Compare commits

..

No commits in common. "pages" and "main" have entirely different histories.
pages ... main

4 changed files with 266 additions and 31 deletions

10
package-lock.json generated Normal file
View File

@ -0,0 +1,10 @@
{
"name": "biot-zhambyl",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "biot-zhambyl"
}
}
}

View File

@ -1,11 +0,0 @@
<!doctype html>
<html lang="ru">
<head>
<meta charset="utf-8">
<meta http-equiv="refresh" content="0; url=https://code.vibe42.kz/vscode/genadis/kak-ya-mogu-skopirovat-chuzh/proxy/3000/">
<title>Перенаправление...</title>
</head>
<body>
<p>Перенаправляем на сайт... <a href="https://code.vibe42.kz/vscode/genadis/kak-ya-mogu-skopirovat-chuzh/proxy/3000/">Если не перенаправило, нажмите здесь</a></p>
</body>
</html>

View File

@ -4,9 +4,6 @@ let events = { biot: [], ctpsr_main: [], gloves: [] };
let currentFilter = 'все'; let currentFilter = 'все';
let currentUser = null; let currentUser = null;
// API_URL пустой — используем относительные пути
const API_URL = '';
// Проверка авторизации при загрузке // Проверка авторизации при загрузке
async function checkAuth() { async function checkAuth() {
const token = localStorage.getItem('token'); const token = localStorage.getItem('token');
@ -39,7 +36,8 @@ function showApp() {
async function login(username, password) { async function login(username, password) {
try { try {
const res = await fetch(API_URL + '/service/login?username=' + encodeURIComponent(username) + '&password=' + encodeURIComponent(password), { // Используем GET с query параметрами — proxy пропускает GET
const res = await fetch('/service/login?username=' + encodeURIComponent(username) + '&password=' + encodeURIComponent(password), {
method: 'GET' method: 'GET'
}); });
const data = await res.json(); const data = await res.json();
@ -49,8 +47,6 @@ async function login(username, password) {
localStorage.setItem('userName', data.name); localStorage.setItem('userName', data.name);
localStorage.setItem('userId', username); localStorage.setItem('userId', username);
showApp(); showApp();
await loadEvents();
render();
} else { } else {
alert(data.error || 'Ошибка входа'); alert(data.error || 'Ошибка входа');
} }
@ -58,10 +54,6 @@ async function login(username, password) {
alert('Ошибка соединения: ' + e.message); alert('Ошибка соединения: ' + e.message);
} }
} }
} catch (e) {
alert('Ошибка соединения: ' + e.message);
}
}
function logout() { function logout() {
localStorage.removeItem('token'); localStorage.removeItem('token');
@ -96,7 +88,7 @@ function closeAdmin() {
async function loadUsers() { async function loadUsers() {
try { try {
const res = await fetch(API_URL + '/service/users', { const res = await fetch('/service/users', {
headers: { 'Authorization': 'Bearer ' + currentUser.token } headers: { 'Authorization': 'Bearer ' + currentUser.token }
}); });
if (!res.ok) { if (!res.ok) {
@ -129,7 +121,7 @@ document.getElementById('add-user-form').addEventListener('submit', async functi
const password = document.getElementById('new-user-password').value.trim(); const password = document.getElementById('new-user-password').value.trim();
try { try {
const res = await fetch(API_URL + '/service/users', { const res = await fetch('/service/users', {
method: 'POST', method: 'POST',
headers: { headers: {
'Content-Type': 'application/json', 'Content-Type': 'application/json',
@ -153,7 +145,7 @@ document.getElementById('add-user-form').addEventListener('submit', async functi
async function deleteUser(id) { async function deleteUser(id) {
if (!confirm('Удалить пользователя ' + id + '?')) return; if (!confirm('Удалить пользователя ' + id + '?')) return;
try { try {
const res = await fetch(API_URL + '/service/users/' + id, { const res = await fetch('/service/users/' + id, {
method: 'DELETE', method: 'DELETE',
headers: { 'Authorization': 'Bearer ' + currentUser.token } headers: { 'Authorization': 'Bearer ' + currentUser.token }
}); });
@ -174,9 +166,9 @@ async function loadEvents() {
try { try {
const headers = { 'Authorization': 'Bearer ' + currentUser.token }; const headers = { 'Authorization': 'Bearer ' + currentUser.token };
const [biotRes, ctpsrRes, glovesRes] = await Promise.all([ const [biotRes, ctpsrRes, glovesRes] = await Promise.all([
fetch(API_URL + '/service/events?tab=biot', { headers }), fetch('/service/events?tab=biot', { headers }),
fetch(API_URL + '/service/events?tab=ctpsr_main', { headers }), fetch('/service/events?tab=ctpsr_main', { headers }),
fetch(API_URL + '/service/events?tab=gloves', { headers }) fetch('/service/events?tab=gloves', { headers })
]); ]);
events.biot = await biotRes.json(); events.biot = await biotRes.json();
events.ctpsr_main = await ctpsrRes.json(); events.ctpsr_main = await ctpsrRes.json();
@ -444,7 +436,7 @@ function addNew() {
async function deleteEvent(id) { async function deleteEvent(id) {
if (!confirm('Вы уверены, что хотите удалить эту запись?')) return; if (!confirm('Вы уверены, что хотите удалить эту запись?')) return;
var key = currentSubtab || currentTab; var key = currentSubtab || currentTab;
await fetch(API_URL + '/service/events/' + id + '?tab=' + key, { await fetch('/service/events/' + id + '?tab=' + key, {
method: 'DELETE', method: 'DELETE',
headers: { 'Authorization': 'Bearer ' + currentUser.token } headers: { 'Authorization': 'Bearer ' + currentUser.token }
}); });
@ -495,7 +487,7 @@ document.getElementById('form').addEventListener('submit', async function(e) {
console.log('Data to save:', data); console.log('Data to save:', data);
var url = id ? API_URL + '/service/events/' + id + '?tab=' + key : API_URL + '/service/events?tab=' + key; var url = id ? '/service/events/' + id + '?tab=' + key : '/service/events?tab=' + key;
console.log('POST to:', url); console.log('POST to:', url);
try { try {
@ -553,7 +545,7 @@ async function testApi() {
return; return;
} }
try { try {
const res = await fetch(API_URL + '/service/events?tab=biot', { const res = await fetch('/service/events?tab=biot', {
method: 'POST', method: 'POST',
headers: { headers: {
'Content-Type': 'application/json', 'Content-Type': 'application/json',

