenderableValue(value.content);
}
return '';
}
return String(value === undefined || value === null ? '' : value);
}
function getCanvasSize(slide) { function getCanvasSize(slide) {
const template = slide && slide.template ? slide.template : null; const template = slide && slide.template ? slide.template : null;
return { return {
@@ -83,14 +121,98 @@ function buildThumbnailRegionStyle(region, canvasWidth, canvasHeight) {
} }
function hasVisibleContent(html) { function hasVisibleContent(html) {
return Boolean(String(html || '').replace(/<[^>]+>/g, '').trim()); var raw = String(html || '').trim();
if (!raw) {
return false;
}
if (/<img\b/i.test(raw)) {
return true;
}
return Boolean(raw.replace(/<[^>]+>/g, '').trim());
} }
function buildTextRegionMarkup(region, regionContent) { function resolvePlaceholderPath(value, expression) {
const pathValue = String(expression || '').replace(/\.image\s*\([^)]*\)\s*$/i, '').trim();
return pathValue.split('.').reduce(function (current, segment) {
return current === undefined || current === null ? '' : current[segment];
}, value);
}
function getImagePlaceholderConfig(expression) {
const match = String(expression || '').match(/\.image\s*\(\s*([0-9]+)?\s*,?\s*([0-9]+)?\s*\)/i);
return {
width: match && match[1] ? Number(match[1]) : 0,
height: match && match[2] ? Number(match[2]) : 0
};
}
function normalizeWeatherExpression(expression) {
const value = String(expression || '').trim();
const currentAliases = { temp: 'current.temperature_2m', feels_like: 'current.apparent_temperature', humidity: 'current.relative_humidity_2m', wind: 'current.wind_speed_10m', precip: 'current.precipitation', uv_index: 'current.uv_index', cloud_cover: 'current.cloud_cover', icon: 'current.weather_code.icon' };
const globalAliases = { temp_unit: 'temperature_unit', wind_unit: 'wind_speed_unit', precip_unit: 'precipitation_unit' };
if (globalAliases[value]) return globalAliases[value];
const currentField = value.replace(/^current\./, '').match(/^([^.()]+)((?:\(.*\))|(?:\..*))?$/);
if (currentField && currentAliases[currentField[1]]) return currentAliases[currentField[1]] + (currentField[2] || '');
const indexed = value.match(/^(daily|hourly)\.(\d+)\.(.+)$/);
if (!indexed) return value;
const fieldMatch = indexed[3].match(/^([^.()]+)((?:\(.*\))|(?:\..*))?$/);
const field = fieldMatch ? fieldMatch[1] : indexed[3];
const aliases = indexed[1] === 'daily' ? { time: 'time', temp_max: 'temperature_2m_max', temp_min: 'temperature_2m_min', precip: 'precipitation_sum', wind: 'wind_speed_10m_max', uv_index: 'uv_index_max', cloud_cover: 'cloud_cover_mean', sunrise: 'sunrise', sunset: 'sunset', icon: 'weather_code' } : { time: 'time', temp: 'temperature_2m', precip: 'precipitation', wind: 'wind_speed_10m', uv_index: 'uv_index', cloud_cover: 'cloud_cover', icon: 'weather_code' };
if (!Object.prototype.hasOwnProperty.call(aliases, field)) return value;
return field === 'icon' ? indexed[1] + '.' + aliases[field] + '.' + indexed[2] + '.icon' + (fieldMatch[2] || '') : indexed[1] + '.' + aliases[field] + '.' + indexed[2] + (fieldMatch[2] || '');
}
function weatherIconForCode(code) {
const value = Number(code);
if (value === 0) return 'bi-sun';
if (value <= 3) return 'bi-cloud-sun';
if (value <= 48) return 'bi-cloud-fog';
if (value <= 67 || value > 77 && value <= 82) return 'bi-cloud-rain';
if (value <= 77) return 'bi-cloud-snow';
return 'bi-cloud-lightning-rain';
}
function substitutePlaceholders(html, regionContent, options) {
const source = String(html || '');
const type = String(regionContent && regionContent.type || '').trim().toLowerCase();
const item = options && typeof options.getItem === 'function' ? options.getItem(type, regionContent) : null;
if (!item) return source;
return source.replace(/\{\{\s*([^{}]+?)\s*\}\}/gi, function (_match, expression) {
const weatherExpression = type === 'weather' ? normalizeWeatherExpression(expression) : expression;
const resolved = typeof placeholderUtils.resolvePlaceholderExpression === 'function'
? placeholderUtils.resolvePlaceholderExpression(item, weatherExpression, { timeZone: item.timezone })
: resolvePlaceholderPath(item, expression);
if (type === 'weather' && /(?:^|\.)weather_code\.\d+\.icon(?:\(|$)|^current\.weather_code\.icon/.test(weatherExpression)) {
const codeExpression = weatherExpression.replace(/\.icon(?:\(.*\))?$/, '');
const iconSize = String(expression).match(/\.icon\(\s*(\d+)(?:\s*,\s*(\d+))?\s*\)$/);
const width = iconSize ? Number(iconSize[1]) : 0;
const height = iconSize && iconSize[2] ? Number(iconSize[2]) : width;
const sizeStyle = width ? ' style="display:inline-block;width:' + width + 'px;height:' + height + 'px;font-size:' + width + 'px;line-height:' + height + 'px;"' : '';
return '<i class="bi ' + weatherIconForCode(placeholderUtils.resolvePlaceholderExpression(item, codeExpression)) + '"' + sizeStyle + ' aria-hidden="true"></i>';
}
const value = typeof placeholderUtils.formatPlaceholderValue === 'function' ? placeholderUtils.formatPlaceholderValue(resolved) : String(resolved || '');
if (typeof placeholderUtils.isImagePlaceholderExpression !== 'function' || !placeholderUtils.isImagePlaceholderExpression(expression)) {
return escapeHtml(value);
}
const remoteUrl = String(value || '').trim();
if (!/^https?:\/\//i.test(remoteUrl)) return '';
const imageConfig = typeof placeholderUtils.getImagePlaceholderConfig === 'function' ? placeholderUtils.getImagePlaceholderConfig(expression) : getImagePlaceholderConfig(expression);
const cacheFile = options && typeof options.getCachedImagePath === 'function' ? options.getCachedImagePath(remoteUrl) : '';
const imageUrl = cacheFile || remoteUrl;
const style = imageConfig.width && imageConfig.height
? 'display:block;width:' + imageConfig.width + 'px;height:' + imageConfig.height + 'px;object-fit:contain;'
: 'display:block;max-width:' + (imageConfig.width || 100) + 'px;max-height:' + (imageConfig.height || 100) + 'px;width:auto;height:auto;';
return '<img src="' + escapeHtml(resolveAssetUrl(options && options.baseUrl, imageUrl)) + '" alt="" style="' + style + '" />';
});
}
function buildTextRegionMarkup(region, regionContent, options) {
