Backend:
- 3 migrations: system_users (citext email único, password_hash, active),
system_sessions (UUID + expires_at + revoked_at), ALTER audit_log con
actor_user_id/actor_email/actor_ip/action_path/summary y entity_id NULL.
- src/modules/auth/: usersRepo, sessionsRepo, passwords (bcrypt cost 10),
auth (login/logout), bootstrap (crea admin desde ADMIN_EMAIL/PASSWORD si
la tabla está vacía). 4 tests passwords (hash distinto cada vez, verify
rechaza, longitud mínima 8).
- middleware/requireAuth: lee cookie bot_session, busca sesión activa,
popula req.user. Whitelist: /styles, /components, /lib, /login, /, /home
y SPA paths (HTML carga sin auth, el JS gatea con /api/auth/me).
- middleware/auditWriter: registra cada POST/PUT/DELETE 2xx en audit_log
con req.user, IP, body redactado (passwords/tokens/secrets). Handlers
pueden enriquecer summary via res.locals.audit.
- routes: /api/auth/{login,logout,me} (cookie httpOnly + DB session),
/api/system-users (ABM con guards: cant_delete_self, cant_deactivate_self,
email único, password ≥ 8), /api/audit-log + /api/audit-log/actors.
- src/app.js: orden estricto — webhooks (sin auth) → auth routes (sin auth)
→ /login HTML → static → SPA HTML → requireAuth + auditWriter → API admin.
Bootstrap del primer admin se ejecuta en index.js antes de listen. Usa
ADMIN_EMAIL/ADMIN_PASSWORD/ADMIN_NAME del .env. Si no están seteados y la
tabla está vacía, warn y exit (nadie puede loguearse).
Frontend:
- /login.html + /login.js: form simple, POST a /api/auth/login con
credentials:include, redirect a ?next=... o /home. Si ya hay sesión
activa, va directo a /home.
- public/app.js gate: chequea /api/auth/me antes de initRouter; sin sesión
redirige a /login?next=<path>. window.__USER__ disponible para shell.
- ops-shell: nav agrega "Operadores" + "Actividad". Header derecha muestra
email del user + botón Salir (POST /api/auth/logout + redirect /login).
- system-users-crud: CRUD lista/form (estilo settings). Crear/editar/
cambiar password/eliminar. UI muestra badge "Vos" + bloquea eliminarse
ni desactivarse a uno mismo.
- audit-log: tabla read-only con filtros (actor, entity_type, since,
search), paginación 50, badges por acción, modal de detalles con
changes JSON. /api/audit-log/actors pobla el dropdown de operadores.
Smoke E2E: login OK + cookie set, /me 200; logout → /me 401; settings POST
genera fila en audit_log con actor_email + action_path; ABM crea/borra
operadores con guards; intentar borrarse devuelve 400 cant_delete_self.
161/161 tests verde (pre-existentes 157 + 4 passwords nuevos).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
131 lines
3.6 KiB
JavaScript
131 lines
3.6 KiB
JavaScript
import { emit } from "./bus.js";
|
|
|
|
// Mapeo de rutas a vistas
|
|
const ROUTES = [
|
|
{ pattern: /^\/$/, view: "home", params: [] },
|
|
{ pattern: /^\/home$/, view: "home", params: [] },
|
|
{ pattern: /^\/chat$/, view: "chat", params: [] },
|
|
{ pattern: /^\/conversaciones$/, view: "conversations", params: [] },
|
|
{ pattern: /^\/usuarios$/, view: "users", params: [] },
|
|
{ pattern: /^\/usuarios\/([^/]+)$/, view: "users", params: ["id"] },
|
|
{ pattern: /^\/productos$/, view: "products", params: [] },
|
|
{ pattern: /^\/productos\/([^/]+)$/, view: "products", params: ["id"] },
|
|
{ pattern: /^\/equivalencias$/, view: "aliases", params: [] },
