Compare commits

..

2 commits

11 changed files with 383 additions and 84 deletions

View file

@ -63,13 +63,15 @@ async function proxy(request: NextRequest, pathSegments: string[]) {
const search = url.search;
const isLogin = request.method === "POST" && targetPath === "v1/auth/login";
const isLogout = request.method === "POST" && targetPath === "v1/auth/logout";
const isSse =
request.method === "GET" && targetPath === "v1/admin/viewers/events";
const headers = new Headers();
const contentType = request.headers.get("content-type");
if (contentType) headers.set("content-type", contentType);
const cookie = request.headers.get("cookie");
if (cookie) headers.set("cookie", cookie);
headers.set("accept", "application/json");
headers.set("accept", isSse ? "text/event-stream" : "application/json");
const body =
request.method !== "GET" && request.method !== "HEAD"
@ -86,6 +88,10 @@ async function proxy(request: NextRequest, pathSegments: string[]) {
headers,
body,
redirect: "manual",
// SSE must not be aborted when the proxy function "returns" the stream
...(isSse
? { cache: "no-store" as RequestCache, signal: request.signal }
: {}),
});
// Special-case auth so the session cookie is owned by admin.vonas.nl
@ -130,6 +136,34 @@ async function proxy(request: NextRequest, pathSegments: string[]) {
return response;
}
if (isSse) {
if (!upstream.ok) {
const errBody = await upstream.arrayBuffer();
return new NextResponse(errBody, {
status: upstream.status,
headers: {
"content-type":
upstream.headers.get("content-type") ?? "application/json",
},
});
}
if (!upstream.body) {
return NextResponse.json(
{ error: { code: "UPSTREAM_ERROR", message: "SSE stream missing body" } },
{ status: 502 }
);
}
return new NextResponse(upstream.body, {
status: 200,
headers: {
"Content-Type": "text/event-stream; charset=utf-8",
"Cache-Control": "no-cache, no-transform",
Connection: "keep-alive",
"X-Accel-Buffering": "no",
},
});
}
const responseBody = await upstream.arrayBuffer();
const response = new NextResponse(responseBody, { status: upstream.status });
response.headers.set(

View file

@ -417,12 +417,20 @@ export default function DownloadsPage() {
}
const results: SubtitleHit[] = data.results ?? [];
setSubs(results);
const warnings: string[] = Array.isArray(data.warnings) ? data.warnings : [];
if (results[0]) {
const preferred = results.find((r) => r.source === "org") || results[0];
setSelectedSubId(preferred.fileId);
setSelectedSubSource(preferred.source === "org" ? "org" : "com");
if (warnings.length) {
setSubsMsg(`Let op: ${warnings.join(" · ")}`);
}
} else {
setSubsMsg("Geen NL-ondertitels gevonden");
setSubsMsg(
warnings.length
? `Geen NL-ondertitels gevonden (${warnings.join(" · ")})`
: "Geen NL-ondertitels gevonden"
);
}
} finally {
setSubsBusy(false);
@ -666,11 +674,17 @@ export default function DownloadsPage() {
return (b.downloadCount || 0) - (a.downloadCount || 0);
});
setSubs(results);
const warnings: string[] = Array.isArray(data.warnings) ? data.warnings : [];
if (results[0]) {
setSelectedSubId(results[0].fileId);
setSelectedSubSource(results[0].source === "org" ? "org" : "com");
if (warnings.length) setSubsMsg(`Let op: ${warnings.join(" · ")}`);
} else {
setSubsMsg("Geen ondertitels gevonden");
setSubsMsg(
warnings.length
? `Geen ondertitels gevonden (${warnings.join(" · ")})`
: "Geen ondertitels gevonden"
);
}
} finally {
setSubsBusy(false);