const fontFamily = sanitizeFontFamily(regionContent.font_family || region.font_family); const fontFamily = sanitizeFontFamily(regionContent.font_family || region.font_family);
const fontSize = sanitizeFontSize(regionContent.font_size || region.font_size); const fontSize = sanitizeFontSize(regionContent.font_size || region.font_size);
const fontColor = sanitizeTextColor(regionContent.font_color || region.font_color); const fontColor = sanitizeTextColor(regionContent.font_color || region.font_color);
const renderedBody = renderEditorJsContent(regionContent.value || ''); const renderedBody = renderEditorJsContent(substitutePlaceholders(regionContent.value || '', regionContent, options));
if (!hasVisibleContent(renderedBody)) { if (!hasVisibleContent(renderedBody)) {
return ''; return '';
} }
@@ -98,9 +220,9 @@ function buildTextRegionMarkup(region, regionContent) {
return '<div class="slide-preview-region slide-preview-text-region" style="' + region.baseStyle + '"><div class="slide-preview-text-content" style="width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;overflow:hidden;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor || '#000000') + ';">' + renderedBody + '</div></div>'; return '<div class="slide-preview-region slide-preview-text-region" style="' + region.baseStyle + '"><div class="slide-preview-text-content" style="width:' + region.pixelWidth + 'px;height:' + region.pixelHeight + 'px;overflow:hidden;' + (fontFamily ? 'font-family:' + escapeHtml(fontFamily) + ';' : '') + 'font-size:' + fontSize + 'px;color:' + escapeHtml(fontColor || '#000000') + ';">' + renderedBody + '</div></div>';
} }
function buildRegionInnerHtml(region, regionContent, baseUrl) { function buildRegionInnerHtml(region, regionContent, baseUrl, options) {
const regionType = String(regionContent.type || region.region_type || 'text').trim().toLowerCase(); const regionType = String(regionContent.type || region.region_type || 'text').trim().toLowerCase();
const rawValue = regionContent && regionContent.value !== undefined ? regionContent.value : ''; const rawValue = normalizeRenderableValue(regionContent && regionContent.value !== undefined ? regionContent.value : '');
if (regionType === 'image') { if (regionType === 'image') {
const src = resolveAssetUrl(baseUrl, rawValue); const src = resolveAssetUrl(baseUrl, rawValue);
@@ -117,10 +239,7 @@ function buildRegionInnerHtml(region, regionContent, baseUrl) {
} }
if (regionType === 'webpage') { if (regionType === 'webpage') {
const src = resolveAssetUrl(baseUrl, rawValue); return '<div class="slide-preview-region slide-preview-webpage-region" style="' + region.baseStyle + '"><div class="slide-preview-webpage-placeholder" style="width:100%;height:100%;display:flex;align-items:center;justify-content:center;background:rgba(255,255,255,0.08);backdrop-filter:blur(8px);-webkit-backdrop-filter:blur(8px);border:1px solid rgba(255,255,255,0.14);box-sizing:border-box;color:rgba(255,255,255,0.72);font-size:24px;font-family:Arial,sans-serif;">Webpage preview unavailable</div></div>';
return src
? '<div class="slide-preview-region slide-preview-webpage-region" style="' + region.baseStyle + '"><iframe src="' + escapeHtml(src) + '" title="' + escapeHtml(region.label || region.region_key || 'webpage') + '" loading="eager" referrerpolicy="no-referrer" scrolling="no"></iframe></div>'
: '';
} }
if (regionType === 'qr-code') { if (regionType === 'qr-code') {
@@ -134,9 +253,13 @@ function buildRegionInnerHtml(region, regionContent, baseUrl) {
if (regionType === 'html') { if (regionType === 'html') {
const html = String(rawValue || '').trim(); const html = String(rawValue || '').trim();
return html if (!html) {
? '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><iframe sandbox="" srcdoc="<!doctype html><html><head><style>html,body{margin:0;width:100%;height:100%;overflow:hidden;background:transparent;}</style></head><body>' + escapeHtml(html) + '</body></html>" title="' + escapeHtml(region.label || region.region_key || 'html') + '" loading="eager" scrolling="no"></iframe></div>' return '';
: ''; }
if (/^<!doctype\b/i.test(html) || /^<html\b/i.test(html)) {
return '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><iframe sandbox="" allowtransparency="true" srcdoc="' + escapeHtml(html) + '" title="' + escapeHtml(region.label || region.region_key || 'html') + '" loading="eager" scrolling="no" style="width:100%;height:100%;border:0;display:block;background:transparent;overflow:hidden;"></iframe></div>';
}
return '<div class="slide-preview-region slide-preview-html-region" style="' + region.baseStyle + '"><div class="slide-preview-html-content" style="width:100%;height:100%;overflow:hidden;background:transparent;">' + html + '</div></div>';
} }
if (regionType === 'rtmp') { if (regionType === 'rtmp') {
@@ -144,7 +267,7 @@ function buildRegionInnerHtml(region, regionContent, baseUrl) {
return '<div class="slide-preview-region slide-preview-rtmp-region" style="' + region.baseStyle + '"><div class="slide-preview-rtmp-placeholder">' + escapeHtml(label) + '</div></div>'; return '<div class="slide-preview-region slide-preview-rtmp-region" style="' + region.baseStyle + '"><div class="slide-preview-rtmp-placeholder">' + escapeHtml(label) + '</div></div>';
} }
return buildTextRegionMarkup(region, regionContent); return buildTextRegionMarkup(region, regionContent, Object.assign({}, options, { baseUrl: baseUrl }));
} }
async function loadChromium() { async function loadChromium() {
@@ -161,7 +284,7 @@ function loadSharp() {
return require('sharp'); return require('sharp');
} }
function buildThumbnailPreviewMarkup(slide, baseUrl) { function buildThumbnailPreviewMarkup(slide, baseUrl, options) {
const template = slide && slide.template ? slide.template : null; const template = slide && slide.template ? slide.template : null;
if (!template) { if (!template) {
return ''; return '';
@@ -176,7 +299,7 @@ function buildThumbnailPreviewMarkup(slide, baseUrl) {
pixelWidth: Math.max(1, Math.round(Number(region && region.width || 0) || 1)), pixelWidth: Math.max(1, Math.round(Number(region && region.width || 0) || 1)),
pixelHeight: Math.max(1, Math.round(Number(region && region.height || 0) || 1)) pixelHeight: Math.max(1, Math.round(Number(region && region.height || 0) || 1))