246
server.js
View File

@ -1 +1,245 @@
404: Not Found const http = require("http");
const fs = require("fs");
const path = require("path");
const PORT = process.env.PORT || 3000;
const DATA = path.join(__dirname, "data.json");
const USERS_FILE = path.join(__dirname, "users.json");
// Простая авторизация по токенам
function loadUsers() {
try { return JSON.parse(fs.readFileSync(USERS_FILE, "utf8")); } catch (_) {
return { users: [{ id: "admin", name: "Админ", token: "tok_" + Date.now() }] };
}
}
function saveUsers(users) {
fs.writeFileSync(USERS_FILE, JSON.stringify(users, null, 2));
}
function readData() {
try { return JSON.parse(fs.readFileSync(DATA, "utf8")); } catch (_) { return { events: [] }; }
}
function writeData(data) {
fs.writeFileSync(DATA, JSON.stringify(data, null, 2));
}
function body(req) {
return new Promise((resolve) => {
let s = "";
req.on("data", (c) => (s += c));
req.on("end", () => { try { resolve(JSON.parse(s || "{}")); } catch (_) { resolve({}); } });
});
}
function checkAuth(req) {
const token = req.headers.authorization?.replace("Bearer ", "");
if (!token) return null;
const users = loadUsers();
return users.users.find(u => u.token === token) || null;
}
http.createServer(async (req, res) => {
res.setHeader("Access-Control-Allow-Origin", "*");
res.setHeader("Access-Control-Allow-Methods", "GET, POST, PUT, DELETE, OPTIONS");
res.setHeader("Access-Control-Allow-Headers", "Content-Type, Authorization");
if (req.method === "OPTIONS") {
res.writeHead(200);
return res.end();
}
const urlPath = req.url.split("?")[0];
const queryString = req.url.split("?")[1] || "";
const query = new URLSearchParams(queryString);
// API: Авторизация (GET и POST для работы через proxy)
if ((req.method === "POST" || req.method === "GET") && urlPath === "/service/login") {
const username = query.get("username") || (await body(req)).username;
const password = query.get("password") || (await body(req)).password;
const users = loadUsers();
const user = users.users.find(u => u.id === username && u.password === password);
if (user) {
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true, token: user.token, name: user.name }));
}
res.writeHead(401, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Неверный логин или пароль" }));
}
// API: Получить текущего пользователя
if (req.method === "GET" && urlPath === "/service/me") {
const user = checkAuth(req);
if (user) {
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ id: user.id, name: user.name, isAdmin: user.id === 'admin' }));
}
res.writeHead(401, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Не авторизован" }));
}
// API: Получить всех пользователей (только admin)
if (req.method === "GET" && urlPath === "/service/users") {
const user = checkAuth(req);
if (!user || user.id !== 'admin') {
res.writeHead(403, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Только для администратора" }));
}
const users = loadUsers();
// Не отдаём пароли и токены
const safeUsers = users.users.map(u => ({ id: u.id, name: u.name }));
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify(safeUsers));
}
// API: Добавить пользователя (только admin)
if (req.method === "POST" && urlPath === "/service/users") {
const user = checkAuth(req);
if (!user || user.id !== 'admin') {
res.writeHead(403, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Только для администратора" }));
}
const { id, name, password } = await body(req);
if (!id || !name || !password) {
res.writeHead(400, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Нужны id, name и password" }));
}
const users = loadUsers();
if (users.users.find(u => u.id === id)) {
res.writeHead(400, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Пользователь уже существует" }));
}
const token = "tok_" + id + "_" + Date.now() + "_" + Math.random().toString(36).slice(2, 8);
users.users.push({ id, name, password, token });
saveUsers(users);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true, user: { id, name, password, token } }));
}
// API: Удалить пользователя (только admin, нельзя удалить admin и себя)
if (req.method === "DELETE" && urlPath.startsWith("/service/users/")) {
const user = checkAuth(req);
