Compare commits
70
Commits
v1.0.5
...
026c2696b6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
026c2696b6 | ||
|
|
6cb4168f44 | ||
|
|
b82ef82f50 | ||
|
|
9a18434f4a | ||
|
|
f126eacf8c | ||
|
|
848b12ce5d | ||
|
|
3d350bd9e5 | ||
|
|
e03dd8c5a6 | ||
|
|
9101a5b48e | ||
|
|
1186f4f620 | ||
|
|
988fcaf855 | ||
|
|
b27031f7c4 | ||
|
|
7ee60e7313 | ||
|
|
671090b1b1 | ||
|
|
0f03bb7446 | ||
|
|
55a1e5bf8f | ||
|
|
33ae035adc | ||
|
|
87d575f335 | ||
|
|
e4329f76b1 | ||
|
|
fa4cf20022 | ||
|
|
2ecfc2e12d | ||
|
|
db2ac80a1e | ||
|
|
99490bfc4d | ||
|
|
fce17654f8 | ||
|
|
419207ac12 | ||
|
|
e30ac71044 | ||
|
|
781e348ded | ||
|
|
e16a18e488 | ||
|
|
7cd3cbaae5 | ||
|
|
60f07fddc9 | ||
|
|
068415849f | ||
|
|
e39e2a361a | ||
|
|
9d3e749c38 | ||
|
|
b7c6cb4d81 | ||
|
|
c41b75e364 | ||
|
|
41630bb8c5 | ||
|
|
b9430e7ab6 | ||
|
|
f1f808d079 | ||
|
|
a8a632e1b0 | ||
|
|
a695ec7319 | ||
|
|
c6730335ef | ||
|
|
247b849759 | ||
|
|
0dee178ded | ||
|
|
9359f26788 | ||
|
|
5630765215 | ||
|
|
ed4a78b109 | ||
|
|
9acb22e2f9 | ||
|
|
6a8361d710 | ||
|
|
502ffee31f | ||
|
|
5a322230ae | ||
|
|
f919c288b2 | ||
|
|
21b948a4f8 | ||
|
|
d04271f942 | ||
|
|
4f08e9ea4d | ||
|
|
67347f1e34 | ||
|
|
75f2b6400d | ||
|
|
26aec1c5af | ||
|
|
0fe7ca0575 | ||
|
|
d745a764fe | ||
|
|
6c273118a2 | ||
|
|
a010a7368a | ||
|
|
08bd00f01f | ||
|
|
cef7f46718 | ||
|
|
ac48f1e9d1 | ||
|
|
3d8bc9019f | ||
|
|
cd65c2799f | ||
|
|
282be290cd | ||
|
|
080f41c7d8 | ||
|
|
37e417e057 | ||
|
|
05b3dc8cb1 |
Vendored
+4
@@ -1,4 +1,5 @@
|
||||
export { MaskedField } from '../globals/SiteIntegrations/components/MaskedField.js';
|
||||
export { TestEmailButton } from '../globals/SiteIntegrations/components/TestEmailButton.js';
|
||||
export { Analytics } from '../modules/analytics/client.js';
|
||||
/**
|
||||
* Entry point: ipal-kit/client
|
||||
@@ -9,5 +10,8 @@ export { Analytics } from '../modules/analytics/client.js';
|
||||
*/
|
||||
export { ConsentProvider, CookieBanner, CookieButton, useConsent, useConsentContext, } from '../modules/consent/client.js';
|
||||
export type { CookieBannerClassNames } from '../modules/consent/client.js';
|
||||
export { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js';
|
||||
export type { FormNotificationTexts } from '../modules/notifications/types.js';
|
||||
export { Turnstile } from '../modules/turnstile/client.js';
|
||||
export { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js';
|
||||
export type { TurnstileProps } from '../modules/turnstile/client.js';
|
||||
|
||||
Vendored
+4
@@ -1,4 +1,6 @@
|
||||
'use client';
|
||||
export { MaskedField } from '../globals/SiteIntegrations/components/MaskedField.js';
|
||||
export { TestEmailButton } from '../globals/SiteIntegrations/components/TestEmailButton.js';
|
||||
export { Analytics } from '../modules/analytics/client.js';
|
||||
/**
|
||||
* Entry point: ipal-kit/client
|
||||
@@ -7,6 +9,8 @@ export { Analytics } from '../modules/analytics/client.js';
|
||||
* components. Kept separate from the main entry so server bundles don't pull in
|
||||
* client-only code.
|
||||
*/ export { ConsentProvider, CookieBanner, CookieButton, useConsent, useConsentContext } from '../modules/consent/client.js';
|
||||
export { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js';
|
||||
export { Turnstile } from '../modules/turnstile/client.js';
|
||||
export { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js';
|
||||
|
||||
//# sourceMappingURL=client.js.map
|
||||
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../src/exports/client.ts"],"sourcesContent":["'use client'\nexport { Analytics } from '../modules/analytics/client.js'\n/**\n * Entry point: ipal-kit/client\n *\n * Client-side ('use client') exports — React hooks, providers, and UI\n * components. Kept separate from the main entry so server bundles don't pull in\n * client-only code.\n */\nexport {\n ConsentProvider,\n CookieBanner,\n CookieButton,\n useConsent,\n useConsentContext,\n} from '../modules/consent/client.js'\nexport type { CookieBannerClassNames } from '../modules/consent/client.js'\nexport { Turnstile } from '../modules/turnstile/client.js'\nexport type { TurnstileProps } from '../modules/turnstile/client.js'\n"],"names":["Analytics","ConsentProvider","CookieBanner","CookieButton","useConsent","useConsentContext","Turnstile"],"mappings":"AAAA;AACA,SAASA,SAAS,QAAQ,iCAAgC;AAC1D;;;;;;CAMC,GACD,SACEC,eAAe,EACfC,YAAY,EACZC,YAAY,EACZC,UAAU,EACVC,iBAAiB,QACZ,+BAA8B;AAErC,SAASC,SAAS,QAAQ,iCAAgC"}
|
||||
{"version":3,"sources":["../../src/exports/client.ts"],"sourcesContent":["'use client'\nexport { MaskedField } from '../globals/SiteIntegrations/components/MaskedField.js'\nexport { TestEmailButton } from '../globals/SiteIntegrations/components/TestEmailButton.js'\nexport { Analytics } from '../modules/analytics/client.js'\n/**\n * Entry point: ipal-kit/client\n *\n * Client-side ('use client') exports — React hooks, providers, and UI\n * components. Kept separate from the main entry so server bundles don't pull in\n * client-only code.\n */\nexport {\n ConsentProvider,\n CookieBanner,\n CookieButton,\n useConsent,\n useConsentContext,\n} from '../modules/consent/client.js'\nexport type { CookieBannerClassNames } from '../modules/consent/client.js'\nexport { resolveFormMessage } from '../modules/notifications/resolveFormMessage.js'\nexport type { FormNotificationTexts } from '../modules/notifications/types.js'\nexport { Turnstile } from '../modules/turnstile/client.js'\nexport { TurnstileProvider, useTurnstile } from '../modules/turnstile/client.js'\nexport type { TurnstileProps } from '../modules/turnstile/client.js'\n"],"names":["MaskedField","TestEmailButton","Analytics","ConsentProvider","CookieBanner","CookieButton","useConsent","useConsentContext","resolveFormMessage","Turnstile","TurnstileProvider","useTurnstile"],"mappings":"AAAA;AACA,SAASA,WAAW,QAAQ,wDAAuD;AACnF,SAASC,eAAe,QAAQ,4DAA2D;AAC3F,SAASC,SAAS,QAAQ,iCAAgC;AAC1D;;;;;;CAMC,GACD,SACEC,eAAe,EACfC,YAAY,EACZC,YAAY,EACZC,UAAU,EACVC,iBAAiB,QACZ,+BAA8B;AAErC,SAASC,kBAAkB,QAAQ,iDAAgD;AAEnF,SAASC,SAAS,QAAQ,iCAAgC;AAC1D,SAASC,iBAAiB,EAAEC,YAAY,QAAQ,iCAAgC"}
|
||||
Vendored
+1
@@ -7,3 +7,4 @@
|
||||
*/
|
||||
export { RenderBlocks } from '../modules/blocks/index.js';
|
||||
export type { BlockComponentMap, BlockData, EnhanceProps, RenderBlocksProps, } from '../modules/blocks/index.js';
|
||||
export { MediaPreconnect } from '../modules/storage/MediaPreconnect.js';
|
||||
|
||||
Vendored
+1
@@ -5,5 +5,6 @@
|
||||
* lives here rather than in the main package entry to keep React out of the
|
||||
* server-config bundle.
|
||||
*/ export { RenderBlocks } from '../modules/blocks/index.js';
|
||||
export { MediaPreconnect } from '../modules/storage/MediaPreconnect.js';
|
||||
|
||||
//# sourceMappingURL=rsc.js.map
|
||||
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../src/exports/rsc.ts"],"sourcesContent":["/**\n * Entry point: ipal-kit/rsc\n *\n * Server-component exports. RenderBlocks is a React Server Component, so it\n * lives here rather than in the main package entry to keep React out of the\n * server-config bundle.\n */\nexport { RenderBlocks } from '../modules/blocks/index.js'\nexport type {\n BlockComponentMap,\n BlockData,\n EnhanceProps,\n RenderBlocksProps,\n} from '../modules/blocks/index.js'\n"],"names":["RenderBlocks"],"mappings":"AAAA;;;;;;CAMC,GACD,SAASA,YAAY,QAAQ,6BAA4B"}
|
||||
{"version":3,"sources":["../../src/exports/rsc.ts"],"sourcesContent":["/**\n * Entry point: ipal-kit/rsc\n *\n * Server-component exports. RenderBlocks is a React Server Component, so it\n * lives here rather than in the main package entry to keep React out of the\n * server-config bundle.\n */\nexport { RenderBlocks } from '../modules/blocks/index.js'\nexport type {\n BlockComponentMap,\n BlockData,\n EnhanceProps,\n RenderBlocksProps,\n} from '../modules/blocks/index.js'\nexport { MediaPreconnect } from '../modules/storage/MediaPreconnect.js'\n"],"names":["RenderBlocks","MediaPreconnect"],"mappings":"AAAA;;;;;;CAMC,GACD,SAASA,YAAY,QAAQ,6BAA4B;AAOzD,SAASC,eAAe,QAAQ,wCAAuC"}
|
||||
Vendored
+82
@@ -0,0 +1,82 @@
|
||||
/**
|
||||
* Fields for the Notifications global — localized user-facing texts for action
|
||||
* results (form submission outcomes, and future contexts). Every text is
|
||||
* localized: true so each language has its own value. Empty fields fall back to
|
||||
* built-in English defaults (see modules/notifications/defaults).
|
||||
*
|
||||
* Grouped per context. `form` holds the outcomes of submitForm; more groups
|
||||
* (e.g. `newsletter`, `system`) can be added the same way without touching
|
||||
* consumers — getNotificationTexts resolves whatever exists, falling back
|
||||
* per field.
|
||||
*/ export const notificationsFields = [
|
||||
{
|
||||
name: 'form',
|
||||
type: 'group',
|
||||
admin: {
|
||||
description: 'Messages shown after a form is submitted. Leave a field empty to use the built-in default.'
|
||||
},
|
||||
fields: [
|
||||
{
|
||||
name: 'success',
|
||||
type: 'text',
|
||||
admin: {
|
||||
placeholder: 'Thank you — your message has been sent.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'error',
|
||||
type: 'text',
|
||||
admin: {
|
||||
placeholder: 'Something went wrong. Please try again later.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'rateLimited',
|
||||
type: 'text',
|
||||
admin: {
|
||||
placeholder: 'Too many attempts. Please wait a moment and try again.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'turnstile',
|
||||
type: 'text',
|
||||
admin: {
|
||||
placeholder: 'Captcha verification failed. Please try again.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'validation',
|
||||
type: 'text',
|
||||
admin: {
|
||||
description: 'Shown on a validation error. Use {field} to insert the offending field name.',
|
||||
placeholder: 'Please check the {field} field and try again.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'consent',
|
||||
type: 'text',
|
||||
admin: {
|
||||
description: 'Shown when the GDPR consent checkbox is left unchecked.',
|
||||
placeholder: 'Please accept the privacy policy to continue.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'notFound',
|
||||
type: 'text',
|
||||
admin: {
|
||||
placeholder: 'This form is no longer available.'
|
||||
},
|
||||
localized: true
|
||||
}
|
||||
],
|
||||
label: 'Form messages'
|
||||
}
|
||||
];
|
||||
|
||||
//# sourceMappingURL=fields.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/globals/Notifications/fields.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Fields for the Notifications global — localized user-facing texts for action\n * results (form submission outcomes, and future contexts). Every text is\n * localized: true so each language has its own value. Empty fields fall back to\n * built-in English defaults (see modules/notifications/defaults).\n *\n * Grouped per context. `form` holds the outcomes of submitForm; more groups\n * (e.g. `newsletter`, `system`) can be added the same way without touching\n * consumers — getNotificationTexts resolves whatever exists, falling back\n * per field.\n */\nexport const notificationsFields: Field[] = [\n {\n name: 'form',\n type: 'group',\n admin: {\n description:\n 'Messages shown after a form is submitted. Leave a field empty to use the built-in default.',\n },\n fields: [\n {\n name: 'success',\n type: 'text',\n admin: { placeholder: 'Thank you — your message has been sent.' },\n localized: true,\n },\n {\n name: 'error',\n type: 'text',\n admin: { placeholder: 'Something went wrong. Please try again later.' },\n localized: true,\n },\n {\n name: 'rateLimited',\n type: 'text',\n admin: { placeholder: 'Too many attempts. Please wait a moment and try again.' },\n localized: true,\n },\n {\n name: 'turnstile',\n type: 'text',\n admin: { placeholder: 'Captcha verification failed. Please try again.' },\n localized: true,\n },\n {\n name: 'validation',\n type: 'text',\n admin: {\n description:\n 'Shown on a validation error. Use {field} to insert the offending field name.',\n placeholder: 'Please check the {field} field and try again.',\n },\n localized: true,\n },\n {\n name: 'consent',\n type: 'text',\n admin: {\n description: 'Shown when the GDPR consent checkbox is left unchecked.',\n placeholder: 'Please accept the privacy policy to continue.',\n },\n localized: true,\n },\n {\n name: 'notFound',\n type: 'text',\n admin: { placeholder: 'This form is no longer available.' },\n localized: true,\n },\n ],\n label: 'Form messages',\n },\n]\n"],"names":["notificationsFields","name","type","admin","description","fields","placeholder","localized","label"],"mappings":"AAEA;;;;;;;;;;CAUC,GACD,OAAO,MAAMA,sBAA+B;IAC1C;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aACE;QACJ;QACAC,QAAQ;YACN;gBACEJ,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAA0C;gBAChEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAgD;gBACtEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAyD;gBAC/EC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAiD;gBACvEC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBACLC,aACE;oBACFE,aAAa;gBACf;gBACAC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBACLC,aAAa;oBACbE,aAAa;gBACf;gBACAC,WAAW;YACb;YACA;gBACEN,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEG,aAAa;gBAAoC;gBAC1DC,WAAW;YACb;SACD;QACDC,OAAO;IACT;CACD,CAAA"}
|
||||
Vendored
+17
@@ -0,0 +1,17 @@
|
||||
import { notificationsFields } from './fields.js';
|
||||
/**
|
||||
* Builds the Notifications global — localized action-result texts. Readable by
|
||||
* any authenticated panel user; server-side helpers read it with overrideAccess
|
||||
* so the frontend can resolve texts without a session.
|
||||
*/ export function buildNotifications() {
|
||||
return {
|
||||
slug: 'notifications',
|
||||
access: {
|
||||
read: ()=>true
|
||||
},
|
||||
fields: notificationsFields,
|
||||
label: 'Notifications'
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=index.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/globals/Notifications/index.ts"],"sourcesContent":["import type { GlobalConfig } from 'payload'\n\nimport { notificationsFields } from './fields.js'\n\n/**\n * Builds the Notifications global — localized action-result texts. Readable by\n * any authenticated panel user; server-side helpers read it with overrideAccess\n * so the frontend can resolve texts without a session.\n */\nexport function buildNotifications(): GlobalConfig {\n return {\n slug: 'notifications',\n access: {\n read: () => true, // texts are public-facing (shown to end users)\n },\n fields: notificationsFields,\n label: 'Notifications',\n }\n}\n"],"names":["notificationsFields","buildNotifications","slug","access","read","fields","label"],"mappings":"AAEA,SAASA,mBAAmB,QAAQ,cAAa;AAEjD;;;;CAIC,GACD,OAAO,SAASC;IACd,OAAO;QACLC,MAAM;QACNC,QAAQ;YACNC,MAAM,IAAM;QACd;QACAC,QAAQL;QACRM,OAAO;IACT;AACF"}
|
||||
@@ -0,0 +1,54 @@
|
||||
'use client';
|
||||
import { jsx as _jsx, jsxs as _jsxs } from "react/jsx-runtime";
|
||||
import { useState } from 'react';
|
||||
export const MaskedField = (props)=>{
|
||||
const { field, path, value: propValue, setValue: propSetValue, onChange: propOnChange } = props || {};
|
||||
const [internalValue, setInternalValue] = useState(propValue ?? '');
|
||||
const [revealed, setRevealed] = useState(false);
|
||||
const label = typeof field?.label === 'string' ? field.label : field?.name ?? path;
|
||||
const handleChange = (e)=>{
|
||||
const newVal = e.target.value;
|
||||
setInternalValue(newVal);
|
||||
if (typeof propSetValue === 'function') {
|
||||
propSetValue(newVal);
|
||||
}
|
||||
if (typeof propOnChange === 'function') {
|
||||
propOnChange(e);
|
||||
}
|
||||
};
|
||||
const currentValue = propValue !== undefined ? propValue : internalValue;
|
||||
return /*#__PURE__*/ _jsxs("div", {
|
||||
className: "field-type text",
|
||||
children: [
|
||||
label && /*#__PURE__*/ _jsx("label", {
|
||||
className: "field-label",
|
||||
children: label
|
||||
}),
|
||||
/*#__PURE__*/ _jsxs("div", {
|
||||
style: {
|
||||
display: 'flex',
|
||||
gap: '.5rem'
|
||||
},
|
||||
children: [
|
||||
/*#__PURE__*/ _jsx("input", {
|
||||
autoComplete: "off",
|
||||
onChange: handleChange,
|
||||
style: {
|
||||
flex: 1
|
||||
},
|
||||
type: revealed ? 'text' : 'password',
|
||||
value: currentValue ?? ''
|
||||
}),
|
||||
/*#__PURE__*/ _jsx("button", {
|
||||
onClick: ()=>setRevealed((r)=>!r),
|
||||
type: "button",
|
||||
children: revealed ? 'Hide' : 'Reveal'
|
||||
})
|
||||
]
|
||||
})
|
||||
]
|
||||
});
|
||||
};
|
||||
export default MaskedField;
|
||||
|
||||
//# sourceMappingURL=MaskedField.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/components/MaskedField.tsx"],"sourcesContent":["'use client'\nimport type { TextFieldClientComponent } from 'payload'\nimport { useState } from 'react'\n\nexport const MaskedField: TextFieldClientComponent = (props: any) => {\n const { field, path, value: propValue, setValue: propSetValue, onChange: propOnChange } = props || {}\n const [internalValue, setInternalValue] = useState(propValue ?? '')\n const [revealed, setRevealed] = useState(false)\n const label = typeof field?.label === 'string' ? field.label : (field?.name ?? path)\n\n const handleChange = (e: React.ChangeEvent<HTMLInputElement>) => {\n const newVal = e.target.value\n setInternalValue(newVal)\n if (typeof propSetValue === 'function') {\n propSetValue(newVal)\n }\n if (typeof propOnChange === 'function') {\n propOnChange(e)\n }\n }\n\n const currentValue = propValue !== undefined ? propValue : internalValue\n\n return (\n <div className=\"field-type text\">\n {label && <label className=\"field-label\">{label}</label>}\n <div style={{ display: 'flex', gap: '.5rem' }}>\n <input\n autoComplete=\"off\"\n onChange={handleChange}\n style={{ flex: 1 }}\n type={revealed ? 'text' : 'password'}\n value={currentValue ?? ''}\n />\n <button onClick={() => setRevealed((r) => !r)} type=\"button\">\n {revealed ? 'Hide' : 'Reveal'}\n </button>\n </div>\n </div>\n )\n}\n\nexport default MaskedField\n"],"names":["useState","MaskedField","props","field","path","value","propValue","setValue","propSetValue","onChange","propOnChange","internalValue","setInternalValue","revealed","setRevealed","label","name","handleChange","e","newVal","target","currentValue","undefined","div","className","style","display","gap","input","autoComplete","flex","type","button","onClick","r"],"mappings":"AAAA;;AAEA,SAASA,QAAQ,QAAQ,QAAO;AAEhC,OAAO,MAAMC,cAAwC,CAACC;IACpD,MAAM,EAAEC,KAAK,EAAEC,IAAI,EAAEC,OAAOC,SAAS,EAAEC,UAAUC,YAAY,EAAEC,UAAUC,YAAY,EAAE,GAAGR,SAAS,CAAC;IACpG,MAAM,CAACS,eAAeC,iBAAiB,GAAGZ,SAASM,aAAa;IAChE,MAAM,CAACO,UAAUC,YAAY,GAAGd,SAAS;IACzC,MAAMe,QAAQ,OAAOZ,OAAOY,UAAU,WAAWZ,MAAMY,KAAK,GAAIZ,OAAOa,QAAQZ;IAE/E,MAAMa,eAAe,CAACC;QACpB,MAAMC,SAASD,EAAEE,MAAM,CAACf,KAAK;QAC7BO,iBAAiBO;QACjB,IAAI,OAAOX,iBAAiB,YAAY;YACtCA,aAAaW;QACf;QACA,IAAI,OAAOT,iBAAiB,YAAY;YACtCA,aAAaQ;QACf;IACF;IAEA,MAAMG,eAAef,cAAcgB,YAAYhB,YAAYK;IAE3D,qBACE,MAACY;QAAIC,WAAU;;YACZT,uBAAS,KAACA;gBAAMS,WAAU;0BAAeT;;0BAC1C,MAACQ;gBAAIE,OAAO;oBAAEC,SAAS;oBAAQC,KAAK;gBAAQ;;kCAC1C,KAACC;wBACCC,cAAa;wBACbpB,UAAUQ;wBACVQ,OAAO;4BAAEK,MAAM;wBAAE;wBACjBC,MAAMlB,WAAW,SAAS;wBAC1BR,OAAOgB,gBAAgB;;kCAEzB,KAACW;wBAAOC,SAAS,IAAMnB,YAAY,CAACoB,IAAM,CAACA;wBAAIH,MAAK;kCACjDlB,WAAW,SAAS;;;;;;AAK/B,EAAC;AAED,eAAeZ,YAAW"}
|
||||
@@ -0,0 +1,11 @@
|
||||
/**
|
||||
* Admin UI: a small "send test email" tool for the SiteIntegrations email tab.
|
||||
* Enter an address, click Send, and it POSTs to /api/ipal/test-email, which
|
||||
* sends through the currently-selected transport (SMTP or Graph). Shows the
|
||||
* result inline so you can confirm delivery — or read the exact error — without
|
||||
* leaving the panel.
|
||||
*
|
||||
* Assigned via a `ui` field's admin.components.Field.
|
||||
*/
|
||||
export declare const TestEmailButton: () => import("react/jsx-runtime").JSX.Element;
|
||||
export default TestEmailButton;
|
||||
@@ -0,0 +1,131 @@
|
||||
'use client';
|
||||
import { jsx as _jsx, jsxs as _jsxs } from "react/jsx-runtime";
|
||||
import { useState } from 'react';
|
||||
/**
|
||||
* Admin UI: a small "send test email" tool for the SiteIntegrations email tab.
|
||||
* Enter an address, click Send, and it POSTs to /api/ipal/test-email, which
|
||||
* sends through the currently-selected transport (SMTP or Graph). Shows the
|
||||
* result inline so you can confirm delivery — or read the exact error — without
|
||||
* leaving the panel.
|
||||
*
|
||||
* Assigned via a `ui` field's admin.components.Field.
|
||||
*/ export const TestEmailButton = ()=>{
|
||||
const [to, setTo] = useState('');
|
||||
const [status, setStatus] = useState({
|
||||
kind: 'idle'
|
||||
});
|
||||
const send = async ()=>{
|
||||
if (!to.trim()) {
|
||||
setStatus({
|
||||
kind: 'error',
|
||||
msg: 'Enter a recipient address.'
|
||||
});
|
||||
return;
|
||||
}
|
||||
setStatus({
|
||||
kind: 'sending'
|
||||
});
|
||||
try {
|
||||
const res = await fetch('/api/ipal/test-email', {
|
||||
body: JSON.stringify({
|
||||
to: to.trim()
|
||||
}),
|
||||
credentials: 'include',
|
||||
headers: {
|
||||
'Content-Type': 'application/json'
|
||||
},
|
||||
method: 'POST'
|
||||
});
|
||||
const data = await res.json();
|
||||
if (data.ok) {
|
||||
setStatus({
|
||||
kind: 'ok',
|
||||
msg: data.message ?? 'Test email sent.'
|
||||
});
|
||||
} else {
|
||||
setStatus({
|
||||
kind: 'error',
|
||||
msg: data.error ?? 'Send failed.'
|
||||
});
|
||||
}
|
||||
} catch {
|
||||
setStatus({
|
||||
kind: 'error',
|
||||
msg: 'Request failed. Is the server running?'
|
||||
});
|
||||
}
|
||||
};
|
||||
return /*#__PURE__*/ _jsxs("div", {
|
||||
className: "field-type",
|
||||
style: {
|
||||
marginTop: '1rem'
|
||||
},
|
||||
children: [
|
||||
/*#__PURE__*/ _jsx("label", {
|
||||
className: "field-label",
|
||||
children: "Send a test email"
|
||||
}),
|
||||
/*#__PURE__*/ _jsx("p", {
|
||||
style: {
|
||||
fontSize: '.85rem',
|
||||
marginTop: 0,
|
||||
opacity: 0.7
|
||||
},
|
||||
children: "Sends through the transport selected above. Save your changes first."