}); });
return buildRegionInnerHtml(previewRegion, regionContent, normalizedBaseUrl); return buildRegionInnerHtml(previewRegion, regionContent, normalizedBaseUrl, options);
}).join(''); }).join('');
} }
@@ -188,9 +311,10 @@ function buildThumbnailPreviewPayload(slide, options) {
canvasWidth: canvasSize.width, canvasWidth: canvasSize.width,
canvasHeight: canvasSize.height, canvasHeight: canvasSize.height,
backgroundColor: template && template.background_color ? String(template.background_color) : '#111111', backgroundColor: template && template.background_color ? String(template.background_color) : '#111111',
backgroundGradient: template && template.background_gradient ? String(template.background_gradient) : '',
backgroundImagePath: template && template.background_image_path ? String(template.background_image_path) : '', backgroundImagePath: template && template.background_image_path ? String(template.background_image_path) : '',
fontStylesheetHref: String(options && options.fontStylesheetHref || '').trim(), fontStylesheetHref: String(options && options.fontStylesheetHref || '').trim(),
html: buildThumbnailPreviewMarkup(slide, options && options.baseUrl) html: buildThumbnailPreviewMarkup(slide, options && options.baseUrl, options)
}; };
} }
@@ -215,8 +339,7 @@ async function launchBrowser() {
args: [ args: [
'--no-sandbox', '--no-sandbox',
'--disable-setuid-sandbox', '--disable-setuid-sandbox',
'--disable-dev-shm-usage', '--disable-dev-shm-usage'
'--disable-gpu'
], ],
defaultViewport: { width: 1920, height: 1080, deviceScaleFactor: 1 }, defaultViewport: { width: 1920, height: 1080, deviceScaleFactor: 1 },
executablePath: executablePath, executablePath: executablePath,
@@ -253,6 +376,74 @@ async function captureSlideThumbnail(options) {
throw new Error('Slide not found.'); throw new Error('Slide not found.');
} }
const rssFeedsData = typeof common.fetchRssFeedsData === 'function' ? await common.fetchRssFeedsData(pool) : { rssFeeds: [] };
const rssFeeds = await Promise.all((rssFeedsData.rssFeeds || []).map(async function (feed) {
const items = typeof common.fetchRssFeedItemsByFeedId === 'function' ? await common.fetchRssFeedItemsByFeedId(pool, feed.id) : [];
return Object.assign({}, feed, { items: items });
}));
const apiSourcesData = typeof common.fetchApiSourcesData === 'function' ? await common.fetchApiSourcesData(pool) : { apiSources: [] };
const apiSources = (apiSourcesData.apiSources || []).map(function (source) {
return Object.assign({}, source, { responseJson: common.parseJsonSafe ? common.parseJsonSafe(source.last_response_json) : null });
});
const weatherLocationsData = typeof common.fetchWeatherLocationsData === 'function' ? await common.fetchWeatherLocationsData(pool) : { weatherLocations: [] };
const weatherLocations = (weatherLocationsData.weatherLocations || []).map(function (location) {
let snapshot = null;
try {
snapshot = JSON.parse(location.last_response_json || '');
} catch (_error) {
snapshot = null;
}
if (!snapshot || typeof snapshot !== 'object') return null;
const temperatureUnit = location.temperature_unit === 'fahrenheit' ? '°F' : '°C';
const windUnit = location.wind_unit === 'mph' ? 'mph' : location.wind_unit === 'ms' ? 'm/s' : 'km/h';
const precipitationUnit = location.precipitation_unit === 'inch' ? 'in' : 'mm';
const data = Object.assign({}, convertWeatherSnapshot(snapshot, { temperature: location.temperature_unit === 'fahrenheit' ? 'fahrenheit' : 'celsius', wind: location.wind_unit === 'mph' ? 'mph' : location.wind_unit === 'ms' ? 'ms' : 'kmh', precipitation: location.precipitation_unit === 'inch' ? 'inch' : 'mm' }), { location_label: location.location_label || '', name: location.name || '', timezone: location.timezone || '', temp_unit: temperatureUnit, wind_unit: windUnit, precip_unit: precipitationUnit });
data.current = Object.assign({}, data.current || {}, { temperature_unit: temperatureUnit, wind_speed_unit: windUnit, precipitation_unit: precipitationUnit });
data.daily = Object.assign({}, data.daily || {}, { temperature_unit: temperatureUnit });
return { id: location.id, data: data };
}).filter(Boolean);
function getApiItems(source) {
const response = source && source.responseJson;
const itemsPath = String(source && source.items_path || '').trim();
if (itemsPath) {
const selected = itemsPath.split('.').reduce(function (current, segment) {
return current === undefined || current === null ? '' : current[segment];
}, response);
return Array.isArray(selected) ? selected : [];
}
if (Array.isArray(response)) return response;
if (response && Array.isArray(response.items)) return response.items;
if (response && Array.isArray(response.results)) return response.results;
if (response && Array.isArray(response.data)) return response.data;
return response ? [response] : [];
}
function getThumbnailItem(type, regionContent) {
const index = Math.max(0, Math.max(1, Number(regionContent && regionContent.item_number || 1)) - 1);
if (type === 'api') {
const source = apiSources.find(function (entry) { return Number(entry.id) === Number(regionContent.source_id); });
return getApiItems(source)[index] || null;
}
if (type === 'rss') {
const feed = rssFeeds.find(function (entry) { return Number(entry.id) === Number(regionContent.feed_id); });
return feed && Array.isArray(feed.items) ? feed.items[index] || null : null;
}
if (type === 'weather') {
const location = weatherLocations.find(function (entry) { return Number(entry.id) === Number(regionContent.weather_location_id); });
return location ? location.data : null;
}
return null;
}
function getCachedImagePath(remoteUrl) {
const hash = crypto.createHash('sha256').update(String(remoteUrl || '')).digest('hex');
const cacheDir = path.join(mediaDir, 'player-cache', 'remote-images');
const candidates = ['.png', '.jpg', '.jpeg', '.gif', '.webp', '.svg'];
const candidate = candidates.map(function (extension) { return path.join(cacheDir, hash + extension); }).find(function (filePath) { return fs.existsSync(filePath); });
return candidate ? '/media/player-cache/remote-images/' + path.basename(candidate) : '';
}
