(change): Client security
This commit is contained in:
1 parent
a11c313a8e
commit
103f1cf3c4
16 files changed
+177
-115
No files matched your search
@@ -5,6 +5,7 @@
|
||||
import HeaderBar from '$lib/client/components/HeaderBar.svelte';
|
||||
|
||||
let { data } = $props();
|
||||
let { tamClientID } = $derived(data);
|
||||
let settings = $state({});
|
||||
let status = $state({
|
||||
message: '',
|
||||
@@ -74,12 +75,15 @@
|
||||
<input type="text" id="venue_name" class={iS.normal} bind:value={settings.venue_name} />
|
||||
</div>
|
||||
<div class="flex flex-row gap-1 items-center">
|
||||
<div>Disable Attribution:</div>
|
||||
<div>Disable Attribution:</div>
|
||||
<button
|
||||
class={bS.gray}
|
||||
onclick={() => {
|
||||
settings.disable_attrib ? settings.disable_attrib = false : settings.disable_attrib = true
|
||||
}}>{ settings.disable_attrib ? "Yes" : "No" }</button>
|
||||
class={bS.gray}
|
||||
onclick={() => {
|
||||
settings.disable_attrib
|
||||
? (settings.disable_attrib = false)
|
||||
: (settings.disable_attrib = true);
|
||||
}}>{settings.disable_attrib ? 'Yes' : 'No'}</button
|
||||
>
|
||||
</div>
|
||||
<div class="flex flex-row gap-1 items-center">
|
||||
<button
|
||||
@@ -88,7 +92,7 @@
|
||||
const res = await fetch('/api/settings', {
|
||||
method: 'POST',
|
||||
body: JSON.stringify(settings),
|
||||
headers: { 'Content-Type': 'application/json' }
|
||||
headers: { 'Content-Type': 'application/json', 'TAM-CLIENT-ID': tamClientID }
|
||||
});
|
||||
if (!res.ok) {
|
||||
status.message = `Error Code: ${res.status}`;
|
||||
|
||||
@@ -3,6 +3,7 @@
|
||||
import { resolve } from '$app/paths';
|
||||
import { bS, iS } from '$lib/client/styles';
|
||||
let { data } = $props();
|
||||
let { tamClientID } = $derived(data);
|
||||
|
||||
const pageTitle = 'Auth Keys | TAM';
|
||||
|
||||
@@ -17,7 +18,7 @@
|
||||
|
||||
async function getKeys() {
|
||||
const res = await fetch('/api/auth', {
|
||||
headers: { 'TAM-PWD': auth.pwd }
|
||||
headers: { 'TAM-PWD': auth.pwd, 'TAM-CLIENT-ID': tamClientID }
|
||||
});
|
||||
if (res.ok) {
|
||||
auth.toggle = true;
|
||||
@@ -72,7 +73,7 @@
|
||||
onclick={async () => {
|
||||
const res = await fetch('/api/settings', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
headers: { 'Content-Type': 'application/json', 'TAM-CLIENT-ID': tamClientID },
|
||||
body: JSON.stringify({ remote_key: key.auth_key })
|
||||
});
|
||||
if (res.ok) {
|
||||
@@ -86,7 +87,7 @@
|
||||
onclick={async () => {
|
||||
const res = await fetch(`/api/auth?key_to_del=${key.auth_key}`, {
|
||||
method: 'DELETE',
|
||||
headers: { 'TAM-PWD': auth.pwd }
|
||||
headers: { 'TAM-PWD': auth.pwd, 'TAM-CLIENT-ID': tamClientID }
|
||||
});
|
||||
if (res.ok) {
|
||||
setTimeout(() => {
|
||||
@@ -112,7 +113,7 @@
|
||||
if (newDesc) {
|
||||
const res = await fetch('/api/auth', {
|
||||
method: 'POST',
|
||||
headers: { 'TAM-PWD': auth.pwd, 'Content-Type': 'application/json' },
|
||||
headers: { 'TAM-PWD': auth.pwd, 'Content-Type': 'application/json', 'TAM-CLIENT-ID': tamClientID },
|
||||
body: JSON.stringify({ description: newDesc })
|
||||
});
|
||||
if (res.ok) {
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
const pageTitle = 'Backup and Restore | TAM';
|
||||
|
||||
let { data } = $props();
|
||||
let remoteServer = $derived(data.remoteServer);
|
||||
let { remoteServer, tamClientID } = $derived(data);
|
||||
let uploadFile = $state();
|
||||
let contents = $state('');
|
||||
let results = $state('');
|
||||
@@ -31,7 +31,7 @@
|
||||
hour: String(now.getHours()).padStart(2, '0'),
|
||||
minutes: String(now.getMinutes()).padStart(2, '0')
|
||||
};
|
||||
const res = await fetch(fetch_url);
|
||||
const res = await fetch(fetch_url, { headers: { 'TAM-CLIENT-ID': tamClientID } });
|
||||
if (res.ok) {
|
||||
const data = await res.json();
|
||||
const jsonString = JSON.stringify(data, null, 2);
|
||||
@@ -58,7 +58,7 @@
|
||||
setTimeout(async () => {
|
||||
const res = await fetch(`/api/backuprestore/${target}`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
headers: { 'Content-Type': 'application/json', 'TAM-CLIENT-ID': tamClientID },
|
||||
body: contents
|
||||
});
|
||||
if (res.ok) setResult('File uploaded successfully. Check to see if your data exists.');
|
||||
@@ -67,7 +67,10 @@
|
||||
}
|
||||
|
||||
async function pushData(target) {
|
||||
const res = await fetch(`/api/backuprestore/push/${target}`, { method: 'HEAD' });
|
||||
const res = await fetch(`/api/backuprestore/push/${target}`, {
|
||||
method: 'HEAD',
|
||||
headers: { 'TAM-CLIENT-ID': tamClientID }
|
||||
});
|
||||
const targetStr = target.charAt(0).toUpperCase() + target.slice(1);
|
||||
if (res.ok) {
|
||||
setResult(`${targetStr} pushed successfully.`);
|
||||
|
||||
@@ -5,6 +5,7 @@
|
||||
import { resolve } from '$app/paths';
|
||||
|
||||
let { data } = $props();
|
||||
let { tamClientID } = $derived(data);
|
||||
|
||||
const pageTitle = 'Prefixes | TAM';
|
||||
|
||||
@@ -56,7 +57,7 @@
|
||||
if (editPrefix.prefix) {
|
||||
const req = await fetch('/api/prefixes', {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
headers: { 'Content-Type': 'application/json', 'TAM-CLIENT-ID': tamClientID },
|
||||
body: JSON.stringify([editPrefix])
|
||||
});
|
||||
if (req.ok) window.location.reload();
|
||||
@@ -125,7 +126,8 @@
|
||||
class={bS[prefix.color]}
|
||||
onclick={async () => {
|
||||
const res = await fetch(`/api/prefixes?p=${prefix.prefix}`, {
|
||||
method: 'DELETE'
|
||||
method: 'DELETE',
|
||||
headers: { 'TAM-CLIENT-ID': tamClientID }
|
||||
});
|
||||
if (res.ok) window.location.reload();
|
||||
}}>Delete</button
|
||||
|
||||
Reference in new issue
Block a user