mirror of
https://gitlab.w-hs.de/an14051/backerup-website.git
synced 2026-07-27 17:35:29 +00:00
feat: implement user authentication and admin management
- Add user management API endpoints for listing and creating users. - Implement login and logout functionality with rate limiting. - Create UI components for login form, logout button, and animated elements. - Add session management with JWT and secure cookie handling. - Seed initial admin user if no users exist. - Introduce utility functions for password hashing and user authentication. - Set up proxy middleware for route protection and security headers. - Create a JSON file for user data storage. - Add links configuration for external resources.
This commit is contained in:
@@ -1,12 +1,18 @@
|
||||
import { NextResponse } from 'next/server'
|
||||
import { nanoid } from 'nanoid'
|
||||
import { addFile } from '@/lib/store'
|
||||
import { getSession } from '@/lib/session'
|
||||
import type { FileRecord } from '@/lib/store'
|
||||
|
||||
const ALLOWED_EXTENSIONS = ['.backerup', '.json']
|
||||
const MAX_SIZE_BYTES = 500 * 1024 * 1024 // 500 MB
|
||||
|
||||
export async function POST(request: Request) {
|
||||
// Belt-and-suspenders auth check (middleware handles the primary check)
|
||||
const session = await getSession()
|
||||
if (!session) {
|
||||
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
||||
}
|
||||
let formData: FormData
|
||||
try {
|
||||
formData = await request.formData()
|
||||
|
||||
Reference in New Issue
Block a user