const thumbnailDir = path.join(mediaDir, 'thumbnails'); const thumbnailDir = path.join(mediaDir, 'thumbnails');
const thumbnailRelativePath = String(slide.thumbnail_path || '').trim() || '/media/thumbnails/slides/slide-' + slide.id + '.png'; const thumbnailRelativePath = String(slide.thumbnail_path || '').trim() || '/media/thumbnails/slides/slide-' + slide.id + '.png';
const filePath = path.join(mediaDir, thumbnailRelativePath.replace(/^\/+media\//, '')); const filePath = path.join(mediaDir, thumbnailRelativePath.replace(/^\/+media\//, ''));
@@ -268,14 +459,9 @@ async function captureSlideThumbnail(options) {
}, { timeout: 30000 }); }, { timeout: 30000 });
await page.waitForFunction(function () { await page.waitForFunction(function () {
var canvas = document.querySelector('#popup-preview-canvas'); var videos = Array.prototype.slice.call(document.querySelectorAll('#popup-preview-canvas video'));
if (!canvas) { return videos.every(function (video) {
return false; return video.readyState >= 2;
}
var images = Array.prototype.slice.call(canvas.querySelectorAll('img'));
return images.every(function (image) {
return image.complete && typeof image.naturalWidth === 'number';
}); });
}, { timeout: 30000 }); }, { timeout: 30000 });
@@ -284,17 +470,13 @@ async function captureSlideThumbnail(options) {
try { try {
await document.fonts.ready; await document.fonts.ready;
} catch (_error) { } catch (_error) {
// Ignore font readiness failures and fall back to the rendered frame. return null;
} }
} }
}); });
await page.evaluate(function () { await new Promise(function (resolve) {
return new Promise(function (resolve) { setTimeout(resolve, 1000);
window.requestAnimationFrame(function () {
window.requestAnimationFrame(resolve);
});
});
}); });
} }
@@ -302,28 +484,49 @@ async function captureSlideThumbnail(options) {
try { try {
const page = await browser.newPage(); const page = await browser.newPage();
try { try {
const previewPath = '/api/internal/slide-thumbnails/' + slide.id + '/popup-preview'; const previewPath = '/api/internal/slide-thumbnails/' + encodeURIComponent(String(slide.id)) + '/popup-preview';
const previewUrl = baseUrl + previewPath; const previewUrl = baseUrl + previewPath;
const previewPayload = buildThumbnailPreviewPayload(slide, { const canvasSize = getThumbnailCanvasSize(slide);
baseUrl: baseUrl, await page.setViewport({
fontStylesheetHref: options && options.fontStylesheetHref ? options.fontStylesheetHref : '' width: Math.max(1, Number(canvasSize.width || PLAYER_VIEWPORT.width)),
height: Math.max(1, Number(canvasSize.height || PLAYER_VIEWPORT.height)),
deviceScaleFactor: 1
}); });
await page.setViewport({ await page.setExtraHTTPHeaders(Object.assign({}, createRequestAuthHeaders({
width: Math.max(1, Number(previewPayload.canvasWidth || PLAYER_VIEWPORT.width)),
height: Math.max(1, Number(previewPayload.canvasHeight || PLAYER_VIEWPORT.height)),
deviceScaleFactor: 1
});
await page.setExtraHTTPHeaders(createRequestAuthHeaders({
method: 'GET', method: 'GET',
pathname: previewPath pathname: previewPath
}), {
'x-pulse-page-auth': createPageAuthToken({ scope: 'thumbnail-preview', slideId: slide.id })
})); }));
await page.goto(previewUrl, { waitUntil: 'domcontentloaded', timeout: 30000 }); const previewResponse = await page.goto(previewUrl, { waitUntil: 'domcontentloaded', timeout: 30000 });
if (!previewResponse || previewResponse.status() >= 400) {
throw new Error('Popup preview returned HTTP ' + (previewResponse ? previewResponse.status() : 'no response') + '.');
}
await waitForThumbnailRender(page); await waitForThumbnailRender(page);
const canvas = await page.$('#popup-preview-canvas'); const canvas = await page.$('#popup-preview-canvas');
if (!canvas) { if (!canvas) {
throw new Error('Popup preview did not produce a slide canvas.'); throw new Error('Popup preview did not produce a slide canvas.');
} }
await canvas.screenshot({ path: fullSizePath }); await page.evaluate(function () {
var canvasElement = document.querySelector('#popup-preview-canvas');
if (canvasElement) {
canvasElement.style.transform = 'none';
canvasElement.style.transformOrigin = 'top left';
}
});
const canvasBounds = await canvas.boundingBox();
if (!canvasBounds) {
throw new Error('Popup preview canvas has no screenshot bounds.');
}
await page.screenshot({
path: fullSizePath,
clip: {
x: Math.max(0, canvasBounds.x),
y: Math.max(0, canvasBounds.y),
width: Math.max(1, canvasBounds.width),
height: Math.max(1, canvasBounds.height)
}
});
} finally { } finally {
await page.close().catch(function () { await page.close().catch(function () {
return null; return null;
+130 -31
View File
@@ -389,6 +389,9 @@ function createUploadSyncService(options) {
} }
const filePath = resolveUploadFilePath(uploadDir, uploadPath); const filePath = resolveUploadFilePath(uploadDir, uploadPath);
if (String(uploadPath || '').startsWith('/media/player-cache/')) {
continue;
}
try { try {
await fs.promises.unlink(filePath); await fs.promises.unlink(filePath);
} catch (error) { } catch (error) {
@@ -441,7 +444,11 @@ function createUploadSyncService(options) {
continue; continue;
} }
uploadPaths.push('/media/uploads/' + nextRelativePath.replace(/\\/g, '/')); const normalizedRelativePath = nextRelativePath.replace(/\\/g, '/');
if (normalizedRelativePath.startsWith('player-cache/') && !normalizedRelativePath.startsWith('player-cache/remote-images/')) {
continue;
}
uploadPaths.push((normalizedRelativePath.startsWith('player-cache/') ? '/media/' : '/media/uploads/') + normalizedRelativePath);
} }
} }
@@ -453,6 +460,23 @@ function createUploadSyncService(options) {
return Boolean(localUploadDir); return Boolean(localUploadDir);
} }
async function fetchLivePlayerRegistrations() {
if (!pool || typeof fetchPlayerRegistrations !== 'function') {
return [];
}
try {
const players = await fetchPlayerRegistrations(pool);
return Array.isArray(players)
? players.filter(function (player) {
return isRecentPlayerRegistration(player, 60);
})
: [];
} catch (_error) {
return [];
}
}
function isPlayerUnavailableError(error) { function isPlayerUnavailableError(error) {
const code = String(error && error.cause && error.cause.code || error && error.code || '').trim().toUpperCase(); const code = String(error && error.cause && error.cause.code || error && error.code || '').trim().toUpperCase();