View file

@ -194,6 +194,48 @@ export default function ViewersPage() {
.catch(() => undefined);
}, [load]);
// Live updates via SSE (device link, login lock, CRUD). Geen interval-poll.
// Overslaan tijdens typen; formuliervelden zitten in aparte state en blijven staan.
useEffect(() => {
let debounce: ReturnType<typeof setTimeout> | null = null;
const isTyping = () => {
const el = document.activeElement;
if (!el || !(el instanceof HTMLElement)) return false;
const tag = el.tagName;
return tag === "INPUT" || tag === "TEXTAREA" || tag === "SELECT" || el.isContentEditable;
};
const scheduleRefresh = () => {
if (isTyping()) return;
if (debounce) clearTimeout(debounce);
debounce = setTimeout(() => {
if (!isTyping()) load();
}, 200);
};
const es = new EventSource("/api/v1/admin/viewers/events");
es.addEventListener("viewers", (ev) => {
try {
const data = JSON.parse((ev as MessageEvent).data) as { type?: string };
if (data.type === "hello") return;
} catch {
// still refresh on malformed payloads
}
scheduleRefresh();
});
// Fallback als je terugkomt op het tabblad (bijv. na korte netwerk-dip)
const onVisibility = () => {
if (document.visibilityState === "visible") scheduleRefresh();
};
document.addEventListener("visibilitychange", onVisibility);
return () => {
if (debounce) clearTimeout(debounce);
es.close();
document.removeEventListener("visibilitychange", onVisibility);
};
}, [load]);
const stats = useMemo(() => {
const active = viewers.filter((v) => v.enabled).length;
const appOn = viewers.filter((v) => v.appAccess).length;
@ -809,6 +851,9 @@ export default function ViewersPage() {
/>
</label>
<div className="sidebar-tools">
<button type="button" onClick={() => load()} title="Lijst opnieuw laden">
Vernieuwen
</button>
{playConfig?.configured ? (
<>
<button type="button" disabled={bulkBusy} onClick={() => void bulkAction("sync-all")}>

View file

@ -154,6 +154,7 @@ export class DownloadService {
imdbId: string | null;
results: SubtitleHit[];
configured: boolean;
warnings?: string[];
}> {
const enabled = await isOpenSubtitlesEnabled();
if (!enabled) {
@ -163,6 +164,7 @@ export class DownloadService {
const comClient = await this.opensubtitles();
const orgClient = this.orgClient();
const configured = true;
const warnings: string[] = [];
const isEpisode =
opts.mediaKind === "episode" ||
@ -198,7 +200,9 @@ export class DownloadService {
const safe = (label: string, p: Promise<SubtitleHit[]>) =>
p.catch((err) => {
console.warn(`[downloads] subtitle search ${label}:`, err instanceof Error ? err.message : err);
const msg = err instanceof Error ? err.message : String(err);
console.warn(`[downloads] subtitle search ${label}:`, msg);
warnings.push(`${label}: ${msg}`);
return [] as SubtitleHit[];
});
@ -225,7 +229,7 @@ export class DownloadService {
}
if (tasks.length === 0) {
return { imdbId, results: [], configured };
return { imdbId, results: [], configured, warnings: warnings.length ? warnings : undefined };
}
const batches = await Promise.all(tasks);
@ -253,7 +257,21 @@ export class DownloadService {
.sort((a, b) => b.score - a.score)
.map((x) => x.r);
return { imdbId, results: scored.slice(0, 40), configured };
// Als .org stil faalde en we alleen .com-hits hebben: expliciet waarschuwen
const hasOrg = scored.some((r) => r.source === "org");
const orgAttempted = !!imdbId || !!query;
if (orgAttempted && !hasOrg && !warnings.some((w) => w.startsWith("org/"))) {
warnings.push(
"org: geen resultaten (controleer IMDb-padding / rest.opensubtitles.org)"
);
}
return {
imdbId,
results: scored.slice(0, 40),
configured,
warnings: warnings.length ? warnings : undefined,
};
}
/** TV/client: resolve IMDb (+ episode query) from media file, then search OS.com/OS.org + local sidecars. */