|
||||
}),
|
||||
/*#__PURE__*/ _jsxs("div", {
|
||||
style: {
|
||||
alignItems: 'center',
|
||||
display: 'flex',
|
||||
flexWrap: 'wrap',
|
||||
gap: '.5rem'
|
||||
},
|
||||
children: [
|
||||
/*#__PURE__*/ _jsx("input", {
|
||||
onChange: (e)=>setTo(e.target.value),
|
||||
placeholder: "[email protected]",
|
||||
style: {
|
||||
flex: 1,
|
||||
minWidth: '220px'
|
||||
},
|
||||
type: "email",
|
||||
value: to
|
||||
}),
|
||||
/*#__PURE__*/ _jsx("button", {
|
||||
className: "btn btn--style-secondary",
|
||||
disabled: status.kind === 'sending',
|
||||
onClick: send,
|
||||
style: {
|
||||
whiteSpace: 'nowrap'
|
||||
},
|
||||
type: "button",
|
||||
children: status.kind === 'sending' ? 'Sending…' : 'Send test'
|
||||
})
|
||||
]
|
||||
}),
|
||||
status.kind === 'ok' && /*#__PURE__*/ _jsxs("p", {
|
||||
style: {
|
||||
color: 'var(--theme-success-500, green)',
|
||||
marginTop: '.5rem'
|
||||
},
|
||||
children: [
|
||||
"✓ ",
|
||||
status.msg
|
||||
]
|
||||
}),
|
||||
status.kind === 'error' && /*#__PURE__*/ _jsxs("p", {
|
||||
style: {
|
||||
color: 'var(--theme-error-500, crimson)',
|
||||
marginTop: '.5rem'
|
||||
},
|
||||
children: [
|
||||
"✗ ",
|
||||
status.msg
|
||||
]
|
||||
})
|
||||
]
|
||||
});
|
||||
};
|
||||
export default TestEmailButton;
|
||||
|
||||
//# sourceMappingURL=TestEmailButton.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/components/TestEmailButton.tsx"],"sourcesContent":["'use client'\n\nimport { useState } from 'react'\n\n/**\n * Admin UI: a small \"send test email\" tool for the SiteIntegrations email tab.\n * Enter an address, click Send, and it POSTs to /api/ipal/test-email, which\n * sends through the currently-selected transport (SMTP or Graph). Shows the\n * result inline so you can confirm delivery — or read the exact error — without\n * leaving the panel.\n *\n * Assigned via a `ui` field's admin.components.Field.\n */\nexport const TestEmailButton = () => {\n const [to, setTo] = useState('')\n const [status, setStatus] = useState<\n | { kind: 'error'; msg: string }\n | { kind: 'idle' }\n | { kind: 'ok'; msg: string }\n | { kind: 'sending' }\n >({ kind: 'idle' })\n\n const send = async () => {\n if (!to.trim()) {\n setStatus({ kind: 'error', msg: 'Enter a recipient address.' })\n return\n }\n setStatus({ kind: 'sending' })\n try {\n const res = await fetch('/api/ipal/test-email', {\n body: JSON.stringify({ to: to.trim() }),\n credentials: 'include',\n headers: { 'Content-Type': 'application/json' },\n method: 'POST',\n })\n const data = await res.json()\n if (data.ok) {\n setStatus({ kind: 'ok', msg: data.message ?? 'Test email sent.' })\n } else {\n setStatus({ kind: 'error', msg: data.error ?? 'Send failed.' })\n }\n } catch {\n setStatus({ kind: 'error', msg: 'Request failed. Is the server running?' })\n }\n }\n\n return (\n <div className=\"field-type\" style={{ marginTop: '1rem' }}>\n <label className=\"field-label\">Send a test email</label>\n <p style={{ fontSize: '.85rem', marginTop: 0, opacity: 0.7 }}>\n Sends through the transport selected above. Save your changes first.\n </p>\n <div style={{ alignItems: 'center', display: 'flex', flexWrap: 'wrap', gap: '.5rem' }}>\n <input\n onChange={(e) => setTo(e.target.value)}\n placeholder=\"[email protected]\"\n style={{ flex: 1, minWidth: '220px' }}\n type=\"email\"\n value={to}\n />\n <button\n className=\"btn btn--style-secondary\"\n disabled={status.kind === 'sending'}\n onClick={send}\n style={{ whiteSpace: 'nowrap' }}\n type=\"button\"\n >\n {status.kind === 'sending' ? 'Sending…' : 'Send test'}\n </button>\n </div>\n {status.kind === 'ok' && (\n <p style={{ color: 'var(--theme-success-500, green)', marginTop: '.5rem' }}>\n ✓ {status.msg}\n </p>\n )}\n {status.kind === 'error' && (\n <p style={{ color: 'var(--theme-error-500, crimson)', marginTop: '.5rem' }}>\n ✗ {status.msg}\n </p>\n )}\n </div>\n )\n}\n\nexport default TestEmailButton\n"],"names":["useState","TestEmailButton","to","setTo","status","setStatus","kind","send","trim","msg","res","fetch","body","JSON","stringify","credentials","headers","method","data","json","ok","message","error","div","className","style","marginTop","label","p","fontSize","opacity","alignItems","display","flexWrap","gap","input","onChange","e","target","value","placeholder","flex","minWidth","type","button","disabled","onClick","whiteSpace","color"],"mappings":"AAAA;;AAEA,SAASA,QAAQ,QAAQ,QAAO;AAEhC;;;;;;;;CAQC,GACD,OAAO,MAAMC,kBAAkB;IAC7B,MAAM,CAACC,IAAIC,MAAM,GAAGH,SAAS;IAC7B,MAAM,CAACI,QAAQC,UAAU,GAAGL,SAK1B;QAAEM,MAAM;IAAO;IAEjB,MAAMC,OAAO;QACX,IAAI,CAACL,GAAGM,IAAI,IAAI;YACdH,UAAU;gBAAEC,MAAM;gBAASG,KAAK;YAA6B;YAC7D;QACF;QACAJ,UAAU;YAAEC,MAAM;QAAU;QAC5B,IAAI;YACF,MAAMI,MAAM,MAAMC,MAAM,wBAAwB;gBAC9CC,MAAMC,KAAKC,SAAS,CAAC;oBAAEZ,IAAIA,GAAGM,IAAI;gBAAG;gBACrCO,aAAa;gBACbC,SAAS;oBAAE,gBAAgB;gBAAmB;gBAC9CC,QAAQ;YACV;YACA,MAAMC,OAAO,MAAMR,IAAIS,IAAI;YAC3B,IAAID,KAAKE,EAAE,EAAE;gBACXf,UAAU;oBAAEC,MAAM;oBAAMG,KAAKS,KAAKG,OAAO,IAAI;gBAAmB;YAClE,OAAO;gBACLhB,UAAU;oBAAEC,MAAM;oBAASG,KAAKS,KAAKI,KAAK,IAAI;gBAAe;YAC/D;QACF,EAAE,OAAM;YACNjB,UAAU;gBAAEC,MAAM;gBAASG,KAAK;YAAyC;QAC3E;IACF;IAEA,qBACE,MAACc;QAAIC,WAAU;QAAaC,OAAO;YAAEC,WAAW;QAAO;;0BACrD,KAACC;gBAAMH,WAAU;0BAAc;;0BAC/B,KAACI;gBAAEH,OAAO;oBAAEI,UAAU;oBAAUH,WAAW;oBAAGI,SAAS;gBAAI;0BAAG;;0BAG9D,MAACP;gBAAIE,OAAO;oBAAEM,YAAY;oBAAUC,SAAS;oBAAQC,UAAU;oBAAQC,KAAK;gBAAQ;;kCAClF,KAACC;wBACCC,UAAU,CAACC,IAAMlC,MAAMkC,EAAEC,MAAM,CAACC,KAAK;wBACrCC,aAAY;wBACZf,OAAO;4BAAEgB,MAAM;4BAAGC,UAAU;wBAAQ;wBACpCC,MAAK;wBACLJ,OAAOrC;;kCAET,KAAC0C;wBACCpB,WAAU;wBACVqB,UAAUzC,OAAOE,IAAI,KAAK;wBAC1BwC,SAASvC;wBACTkB,OAAO;4BAAEsB,YAAY;wBAAS;wBAC9BJ,MAAK;kCAEJvC,OAAOE,IAAI,KAAK,YAAY,aAAa;;;;YAG7CF,OAAOE,IAAI,KAAK,sBACf,MAACsB;gBAAEH,OAAO;oBAAEuB,OAAO;oBAAmCtB,WAAW;gBAAQ;;oBAAG;oBACvEtB,OAAOK,GAAG;;;YAGhBL,OAAOE,IAAI,KAAK,yBACf,MAACsB;gBAAEH,OAAO;oBAAEuB,OAAO;oBAAmCtB,WAAW;gBAAQ;;oBAAG;oBACvEtB,OAAOK,GAAG;;;;;AAKvB,EAAC;AAED,eAAeR,gBAAe"}
|
||||
+36
-1
@@ -5,8 +5,30 @@
|
||||
* user), so all fields — including the password — stay editable in the admin
|
||||
* panel while remaining inaccessible to anonymous API requests.
|
||||
*/ export const smtpFields = [
|
||||
{
|
||||
name: 'emailTransport',
|
||||
type: 'select',
|
||||
admin: {
|
||||
description: 'How outbound email is sent. "Microsoft Graph" is only available when configured by the administrator (Intecion).'
|
||||
},
|
||||
defaultValue: 'smtp',
|
||||
options: [
|
||||
{
|
||||
label: 'SMTP',
|
||||
value: 'smtp'
|
||||
},
|
||||
{
|
||||
label: 'Microsoft Graph (Exchange)',
|
||||
value: 'graph'
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
type: 'row',
|
||||
admin: {
|
||||
// Hide SMTP fields when Graph is selected — they're not used then.
|
||||
condition: (_, siblingData)=>siblingData?.emailTransport !== 'graph'
|
||||
},
|
||||
fields: [
|
||||
{
|
||||
name: 'smtpHost',
|
||||
@@ -37,7 +59,11 @@
|
||||
name: 'smtpPassword',
|
||||
type: 'text',
|
||||
admin: {
|
||||
description: 'SMTP account password.'
|
||||
description: 'SMTP account password.',
|
||||
// Masked in the UI (••••) — stored plaintext, readable for SMTP auth.
|
||||
components: {
|
||||
Field: '@intecion/ipal-kit/client#MaskedField'
|
||||
}
|
||||
}
|
||||
},
|
||||
{
|
||||
@@ -53,6 +79,15 @@
|
||||
admin: {
|
||||
description: 'Default "from" display name.'
|
||||
}
|
||||
},
|
||||
{
|
||||
name: 'emailTest',
|
||||
type: 'ui',
|
||||
admin: {
|
||||
components: {
|
||||
Field: '@intecion/ipal-kit/client#TestEmailButton'
|
||||
}
|
||||
}
|
||||
}
|
||||
];
|
||||
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/smtp.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * SMTP transport settings for outbound email.\n *\n * Protected at the global level (SiteIntegrations requires an authenticated\n * user), so all fields — including the password — stay editable in the admin\n * panel while remaining inaccessible to anonymous API requests.\n */\nexport const smtpFields: Field[] = [\n {\n type: 'row',\n fields: [\n {\n name: 'smtpHost',\n type: 'text',\n admin: { placeholder: 'smtp.example.com', width: '70%' },\n },\n {\n name: 'smtpPort',\n type: 'number',\n admin: { width: '30%' },\n defaultValue: 587,\n },\n ],\n },\n {\n name: 'smtpUser',\n type: 'text',\n admin: {\n description: 'SMTP account username.',\n },\n },\n {\n name: 'smtpPassword',\n type: 'text',\n admin: {\n description: 'SMTP account password.',\n },\n },\n {\n name: 'smtpFromAddress',\n type: 'email',\n admin: {\n description: 'Default \"from\" address for outgoing mail.',\n },\n },\n {\n name: 'smtpFromName',\n type: 'text',\n admin: {\n description: 'Default \"from\" display name.',\n },\n },\n]\n"],"names":["smtpFields","type","fields","name","admin","placeholder","width","defaultValue","description"],"mappings":"AAEA;;;;;;CAMC,GACD,OAAO,MAAMA,aAAsB;IACjC;QACEC,MAAM;QACNC,QAAQ;YACN;gBACEC,MAAM;gBACNF,MAAM;gBACNG,OAAO;oBAAEC,aAAa;oBAAoBC,OAAO;gBAAM;YACzD;YACA;gBACEH,MAAM;gBACNF,MAAM;gBACNG,OAAO;oBAAEE,OAAO;gBAAM;gBACtBC,cAAc;YAChB;SACD;IACH;IACA;QACEJ,MAAM;QACNF,MAAM;QACNG,OAAO;YACLI,aAAa;QACf;IACF;IACA;QACEL,MAAM;QACNF,MAAM;QACNG,OAAO;YACLI,aAAa;QACf;IACF;IACA;QACEL,MAAM;QACNF,MAAM;QACNG,OAAO;YACLI,aAAa;QACf;IACF;IACA;QACEL,MAAM;QACNF,MAAM;QACNG,OAAO;YACLI,aAAa;QACf;IACF;CACD,CAAA"}
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/smtp.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * SMTP transport settings for outbound email.\n *\n * Protected at the global level (SiteIntegrations requires an authenticated\n * user), so all fields — including the password — stay editable in the admin\n * panel while remaining inaccessible to anonymous API requests.\n */\nexport const smtpFields: Field[] = [\n {\n name: 'emailTransport',\n type: 'select',\n admin: {\n description:\n 'How outbound email is sent. \"Microsoft Graph\" is only available when configured by the administrator (Intecion).',\n // The Graph option only makes sense when agency credentials exist in env.\n // We can't read process.env in the admin UI directly, so a client project\n // that hasn't set up Graph should filter this option via integrationsFields\n // override, or simply leave it on 'smtp'. The adapter enforces the real\n // availability at send time regardless of what's selected here.\n },\n defaultValue: 'smtp',\n options: [\n { label: 'SMTP', value: 'smtp' },\n { label: 'Microsoft Graph (Exchange)', value: 'graph' },\n ],\n },\n {\n type: 'row',\n admin: {\n // Hide SMTP fields when Graph is selected — they're not used then.\n condition: (_, siblingData) => siblingData?.emailTransport !== 'graph',\n },\n fields: [\n {\n name: 'smtpHost',\n type: 'text',\n admin: { placeholder: 'smtp.example.com', width: '70%' },\n },\n {\n name: 'smtpPort',\n type: 'number',\n admin: { width: '30%' },\n defaultValue: 587,\n },\n ],\n },\n {\n name: 'smtpUser',\n type: 'text',\n admin: {\n description: 'SMTP account username.',\n },\n },\n {\n name: 'smtpPassword',\n type: 'text',\n admin: {\n description: 'SMTP account password.',\n // Masked in the UI (••••) — stored plaintext, readable for SMTP auth.\n components: {\n Field: '@intecion/ipal-kit/client#MaskedField',\n },\n },\n },\n {\n name: 'smtpFromAddress',\n type: 'email',\n admin: {\n description: 'Default \"from\" address for outgoing mail.',\n },\n },\n {\n name: 'smtpFromName',\n type: 'text',\n admin: {\n description: 'Default \"from\" display name.',\n },\n },\n {\n name: 'emailTest',\n type: 'ui',\n admin: {\n components: {\n Field: '@intecion/ipal-kit/client#TestEmailButton',\n },\n },\n },\n]\n"],"names":["smtpFields","name","type","admin","description","defaultValue","options","label","value","condition","_","siblingData","emailTransport","fields","placeholder","width","components","Field"],"mappings":"AAEA;;;;;;CAMC,GACD,OAAO,MAAMA,aAAsB;IACjC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aACE;QAMJ;QACAC,cAAc;QACdC,SAAS;YACP;gBAAEC,OAAO;gBAAQC,OAAO;YAAO;YAC/B;gBAAED,OAAO;gBAA8BC,OAAO;YAAQ;SACvD;IACH;IACA;QACEN,MAAM;QACNC,OAAO;YACL,mEAAmE;YACnEM,WAAW,CAACC,GAAGC,cAAgBA,aAAaC,mBAAmB;QACjE;QACAC,QAAQ;YACN;gBACEZ,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEW,aAAa;oBAAoBC,OAAO;gBAAM;YACzD;YACA;gBACEd,MAAM;gBACNC,MAAM;gBACNC,OAAO;oBAAEY,OAAO;gBAAM;gBACtBV,cAAc;YAChB;SACD;IACH;IACA;QACEJ,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;YACb,sEAAsE;YACtEY,YAAY;gBACVC,OAAO;YACT;QACF;IACF;IACA;QACEhB,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLa,YAAY;gBACVC,OAAO;YACT;QACF;IACF;CACD,CAAA"}
|
||||
+5
-1
@@ -31,7 +31,11 @@
|
||||
name: 'r2SecretAccessKey',
|
||||
type: 'text',
|
||||
admin: {
|
||||
description: 'R2 secret access key.'
|
||||
description: 'R2 secret access key.',
|
||||
// Masked in the UI (••••) — stored plaintext, readable for R2 auth.
|
||||
components: {
|
||||
Field: '@intecion/ipal-kit/client#MaskedField'
|
||||
}
|
||||
}
|
||||
}
|
||||
];
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/storage.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Cloudflare R2 storage credentials.\n * Reserved for future use — media offloading to R2.\n *\n * Protected at the global level (SiteIntegrations requires an authenticated\n * user), so the access keys stay editable in the admin panel while remaining\n * inaccessible to anonymous API requests.\n */\nexport const storageFields: Field[] = [\n {\n name: 'r2Bucket',\n type: 'text',\n admin: {\n description: 'R2 bucket name.',\n },\n },\n {\n name: 'r2Endpoint',\n type: 'text',\n admin: {\n description: 'R2 S3-compatible endpoint URL.',\n },\n },\n {\n name: 'r2AccessKeyId',\n type: 'text',\n admin: {\n description: 'R2 access key ID.',\n },\n },\n {\n name: 'r2SecretAccessKey',\n type: 'text',\n admin: {\n description: 'R2 secret access key.',\n },\n },\n]\n"],"names":["storageFields","name","type","admin","description"],"mappings":"AAEA;;;;;;;CAOC,GACD,OAAO,MAAMA,gBAAyB;IACpC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;CACD,CAAA"}
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/storage.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Cloudflare R2 storage credentials.\n * Reserved for future use — media offloading to R2.\n *\n * Protected at the global level (SiteIntegrations requires an authenticated\n * user), so the access keys stay editable in the admin panel while remaining\n * inaccessible to anonymous API requests.\n */\nexport const storageFields: Field[] = [\n {\n name: 'r2Bucket',\n type: 'text',\n admin: {\n description: 'R2 bucket name.',\n },\n },\n {\n name: 'r2Endpoint',\n type: 'text',\n admin: {\n description: 'R2 S3-compatible endpoint URL.',\n },\n },\n {\n name: 'r2AccessKeyId',\n type: 'text',\n admin: {\n description: 'R2 access key ID.',\n },\n },\n {\n name: 'r2SecretAccessKey',\n type: 'text',\n admin: {\n description: 'R2 secret access key.',\n // Masked in the UI (••••) — stored plaintext, readable for R2 auth.\n components: {\n Field: '@intecion/ipal-kit/client#MaskedField',\n },\n },\n },\n]\n"],"names":["storageFields","name","type","admin","description","components","Field"],"mappings":"AAEA;;;;;;;CAOC,GACD,OAAO,MAAMA,gBAAyB;IACpC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;YACb,oEAAoE;YACpEC,YAAY;gBACVC,OAAO;YACT;QACF;IACF;CACD,CAAA"}
|
||||
+5
-1
@@ -17,7 +17,11 @@
|
||||
name: 'turnstileSecretKey',
|
||||
type: 'text',
|
||||
admin: {
|
||||
description: 'Secret key used for server-side verification.'
|
||||
description: 'Secret key used for server-side verification.',
|
||||
// Masked in the UI (••••) — stored plaintext, readable for verification.
|
||||
components: {
|
||||
Field: '@intecion/ipal-kit/client#MaskedField'
|
||||
}
|
||||
}
|
||||
}
|
||||
];
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/turnstile.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Cloudflare Turnstile credentials.\n *\n * siteKey is public (rendered in the widget); secretKey is used for\n * server-side verification. Both are protected at the global level\n * (SiteIntegrations requires an authenticated user) rather than per-field,\n * so they remain editable in the admin panel.\n */\nexport const turnstileFields: Field[] = [\n {\n name: 'turnstileSiteKey',\n type: 'text',\n admin: {\n description: 'Public site key rendered in the Turnstile widget.',\n },\n },\n {\n name: 'turnstileSecretKey',\n type: 'text',\n admin: {\n description: 'Secret key used for server-side verification.',\n },\n },\n]\n"],"names":["turnstileFields","name","type","admin","description"],"mappings":"AAEA;;;;;;;CAOC,GACD,OAAO,MAAMA,kBAA2B;IACtC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;CACD,CAAA"}
|
||||
{"version":3,"sources":["../../../../src/globals/SiteIntegrations/fields/turnstile.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * Cloudflare Turnstile credentials.\n *\n * siteKey is public (rendered in the widget); secretKey is used for\n * server-side verification. Both are protected at the global level\n * (SiteIntegrations requires an authenticated user) rather than per-field,\n * so they remain editable in the admin panel.\n */\nexport const turnstileFields: Field[] = [\n {\n name: 'turnstileSiteKey',\n type: 'text',\n admin: {\n description: 'Public site key rendered in the Turnstile widget.',\n },\n },\n {\n name: 'turnstileSecretKey',\n type: 'text',\n admin: {\n description: 'Secret key used for server-side verification.',\n // Masked in the UI (••••) — stored plaintext, readable for verification.\n components: {\n Field: '@intecion/ipal-kit/client#MaskedField',\n },\n },\n },\n]\n"],"names":["turnstileFields","name","type","admin","description","components","Field"],"mappings":"AAEA;;;;;;;CAOC,GACD,OAAO,MAAMA,kBAA2B;IACtC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;IACF;IACA;QACEH,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;YACb,yEAAyE;YACzEC,YAAY;gBACVC,OAAO;YACT;QACF;IACF;CACD,CAAA"}
|
||||
+4
@@ -14,6 +14,10 @@ type BuildSiteIntegrationsArgs = {
|
||||
* impossible to enter.)
|
||||
*
|
||||
* Unnamed tabs keep data flat (siteIntegrations.ga4MeasurementId).
|
||||
*
|
||||
* Note: R2 storage credentials are NOT here — storage is infrastructure and
|
||||
* binds at boot, so its config lives in .env (R2_BUCKET, R2_ENDPOINT, ...),
|
||||
* consumed by buildR2Storage. See docs/storage.md.
|
||||
*/
|
||||
export declare function buildSiteIntegrations({ additionalFields, }?: BuildSiteIntegrationsArgs): GlobalConfig;
|
||||
export {};
|
||||
|
||||
+4
-5
@@ -1,7 +1,6 @@
|
||||
import { isAdmin } from '../../modules/access/index.js';
|
||||
import { analyticsFields } from './fields/analytics.js';
|
||||
import { smtpFields } from './fields/smtp.js';
|
||||
import { storageFields } from './fields/storage.js';
|
||||
import { turnstileFields } from './fields/turnstile.js';
|
||||
/**
|
||||
* Builds the SiteIntegrations global.
|
||||
@@ -14,6 +13,10 @@ import { turnstileFields } from './fields/turnstile.js';
|
||||
* impossible to enter.)
|
||||
*
|
||||
* Unnamed tabs keep data flat (siteIntegrations.ga4MeasurementId).
|
||||
*
|
||||
* Note: R2 storage credentials are NOT here — storage is infrastructure and
|
||||
* binds at boot, so its config lives in .env (R2_BUCKET, R2_ENDPOINT, ...),
|
||||
* consumed by buildR2Storage. See docs/storage.md.
