15 Commits
Author SHA1 Message Date
MichelleandClaude Fable 5 6a312ba055 chore: update version to 2.5.0
Build & Push Docker Image / build (release) Successful in 3m56s
Build & Push Docker Image / build (push) Successful in 3m57s
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:47:30 +02:00
MichelleandClaude Fable 5 8c65e4acd2 refactor: replace exceljs with write-excel-file for analytics export
Build & Push Docker Image / build (push) Successful in 3m57s
exceljs (latest 4.4.0) ships years-old transitive dependencies that
npm flags as deprecated on every install (rimraf 2, glob 7, inflight,
fstream, lodash.isequal) and needed a uuid override for a security
advisory. It was only used for the single-sheet analytics XLSX export,
which write-excel-file covers with the same output (column widths,
bold/grey header, formula-injection escaping).

Removes the now-unneeded exceljs uuid override.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:40:53 +02:00
MichelleandClaude Fable 5 fcd73d0667 fix: constrain modals to viewport height with internal scrolling
Build & Push Docker Image / build (push) Successful in 4m2s
Modal dialogs (e.g. the create-event form) grew beyond the screen and
scrolled the page behind them. Cap the card at the viewport height and
scroll the body inside it, keeping the header pinned.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:33:21 +02:00
MichelleandClaude Fable 5 8830f42ac5 feat: disable AI summary/transcription when room recording is off
- Unchecking "allow recording" in room settings now also clears the
  transcript/AI summary checkbox (it was only greyed out before, so a
  previously enabled value stayed checked and got saved)
- Server enforces the coupling on room create and update: with
  recording disabled, recording_transcript is always stored as 0

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:32:05 +02:00
MichelleandClaude Fable 5 e7c7dd28d3 chore: update dependencies and fix security vulnerabilities
Build & Push Docker Image / build (push) Successful in 4m1s
- npm update for all semver-compatible packages (vite 8.1.5,
  concurrently 9.2.4, axios 1.18.1, better-sqlite3 12.11.1, ...)
- nodemailer 8 -> 9 (fixes GHSA-p6gq-j5cr-w38f and three further
  advisories: CRLF header injection, jsonTransport/raw file-access
  bypasses, OAuth2 TLS validation)
- override exceljs' nested uuid to ^11.1.1 (GHSA-w5hq-g745-h8pq)
  instead of the breaking exceljs downgrade npm audit suggests
- allow better-sqlite3 install script (npm allowScripts policy)

npm audit: 0 vulnerabilities

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 09:15:28 +02:00
MichelleandClaude Fable 5 69e901f145 feat: send calendar event invitations by email or federation
Build & Push Docker Image / build (push) Successful in 4m18s
- New endpoint POST /api/calendar/events/:id/email sends event
  invitations with an .ics attachment to external email addresses
  (rate-limited like room email invites)
- Create-event dialog gets an optional invitations section to invite
  people by email or federation address right away
- The "Invite remote" dialog on existing events now accepts email
  addresses in addition to federation IDs

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-17 08:58:28 +02:00
MichelleandClaude Opus 4.8 849f54db7d chore: update version to 2.4.1
Build & Push Docker Image / build (push) Canceled after 0s
Build & Push Docker Image / build (release) Successful in 4m16s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 09:03:40 +02:00
MichelleandClaude Opus 4.8 4e89d9d0fe feat: disable transcript/summary recording formats when transcription is off
Build & Push Docker Image / build (push) Successful in 4m16s
When the per-room AI summary/transcript setting is disabled (or the
integration is not configured), pass
meta_bbb-disable-recording-formats=transcript,summary on meeting create
so BBB skips processing and publishing those formats entirely
(bigbluebutton/bigbluebutton#25277).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-16 09:01:18 +02:00
MichelleandClaude Opus 4.8 4aeca36a9c fix: log underlying network error cause for failed transcription requests
Build & Push Docker Image / build (push) Successful in 4m5s
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 12:30:17 +02:00
MichelleandClaude Opus 4.8 51b42cfee5 feat: add AI summary / transcript integration for recordings
Build & Push Docker Image / build (push) Successful in 4m17s
Build & Push Docker Image / build (release) Successful in 3m57s
Ported from greenlight-tm: when TRANSCRIPTION_API_URL and
TRANSCRIPTION_API_KEY are set in the .env and the per-room
"AI summary / transcript" setting is enabled, Redlight POSTs to
${TRANSCRIPTION_API_URL}/prompt (header X-Api-Key) as soon as the
"video" format of a recording becomes available.