return code === 'ENOTFOUND' || code === 'ECONNREFUSED' || code === 'EAI_AGAIN' || code === 'ETIMEDOUT'; return code === 'ENOTFOUND' || code === 'ECONNREFUSED' || code === 'EAI_AGAIN' || code === 'ETIMEDOUT';
@@ -462,16 +486,33 @@ function createUploadSyncService(options) {
return Boolean(response) && Number(response.status) === 503; return Boolean(response) && Number(response.status) === 503;
} }
function buildPendingPlayerUploadSyncKey(operation) {
const uploadPath = normalizeUploadReference(operation && operation.uploadPath);
const metadata = operation && operation.metadata && typeof operation.metadata === 'object'
? operation.metadata
: null;
const playerIdentifier = String((operation && operation.playerIdentifier) || (metadata && metadata.playerIdentifier) || '').trim();
const playerInternalBaseUrl = normalizeBaseUrl((operation && operation.playerInternalBaseUrl) || (metadata && metadata.playerInternalBaseUrl) || '');
return [uploadPath, playerIdentifier, playerInternalBaseUrl].filter(Boolean).join('|');
}
function queuePlayerUploadSync(operation) { function queuePlayerUploadSync(operation) {
if (!operation || !operation.uploadPath) { if (!operation || !operation.uploadPath) {
return; return;
} }
pendingPlayerUploadSyncs.set(normalizeUploadReference(operation.uploadPath), { const metadata = operation.metadata && typeof operation.metadata === 'object' ? operation.metadata : null;
const playerIdentifier = String((operation && operation.playerIdentifier) || (metadata && metadata.playerIdentifier) || '').trim();
const playerInternalBaseUrl = normalizeBaseUrl((operation && operation.playerInternalBaseUrl) || (metadata && metadata.playerInternalBaseUrl) || '');
pendingPlayerUploadSyncs.set(buildPendingPlayerUploadSyncKey(operation), {
type: operation.type === 'delete' ? 'delete' : 'put', type: operation.type === 'delete' ? 'delete' : 'put',
uploadPath: normalizeUploadReference(operation.uploadPath), uploadPath: normalizeUploadReference(operation.uploadPath),
uploadDir: operation.uploadDir || null, uploadDir: operation.uploadDir || null,
metadata: operation.metadata || null metadata: metadata,
playerIdentifier: playerIdentifier || null,
playerInternalBaseUrl: playerInternalBaseUrl || null
}); });
schedulePendingPlayerUploadSyncFlush(); schedulePendingPlayerUploadSyncFlush();
@@ -592,20 +633,26 @@ function createUploadSyncService(options) {
} }
} }
async function syncUploadRefsToPlayer(uploadRefs, localUploadDir) { async function syncUploadRefsToPlayer(uploadRefs, localUploadDir, preferredPlayerIdentifier, preferredPlayerInternalBaseUrl) {
if (!shouldMirrorUploads(localUploadDir)) { if (!shouldMirrorUploads(localUploadDir)) {
return; return;
} }
const resolvedPlayerInternalBaseUrl = await getPlayerInternalBaseUrl(); const resolvedPlayerInternalBaseUrl = await getPlayerInternalBaseUrl(preferredPlayerIdentifier, preferredPlayerInternalBaseUrl);
const uniqueRefs = Array.from(new Set((uploadRefs || []).map(normalizeUploadReference).filter(Boolean))); const uniqueRefs = Array.from(new Set((uploadRefs || []).map(normalizeUploadReference).filter(Boolean)));
for (let i = 0; i < uniqueRefs.length; i += 1) { for (let i = 0; i < uniqueRefs.length; i += 1) {
const success = await pushUploadFileToPlayer(uniqueRefs[i], localUploadDir, resolvedPlayerInternalBaseUrl); const success = await pushUploadFileToPlayer(uniqueRefs[i], localUploadDir, resolvedPlayerInternalBaseUrl, preferredPlayerIdentifier);
if (!success) { if (!success) {
queuePlayerUploadSync({ queuePlayerUploadSync({
type: 'put', type: 'put',
uploadPath: uniqueRefs[i], uploadPath: uniqueRefs[i],
uploadDir: localUploadDir uploadDir: localUploadDir,
playerIdentifier: preferredPlayerIdentifier,
playerInternalBaseUrl: preferredPlayerInternalBaseUrl,
metadata: preferredPlayerIdentifier || preferredPlayerInternalBaseUrl ? {
playerIdentifier: preferredPlayerIdentifier || null,
playerInternalBaseUrl: preferredPlayerInternalBaseUrl || null
} : null
}); });
} }
} }
@@ -723,10 +770,27 @@ function createUploadSyncService(options) {
return; return;
} }
return queueMediaSyncTask('media-sync:' + operation.key, 'Media sync', { const players = await fetchLivePlayerRegistrations();
mode: 'playlist', if (!players.length) {
operation: operation return queueMediaSyncTask('media-sync:' + operation.key, 'Media sync', {
}); mode: 'playlist',
operation: operation
});
}
return Promise.all(players.map(function (player) {
const playerIdentifier = String(player && player.identifier || '').trim();
const playerInternalBaseUrl = String(player && player.internal_base_url || '').trim().replace(/\/$/, '');
const playerPublicBaseUrl = String(player && player.public_base_url || '').trim().replace(/\/$/, '');
return queueMediaSyncTask('media-sync:' + operation.key + (playerIdentifier ? ':' + playerIdentifier : ''), 'Media sync', {
mode: 'playlist',
operation: operation,
playerIdentifier: playerIdentifier || null,
playerInternalBaseUrl: playerInternalBaseUrl || null,
playerPublicBaseUrl: playerPublicBaseUrl || null
});
}));
} }
async function flushPendingPlaylistUploadSyncs() { async function flushPendingPlaylistUploadSyncs() {
@@ -787,22 +851,27 @@ function createUploadSyncService(options) {
} }
pendingPlayerUploadSyncFlushInFlight = (async function () { pendingPlayerUploadSyncFlushInFlight = (async function () {
const pendingEntries = Array.from(pendingPlayerUploadSyncs.values()); const pendingEntries = Array.from(pendingPlayerUploadSyncs.entries());
const playerMetadata = pendingEntries.length && pendingEntries[0] && pendingEntries[0].metadata const firstOperation = pendingEntries.length && pendingEntries[0] ? pendingEntries[0][1] : null;
? pendingEntries[0].metadata const summaryPlayerMetadata = firstOperation && firstOperation.metadata
: await getPlayerTaskMetadata(); ? firstOperation.metadata
if (playerMetadata && playerMetadata.playerActive === false) { : await getPlayerTaskMetadata(firstOperation && firstOperation.playerIdentifier, firstOperation && firstOperation.playerInternalBaseUrl);
pendingPlayerUploadSyncs.clear();
pendingPlayerUploadSyncRetryLogAt = 0;
return;