|
||||
*/ export function buildSiteIntegrations({ additionalFields } = {}) {
|
||||
return {
|
||||
slug: 'site-integrations',
|
||||
@@ -42,10 +45,6 @@ import { turnstileFields } from './fields/turnstile.js';
|
||||
fields: smtpFields,
|
||||
label: 'SMTP'
|
||||
},
|
||||
{
|
||||
fields: storageFields,
|
||||
label: 'Storage'
|
||||
},
|
||||
...additionalFields?.length ? [
|
||||
{
|
||||
fields: additionalFields,
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../src/globals/SiteIntegrations/index.ts"],"sourcesContent":["import type { Field, GlobalConfig } from 'payload'\n\nimport { isAdmin } from '../../modules/access/index.js'\nimport { analyticsFields } from './fields/analytics.js'\nimport { smtpFields } from './fields/smtp.js'\nimport { storageFields } from './fields/storage.js'\nimport { turnstileFields } from './fields/turnstile.js'\n\ntype BuildSiteIntegrationsArgs = {\n /** Extra fields injected by the client project */\n additionalFields?: Field[]\n}\n\n/**\n * Builds the SiteIntegrations global.\n *\n * Holds third-party service credentials. Access is enforced at the global\n * level — the whole global requires an authenticated user — so secrets stay\n * out of anonymous API responses while remaining editable in the admin panel\n * and readable via the server-side Local API. (Field-level read:false was\n * avoided because it also hides fields from the admin UI, making them\n * impossible to enter.)\n *\n * Unnamed tabs keep data flat (siteIntegrations.ga4MeasurementId).\n */\nexport function buildSiteIntegrations({\n additionalFields,\n}: BuildSiteIntegrationsArgs = {}): GlobalConfig {\n return {\n slug: 'site-integrations',\n access: {\n // Admin-only — secrets live here. Anonymous and non-admin users get\n // nothing through the API; admins read/edit in the panel and via Local API.\n read: ({ req: { user } }) => isAdmin(user),\n update: ({ req: { user } }) => isAdmin(user),\n },\n admin: {\n group: 'Settings',\n },\n fields: [\n {\n type: 'tabs',\n tabs: [\n { fields: analyticsFields, label: 'Analytics' },\n { fields: turnstileFields, label: 'Turnstile' },\n { fields: smtpFields, label: 'SMTP' },\n { fields: storageFields, label: 'Storage' },\n ...(additionalFields?.length ? [{ fields: additionalFields, label: 'Custom' }] : []),\n ],\n },\n ],\n label: 'Site Integrations',\n }\n}\n"],"names":["isAdmin","analyticsFields","smtpFields","storageFields","turnstileFields","buildSiteIntegrations","additionalFields","slug","access","read","req","user","update","admin","group","fields","type","tabs","label","length"],"mappings":"AAEA,SAASA,OAAO,QAAQ,gCAA+B;AACvD,SAASC,eAAe,QAAQ,wBAAuB;AACvD,SAASC,UAAU,QAAQ,mBAAkB;AAC7C,SAASC,aAAa,QAAQ,sBAAqB;AACnD,SAASC,eAAe,QAAQ,wBAAuB;AAOvD;;;;;;;;;;;CAWC,GACD,OAAO,SAASC,sBAAsB,EACpCC,gBAAgB,EACU,GAAG,CAAC,CAAC;IAC/B,OAAO;QACLC,MAAM;QACNC,QAAQ;YACN,oEAAoE;YACpE,4EAA4E;YAC5EC,MAAM,CAAC,EAAEC,KAAK,EAAEC,IAAI,EAAE,EAAE,GAAKX,QAAQW;YACrCC,QAAQ,CAAC,EAAEF,KAAK,EAAEC,IAAI,EAAE,EAAE,GAAKX,QAAQW;QACzC;QACAE,OAAO;YACLC,OAAO;QACT;QACAC,QAAQ;YACN;gBACEC,MAAM;gBACNC,MAAM;oBACJ;wBAAEF,QAAQd;wBAAiBiB,OAAO;oBAAY;oBAC9C;wBAAEH,QAAQX;wBAAiBc,OAAO;oBAAY;oBAC9C;wBAAEH,QAAQb;wBAAYgB,OAAO;oBAAO;oBACpC;wBAAEH,QAAQZ;wBAAee,OAAO;oBAAU;uBACtCZ,kBAAkBa,SAAS;wBAAC;4BAAEJ,QAAQT;4BAAkBY,OAAO;wBAAS;qBAAE,GAAG,EAAE;iBACpF;YACH;SACD;QACDA,OAAO;IACT;AACF"}
|
||||
{"version":3,"sources":["../../../src/globals/SiteIntegrations/index.ts"],"sourcesContent":["import type { Field, GlobalConfig } from 'payload'\n\nimport { isAdmin } from '../../modules/access/index.js'\nimport { analyticsFields } from './fields/analytics.js'\nimport { smtpFields } from './fields/smtp.js'\nimport { turnstileFields } from './fields/turnstile.js'\n\ntype BuildSiteIntegrationsArgs = {\n /** Extra fields injected by the client project */\n additionalFields?: Field[]\n}\n\n/**\n * Builds the SiteIntegrations global.\n *\n * Holds third-party service credentials. Access is enforced at the global\n * level — the whole global requires an authenticated user — so secrets stay\n * out of anonymous API responses while remaining editable in the admin panel\n * and readable via the server-side Local API. (Field-level read:false was\n * avoided because it also hides fields from the admin UI, making them\n * impossible to enter.)\n *\n * Unnamed tabs keep data flat (siteIntegrations.ga4MeasurementId).\n *\n * Note: R2 storage credentials are NOT here — storage is infrastructure and\n * binds at boot, so its config lives in .env (R2_BUCKET, R2_ENDPOINT, ...),\n * consumed by buildR2Storage. See docs/storage.md.\n */\nexport function buildSiteIntegrations({\n additionalFields,\n}: BuildSiteIntegrationsArgs = {}): GlobalConfig {\n return {\n slug: 'site-integrations',\n access: {\n // Admin-only — secrets live here. Anonymous and non-admin users get\n // nothing through the API; admins read/edit in the panel and via Local API.\n read: ({ req: { user } }) => isAdmin(user),\n update: ({ req: { user } }) => isAdmin(user),\n },\n admin: {\n group: 'Settings',\n },\n fields: [\n {\n type: 'tabs',\n tabs: [\n { fields: analyticsFields, label: 'Analytics' },\n { fields: turnstileFields, label: 'Turnstile' },\n { fields: smtpFields, label: 'SMTP' },\n ...(additionalFields?.length ? [{ fields: additionalFields, label: 'Custom' }] : []),\n ],\n },\n ],\n label: 'Site Integrations',\n }\n}\n"],"names":["isAdmin","analyticsFields","smtpFields","turnstileFields","buildSiteIntegrations","additionalFields","slug","access","read","req","user","update","admin","group","fields","type","tabs","label","length"],"mappings":"AAEA,SAASA,OAAO,QAAQ,gCAA+B;AACvD,SAASC,eAAe,QAAQ,wBAAuB;AACvD,SAASC,UAAU,QAAQ,mBAAkB;AAC7C,SAASC,eAAe,QAAQ,wBAAuB;AAOvD;;;;;;;;;;;;;;;CAeC,GACD,OAAO,SAASC,sBAAsB,EACpCC,gBAAgB,EACU,GAAG,CAAC,CAAC;IAC/B,OAAO;QACLC,MAAM;QACNC,QAAQ;YACN,oEAAoE;YACpE,4EAA4E;YAC5EC,MAAM,CAAC,EAAEC,KAAK,EAAEC,IAAI,EAAE,EAAE,GAAKV,QAAQU;YACrCC,QAAQ,CAAC,EAAEF,KAAK,EAAEC,IAAI,EAAE,EAAE,GAAKV,QAAQU;QACzC;QACAE,OAAO;YACLC,OAAO;QACT;QACAC,QAAQ;YACN;gBACEC,MAAM;gBACNC,MAAM;oBACJ;wBAAEF,QAAQb;wBAAiBgB,OAAO;oBAAY;oBAC9C;wBAAEH,QAAQX;wBAAiBc,OAAO;oBAAY;oBAC9C;wBAAEH,QAAQZ;wBAAYe,OAAO;oBAAO;uBAChCZ,kBAAkBa,SAAS;wBAAC;4BAAEJ,QAAQT;4BAAkBY,OAAO;wBAAS;qBAAE,GAAG,EAAE;iBACpF;YACH;SACD;QACDA,OAAO;IACT;AACF"}
|
||||
+16
-1
@@ -1,3 +1,4 @@
|
||||
import { validateFaviconField } from '../../../modules/seo/index.js';
|
||||
/**
|
||||
* General site identity fields.
|
||||
* Consumed by SEO/OG (siteName, defaultShareImage) and frontend (logo).
|
||||
@@ -11,6 +12,14 @@
|
||||
localized: true,
|
||||
required: true
|
||||
},
|
||||
{
|
||||
name: 'siteDescription',
|
||||
type: 'textarea',
|
||||
admin: {
|
||||
description: 'Fallback meta description when a page has none. Also used for llms.txt and Open Graph.'
|
||||
},
|
||||
localized: true
|
||||
},
|
||||
{
|
||||
name: 'titleOrder',
|
||||
type: 'select',
|
||||
@@ -79,7 +88,13 @@
|
||||
name: 'favicon',
|
||||
type: 'upload',
|
||||
admin: {
|
||||
description: 'Square source icon (PNG or SVG) for the browser tab. Rendered by the frontend.'
|
||||
description: 'Square icon, PNG or SVG, min. 48×48px (Google requires this to show it in search). Rendered via buildIconsMetadata.'
|
||||
},
|
||||
hooks: {
|
||||
// Warn the editor if the favicon is too small / not square for Google.
|
||||
beforeValidate: [
|
||||
validateFaviconField
|
||||
]
|
||||
},
|
||||
relationTo: 'media'
|
||||
}
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../../src/globals/SiteSettings/fields/general.ts"],"sourcesContent":["import type { Field } from 'payload'\n\n/**\n * General site identity fields.\n * Consumed by SEO/OG (siteName, defaultShareImage) and frontend (logo).\n */\nexport const generalFields: Field[] = [\n {\n name: 'siteName',\n type: 'text',\n admin: {\n description: 'Used in page titles and Open Graph metadata.',\n },\n localized: true,\n required: true,\n },\n {\n name: 'titleOrder',\n type: 'select',\n admin: {\n description: 'Which comes first in browser tabs.',\n },\n defaultValue: 'page-first',\n options: [\n { label: 'Page first — About Us | Acme', value: 'page-first' },\n { label: 'Site first — Acme | About Us', value: 'site-first' },\n ],\n },\n {\n name: 'titleSeparator',\n type: 'select',\n admin: {\n description: 'Separates the page title from the site name in browser tabs.',\n },\n defaultValue: '|',\n options: [\n { label: 'Pipe — Page | Site', value: '|' },\n { label: 'Dash — Page – Site', value: '–' },\n { label: 'Hyphen — Page - Site', value: '-' },\n { label: 'Bullet — Page · Site', value: '·' },\n { label: 'Slash — Page / Site', value: '/' },\n ],\n },\n {\n name: 'logo',\n type: 'upload',\n admin: {\n description: 'Primary site logo.',\n },\n relationTo: 'media',\n },\n {\n name: 'defaultShareImage',\n type: 'upload',\n admin: {\n description: 'Fallback Open Graph image when a page has none.',\n },\n relationTo: 'media',\n },\n {\n name: 'favicon',\n type: 'upload',\n admin: {\n description: 'Square source icon (PNG or SVG) for the browser tab. Rendered by the frontend.',\n },\n relationTo: 'media',\n },\n]\n"],"names":["generalFields","name","type","admin","description","localized","required","defaultValue","options","label","value","relationTo"],"mappings":"AAEA;;;CAGC,GACD,OAAO,MAAMA,gBAAyB;IACpC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAC,WAAW;QACXC,UAAU;IACZ;IACA;QACEL,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAG,cAAc;QACdC,SAAS;YACP;gBAAEC,OAAO;gBAAkCC,OAAO;YAAa;YAC/D;gBAAED,OAAO;gBAAkCC,OAAO;YAAa;SAChE;IACH;IACA;QACET,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAG,cAAc;QACdC,SAAS;YACP;gBAAEC,OAAO;gBAAwBC,OAAO;YAAI;YAC5C;gBAAED,OAAO;gBAAwBC,OAAO;YAAI;YAC5C;gBAAED,OAAO;gBAA0BC,OAAO;YAAI;YAC9C;gBAAED,OAAO;gBAA0BC,OAAO;YAAI;YAC9C;gBAAED,OAAO;gBAAyBC,OAAO;YAAI;SAC9C;IACH;IACA;QACET,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAO,YAAY;IACd;IACA;QACEV,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAO,YAAY;IACd;IACA;QACEV,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAO,YAAY;IACd;CACD,CAAA"}
|
||||
{"version":3,"sources":["../../../../src/globals/SiteSettings/fields/general.ts"],"sourcesContent":["import type { Field } from 'payload'\n\nimport { validateFaviconField } from '../../../modules/seo/index.js'\n\n/**\n * General site identity fields.\n * Consumed by SEO/OG (siteName, defaultShareImage) and frontend (logo).\n */\nexport const generalFields: Field[] = [\n {\n name: 'siteName',\n type: 'text',\n admin: {\n description: 'Used in page titles and Open Graph metadata.',\n },\n localized: true,\n required: true,\n },\n {\n name: 'siteDescription',\n type: 'textarea',\n admin: {\n description:\n 'Fallback meta description when a page has none. Also used for llms.txt and Open Graph.',\n },\n localized: true,\n },\n {\n name: 'titleOrder',\n type: 'select',\n admin: {\n description: 'Which comes first in browser tabs.',\n },\n defaultValue: 'page-first',\n options: [\n { label: 'Page first — About Us | Acme', value: 'page-first' },\n { label: 'Site first — Acme | About Us', value: 'site-first' },\n ],\n },\n {\n name: 'titleSeparator',\n type: 'select',\n admin: {\n description: 'Separates the page title from the site name in browser tabs.',\n },\n defaultValue: '|',\n options: [\n { label: 'Pipe — Page | Site', value: '|' },\n { label: 'Dash — Page – Site', value: '–' },\n { label: 'Hyphen — Page - Site', value: '-' },\n { label: 'Bullet — Page · Site', value: '·' },\n { label: 'Slash — Page / Site', value: '/' },\n ],\n },\n {\n name: 'logo',\n type: 'upload',\n admin: {\n description: 'Primary site logo.',\n },\n relationTo: 'media',\n },\n {\n name: 'defaultShareImage',\n type: 'upload',\n admin: {\n description: 'Fallback Open Graph image when a page has none.',\n },\n relationTo: 'media',\n },\n {\n name: 'favicon',\n type: 'upload',\n admin: {\n description:\n 'Square icon, PNG or SVG, min. 48×48px (Google requires this to show it in search). Rendered via buildIconsMetadata.',\n },\n hooks: {\n // Warn the editor if the favicon is too small / not square for Google.\n beforeValidate: [validateFaviconField],\n },\n relationTo: 'media',\n },\n]\n"],"names":["validateFaviconField","generalFields","name","type","admin","description","localized","required","defaultValue","options","label","value","relationTo","hooks","beforeValidate"],"mappings":"AAEA,SAASA,oBAAoB,QAAQ,gCAA+B;AAEpE;;;CAGC,GACD,OAAO,MAAMC,gBAAyB;IACpC;QACEC,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAC,WAAW;QACXC,UAAU;IACZ;IACA;QACEL,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aACE;QACJ;QACAC,WAAW;IACb;IACA;QACEJ,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAG,cAAc;QACdC,SAAS;YACP;gBAAEC,OAAO;gBAAkCC,OAAO;YAAa;YAC/D;gBAAED,OAAO;gBAAkCC,OAAO;YAAa;SAChE;IACH;IACA;QACET,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAG,cAAc;QACdC,SAAS;YACP;gBAAEC,OAAO;gBAAwBC,OAAO;YAAI;YAC5C;gBAAED,OAAO;gBAAwBC,OAAO;YAAI;YAC5C;gBAAED,OAAO;gBAA0BC,OAAO;YAAI;YAC9C;gBAAED,OAAO;gBAA0BC,OAAO;YAAI;YAC9C;gBAAED,OAAO;gBAAyBC,OAAO;YAAI;SAC9C;IACH;IACA;QACET,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAO,YAAY;IACd;IACA;QACEV,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aAAa;QACf;QACAO,YAAY;IACd;IACA;QACEV,MAAM;QACNC,MAAM;QACNC,OAAO;YACLC,aACE;QACJ;QACAQ,OAAO;YACL,uEAAuE;YACvEC,gBAAgB;gBAACd;aAAqB;QACxC;QACAY,YAAY;IACd;CACD,CAAA"}
|
||||
Vendored
+19
@@ -7,23 +7,42 @@ export type { ConsentCategory, ConsentState, ConsentTexts } from './modules/cons
|
||||
export type { ContentCollectionOption, ContentOption, ResolvedRoute, } from './modules/content/index.js';
|
||||
export { archiveFieldName, buildArchivePath, buildEntryPath, getArchiveEntries, parsePageParam, resolveRoute, } from './modules/content/index.js';
|
||||
export type { ArchiveEntries } from './modules/content/index.js';
|
||||
export { graphAdapter } from './modules/email/graphAdapter.js';
|
||||
export type { GraphAdapterArgs } from './modules/email/graphAdapter.js';
|
||||
export { mailAdapter } from './modules/email/mailAdapter.js';
|
||||
export type { MailAdapterArgs } from './modules/email/mailAdapter.js';
|
||||
export { panelSmtpAdapter } from './modules/email/panelSmtpAdapter.js';
|
||||
export type { PanelSmtpAdapterArgs } from './modules/email/panelSmtpAdapter.js';
|
||||
export { buildFormsPlugin } from './modules/forms/formsPluginConfig.js';
|
||||
export type { FormsCollectionOverrides, FormsFieldsOverride, FormsOption, } from './modules/forms/types.js';
|
||||
export { createContentHelpers } from './modules/frontend/index.js';
|
||||
export { buildPreventDeleteSystemPage, buildRevalidateHook, buildValidateUniqueRole, setPublishedAtHook, trackSlugHistoryHook, } from './modules/hooks/index.js';
|
||||
export type { I18nConfig, LocaleDefinition, LocalizedSlugs } from './modules/i18n/index.js';
|
||||
export { buildLocalizedPath, getDefaultLocale, getLocaleCodes, getLocaleDefinition, getLocalizedSlugs, isValidLocale, LOCALE_COOKIE_NAME, matchAcceptLanguage, negotiateLocale, switchLocalePath, } from './modules/i18n/index.js';
|
||||
export type { LocaleMiddlewareResult } from './modules/i18n/index.js';
|
||||
export { createLocaleMiddleware, DEFAULT_MIDDLEWARE_MATCHER } from './modules/i18n/index.js';
|
||||
export { normalizeFilename, normalizeFilenameHook } from './modules/media/index.js';
|
||||
export { getNotificationTexts, NOTIFICATION_FALLBACK, resolveFormMessage, } from './modules/notifications/index.js';
|
||||
export type { FormNotificationTexts, NotificationTexts } from './modules/notifications/index.js';
|
||||
export type { PagesOption, SystemPageRole } from './modules/pages/index.js';
|
||||
export { ALL_SYSTEM_PAGE_ROLES, getSystemPagePath } from './modules/pages/index.js';
|
||||
export type { GlobalQueryOptions } from './modules/payload/index.js';
|
||||
export { getGlobal, getSiteIntegrations, getSiteSettings, SITE_INTEGRATIONS_SLUG, SITE_SETTINGS_SLUG, } from './modules/payload/index.js';
|
||||
export { buildSecurityHeaders } from './modules/security/index.js';
|
||||
export { buildCsp } from './modules/security/index.js';
|
||||
export type { BuildCspArgs } from './modules/security/index.js';
|
||||
export type { BuildSecurityHeadersArgs, SecurityHeader } from './modules/security/index.js';
|
||||
export type { PageMetadata, SeoMeta, SeoOption } from './modules/seo/index.js';
|
||||
export { buildHreflangAlternates, buildMetadata, composeTitle } from './modules/seo/index.js';
|
||||
export type { AutoFillMapping, RobotsRules, SitemapEntry } from './modules/seo/index.js';
|
||||
export { buildAutoFillMetaHook, buildRobots, buildSitemapEntries, createMetadataGenerator, createPageMetadata, injectAutoFillMeta, } from './modules/seo/index.js';
|
||||
export { buildIconsMetadata, buildOrganizationJsonLd, validateFaviconField, } from './modules/seo/index.js';
|
||||
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd, } from './modules/seo/index.js';
|
||||
export { buildFaqJsonLd, buildLocalBusinessJsonLd, buildServiceJsonLd, } from './modules/seo/index.js';
|
||||
export { buildArticleJsonLd } from './modules/seo/index.js';
|
||||
export { buildSitemapXml } from './modules/seo/index.js';
|
||||
export { buildLlmsTxt } from './modules/seo/index.js';
|
||||
export { buildSlugField, toSlug } from './modules/slug/index.js';
|
||||
export { buildR2Storage } from './modules/storage/index.js';
|
||||
export { ipalKit } from './plugin.js';
|
||||
export type { IpalOptions } from './types.js';
|
||||
|
||||
Vendored
+15
@@ -2,19 +2,34 @@ export { adminOnly, adminOnlyField, adminOrEditor, adminOrEditorField, adminOrSe
|
||||
export { getAnalyticsConfig } from './modules/analytics/index.js';
|
||||
export { ACCEPT_ALL_CONSENT, CONSENT_CATEGORIES, CONSENT_COOKIE, CONSENT_MAX_AGE, CONSENT_VERSION, DEFAULT_CONSENT, getConsentTexts, parseConsent, REJECT_ALL_CONSENT, serializeConsent, setDefaultConsent, updateConsent } from './modules/consent/index.js';
|
||||
export { archiveFieldName, buildArchivePath, buildEntryPath, getArchiveEntries, parsePageParam, resolveRoute } from './modules/content/index.js';
|
||||
export { graphAdapter } from './modules/email/graphAdapter.js';
|
||||
export { mailAdapter } from './modules/email/mailAdapter.js';
|
||||
// Imported straight from the file, NOT from ./modules/email/index.js — that
|
||||
// barrel re-exports sendEmail, which imports 'server-only' and would crash when
|
||||
// Payload loads the config (or runs generate:importmap) as a plain Node script.
|
||||
export { panelSmtpAdapter } from './modules/email/panelSmtpAdapter.js';
|
||||
export { buildFormsPlugin } from './modules/forms/formsPluginConfig.js';
|
||||
export { createContentHelpers } from './modules/frontend/index.js';
|
||||
export { buildPreventDeleteSystemPage, buildRevalidateHook, buildValidateUniqueRole, setPublishedAtHook, trackSlugHistoryHook } from './modules/hooks/index.js';
|
||||
export { buildLocalizedPath, getDefaultLocale, getLocaleCodes, getLocaleDefinition, getLocalizedSlugs, isValidLocale, LOCALE_COOKIE_NAME, matchAcceptLanguage, negotiateLocale, switchLocalePath } from './modules/i18n/index.js';
|
||||
export { createLocaleMiddleware, DEFAULT_MIDDLEWARE_MATCHER } from './modules/i18n/index.js';
|
||||
export { normalizeFilename, normalizeFilenameHook } from './modules/media/index.js';
|
||||
export { getNotificationTexts, NOTIFICATION_FALLBACK, resolveFormMessage } from './modules/notifications/index.js';
|
||||
export { ALL_SYSTEM_PAGE_ROLES, getSystemPagePath } from './modules/pages/index.js';
|
||||
export { getGlobal, getSiteIntegrations, getSiteSettings, SITE_INTEGRATIONS_SLUG, SITE_SETTINGS_SLUG } from './modules/payload/index.js';
|
||||
export { buildSecurityHeaders } from './modules/security/index.js';
|
||||
export { buildCsp } from './modules/security/index.js';
|
||||
export { buildHreflangAlternates, buildMetadata, composeTitle } from './modules/seo/index.js';
|
||||
export { buildAutoFillMetaHook, buildRobots, buildSitemapEntries, createMetadataGenerator, createPageMetadata, injectAutoFillMeta } from './modules/seo/index.js';
|
||||
export { buildIconsMetadata, buildOrganizationJsonLd, validateFaviconField } from './modules/seo/index.js';
|
||||
export { buildBreadcrumbJsonLd, buildSiteNavigationJsonLd, buildWebSiteJsonLd } from './modules/seo/index.js';
|
||||
// Local SEO structured data — LocalBusiness (map pack), Service (offering), FAQPage.
|
||||
export { buildFaqJsonLd, buildLocalBusinessJsonLd, buildServiceJsonLd } from './modules/seo/index.js';
|
||||
export { buildArticleJsonLd } from './modules/seo/index.js';
|
||||
export { buildSitemapXml } from './modules/seo/index.js';
|
||||
export { buildLlmsTxt } from './modules/seo/index.js';
|
||||
export { buildSlugField, toSlug } from './modules/slug/index.js';
|
||||
export { buildR2Storage } from './modules/storage/index.js';
|
||||
export { ipalKit } from './plugin.js';
|
||||
|
||||
//# sourceMappingURL=index.js.map
|
||||
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+25
@@ -0,0 +1,25 @@
|
||||
import type { PayloadEmailAdapter } from 'payload';
|
||||
export type GraphAdapterArgs = {
|
||||
fallbackFromAddress?: string;
|
||||
fallbackFromName?: string;
|
||||
};
|
||||
/**
|
||||
* Payload email adapter that sends through Microsoft Graph (our Exchange),
|
||||
* using app-only client-credentials auth. Drop-in alternative to
|
||||
* panelSmtpAdapter — same PayloadEmailAdapter contract, so payload.sendEmail
|
||||
* and the form-builder's submission emails work unchanged.
|
||||
*
|
||||
* Split of configuration (deliberate):
|
||||
* - Graph credentials (tenant/client/secret/sender) = AGENCY secrets, from env.
|
||||
* The client never sees or sets them — it's our Exchange, one mailbox
|
||||
* (GRAPH_SENDER, e.g. [email protected]) for every project.
|
||||
* - From-display + recipient = per-project, from the panel (SiteIntegrations),
|
||||
* so an editor controls how the mail is labelled and where it lands.
|
||||
*
|
||||
* Wiring: email: process.env.GRAPH_CLIENT_ID ? graphAdapter() : panelSmtpAdapter()
|
||||
*
|
||||
* Azure setup (one-time, our side): App registration → Mail.Send APPLICATION
|
||||
* permission → admin consent → in Exchange, grant the app "Send As" on the
|
||||
* shared mailbox GRAPH_SENDER.
|
||||
*/
|
||||
export declare const graphAdapter: (args?: GraphAdapterArgs) => PayloadEmailAdapter;
|
||||
Vendored
+189
@@ -0,0 +1,189 @@
|
||||
import { getSiteIntegrations } from '../payload/index.js';
|
||||
/** Reads + validates the agency Graph credentials from env. */ function readGraphEnv() {
|
||||
const tenantId = process.env.GRAPH_TENANT_ID;
|
||||
const clientId = process.env.GRAPH_CLIENT_ID;
|
||||
const clientSecret = process.env.GRAPH_CLIENT_SECRET;
|
||||
const sender = process.env.GRAPH_SENDER;
|
||||
if (!tenantId || !clientId || !clientSecret || !sender) {
|
||||
return null;
|
||||
}
|
||||
return {
|
||||
clientId,
|
||||
clientSecret,
|
||||
sender,
|
||||
tenantId
|
||||
};
|
||||
}
|
||||
/**
|
||||
* Fetches an app-only access token via the OAuth2 client-credentials flow.
|
||||
* Scope MUST be '.../.default' — passing 'Mail.Send' directly is rejected
|
||||
* (AADSTS1002012). Tokens last ~1h; we fetch per send for simplicity and to
|
||||
* avoid holding state in a possibly multi-instance deployment. If you send at
|
||||
* high volume, cache by expiry.
|
||||
*/ async function getAccessToken(env) {
|
||||
const url = `https://login.microsoftonline.com/${env.tenantId}/oauth2/v2.0/token`;
|
||||
const body = new URLSearchParams({
|
||||
client_id: env.clientId,
|
||||
client_secret: env.clientSecret,
|
||||
grant_type: 'client_credentials',
|
||||
scope: 'https://graph.microsoft.com/.default'
|
||||
});
|
||||
const res = await fetch(url, {
|
||||
body,
|
||||
headers: {
|
||||
'Content-Type': 'application/x-www-form-urlencoded'
|
||||
},
|
||||
method: 'POST'
|
||||
});
|
||||
if (!res.ok) {
|
||||
const detail = await res.text();
|
||||
throw new Error(`Graph token request failed (${res.status}): ${detail}`);
|
||||
}
|
||||
const data = await res.json();
|
||||
if (!data.access_token) {
|
||||
throw new Error('Graph token response had no access_token');
|
||||
}
|
||||
return data.access_token;
|
||||
}
|
||||
/** Normalizes Payload's to/cc (string | string[] | Address[]) into Graph recipients. */ function toRecipients(value) {
|
||||
if (!value) {
|
||||
return [];
|
||||
}
|
||||
const list = Array.isArray(value) ? value : [
|
||||
value
|
||||
];
|
||||
return list.map((v)=>typeof v === 'string' ? v : v.address).filter((a)=>typeof a === 'string' && a.length > 0).map((address)=>({
|
||||
emailAddress: {
|
||||
address
|
||||
}
|
||||
}));
|
||||
}
|
||||
/**
|
||||
* Payload email adapter that sends through Microsoft Graph (our Exchange),
|
||||
* using app-only client-credentials auth. Drop-in alternative to
|
||||
* panelSmtpAdapter — same PayloadEmailAdapter contract, so payload.sendEmail
|
||||
* and the form-builder's submission emails work unchanged.
|
||||
*
|
||||
* Split of configuration (deliberate):
|
||||
* - Graph credentials (tenant/client/secret/sender) = AGENCY secrets, from env.
|
||||
* The client never sees or sets them — it's our Exchange, one mailbox
|
||||
* (GRAPH_SENDER, e.g. [email protected]) for every project.
|
||||
* - From-display + recipient = per-project, from the panel (SiteIntegrations),
|
||||
* so an editor controls how the mail is labelled and where it lands.
