Backend for the CMS page builder, all under the existing /api/v1: - pages.model: authoritative save gate — validates blocks against the registry and sanitizes them on every create/update; maps rows to/from the grouped API shape (metadata / settings); slug validated + reserved-checked at create and immutable after; `protected` can be set true via PATCH but only cleared via the unprotect path; published_at stamped on first publish. - sanitizeBlocks: post-validation normalizer (applies each block's sanitize, stamps version, defaults visible, recurses container slots). - reservedSlugs: guards page slugs from shadowing named routes/API namespaces. - Admin routes (staff-gated): GET/POST /pages, GET/PATCH/DELETE /pages/:id, POST /pages/:id/unprotect (password step-up, verified against the caller's own hash, never logged), POST /pages/:id/preview (1h token). Audit-logs create/publish/unpublish/protect/unprotect/delete. - Public routes: GET /public/pages/:slug (published; staff see drafts; site- mode gated) and GET /public/pages/:id/preview/:token (ungated, token is the access control). Preview token primitives added to auth/token.js. - Swagger annotations for all new endpoints. Verified end-to-end: model integration test against the dev DB (sanitize, invalid-block rejection, slug immutability, protected/unprotect, dup/reserved slug, published_at) + authenticated HTTP smoke (201 create, 400 invalid blocks, publish, public slug fetch, preview mint+fetch, 403 delete-protected, 401 wrong-password unprotect). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
29 lines
1.1 KiB
JavaScript
29 lines
1.1 KiB
JavaScript
// Slugs a CMS page may not claim, because a top-level page lives at `/:slug` and
|
|
// must never shadow an existing named route (SPA route or API namespace). The
|
|
// catch-all page route is matched only after these, but reserving the names up
|
|
// front gives the admin a clear "that slug is reserved" error at create time
|
|
// instead of a silently unreachable page.
|
|
//
|
|
// Kept as a Set of lowercase single-segment slugs. Page slugs are validated to a
|
|
// single segment (^[a-z0-9-]+$) so we only need to guard first path segments.
|
|
|
|
const RESERVED_SLUGS = new Set([
|
|
// API / infrastructure
|
|
'api', 'internal', 'uploads', 'assets', 'static', 'public',
|
|
// Auth / account
|
|
'login', 'logout', 'register', 'account', 'auth',
|
|
// Admin app
|
|
'admin',
|
|
// Existing top-level SPA sections
|
|
'site', 'wiki', 'news', 'newsletter', 'screenshots', 'five-on-friday', 'about', 'status',
|
|
// Page-builder's own surface
|
|
'pages', 'preview',
|
|
])
|
|
|
|
/** @returns {boolean} true if `slug` collides with a reserved route name. */
|
|
function isReservedSlug(slug) {
|
|
return RESERVED_SLUGS.has(String(slug).toLowerCase())
|
|
}
|
|
|
|
module.exports = { RESERVED_SLUGS, isReservedSlug }
|