Backend for the CMS page builder, all under the existing /api/v1: - pages.model: authoritative save gate — validates blocks against the registry and sanitizes them on every create/update; maps rows to/from the grouped API shape (metadata / settings); slug validated + reserved-checked at create and immutable after; `protected` can be set true via PATCH but only cleared via the unprotect path; published_at stamped on first publish. - sanitizeBlocks: post-validation normalizer (applies each block's sanitize, stamps version, defaults visible, recurses container slots). - reservedSlugs: guards page slugs from shadowing named routes/API namespaces. - Admin routes (staff-gated): GET/POST /pages, GET/PATCH/DELETE /pages/:id, POST /pages/:id/unprotect (password step-up, verified against the caller's own hash, never logged), POST /pages/:id/preview (1h token). Audit-logs create/publish/unpublish/protect/unprotect/delete. - Public routes: GET /public/pages/:slug (published; staff see drafts; site- mode gated) and GET /public/pages/:id/preview/:token (ungated, token is the access control). Preview token primitives added to auth/token.js. - Swagger annotations for all new endpoints. Verified end-to-end: model integration test against the dev DB (sanitize, invalid-block rejection, slug immutability, protected/unprotect, dup/reserved slug, published_at) + authenticated HTTP smoke (201 create, 400 invalid blocks, publish, public slug fetch, preview mint+fetch, 403 delete-protected, 401 wrong-password unprotect). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
31 lines
1.1 KiB
JavaScript
31 lines
1.1 KiB
JavaScript
// Block registry entrypoint. Requiring this module registers every server-side
|
|
// block definition (schema + cache policy) exactly once, then re-exports the
|
|
// registry API and the blocks validator. Anything that needs to validate a
|
|
// page's blocks or look up a block type should require THIS module, not
|
|
// ./registry directly, so the definitions are guaranteed to be loaded.
|
|
//
|
|
// Wave 1 block definitions are registered below, one require() per block (each
|
|
// module self-registers on load). Requiring THIS module guarantees they are all
|
|
// present before anything validates a page's blocks.
|
|
|
|
const registry = require('./registry')
|
|
const { validateBlocks, MAX_BLOCKS, MAX_SUBBLOCKS } = require('./validateBlocks')
|
|
const { sanitizeBlocks } = require('./sanitizeBlocks')
|
|
|
|
// ── Wave 1 block definitions (self-register on require) ────────────────
|
|
require('./types/heading')
|
|
require('./types/richText')
|
|
require('./types/image')
|
|
require('./types/twoColumn')
|
|
require('./types/cta')
|
|
require('./types/divider')
|
|
require('./types/quote')
|
|
|
|
module.exports = {
|
|
...registry,
|
|
validateBlocks,
|
|
sanitizeBlocks,
|
|
MAX_BLOCKS,
|
|
MAX_SUBBLOCKS,
|
|
}
|