View file

@ -138,68 +138,77 @@ export class OpenSubtitlesClient {
token ? { Authorization: `Bearer ${token}` } : undefined
);
const res = await fetch(`${this.root()}/api/v1/subtitles?${params}`, { headers });
if (!res.ok) {
const text = await res.text().catch(() => "");
if (res.status === 403 || /cannot consume/i.test(text)) {
const out: SubtitleHit[] = [];
const maxPages = 3;
for (let page = 1; page <= maxPages; page++) {
params.set("page", String(page));
const res = await fetch(`${this.root()}/api/v1/subtitles?${params}`, { headers });
if (!res.ok) {
const text = await res.text().catch(() => "");
if (res.status === 403 || /cannot consume/i.test(text)) {
throw new AppError(
"OPENSUBTITLES",
`OpenSubtitles.com zoeken geweigerd (403). User-Agent "${this.userAgent}" moet exact je API Consumer-naam zijn, of gebruik alleen OS.org-hits.`,
400
);
}
throw new AppError(
"OPENSUBTITLES",
`OpenSubtitles.com zoeken geweigerd (403). User-Agent "${this.userAgent}" moet exact je API Consumer-naam zijn, of gebruik alleen OS.org-hits.`,
`OpenSubtitles.com zoeken mislukt (${res.status}): ${text.slice(0, 160)}`,
400
);
}
throw new AppError(
"OPENSUBTITLES",
`OpenSubtitles.com zoeken mislukt (${res.status}): ${text.slice(0, 160)}`,
400
);
}
const body = (await res.json()) as {
data?: Array<{
attributes?: {
language?: string;
release?: string;
download_count?: number;
hearing_impaired?: boolean;
fps?: number;
feature_details?: {
imdb_id?: number | string;
title?: string;
year?: number;
const body = (await res.json()) as {
total_pages?: number;
data?: Array<{
attributes?: {
language?: string;
release?: string;
download_count?: number;
hearing_impaired?: boolean;
fps?: number;
feature_details?: {
imdb_id?: number | string;
title?: string;
year?: number;
};
files?: Array<{ file_id?: number; file_name?: string }>;
uploader?: { name?: string };
};
files?: Array<{ file_id?: number; file_name?: string }>;
uploader?: { name?: string };
};
}>;
};
}>;
};
const out: SubtitleHit[] = [];
for (const row of body.data ?? []) {
const a = row.attributes;
const file = a?.files?.[0];
if (!file?.file_id) continue;
const featImdb = a?.feature_details?.imdb_id
? String(a.feature_details.imdb_id).replace(/^tt/i, "").replace(/^0+/, "")
: null;
// Movie search: keep IMDb strict. Episode search: parent/series IMDb ≠ episode IMDb.
if (!hasEpisode && featImdb && imdb && featImdb !== imdb) continue;
out.push({
fileId: file.file_id,
language: (a?.language || languages).toLowerCase(),
release: a?.release || file.file_name || "",
fileName: file.file_name || a?.release || `sub-${file.file_id}.srt`,
downloadCount: a?.download_count ?? 0,
hearingImpaired: !!a?.hearing_impaired,
fps: a?.fps ?? null,
uploader: a?.uploader?.name ?? null,
source: "com",
movieName: a?.feature_details?.title ?? null,
movieYear: a?.feature_details?.year ?? null,
imdbId: featImdb || imdb,
});
for (const row of body.data ?? []) {
const a = row.attributes;
const file = a?.files?.[0];
if (!file?.file_id) continue;
const featImdb = a?.feature_details?.imdb_id
? String(a.feature_details.imdb_id).replace(/^tt/i, "").replace(/^0+/, "")
: null;
// Movie search: keep IMDb strict. Episode search: parent/series IMDb ≠ episode IMDb.
if (!hasEpisode && featImdb && imdb && featImdb !== imdb) continue;
out.push({
fileId: file.file_id,
language: (a?.language || languages).toLowerCase(),
release: a?.release || file.file_name || "",
fileName: file.file_name || a?.release || `sub-${file.file_id}.srt`,
downloadCount: a?.download_count ?? 0,
hearingImpaired: !!a?.hearing_impaired,
fps: a?.fps ?? null,
uploader: a?.uploader?.name ?? null,
source: "com",
movieName: a?.feature_details?.title ?? null,
movieYear: a?.feature_details?.year ?? null,
imdbId: featImdb || imdb,
});
}
const totalPages = body.total_pages ?? page;
if (page >= totalPages || out.length >= 50) break;
}
return out.slice(0, 40);
return out.slice(0, 50);
}
async downloadFile(fileId: number): Promise<{ content: Buffer; fileName: string }> {