|
||||
*
|
||||
* Wiring: email: process.env.GRAPH_CLIENT_ID ? graphAdapter() : panelSmtpAdapter()
|
||||
*
|
||||
* Azure setup (one-time, our side): App registration → Mail.Send APPLICATION
|
||||
* permission → admin consent → in Exchange, grant the app "Send As" on the
|
||||
* shared mailbox GRAPH_SENDER.
|
||||
*/ export const graphAdapter = (args = {})=>({ payload })=>({
|
||||
name: 'ipal-graph',
|
||||
defaultFromAddress: args.fallbackFromAddress ?? 'noreply@localhost',
|
||||
defaultFromName: args.fallbackFromName ?? 'Website',
|
||||
sendEmail: async (message)=>{
|
||||
const env = readGraphEnv();
|
||||
if (!env) {
|
||||
payload.logger.error('[ipal] Email not sent: Graph is not configured. Set GRAPH_TENANT_ID, GRAPH_CLIENT_ID, GRAPH_CLIENT_SECRET, GRAPH_SENDER.');
|
||||
return {
|
||||
error: 'Graph is not configured (missing env vars).',
|
||||
sent: false
|
||||
};
|
||||
}
|
||||
// Display name on the From, WITHOUT triggering Send-As.
|
||||
//
|
||||
// The trick: we may set a `from` as long as its ADDRESS stays the sender
|
||||
// mailbox (GRAPH_SENDER) — only the display NAME changes. Exchange only
|
||||
// demands Send-As when the from ADDRESS differs from the mailbox, so a
|
||||
// same-address / custom-name From is allowed and gives each project its
|
||||
// own sender label (e.g. "Kancelaria Kędzierski") over the shared mailbox.
|
||||
//
|
||||
// The panel's from-address becomes Reply-To (so replies reach the client),
|
||||
// and the panel's from-name becomes the sender display name.
|
||||
const panel = await getSiteIntegrations(payload);
|
||||
const replyToAddress = panel.smtpFromAddress || undefined;
|
||||
const senderName = panel.smtpFromName || undefined;
|
||||
const to = toRecipients(message.to);
|
||||
if (to.length === 0) {
|
||||
payload.logger.error('[ipal] Email not sent: no valid recipient.');
|
||||
return {
|
||||
error: 'No valid recipient.',
|
||||
sent: false
|
||||
};
|
||||
}
|
||||
// Graph accepts either HTML or Text; Payload gives us html and/or text.
|
||||
const isHtml = typeof message.html === 'string' && message.html.length > 0;
|
||||
const content = isHtml ? String(message.html) : String(message.text ?? '');
|
||||
// Reply-To: prefer whatever the caller set; otherwise the panel address.
|
||||
const replyTo = message.replyTo ? toRecipients(message.replyTo) : replyToAddress ? [
|
||||
{
|
||||
emailAddress: {
|
||||
address: replyToAddress
|
||||
}
|
||||
}
|
||||
] : [];
|
||||
const graphMessage = {
|
||||
body: {
|
||||
content,
|
||||
contentType: isHtml ? 'HTML' : 'Text'
|
||||
},
|
||||
subject: message.subject ?? '',
|
||||
toRecipients: to,
|
||||
...message.cc ? {
|
||||
ccRecipients: toRecipients(message.cc)
|
||||
} : {},
|
||||
...message.bcc ? {
|
||||
bccRecipients: toRecipients(message.bcc)
|
||||
} : {},
|
||||
// From with the sender's OWN address (no Send-As) plus an optional
|
||||
// display name from the panel. Omit entirely when no name is set —
|
||||
// Graph then uses the mailbox's default name.
|
||||
...senderName ? {
|
||||
from: {
|
||||
emailAddress: {
|
||||
name: senderName,
|
||||
address: env.sender
|
||||
}
|
||||
}
|
||||
} : {},
|
||||
...replyTo.length > 0 ? {
|
||||
replyTo
|
||||
} : {}
|
||||
};
|
||||
try {
|
||||
const token = await getAccessToken(env);
|
||||
// App-only: MUST target /users/{sender}, never /me.
|
||||
const res = await fetch(`https://graph.microsoft.com/v1.0/users/${encodeURIComponent(env.sender)}/sendMail`, {
|
||||
body: JSON.stringify({
|
||||
message: graphMessage,
|
||||
saveToSentItems: false
|
||||
}),
|
||||
headers: {
|
||||
Authorization: `Bearer ${token}`,
|
||||
'Content-Type': 'application/json'
|
||||
},
|
||||
method: 'POST'
|
||||
});
|
||||
// sendMail returns 202 Accepted with an empty body on success.
|
||||
if (res.status === 202) {
|
||||
return {
|
||||
sent: true
|
||||
};
|
||||
}
|
||||
const detail = await res.text();
|
||||
payload.logger.error(`[ipal] Graph sendMail failed (${res.status}): ${detail}`);
|
||||
return {
|
||||
error: `Graph sendMail failed (${res.status}).`,
|
||||
sent: false
|
||||
};
|
||||
} catch (err) {
|
||||
const msg = err instanceof Error ? err.message : String(err);
|
||||
payload.logger.error(`[ipal] Graph send error: ${msg}`);
|
||||
return {
|
||||
error: 'Graph send error.',
|
||||
sent: false
|
||||
};
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
//# sourceMappingURL=graphAdapter.js.map
|
||||
+1
File diff suppressed because one or more lines are too long
Vendored
+4
@@ -1,2 +1,6 @@
|
||||
export { graphAdapter } from './graphAdapter.js';
|
||||
export type { GraphAdapterArgs } from './graphAdapter.js';
|
||||
export { mailAdapter } from './mailAdapter.js';
|
||||
export type { MailAdapterArgs } from './mailAdapter.js';
|
||||
export { sendEmail } from './sendEmail.js';
|
||||
export type { SendEmailArgs, SendEmailResult } from './sendEmail.js';
|
||||
|
||||
Vendored
+2
@@ -1,3 +1,5 @@
|
||||
export { graphAdapter } from './graphAdapter.js';
|
||||
export { mailAdapter } from './mailAdapter.js';
|
||||
// Server-only exports. sendEmail imports 'server-only' (SMTP password, nodemailer)
|
||||
// so this must never be imported from a client component.
|
||||
export { sendEmail } from './sendEmail.js';
|
||||
|
||||
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/email/index.ts"],"sourcesContent":["// Server-only exports. sendEmail imports 'server-only' (SMTP password, nodemailer)\n// so this must never be imported from a client component.\nexport { sendEmail } from './sendEmail.js'\nexport type { SendEmailArgs, SendEmailResult } from './sendEmail.js'\n"],"names":["sendEmail"],"mappings":"AAAA,mFAAmF;AACnF,0DAA0D;AAC1D,SAASA,SAAS,QAAQ,iBAAgB"}
|
||||
{"version":3,"sources":["../../../src/modules/email/index.ts"],"sourcesContent":["export { graphAdapter } from './graphAdapter.js'\nexport type { GraphAdapterArgs } from './graphAdapter.js'\nexport { mailAdapter } from './mailAdapter.js'\nexport type { MailAdapterArgs } from './mailAdapter.js'\n// Server-only exports. sendEmail imports 'server-only' (SMTP password, nodemailer)\n// so this must never be imported from a client component.\nexport { sendEmail } from './sendEmail.js'\nexport type { SendEmailArgs, SendEmailResult } from './sendEmail.js'\n"],"names":["graphAdapter","mailAdapter","sendEmail"],"mappings":"AAAA,SAASA,YAAY,QAAQ,oBAAmB;AAEhD,SAASC,WAAW,QAAQ,mBAAkB;AAE9C,mFAAmF;AACnF,0DAA0D;AAC1D,SAASC,SAAS,QAAQ,iBAAgB"}
|
||||
Vendored
+28
@@ -0,0 +1,28 @@
|
||||
import type { PayloadEmailAdapter } from 'payload';
|
||||
import { type GraphAdapterArgs } from './graphAdapter.js';
|
||||
import { type PanelSmtpAdapterArgs } from './panelSmtpAdapter.js';
|
||||
export type MailAdapterArgs = {
|
||||
fallbackFromAddress?: string;
|
||||
fallbackFromName?: string;
|
||||
graph?: GraphAdapterArgs;
|
||||
smtp?: PanelSmtpAdapterArgs;
|
||||
};
|
||||
/**
|
||||
* Dispatcher email adapter: wired into the config ONCE, but picks the transport
|
||||
* (SMTP or Graph) per send by reading `emailTransport` from SiteIntegrations.
|
||||
* This is what makes the choice switchable in the panel — Payload builds the
|
||||
* email adapter at boot and can't swap it at runtime, so instead of choosing
|
||||
* between two adapters at boot we install one that delegates on every send.
|
||||
*
|
||||
* Availability guard: Graph only runs if its agency credentials exist in env
|
||||
* (this is *our* Exchange). If the panel says 'graph' but env isn't set up,
|
||||
* we DON'T silently fail — we log clearly and fall back to SMTP, so a client
|
||||
* flipping the switch without the backing config still gets mail out (over SMTP)
|
||||
* rather than silent nothing. If neither is usable, the send reports an error.
|
||||
*
|
||||
* @example
|
||||
* // payload.config.ts
|
||||
* import { mailAdapter } from '@intecion/ipal-kit'
|
||||
* email: mailAdapter()
|
||||
*/
|
||||
export declare const mailAdapter: (args?: MailAdapterArgs) => PayloadEmailAdapter;
|
||||
Vendored
+58
@@ -0,0 +1,58 @@
|
||||
import { getSiteIntegrations } from '../payload/index.js';
|
||||
import { graphAdapter } from './graphAdapter.js';
|
||||
import { panelSmtpAdapter } from './panelSmtpAdapter.js';
|
||||
/** True when the agency Graph credentials are present in the environment. */ function graphAvailable() {
|
||||
return Boolean(process.env.GRAPH_TENANT_ID && process.env.GRAPH_CLIENT_ID && process.env.GRAPH_CLIENT_SECRET && process.env.GRAPH_SENDER);
|
||||
}
|
||||
/**
|
||||
* Dispatcher email adapter: wired into the config ONCE, but picks the transport
|
||||
* (SMTP or Graph) per send by reading `emailTransport` from SiteIntegrations.
|
||||
* This is what makes the choice switchable in the panel — Payload builds the
|
||||
* email adapter at boot and can't swap it at runtime, so instead of choosing
|
||||
* between two adapters at boot we install one that delegates on every send.
|
||||
*
|
||||
* Availability guard: Graph only runs if its agency credentials exist in env
|
||||
* (this is *our* Exchange). If the panel says 'graph' but env isn't set up,
|
||||
* we DON'T silently fail — we log clearly and fall back to SMTP, so a client
|
||||
* flipping the switch without the backing config still gets mail out (over SMTP)
|
||||
* rather than silent nothing. If neither is usable, the send reports an error.
|
||||
*
|
||||
* @example
|
||||
* // payload.config.ts
|
||||
* import { mailAdapter } from '@intecion/ipal-kit'
|
||||
* email: mailAdapter()
|
||||
*/ export const mailAdapter = (args = {})=>(deps)=>{
|
||||
// Build both delegates once; each still resolves its own config per send.
|
||||
const smtp = panelSmtpAdapter({
|
||||
fallbackFromAddress: args.fallbackFromAddress,
|
||||
fallbackFromName: args.fallbackFromName,
|
||||
...args.smtp
|
||||
})(deps);
|
||||
const graph = graphAdapter({
|
||||
fallbackFromAddress: args.fallbackFromAddress,
|
||||
fallbackFromName: args.fallbackFromName,
|
||||
...args.graph
|
||||
})(deps);
|
||||
const { payload } = deps;
|
||||
return {
|
||||
name: 'ipal-mail-dispatcher',
|
||||
defaultFromAddress: smtp.defaultFromAddress,
|
||||
defaultFromName: smtp.defaultFromName,
|
||||
sendEmail: async (message)=>{
|
||||
const settings = await getSiteIntegrations(payload);
|
||||
const choice = settings.emailTransport ?? 'smtp';
|
||||
if (choice === 'graph') {
|
||||
if (graphAvailable()) {
|
||||
return graph.sendEmail(message);
|
||||
}
|
||||
// Panel asked for Graph but the agency creds aren't configured for
|
||||
// this project. Fall back to SMTP rather than silently dropping mail.
|
||||
payload.logger.warn('[ipal] Transport set to Graph but GRAPH_* env vars are missing; falling back to SMTP.');
|
||||
return smtp.sendEmail(message);
|
||||
}
|
||||
return smtp.sendEmail(message);
|
||||
}
|
||||
};
|
||||
};
|
||||
|
||||
//# sourceMappingURL=mailAdapter.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/email/mailAdapter.ts"],"sourcesContent":["import type { PayloadEmailAdapter, SendEmailOptions } from 'payload'\n\nimport { getSiteIntegrations } from '../payload/index.js'\nimport { graphAdapter, type GraphAdapterArgs } from './graphAdapter.js'\nimport { panelSmtpAdapter, type PanelSmtpAdapterArgs } from './panelSmtpAdapter.js'\n\ntype TransportIntegrations = {\n /** 'smtp' | 'graph' — chosen by the editor in SiteIntegrations. */\n emailTransport?: 'graph' | 'smtp' | null\n}\n\nexport type MailAdapterArgs = {\n fallbackFromAddress?: string\n fallbackFromName?: string\n graph?: GraphAdapterArgs\n smtp?: PanelSmtpAdapterArgs\n}\n\n/** True when the agency Graph credentials are present in the environment. */\nfunction graphAvailable(): boolean {\n return Boolean(\n process.env.GRAPH_TENANT_ID &&\n process.env.GRAPH_CLIENT_ID &&\n process.env.GRAPH_CLIENT_SECRET &&\n process.env.GRAPH_SENDER,\n )\n}\n\n/**\n * Dispatcher email adapter: wired into the config ONCE, but picks the transport\n * (SMTP or Graph) per send by reading `emailTransport` from SiteIntegrations.\n * This is what makes the choice switchable in the panel — Payload builds the\n * email adapter at boot and can't swap it at runtime, so instead of choosing\n * between two adapters at boot we install one that delegates on every send.\n *\n * Availability guard: Graph only runs if its agency credentials exist in env\n * (this is *our* Exchange). If the panel says 'graph' but env isn't set up,\n * we DON'T silently fail — we log clearly and fall back to SMTP, so a client\n * flipping the switch without the backing config still gets mail out (over SMTP)\n * rather than silent nothing. If neither is usable, the send reports an error.\n *\n * @example\n * // payload.config.ts\n * import { mailAdapter } from '@intecion/ipal-kit'\n * email: mailAdapter()\n */\nexport const mailAdapter =\n (args: MailAdapterArgs = {}): PayloadEmailAdapter =>\n (deps) => {\n // Build both delegates once; each still resolves its own config per send.\n const smtp = panelSmtpAdapter({\n fallbackFromAddress: args.fallbackFromAddress,\n fallbackFromName: args.fallbackFromName,\n ...args.smtp,\n })(deps)\n const graph = graphAdapter({\n fallbackFromAddress: args.fallbackFromAddress,\n fallbackFromName: args.fallbackFromName,\n ...args.graph,\n })(deps)\n\n const { payload } = deps\n\n return {\n name: 'ipal-mail-dispatcher',\n defaultFromAddress: smtp.defaultFromAddress,\n defaultFromName: smtp.defaultFromName,\n\n sendEmail: async (message: SendEmailOptions) => {\n const settings = await getSiteIntegrations<TransportIntegrations>(payload)\n const choice = settings.emailTransport ?? 'smtp'\n\n if (choice === 'graph') {\n if (graphAvailable()) {\n return graph.sendEmail(message)\n }\n // Panel asked for Graph but the agency creds aren't configured for\n // this project. Fall back to SMTP rather than silently dropping mail.\n payload.logger.warn(\n '[ipal] Transport set to Graph but GRAPH_* env vars are missing; falling back to SMTP.',\n )\n return smtp.sendEmail(message)\n }\n\n return smtp.sendEmail(message)\n },\n }\n }\n"],"names":["getSiteIntegrations","graphAdapter","panelSmtpAdapter","graphAvailable","Boolean","process","env","GRAPH_TENANT_ID","GRAPH_CLIENT_ID","GRAPH_CLIENT_SECRET","GRAPH_SENDER","mailAdapter","args","deps","smtp","fallbackFromAddress","fallbackFromName","graph","payload","name","defaultFromAddress","defaultFromName","sendEmail","message","settings","choice","emailTransport","logger","warn"],"mappings":"AAEA,SAASA,mBAAmB,QAAQ,sBAAqB;AACzD,SAASC,YAAY,QAA+B,oBAAmB;AACvE,SAASC,gBAAgB,QAAmC,wBAAuB;AAcnF,2EAA2E,GAC3E,SAASC;IACP,OAAOC,QACLC,QAAQC,GAAG,CAACC,eAAe,IAC3BF,QAAQC,GAAG,CAACE,eAAe,IAC3BH,QAAQC,GAAG,CAACG,mBAAmB,IAC/BJ,QAAQC,GAAG,CAACI,YAAY;AAE5B;AAEA;;;;;;;;;;;;;;;;;CAiBC,GACD,OAAO,MAAMC,cACX,CAACC,OAAwB,CAAC,CAAC,GAC3B,CAACC;QACC,0EAA0E;QAC1E,MAAMC,OAAOZ,iBAAiB;YAC5Ba,qBAAqBH,KAAKG,mBAAmB;YAC7CC,kBAAkBJ,KAAKI,gBAAgB;YACvC,GAAGJ,KAAKE,IAAI;QACd,GAAGD;QACH,MAAMI,QAAQhB,aAAa;YACzBc,qBAAqBH,KAAKG,mBAAmB;YAC7CC,kBAAkBJ,KAAKI,gBAAgB;YACvC,GAAGJ,KAAKK,KAAK;QACf,GAAGJ;QAEH,MAAM,EAAEK,OAAO,EAAE,GAAGL;QAEpB,OAAO;YACLM,MAAM;YACNC,oBAAoBN,KAAKM,kBAAkB;YAC3CC,iBAAiBP,KAAKO,eAAe;YAErCC,WAAW,OAAOC;gBAChB,MAAMC,WAAW,MAAMxB,oBAA2CkB;gBAClE,MAAMO,SAASD,SAASE,cAAc,IAAI;gBAE1C,IAAID,WAAW,SAAS;oBACtB,IAAItB,kBAAkB;wBACpB,OAAOc,MAAMK,SAAS,CAACC;oBACzB;oBACA,mEAAmE;oBACnE,sEAAsE;oBACtEL,QAAQS,MAAM,CAACC,IAAI,CACjB;oBAEF,OAAOd,KAAKQ,SAAS,CAACC;gBACxB;gBAEA,OAAOT,KAAKQ,SAAS,CAACC;YACxB;QACF;IACF,EAAC"}
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
import type { Endpoint } from 'payload';
|
||||
/**
|
||||
* Custom endpoint: send a test email to a given address through whatever
|
||||
* transport is currently active (SMTP or Graph — mailAdapter reads the panel
|
||||
* setting per send, so the test exercises the REAL path a form email would
|
||||
* take). Mounted at POST /api/ipal/test-email.
|
||||
*
|
||||
* Admin-only: uses payload.sendEmail (server-side), and requires an
|
||||
* authenticated admin user — a test-send button must never be open to the
|
||||
* public (it would be an open relay / spam vector).
|
||||
*
|
||||
* Returns the adapter's own result so the panel can show exactly what happened,
|
||||
* including the transport-specific error (SMTP auth failure, Graph 401, etc.).
|
||||
*/
|
||||
export declare const testEmailEndpoint: Endpoint;
|
||||
+74
@@ -0,0 +1,74 @@
|
||||
import { addDataAndFileToRequest } from 'payload';
|
||||
/**
|
||||
* Custom endpoint: send a test email to a given address through whatever
|
||||
* transport is currently active (SMTP or Graph — mailAdapter reads the panel
|
||||
* setting per send, so the test exercises the REAL path a form email would
|
||||
* take). Mounted at POST /api/ipal/test-email.
|
||||
*
|
||||
* Admin-only: uses payload.sendEmail (server-side), and requires an
|
||||
* authenticated admin user — a test-send button must never be open to the
|
||||
* public (it would be an open relay / spam vector).
|
||||
*
|
||||
* Returns the adapter's own result so the panel can show exactly what happened,
|
||||
* including the transport-specific error (SMTP auth failure, Graph 401, etc.).
|
||||
*/ export const testEmailEndpoint = {
|
||||
handler: async (req)=>{
|
||||
// Auth: only signed-in admins may trigger a send.
|
||||
if (!req.user) {
|
||||
return Response.json({
|
||||
error: 'Unauthorized',
|
||||
ok: false
|
||||
}, {
|
||||
status: 401
|
||||
});
|
||||
}
|
||||
await addDataAndFileToRequest(req);
|
||||
const to = req.data?.to?.trim();
|
||||
if (!to || !/^[^@\s]+@[^\s@][^\s.@]*\.[^\s@]+$/.test(to)) {
|
||||
return Response.json({
|
||||
error: 'Provide a valid recipient address.',
|
||||
ok: false
|
||||
}, {
|
||||
status: 400
|
||||
});
|
||||
}
|
||||
try {
|
||||
const info = await req.payload.sendEmail({
|
||||
html: '<p>This is a test message from <strong>ipal-kit</strong>. If you received it, outbound email is configured correctly.</p>',
|
||||
subject: 'ipal-kit — test email',
|
||||
text: 'This is a test message from ipal-kit. If you received it, outbound email is configured correctly.',
|
||||
to
|
||||
});
|
||||
// Payload's sendEmail resolves with the adapter's result. Our adapters
|
||||
// return { sent: boolean, error?: string }; nodemailer returns info with
|
||||
// messageId. Normalize to a simple ok/message for the panel.
|
||||
const sent = info && typeof info === 'object' && 'sent' in info ? info.sent !== false : true;
|
||||
if (!sent) {
|
||||
const error = info?.error ?? 'Send failed (see server logs).';
|
||||
return Response.json({
|
||||
error,
|
||||
ok: false
|
||||
}, {
|
||||
status: 502
|
||||
});
|
||||
}
|
||||
return Response.json({
|
||||
message: `Test email sent to ${to}.`,
|
||||
ok: true
|
||||
});
|
||||
} catch (err) {
|
||||
const message = err instanceof Error ? err.message : String(err);
|
||||
req.payload.logger.error(`[ipal] Test email failed: ${message}`);
|
||||
return Response.json({
|
||||
error: 'Send failed. Check transport settings and server logs.',
|
||||
ok: false
|
||||
}, {
|
||||
status: 502
|
||||
});
|
||||
}
|
||||
},
|
||||
method: 'post',
|
||||
path: '/ipal/test-email'
|
||||
};
|
||||
|
||||
//# sourceMappingURL=testEmailEndpoint.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../../src/modules/email/test/testEmailEndpoint.ts"],"sourcesContent":["import type { Endpoint, PayloadRequest } from 'payload'\n\nimport { addDataAndFileToRequest } from 'payload'\n\n/**\n * Custom endpoint: send a test email to a given address through whatever\n * transport is currently active (SMTP or Graph — mailAdapter reads the panel\n * setting per send, so the test exercises the REAL path a form email would\n * take). Mounted at POST /api/ipal/test-email.\n *\n * Admin-only: uses payload.sendEmail (server-side), and requires an\n * authenticated admin user — a test-send button must never be open to the\n * public (it would be an open relay / spam vector).\n *\n * Returns the adapter's own result so the panel can show exactly what happened,\n * including the transport-specific error (SMTP auth failure, Graph 401, etc.).\n */\nexport const testEmailEndpoint: Endpoint = {\n handler: async (req: PayloadRequest) => {\n // Auth: only signed-in admins may trigger a send.\n if (!req.user) {\n return Response.json({ error: 'Unauthorized', ok: false }, { status: 401 })\n }\n\n await addDataAndFileToRequest(req)\n const to = (req.data?.to as string | undefined)?.trim()\n\n if (!to || !/^[^@\\s]+@[^\\s@][^\\s.@]*\\.[^\\s@]+$/.test(to)) {\n return Response.json(\n { error: 'Provide a valid recipient address.', ok: false },\n { status: 400 },\n )\n }\n\n try {\n const info = await req.payload.sendEmail({\n html: '<p>This is a test message from <strong>ipal-kit</strong>. If you received it, outbound email is configured correctly.</p>',\n subject: 'ipal-kit — test email',\n text: 'This is a test message from ipal-kit. If you received it, outbound email is configured correctly.',\n to,\n })\n\n // Payload's sendEmail resolves with the adapter's result. Our adapters\n // return { sent: boolean, error?: string }; nodemailer returns info with\n // messageId. Normalize to a simple ok/message for the panel.\n const sent =\n info && typeof info === 'object' && 'sent' in info\n ? (info as { sent?: boolean }).sent !== false\n : true\n\n if (!sent) {\n const error = (info as { error?: string })?.error ?? 'Send failed (see server logs).'\n return Response.json({ error, ok: false }, { status: 502 })\n }\n\n return Response.json({ message: `Test email sent to ${to}.`, ok: true })\n } catch (err) {\n const message = err instanceof Error ? err.message : String(err)\n req.payload.logger.error(`[ipal] Test email failed: ${message}`)\n return Response.json(\n { error: 'Send failed. Check transport settings and server logs.', ok: false },\n { status: 502 },\n )\n }\n },\n method: 'post',\n path: '/ipal/test-email',\n}\n"],"names":["addDataAndFileToRequest","testEmailEndpoint","handler","req","user","Response","json","error","ok","status","to","data","trim","test","info","payload","sendEmail","html","subject","text","sent","message","err","Error","String","logger","method","path"],"mappings":"AAEA,SAASA,uBAAuB,QAAQ,UAAS;AAEjD;;;;;;;;;;;;CAYC,GACD,OAAO,MAAMC,oBAA8B;IACzCC,SAAS,OAAOC;QACd,kDAAkD;QAClD,IAAI,CAACA,IAAIC,IAAI,EAAE;YACb,OAAOC,SAASC,IAAI,CAAC;gBAAEC,OAAO;gBAAgBC,IAAI;YAAM,GAAG;gBAAEC,QAAQ;YAAI;QAC3E;QAEA,MAAMT,wBAAwBG;QAC9B,MAAMO,KAAMP,IAAIQ,IAAI,EAAED,IAA2BE;QAEjD,IAAI,CAACF,MAAM,CAAC,oCAAoCG,IAAI,CAACH,KAAK;YACxD,OAAOL,SAASC,IAAI,CAClB;gBAAEC,OAAO;gBAAsCC,IAAI;YAAM,GACzD;gBAAEC,QAAQ;YAAI;QAElB;QAEA,IAAI;YACF,MAAMK,OAAO,MAAMX,IAAIY,OAAO,CAACC,SAAS,CAAC;gBACvCC,MAAM;gBACNC,SAAS;gBACTC,MAAM;gBACNT;YACF;YAEA,uEAAuE;YACvE,yEAAyE;YACzE,6DAA6D;YAC7D,MAAMU,OACJN,QAAQ,OAAOA,SAAS,YAAY,UAAUA,OAC1C,AAACA,KAA4BM,IAAI,KAAK,QACtC;YAEN,IAAI,CAACA,MAAM;gBACT,MAAMb,QAAQ,AAACO,MAA6BP,SAAS;gBACrD,OAAOF,SAASC,IAAI,CAAC;oBAAEC;oBAAOC,IAAI;gBAAM,GAAG;oBAAEC,QAAQ;gBAAI;YAC3D;YAEA,OAAOJ,SAASC,IAAI,CAAC;gBAAEe,SAAS,CAAC,mBAAmB,EAAEX,GAAG,CAAC,CAAC;gBAAEF,IAAI;YAAK;QACxE,EAAE,OAAOc,KAAK;YACZ,MAAMD,UAAUC,eAAeC,QAAQD,IAAID,OAAO,GAAGG,OAAOF;YAC5DnB,IAAIY,OAAO,CAACU,MAAM,CAAClB,KAAK,CAAC,CAAC,0BAA0B,EAAEc,SAAS;YAC/D,OAAOhB,SAASC,IAAI,CAClB;gBAAEC,OAAO;gBAA0DC,IAAI;YAAM,GAC7E;gBAAEC,QAAQ;YAAI;QAElB;IACF;IACAiB,QAAQ;IACRC,MAAM;AACR,EAAC"}
|
||||
Vendored
+9
-2
@@ -14,7 +14,7 @@ import { validateSubmission } from './validateSubmission.js';
|
||||
* which goes out over panelSmtpAdapter. Storing the submission is enough.
