5 Commits

Author SHA1 Message Date
32027f7384 feat: add first volunteer skill endpoint (add_skill) along with dtos 2025-05-31 18:19:15 +02:00
AleksDw
2a8fff39c9 Fix logout so it deletes token in database 2025-05-31 14:37:06 +02:00
AleksDw
b194819b6e Add login/logout in every page 2025-05-31 14:21:02 +02:00
AleksDw
5da58ee030 fix auth.ts 2025-05-31 13:57:58 +02:00
AleksDw
42e468f28f auth frontend 2025-05-31 13:34:18 +02:00
14 changed files with 317 additions and 6 deletions

View File

@@ -0,0 +1,8 @@
using System.ComponentModel.DataAnnotations;
namespace WebApp.DTOs;
public record class SingleSkillDto
(
[Required] int Skill
);

View File

@@ -0,0 +1,9 @@
using System.ComponentModel.DataAnnotations;
namespace WebApp.DTOs;
public record class SkillSummaryDto
(
[Required] int SkillId,
[Required] string SkillName
);

View File

@@ -1,5 +1,6 @@
using Microsoft.AspNetCore.Http.HttpResults;
using Microsoft.EntityFrameworkCore;
using System.Runtime.Intrinsics.Arm;
using System.Security.Cryptography;
using System.Text;
using WebApp.Data;
@@ -123,6 +124,42 @@ namespace WebApp.Endpoints
});
group.MapPost("/add_skill", async (SingleSkillDto dto, HttpContext httpContext, ApplicationDbContext context, GeneralUseHelpers guh) =>
{
// Uzyskaj użytkownika z tokenu
Token? token = await guh.GetTokenFromHTTPContext(httpContext);
User? user = await guh.GetUserFromToken(token);
// Tylko wolontariusze powinno móc dodawać swoje skille
if (user == null || user.IsOrganisation) {
return Results.Json(new { message = "Unauthorized" }, statusCode: 401);
}
// Szukamy skilla w bazie o ID takim, jak w otrzymanym DTO
Skill? skill = await context.Skills.FindAsync(dto.Skill);
if (skill is null)
{
return Results.Json(new { message = "Skill not found" }, statusCode: 404);
}
// Sprawdzamy, czy ten użytkownik nie ma już takiego skilla. Jeżeli ma, nie ma sensu dodawać go kilkukrotnie.
VolunteerSkill? vs = await context.VolunteerSkills.FirstOrDefaultAsync(v => v.UserId == user.UserId && v.SkillId == dto.Skill);
if (vs is null)
{
// Nie ma - zatem musimy dodać nowy VolunteerSkill do bazy
VolunteerSkill newVs = dto.ToVolunteerSkillEntity(user.UserId);
context.VolunteerSkills.Add(newVs);
await context.SaveChangesAsync();
} else
{
// Ma - (ta para UserId <-> SkillId już istnieje w bazie) użytkownik już ma ten skill
return Results.Json(new { message = "User already has this skill" }, statusCode: 400);
}
return Results.Json(new { message = "Skill added successfully!" }, statusCode: 201);
});
return group;
}

View File

@@ -0,0 +1,25 @@
using WebApp.DTOs;
using WebApp.Entities;
namespace WebApp.Mapping
{
public static class SkillMapping
{
public static Skill ToSkillEntity(this SingleSkillDto SSDto, string name)
{
return new Skill()
{
SkillId = SSDto.Skill,
Name = name
};
}
public static SkillSummaryDto ToSkillSummaryDto(this Skill s)
{
return new SkillSummaryDto(
s.SkillId,
s.Name
);
}
}
}

View File

@@ -0,0 +1,17 @@
using WebApp.DTOs;
using WebApp.Entities;
namespace WebApp.Mapping
{
public static class VolunteerSkillMapping
{
public static VolunteerSkill ToVolunteerSkillEntity(this SingleSkillDto SSDto, int uid)
{
return new VolunteerSkill()
{
UserId = uid,
SkillId = SSDto.Skill,
};
}
}
}