- transcription.js: service with env gating, timeout and logging
- bbb.js: pass meta_bbb-recording-ready-url on meeting create when the
  room has the setting enabled
- recordings.js: unauthenticated /recording-ready callback that
  verifies BBB's signed_parameters JWT (HS256, shared secret), caches
  the recording and requests the transcription once per recording
  (deduped via transcript_requested_at)
- rooms: new recording_transcript column, accepted on create/update
- branding endpoint exposes transcriptionEnabled so the UI only shows
  the toggle when the server is configured
- RoomDetail: toggle under "Allow recording" (disabled when recording
  is off), de/en i18n
- chore: bump version to 2.4.0

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-14 11:56:45 +02:00
MichelleandClaude Opus 4.8 dffb68efe5 fix: move resetPassword email locales to server i18n
Build & Push Docker Image / build (push) Successful in 4m9s
The password reset email is rendered server-side via emaili18n.js,
which loads translations from server/i18n. The email.resetPassword
keys only existed in the frontend src/i18n locales, so t() returned
the raw key paths in the sent email. Move the EN/DE block to the
server locales and drop the unused copy from the frontend.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-28 22:28:37 +02:00
MichelleandClaude Opus 4.8 db82cd944f feat: add password reset ("forgot password") flow
Build & Push Docker Image / build (push) Successful in 4m12s
Add a self-service password reset to the login flow:

- Login page now shows a "Passwort vergessen?" link under the password field
- New /forgot-password page requests a reset email by address
- New /reset-password page sets a new password from an emailed token
- Backend: POST /auth/forgot-password and /auth/reset-password with
  dedicated rate limiters; tokens stored as SHA-256 hashes with a 1h expiry
- Generic responses avoid leaking account existence or SMTP/SSO state;
  SSO-only accounts are skipped
- New sendPasswordResetEmail mailer + email/auth i18n keys (de + en)
- DB migration: reset_token_hash, reset_token_expires, reset_requested_at

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-26 23:40:11 +02:00
Michelle 2f65e53a24 fix: wrap screenshots in collapsible details section in README
Build & Push Docker Image / build (push) Successful in 4m6s
2026-06-21 22:17:58 +02:00
Michelle 1518645145 Merge branch 'main' of https://git.scrunkly.cat/Michelle/redlight
Build & Push Docker Image / build (push) Successful in 4m13s
2026-06-21 22:16:43 +02:00
Michelle 64a1ba2548 Add screenshots to README 2026-06-21 22:16:42 +02:00
30 changed files with 1570 additions and 1390 deletions
+1
View File
@@ -9,3 +9,4 @@ uploads/
.gitignore .gitignore
.vscode/ .vscode/
*.md *.md
screenshots/
+7
View File
@@ -37,6 +37,13 @@ SMTP_FROM=noreply@example.com
# App URL (used for verification links, auto-detected if not set) # App URL (used for verification links, auto-detected if not set)
# APP_URL=https://your-domain.com # APP_URL=https://your-domain.com
# Recording Transcription / AI Summarization
# When the per-room "AI summary / transcript" setting is enabled, Redlight will POST to
# ${TRANSCRIPTION_API_URL}/prompt with header `X-Api-Key: ${TRANSCRIPTION_API_KEY}` as soon as
# the "video" format of the recording is available. Leave empty to disable the integration entirely.
# TRANSCRIPTION_API_URL=
# TRANSCRIPTION_API_KEY=
# Reverse Proxy trust depth (express 'trust proxy' setting) # Reverse Proxy trust depth (express 'trust proxy' setting)
# loopback = trust only 127.0.0.1 / ::1 (default) # loopback = trust only 127.0.0.1 / ::1 (default)
# Use a number for proxy hops (e.g. 1), or a specific IP/CIDR. # Use a number for proxy hops (e.g. 1), or a specific IP/CIDR.
+11
View File
@@ -9,6 +9,17 @@ A modern, self-hosted BigBlueButton frontend with 25+ themes, federation, calend
![License](https://img.shields.io/badge/License-GPL-pink) ![License](https://img.shields.io/badge/License-GPL-pink)
![BigBlueButton](https://img.shields.io/badge/BigBlueButton-Compatible-red) ![BigBlueButton](https://img.shields.io/badge/BigBlueButton-Compatible-red)
## 🖼️ Pictures
<details>
<summary>Click to expand screenshots</summary>
![Home](screenshots/home.png)
![Dashboard](screenshots/dashboard.png)
![Rooms](screenshots/rooms.png)
</details>
## ✨ Features ## ✨ Features
### Core Features ### Core Features
+519 -1340
View File
File diff suppressed because it is too large Load Diff
+6 -3
View File
@@ -1,7 +1,7 @@
{ {
"name": "redlight", "name": "redlight",
"private": true, "private": true,
"version": "2.3.0", "version": "2.5.0",
"license": "GPL-3.0-or-later", "license": "GPL-3.0-or-later",
"type": "module", "type": "module",
"scripts": { "scripts": {
@@ -19,7 +19,6 @@
"concurrently": "^9.0.0", "concurrently": "^9.0.0",
"cors": "^2.8.5", "cors": "^2.8.5",
"dotenv": "^17.3.1", "dotenv": "^17.3.1",
"exceljs": "^4.4.0",
"express": "^5.2.1", "express": "^5.2.1",
"express-rate-limit": "^8.5.2", "express-rate-limit": "^8.5.2",
"flatpickr": "^4.6.13", "flatpickr": "^4.6.13",
@@ -27,7 +26,7 @@
"jsonwebtoken": "^9.0.0", "jsonwebtoken": "^9.0.0",
"lucide-react": "^1.16.0", "lucide-react": "^1.16.0",
"multer": "^2.1.0", "multer": "^2.1.0",
"nodemailer": "^8.0.1", "nodemailer": "^9.0.3",
"otpauth": "^9.5.0", "otpauth": "^9.5.0",
"pdfkit": "^0.18.0", "pdfkit": "^0.18.0",
"pg": "^8.18.0", "pg": "^8.18.0",
@@ -38,6 +37,7 @@
"react-hot-toast": "^2.4.0", "react-hot-toast": "^2.4.0",
"react-router-dom": "^7.15.1", "react-router-dom": "^7.15.1",
"uuid": "^14.0.0", "uuid": "^14.0.0",
"write-excel-file": "^4.1.1",
"xml2js": "^0.6.0" "xml2js": "^0.6.0"
}, },
"devDependencies": { "devDependencies": {
@@ -48,5 +48,8 @@
"postcss": "^8.4.0", "postcss": "^8.4.0",
"tailwindcss": "^4.3.0", "tailwindcss": "^4.3.0",
"vite": "^8.0.0" "vite": "^8.0.0"
},
"allowScripts": {
"better-sqlite3@12.11.1": true
} }
} }
Binary file not shown.