|
|
{ pattern: /^\/crosssell$/, view: "crosssell", params: [] },
|
|
{ pattern: /^\/crosssell\/([^/]+)$/, view: "crosssell", params: ["id"] },
|
|
{ pattern: /^\/cantidades$/, view: "quantities", params: [] },
|
|
{ pattern: /^\/pedidos$/, view: "orders", params: [] },
|
|
{ pattern: /^\/pedidos\/([^/]+)$/, view: "orders", params: ["id"] },
|
|
{ pattern: /^\/config-prompts$/, view: "prompts", params: [] },
|
|
{ pattern: /^\/atencion-humana$/, view: "takeovers", params: [] },
|
|
{ pattern: /^\/configuracion$/, view: "settings", params: [] },
|
|
{ pattern: /^\/operadores$/, view: "operadores", params: [] },
|
|
{ pattern: /^\/actividad$/, view: "actividad", params: [] },
|
|
];
|
|
|
|
// Mapeo de vistas a rutas base (para navegación sin parámetros)
|
|
const VIEW_TO_PATH = {
|
|
home: "/home",
|
|
chat: "/chat",
|
|
conversations: "/conversaciones",
|
|
users: "/usuarios",
|
|
products: "/productos",
|
|
aliases: "/equivalencias",
|
|
crosssell: "/crosssell",
|
|
quantities: "/cantidades",
|
|
orders: "/pedidos",
|
|
prompts: "/config-prompts",
|
|
takeovers: "/atencion-humana",
|
|
settings: "/configuracion",
|
|
operadores: "/operadores",
|
|
actividad: "/actividad",
|
|
};
|
|
|
|
/**
|
|
* Parsea el pathname y devuelve { view, params }
|
|
*/
|
|
export function parseRoute(pathname) {
|
|
const path = pathname || "/";
|
|
|
|
for (const route of ROUTES) {
|
|
const match = path.match(route.pattern);
|
|
if (match) {
|
|
const params = {};
|
|
route.params.forEach((name, i) => {
|
|
params[name] = match[i + 1];
|
|
});
|
|
return { view: route.view, params };
|
|
}
|
|
}
|
|
|
|
// Fallback a home si no matchea ninguna ruta
|
|
return { view: "home", params: {} };
|
|
}
|
|
|
|
/**
|
|
* Obtiene la ruta actual del browser
|
|
*/
|
|
export function getCurrentRoute() {
|
|
return parseRoute(window.location.pathname);
|
|
}
|
|
|
|
/**
|
|
* Navega a una nueva ruta sin recargar la página
|
|
*/
|
|
export function navigate(path, { replace = false } = {}) {
|
|
if (replace) {
|
|
history.replaceState(null, "", path);
|
|
} else {
|
|
history.pushState(null, "", path);
|
|
}
|
|
|
|
const route = parseRoute(path);
|
|
emit("router:change", route);
|
|
}
|
|
|
|
/**
|
|
* Navega a una vista (sin parámetros)
|
|
*/
|
|
export function navigateToView(view) {
|
|
const path = VIEW_TO_PATH[view] || "/";
|
|
navigate(path);
|
|
}
|
|
|
|
/**
|
|
* Navega a una vista con un ID específico
|
|
*/
|
|
export function navigateToItem(view, id) {
|
|
const basePath = VIEW_TO_PATH[view];
|
|
if (!basePath) return;
|
|
|
|
const path = id ? `${basePath}/${encodeURIComponent(id)}` : basePath;
|
|
navigate(path);
|
|
}
|
|
|
|
/**
|
|
* Inicializa el router - debe llamarse después de que los componentes estén listos
|
|
*/
|
|
export function initRouter() {
|
|
// Escuchar popstate (botón atrás/adelante del browser)
|
|
window.addEventListener("popstate", () => {
|
|
const route = getCurrentRoute();
|
|
emit("router:change", route);
|
|
});
|
|
|
|
// Emitir la ruta inicial
|
|
const route = getCurrentRoute();
|
|
emit("router:change", route);
|
|
|
|
return route;
|
|
}
|
|
|
|
export const router = {
|
|
parseRoute,
|
|
getCurrentRoute,
|
|
navigate,
|
|
navigateToView,
|
|
navigateToItem,
|
|
initRouter,
|
|
VIEW_TO_PATH,
|
|
};
|