|
||||
*
|
||||
* server-only: touches the Turnstile secret.
|
||||
*/ export async function submitForm({ data, formId, ip, maxPerMinute = 5, payload, turnstileToken }) {
|
||||
*/ export async function submitForm({ consentFieldName, data, formId, ip, maxPerMinute = 5, payload, turnstileToken }) {
|
||||
// 1. Rate limit — cheapest gate, drops a flood before any real work.
|
||||
if (maxPerMinute > 0 && ip) {
|
||||
if (!checkRateLimit({
|
||||
@@ -43,7 +43,7 @@ import { validateSubmission } from './validateSubmission.js';
|
||||
}
|
||||
// 3. Validate against the form's schema. A public endpoint can't trust the
|
||||
// shape of `data` — drop unknown keys, enforce required, cap length.
|
||||
const validation = await validateSubmission(payload, formId, data);
|
||||
const validation = await validateSubmission(payload, formId, data, consentFieldName);
|
||||
if (!validation.ok) {
|
||||
if (validation.reason === 'not_found') {
|
||||
return {
|
||||
@@ -51,6 +51,13 @@ import { validateSubmission } from './validateSubmission.js';
|
||||
success: false
|
||||
};
|
||||
}
|
||||
if (validation.reason === 'consent') {
|
||||
return {
|
||||
field: validation.field,
|
||||
reason: 'consent',
|
||||
success: false
|
||||
};
|
||||
}
|
||||
return {
|
||||
reason: 'validation',
|
||||
success: false,
|
||||
|
||||
Vendored
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/forms/types.ts"],"sourcesContent":["import type { CollectionConfig, Field } from 'payload'\n\n/**\n * Receives the collection's default fields and returns the final list — add,\n * remove, or reorder. Same shape the form-builder uses.\n */\nexport type FormsFieldsOverride = (args: { defaultFields: Field[] }) => Field[]\n\n/**\n * Overrides for a forms-related collection: replace the fields and/or any\n * other collection setting (admin, access, hooks…).\n */\nexport type FormsCollectionOverrides = {\n fields?: FormsFieldsOverride\n} & Partial<Omit<CollectionConfig, 'fields'>>\n\n/**\n * Forms configuration — mirrors the fields a client enables in the\n * form-builder plugin. Kept minimal; the plugin passes these through.\n */\nexport type FormsOption = {\n /** Field types available in the form builder. Sensible defaults applied. */\n fields?: {\n checkbox?: boolean\n email?: boolean\n message?: boolean\n number?: boolean\n payment?: boolean\n select?: boolean\n text?: boolean\n textarea?: boolean\n }\n /**\n * Override the forms collection. The plugin stays opinion-free about what a\n * form needs beyond its fields — a client that wants, say, a per-form\n * notification address adds it here:\n *\n * formOverrides: {\n * fields: ({ defaultFields }) => [\n * ...defaultFields,\n * { name: 'notificationEmail', type: 'email' },\n * ],\n * }\n */\n formOverrides?: FormsCollectionOverrides\n /** Override the form-submissions collection (same shape). */\n formSubmissionOverrides?: FormsCollectionOverrides\n /** Collections a form can redirect to (e.g. ['pages']). */\n redirectRelationships?: string[]\n}\n"],"names":[],"mappings":"AAgBA;;;CAGC,GACD,WA6BC"}
|
||||
{"version":3,"sources":["../../../src/modules/forms/types.ts"],"sourcesContent":["import type { CollectionConfig, Field } from 'payload'\n\n/**\n * Receives the collection's default fields and returns the final list — add,\n * remove, or reorder. Same shape the form-builder uses.\n */\nexport type FormsFieldsOverride = (args: { defaultFields: Field[] }) => Field[]\n\n/**\n * Overrides for a forms-related collection: replace the fields and/or any\n * other collection setting (admin, access, hooks…).\n */\nexport type FormsCollectionOverrides = {\n fields?: FormsFieldsOverride\n} & Partial<Omit<CollectionConfig, 'fields'>>\n\n/**\n * Forms configuration — mirrors the fields a client enables in the\n * form-builder plugin. Kept minimal; the plugin passes these through.\n */\nexport type FormsOption = {\n /**\n * Name of the checkbox field treated as a GDPR consent gate. A form field\n * with this name must be checked for submission to succeed — enforced\n * server-side in submitForm. Defaults to 'consent'.\n */\n consentFieldName?: string\n /** Field types available in the form builder. Sensible defaults applied. */\n fields?: {\n checkbox?: boolean\n email?: boolean\n message?: boolean\n number?: boolean\n payment?: boolean\n select?: boolean\n text?: boolean\n textarea?: boolean\n }\n /**\n * Override the forms collection. The plugin stays opinion-free about what a\n * form needs beyond its fields — a client that wants, say, a per-form\n * notification address adds it here:\n *\n * formOverrides: {\n * fields: ({ defaultFields }) => [\n * ...defaultFields,\n * { name: 'notificationEmail', type: 'email' },\n * ],\n * }\n */\n formOverrides?: FormsCollectionOverrides\n /** Override the form-submissions collection (same shape). */\n formSubmissionOverrides?: FormsCollectionOverrides\n /** Collections a form can redirect to (e.g. ['pages']). */\n redirectRelationships?: string[]\n}\n"],"names":[],"mappings":"AAgBA;;;CAGC,GACD,WAmCC"}
|
||||
+22
-2
@@ -12,6 +12,14 @@
|
||||
'g-recaptcha-response'
|
||||
]);
|
||||
/** Hard ceiling on a single field's length, independent of the form config. */ const MAX_FIELD_LENGTH = 5000;
|
||||
/**
|
||||
* Default name for a GDPR consent field. A checkbox with this name is treated
|
||||
* as a consent gate: it MUST be checked for the submission to go through,
|
||||
* enforced here server-side regardless of how the field was configured in the
|
||||
* panel (so an editor can't weaken it by forgetting `required` or, worse,
|
||||
* pre-ticking it with defaultValue: true — which GDPR forbids). Configurable
|
||||
* via FormsOption.consentFieldName.
|
||||
*/ const DEFAULT_CONSENT_FIELD = 'consent';
|
||||
/**
|
||||
* Checks submitted data against the form's own definition, rather than trusting
|
||||
* whatever arrived.
|
||||
@@ -24,7 +32,7 @@
|
||||
*
|
||||
* Returns the loaded form on success so the caller doesn't fetch it twice, and
|
||||
* a code + offending field on failure so the frontend can point at it.
|
||||
*/ export async function validateSubmission(payload, formId, data) {
|
||||
*/ export async function validateSubmission(payload, formId, data, consentFieldName = DEFAULT_CONSENT_FIELD) {
|
||||
let form;
|
||||
try {
|
||||
form = await payload.findByID({
|
||||
@@ -47,7 +55,19 @@
|
||||
for (const field of fields){
|
||||
const value = data[field.name];
|
||||
const isBlank = value == null || typeof value === 'string' && value.trim() === '' || value === false;
|
||||
if (field.required && isBlank) {
|
||||
// GDPR consent gate: a field matching the consent name must be truthy
|
||||
// (checked). Enforced independently of `required`, so it can't be weakened
|
||||
// in the panel. This is the one field where server-side enforcement is the
|
||||
// legal guarantee — the frontend can't bypass it, the editor can't misset it.
|
||||
if (field.name === consentFieldName) {
|
||||
if (value !== true) {
|
||||
return {
|
||||
field: field.name,
|
||||
ok: false,
|
||||
reason: 'consent'
|
||||
};
|
||||
}
|
||||
} else if (field.required && isBlank) {
|
||||
return {
|
||||
field: field.name,
|
||||
kind: 'required',
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
@@ -53,6 +53,12 @@ type CreateContentHelpersArgs = {
|
||||
* not the second, and a page component composes them in two obvious lines.
|
||||
*/
|
||||
export declare function createContentHelpers({ baseUrl, config, content, i18n, pagesSlug, settingsSlug, }: CreateContentHelpersArgs): {
|
||||
generateStaticParams: () => Promise<Array<{
|
||||
locale: string;
|
||||
slug: string[];
|
||||
} | {
|
||||
slug: string[];
|
||||
}>>;
|
||||
getCachedPayload: () => Promise<BasePayload>;
|
||||
getConfiguredLocales: () => Promise<string[]>;
|
||||
getEntries: (collection: string, locale: string, page: number, perPage: number) => Promise<ArchiveEntries>;
|
||||
|
||||
+137
-8
@@ -73,19 +73,39 @@ import { buildRobots, buildSitemapEntries } from '../seo/index.js';
|
||||
* ```ts
|
||||
* // app/sitemap.ts
|
||||
* export { sitemap as default } from '@/lib/content'
|
||||
* export const dynamic = 'force-dynamic' // generate at runtime, not build
|
||||
* ```
|
||||
*
|
||||
* IMPORTANT — container deploys (Coolify/Docker/Railway/CI): Next treats
|
||||
* sitemap.ts as STATIC by default and prerenders it during `next build`, which
|
||||
* calls into Payload → the database. The build container usually has no access
|
||||
* to the internal Docker network, so the DB connection fails (ENOTFOUND) and
|
||||
* the build dies. Two defenses:
|
||||
* 1. `export const dynamic = 'force-dynamic'` in app/sitemap.ts — skips build
|
||||
* prerender, generates at runtime when the DB is reachable (recommended).
|
||||
* 2. This handler also catches DB errors and returns [] so that even without
|
||||
* (1) the build won't crash — it just ships an empty sitemap until the
|
||||
* next runtime regeneration. (1) is still preferred; (2) is a safety net.
|
||||
*/ const sitemap = cache(async ()=>{
|
||||
if (!i18n) {
|
||||
throw new Error('[ipal] createContentHelpers: pass `i18n` to use the sitemap handler.');
|
||||
}
|
||||
return buildSitemapEntries({
|
||||
baseUrl: origin,
|
||||
config: i18n,
|
||||
content,
|
||||
pagesSlug,
|
||||
payload: await getCachedPayload(),
|
||||
settingsSlug
|
||||
});
|
||||
try {
|
||||
return await buildSitemapEntries({
|
||||
baseUrl: origin,
|
||||
config: i18n,
|
||||
content,
|
||||
pagesSlug,
|
||||
payload: await getCachedPayload(),
|
||||
settingsSlug
|
||||
});
|
||||
} catch (error) {
|
||||
// DB unreachable (typically a container build with no DB network) — return
|
||||
// an empty sitemap instead of failing the build. Runtime regeneration will
|
||||
// produce the real one once the DB is reachable. See dynamic='force-dynamic'.
|
||||
console.warn('[ipal] sitemap: could not reach the database, returning empty entries ' + "(add `export const dynamic = 'force-dynamic'` to app/sitemap.ts to " + 'generate at runtime and avoid build-time DB access):', error);
|
||||
return [];
|
||||
}
|
||||
});
|
||||
/**
|
||||
* Ready-made handler for Next's `app/robots.ts`. Re-export directly:
|
||||
@@ -97,7 +117,116 @@ import { buildRobots, buildSitemapEntries } from '../seo/index.js';
|
||||
*/ const robots = ()=>buildRobots({
|
||||
baseUrl: origin
|
||||
});
|
||||
/**
|
||||
* Next.js generateStaticParams for the [[...slug]] route (or
|
||||
* [locale]/[[...slug]]). Returns every routable page as a params object, so
|
||||
* Next PRE-RENDERS them as static (SSG) instead of dynamic.
|
||||
*
|
||||
* Why this matters beyond convenience: an optional catch-all with no
|
||||
* generateStaticParams is treated as a DYNAMIC route (ƒ), which streams
|
||||
* metadata into <body> (crawlers miss it). Providing generateStaticParams
|
||||
* compiles routes as SSG (●) — the <head> is synchronous and complete. This is
|
||||
* the strongest fix for the metadata-in-head problem (stronger than ISR alone).
|
||||
*
|
||||
* Handles automatically:
|
||||
* - pages collection + content collections (with their archive prefix)
|
||||
* - excludes the homepage (maps to { slug: [] } — the root)
|
||||
* - excludes drafts and 404/500/system slugs
|
||||
* - KEEPS noindex pages (they must still render — noindex controls indexing,
|
||||
* not existence; skipping them would force dynamic rendering)
|
||||
* - localized slugs (string or per-locale map) both handled
|
||||
* - single-locale → { slug }[]; multi-locale → { locale, slug }[]
|
||||
*
|
||||
* Wire it in the project:
|
||||
* // app/(frontend)/[[...slug]]/page.tsx (or [locale]/[[...slug]])
|
||||
* export { generateStaticParams } from '@/lib/content'
|
||||
*/ const generateStaticParams = async ()=>{
|
||||
try {
|
||||
const payload = await getCachedPayload();
|
||||
const locales = i18n ? i18n.locales.map((l)=>l.code) : [
|
||||
undefined
|
||||
];
|
||||
const singleLocale = !i18n || i18n.locales.length === 1;
|
||||
// Home slug per locale, to exclude the homepage (it's the root, slug []).
|
||||
const settings = await payload.findGlobal({
|
||||
slug: settingsSlug,
|
||||
depth: 1,
|
||||
locale: 'all'
|
||||
}).catch(()=>null);
|
||||
const homeId = settings?.homepage?.id;
|
||||
const EXCLUDED = new Set([
|
||||
'404',
|
||||
'500',
|
||||
'error',
|
||||
'not-found'
|
||||
]);
|
||||
const params = [];
|
||||
for (const locale of locales){
|
||||
// NO where:{_status} filter — collections without drafts enabled don't
|
||||
// register the _status field, and querying it throws
|
||||
// "path cannot be queried: _status". We filter drafts in memory below,
|
||||
// which is safe for every collection (with or without drafts).
|
||||
const result = await payload.find({
|
||||
collection: pagesSlug,
|
||||
depth: 0,
|
||||
limit: 1000,
|
||||
locale: locale ?? 'all'
|
||||
});
|
||||
for (const raw of result.docs){
|
||||
// Draft filter in memory (safe whether or not the collection has drafts).
|
||||
if (raw._status && raw._status !== 'published') {
|
||||
continue;
|
||||
}
|
||||
// NOTE: unlike the sitemap, we do NOT skip meta.noindex here. A noindex
|
||||
// page (privacy, cookies, terms) still needs to render — users reach it
|
||||
// from the footer and crawlers read its <meta robots=noindex>. Pre-render
|
||||
// it as SSG so it's fast and its <head> is complete; noindex controls
|
||||
// INDEXING, not whether the page exists. Skipping it would force dynamic
|
||||
// rendering (the very streaming problem we're avoiding).
|
||||
if (homeId && raw.id === homeId) {
|
||||
// Homepage → root. Emit an empty-slug param so '/' (or '/pl') builds.
|
||||
const empty = singleLocale ? {
|
||||
slug: []
|
||||
} : {
|
||||
slug: [],
|
||||
locale: locale
|
||||
};
|
||||
if (!params.some((p)=>JSON.stringify(p) === JSON.stringify(empty))) {
|
||||
params.push(empty);
|
||||
}
|
||||
continue;
|
||||
}
|
||||
// Slug may be a plain string OR a localized map ({ pl: 'kontakt' }) when
|
||||
// read with locale:'all' or left unflattened. Handle both, or localized
|
||||
// pages get silently dropped.
|
||||
const rawSlug = raw.slug;
|
||||
const slug = typeof rawSlug === 'string' ? rawSlug : rawSlug && typeof rawSlug === 'object' ? rawSlug[locale ?? ''] ?? Object.values(rawSlug)[0] : undefined;
|
||||
if (!slug || EXCLUDED.has(slug)) {
|
||||
continue;
|
||||
}
|
||||
// Multi-level slugs ('atrakcje/telefon') → array segments.
|
||||
const segments = String(slug).split('/').filter(Boolean);
|
||||
params.push(singleLocale ? {
|
||||
slug: segments
|
||||
} : {
|
||||
slug: segments,
|
||||
locale: locale
|
||||
});
|
||||
}
|
||||
}
|
||||
return params;
|
||||
} catch (err) {
|
||||
// DB unreachable — typically a container build (Docker/Coolify/CI) with no
|
||||
// database network. Return [] so the build doesn't crash: Next falls back
|
||||
// to on-demand rendering for the routes, which fill in once the DB is
|
||||
// reachable at runtime. Without this every project would need its own
|
||||
// try/catch here. (Same graceful-degradation as the sitemap handler.)
|
||||
console.warn('[ipal] generateStaticParams: database not reachable during build ' + '(Docker/CI) — returning empty params; routes render on-demand at runtime:', err);
|
||||
return [];
|
||||
}
|
||||
};
|
||||
return {
|
||||
generateStaticParams,
|
||||
getCachedPayload,
|
||||
getConfiguredLocales,
|
||||
getEntries,
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
+35
@@ -0,0 +1,35 @@
|
||||
import type { CollectionAfterChangeHook, CollectionAfterDeleteHook } from 'payload';
|
||||
import type { I18nConfig } from '../i18n/index.js';
|
||||
type RevalidateFn = (path: string) => void;
|
||||
type BuildRevalidateHookArgs = {
|
||||
config: I18nConfig;
|
||||
/** Home slug (string or per-locale map) — home revalidates the root. */
|
||||
homeSlug?: Record<string, string> | string;
|
||||
/**
|
||||
* next/cache revalidatePath, INJECTED by the project. The plugin never imports
|
||||
* next/cache itself — that would crash when Payload runs as plain Node
|
||||
* (generate:importmap). The project passes it: `revalidatePath` from 'next/cache'.
|
||||
*/
|
||||
revalidatePath: RevalidateFn;
|
||||
};
|
||||
/**
|
||||
* Builds afterChange + afterDelete hooks that revalidate a page's ISR cache when
|
||||
* an editor saves or deletes it — so changes appear immediately instead of
|
||||
* waiting for the revalidate window. Without this, ISR means editors wait; with
|
||||
* it, ISR is usable for a CMS.
|
||||
*
|
||||
* Handles every locale, the root (home), AND a changed slug (revalidates both the
|
||||
* old and new path so neither goes stale). revalidatePath is injected — the
|
||||
* plugin never imports next/cache (safe under generate:importmap / plain Node).
|
||||
*
|
||||
* // in your Media/Pages collection config, from a project file that CAN import next/cache:
|
||||
* import { revalidatePath } from 'next/cache'
|
||||
* import { buildRevalidateHook } from '@intecion/ipal-kit'
|
||||
* const { afterChange, afterDelete } = buildRevalidateHook({ revalidatePath, config: i18nConfig })
|
||||
* // hooks: { afterChange: [afterChange], afterDelete: [afterDelete] }
|
||||
*/
|
||||
export declare function buildRevalidateHook({ config, homeSlug, revalidatePath, }: BuildRevalidateHookArgs): {
|
||||
afterChange: CollectionAfterChangeHook;
|
||||
afterDelete: CollectionAfterDeleteHook;
|
||||
};
|
||||
export {};
|
||||
+71
@@ -0,0 +1,71 @@
|
||||
import { buildLocalizedPath, getLocaleCodes } from '../i18n/index.js';
|
||||
/** Resolve a doc's path in one locale (root for home). Null if no slug there. */ function pathForLocale(doc, locale, config, homeSlug) {
|
||||
const slugField = doc.slug;
|
||||
const slug = typeof slugField === 'string' ? slugField : slugField && typeof slugField === 'object' ? slugField[locale] : undefined;
|
||||
if (!slug) {
|
||||
return null;
|
||||
}
|
||||
return buildLocalizedPath({
|
||||
config,
|
||||
homeSlug,
|
||||
locale,
|
||||
slugs: {
|
||||
[locale]: slug
|
||||
}
|
||||
}) ?? null;
|
||||
}
|
||||
/**
|
||||
* Builds afterChange + afterDelete hooks that revalidate a page's ISR cache when
|
||||
* an editor saves or deletes it — so changes appear immediately instead of
|
||||
* waiting for the revalidate window. Without this, ISR means editors wait; with
|
||||
* it, ISR is usable for a CMS.
|
||||
*
|
||||
* Handles every locale, the root (home), AND a changed slug (revalidates both the
|
||||
* old and new path so neither goes stale). revalidatePath is injected — the
|
||||
* plugin never imports next/cache (safe under generate:importmap / plain Node).
|
||||
*
|
||||
* // in your Media/Pages collection config, from a project file that CAN import next/cache:
|
||||
* import { revalidatePath } from 'next/cache'
|
||||
* import { buildRevalidateHook } from '@intecion/ipal-kit'
|
||||
* const { afterChange, afterDelete } = buildRevalidateHook({ revalidatePath, config: i18nConfig })
|
||||
* // hooks: { afterChange: [afterChange], afterDelete: [afterDelete] }
|
||||
*/ export function buildRevalidateHook({ config, homeSlug, revalidatePath }) {
|
||||
const locales = getLocaleCodes(config);
|
||||
const afterChange = ({ doc, previousDoc })=>{
|
||||
const seen = new Set();
|
||||
for (const locale of locales){
|
||||
// New path.
|
||||
const newPath = pathForLocale(doc, locale, config, homeSlug);
|
||||
if (newPath && !seen.has(newPath)) {
|
||||
revalidatePath(newPath);
|
||||
seen.add(newPath);
|
||||
}
|
||||
// Old path, if the slug changed — so the old URL doesn't serve stale content.
|
||||
if (previousDoc) {
|
||||
const oldPath = pathForLocale(previousDoc, locale, config, homeSlug);
|
||||
if (oldPath && oldPath !== newPath && !seen.has(oldPath)) {
|
||||
revalidatePath(oldPath);
|
||||
seen.add(oldPath);
|
||||
}
|
||||
}
|
||||
}
|
||||
return doc;
|
||||
};
|
||||
const afterDelete = ({ doc })=>{
|
||||
const seen = new Set();
|
||||
for (const locale of locales){
|
||||
const path = pathForLocale(doc, locale, config, homeSlug);
|
||||
if (path && !seen.has(path)) {
|
||||
revalidatePath(path);
|
||||
seen.add(path);
|
||||
}
|
||||
}
|
||||
return doc;
|
||||
};
|
||||
return {
|
||||
afterChange,
|
||||
afterDelete
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=buildRevalidateHook.js.map
|
||||
File diff suppressed because one or more lines are too long
Vendored
+7
@@ -0,0 +1,7 @@
|
||||
export { normalizeFilenameHook } from '../media/index.js';
|
||||
export { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js';
|
||||
export { buildRevalidateHook } from './buildRevalidateHook.js';
|
||||
export { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js';
|
||||
export { setPublishedAtHook } from './setPublishedAt.js';
|
||||
export { trackSlugHistoryHook } from './trackSlugHistory.js';
|
||||
export { buildValidateUniqueRole } from './validateUniqueRole.js';
|
||||
Vendored
+11
@@ -0,0 +1,11 @@
|
||||
// Re-eksport hooków domenowych (mieszkają w swoich modułach, tu dla przeglądu —
|
||||
// żeby był jeden katalog "wszystkie hooki pluginu"). Źródło prawdy to ich moduły.
|
||||
export { normalizeFilenameHook } from '../media/index.js';
|
||||
export { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js';
|
||||
export { buildRevalidateHook } from './buildRevalidateHook.js';
|
||||
export { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js';
|
||||
export { setPublishedAtHook } from './setPublishedAt.js';
|
||||
export { trackSlugHistoryHook } from './trackSlugHistory.js';
|
||||
export { buildValidateUniqueRole } from './validateUniqueRole.js';
|
||||
|
||||
//# sourceMappingURL=index.js.map
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/hooks/index.ts"],"sourcesContent":["// Re-eksport hooków domenowych (mieszkają w swoich modułach, tu dla przeglądu —\n// żeby był jeden katalog \"wszystkie hooki pluginu\"). Źródło prawdy to ich moduły.\nexport { normalizeFilenameHook } from '../media/index.js'\nexport { buildAutoFillMetaHook, validateFaviconField } from '../seo/index.js'\nexport { buildRevalidateHook } from './buildRevalidateHook.js'\nexport { buildPreventDeleteSystemPage } from './preventDeleteSystemPage.js'\nexport { setPublishedAtHook } from './setPublishedAt.js'\n\nexport { trackSlugHistoryHook } from './trackSlugHistory.js'\nexport { buildValidateUniqueRole } from './validateUniqueRole.js'\n"],"names":["normalizeFilenameHook","buildAutoFillMetaHook","validateFaviconField","buildRevalidateHook","buildPreventDeleteSystemPage","setPublishedAtHook","trackSlugHistoryHook","buildValidateUniqueRole"],"mappings":"AAAA,gFAAgF;AAChF,kFAAkF;AAClF,SAASA,qBAAqB,QAAQ,oBAAmB;AACzD,SAASC,qBAAqB,EAAEC,oBAAoB,QAAQ,kBAAiB;AAC7E,SAASC,mBAAmB,QAAQ,2BAA0B;AAC9D,SAASC,4BAA4B,QAAQ,+BAA8B;AAC3E,SAASC,kBAAkB,QAAQ,sBAAqB;AAExD,SAASC,oBAAoB,QAAQ,wBAAuB;AAC5D,SAASC,uBAAuB,QAAQ,0BAAyB"}
|
||||
+15
@@ -0,0 +1,15 @@
|
||||
import type { CollectionBeforeDeleteHook } from 'payload';
|
||||
/**
|
||||
* Blocks deletion of a page assigned a System Page role (homepage,
|
||||
* privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy
|
||||
* policy or homepage by accident would break routing and compliance links; this
|
||||
* stops it with a clear error. They must unassign the role first (deliberate).