}
const resolvedPlayerInternalBaseUrl = playerMetadata && playerMetadata.playerInternalBaseUrl
? playerMetadata.playerInternalBaseUrl
: await getPlayerInternalBaseUrl(playerMetadata && playerMetadata.playerIdentifier, playerMetadata && playerMetadata.playerInternalBaseUrl);
let successCount = 0; let successCount = 0;
let failureCount = 0; let failureCount = 0;
for (let i = 0; i < pendingEntries.length; i += 1) { for (let i = 0; i < pendingEntries.length; i += 1) {
const operation = pendingEntries[i]; const entry = pendingEntries[i];
const pendingKey = entry[0];
const operation = entry[1];
const playerMetadata = operation && operation.metadata
? operation.metadata
: await getPlayerTaskMetadata(operation && operation.playerIdentifier, operation && operation.playerInternalBaseUrl);
if (playerMetadata && playerMetadata.playerActive === false) {
pendingPlayerUploadSyncs.delete(pendingKey);
continue;
}
const resolvedPlayerInternalBaseUrl = playerMetadata && playerMetadata.playerInternalBaseUrl
? playerMetadata.playerInternalBaseUrl
: await getPlayerInternalBaseUrl(playerMetadata && playerMetadata.playerIdentifier, playerMetadata && playerMetadata.playerInternalBaseUrl);
let success = false; let success = false;
if (operation.type === 'delete') { if (operation.type === 'delete') {
success = await removeUploadFileFromPlayer(operation.uploadPath, operation.uploadDir, resolvedPlayerInternalBaseUrl, playerMetadata && playerMetadata.playerIdentifier); success = await removeUploadFileFromPlayer(operation.uploadPath, operation.uploadDir, resolvedPlayerInternalBaseUrl, playerMetadata && playerMetadata.playerIdentifier);
@@ -811,20 +880,20 @@ function createUploadSyncService(options) {
} }
if (success) { if (success) {
successCount += 1; successCount += 1;
pendingPlayerUploadSyncs.delete(operation.uploadPath); pendingPlayerUploadSyncs.delete(pendingKey);
} else { } else {
failureCount += 1; failureCount += 1;
} }
} }
if (successCount) { if (successCount) {
logMediaSyncSummary('info', `Media sync completed ${successCount} upload${successCount === 1 ? '' : 's'}`, playerMetadata); logMediaSyncSummary('info', `Media sync completed ${successCount} upload${successCount === 1 ? '' : 's'}`, summaryPlayerMetadata);
} }
if (failureCount) { if (failureCount) {
const now = Date.now(); const now = Date.now();
if (!pendingPlayerUploadSyncRetryLogAt || now - pendingPlayerUploadSyncRetryLogAt >= PLAYER_UPLOAD_SYNC_RETRY_LOG_INTERVAL_MS) { if (!pendingPlayerUploadSyncRetryLogAt || now - pendingPlayerUploadSyncRetryLogAt >= PLAYER_UPLOAD_SYNC_RETRY_LOG_INTERVAL_MS) {
pendingPlayerUploadSyncRetryLogAt = now; pendingPlayerUploadSyncRetryLogAt = now;
logMediaSyncSummary('warn', `Player unavailable, retry queued for ${failureCount} upload${failureCount === 1 ? '' : 's'}`, playerMetadata); logMediaSyncSummary('warn', `Player unavailable, retry queued for ${failureCount} upload${failureCount === 1 ? '' : 's'}`, summaryPlayerMetadata);
} }
} else if (!pendingPlayerUploadSyncs.size) { } else if (!pendingPlayerUploadSyncs.size) {
pendingPlayerUploadSyncRetryLogAt = 0; pendingPlayerUploadSyncRetryLogAt = 0;
@@ -864,6 +933,12 @@ function createUploadSyncService(options) {
}); });
}); });
const fontLibraryOperations = collectFontLibrarySyncOperations(uploadDir); const fontLibraryOperations = collectFontLibrarySyncOperations(uploadDir);
const generatedCachePaths = await collectUploadPathsFromDirectory(uploadDir);
generatedCachePaths.filter(function (uploadPath) {
return String(uploadPath || '').startsWith('/media/player-cache/remote-images/');
}).forEach(function (uploadPath) {
uploadRefs.add(uploadPath);
});
Array.from(uploadRefs).forEach(function (uploadPath) { Array.from(uploadRefs).forEach(function (uploadPath) {
queuePlayerUploadSync({ queuePlayerUploadSync({
type: 'put', type: 'put',
@@ -891,15 +966,39 @@ function createUploadSyncService(options) {
if (mode === 'playlist') { if (mode === 'playlist') {
const operation = normalizePlaylistUploadSyncOperation(taskPayload.operation || taskPayload); const operation = normalizePlaylistUploadSyncOperation(taskPayload.operation || taskPayload);
if (operation.nextUploadRefs.length) { const generatedCachePaths = await collectUploadPathsFromDirectory(operation.localUploadDir);
await syncUploadRefsToPlayer(operation.nextUploadRefs, operation.localUploadDir); const nextUploadRefs = operation.nextUploadRefs.concat(generatedCachePaths.filter(function (uploadPath) {
return String(uploadPath || '').startsWith('/media/player-cache/remote-images/');
}));
if (nextUploadRefs.length) {
await syncUploadRefsToPlayer(nextUploadRefs, operation.localUploadDir, taskPayload.playerIdentifier, taskPayload.playerInternalBaseUrl);
} }
if (operation.previousUploadRefs.length) { if (operation.previousUploadRefs.length) {
const nextUploadRefSet = new Set(operation.nextUploadRefs); const nextUploadRefSet = new Set(operation.nextUploadRefs);
await removeUnusedUploadFiles(pool, operation.localUploadDir, operation.previousUploadRefs.filter(function (reference) { const removedUploadRefs = operation.previousUploadRefs.filter(function (reference) {
return !nextUploadRefSet.has(reference); return !nextUploadRefSet.has(reference);
})); });
for (let i = 0; i < removedUploadRefs.length; i += 1) {
const removedUploadRef = removedUploadRefs[i];
const referenceCount = await countUploadReferences(pool, removedUploadRef);
if (referenceCount > 0) {
continue;
}
const deleted = await removeUploadFileFromPlayer(removedUploadRef, operation.localUploadDir, taskPayload.playerInternalBaseUrl, taskPayload.playerIdentifier);
if (!deleted) {
queuePlayerUploadSync({
type: 'delete',
uploadPath: removedUploadRef,
uploadDir: operation.localUploadDir,
playerIdentifier: taskPayload.playerIdentifier,
playerInternalBaseUrl: taskPayload.playerInternalBaseUrl,
metadata: playerMetadata
});
}
}
await removeUnusedUploadFiles(pool, operation.localUploadDir, removedUploadRefs);
} }
if (operation.refreshScreenSlugs.length) { if (operation.refreshScreenSlugs.length) {
+23 -4
View File
@@ -1,4 +1,6 @@
function createNotifyPlayerScreens(forwardPlayerCommand) { // Route screen refresh commands to the physical player hosting each screen.
