All checks were successful
CD / Build and push images (push) Successful in 10m39s
CI / Lint, typecheck, test (push) Successful in 3m12s
CI / Auth e2e pack (push) Successful in 4m9s
CI / Build container images (push) Has been skipped
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m18s
CD / Promote to Int (push) Successful in 11s
A signed-in account can export all of its own data — profile, a list of its memberships/grants, and the Markdown of its personal pond plus the shared ponds it owns — as one ZIP. Foreign content never appears: only owned ponds are bundled and the per-page read filter (reused from #65) runs for each. - Reuse the conversion-job queue as the async carrier: a `data_export` job whose worker branch resolves DataExportService via a token (no DI cycle), builds the ZIP, and stores it with an `expiresAt`. The download link 404s past expiry and an hourly scheduled purge drops the bytes (data minimization, security.md §Privacy). - Extract ExportService.appendPondMarkdown so the pond ZIP (#65) and the data export share one read-filtered pond archiver. - Rate-limit requests per account (RateLimitService); POST /users/me/data-export enqueues, GET /jobs/:id(/result) poll/download. - Settings UI "Export my data" (de+en); web share pollJob/downloadJobResult between the document and data export hooks. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
257 lines
8.3 KiB
TypeScript
257 lines
8.3 KiB
TypeScript
import { zodResolver } from '@hookform/resolvers/zod';
|
|
import { changePasswordInputSchema, updateProfileInputSchema } from '@dorfteich/shared';
|
|
import { useMutation, useQuery, useQueryClient } from '@tanstack/react-query';
|
|
import { useState } from 'react';
|
|
import { useForm } from 'react-hook-form';
|
|
import { useTranslation } from 'react-i18next';
|
|
|
|
import { useAuth } from '../auth/auth-context';
|
|
import { Field, FormError, FormSuccess, applyFieldErrors } from '../components/forms';
|
|
import { useDataExport } from '../export/use-data-export';
|
|
import { apiDelete, apiGet, apiPatch, apiPost } from '../lib/api';
|
|
|
|
interface SessionView {
|
|
id: string;
|
|
createdAt: string;
|
|
lastSeenAt: string;
|
|
userAgent: string | null;
|
|
current: boolean;
|
|
}
|
|
|
|
export function SettingsPage(): React.JSX.Element {
|
|
const { t } = useTranslation();
|
|
return (
|
|
<>
|
|
<h1>{t('settings:title')}</h1>
|
|
<ProfileSection />
|
|
<PasswordSection />
|
|
<SessionsSection />
|
|
<DataExportSection />
|
|
</>
|
|
);
|
|
}
|
|
|
|
function DataExportSection(): React.JSX.Element {
|
|
const { t, i18n } = useTranslation();
|
|
const { status, expiresAt, request, download } = useDataExport();
|
|
|
|
const formatTime = (iso: string): string =>
|
|
new Intl.DateTimeFormat(i18n.language, { dateStyle: 'medium', timeStyle: 'short' }).format(
|
|
new Date(iso),
|
|
);
|
|
|
|
return (
|
|
<section className="settings-section">
|
|
<h2>{t('settings:dataExport.title')}</h2>
|
|
<p className="sidebar__hint">{t('settings:dataExport.description')}</p>
|
|
{status === 'error' && (
|
|
<p className="form-banner form-banner--error" role="alert">
|
|
{t('settings:dataExport.failed')}
|
|
</p>
|
|
)}
|
|
{status === 'rateLimited' && (
|
|
<p className="form-banner form-banner--error" role="alert">
|
|
{t('settings:dataExport.rateLimited')}
|
|
</p>
|
|
)}
|
|
{status === 'ready' ? (
|
|
<>
|
|
<FormSuccess message={t('settings:dataExport.ready')} />
|
|
<button type="button" className="button" onClick={download}>
|
|
{t('settings:dataExport.download')}
|
|
</button>
|
|
{expiresAt && (
|
|
<p className="sidebar__hint">
|
|
{t('settings:dataExport.expiresHint', { when: formatTime(expiresAt) })}
|
|
</p>
|
|
)}
|
|
</>
|
|
) : (
|
|
<button type="button" className="button" onClick={request} disabled={status === 'busy'}>
|
|
{status === 'busy'
|
|
? t('settings:dataExport.preparing')
|
|
: t('settings:dataExport.request')}
|
|
</button>
|
|
)}
|
|
</section>
|
|
);
|
|
}
|
|
|
|
function ProfileSection(): React.JSX.Element {
|
|
const { t, i18n } = useTranslation();
|
|
const { user, refresh } = useAuth();
|
|
const [error, setError] = useState<unknown>(null);
|
|
const [saved, setSaved] = useState(false);
|
|
|
|
const form = useForm<{ displayName?: string; locale?: 'de' | 'en' }>({
|
|
resolver: zodResolver(updateProfileInputSchema),
|
|
values: { displayName: user?.displayName, locale: user?.locale },
|
|
});
|
|
|
|
const onSubmit = form.handleSubmit(async (input) => {
|
|
setError(null);
|
|
setSaved(false);
|
|
try {
|
|
await apiPatch('/users/me', input);
|
|
// The new language applies immediately, before the refetch lands.