|
||||
*
|
||||
* Reads the role assignments from SiteSettings (which page holds which role).
|
||||
*
|
||||
* hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
|
||||
*/
|
||||
export declare function buildPreventDeleteSystemPage(args?: {
|
||||
roleFields?: string[];
|
||||
settingsSlug?: string;
|
||||
}): CollectionBeforeDeleteHook;
|
||||
+37
@@ -0,0 +1,37 @@
|
||||
import { APIError } from 'payload';
|
||||
/**
|
||||
* Blocks deletion of a page assigned a System Page role (homepage,
|
||||
* privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy
|
||||
* policy or homepage by accident would break routing and compliance links; this
|
||||
* stops it with a clear error. They must unassign the role first (deliberate).
|
||||
*
|
||||
* Reads the role assignments from SiteSettings (which page holds which role).
|
||||
*
|
||||
* hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }
|
||||
*/ export function buildPreventDeleteSystemPage(args = {}) {
|
||||
const settingsSlug = args.settingsSlug ?? 'site-settings';
|
||||
const roleFields = args.roleFields ?? [
|
||||
'homepage',
|
||||
'privacyPolicy',
|
||||
'cookiePolicy',
|
||||
'termsOfService'
|
||||
];
|
||||
return async ({ id, req })=>{
|
||||
const settings = await req.payload.findGlobal({
|
||||
slug: settingsSlug,
|
||||
depth: 0
|
||||
}).catch(()=>null);
|
||||
if (!settings) {
|
||||
return;
|
||||
}
|
||||
for (const field of roleFields){
|
||||
const assigned = settings[field];
|
||||
const assignedId = assigned && typeof assigned === 'object' ? assigned.id : assigned;
|
||||
if (assignedId != null && String(assignedId) === String(id)) {
|
||||
throw new APIError(`Nie można usunąć strony przypisanej do roli systemowej "${field}". ` + `Najpierw odłącz rolę w Site Settings.`, 400);
|
||||
}
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=preventDeleteSystemPage.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/hooks/preventDeleteSystemPage.ts"],"sourcesContent":["import type { CollectionBeforeDeleteHook } from 'payload'\n\nimport { APIError } from 'payload'\n\n/**\n * Blocks deletion of a page assigned a System Page role (homepage,\n * privacyPolicy, cookiePolicy, termsOfService). An editor deleting the privacy\n * policy or homepage by accident would break routing and compliance links; this\n * stops it with a clear error. They must unassign the role first (deliberate).\n *\n * Reads the role assignments from SiteSettings (which page holds which role).\n *\n * hooks: { beforeDelete: [buildPreventDeleteSystemPage({ settingsSlug: 'site-settings' })] }\n */\nexport function buildPreventDeleteSystemPage(\n args: { roleFields?: string[]; settingsSlug?: string } = {},\n): CollectionBeforeDeleteHook {\n const settingsSlug = args.settingsSlug ?? 'site-settings'\n const roleFields = args.roleFields ?? [\n 'homepage',\n 'privacyPolicy',\n 'cookiePolicy',\n 'termsOfService',\n ]\n\n return async ({ id, req }) => {\n const settings = (await req.payload\n .findGlobal({ slug: settingsSlug as never, depth: 0 })\n .catch(() => null)) as null | Record<string, unknown>\n if (!settings) {return}\n\n for (const field of roleFields) {\n const assigned = settings[field]\n const assignedId =\n assigned && typeof assigned === 'object' ? (assigned as { id?: unknown }).id : assigned\n if (assignedId != null && String(assignedId) === String(id)) {\n throw new APIError(\n `Nie można usunąć strony przypisanej do roli systemowej \"${field}\". ` +\n `Najpierw odłącz rolę w Site Settings.`,\n 400,\n )\n }\n }\n }\n}\n"],"names":["APIError","buildPreventDeleteSystemPage","args","settingsSlug","roleFields","id","req","settings","payload","findGlobal","slug","depth","catch","field","assigned","assignedId","String"],"mappings":"AAEA,SAASA,QAAQ,QAAQ,UAAS;AAElC;;;;;;;;;CASC,GACD,OAAO,SAASC,6BACdC,OAAyD,CAAC,CAAC;IAE3D,MAAMC,eAAeD,KAAKC,YAAY,IAAI;IAC1C,MAAMC,aAAaF,KAAKE,UAAU,IAAI;QACpC;QACA;QACA;QACA;KACD;IAED,OAAO,OAAO,EAAEC,EAAE,EAAEC,GAAG,EAAE;QACvB,MAAMC,WAAY,MAAMD,IAAIE,OAAO,CAChCC,UAAU,CAAC;YAAEC,MAAMP;YAAuBQ,OAAO;QAAE,GACnDC,KAAK,CAAC,IAAM;QACf,IAAI,CAACL,UAAU;YAAC;QAAM;QAEtB,KAAK,MAAMM,SAAST,WAAY;YAC9B,MAAMU,WAAWP,QAAQ,CAACM,MAAM;YAChC,MAAME,aACJD,YAAY,OAAOA,aAAa,WAAW,AAACA,SAA8BT,EAAE,GAAGS;YACjF,IAAIC,cAAc,QAAQC,OAAOD,gBAAgBC,OAAOX,KAAK;gBAC3D,MAAM,IAAIL,SACR,CAAC,wDAAwD,EAAEa,MAAM,GAAG,CAAC,GACnE,CAAC,qCAAqC,CAAC,EACzC;YAEJ;QACF;IACF;AACF"}
|
||||
+13
@@ -0,0 +1,13 @@
|
||||
import type { CollectionBeforeChangeHook } from 'payload';
|
||||
/**
|
||||
* Sets `publishedAt` to now the first time a document transitions to published,
|
||||
* if it isn't already set. Saves editors from filling the date manually and
|
||||
* keeps blog/article dates accurate for Article JSON-LD and sitemaps.
|
||||
*
|
||||
* Attach to collections with drafts enabled (blog, articles):
|
||||
* hooks: { beforeChange: [setPublishedAtHook] }
|
||||
*
|
||||
* Only sets on the published transition; never overwrites an existing date
|
||||
* (an editor can still backdate manually).
|
||||
*/
|
||||
export declare const setPublishedAtHook: CollectionBeforeChangeHook;
|
||||
Vendored
+19
@@ -0,0 +1,19 @@
|
||||
/**
|
||||
* Sets `publishedAt` to now the first time a document transitions to published,
|
||||
* if it isn't already set. Saves editors from filling the date manually and
|
||||
* keeps blog/article dates accurate for Article JSON-LD and sitemaps.
|
||||
*
|
||||
* Attach to collections with drafts enabled (blog, articles):
|
||||
* hooks: { beforeChange: [setPublishedAtHook] }
|
||||
*
|
||||
* Only sets on the published transition; never overwrites an existing date
|
||||
* (an editor can still backdate manually).
|
||||
*/ export const setPublishedAtHook = ({ data, originalDoc })=>{
|
||||
const becomingPublished = data._status === 'published' && originalDoc?._status !== 'published';
|
||||
if (becomingPublished && !data.publishedAt) {
|
||||
data.publishedAt = new Date().toISOString();
|
||||
}
|
||||
return data;
|
||||
};
|
||||
|
||||
//# sourceMappingURL=setPublishedAt.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/hooks/setPublishedAt.ts"],"sourcesContent":["import type { CollectionBeforeChangeHook } from 'payload'\n\n/**\n * Sets `publishedAt` to now the first time a document transitions to published,\n * if it isn't already set. Saves editors from filling the date manually and\n * keeps blog/article dates accurate for Article JSON-LD and sitemaps.\n *\n * Attach to collections with drafts enabled (blog, articles):\n * hooks: { beforeChange: [setPublishedAtHook] }\n *\n * Only sets on the published transition; never overwrites an existing date\n * (an editor can still backdate manually).\n */\nexport const setPublishedAtHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {\n const becomingPublished = data._status === 'published' && originalDoc?._status !== 'published'\n if (becomingPublished && !data.publishedAt) {\n data.publishedAt = new Date().toISOString()\n }\n return data\n}\n"],"names":["setPublishedAtHook","data","originalDoc","becomingPublished","_status","publishedAt","Date","toISOString"],"mappings":"AAEA;;;;;;;;;;CAUC,GACD,OAAO,MAAMA,qBAAiD,CAAC,EAAEC,IAAI,EAAEC,WAAW,EAAE;IAClF,MAAMC,oBAAoBF,KAAKG,OAAO,KAAK,eAAeF,aAAaE,YAAY;IACnF,IAAID,qBAAqB,CAACF,KAAKI,WAAW,EAAE;QAC1CJ,KAAKI,WAAW,GAAG,IAAIC,OAAOC,WAAW;IAC3C;IACA,OAAON;AACT,EAAC"}
|
||||
+17
@@ -0,0 +1,17 @@
|
||||
import type { CollectionBeforeChangeHook } from 'payload';
|
||||
/**
|
||||
* When a document's slug changes, appends the OLD slug to a `slugHistory` array
|
||||
* field. The project reads slugHistory to serve a 301 redirect from old URLs to
|
||||
* the current one — so changing a slug doesn't 404 the old address (a real SEO
|
||||
* loss / audit finding).
|
||||
*
|
||||
* Requires a `slugHistory` field on the collection:
|
||||
* { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],
|
||||
* admin: { readOnly: true } }
|
||||
*
|
||||
* hooks: { beforeChange: [trackSlugHistoryHook] }
|
||||
*
|
||||
* The project then, in resolveRoute or a redirect check, looks up slugHistory and
|
||||
* 301s to the current slug. See docs/hooks.md.
|
||||
*/
|
||||
export declare const trackSlugHistoryHook: CollectionBeforeChangeHook;
|
||||
+33
@@ -0,0 +1,33 @@
|
||||
/**
|
||||
* When a document's slug changes, appends the OLD slug to a `slugHistory` array
|
||||
* field. The project reads slugHistory to serve a 301 redirect from old URLs to
|
||||
* the current one — so changing a slug doesn't 404 the old address (a real SEO
|
||||
* loss / audit finding).
|
||||
*
|
||||
* Requires a `slugHistory` field on the collection:
|
||||
* { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],
|
||||
* admin: { readOnly: true } }
|
||||
*
|
||||
* hooks: { beforeChange: [trackSlugHistoryHook] }
|
||||
*
|
||||
* The project then, in resolveRoute or a redirect check, looks up slugHistory and
|
||||
* 301s to the current slug. See docs/hooks.md.
|
||||
*/ export const trackSlugHistoryHook = ({ data, originalDoc })=>{
|
||||
const oldSlug = originalDoc?.slug;
|
||||
const newSlug = data.slug;
|
||||
if (typeof oldSlug === 'string' && typeof newSlug === 'string' && oldSlug !== newSlug && oldSlug.length > 0) {
|
||||
const history = Array.isArray(data.slugHistory) ? data.slugHistory : Array.isArray(originalDoc?.slugHistory) ? originalDoc.slugHistory : [];
|
||||
// Avoid duplicates; don't record the new slug itself.
|
||||
if (!history.some((h)=>h?.slug === oldSlug)) {
|
||||
data.slugHistory = [
|
||||
...history,
|
||||
{
|
||||
slug: oldSlug
|
||||
}
|
||||
];
|
||||
}
|
||||
}
|
||||
return data;
|
||||
};
|
||||
|
||||
//# sourceMappingURL=trackSlugHistory.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/hooks/trackSlugHistory.ts"],"sourcesContent":["import type { CollectionBeforeChangeHook } from 'payload'\n\n/**\n * When a document's slug changes, appends the OLD slug to a `slugHistory` array\n * field. The project reads slugHistory to serve a 301 redirect from old URLs to\n * the current one — so changing a slug doesn't 404 the old address (a real SEO\n * loss / audit finding).\n *\n * Requires a `slugHistory` field on the collection:\n * { name: 'slugHistory', type: 'array', fields: [{ name: 'slug', type: 'text' }],\n * admin: { readOnly: true } }\n *\n * hooks: { beforeChange: [trackSlugHistoryHook] }\n *\n * The project then, in resolveRoute or a redirect check, looks up slugHistory and\n * 301s to the current slug. See docs/hooks.md.\n */\nexport const trackSlugHistoryHook: CollectionBeforeChangeHook = ({ data, originalDoc }) => {\n const oldSlug = originalDoc?.slug\n const newSlug = data.slug\n if (\n typeof oldSlug === 'string' &&\n typeof newSlug === 'string' &&\n oldSlug !== newSlug &&\n oldSlug.length > 0\n ) {\n const history: Array<{ slug: string }> = Array.isArray(data.slugHistory)\n ? data.slugHistory\n : Array.isArray(originalDoc?.slugHistory)\n ? originalDoc.slugHistory\n : []\n // Avoid duplicates; don't record the new slug itself.\n if (!history.some((h) => h?.slug === oldSlug)) {\n data.slugHistory = [...history, { slug: oldSlug }]\n }\n }\n return data\n}\n"],"names":["trackSlugHistoryHook","data","originalDoc","oldSlug","slug","newSlug","length","history","Array","isArray","slugHistory","some","h"],"mappings":"AAEA;;;;;;;;;;;;;;CAcC,GACD,OAAO,MAAMA,uBAAmD,CAAC,EAAEC,IAAI,EAAEC,WAAW,EAAE;IACpF,MAAMC,UAAUD,aAAaE;IAC7B,MAAMC,UAAUJ,KAAKG,IAAI;IACzB,IACE,OAAOD,YAAY,YACnB,OAAOE,YAAY,YACnBF,YAAYE,WACZF,QAAQG,MAAM,GAAG,GACjB;QACA,MAAMC,UAAmCC,MAAMC,OAAO,CAACR,KAAKS,WAAW,IACnET,KAAKS,WAAW,GAChBF,MAAMC,OAAO,CAACP,aAAaQ,eACzBR,YAAYQ,WAAW,GACvB,EAAE;QACR,sDAAsD;QACtD,IAAI,CAACH,QAAQI,IAAI,CAAC,CAACC,IAAMA,GAAGR,SAASD,UAAU;YAC7CF,KAAKS,WAAW,GAAG;mBAAIH;gBAAS;oBAAEH,MAAMD;gBAAQ;aAAE;QACpD;IACF;IACA,OAAOF;AACT,EAAC"}
|
||||
+16
@@ -0,0 +1,16 @@
|
||||
import type { FieldHook } from 'payload';
|
||||
/**
|
||||
* Field hook for a System Page role relationship in SiteSettings: ensures a page
|
||||
* isn't assigned to two roles at once (e.g. the same page as both homepage and
|
||||
* privacyPolicy), which would make routing ambiguous.
|
||||
*
|
||||
* Attach to each role field's beforeValidate. `siblingFields` are the OTHER role
|
||||
* field names to check against.
|
||||
*
|
||||
* hooks: { beforeValidate: [buildValidateUniqueRole({
|
||||
* siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],
|
||||
* })] }
|
||||
*/
|
||||
export declare function buildValidateUniqueRole(args: {
|
||||
siblingFields: string[];
|
||||
}): FieldHook;
|
||||
+31
@@ -0,0 +1,31 @@
|
||||
import { APIError } from 'payload';
|
||||
/**
|
||||
* Field hook for a System Page role relationship in SiteSettings: ensures a page
|
||||
* isn't assigned to two roles at once (e.g. the same page as both homepage and
|
||||
* privacyPolicy), which would make routing ambiguous.
|
||||
*
|
||||
* Attach to each role field's beforeValidate. `siblingFields` are the OTHER role
|
||||
* field names to check against.
|
||||
*
|
||||
* hooks: { beforeValidate: [buildValidateUniqueRole({
|
||||
* siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],
|
||||
* })] }
|
||||
*/ export function buildValidateUniqueRole(args) {
|
||||
return ({ field, siblingData, value })=>{
|
||||
if (value == null) {
|
||||
return value;
|
||||
}
|
||||
const thisId = typeof value === 'object' ? value.id : value;
|
||||
for (const sibling of args.siblingFields){
|
||||
const other = siblingData?.[sibling];
|
||||
const otherId = other && typeof other === 'object' ? other.id : other;
|
||||
if (otherId != null && String(otherId) === String(thisId)) {
|
||||
const name = typeof field === 'object' && 'name' in field ? field.name : 'ta rola';
|
||||
throw new APIError(`Ta sama strona jest przypisana do "${name}" i "${sibling}". ` + `Każda rola systemowa musi wskazywać inną stronę.`, 400);
|
||||
}
|
||||
}
|
||||
return value;
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=validateUniqueRole.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/hooks/validateUniqueRole.ts"],"sourcesContent":["import type { FieldHook } from 'payload'\n\nimport { APIError } from 'payload'\n\n/**\n * Field hook for a System Page role relationship in SiteSettings: ensures a page\n * isn't assigned to two roles at once (e.g. the same page as both homepage and\n * privacyPolicy), which would make routing ambiguous.\n *\n * Attach to each role field's beforeValidate. `siblingFields` are the OTHER role\n * field names to check against.\n *\n * hooks: { beforeValidate: [buildValidateUniqueRole({\n * siblingFields: ['privacyPolicy', 'cookiePolicy', 'termsOfService'],\n * })] }\n */\nexport function buildValidateUniqueRole(args: { siblingFields: string[] }): FieldHook {\n return ({ field, siblingData, value }) => {\n if (value == null) {return value}\n const thisId = typeof value === 'object' ? (value as { id?: unknown }).id : value\n for (const sibling of args.siblingFields) {\n const other = (siblingData as Record<string, unknown>)?.[sibling]\n const otherId = other && typeof other === 'object' ? (other as { id?: unknown }).id : other\n if (otherId != null && String(otherId) === String(thisId)) {\n const name = typeof field === 'object' && 'name' in field ? field.name : 'ta rola'\n throw new APIError(\n `Ta sama strona jest przypisana do \"${name}\" i \"${sibling}\". ` +\n `Każda rola systemowa musi wskazywać inną stronę.`,\n 400,\n )\n }\n }\n return value\n }\n}\n"],"names":["APIError","buildValidateUniqueRole","args","field","siblingData","value","thisId","id","sibling","siblingFields","other","otherId","String","name"],"mappings":"AAEA,SAASA,QAAQ,QAAQ,UAAS;AAElC;;;;;;;;;;;CAWC,GACD,OAAO,SAASC,wBAAwBC,IAAiC;IACvE,OAAO,CAAC,EAAEC,KAAK,EAAEC,WAAW,EAAEC,KAAK,EAAE;QACnC,IAAIA,SAAS,MAAM;YAAC,OAAOA;QAAK;QAChC,MAAMC,SAAS,OAAOD,UAAU,WAAW,AAACA,MAA2BE,EAAE,GAAGF;QAC5E,KAAK,MAAMG,WAAWN,KAAKO,aAAa,CAAE;YACxC,MAAMC,QAASN,aAAyC,CAACI,QAAQ;YACjE,MAAMG,UAAUD,SAAS,OAAOA,UAAU,WAAW,AAACA,MAA2BH,EAAE,GAAGG;YACtF,IAAIC,WAAW,QAAQC,OAAOD,aAAaC,OAAON,SAAS;gBACzD,MAAMO,OAAO,OAAOV,UAAU,YAAY,UAAUA,QAAQA,MAAMU,IAAI,GAAG;gBACzE,MAAM,IAAIb,SACR,CAAC,mCAAmC,EAAEa,KAAK,KAAK,EAAEL,QAAQ,GAAG,CAAC,GAC5D,CAAC,gDAAgD,CAAC,EACpD;YAEJ;QACF;QACA,OAAOH;IACT;AACF"}
|
||||
+22
-22
@@ -1,21 +1,21 @@
|
||||
import type { I18nConfig } from './types.js';
|
||||
import type { I18nConfig } from '../i18n/index.js';
|
||||
/**
|
||||
* Minimal request shape the middleware reads. Kept structural so the plugin
|
||||
* doesn't hard-depend on next/server types; a Next.js `NextRequest` satisfies it.
|
||||
*/
|
||||
type MiddlewareRequest = {
|
||||
nextUrl: {
|
||||
pathname: string;
|
||||
search: string;
|
||||
clone: () => URL;
|
||||
};
|
||||
cookies: {
|
||||
get: (name: string) => {
|
||||
value: string;
|
||||
} | undefined;
|
||||
};
|
||||
headers: {
|
||||
get: (name: string) => null | string;
|
||||
};
|
||||
nextUrl: {
|
||||
clone: () => URL;
|
||||
pathname: string;
|
||||
search: string;
|
||||
get: (name: string) => string | null;
|
||||
};
|
||||
url: string;
|
||||
};
|
||||
@@ -25,21 +25,23 @@ type MiddlewareRequest = {
|
||||
* `next` means let the request pass through untouched.
|
||||
*/
|
||||
export type LocaleMiddlewareResult = {
|
||||
cookie?: {
|
||||
name: string;
|
||||
value: string;
|
||||
};
|
||||
location: string;
|
||||
type: 'redirect';
|
||||
} | {
|
||||
cookie?: {
|
||||
name: string;
|
||||
value: string;
|
||||
};
|
||||
type: 'next';
|
||||
cookie?: {
|
||||
name: string;
|
||||
value: string;
|
||||
};
|
||||
} | {
|
||||
type: 'redirect';
|
||||
location: string;
|
||||
cookie?: {
|
||||
name: string;
|
||||
value: string;
|
||||
};
|
||||
};
|
||||
type CreateLocaleMiddlewareArgs = {
|
||||
config: I18nConfig;
|
||||
/** Cookie name for the locale choice. Defaults to LOCALE_COOKIE_NAME. */
|
||||
cookieName?: string;
|
||||
/**
|
||||
* Consent category that gates *persisting* the locale cookie. The locale is
|
||||
* always detected (routing works regardless), but the choice is only written
|
||||
@@ -47,11 +49,9 @@ type CreateLocaleMiddlewareArgs = {
|
||||
* 'functional'. Pass 'necessary' to always persist (treat locale as strictly
|
||||
* necessary), which restores the pre-consent behaviour.
|
||||
*/
|
||||
consentCategory?: 'functional' | 'necessary';
|
||||
consentCategory?: 'necessary' | 'functional';
|
||||
/** Name of the consent cookie to read. Defaults to CONSENT_COOKIE. */
|
||||
consentCookieName?: string;
|
||||
/** Cookie name for the locale choice. Defaults to LOCALE_COOKIE_NAME. */
|
||||
cookieName?: string;
|
||||
};
|
||||
/**
|
||||
* Builds locale-routing logic for Next.js middleware.
|
||||
@@ -80,7 +80,7 @@ type CreateLocaleMiddlewareArgs = {
|
||||
* return res
|
||||
* }
|
||||
*/
|
||||
export declare function createLocaleMiddleware({ config, consentCategory, consentCookieName, cookieName, }: CreateLocaleMiddlewareArgs): (request: MiddlewareRequest) => LocaleMiddlewareResult;
|
||||
export declare function createLocaleMiddleware({ config, cookieName, consentCategory, consentCookieName, }: CreateLocaleMiddlewareArgs): (request: MiddlewareRequest) => LocaleMiddlewareResult;
|
||||
/**
|
||||
* Default Next.js middleware matcher: run on everything except API routes, the
|
||||
* admin panel, Next internals, and files with an extension (static assets).
|
||||
|
||||
+15
-7
@@ -1,5 +1,5 @@
|
||||
import { negotiateLocale, isValidLocale, LOCALE_COOKIE_NAME } from '../i18n/index.js';
|
||||
import { CONSENT_COOKIE, parseConsent } from '../consent/storage.js';
|
||||
import { isValidLocale, LOCALE_COOKIE_NAME, negotiateLocale } from '../i18n/index.js';
|
||||
/**
|
||||
* First path segment of a URL pathname, or '' for root.
|
||||
* '/pl/o-nas' → 'pl', '/o-nas' → 'o-nas', '/' → ''.
|
||||
@@ -32,18 +32,26 @@ import { isValidLocale, LOCALE_COOKIE_NAME, negotiateLocale } from '../i18n/inde
|
||||
* if (r.cookie) res.cookies.set(r.cookie.name, r.cookie.value)
|
||||
* return res
|
||||
* }
|
||||
*/ export function createLocaleMiddleware({ config, consentCategory = 'functional', consentCookieName = CONSENT_COOKIE, cookieName = LOCALE_COOKIE_NAME }) {
|
||||
*/ export function createLocaleMiddleware({ config, cookieName = LOCALE_COOKIE_NAME, consentCategory = 'functional', consentCookieName = CONSENT_COOKIE }) {
|
||||
// Whether the locale cookie may be written: 'necessary' is always granted;
|
||||
// 'functional' (default) requires the visitor to have consented.
|
||||
function mayPersistLocale(request) {
|
||||
if (consentCategory === 'necessary') {
|
||||
return true;
|
||||
}
|
||||
if (consentCategory === 'necessary') return true;
|
||||
const consent = parseConsent(request.cookies.get(consentCookieName)?.value);
|
||||
return consent?.[consentCategory] === true;
|
||||
}
|
||||
return function localeMiddleware(request) {
|
||||
const { pathname } = request.nextUrl;
|
||||
// Single-locale sites have no /pl, /en prefix and no negotiation — one
|
||||
// language, no redirect. The middleware becomes a pass-through: paths stay
|
||||
// as-is (/o-nas), nothing to detect or persist. (Projects that are truly
|
||||
// single-locale usually don't even mount this middleware, but guarding here
|
||||
// makes it safe if they do.)
|
||||
if (config.locales.length === 1) {
|
||||
return {
|
||||
type: 'next'
|
||||
};
|
||||
}
|
||||
// Already locale-prefixed (e.g. the visitor switched language by
|
||||
// navigating to /en). Routing is fine — but if the URL's locale differs
|
||||
// from the stored cookie, the visitor is *choosing* a language, and we
|
||||
@@ -68,9 +76,9 @@ import { isValidLocale, LOCALE_COOKIE_NAME, negotiateLocale } from '../i18n/inde
|
||||
}
|
||||
// Resolve the locale to use
|
||||
const locale = negotiateLocale({
|
||||
cookieLocale: request.cookies.get(cookieName)?.value ?? null,
|
||||
acceptLanguage: request.headers.get('accept-language'),
|
||||
config,
|
||||
cookieLocale: request.cookies.get(cookieName)?.value ?? null
|
||||
config
|
||||
});
|
||||
// Redirect to the locale-prefixed path, preserving the rest
|
||||
const url = request.nextUrl.clone();
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+19
-13
@@ -8,14 +8,22 @@ import type { I18nConfig } from './types.js';
|
||||
*/
|
||||
export type LocalizedSlugs = Record<string, string>;
|
||||
type BuildPathArgs = {
|
||||
config: I18nConfig;
|
||||
/**
|
||||
* Slug that represents the site root (served at /{locale} with no trailing
|
||||
* segment). Defaults to 'home'. Matched against the slug in the target locale.