57
WebApp/ts/auth.ts Normal file
View File

@@ -0,0 +1,57 @@
// /js/auth.ts
function deleteCookie(name: string): void {
document.cookie = `${name}=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT`;
}
async function logoutUser(): Promise<void> {
await fetch("/api/auth/logout", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
});
deleteCookie('token');
window.location.href = "/index.html";
}
function redirectToLogin(): void {
window.location.href = 'login.html';
}
function checkAuth(): boolean {
// Basic auth check via presence of token cookie
return document.cookie.includes('token=');
}
function setupAuthUI(): void {
const joinNowBtn = document.getElementById('joinnow-btn');
const signInBtn = document.getElementById('signin-btn');
const logoutBtn = document.getElementById('logout-btn');
const isAuthenticated = checkAuth();
if (joinNowBtn) {
joinNowBtn.classList.toggle('d-none', isAuthenticated);
joinNowBtn.addEventListener('click', redirectToLogin);
}
if (signInBtn) {
signInBtn.classList.toggle('d-none', isAuthenticated);
signInBtn.addEventListener('click', redirectToLogin);
}
if (logoutBtn) {
logoutBtn.classList.toggle('d-none', !isAuthenticated);
logoutBtn.addEventListener('click', (e) => {
e.preventDefault();
logoutUser();
});
}
}
// Initialize on load
document.addEventListener('DOMContentLoaded', setupAuthUI);

38
WebApp/ts/login.ts Normal file
View File

@@ -0,0 +1,38 @@
document.addEventListener("DOMContentLoaded", () => {
const form = document.getElementById("loginForm") as HTMLFormElement;
const message = document.getElementById("message") as HTMLParagraphElement;
form.addEventListener("submit", async (e) => {
e.preventDefault();
message.textContent = "";
const email = (document.getElementById("email") as HTMLInputElement).value;
const password = (document.getElementById("password") as HTMLInputElement).value;
try {
const response = await fetch("/api/auth/login", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({ email, password }),
});
const data = await response.json();
if (!response.ok) {
message.textContent = data.message || "Login failed.";
return;
}
document.cookie = `token=${data.token}; path=/; SameSite=Lax; Secure`;
message.style.color = "green";
message.textContent = "Login successful!";
window.location.href = "/index.html";
} catch (error) {
message.textContent = "Something went wrong.";
console.error(error);
}
});
});

View File

@@ -80,6 +80,8 @@
<script type="module" src="/js/eventCreate.js"></script>
<script type="module" src="/js/generalUseHelpers.js"></script>
<script type="module" src="/js/auth.js"></script>
</body>

View File

@@ -56,21 +56,21 @@
<!-- Main content -->
<div class="main">
<div class="position-relative search-bar">
<input type="text" class="form-control pe-5" placeholder="" id="searchbar"/>
<input type="text" class="form-control pe-5" placeholder="" id="searchbar" />
<span class="position-absolute top-50 end-0 translate-middle-y me-3">
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#2898BD"><path d="M784-120 532-372q-30 24-69 38t-83 14q-109 0-184.5-75.5T120-580q0-109 75.5-184.5T380-840q109 0 184.5 75.5T640-580q0 44-14 83t-38 69l252 252-56 56ZM380-400q75 0 127.5-52.5T560-580q0-75-52.5-127.5T380-760q-75 0-127.5 52.5T200-580q0 75 52.5 127.5T380-400Z" /></svg>
</span>
</div>
<!--<a href="/create.html" class="button-add text-decoration-none">
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#FFFFFF"><path d="M440-440H200v-80h240v-240h80v240h240v80H520v240h-80v-240Z" /></svg>
</a>-->
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#FFFFFF"><path d="M440-440H200v-80h240v-240h80v240h240v80H520v240h-80v-240Z" /></svg>
</a>-->
<div class="events-card bg-white p-4 rounded-4 shadow position-relative">
<div class="d-flex justify-content-between align-items-center mb-3">
<h2 class="eventsText">Events</h2>
<span class="position-absolute end-0 translate-middle-y me-4" style="margin-top: 20px;">
<button class="btn btn-link" onclick="">
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#2898BD"><path d="M440-120v-240h80v80h320v80H520v80h-80Zm-320-80v-80h240v80H120Zm160-160v-80H120v-80h160v-80h80v240h-80Zm160-80v-80h400v80H440Zm160-160v-240h80v80h160v80H680v80h-80Zm-480-80v-80h400v80H120Z" /></svg>
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#2898BD"><path d="M440-120v-240h80v80h320v80H520v80h-80ZŁm-320-80v-80h240v80H120Zm160-160v-80H120v-80h160v-80h80v240h-80Zm160-80v-80h400v80H440Zm160-160v-240h80v80h160v80H680v80h-80Zm-480-80v-80h400v80H120Z" /></svg>
</button>
<button class="btn btn-link" id="list-sort-btn" onclick=""><svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#2898BD"><path d="M320-440v-287L217-624l-57-56 200-200 200 200-57 56-103-103v287h-80ZM600-80 400-280l57-56 103 103v-287h80v287l103-103 57 56L600-80Z" /></svg></button>
</span>
@@ -92,5 +92,6 @@
<a href="/create.html" class="button-add mt-xl-auto rounded-5 align-content-center center-text hidden-before-load" id="addnewevent-btn">
<svg xmlns="http://www.w3.org/2000/svg" height="30px" viewBox="0 -960 960 960" width="30px" fill="#FFFFFF"><path d="M440-440H200v-80h240v-240h80v240h240v80H520v240h-80v-240Z" /></svg>
</a>
<script type="module" src="/js/auth.js"></script>
</body>
</html>