if (!user || user.id !== 'admin') {
res.writeHead(403, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Только для администратора" }));
}
const idToDelete = urlPath.split("/")[3];
if (idToDelete === 'admin') {
res.writeHead(400, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Нельзя удалить admin" }));
}
const users = loadUsers();
users.users = users.users.filter(u => u.id !== idToDelete);
saveUsers(users);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true }));
}
// API: Изменить пароль пользователя (только admin)
if (req.method === "PUT" && urlPath.startsWith("/service/users/")) {
const user = checkAuth(req);
if (!user || user.id !== 'admin') {
res.writeHead(403, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Только для администратора" }));
}
const userId = urlPath.split("/")[3];
const { password } = await body(req);
if (!password) {
res.writeHead(400, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Нужен password" }));
}
const users = loadUsers();
const u = users.users.find(u => u.id === userId);
if (!u) {
res.writeHead(404, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Пользователь не найден" }));
}
u.password = password;
saveUsers(users);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true }));
}
// API: GET /service/events
if (req.method === "GET" && urlPath === "/service/events") {
const tab = query.get("tab") || "biot";
const data = readData();
const events = data[tab + "Events"] || [];
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify(events));
}
// API: POST /service/events (требуется авторизация)
if (req.method === "POST" && urlPath === "/service/events") {
const user = checkAuth(req);
if (!user) {
res.writeHead(401, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Требуется авторизация" }));
}
const tab = query.get("tab") || "biot";
console.log("POST /service/events tab:", tab, "user:", user.name);
const data = readData();
const event = await body(req);
console.log("Event data:", event);
event.id = Date.now();
event.tab = tab;
event.createdBy = user.id;
const arrayName = tab + "Events";
if (!data[arrayName]) data[arrayName] = [];
data[arrayName].push(event);
console.log("Saving to:", arrayName, "Total:", data[arrayName].length);
writeData(data);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true, event }));
}
// API: PUT /service/events/:id (требуется авторизация)
if (req.method === "PUT" && urlPath.startsWith("/service/events/")) {
const user = checkAuth(req);
if (!user) {
res.writeHead(401, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Требуется авторизация" }));
}
const tab = query.get("tab") || "biot";
const id = parseInt(urlPath.split("/")[3]);
const data = readData();
const events = data[tab + "Events"] || [];
const idx = events.findIndex(e => e.id === id);
if (idx !== -1) {
events[idx] = { ...events[idx], ...await body(req), updatedBy: user.id };
data[tab + "Events"] = events;
writeData(data);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true }));
}
res.writeHead(404);
return res.end(JSON.stringify({ error: "Не найдено" }));
}
// API: DELETE /service/events/:id (требуется авторизация)
if (req.method === "DELETE" && urlPath.startsWith("/service/events/")) {
const user = checkAuth(req);
if (!user) {
res.writeHead(401, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ error: "Требуется авторизация" }));
}
const tab = query.get("tab") || "biot";
const id = parseInt(urlPath.split("/")[3]);
const data = readData();
data[tab + "Events"] = (data[tab + "Events"] || []).filter(e => e.id !== id);
writeData(data);
res.writeHead(200, { "Content-Type": "application/json" });
return res.end(JSON.stringify({ ok: true }));
}
// Статика
let file = urlPath === "/" ? "/index.html" : urlPath;
const full = path.join(__dirname, file);
if (full.startsWith(__dirname) && fs.existsSync(full) && fs.statSync(full).isFile()) {
const ext = path.extname(full);
const type = ext === ".css" ? "text/css" : ext === ".js" ? "application/javascript" : "text/html";
res.writeHead(200, { "Content-Type": type + "; charset=utf-8" });
return res.end(fs.readFileSync(full));
}
res.writeHead(404);
res.end("Not found");
}).listen(PORT, () => console.log("Сервер запущен на порту " + PORT));