After

Width:  |  Height:  |  Size: 104 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 498 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 155 KiB

+12
View File
@@ -2,6 +2,7 @@
import xml2js from 'xml2js'; import xml2js from 'xml2js';
import { log, fmtDuration, fmtStatus, fmtMethod, fmtReturncode, sanitizeBBBParams } from './logger.js'; import { log, fmtDuration, fmtStatus, fmtMethod, fmtReturncode, sanitizeBBBParams } from './logger.js';
import { t } from './emaili18n.js'; import { t } from './emaili18n.js';
import { isTranscriptionEnabled } from './transcription.js';
const BBB_URL = process.env.BBB_URL || 'https://your-bbb-server.com/bigbluebutton/api/'; const BBB_URL = process.env.BBB_URL || 'https://your-bbb-server.com/bigbluebutton/api/';
const BBB_SECRET = process.env.BBB_SECRET || ''; const BBB_SECRET = process.env.BBB_SECRET || '';
@@ -115,6 +116,17 @@ export async function createMeeting(room, logoutURL, loginURL = null, presentati
if (analyticsCallbackURL) { if (analyticsCallbackURL) {
params['meta_analytics-callback-url'] = analyticsCallbackURL; params['meta_analytics-callback-url'] = analyticsCallbackURL;
} }
if (room.recording_transcript && isTranscriptionEnabled()) {
// BBB posts a signed recording-ready callback there once recording formats
// are processed; used to trigger the AI summary/transcript integration.
if (logoutURL) {
params['meta_bbb-recording-ready-url'] = `${logoutURL}/api/recordings/recording-ready`;
}
} else {
// Transcription/summary is off for this room — tell BBB to skip processing
// and publishing those recording formats entirely (BBB PR #25277).
params['meta_bbb-disable-recording-formats'] = 'transcript,summary';
}
// Build optional presentation XML body - escape URL to prevent XML injection // Build optional presentation XML body - escape URL to prevent XML injection
let xmlBody = null; let xmlBody = null;
+31
View File
@@ -384,6 +384,25 @@ export async function initDatabase() {
} }
} }
// Password reset: store a SHA-256 hash of the reset token (never the raw token)
if (!(await db.columnExists('users', 'reset_token_hash'))) {
await db.exec('ALTER TABLE users ADD COLUMN reset_token_hash TEXT DEFAULT NULL');
}
if (!(await db.columnExists('users', 'reset_token_expires'))) {
if (isPostgres) {
await db.exec('ALTER TABLE users ADD COLUMN reset_token_expires TIMESTAMP DEFAULT NULL');
} else {
await db.exec('ALTER TABLE users ADD COLUMN reset_token_expires DATETIME DEFAULT NULL');
}
}
if (!(await db.columnExists('users', 'reset_requested_at'))) {
if (isPostgres) {
await db.exec('ALTER TABLE users ADD COLUMN reset_requested_at TIMESTAMP DEFAULT NULL');
} else {
await db.exec('ALTER TABLE users ADD COLUMN reset_requested_at DATETIME DEFAULT NULL');
}
}
// Federation sync: add deleted + updated_at to federated_rooms // Federation sync: add deleted + updated_at to federated_rooms
if (!(await db.columnExists('federated_rooms', 'deleted'))) { if (!(await db.columnExists('federated_rooms', 'deleted'))) {
await db.exec('ALTER TABLE federated_rooms ADD COLUMN deleted INTEGER DEFAULT 0'); await db.exec('ALTER TABLE federated_rooms ADD COLUMN deleted INTEGER DEFAULT 0');
@@ -860,6 +879,18 @@ export async function initDatabase() {
`); `);
} }
// ── Recording transcription / AI summary ────────────────────────────────
if (!(await db.columnExists('rooms', 'recording_transcript'))) {
await db.exec('ALTER TABLE rooms ADD COLUMN recording_transcript INTEGER DEFAULT 0');
}
if (!(await db.columnExists('recordings', 'transcript_requested_at'))) {
if (isPostgres) {
await db.exec('ALTER TABLE recordings ADD COLUMN transcript_requested_at TIMESTAMP DEFAULT NULL');
} else {
await db.exec('ALTER TABLE recordings ADD COLUMN transcript_requested_at DATETIME DEFAULT NULL');
}
}
// ── Default admin (only on very first start) ──────────────────────────── // ── Default admin (only on very first start) ────────────────────────────
const adminAlreadySeeded = await db.get("SELECT value FROM settings WHERE key = 'admin_seeded'"); const adminAlreadySeeded = await db.get("SELECT value FROM settings WHERE key = 'admin_seeded'");
if (!adminAlreadySeeded) { if (!adminAlreadySeeded) {
+116
View File
@@ -92,6 +92,50 @@ export async function sendVerificationEmail(to, name, verifyUrl, appName = 'Redl
}); });
} }
/**
* Send a password reset email with a clickable link.