function createNotifyPlayerScreens(forwardPlayerCommand, getScreenConnections, forwardPlayerCommandToBaseUrl, resolvePlayerBaseUrl) {
if (typeof forwardPlayerCommand !== 'function') { if (typeof forwardPlayerCommand !== 'function') {
throw new Error('createNotifyPlayerScreens requires a player command sender.'); throw new Error('createNotifyPlayerScreens requires a player command sender.');
} }
@@ -12,12 +14,29 @@ function createNotifyPlayerScreens(forwardPlayerCommand) {
return Promise.resolve(0); return Promise.resolve(0);
} }
return Promise.allSettled(uniqueSlugs.map(function (slug) { return Promise.allSettled(uniqueSlugs.map(async function (slug) {
// A screen may have connections on multiple players after a remote move or reconnect.
if (typeof getScreenConnections === 'function' && typeof forwardPlayerCommandToBaseUrl === 'function') {
const screenState = await getScreenConnections(slug);
const connections = Array.isArray(screenState && screenState.connections) ? screenState.connections : [];
const playerBaseUrls = Array.from(new Set(connections.map(function (connection) {
return String(connection && connection.playerPublicBaseUrl || '').trim().replace(/\/$/, '');
}).filter(Boolean)));
if (playerBaseUrls.length) {
const resolvedPlayerBaseUrls = typeof resolvePlayerBaseUrl === 'function'
? await Promise.all(playerBaseUrls.map(function (playerBaseUrl) { return resolvePlayerBaseUrl(playerBaseUrl); }))
: playerBaseUrls;
return Promise.all(resolvedPlayerBaseUrls.filter(Boolean).map(function (playerBaseUrl) {
return forwardPlayerCommandToBaseUrl(playerBaseUrl, slug, commandOrPayload || 'refresh');
}));
}
}
return forwardPlayerCommand(slug, commandOrPayload || 'refresh'); return forwardPlayerCommand(slug, commandOrPayload || 'refresh');
})).then(function (results) { })).then(function (results) {
return results.filter(function (result) { const successful = results.filter(function (result) {
return result.status === 'fulfilled'; return result.status === 'fulfilled' && (!result.value || result.value.ok !== false);
}).length; }).length;
return successful;
}); });
}; };
} }
+66 -22
View File
@@ -1,3 +1,5 @@
// Commands and synchronization actions forwarded from the web app to players.
const { createRequestAuthHeaders } = require('#src/request-auth'); const { createRequestAuthHeaders } = require('#src/request-auth');
const { getConfiguredPlayerIdentifier } = require('#src/data/player-registry'); const { getConfiguredPlayerIdentifier } = require('#src/data/player-registry');
@@ -215,36 +217,77 @@ function createPlayerActionService(options) {
return forwardPlayerCommandToBaseUrl(resolvedPlayerInternalBaseUrl, slug, commandOrPayload, connectionId); return forwardPlayerCommandToBaseUrl(resolvedPlayerInternalBaseUrl, slug, commandOrPayload, connectionId);
} }
async function resolvePlayerBaseUrlForPublicUrl(playerPublicBaseUrl) {
const normalizedPublicBaseUrl = normalizeBaseUrl(playerPublicBaseUrl);
if (!normalizedPublicBaseUrl) {
return '';
}
try {
const players = await fetchPlayerRegistrations(pool);
const matchedPlayer = (Array.isArray(players) ? players : []).find(function (player) {
return normalizeBaseUrl(player && player.public_base_url) === normalizedPublicBaseUrl;
});
const registeredInternalBaseUrl = normalizeBaseUrl(matchedPlayer && matchedPlayer.internal_base_url);
if (registeredInternalBaseUrl) {
return registeredInternalBaseUrl;
}
} catch (_error) {
}
if (isLocalLikeBaseUrl(normalizedPublicBaseUrl) && configuredPlayerInternalBaseUrl) {
return configuredPlayerInternalBaseUrl;
}
return normalizedPublicBaseUrl;
}
async function forwardAnnouncementRefresh(slug) { async function forwardAnnouncementRefresh(slug) {
const authHeaders = createRequestAuthHeaders({
method: 'POST',
pathname: `/api/screens/${encodeURIComponent(slug)}/announcements/refresh`,
body: { command: 'announcement-refresh' }
});
const resolvedPlayerInternalBaseUrl = await getPlayerInternalBaseUrl(); const resolvedPlayerInternalBaseUrl = await getPlayerInternalBaseUrl();
if (!resolvedPlayerInternalBaseUrl) { const targetBaseUrls = Array.from(new Set([
resolvedPlayerInternalBaseUrl,
configuredBridgeInternalBaseUrl
].map(normalizeBaseUrl).filter(Boolean)));
if (!targetBaseUrls.length) {
throw new Error('Unable to resolve the player internal base URL.'); throw new Error('Unable to resolve the player internal base URL.');
} }
const response = await fetch(`${resolvedPlayerInternalBaseUrl}/api/screens/${encodeURIComponent(slug)}/announcements/refresh`, { const results = await Promise.allSettled(targetBaseUrls.map(async function (targetBaseUrl) {
method: 'POST', const authHeaders = createRequestAuthHeaders({
headers: { method: 'POST',
'Content-Type': 'application/json', pathname: `/api/screens/${encodeURIComponent(slug)}/announcements/refresh`,
Accept: 'application/json', body: { command: 'announcement-refresh' }
...authHeaders });
}, const response = await fetch(`${targetBaseUrl}/api/screens/${encodeURIComponent(slug)}/announcements/refresh`, {
body: JSON.stringify({ command: 'announcement-refresh' }) method: 'POST',
}); headers: {
'Content-Type': 'application/json',
Accept: 'application/json',
...authHeaders
},
body: JSON.stringify({ command: 'announcement-refresh' })
});
if (!response.ok) { if (!response.ok) {
const errorText = await response.text().catch(function () { return ''; }); const errorText = await response.text().catch(function () { return ''; });
const error = new Error(errorText || `Unable to refresh announcements for player ${slug}.`); const error = new Error(errorText || `Unable to refresh announcements for player ${slug}.`);
error.statusCode = response.status; error.statusCode = response.status;
throw error; throw error;
}
return response.json().catch(function () {
return { ok: true };
});
}));
const successfulResults = results.filter(function (result) {
return result.status === 'fulfilled';
});
if (!successfulResults.length) {
throw (results[0] && results[0].reason) || new Error(`Unable to refresh announcements for player ${slug}.`);
} }
return response.json().catch(function () { return successfulResults.map(function (result) {
return { ok: true }; return result.value;
}); });
} }
@@ -351,6 +394,7 @@ function createPlayerActionService(options) {
return { return {
forwardPlayerCommand: forwardPlayerCommand, forwardPlayerCommand: forwardPlayerCommand,
resolvePlayerBaseUrlForPublicUrl: resolvePlayerBaseUrlForPublicUrl,
forwardAnnouncementRefresh: forwardAnnouncementRefresh, forwardAnnouncementRefresh: forwardAnnouncementRefresh,
getScreenConnections: getScreenConnections, getScreenConnections: getScreenConnections,
forwardPlayerCommandToBaseUrl: forwardPlayerCommandToBaseUrl, forwardPlayerCommandToBaseUrl: forwardPlayerCommandToBaseUrl,
+3 -1
View File
@@ -1,10 +1,12 @@
// Load and normalize browser region scripts for server-rendered player pages.