|
||||
*/
|
||||
homeSlug?: string;
|
||||
/** slug per locale, e.g. { pl: 'strona-glowna', en: 'home' } */
|
||||
slugs: LocalizedSlugs;
|
||||
/** Target locale to build the path for */
|
||||
locale: string;
|
||||
config: I18nConfig;
|
||||
/**
|
||||
* Slug(s) representing the site root (served at /{locale} with no trailing
|
||||
* segment). Defaults to 'home'. Matched against the slug in the target locale.
|
||||
*
|
||||
* Can be a single string (same home slug in every locale) OR a per-locale map
|
||||
* (`{ pl: 'strona-glowna', de: 'startseite', en: 'home' }`). The map form is
|
||||
* REQUIRED for multilingual homepages whose slug differs per language —
|
||||
* otherwise the home page collapses to '/pl' but '/de/startseite' stays
|
||||
* un-collapsed, breaking hreflang return tags (a real GSC error).
|
||||
*/
|
||||
homeSlug?: string | Record<string, string>;
|
||||
/**
|
||||
* Localized segment the document lives under, e.g.
|
||||
* `{ pl: 'artykuly', en: 'articles' }` → /pl/artykuly/moj-post.
|
||||
@@ -25,8 +33,6 @@ type BuildPathArgs = {
|
||||
* A document under a prefix is never the home page, so homeSlug is ignored.
|
||||
*/
|
||||
prefix?: LocalizedSlugs;
|
||||
/** slug per locale, e.g. { pl: 'strona-glowna', en: 'home' } */
|
||||
slugs: LocalizedSlugs;
|
||||
};
|
||||
/**
|
||||
* Builds a locale-prefixed path for a document in a target locale.
|
||||
@@ -50,13 +56,13 @@ type BuildPathArgs = {
|
||||
* })
|
||||
* // → '/en/articles/my-post'
|
||||
*/
|
||||
export declare function buildLocalizedPath({ config, homeSlug, locale, prefix, slugs, }: BuildPathArgs): string | undefined;
|
||||
export declare function buildLocalizedPath({ slugs, locale, config, homeSlug, prefix, }: BuildPathArgs): string | undefined;
|
||||
type SwitchLocaleArgs = {
|
||||
config: I18nConfig;
|
||||
homeSlug?: string;
|
||||
prefix?: LocalizedSlugs;
|
||||
slugs: LocalizedSlugs;
|
||||
targetLocale: string;
|
||||
config: I18nConfig;
|
||||
homeSlug?: string | Record<string, string>;
|
||||
prefix?: LocalizedSlugs;
|
||||
};
|
||||
/**
|
||||
* Resolves the equivalent path for the same document in a different locale —
|
||||
@@ -66,5 +72,5 @@ type SwitchLocaleArgs = {
|
||||
* falls back to the archive it belongs to (/en/articles) if there is one, and
|
||||
* to the locale root otherwise — the closest place the visitor would want.
|
||||
*/
|
||||
export declare function switchLocalePath({ config, homeSlug, prefix, slugs, targetLocale, }: SwitchLocaleArgs): string;
|
||||
export declare function switchLocalePath({ slugs, targetLocale, config, homeSlug, prefix, }: SwitchLocaleArgs): string;
|
||||
export {};
|
||||
|
||||
Vendored
+23
-15
@@ -20,7 +20,7 @@ import { isValidLocale } from './helpers.js';
|
||||
* config,
|
||||
* })
|
||||
* // → '/en/articles/my-post'
|
||||
*/ export function buildLocalizedPath({ config, homeSlug = 'home', locale, prefix, slugs }) {
|
||||
*/ export function buildLocalizedPath({ slugs, locale, config, homeSlug = 'home', prefix }) {
|
||||
if (!isValidLocale(locale, config)) {
|
||||
return undefined;
|
||||
}
|
||||
@@ -28,6 +28,12 @@ import { isValidLocale } from './helpers.js';
|
||||
if (!slug) {
|
||||
return undefined;
|
||||
}
|
||||
// Single-locale sites have no /pl, /en prefix — the language segment is
|
||||
// dropped entirely (path is /o-nas, not /pl/o-nas). Detected automatically:
|
||||
// one configured locale means one language, so no prefix is needed. The
|
||||
// project's folder structure matches (app/[[...slug]] without [locale]).
|
||||
const singleLocale = config.locales.length === 1;
|
||||
const localeSegment = singleLocale ? '' : `/${locale}`;
|
||||
if (prefix) {
|
||||
const segment = prefix[locale];
|
||||
// No archive slug in this locale means the entry is unreachable there —
|
||||
@@ -36,12 +42,18 @@ import { isValidLocale } from './helpers.js';
|
||||
if (!segment) {
|
||||
return undefined;
|
||||
}
|
||||
return `/${locale}/${segment}/${slug}`;
|
||||
return `${localeSegment}/${segment}/${slug}`;
|
||||
}
|
||||
if (slug === homeSlug) {
|
||||
return `/${locale}`;
|
||||
// Resolve the home slug for THIS locale. With a per-locale map, each language
|
||||
// has its own home slug (pl: 'strona-glowna', de: 'startseite'), so the check
|
||||
// below correctly collapses each language's home to its root — instead of only
|
||||
// the current-language slug matching and the others staying un-collapsed.
|
||||
const targetHomeSlug = typeof homeSlug === 'object' ? homeSlug[locale] : homeSlug;
|
||||
if (slug === targetHomeSlug) {
|
||||
// Home collapses to the root: '/' for single-locale, '/pl' otherwise.
|
||||
return localeSegment || '/';
|
||||
}
|
||||
return `/${locale}/${slug}`;
|
||||
return `${localeSegment}/${slug}`;
|
||||
}
|
||||
/**
|
||||
* Resolves the equivalent path for the same document in a different locale —
|
||||
@@ -50,21 +62,17 @@ import { isValidLocale } from './helpers.js';
|
||||
* Never dead-ends on a 404. When the document has no slug in the target locale,
|
||||
* falls back to the archive it belongs to (/en/articles) if there is one, and
|
||||
* to the locale root otherwise — the closest place the visitor would want.
|
||||
*/ export function switchLocalePath({ config, homeSlug = 'home', prefix, slugs, targetLocale }) {
|
||||
*/ export function switchLocalePath({ slugs, targetLocale, config, homeSlug = 'home', prefix }) {
|
||||
const path = buildLocalizedPath({
|
||||
slugs,
|
||||
locale: targetLocale,
|
||||
config,
|
||||
homeSlug,
|
||||
locale: targetLocale,
|
||||
prefix,
|
||||
slugs
|
||||
prefix
|
||||
});
|
||||
if (path) {
|
||||
return path;
|
||||
}
|
||||
if (path) return path;
|
||||
const archiveSegment = prefix?.[targetLocale];
|
||||
if (archiveSegment) {
|
||||
return `/${targetLocale}/${archiveSegment}`;
|
||||
}
|
||||
if (archiveSegment) return `/${targetLocale}/${archiveSegment}`;
|
||||
return `/${targetLocale}`;
|
||||
}
|
||||
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
+8
-1
@@ -1,6 +1,13 @@
|
||||
import type { I18nConfig } from './types.js';
|
||||
/** Cookie name the template uses to persist a visitor's locale choice. */
|
||||
export declare const LOCALE_COOKIE_NAME = "ipal-locale";
|
||||
/**
|
||||
* Cookie name for the persisted locale choice. Uses NEXT_LOCALE — the convention
|
||||
* Next.js and its i18n ecosystem expect — so the cookie is interoperable with
|
||||
* other libraries that read the active locale (instead of a plugin-specific
|
||||
* name). Written only under functional consent; cleared when that consent is
|
||||
* withdrawn (see consent cookieMap).
|
||||
*/
|
||||
export declare const LOCALE_COOKIE_NAME = "NEXT_LOCALE";
|
||||
type NegotiateLocaleArgs = {
|
||||
/** Raw Accept-Language header value */
|
||||
acceptLanguage?: null | string;
|
||||
|
||||
Vendored
+7
-1
@@ -1,5 +1,11 @@
|
||||
import { getLocaleCodes, isValidLocale } from './helpers.js';
|
||||
/** Cookie name the template uses to persist a visitor's locale choice. */ export const LOCALE_COOKIE_NAME = 'ipal-locale';
|
||||
/** Cookie name the template uses to persist a visitor's locale choice. */ /**
|
||||
* Cookie name for the persisted locale choice. Uses NEXT_LOCALE — the convention
|
||||
* Next.js and its i18n ecosystem expect — so the cookie is interoperable with
|
||||
* other libraries that read the active locale (instead of a plugin-specific
|
||||
* name). Written only under functional consent; cleared when that consent is
|
||||
* withdrawn (see consent cookieMap).
|
||||
*/ export const LOCALE_COOKIE_NAME = 'NEXT_LOCALE';
|
||||
/**
|
||||
* Resolves which locale to serve, in priority order:
|
||||
* 1. Cookie (explicit prior choice)
|
||||
|
||||
+1
-1
File diff suppressed because one or more lines are too long
Vendored
+1
@@ -0,0 +1 @@
|
||||
export { normalizeFilename, normalizeFilenameHook } from './normalizeFilename.js';
|
||||
Vendored
+3
@@ -0,0 +1,3 @@
|
||||
export { normalizeFilename, normalizeFilenameHook } from './normalizeFilename.js';
|
||||
|
||||
//# sourceMappingURL=index.js.map
|
||||
Vendored
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/media/index.ts"],"sourcesContent":["export { normalizeFilename, normalizeFilenameHook } from './normalizeFilename.js'\n"],"names":["normalizeFilename","normalizeFilenameHook"],"mappings":"AAAA,SAASA,iBAAiB,EAAEC,qBAAqB,QAAQ,yBAAwB"}
|
||||
+25
@@ -0,0 +1,25 @@
|
||||
import type { CollectionBeforeOperationHook } from 'payload';
|
||||
/**
|
||||
* Normalizes a filename: slugifies the NAME part (diacritics, spaces, case)
|
||||
* while preserving the extension. Keeps uploaded media URLs clean and portable.
|
||||
*
|
||||
* "Zdjęcie jeden nad morzem.jpg" → "zdjecie-jeden-nad-morzem.jpg"
|
||||
* "Faktura #12 (2024).PDF" → "faktura-12-2024.pdf"
|
||||
* "already-clean.webp" → "already-clean.webp"
|
||||
*
|
||||
* Why not toSlug(): toSlug uses strict:true, which would strip the dot and
|
||||
* merge name+extension. Here we split on the LAST dot, slug the stem, lowercase
|
||||
* the extension, and rejoin.
|
||||
*/
|
||||
export declare function normalizeFilename(filename: string): string;
|
||||
/**
|
||||
* beforeOperation hook for an upload collection (e.g. Media). Rewrites the
|
||||
* incoming file's name to its normalized form before Payload stores it, so both
|
||||
* the stored file and its DB filename are clean. Works with local disk and with
|
||||
* cloud storage adapters (R2/S3) — it runs before the storage layer.
|
||||
*
|
||||
* Wire into your Media collection:
|
||||
* import { normalizeFilenameHook } from '@intecion/ipal-kit'
|
||||
* hooks: { beforeOperation: [normalizeFilenameHook] }
|
||||
*/
|
||||
export declare const normalizeFilenameHook: CollectionBeforeOperationHook;
|
||||
+57
@@ -0,0 +1,57 @@
|
||||
import slugify from 'slugify';
|
||||
/**
|
||||
* Normalizes a filename: slugifies the NAME part (diacritics, spaces, case)
|
||||
* while preserving the extension. Keeps uploaded media URLs clean and portable.
|
||||
*
|
||||
* "Zdjęcie jeden nad morzem.jpg" → "zdjecie-jeden-nad-morzem.jpg"
|
||||
* "Faktura #12 (2024).PDF" → "faktura-12-2024.pdf"
|
||||
* "already-clean.webp" → "already-clean.webp"
|
||||
*
|
||||
* Why not toSlug(): toSlug uses strict:true, which would strip the dot and
|
||||
* merge name+extension. Here we split on the LAST dot, slug the stem, lowercase
|
||||
* the extension, and rejoin.
|
||||
*/ export function normalizeFilename(filename) {
|
||||
const lastDot = filename.lastIndexOf('.');
|
||||
// No extension (or leading-dot dotfile) → slug the whole thing.
|
||||
if (lastDot <= 0) {
|
||||
return slugify(filename, {
|
||||
lower: true,
|
||||
strict: true,
|
||||
trim: true
|
||||
});
|
||||
}
|
||||
const stem = filename.slice(0, lastDot);
|
||||
const ext = filename.slice(lastDot + 1).toLowerCase();
|
||||
const cleanStem = slugify(stem, {
|
||||
lower: true,
|
||||
strict: true,
|
||||
trim: true
|
||||
});
|
||||
const cleanExt = slugify(ext, {
|
||||
lower: true,
|
||||
strict: true,
|
||||
trim: true
|
||||
});
|
||||
// Stem could slug to empty (e.g. filename was all symbols) — fall back so we
|
||||
// never produce a nameless file.
|
||||
const safeStem = cleanStem || 'plik';
|
||||
return cleanExt ? `${safeStem}.${cleanExt}` : safeStem;
|
||||
}
|
||||
/**
|
||||
* beforeOperation hook for an upload collection (e.g. Media). Rewrites the
|
||||
* incoming file's name to its normalized form before Payload stores it, so both
|
||||
* the stored file and its DB filename are clean. Works with local disk and with
|
||||
* cloud storage adapters (R2/S3) — it runs before the storage layer.
|
||||
*
|
||||
* Wire into your Media collection:
|
||||
* import { normalizeFilenameHook } from '@intecion/ipal-kit'
|
||||
* hooks: { beforeOperation: [normalizeFilenameHook] }
|
||||
*/ export const normalizeFilenameHook = ({ req, operation })=>{
|
||||
if (operation !== 'create' && operation !== 'update') return;
|
||||
const file = req.file;
|
||||
if (file?.name) {
|
||||
file.name = normalizeFilename(file.name);
|
||||
}
|
||||
};
|
||||
|
||||
//# sourceMappingURL=normalizeFilename.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/media/normalizeFilename.ts"],"sourcesContent":["import type { CollectionBeforeOperationHook } from 'payload'\nimport slugify from 'slugify'\n\n/**\n * Normalizes a filename: slugifies the NAME part (diacritics, spaces, case)\n * while preserving the extension. Keeps uploaded media URLs clean and portable.\n *\n * \"Zdjęcie jeden nad morzem.jpg\" → \"zdjecie-jeden-nad-morzem.jpg\"\n * \"Faktura #12 (2024).PDF\" → \"faktura-12-2024.pdf\"\n * \"already-clean.webp\" → \"already-clean.webp\"\n *\n * Why not toSlug(): toSlug uses strict:true, which would strip the dot and\n * merge name+extension. Here we split on the LAST dot, slug the stem, lowercase\n * the extension, and rejoin.\n */\nexport function normalizeFilename(filename: string): string {\n const lastDot = filename.lastIndexOf('.')\n\n // No extension (or leading-dot dotfile) → slug the whole thing.\n if (lastDot <= 0) {\n return slugify(filename, { lower: true, strict: true, trim: true })\n }\n\n const stem = filename.slice(0, lastDot)\n const ext = filename.slice(lastDot + 1).toLowerCase()\n\n const cleanStem = slugify(stem, { lower: true, strict: true, trim: true })\n const cleanExt = slugify(ext, { lower: true, strict: true, trim: true })\n\n // Stem could slug to empty (e.g. filename was all symbols) — fall back so we\n // never produce a nameless file.\n const safeStem = cleanStem || 'plik'\n\n return cleanExt ? `${safeStem}.${cleanExt}` : safeStem\n}\n\n/**\n * beforeOperation hook for an upload collection (e.g. Media). Rewrites the\n * incoming file's name to its normalized form before Payload stores it, so both\n * the stored file and its DB filename are clean. Works with local disk and with\n * cloud storage adapters (R2/S3) — it runs before the storage layer.\n *\n * Wire into your Media collection:\n * import { normalizeFilenameHook } from '@intecion/ipal-kit'\n * hooks: { beforeOperation: [normalizeFilenameHook] }\n */\nexport const normalizeFilenameHook: CollectionBeforeOperationHook = ({ req, operation }) => {\n if (operation !== 'create' && operation !== 'update') return\n const file = req.file\n if (file?.name) {\n file.name = normalizeFilename(file.name)\n }\n}\n"],"names":["slugify","normalizeFilename","filename","lastDot","lastIndexOf","lower","strict","trim","stem","slice","ext","toLowerCase","cleanStem","cleanExt","safeStem","normalizeFilenameHook","req","operation","file","name"],"mappings":"AACA,OAAOA,aAAa,UAAS;AAE7B;;;;;;;;;;;CAWC,GACD,OAAO,SAASC,kBAAkBC,QAAgB;IAChD,MAAMC,UAAUD,SAASE,WAAW,CAAC;IAErC,gEAAgE;IAChE,IAAID,WAAW,GAAG;QAChB,OAAOH,QAAQE,UAAU;YAAEG,OAAO;YAAMC,QAAQ;YAAMC,MAAM;QAAK;IACnE;IAEA,MAAMC,OAAON,SAASO,KAAK,CAAC,GAAGN;IAC/B,MAAMO,MAAMR,SAASO,KAAK,CAACN,UAAU,GAAGQ,WAAW;IAEnD,MAAMC,YAAYZ,QAAQQ,MAAM;QAAEH,OAAO;QAAMC,QAAQ;QAAMC,MAAM;IAAK;IACxE,MAAMM,WAAWb,QAAQU,KAAK;QAAEL,OAAO;QAAMC,QAAQ;QAAMC,MAAM;IAAK;IAEtE,6EAA6E;IAC7E,iCAAiC;IACjC,MAAMO,WAAWF,aAAa;IAE9B,OAAOC,WAAW,GAAGC,SAAS,CAAC,EAAED,UAAU,GAAGC;AAChD;AAEA;;;;;;;;;CASC,GACD,OAAO,MAAMC,wBAAuD,CAAC,EAAEC,GAAG,EAAEC,SAAS,EAAE;IACrF,IAAIA,cAAc,YAAYA,cAAc,UAAU;IACtD,MAAMC,OAAOF,IAAIE,IAAI;IACrB,IAAIA,MAAMC,MAAM;QACdD,KAAKC,IAAI,GAAGlB,kBAAkBiB,KAAKC,IAAI;IACzC;AACF,EAAC"}
|
||||
+17
@@ -0,0 +1,17 @@
|
||||
/**
|
||||
* Built-in English fallbacks, used per field when the Notifications global
|
||||
* leaves a text empty. Same philosophy as consent FALLBACK: the site works out
|
||||
* of the box, editors override per locale as needed.
|
||||
*/ export const NOTIFICATION_FALLBACK = {
|
||||
form: {
|
||||
success: 'Thank you — your message has been sent.',
|
||||
error: 'Something went wrong. Please try again later.',
|
||||
rateLimited: 'Too many attempts. Please wait a moment and try again.',
|
||||
turnstile: 'Captcha verification failed. Please try again.',
|
||||
validation: 'Please check the {field} field and try again.',
|
||||
consent: 'Please accept the privacy policy to continue.',
|
||||
notFound: 'This form is no longer available.'
|
||||
}
|
||||
};
|
||||
|
||||
//# sourceMappingURL=defaults.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/notifications/defaults.ts"],"sourcesContent":["import type { NotificationTexts } from './types.js'\n\n/**\n * Built-in English fallbacks, used per field when the Notifications global\n * leaves a text empty. Same philosophy as consent FALLBACK: the site works out\n * of the box, editors override per locale as needed.\n */\nexport const NOTIFICATION_FALLBACK: NotificationTexts = {\n form: {\n success: 'Thank you — your message has been sent.',\n error: 'Something went wrong. Please try again later.',\n rateLimited: 'Too many attempts. Please wait a moment and try again.',\n turnstile: 'Captcha verification failed. Please try again.',\n validation: 'Please check the {field} field and try again.',\n consent: 'Please accept the privacy policy to continue.',\n notFound: 'This form is no longer available.',\n },\n}\n"],"names":["NOTIFICATION_FALLBACK","form","success","error","rateLimited","turnstile","validation","consent","notFound"],"mappings":"AAEA;;;;CAIC,GACD,OAAO,MAAMA,wBAA2C;IACtDC,MAAM;QACJC,SAAS;QACTC,OAAO;QACPC,aAAa;QACbC,WAAW;QACXC,YAAY;QACZC,SAAS;QACTC,UAAU;IACZ;AACF,EAAC"}
|
||||
@@ -0,0 +1,27 @@
|
||||
import { getGlobal } from '../payload/index.js';
|
||||
import { NOTIFICATION_FALLBACK } from './defaults.js';
|
||||
/**
|
||||
* Resolves notification texts from the Notifications global, falling back to
|
||||
* English defaults per field. Mirrors getConsentTexts: one read, per-field
|
||||
* fallback, locale-aware. The frontend maps a submitForm result code to the
|
||||
* matching text and styles it however it likes (toast, inline, banner).
|
||||
*/ export async function getNotificationTexts({ locale, payload }) {
|
||||
const g = await getGlobal(payload, 'notifications', {
|
||||
locale
|
||||
});
|
||||
const f = g.form ?? {};
|
||||
const fb = NOTIFICATION_FALLBACK.form;
|
||||
return {
|
||||
form: {
|
||||
consent: f.consent || fb.consent,
|
||||
error: f.error || fb.error,
|
||||
notFound: f.notFound || fb.notFound,
|
||||
rateLimited: f.rateLimited || fb.rateLimited,
|
||||
success: f.success || fb.success,
|
||||
turnstile: f.turnstile || fb.turnstile,
|
||||
validation: f.validation || fb.validation
|
||||
}
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=getNotificationTexts.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/notifications/getNotificationTexts.ts"],"sourcesContent":["import type { BasePayload } from 'payload'\n\nimport type { NotificationsData, NotificationTexts } from './types.js'\n\nimport { getGlobal } from '../payload/index.js'\nimport { NOTIFICATION_FALLBACK } from './defaults.js'\n\ntype GetNotificationTextsArgs = {\n /** Active locale — selects the language variant of each text. */\n locale?: string\n payload: BasePayload\n}\n\n/**\n * Resolves notification texts from the Notifications global, falling back to\n * English defaults per field. Mirrors getConsentTexts: one read, per-field\n * fallback, locale-aware. The frontend maps a submitForm result code to the\n * matching text and styles it however it likes (toast, inline, banner).\n */\nexport async function getNotificationTexts({\n locale,\n payload,\n}: GetNotificationTextsArgs): Promise<NotificationTexts> {\n const g = await getGlobal<NotificationsData>(payload, 'notifications', { locale })\n\n const f = g.form ?? {}\n const fb = NOTIFICATION_FALLBACK.form\n\n return {\n form: {\n consent: f.consent || fb.consent,\n error: f.error || fb.error,\n notFound: f.notFound || fb.notFound,\n rateLimited: f.rateLimited || fb.rateLimited,\n success: f.success || fb.success,\n turnstile: f.turnstile || fb.turnstile,\n validation: f.validation || fb.validation,\n },\n }\n}\n"],"names":["getGlobal","NOTIFICATION_FALLBACK","getNotificationTexts","locale","payload","g","f","form","fb","consent","error","notFound","rateLimited","success","turnstile","validation"],"mappings":"AAIA,SAASA,SAAS,QAAQ,sBAAqB;AAC/C,SAASC,qBAAqB,QAAQ,gBAAe;AAQrD;;;;;CAKC,GACD,OAAO,eAAeC,qBAAqB,EACzCC,MAAM,EACNC,OAAO,EACkB;IACzB,MAAMC,IAAI,MAAML,UAA6BI,SAAS,iBAAiB;QAAED;IAAO;IAEhF,MAAMG,IAAID,EAAEE,IAAI,IAAI,CAAC;IACrB,MAAMC,KAAKP,sBAAsBM,IAAI;IAErC,OAAO;QACLA,MAAM;YACJE,SAASH,EAAEG,OAAO,IAAID,GAAGC,OAAO;YAChCC,OAAOJ,EAAEI,KAAK,IAAIF,GAAGE,KAAK;YAC1BC,UAAUL,EAAEK,QAAQ,IAAIH,GAAGG,QAAQ;YACnCC,aAAaN,EAAEM,WAAW,IAAIJ,GAAGI,WAAW;YAC5CC,SAASP,EAAEO,OAAO,IAAIL,GAAGK,OAAO;YAChCC,WAAWR,EAAEQ,SAAS,IAAIN,GAAGM,SAAS;YACtCC,YAAYT,EAAES,UAAU,IAAIP,GAAGO,UAAU;QAC3C;IACF;AACF"}
|
||||
Vendored
+5
@@ -0,0 +1,5 @@
|
||||
export { NOTIFICATION_FALLBACK } from './defaults.js';
|
||||
export { getNotificationTexts } from './getNotificationTexts.js';
|
||||
export { resolveFormMessage } from './resolveFormMessage.js';
|
||||
|
||||
//# sourceMappingURL=index.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/notifications/index.ts"],"sourcesContent":["export { NOTIFICATION_FALLBACK } from './defaults.js'\nexport { getNotificationTexts } from './getNotificationTexts.js'\nexport { resolveFormMessage } from './resolveFormMessage.js'\nexport type { FormNotificationTexts, NotificationsData, NotificationTexts } from './types.js'\n"],"names":["NOTIFICATION_FALLBACK","getNotificationTexts","resolveFormMessage"],"mappings":"AAAA,SAASA,qBAAqB,QAAQ,gBAAe;AACrD,SAASC,oBAAoB,QAAQ,4BAA2B;AAChE,SAASC,kBAAkB,QAAQ,0BAAyB"}
|
||||
@@ -0,0 +1,35 @@
|
||||
/**
|
||||
* Maps a submitForm result to the user-facing message, interpolating {field}
|
||||
* for validation errors. This is the bridge the frontend uses: it gets a result
|
||||
* code from submitForm and the resolved texts from getNotificationTexts, and
|
||||
* this turns them into one string to display. Keeping the mapping here means the
|
||||
* frontend never hard-codes messages or knows about result codes.
|
||||
*
|
||||
* Never surfaces raw backend/exception detail — 'error' maps to a friendly
|
||||
* generic message, not the thrown error's text (which could leak internals).
|
||||
*/ export function resolveFormMessage(result, texts) {
|
||||
if (result.success) {
|
||||
return texts.success;
|
||||
}
|
||||
switch(result.reason){
|
||||
case 'consent':
|
||||
return texts.consent;
|
||||
case 'not_found':
|
||||
return texts.notFound;
|
||||
case 'rate_limited':
|
||||
return texts.rateLimited;
|
||||
case 'turnstile':
|
||||
return texts.turnstile;
|
||||
case 'validation':
|
||||
{
|
||||
// Interpolate {field} with the offending field name when present.