View file

@ -0,0 +1,18 @@
import { imdbIdsMatch, normalizeImdbForUrl } from "./org-client";
function assert(cond: unknown, msg: string): asserts cond {
if (!cond) throw new Error(msg);
}
assert(normalizeImdbForUrl("tt0468569") === "0468569", "pad Dark Knight");
assert(normalizeImdbForUrl("468569") === "0468569", "pad short id");
assert(normalizeImdbForUrl("0468569") === "0468569", "keep padded");
assert(normalizeImdbForUrl("tt1375666") === "1375666", "no over-pad Inception");
assert(normalizeImdbForUrl("1375666") === "1375666", "7-digit unchanged");
assert(normalizeImdbForUrl("tt0111161") === "0111161", "Shawshank pad");
assert(normalizeImdbForUrl(null) === null, "null");
assert(imdbIdsMatch("0468569", "468569"), "match padded vs short");
assert(imdbIdsMatch("0111161", "111161"), "match shawshank forms");
assert(!imdbIdsMatch("0468569", "1375666"), "different titles");
console.log("opensubtitles/org-client imdb helpers: ok");

View file

@ -22,6 +22,10 @@ type OrgRow = {
/**
* OpenSubtitles.org legacy REST (rest.opensubtitles.org).
* Dutch language id is `dut`. IMDb without "tt". No API key.
*
* Important: unpadded IMDb IDs (e.g. `468569` instead of `0468569`) make OS.org
* respond with `302 Location: https://_/search/imdbid-0468569/...`. Following that
* redirect fails (ENOTFOUND) and searches look empty while .com still works.
*/
export class OpenSubtitlesOrgClient {
private readonly ua = "MediaCluster v1.3.2";
@ -31,17 +35,21 @@ export class OpenSubtitlesOrgClient {
query?: string;
languages?: string;
}): Promise<SubtitleHit[]> {
const lang = toOrgLang(opts.languages || "nl");
const imdbDigits = normalizeImdb(opts.imdbId);
const langs = toOrgLangs(opts.languages || "nl");
const imdbDigits = normalizeImdbForUrl(opts.imdbId);
const urls: string[] = [];
if (imdbDigits) {
urls.push(
`https://rest.opensubtitles.org/search/imdbid-${imdbDigits}/sublanguageid-${lang}`
);
for (const lang of langs) {
urls.push(
`https://rest.opensubtitles.org/search/imdbid-${imdbDigits}/sublanguageid-${lang}`
);
}
} else if (opts.query?.trim()) {
const q = encodeURIComponent(opts.query.trim()).replace(/%20/g, "+");
urls.push(`https://rest.opensubtitles.org/search/query-${q}/sublanguageid-${lang}`);
for (const lang of langs) {
urls.push(`https://rest.opensubtitles.org/search/query-${q}/sublanguageid-${lang}`);
}
}
if (!urls.length) return [];
@ -54,10 +62,11 @@ export class OpenSubtitlesOrgClient {
const rows = await this.fetchSearch(url);
console.info(`[opensubtitles.org] ${url} -> ${rows.length} raw`);
for (const row of rows) {
const hit = mapRow(row, lang);
const hit = mapRow(row, langs[0] || "dut");
if (!hit || seen.has(hit.fileId)) continue;
// Alleen droppen bij expliciet andere IMDb — ontbrekende IDMovieImdb behouden
if (imdbDigits && hit.imdbId && hit.imdbId !== imdbDigits) continue;
// Alleen droppen bij expliciet andere IMDb — ontbrekende IDMovieImdb behouden.
// Vergelijk canoniek (zonder leading zeros): API geeft vaak "468569", URL "0468569".
if (imdbDigits && hit.imdbId && !imdbIdsMatch(hit.imdbId, imdbDigits)) continue;
seen.add(hit.fileId);
out.push(hit);
}
@ -73,15 +82,36 @@ export class OpenSubtitlesOrgClient {
return out.slice(0, 50);
}
private async fetchSearch(url: string): Promise<OrgRow[]> {