const fs = require('fs'); const fs = require('fs');
const path = require('path'); const path = require('path');
const PUBLIC_JS_ROOT = path.join(__dirname, '..', 'public', 'js'); const PUBLIC_JS_ROOT = path.join(__dirname, '..', 'public', 'js');
const REGION_ROOT_DIR = path.join(PUBLIC_JS_ROOT, 'regions'); const REGION_ROOT_DIR = path.join(PUBLIC_JS_ROOT, 'regions');
const REGION_TYPE_DIR = path.join(REGION_ROOT_DIR, 'type'); const REGION_TYPE_DIR = path.join(REGION_ROOT_DIR, 'type');
const REGION_CORE_SCRIPTS = ['js/shared/placeholder-utils.js', 'js/shared/placeholder-chips.js', 'js/shared/time-date-placeholders.js', 'js/regions/region-utils.js', 'js/regions/region-types.js']; const REGION_CORE_SCRIPTS = ['js/shared/placeholder-utils.js', 'js/shared/placeholder-chips.js', 'js/shared/placeholder-info.js', 'js/shared/time-date-placeholders.js', 'js/regions/region-utils.js', 'js/regions/region-types.js'];
function withAssetVersion(scriptPath, assetVersion) { function withAssetVersion(scriptPath, assetVersion) {
if (!assetVersion) { if (!assetVersion) {
+3
View File
@@ -1,3 +1,5 @@
// Start background services, scheduled tasks, and web application dependencies.
async function initializeWebServer(options) { async function initializeWebServer(options) {
const common = options && options.common; const common = options && options.common;
const pool = options && options.pool; const pool = options && options.pool;
@@ -22,6 +24,7 @@ async function initializeWebServer(options) {
pool: pool, pool: pool,
common: common, common: common,
backgroundTaskQueue: backgroundTaskQueue, backgroundTaskQueue: backgroundTaskQueue,
notifyPlayerScreens: options && options.notifyPlayerScreens ? options.notifyPlayerScreens : null,
uploadSyncService: webBootstrap.uploadSyncService, uploadSyncService: webBootstrap.uploadSyncService,
captureSlideThumbnail: captureSlideThumbnail, captureSlideThumbnail: captureSlideThumbnail,
mediaDir: mediaDir, mediaDir: mediaDir,
+7 -2
View File
@@ -29,10 +29,15 @@ module.exports = function registerMiddleware(app, deps) {
}); });
app.use(function (req, res, next) { app.use(function (req, res, next) {
if (req.path === '/' || req.path === '/login' || req.path === '/logout' || req.path.indexOf('/api/internal/slide-thumbnails/') === 0 || req.path === '/api/internal/sync/player-media' || req.path === '/api/internal/sync/player-font') { if (req.path === '/' || req.path === '/login' || req.path === '/logout' || req.path === '/slides/popup-preview' || req.path.indexOf('/api/internal/slide-thumbnails/') === 0 || req.path === '/api/internal/sync/player-media' || req.path === '/api/internal/sync/player-font') {
return next(); return next();
} }
return requireAuth(req, res, next); return requireAuth(req, res, function () {
if (req.currentUser && req.currentUser.mustChangePassword && req.path !== '/account' && req.path !== '/account/password' && req.path !== '/account/sessions/revoke' && req.path !== '/logout') {
return res.redirect('/account?message=' + encodeURIComponent('Please change your password before continuing.'));
}
next();
});
}); });
}; };
+9
View File
@@ -0,0 +1,9 @@
// Forward unmatched requests to the shared error-page handler.
module.exports = function registerNotFoundHandler(app) {
app.use(function (_req, _res, next) {
const error = new Error('Page not found.');
error.statusCode = 404;
next(error);
});
};
+5
View File
@@ -9,6 +9,8 @@ function routePath(...segments) {
module.exports = { module.exports = {
renderLoginPage: require(routePath('auth', 'login')), renderLoginPage: require(routePath('auth', 'login')),
renderAccountPage: require(routePath('account', 'password')), renderAccountPage: require(routePath('account', 'password')),
renderSettingsPage: require(routePath('settings', 'index')),
renderAboutPage: require(routePath('settings', 'about', 'index')),
renderUsersPage: require(routePath('settings', 'users', 'list')), renderUsersPage: require(routePath('settings', 'users', 'list')),
renderUsersAddPage: require(routePath('settings', 'users', 'add')), renderUsersAddPage: require(routePath('settings', 'users', 'add')),
renderUsersEditPage: require(routePath('settings', 'users', 'edit')), renderUsersEditPage: require(routePath('settings', 'users', 'edit')),
@@ -27,6 +29,9 @@ module.exports = {
renderRssFeedsPage: require(routePath('data-sources', 'rss-feeds', 'list')), renderRssFeedsPage: require(routePath('data-sources', 'rss-feeds', 'list')),
renderRssFeedAddPage: require(routePath('data-sources', 'rss-feeds', 'add')), renderRssFeedAddPage: require(routePath('data-sources', 'rss-feeds', 'add')),
renderRssFeedEditPage: require(routePath('data-sources', 'rss-feeds', 'edit')), renderRssFeedEditPage: require(routePath('data-sources', 'rss-feeds', 'edit')),
renderWeatherLocationsPage: require(routePath('data-sources', 'weather', 'list')),
renderWeatherLocationAddPage: require(routePath('data-sources', 'weather', 'add')),
renderWeatherLocationEditPage: require(routePath('data-sources', 'weather', 'edit')),
renderScreensPage: require(routePath('signage', 'screens', 'list')), renderScreensPage: require(routePath('signage', 'screens', 'list')),
renderScreenFormPage: require(routePath('signage', 'screens', 'add')), renderScreenFormPage: require(routePath('signage', 'screens', 'add')),
renderScreenEditPage: require(routePath('signage', 'screens', 'edit')), renderScreenEditPage: require(routePath('signage', 'screens', 'edit')),

Some files were not shown because too many files have changed in this diff Show More