56
WebApp/wwwroot/js/auth.js Normal file
View File

@@ -0,0 +1,56 @@
"use strict";
// /js/auth.ts
var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {
function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
return new (P || (P = Promise))(function (resolve, reject) {
function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
step((generator = generator.apply(thisArg, _arguments || [])).next());
});
};
function deleteCookie(name) {
document.cookie = `${name}=; path=/; expires=Thu, 01 Jan 1970 00:00:00 GMT`;
}
function logoutUser() {
return __awaiter(this, void 0, void 0, function* () {
yield fetch("/api/auth/logout", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
});
deleteCookie('token');
window.location.href = "/index.html";
});
}
function redirectToLogin() {
window.location.href = 'login.html';
}
function checkAuth() {
// Basic auth check via presence of token cookie
return document.cookie.includes('token=');
}
function setupAuthUI() {
const joinNowBtn = document.getElementById('joinnow-btn');
const signInBtn = document.getElementById('signin-btn');
const logoutBtn = document.getElementById('logout-btn');
const isAuthenticated = checkAuth();
if (joinNowBtn) {
joinNowBtn.classList.toggle('d-none', isAuthenticated);
joinNowBtn.addEventListener('click', redirectToLogin);
}
if (signInBtn) {
signInBtn.classList.toggle('d-none', isAuthenticated);
signInBtn.addEventListener('click', redirectToLogin);
}
if (logoutBtn) {
logoutBtn.classList.toggle('d-none', !isAuthenticated);
logoutBtn.addEventListener('click', (e) => {
e.preventDefault();
logoutUser();
});
}
}
// Initialize on load
document.addEventListener('DOMContentLoaded', setupAuthUI);

View File

@@ -29,7 +29,7 @@ export function getMyAccount() {
return __awaiter(this, void 0, void 0, function* () {
const res = yield fetch("/api/auth/my_account");
if (!res.ok) {
throw Error("Użytkownik niezalogowany!");
throw Error("U<EFBFBD>ytkownik niezalogowany!");
}
const data = yield res.json();
return data;

View File

@@ -0,0 +1,42 @@
"use strict";
var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {
function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }
return new (P || (P = Promise))(function (resolve, reject) {
function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }
function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }
function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }
step((generator = generator.apply(thisArg, _arguments || [])).next());
});
};
document.addEventListener("DOMContentLoaded", () => {
const form = document.getElementById("loginForm");
const message = document.getElementById("message");
form.addEventListener("submit", (e) => __awaiter(void 0, void 0, void 0, function* () {
e.preventDefault();
message.textContent = "";
const email = document.getElementById("email").value;
const password = document.getElementById("password").value;
try {
const response = yield fetch("/api/auth/login", {
method: "POST",
headers: {
"Content-Type": "application/json",
},
body: JSON.stringify({ email, password }),
});
const data = yield response.json();
if (!response.ok) {
message.textContent = data.message || "Login failed.";
return;
}
document.cookie = `token=${data.token}; path=/; SameSite=Lax; Secure`;
message.style.color = "green";
message.textContent = "Login successful!";
window.location.href = "/index.html";
}
catch (error) {
message.textContent = "Something went wrong.";
console.error(error);
}
}));
});

17
WebApp/wwwroot/login.html Normal file
View File

@@ -0,0 +1,17 @@
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<title>Login</title>
<script src="/js/login.js" defer></script>
</head>
<body>
<h2>Login</h2>
<form id="loginForm">
<label>Email: <input type="email" id="email" required /></label><br /><br />
<label>Password: <input type="password" id="password" required /></label><br /><br />
<button type="submit">Login</button>
<p id="message" style="color: red;"></p>
</form>
</body>
</html>

View File

@@ -61,7 +61,7 @@
<h2 id="locationText">Place: 127.0.0.1</h2>
<h2 id="dateText">When: now or never!</h2>
<h3>Description:</h3>
<h4 id="descText"></h4><br/>
<h4 id="descText"></h4><br />
<button id="applyBtn" class="button hidden-before-load"><span>Apply</span><span>&#11166;</span></button>
<button id="editBtn" class="button hidden-before-load"><span>Modify</span><span>&#11166;</span></button>
@@ -71,6 +71,8 @@
<script type="module" src="/js/eventView.js"></script>
<script type="module" src="/js/generalUseHelpers.js"></script>
<script type="module" src="/js/auth.js"></script>
</body>