|
|
if (input.locale) await i18n.changeLanguage(input.locale);
|
|
await refresh();
|
|
setSaved(true);
|
|
} catch (err) {
|
|
setError(err);
|
|
applyFieldErrors(err, (name, fieldError) =>
|
|
form.setError(name as 'displayName' | 'locale', fieldError),
|
|
);
|
|
}
|
|
});
|
|
|
|
return (
|
|
<section className="settings-section">
|
|
<h2>{t('settings:profile.title')}</h2>
|
|
<form onSubmit={onSubmit} noValidate>
|
|
<FormError error={error} />
|
|
<FormSuccess message={saved ? t('settings:profile.saved') : null} />
|
|
<Field
|
|
label={t('settings:profile.displayName')}
|
|
error={form.formState.errors.displayName?.message}
|
|
>
|
|
<input type="text" autoComplete="name" {...form.register('displayName')} />
|
|
</Field>
|
|
<Field label={t('settings:profile.locale')}>
|
|
<select {...form.register('locale')}>
|
|
<option value="de">{t('settings:profile.locales.de')}</option>
|
|
<option value="en">{t('settings:profile.locales.en')}</option>
|
|
</select>
|
|
</Field>
|
|
<button type="submit" className="button" disabled={form.formState.isSubmitting}>
|
|
{t('settings:profile.save')}
|
|
</button>
|
|
</form>
|
|
</section>
|
|
);
|
|
}
|
|
|
|
function PasswordSection(): React.JSX.Element {
|
|
const { t } = useTranslation();
|
|
const [error, setError] = useState<unknown>(null);
|
|
const [changed, setChanged] = useState(false);
|
|
|
|
const form = useForm<{ currentPassword: string; newPassword: string }>({
|
|
resolver: zodResolver(changePasswordInputSchema),
|
|
});
|
|
|
|
const onSubmit = form.handleSubmit(async (input) => {
|
|
setError(null);
|
|
setChanged(false);
|
|
try {
|
|
await apiPost('/users/me/change-password', input);
|
|
form.reset();
|
|
setChanged(true);
|
|
} catch (err) {
|
|
setError(err);
|
|
}
|
|
});
|
|
|
|
return (
|
|
<section className="settings-section">
|
|
<h2>{t('settings:password.title')}</h2>
|
|
<form onSubmit={onSubmit} noValidate>
|
|
<FormError error={error} />
|
|
<FormSuccess message={changed ? t('settings:password.changed') : null} />
|
|
<Field
|
|
label={t('settings:password.current')}
|
|
error={form.formState.errors.currentPassword?.message}
|
|
>
|
|
<input
|
|
type="password"
|
|
autoComplete="current-password"
|
|
{...form.register('currentPassword')}
|
|
/>
|
|
</Field>
|
|
<Field
|
|
label={t('settings:password.new')}
|
|
hint={t('auth:signup.passwordHint')}
|
|
error={form.formState.errors.newPassword?.message}
|
|
>
|
|
<input type="password" autoComplete="new-password" {...form.register('newPassword')} />
|
|
</Field>
|
|
<button type="submit" className="button" disabled={form.formState.isSubmitting}>
|
|
{t('settings:password.submit')}
|
|
</button>
|
|
</form>
|
|
</section>
|
|
);
|
|
}
|
|
|
|
function SessionsSection(): React.JSX.Element {
|
|
const { t, i18n } = useTranslation();
|
|
const queryClient = useQueryClient();
|
|
const sessions = useQuery({
|
|
queryKey: ['sessions'],
|
|
queryFn: () => apiGet<SessionView[]>('/users/me/sessions'),
|
|
});
|
|
const invalidate = () => queryClient.invalidateQueries({ queryKey: ['sessions'] });
|
|
|
|
const revoke = useMutation({
|
|
mutationFn: (id: string) => apiDelete(`/users/me/sessions/${id}`),
|
|
onSuccess: invalidate,
|
|
});
|
|
const revokeOthers = useMutation({
|
|
mutationFn: () => apiDelete('/users/me/sessions'),
|
|
onSuccess: invalidate,
|
|
});
|
|
|
|
const formatTime = (iso: string) =>
|
|
new Intl.DateTimeFormat(i18n.language, { dateStyle: 'medium', timeStyle: 'short' }).format(
|
|
new Date(iso),
|
|
);
|
|
|
|
const others = (sessions.data ?? []).filter((s) => !s.current);
|
|
|
|
return (
|
|
<section className="settings-section">
|
|
<h2>{t('settings:sessions.title')}</h2>
|
|
<table className="table">
|
|
<thead>
|
|
<tr>
|
|
<th>{t('settings:sessions.device')}</th>
|
|
<th>{t('settings:sessions.created')}</th>
|
|
<th>{t('settings:sessions.lastSeen')}</th>
|
|
<th></th>
|
|
</tr>
|
|
</thead>
|
|
<tbody>
|
|
{(sessions.data ?? []).map((session) => (
|
|
<tr key={session.id}>
|
|
<td>
|
|
{session.userAgent ?? '—'}
|
|
{session.current && <span className="badge">{t('settings:sessions.current')}</span>}
|
|
</td>
|
|
<td>{formatTime(session.createdAt)}</td>
|
|
<td>{formatTime(session.lastSeenAt)}</td>
|
|
<td>
|
|
{!session.current && (
|
|
<button
|
|
type="button"
|
|
className="linklike"
|
|
onClick={() => revoke.mutate(session.id)}
|
|
>
|
|
{t('settings:sessions.revoke')}
|
|
</button>
|
|
)}
|
|
</td>
|
|
</tr>
|
|
))}
|
|
</tbody>
|
|
</table>
|
|
{others.length > 0 ? (
|
|
<button type="button" className="button" onClick={() => revokeOthers.mutate()}>
|
|
{t('settings:sessions.revokeAll')}
|
|
</button>
|
|
) : (
|
|
<p className="sidebar__hint">{t('settings:sessions.empty')}</p>
|
|
)}
|
|
</section>
|
|
);
|
|
}
|