* @param {string} to - recipient email
* @param {string} name - user's display name
* @param {string} resetUrl - full password reset URL
* @param {string} appName - branding app name (default "Redlight")
* @param {string} lang - language code
*/
export async function sendPasswordResetEmail(to, name, resetUrl, appName = 'Redlight', lang = 'en') {
if (!transporter) {
throw new Error('SMTP not configured');
}
const from = process.env.SMTP_FROM || process.env.SMTP_USER;
const headerAppName = sanitizeHeaderValue(appName);
const safeName = escapeHtml(name);
await transporter.sendMail({
from: `"${headerAppName}" <${from}>`,
to,
subject: t(lang, 'email.resetPassword.subject', { appName: headerAppName }),
html: `
<div style="font-family:Arial,sans-serif;max-width:520px;margin:0 auto;padding:32px;background:#1e1e2e;color:#cdd6f4;border-radius:12px;">
<h2 style="color:#cba6f7;margin-top:0;">${t(lang, 'email.greeting', { name: safeName })}</h2>
<p>${t(lang, 'email.resetPassword.intro')}</p>
<p style="text-align:center;margin:28px 0;">
<a href="${resetUrl}"
style="display:inline-block;background:#cba6f7;color:#1e1e2e;padding:12px 32px;border-radius:8px;text-decoration:none;font-weight:bold;">
${t(lang, 'email.resetPassword.button')}
</a>
</p>
<p style="font-size:13px;color:#7f849c;">
${t(lang, 'email.linkHint')}<br/>
<a href="${resetUrl}" style="color:#89b4fa;word-break:break-all;">${escapeHtml(resetUrl)}</a>
</p>
<p style="font-size:13px;color:#7f849c;">${t(lang, 'email.resetPassword.validity')}</p>
<hr style="border:none;border-top:1px solid #313244;margin:24px 0;"/>
<p style="font-size:12px;color:#585b70;">${t(lang, 'email.resetPassword.footer')}</p>
</div>
`,
text: `${t(lang, 'email.greeting', { name })}\n\n${t(lang, 'email.resetPassword.intro')}\n${resetUrl}\n\n${t(lang, 'email.resetPassword.validity')}\n\n- ${appName}`,
});
}
/** /**
* Send a federation meeting invitation email. * Send a federation meeting invitation email.
* @param {string} to - recipient email * @param {string} to - recipient email
@@ -245,6 +289,78 @@ export async function sendCalendarInviteEmail(to, name, fromUser, title, startTi
}); });
} }
/**
* Send a calendar event invitation to an external email address (with ICS attachment).