private async fetchSearch(url: string, redirectHop = 0): Promise<OrgRow[]> {
const res = await fetch(url, {
headers: {
Accept: "application/json",
"User-Agent": this.ua,
"X-User-Agent": this.ua,
},
redirect: "follow",
// Manual: OS.org sometimes 302's to host "_" with the *correct* padded path.
redirect: "manual",
});
if (res.status >= 300 && res.status < 400) {
const loc = res.headers.get("location") || "";
const pathMatch = loc.match(/\/search\/[^?#\s]+/);
if (pathMatch && redirectHop < 2) {
const fixed = `https://rest.opensubtitles.org${pathMatch[0]}`;
if (fixed !== url) {
console.warn(
`[opensubtitles.org] broken redirect (${res.status} → ${loc}); retry ${fixed}`
);
return this.fetchSearch(fixed, redirectHop + 1);
}
}
throw new AppError(
"OPENSUBTITLES",
`OpenSubtitles.org zoeken mislukt (${res.status} redirect: ${loc.slice(0, 120)})`,
400
);
}
if (!res.ok) {
const text = await res.text().catch(() => "");
throw new AppError(
@ -131,7 +161,7 @@ function mapRow(row: OrgRow, fallbackLang: string): SubtitleHit | null {
if (!Number.isFinite(fileId) || fileId <= 0) return null;
const fps = row.MovieFPS ? parseFloat(row.MovieFPS) : null;
const yearRaw = row.MovieYear ? parseInt(String(row.MovieYear), 10) : NaN;
const imdb = normalizeImdb(row.IDMovieImdb || undefined);
const imdb = normalizeImdbForUrl(row.IDMovieImdb || undefined);
return {
fileId,
language: (row.ISO639 || row.SubLanguageID || fallbackLang || "nl").toLowerCase(),
@ -148,22 +178,38 @@ function mapRow(row: OrgRow, fallbackLang: string): SubtitleHit | null {
};
}
function normalizeImdb(id?: string | null): string | null {
/** Digits only, zero-padded to ≥7 for OS.org URL paths. */
export function normalizeImdbForUrl(id?: string | null): string | null {
if (!id) return null;
const digits = String(id).trim().replace(/^tt/i, "").replace(/\D/g, "");
if (!digits) return null;
// OS.org URLs expect ≥7-digit zero-padded IDs; stripping zeros causes a
// broken 302 to host "_" and silent empty search results.
return digits.padStart(7, "0");
return digits.length >= 7 ? digits : digits.padStart(7, "0");
}
/** Canonical compare: "0468569" === "468569". */
export function imdbIdsMatch(a: string, b: string): boolean {
const ca = a.replace(/^0+/, "") || "0";
const cb = b.replace(/^0+/, "") || "0";
return ca === cb;
}
/** Legacy REST uses OpenSubtitles language ids (`dut` = Dutch). */
function toOrgLang(languages: string): string {
const first = languages.split(",")[0]?.trim().toLowerCase() || "nl";
if (first === "nl" || first === "nld" || first === "dut" || first === "dutch") return "dut";
if (first === "en" || first === "eng") return "eng";
if (first.length === 3) return first;
return first;
function toOrgLangs(languages: string): string[] {
const out: string[] = [];
const seen = new Set<string>();
for (const part of languages.split(",")) {
const first = part.trim().toLowerCase();
if (!first) continue;
let code: string;
if (first === "nl" || first === "nld" || first === "dut" || first === "dutch") code = "dut";
else if (first === "en" || first === "eng") code = "eng";
else if (first.length === 3) code = first;
else code = first;
if (seen.has(code)) continue;
seen.add(code);
out.push(code);
}
return out.length ? out : ["dut"];
}
function isGzip(buf: Buffer): boolean {