|
||||
const field = 'field' in result && result.field ? result.field : '';
|
||||
return texts.validation.replace('{field}', field);
|
||||
}
|
||||
case 'error':
|
||||
default:
|
||||
return texts.error;
|
||||
}
|
||||
}
|
||||
|
||||
//# sourceMappingURL=resolveFormMessage.js.map
|
||||
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/notifications/resolveFormMessage.ts"],"sourcesContent":["import type { SubmitFormResult } from '../forms/index.js'\nimport type { FormNotificationTexts } from './types.js'\n\n/**\n * Maps a submitForm result to the user-facing message, interpolating {field}\n * for validation errors. This is the bridge the frontend uses: it gets a result\n * code from submitForm and the resolved texts from getNotificationTexts, and\n * this turns them into one string to display. Keeping the mapping here means the\n * frontend never hard-codes messages or knows about result codes.\n *\n * Never surfaces raw backend/exception detail — 'error' maps to a friendly\n * generic message, not the thrown error's text (which could leak internals).\n */\nexport function resolveFormMessage(result: SubmitFormResult, texts: FormNotificationTexts): string {\n if (result.success) {return texts.success}\n\n switch (result.reason) {\n case 'consent':\n return texts.consent\n case 'not_found':\n return texts.notFound\n case 'rate_limited':\n return texts.rateLimited\n case 'turnstile':\n return texts.turnstile\n case 'validation': {\n // Interpolate {field} with the offending field name when present.\n const field = 'field' in result && result.field ? result.field : ''\n return texts.validation.replace('{field}', field)\n }\n case 'error':\n default:\n return texts.error\n }\n}\n"],"names":["resolveFormMessage","result","texts","success","reason","consent","notFound","rateLimited","turnstile","field","validation","replace","error"],"mappings":"AAGA;;;;;;;;;CASC,GACD,OAAO,SAASA,mBAAmBC,MAAwB,EAAEC,KAA4B;IACvF,IAAID,OAAOE,OAAO,EAAE;QAAC,OAAOD,MAAMC,OAAO;IAAA;IAEzC,OAAQF,OAAOG,MAAM;QACnB,KAAK;YACH,OAAOF,MAAMG,OAAO;QACtB,KAAK;YACH,OAAOH,MAAMI,QAAQ;QACvB,KAAK;YACH,OAAOJ,MAAMK,WAAW;QAC1B,KAAK;YACH,OAAOL,MAAMM,SAAS;QACxB,KAAK;YAAc;gBACjB,kEAAkE;gBAClE,MAAMC,QAAQ,WAAWR,UAAUA,OAAOQ,KAAK,GAAGR,OAAOQ,KAAK,GAAG;gBACjE,OAAOP,MAAMQ,UAAU,CAACC,OAAO,CAAC,WAAWF;YAC7C;QACA,KAAK;QACL;YACE,OAAOP,MAAMU,KAAK;IACtB;AACF"}
|
||||
Vendored
+6
@@ -0,0 +1,6 @@
|
||||
/**
|
||||
* Resolved notification texts, ready for the frontend. Grouped per context;
|
||||
* `form` maps submitForm result codes to user-facing messages.
|
||||
*/ /** Raw shape read from the Notifications global (all fields optional). */ export { };
|
||||
|
||||
//# sourceMappingURL=types.js.map
|
||||
+1
@@ -0,0 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/notifications/types.ts"],"sourcesContent":["/**\n * Resolved notification texts, ready for the frontend. Grouped per context;\n * `form` maps submitForm result codes to user-facing messages.\n */\nexport type FormNotificationTexts = {\n success: string\n error: string\n rateLimited: string\n turnstile: string\n /** May contain the {field} placeholder — resolve with resolveValidationText. */\n validation: string\n /** Shown when a required GDPR consent checkbox was left unchecked. */\n consent: string\n notFound: string\n}\n\nexport type NotificationTexts = {\n form: FormNotificationTexts\n}\n\n/** Raw shape read from the Notifications global (all fields optional). */\nexport type NotificationsData = {\n form?: Partial<FormNotificationTexts>\n}\n"],"names":[],"mappings":"AAAA;;;CAGC,GAiBD,wEAAwE,GACxE,WAEC"}
|
||||
+1
-1
@@ -16,7 +16,7 @@ type GetSystemPagePathArgs = {
|
||||
* page's slug in the target locale equals this, the path collapses to the
|
||||
* locale root (/pl, /en).
|
||||
*/
|
||||
homeSlug?: string;
|
||||
homeSlug?: string | Record<string, string>;
|
||||
/** Target locale to build the path for. */
|
||||
locale: string;
|
||||
/**
|
||||
|
||||
+1
-1
@@ -1 +1 @@
|
||||
{"version":3,"sources":["../../../src/modules/pages/getSystemPagePath.ts"],"sourcesContent":["import type { I18nConfig } from '../i18n/index.js'\nimport type { SystemPageRole } from './types.js'\n\nimport { buildLocalizedPath, getLocalizedSlugs } from '../i18n/index.js'\n\n/**\n * The shape we need from an assigned system-page document: its localized slug\n * field, as returned by Payload when the parent is read with `locale: 'all'`.\n *\n * The plugin doesn't know the client's Pages type, so it depends only on this\n * minimal contract.\n */\ntype AssignedPage = {\n slug?: null | Record<string, unknown>\n}\n\ntype GetSystemPagePathArgs = {\n config: I18nConfig\n /**\n * Slug that represents the site root. Defaults to 'home'. When the assigned\n * page's slug in the target locale equals this, the path collapses to the\n * locale root (/pl, /en).\n */\n homeSlug?: string\n /** Target locale to build the path for. */\n locale: string\n /**\n * The resolved system-page assignment from SiteSettings — the related\n * document object (not just an ID), read with `locale: 'all'` so its slug\n * is a locale→value map. Pass null/undefined if the role is unassigned.\n */\n page: AssignedPage | null | undefined\n}\n\n/**\n * Resolves a system-page assignment to a locale-aware path.\n *\n * Bridges the Pages module (which document plays a role) and the i18n module\n * (how that document's localized slug becomes a URL). This is what powers\n * \"visit /pl → serve the homepage\": read SiteSettings.homepage, pass the\n * related document here, get /pl/strona-glowna (or /pl if it's the home slug).\n *\n * Returns undefined when the role is unassigned or the assigned page has no\n * slug in the target locale — the caller decides the fallback (e.g. 404,\n * redirect to default locale).\n *\n * @example\n * const settings = await payload.findGlobal({ slug: 'site-settings', locale: 'all', depth: 1 })\n * getSystemPagePath({ page: settings.homepage, locale: 'pl', config })\n * // → '/pl' (home slug collapses to root)\n * getSystemPagePath({ page: settings.privacyPolicy, locale: 'en', config })\n * // → '/en/privacy-policy'\n */\nexport function getSystemPagePath({\n config,\n homeSlug = 'home',\n locale,\n page,\n}: GetSystemPagePathArgs): string | undefined {\n if (!page?.slug) {\n return undefined\n }\n\n const slugs = getLocalizedSlugs({ config, slugField: page.slug })\n return buildLocalizedPath({ config, homeSlug, locale, slugs })\n}\n"],"names":["buildLocalizedPath","getLocalizedSlugs","getSystemPagePath","config","homeSlug","locale","page","slug","undefined","slugs","slugField"],"mappings":"AAGA,SAASA,kBAAkB,EAAEC,iBAAiB,QAAQ,mBAAkB;AA+BxE;;;;;;;;;;;;;;;;;;CAkBC,GACD,OAAO,SAASC,kBAAkB,EAChCC,MAAM,EACNC,WAAW,MAAM,EACjBC,MAAM,EACNC,IAAI,EACkB;IACtB,IAAI,CAACA,MAAMC,MAAM;QACf,OAAOC;IACT;IAEA,MAAMC,QAAQR,kBAAkB;QAAEE;QAAQO,WAAWJ,KAAKC,IAAI;IAAC;IAC/D,OAAOP,mBAAmB;QAAEG;QAAQC;QAAUC;QAAQI;IAAM;AAC9D"}
|
||||
{"version":3,"sources":["../../../src/modules/pages/getSystemPagePath.ts"],"sourcesContent":["import type { I18nConfig } from '../i18n/index.js'\nimport type { SystemPageRole } from './types.js'\n\nimport { buildLocalizedPath, getLocalizedSlugs } from '../i18n/index.js'\n\n/**\n * The shape we need from an assigned system-page document: its localized slug\n * field, as returned by Payload when the parent is read with `locale: 'all'`.\n *\n * The plugin doesn't know the client's Pages type, so it depends only on this\n * minimal contract.\n */\ntype AssignedPage = {\n slug?: null | Record<string, unknown>\n}\n\ntype GetSystemPagePathArgs = {\n config: I18nConfig\n /**\n * Slug that represents the site root. Defaults to 'home'. When the assigned\n * page's slug in the target locale equals this, the path collapses to the\n * locale root (/pl, /en).\n */\n homeSlug?: string | Record<string, string>\n /** Target locale to build the path for. */\n locale: string\n /**\n * The resolved system-page assignment from SiteSettings — the related\n * document object (not just an ID), read with `locale: 'all'` so its slug\n * is a locale→value map. Pass null/undefined if the role is unassigned.\n */\n page: AssignedPage | null | undefined\n}\n\n/**\n * Resolves a system-page assignment to a locale-aware path.\n *\n * Bridges the Pages module (which document plays a role) and the i18n module\n * (how that document's localized slug becomes a URL). This is what powers\n * \"visit /pl → serve the homepage\": read SiteSettings.homepage, pass the\n * related document here, get /pl/strona-glowna (or /pl if it's the home slug).\n *\n * Returns undefined when the role is unassigned or the assigned page has no\n * slug in the target locale — the caller decides the fallback (e.g. 404,\n * redirect to default locale).\n *\n * @example\n * const settings = await payload.findGlobal({ slug: 'site-settings', locale: 'all', depth: 1 })\n * getSystemPagePath({ page: settings.homepage, locale: 'pl', config })\n * // → '/pl' (home slug collapses to root)\n * getSystemPagePath({ page: settings.privacyPolicy, locale: 'en', config })\n * // → '/en/privacy-policy'\n */\nexport function getSystemPagePath({\n config,\n homeSlug = 'home',\n locale,\n page,\n}: GetSystemPagePathArgs): string | undefined {\n if (!page?.slug) {\n return undefined\n }\n\n const slugs = getLocalizedSlugs({ config, slugField: page.slug })\n return buildLocalizedPath({ config, homeSlug, locale, slugs })\n}\n"],"names":["buildLocalizedPath","getLocalizedSlugs","getSystemPagePath","config","homeSlug","locale","page","slug","undefined","slugs","slugField"],"mappings":"AAGA,SAASA,kBAAkB,EAAEC,iBAAiB,QAAQ,mBAAkB;AA+BxE;;;;;;;;;;;;;;;;;;CAkBC,GACD,OAAO,SAASC,kBAAkB,EAChCC,MAAM,EACNC,WAAW,MAAM,EACjBC,MAAM,EACNC,IAAI,EACkB;IACtB,IAAI,CAACA,MAAMC,MAAM;QACf,OAAOC;IACT;IAEA,MAAMC,QAAQR,kBAAkB;QAAEE;QAAQO,WAAWJ,KAAKC,IAAI;IAAC;IAC/D,OAAOP,mBAAmB;QAAEG;QAAQC;QAAUC;QAAQI;IAAM;AAC9D"}
|
||||
Vendored
+46
@@ -0,0 +1,46 @@
|
||||
export type BuildCspArgs = {
|
||||
/** Google Analytics / GTM — adds googletagmanager + google-analytics. */
|
||||
analytics?: boolean;
|
||||
/** Extra sources per directive, merged with the built-ins. */
|
||||
extra?: Partial<Record<CspDirective, string[]>>;
|
||||
/** Google Maps embeds — adds maps.google.com / *.gstatic.com. */
|
||||
googleMaps?: boolean;
|
||||
/** 'enforce' → Content-Security-Policy; 'report-only' → …-Report-Only header. */
|
||||
mode?: 'enforce' | 'report-only';
|
||||
/** Media/R2 public URL (from R2_PUBLIC_URL) — added to img-src. */
|
||||
r2Url?: string;
|
||||
/** Cloudflare Turnstile — adds challenges.cloudflare.com to script/frame/connect. */
|
||||
turnstile?: boolean;
|
||||
/** YouTube embeds — adds youtube to frame-src. */
|
||||
youtube?: boolean;
|
||||
};
|
||||
type CspDirective = 'base-uri' | 'connect-src' | 'default-src' | 'font-src' | 'form-action' | 'frame-ancestors' | 'frame-src' | 'img-src' | 'media-src' | 'object-src' | 'script-src' | 'style-src' | 'worker-src';
|
||||
/**
|
||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||
* directives baked in, and opt-in sources for common third parties. Solves the
|
||||
* real risk of hand-writing raw CSP per project and forgetting `base-uri 'self'`
|
||||
* or `object-src 'none'`.
|
||||
*
|
||||
* CSP still lives in the project (it lists the project's own domains), but this
|
||||
* helper standardizes the skeleton so every project's CSP has the same hardened
|
||||
* base — you only flip flags for what the project actually loads.
|
||||
*
|
||||
* Returns { key, value } ready for buildSecurityHeaders `additional`:
|
||||
*
|
||||
* import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
|
||||
* const csp = buildCsp({
|
||||
* mode: 'report-only', // start here; switch to 'enforce' when clean
|
||||
* r2Url: process.env.R2_PUBLIC_URL,
|
||||
* turnstile: true, analytics: true,
|
||||
* })
|
||||
* const headers = buildSecurityHeaders({ hsts: prod, additional: [csp] })
|
||||
*
|
||||
* Deploy CSP carefully: start with mode:'report-only', check the console for
|
||||
* violations across the whole site (forms/Turnstile, gallery/R2, embeds), add
|
||||
* missing sources via `extra`, THEN switch to 'enforce'. See docs/security.md.
|
||||
*/
|
||||
export declare function buildCsp(args?: BuildCspArgs): {
|
||||
key: string;
|
||||
value: string;
|
||||
};
|
||||
export {};
|
||||
Vendored
+109
@@ -0,0 +1,109 @@
|
||||
/**
|
||||
* Builds a Content-Security-Policy string with the hard OWASP/Lighthouse-required
|
||||
* directives baked in, and opt-in sources for common third parties. Solves the
|
||||
* real risk of hand-writing raw CSP per project and forgetting `base-uri 'self'`
|
||||
* or `object-src 'none'`.
|
||||
*
|
||||
* CSP still lives in the project (it lists the project's own domains), but this
|
||||
* helper standardizes the skeleton so every project's CSP has the same hardened
|
||||
* base — you only flip flags for what the project actually loads.
|
||||
*
|
||||
* Returns { key, value } ready for buildSecurityHeaders `additional`:
|
||||
*
|
||||
* import { buildCsp, buildSecurityHeaders } from '@intecion/ipal-kit'
|
||||
* const csp = buildCsp({
|
||||
* mode: 'report-only', // start here; switch to 'enforce' when clean
|
||||
* r2Url: process.env.R2_PUBLIC_URL,
|
||||
* turnstile: true, analytics: true,
|
||||
* })
|
||||
* const headers = buildSecurityHeaders({ hsts: prod, additional: [csp] })
|
||||
*
|
||||
* Deploy CSP carefully: start with mode:'report-only', check the console for
|
||||
* violations across the whole site (forms/Turnstile, gallery/R2, embeds), add
|
||||
* missing sources via `extra`, THEN switch to 'enforce'. See docs/security.md.
|
||||
*/ export function buildCsp(args = {}) {
|
||||
const { analytics, extra = {}, googleMaps, mode = 'enforce', r2Url, turnstile, youtube } = args;
|
||||
const src = {
|
||||
'default-src': [
|
||||
"'self'"
|
||||
],
|
||||
// 'unsafe-inline' is hard to avoid with Next/analytics; 'unsafe-eval' is NOT
|
||||
// added by default (weakens CSP) — add via extra only if a library needs it.
|
||||
'connect-src': [
|
||||
"'self'"
|
||||
],
|
||||
'font-src': [
|
||||
"'self'",
|
||||
'https://fonts.gstatic.com',
|
||||
'data:'
|
||||
],
|
||||
'form-action': [
|
||||
"'self'"
|
||||
],
|
||||
'frame-src': [],
|
||||
'img-src': [
|
||||
"'self'",
|
||||
'data:',
|
||||
'blob:'
|
||||
],
|
||||
'media-src': [],
|
||||
'script-src': [
|
||||
"'self'",
|
||||
"'unsafe-inline'"
|
||||
],
|
||||
'style-src': [
|
||||
"'self'",
|
||||
"'unsafe-inline'",
|
||||
'https://fonts.googleapis.com'
|
||||
],
|
||||
'worker-src': [],
|
||||
// HARD defaults (OWASP/Lighthouse) — always on, no reason to omit:
|
||||
'base-uri': [
|
||||
"'self'"
|
||||
],
|
||||
'frame-ancestors': [
|
||||
"'none'"
|
||||
],
|
||||
'object-src': [
|
||||
"'none'"
|
||||
]
|
||||
};
|
||||
if (r2Url) {
|
||||
src['img-src'].push(r2Url);
|
||||
}
|
||||
if (turnstile) {
|
||||
src['script-src'].push('https://challenges.cloudflare.com');
|
||||
src['frame-src'].push('https://challenges.cloudflare.com');
|
||||
src['connect-src'].push('https://challenges.cloudflare.com');
|
||||
}
|
||||
if (analytics) {
|
||||
src['script-src'].push('https://www.googletagmanager.com');
|
||||
src['connect-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com');
|
||||
src['img-src'].push('https://www.google-analytics.com', 'https://www.googletagmanager.com');
|
||||
}
|
||||
if (youtube) {
|
||||
src['frame-src'].push('https://www.youtube.com', 'https://www.youtube-nocookie.com');
|
||||
}
|
||||
if (googleMaps) {
|
||||
src['frame-src'].push('https://www.google.com', 'https://maps.google.com');
|
||||
src['script-src'].push('https://maps.googleapis.com');
|
||||
src['img-src'].push('https://maps.gstatic.com', 'https://*.googleapis.com');
|
||||
}
|
||||
// Merge caller extras.
|
||||
for (const [dir, values] of Object.entries(extra)){
|
||||
if (values && values.length) {
|
||||
src[dir] = [
|
||||
...src[dir] ?? [],
|
||||
...values
|
||||
];
|
||||
}
|
||||
}
|
||||
const value = Object.entries(src).filter(([, values])=>values.length > 0).map(([dir, values])=>`${dir} ${values.join(' ')}`).join('; ');
|
||||
const key = mode === 'report-only' ? 'Content-Security-Policy-Report-Only' : 'Content-Security-Policy';
|
||||
return {
|
||||
key,
|
||||
value
|
||||
};
|
||||
}
|
||||
|
||||
//# sourceMappingURL=buildCsp.js.map
|
||||
+1
File diff suppressed because one or more lines are too long
+78
@@ -0,0 +1,78 @@
|
||||
/**
|
||||
* A single HTTP header, in the shape Next.js next.config headers() expects.
|
||||
*/
|
||||
export type SecurityHeader = {
|
||||
key: string;
|
||||
value: string;
|
||||
};
|
||||
export type BuildSecurityHeadersArgs = {
|
||||
/**
|
||||
* Extra headers to append or override. Same-key entries replace the default,
|
||||
* so you can e.g. add your project's Content-Security-Policy here — CSP is
|
||||
* intentionally NOT a default because it depends on the project's own
|
||||
* domains (scripts, images, fonts, analytics). Keep CSP in your project.
|
||||
*/
|
||||
additional?: SecurityHeader[];
|
||||
/**
|
||||
* Cross-Origin-Opener-Policy. Default 'same-origin' — isolates the browsing
|
||||
* context so a malicious page can't hold a window.opener reference (protects
|
||||
* against XS-Leaks / Spectre-class attacks). Project-independent, so it's a
|
||||
* default. Use 'same-origin-allow-popups' if you open OAuth/payment popups
|
||||
* that need window.opener; false to omit.
|
||||
*/
|
||||
coop?: 'same-origin' | 'same-origin-allow-popups' | false;
|
||||
/**
|
||||
* X-Frame-Options value. 'DENY' (default) blocks all framing; 'SAMEORIGIN'
|
||||
* allows same-origin framing. Note: CSP frame-ancestors supersedes this in
|
||||
* modern browsers, but X-Frame-Options is kept for older ones. Set to null
|
||||
* to omit (e.g. if you set frame-ancestors in your project CSP).
|
||||
*/
|
||||
frameOptions?: 'DENY' | 'SAMEORIGIN' | null;
|
||||
/**
|
||||
* Enable HSTS (Strict-Transport-Security). Only takes effect over HTTPS, and
|
||||
* tells browsers to force HTTPS for `maxAge` seconds. Default true. Turn OFF
|
||||
* in local/dev over plain HTTP, or you may lock the browser to https on
|
||||
* localhost. Set the env guard in your next.config (see docs).
|
||||
*/
|
||||
hsts?: boolean;
|
||||
/** Add includeSubDomains to HSTS. Default true. */
|
||||
hstsIncludeSubDomains?: boolean;
|
||||
/** HSTS max-age in seconds. Default 63072000 (2 years), the common baseline. */
|
||||
hstsMaxAge?: number;
|
||||
/** Add preload to HSTS (only if you'll submit to the preload list). Default false. */
|
||||
hstsPreload?: boolean;
|
||||
/**
|
||||
* Permissions-Policy. Default disables camera, microphone, geolocation. Pass
|
||||
* your own string to override, or null to omit.
|
||||
*/
|
||||
permissionsPolicy?: null | string;
|
||||
/** Referrer-Policy. Default 'strict-origin-when-cross-origin' (browser default, explicit). */
|
||||
referrerPolicy?: null | string;
|
||||
};
|
||||
/**
|
||||
* Builds the generic, project-independent security headers every site should
|
||||
* send: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy,
|
||||
* Permissions-Policy. These are identical across projects, so the plugin owns
|
||||
* the boilerplate; the client spreads the result into next.config's headers().
|
||||
*
|
||||
* Content-Security-Policy is deliberately excluded: a useful CSP enumerates the
|
||||
* exact domains a project loads from (its CDN, analytics, embeds), so it can't
|
||||
* be generic without being either too loose (useless) or too strict (breaks the
|
||||
* site). Add your project's CSP via `additional`.
|
||||
*
|
||||
* @example
|
||||
* // next.config.ts
|
||||
* import { buildSecurityHeaders } from '@intecion/ipal-kit'
|
||||
* const securityHeaders = buildSecurityHeaders({
|
||||
* hsts: process.env.NODE_ENV === 'production', // off in dev over http
|
||||
* additional: [
|
||||
* { key: 'Content-Security-Policy', value: "default-src 'self'; ..." },
|
||||
* ],
|
||||
* })
|
||||
* const nextConfig = {
|
||||
* async headers() {
|
||||
* return [{ source: '/:path*', headers: securityHeaders }]
|
||||
* },
|
||||
* }
|
||||
*/
|
||||
export declare function buildSecurityHeaders(args?: BuildSecurityHeadersArgs): SecurityHeader[];
|
||||
+88
@@ -0,0 +1,88 @@
|
||||
/**
|
||||
* A single HTTP header, in the shape Next.js next.config headers() expects.
|
||||
*/ /**
|
||||
* Builds the generic, project-independent security headers every site should
|
||||
* send: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy,
|
||||
* Permissions-Policy. These are identical across projects, so the plugin owns
|
||||
* the boilerplate; the client spreads the result into next.config's headers().
|
||||
*
|
||||
* Content-Security-Policy is deliberately excluded: a useful CSP enumerates the
|
||||
* exact domains a project loads from (its CDN, analytics, embeds), so it can't
|
||||
* be generic without being either too loose (useless) or too strict (breaks the
|
||||
* site). Add your project's CSP via `additional`.
|
||||
*
|
||||
* @example
|
||||
* // next.config.ts
|
||||
* import { buildSecurityHeaders } from '@intecion/ipal-kit'
|
||||
* const securityHeaders = buildSecurityHeaders({
|
||||
* hsts: process.env.NODE_ENV === 'production', // off in dev over http
|
||||
* additional: [
|
||||
* { key: 'Content-Security-Policy', value: "default-src 'self'; ..." },
|
||||
* ],
|
||||
* })
|
||||
* const nextConfig = {
|
||||
* async headers() {
|
||||
* return [{ source: '/:path*', headers: securityHeaders }]
|
||||
* },
|
||||
* }
|
||||
*/ export function buildSecurityHeaders(args = {}) {
|
||||
const { additional = [], coop = 'same-origin', frameOptions = 'DENY', hsts = true, hstsIncludeSubDomains = true, hstsMaxAge = 63072000, hstsPreload = false, permissionsPolicy = 'camera=(), microphone=(), geolocation=()', referrerPolicy = 'strict-origin-when-cross-origin' } = args;
|
||||
const headers = [];
|
||||
if (hsts) {
|
||||
const parts = [
|
||||
`max-age=${hstsMaxAge}`
|
||||
];
|
||||
if (hstsIncludeSubDomains) {
|
||||
parts.push('includeSubDomains');
|
||||
}
|
||||
if (hstsPreload) {
|
||||
parts.push('preload');
|
||||
}
|
||||
headers.push({
|
||||
key: 'Strict-Transport-Security',
|
||||
value: parts.join('; ')
|
||||
});
|
||||
}
|
||||
if (frameOptions) {
|
||||
headers.push({
|
||||
key: 'X-Frame-Options',
|
||||
value: frameOptions
|
||||
});
|
||||
}
|
||||
// Prevents MIME-type sniffing — always safe, no project specifics.
|
||||
headers.push({
|
||||
key: 'X-Content-Type-Options',
|
||||
value: 'nosniff'
|
||||
});
|
||||
if (referrerPolicy) {
|
||||
headers.push({
|
||||
key: 'Referrer-Policy',
|
||||
value: referrerPolicy
|
||||
});
|
||||
}
|
||||
if (permissionsPolicy) {
|
||||
headers.push({
|
||||
key: 'Permissions-Policy',
|
||||
value: permissionsPolicy
|
||||
});
|
||||
}
|
||||
// COOP — isolates the browsing context (XS-Leaks / Spectre protection).
|
||||
if (coop) {
|
||||
headers.push({
|
||||
key: 'Cross-Origin-Opener-Policy',
|
||||
value: coop
|
||||
});
|
||||
}
|
||||
// Merge additional: same-key entries override the defaults above.
|
||||
for (const extra of additional){
|
||||
const i = headers.findIndex((h)=>h.key.toLowerCase() === extra.key.toLowerCase());
|
||||
if (i >= 0) {
|
||||
headers[i] = extra;
|
||||
} else {
|
||||
headers.push(extra);
|
||||
}
|
||||
}
|
||||
return headers;
|
||||
}
|
||||
|
||||
//# sourceMappingURL=buildSecurityHeaders.js.map
|
||||
File diff suppressed because one or more lines are too long
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user