* @param {string} to - recipient email
* @param {string} fromUser - sender display name
* @param {string} title - event title
* @param {string} startTime - ISO start time
* @param {string} endTime - ISO end time
* @param {string|null} description - optional event description
* @param {string|null} joinUrl - direct meeting join URL if a room is linked
* @param {string} ics - ICS file content to attach
* @param {string} appName - branding app name
* @param {string} lang - language code
*/
export async function sendCalendarEventEmail(to, fromUser, title, startTime, endTime, description, joinUrl, ics, appName = 'Redlight', lang = 'en') {
if (!transporter) {
throw new Error('SMTP not configured');
}
const from = process.env.SMTP_FROM || process.env.SMTP_USER;
const headerAppName = sanitizeHeaderValue(appName);
const safeFromUser = escapeHtml(fromUser);
const safeTitle = escapeHtml(title);
const safeDesc = description ? escapeHtml(description) : null;
const formatDate = (iso) => {
try { return new Date(iso).toLocaleString(lang === 'de' ? 'de-DE' : 'en-GB', { dateStyle: 'full', timeStyle: 'short' }); }
catch { return iso; }
};
const introHtml = t(lang, 'email.calendarEventInvite.intro')
.replace('{fromUser}', `<strong style="color:#cdd6f4;">${safeFromUser}</strong>`);
await transporter.sendMail({
from: `"${headerAppName}" <${from}>`,
to,
subject: t(lang, 'email.calendarEventInvite.subject', { appName: headerAppName, title: sanitizeHeaderValue(title) }),
html: `
<div style="font-family:Arial,sans-serif;max-width:520px;margin:0 auto;padding:32px;background:#1e1e2e;color:#cdd6f4;border-radius:12px;">
<h2 style="color:#cba6f7;margin-top:0;">${t(lang, 'email.calendarEventInvite.title')}</h2>
<p>${introHtml}</p>
<div style="background:#313244;border-radius:8px;padding:16px;margin:20px 0;">
<p style="margin:0 0 4px 0;font-size:15px;font-weight:bold;color:#cdd6f4;">${safeTitle}</p>
<p style="margin:6px 0 0 0;font-size:13px;color:#a6adc8;">${escapeHtml(formatDate(startTime))} - ${escapeHtml(formatDate(endTime))}</p>
${safeDesc ? `<p style="margin:10px 0 0 0;font-size:13px;color:#a6adc8;font-style:italic;">&quot;${safeDesc}&quot;</p>` : ''}
</div>
${joinUrl ? `
<p style="text-align:center;margin:28px 0;">
<a href="${joinUrl}"
style="display:inline-block;background:#cba6f7;color:#1e1e2e;padding:12px 32px;border-radius:8px;text-decoration:none;font-weight:bold;">
${t(lang, 'email.calendarEventInvite.joinButton')}
</a>
</p>
<p style="font-size:13px;color:#7f849c;">
${t(lang, 'email.linkHint')}<br/>
<a href="${joinUrl}" style="color:#89b4fa;word-break:break-all;">${escapeHtml(joinUrl)}</a>
</p>` : ''}
<p style="font-size:13px;color:#7f849c;">${t(lang, 'email.calendarEventInvite.icsHint')}</p>
<hr style="border:none;border-top:1px solid #313244;margin:24px 0;"/>
<p style="font-size:12px;color:#585b70;">${t(lang, 'email.calendarEventInvite.footer', { appName: escapeHtml(appName) })}</p>
</div>
`,
text: `${t(lang, 'email.calendarEventInvite.intro', { fromUser })}\n${title}\n${formatDate(startTime)} ${formatDate(endTime)}${description ? `\n\n"${description}"` : ''}${joinUrl ? `\n\n${t(lang, 'email.calendarEventInvite.joinButton')}: ${joinUrl}` : ''}\n\n${t(lang, 'email.calendarEventInvite.icsHint')}\n\n ${appName}`,
attachments: [
{
filename: 'event.ics',
content: ics,
contentType: 'text/calendar; charset=utf-8; method=PUBLISH',
},
],
});
}
/** /**
* Notify a user that a federated calendar event they received was deleted by the organiser. * Notify a user that a federated calendar event they received was deleted by the organiser.
*/ */
+71
View File
@@ -0,0 +1,71 @@
import { log } from './logger.js';
/**
* Recording transcription / AI summarization integration.
*
* When the per-room "recording transcript" setting is enabled, Redlight POSTs
* to ${TRANSCRIPTION_API_URL}/prompt with header `X-Api-Key: ${TRANSCRIPTION_API_KEY}`
* as soon as the "video" format of a recording becomes available (delivered via
* BBB's recording-ready callback). Leave both env vars empty to disable the
* integration entirely.
*/
const TRANSCRIPTION_API_URL = process.env.TRANSCRIPTION_API_URL || '';
const TRANSCRIPTION_API_KEY = process.env.TRANSCRIPTION_API_KEY || '';
const DEFAULT_PROMPT = 'Summarise the key decisions made in this meeting.';
export function isTranscriptionEnabled() {
return !!(TRANSCRIPTION_API_URL && TRANSCRIPTION_API_KEY);
}
/**
* Request a summary/transcript for a recording. Never throws — failures are
* logged and reported via the boolean return value.
*
* @param {object} opts
* @param {string} opts.meetingId Room UID / BBB meeting ID
* @param {string} opts.recordingId BBB record ID
* @param {string} [opts.prompt] Optional custom prompt
* @returns {Promise<boolean>} true if the request was accepted
*/
export async function requestTranscription({ meetingId, recordingId, prompt }) {
if (!isTranscriptionEnabled()) {
log.server.warn('Transcription request skipped: TRANSCRIPTION_API_URL or TRANSCRIPTION_API_KEY is not configured');
return false;
}
const base = TRANSCRIPTION_API_URL.endsWith('/') ? TRANSCRIPTION_API_URL : `${TRANSCRIPTION_API_URL}/`;
const url = new URL('prompt', base).toString();
try {
const response = await fetch(url, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'X-Api-Key': TRANSCRIPTION_API_KEY,
},
body: JSON.stringify({
prompt: prompt || DEFAULT_PROMPT,
meeting_id: meetingId,
recording_id: recordingId,
}),
signal: AbortSignal.timeout(15_000),
});
if (!response.ok) {
const body = await response.text().catch(() => '');
log.server.error(`Transcription request failed: status=${response.status} body=${body.slice(0, 200)}`);
return false;
}
log.server.info(`Transcription requested for recording ${recordingId} (meeting: ${meetingId})`);
return true;
} catch (err) {
// undici wraps the real network error (ECONNREFUSED, ENOTFOUND, timeout, …)
// in err.cause — surface it, "fetch failed" alone is undiagnosable.