View file

@ -103,7 +103,9 @@ export async function upsertOpenSubtitlesSettings(
try {
const { OpenSubtitlesOrgClient } = await import("../opensubtitles/org-client");
await new OpenSubtitlesOrgClient().search({ imdbId: "tt1375666", languages: "nl" });
// tt0111161 (Shawshank) has a leading zero — catches the OS.org padding/redirect bug
// that tt1375666 (Inception) does not.
await new OpenSubtitlesOrgClient().search({ imdbId: "tt0111161", languages: "nl" });
orgOk = true;
} catch (err) {
const msg = err instanceof Error ? err.message : "OpenSubtitles.org test mislukt";

View file

@ -0,0 +1,40 @@
/**
* In-process fan-out for admin UI SSE (/api/v1/admin/viewers/events).
* Single master-api instance — fine for this deploy. No Redis needed.
*/
export type ViewerAdminEvent = {
type: string;
viewerId?: string;
at: number;
};
type Listener = (event: ViewerAdminEvent) => void;
const listeners = new Set<Listener>();
export function notifyViewersChanged(
type: string,
opts?: { viewerId?: string }
): void {
if (listeners.size === 0) return;
const event: ViewerAdminEvent = {
type,
viewerId: opts?.viewerId,
at: Date.now(),
};
for (const listener of listeners) {
try {
listener(event);
} catch {
// never break the mutation path for a broken SSE client
}
}
}
export function subscribeViewersChanged(listener: Listener): () => void {
listeners.add(listener);
return () => {
listeners.delete(listener);
};
}

View file

@ -8,6 +8,7 @@ import { ViewerProfileService } from "./profiles";
import type { DownloadService } from "../downloads/service";
import type { SubtitleSource } from "../opensubtitles/client";
import { GooglePlayAccessService } from "../google-play/service";
import { subscribeViewersChanged } from "./admin-events";
export function registerViewerRoutes(
app: FastifyInstance,
@ -24,6 +25,50 @@ export function registerViewerRoutes(
return { viewers: await viewers.listViewers() };
});
/**
* Live updates for admin UI (device link, login lock, CRUD).
* One long-lived connection per open viewers page; heartbeats keep proxies happy.
*/
app.get(
"/api/v1/admin/viewers/events",
{
preHandler: requireAdmin,
config: { rateLimit: false },
},
(request, reply) => {
reply.hijack();
const res = reply.raw;
res.writeHead(200, {
"Content-Type": "text/event-stream; charset=utf-8",
"Cache-Control": "no-cache, no-transform",
Connection: "keep-alive",
"X-Accel-Buffering": "no",
});
const write = (chunk: string) => {
if (!res.writableEnded) res.write(chunk);
};
write(": connected\n\n");
write(`event: viewers\ndata: ${JSON.stringify({ type: "hello", at: Date.now() })}\n\n`);
const unsubscribe = subscribeViewersChanged((event) => {
write(`event: viewers\ndata: ${JSON.stringify(event)}\n\n`);
});
const ping = setInterval(() => {
write(`: ping ${Date.now()}\n\n`);
}, 20_000);
const cleanup = () => {
clearInterval(ping);
unsubscribe();
};
request.raw.on("close", cleanup);
request.raw.on("error", cleanup);
}
);
app.post("/api/v1/admin/viewers", { preHandler: requireAdmin }, async (request) => {
const body = request.body as {
email?: string;