const cause = err.cause ? ` (${err.cause.code || ''} ${err.cause.message || ''})`.trimEnd() : '';
log.server.error(`Transcription request to ${url} failed: ${err.message}${cause}`);
return false;
}
}
+15
View File
@@ -11,6 +11,13 @@
"validity": "Dieser Link ist 24 Stunden gültig.", "validity": "Dieser Link ist 24 Stunden gültig.",
"footer": "Falls du dich nicht registriert hast, kannst du diese E-Mail ignorieren." "footer": "Falls du dich nicht registriert hast, kannst du diese E-Mail ignorieren."
}, },
"resetPassword": {
"subject": "{appName} - Passwort zurücksetzen",
"intro": "Du hast angefordert, dein Passwort zurückzusetzen. Klicke auf den Button, um ein neues Passwort festzulegen:",
"button": "Passwort zurücksetzen",
"validity": "Dieser Link ist 1 Stunde gültig.",
"footer": "Falls du das nicht angefordert hast, kannst du diese E-Mail ignorieren dein Passwort bleibt unverändert."
},
"invite": { "invite": {
"subject": "{appName} - Du wurdest eingeladen", "subject": "{appName} - Du wurdest eingeladen",
"title": "Du wurdest eingeladen", "title": "Du wurdest eingeladen",
@@ -36,6 +43,14 @@
"subject": "{appName} - Kalendereinladung von {fromUser}", "subject": "{appName} - Kalendereinladung von {fromUser}",
"intro": "Du hast eine Kalendereinladung von {fromUser} erhalten." "intro": "Du hast eine Kalendereinladung von {fromUser} erhalten."
}, },
"calendarEventInvite": {
"subject": "{appName} - Kalendereinladung: {title}",
"title": "Kalendereinladung",
"intro": "{fromUser} hat dich zu folgendem Termin eingeladen:",
"joinButton": "Meeting beitreten",
"icsHint": "Mit der angehängten .ics-Datei kannst du den Termin zu deinem Kalender hinzufügen.",
"footer": "Diese Einladung wurde über {appName} versendet."
},
"calendarDeleted": { "calendarDeleted": {
"subject": "{appName} - Kalendereintrag abgesagt: {title}", "subject": "{appName} - Kalendereintrag abgesagt: {title}",
"intro": "Der folgende Kalendereintrag wurde vom Organisator ({fromUser}) gelöscht und ist nicht mehr verfügbar:", "intro": "Der folgende Kalendereintrag wurde vom Organisator ({fromUser}) gelöscht und ist nicht mehr verfügbar:",
+15
View File
@@ -11,6 +11,13 @@
"validity": "This link is valid for 24 hours.", "validity": "This link is valid for 24 hours.",
"footer": "If you didn't register, please ignore this email." "footer": "If you didn't register, please ignore this email."
}, },
"resetPassword": {
"subject": "{appName} - Reset your password",
"intro": "You requested to reset your password. Click the button below to set a new one:",
"button": "Reset Password",
"validity": "This link is valid for 1 hour.",
"footer": "If you didn't request this, you can safely ignore this email — your password will remain unchanged."
},
"invite": { "invite": {
"subject": "{appName} - You've been invited", "subject": "{appName} - You've been invited",
"title": "You have been invited", "title": "You have been invited",
@@ -36,6 +43,14 @@
"subject": "{appName} - Calendar invitation from {fromUser}", "subject": "{appName} - Calendar invitation from {fromUser}",
"intro": "You have received a calendar invitation from {fromUser}." "intro": "You have received a calendar invitation from {fromUser}."
}, },
"calendarEventInvite": {
"subject": "{appName} - Calendar invitation: {title}",
"title": "Calendar Invitation",
"intro": "{fromUser} has invited you to the following event:",
"joinButton": "Join Meeting",
"icsHint": "You can add this event to your calendar using the attached .ics file.",
"footer": "This invitation was sent via {appName}."
},
"calendarDeleted": { "calendarDeleted": {
"subject": "{appName} - Calendar event cancelled: {title}", "subject": "{appName} - Calendar event cancelled: {title}",
"intro": "The following calendar event was deleted by the organiser ({fromUser}) and is no longer available:", "intro": "The following calendar event was deleted by the organiser ({fromUser}) and is no longer available:",
+16 -18
View File
@@ -1,6 +1,6 @@
import { Router, json } from 'express'; import { Router, json } from 'express';
import crypto from 'crypto'; import crypto from 'crypto';
import ExcelJS from 'exceljs'; import writeXlsxFile from 'write-excel-file/node';
import PDFDocument from 'pdfkit'; import PDFDocument from 'pdfkit';
import { getDb } from '../config/database.js'; import { getDb } from '../config/database.js';
import { authenticateToken } from '../middleware/auth.js'; import { authenticateToken } from '../middleware/auth.js';
@@ -246,26 +246,24 @@ router.get('/:id/export/:format', authenticateToken, async (req, res) => {
if (format === 'xlsx') { if (format === 'xlsx') {
// Prefix-escape strings that would otherwise be evaluated as formulas. // Prefix-escape strings that would otherwise be evaluated as formulas.
const sanitizeXlsx = (r) => { const sanitizeXlsx = (v) =>
const out = {}; (typeof v === 'string' && /^[=+\-@\t\r]/.test(v)) ? "'" + v : v;
for (const k of Object.keys(r)) {
const v = r[k]; const headerRow = COLUMNS.map(c => ({
out[k] = (typeof v === 'string' && /^[=+\-@\t\r]/.test(v)) ? "'" + v : v; value: c.header,
} fontWeight: 'bold',
return out; backgroundColor: '#e0e0e0',
}; }));
const workbook = new ExcelJS.Workbook(); const dataRows = rows.map(r => COLUMNS.map(c => ({ value: sanitizeXlsx(r[c.key]) })));
const sheet = workbook.addWorksheet('Analytics');
sheet.columns = COLUMNS; const buffer = await writeXlsxFile([headerRow, ...dataRows], {
rows.forEach(r => sheet.addRow(sanitizeXlsx(r))); columns: COLUMNS.map(c => ({ width: c.width })),
// Style header row sheet: 'Analytics',
sheet.getRow(1).font = { bold: true }; }).toBuffer();
sheet.getRow(1).fill = { type: 'pattern', pattern: 'solid', fgColor: { argb: 'FFE0E0E0' } };
res.setHeader('Content-Type', 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet'); res.setHeader('Content-Type', 'application/vnd.openxmlformats-officedocument.spreadsheetml.sheet');
res.setHeader('Content-Disposition', `attachment; filename="${safeName}.xlsx"`); res.setHeader('Content-Disposition', `attachment; filename="${safeName}.xlsx"`);
await workbook.xlsx.write(res); return res.send(buffer);
return res.end();
} }
if (format === 'pdf') { if (format === 'pdf') {
+131 -1
View File
@@ -2,6 +2,7 @@ import { Router } from 'express';
import bcrypt from 'bcryptjs'; import bcrypt from 'bcryptjs';
import jwt from 'jsonwebtoken'; import jwt from 'jsonwebtoken';
import { v4 as uuidv4 } from 'uuid'; import { v4 as uuidv4 } from 'uuid';
import crypto from 'crypto';
import fs from 'fs'; import fs from 'fs';
import path from 'path'; import path from 'path';
import { fileURLToPath } from 'url'; import { fileURLToPath } from 'url';
@@ -11,7 +12,7 @@ import * as OTPAuth from 'otpauth';
import { getDb } from '../config/database.js'; import { getDb } from '../config/database.js';
import redis from '../config/redis.js'; import redis from '../config/redis.js';
import { authenticateToken, generateToken, getBaseUrl } from '../middleware/auth.js'; import { authenticateToken, generateToken, getBaseUrl } from '../middleware/auth.js';
import { isMailerConfigured, sendVerificationEmail } from '../config/mailer.js'; import { isMailerConfigured, sendVerificationEmail, sendPasswordResetEmail } from '../config/mailer.js';
import { getOAuthConfig, discoverOIDC } from '../config/oauth.js'; import { getOAuthConfig, discoverOIDC } from '../config/oauth.js';
import { getAppName } from '../config/appName.js'; import { getAppName } from '../config/appName.js';
import { log } from '../config/logger.js'; import { log } from '../config/logger.js';
@@ -167,6 +168,26 @@ const twoFaLimiter = rateLimit({
store: makeRedisStore('rl:2fa:'), store: makeRedisStore('rl:2fa:'),
}); });
// Rate limit forgot-password to prevent SMTP abuse / email enumeration spam
const forgotPasswordLimiter = rateLimit({
windowMs: 15 * 60 * 1000, // 15 minutes
max: 5,
standardHeaders: true,
legacyHeaders: false,
message: { error: 'Too many requests. Please try again later.' },
store: makeRedisStore('rl:forgot:'),
});
// Rate limit reset-password submissions to slow token brute-forcing
const resetPasswordLimiter = rateLimit({
windowMs: 15 * 60 * 1000, // 15 minutes
max: 10,
standardHeaders: true,
legacyHeaders: false,
message: { error: 'Too many attempts. Please try again later.' },
store: makeRedisStore('rl:reset:'),
});
const __filename = fileURLToPath(import.meta.url); const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename); const __dirname = path.dirname(__filename);
const uploadsDir = path.join(__dirname, '..', '..', 'uploads', 'avatars'); const uploadsDir = path.join(__dirname, '..', '..', 'uploads', 'avatars');
@@ -391,6 +412,115 @@ router.post('/resend-verification', resendVerificationLimiter, async (req, res)
} }
}); });
// Hash a reset token for storage/lookup (never store the raw token)
function hashResetToken(token) {
return crypto.createHash('sha256').update(token).digest('hex');
}
// POST /api/auth/forgot-password
router.post('/forgot-password', forgotPasswordLimiter, async (req, res) => {
try {
const { email } = req.body;
if (!email || typeof email !== 'string' || !EMAIL_RE.test(email)) {
return res.status(400).json({ error: 'A valid email address is required' });
}
// Generic response used in every branch so we never reveal whether an
// account exists, whether it uses SSO, or whether SMTP is configured.