View file

@ -22,6 +22,7 @@ import {
kidsSeriesSql,
isKidsBlockedTitle,
} from "./kids-filter";
import { notifyViewersChanged } from "./admin-events";
const CODE_TTL_MS = 10 * 60 * 1000;
const CODE_ALPHABET = "ABCDEFGHJKLMNPQRSTUVWXYZ23456789";
@ -116,6 +117,7 @@ export class ViewerService {
},
});
await ensureOwnerProfile(viewer.id, viewer.name);
notifyViewersChanged("viewer.created", { viewerId: viewer.id });
return viewer;
}
@ -217,6 +219,7 @@ export class ViewerService {
if (!existing) throw new AppError("NOT_FOUND", "Gebruiker niet gevonden", 404);
// Cascade: profiles, devices, prefs, favorites, iptv-lijn; addon-tokens blijven (viewerUserId → null)
await prisma.viewerUser.delete({ where: { id } });
notifyViewersChanged("viewer.deleted", { viewerId: id });
return { ok: true };
}
@ -291,14 +294,24 @@ export class ViewerService {
} else if (patch.passwordHash) {
await this.clearLoginLock(updated.email.toLowerCase());
}
if (Object.keys(patch).length > 0) {
notifyViewersChanged("viewer.updated", { viewerId: updated.id });
}
return updated;
}
async revokeDevice(deviceId: string) {
const device = await prisma.viewerDevice.findUnique({
where: { id: deviceId },
select: { id: true, viewerUserId: true },
});
await prisma.viewerDevice.update({
where: { id: deviceId },
data: { revoked: true, refreshTokenHash: hashToken(`revoked:${deviceId}:${Date.now()}`) },
});
if (device) {
notifyViewersChanged("device.revoked", { viewerId: device.viewerUserId });
}
return { ok: true };
}
@ -448,6 +461,7 @@ export class ViewerService {
if (!device) return { status: "already_linked" as const };
notifyViewersChanged("device.linked", { viewerId: viewer.id });
return {
status: "linked" as const,
refreshToken,
@ -553,6 +567,7 @@ export class ViewerService {
await this.clearLoginLock(email);
await ensureOwnerProfile(viewer.id, viewer.name);
notifyViewersChanged("device.login", { viewerId: viewer.id });
return {
refreshToken,
device: { id: device.id, name: device.name, platform: device.platform },
@ -590,15 +605,28 @@ export class ViewerService {
const failedCount = baseCount + 1;
const lockedUntil =
failedCount >= LOGIN_MAX_FAILURES ? new Date(now + LOGIN_LOCK_MS) : null;
return prisma.viewerLoginLock.upsert({
const lock = await prisma.viewerLoginLock.upsert({
where: { email },
create: { email, failedCount, lockedUntil },
update: { failedCount, lockedUntil },
});
const viewer = await prisma.viewerUser.findUnique({
where: { email },
select: { id: true },
});
notifyViewersChanged("login.lock", { viewerId: viewer?.id });
return lock;
}
private async clearLoginLock(email: string) {
await prisma.viewerLoginLock.deleteMany({ where: { email } });
const result = await prisma.viewerLoginLock.deleteMany({ where: { email } });
if (result.count > 0) {
const viewer = await prisma.viewerUser.findUnique({
where: { email },
select: { id: true },
});
notifyViewersChanged("login.unlock", { viewerId: viewer?.id });
}
}
async authFromBearer(authHeader?: string): Promise<AuthedViewer> {