const genericResponse = { message: 'If an account exists for that address, a password reset email has been sent.' };
if (!isMailerConfigured()) {
return res.json(genericResponse);
}
const db = getDb();
const user = await db.get('SELECT id, name, display_name, email, language, oauth_provider, reset_requested_at FROM users WHERE email = ?', [email.toLowerCase()]);
// No account, or an SSO-only account that has no local password to reset
if (!user || user.oauth_provider) {
return res.json(genericResponse);
}
// Server-side 60s throttle per account to limit repeated emails
if (user.reset_requested_at) {
const secondsAgo = (Date.now() - new Date(user.reset_requested_at).getTime()) / 1000;
if (secondsAgo < 60) {
return res.json(genericResponse);
}
}
const resetToken = uuidv4();
const tokenHash = hashResetToken(resetToken);
const expires = new Date(Date.now() + 60 * 60 * 1000).toISOString(); // 1 hour
const now = new Date().toISOString();
await db.run(
'UPDATE users SET reset_token_hash = ?, reset_token_expires = ?, reset_requested_at = ?, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
[tokenHash, expires, now, user.id]
);
const baseUrl = getBaseUrl(req);
const resetUrl = `${baseUrl}/reset-password?token=${resetToken}`;
const appName = await getAppName();
try {
await sendPasswordResetEmail(email.toLowerCase(), user.display_name || user.name, resetUrl, appName, user.language || 'en');
} catch (mailErr) {
log.auth.error(`Password reset mail failed: ${mailErr.message}`);
// Still return generic success — don't leak SMTP state to the client
}
res.json(genericResponse);
} catch (err) {
log.auth.error(`Forgot password error: ${err.message}`);
res.status(500).json({ error: 'Internal server error' });
}
});
// POST /api/auth/reset-password
router.post('/reset-password', resetPasswordLimiter, async (req, res) => {
try {
const { token, password } = req.body;
if (!token || typeof token !== 'string') {
return res.status(400).json({ error: 'Invalid or expired reset link.' });
}
if (!password || typeof password !== 'string') {
return res.status(400).json({ error: 'A new password is required' });
}
if (password.length < MIN_PASSWORD_LENGTH) {
return res.status(400).json({ error: `Password must be at least ${MIN_PASSWORD_LENGTH} characters long` });
}
if (password.length > MAX_PASSWORD_LENGTH) {
return res.status(400).json({ error: `Password must not exceed ${MAX_PASSWORD_LENGTH} characters` });
}
const db = getDb();
const tokenHash = hashResetToken(token);
const user = await db.get('SELECT id, reset_token_expires FROM users WHERE reset_token_hash = ?', [tokenHash]);
if (!user) {
return res.status(400).json({ error: 'Invalid or expired reset link.' });
}
if (!user.reset_token_expires || new Date(user.reset_token_expires) < new Date()) {
return res.status(400).json({ error: 'Invalid or expired reset link.' });
}
const hash = await bcrypt.hash(password, 12);
// Set the new password, verify the email (proves mailbox ownership), and
// clear the reset token so it can't be reused.
await db.run(
'UPDATE users SET password_hash = ?, email_verified = 1, reset_token_hash = NULL, reset_token_expires = NULL, reset_requested_at = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
[hash, user.id]
);
res.json({ message: 'Password has been reset successfully. You can now sign in.' });
} catch (err) {
log.auth.error(`Reset password error: ${err.message}`);
res.status(500).json({ error: 'Password could not be reset' });
}
});
// POST /api/auth/login // POST /api/auth/login
router.post('/login', loginLimiter, async (req, res) => { router.post('/login', loginLimiter, async (req, res) => {
try { try {
+2
View File
@@ -7,6 +7,7 @@ import { getDb } from '../config/database.js';
import { authenticateToken, requireAdmin } from '../middleware/auth.js'; import { authenticateToken, requireAdmin } from '../middleware/auth.js';
import { log } from '../config/logger.js'; import { log } from '../config/logger.js';
import { getOAuthConfig } from '../config/oauth.js'; import { getOAuthConfig } from '../config/oauth.js';
import { isTranscriptionEnabled } from '../config/transcription.js';
const __filename = fileURLToPath(import.meta.url); const __filename = fileURLToPath(import.meta.url);
const __dirname = path.dirname(__filename); const __dirname = path.dirname(__filename);
@@ -121,6 +122,7 @@ router.get('/', async (req, res) => {
oauthEnabled, oauthEnabled,
oauthDisplayName, oauthDisplayName,
hideAppName: hideAppName === 'true', hideAppName: hideAppName === 'true',
transcriptionEnabled: isTranscriptionEnabled(),
}); });
} catch (err) { } catch (err) {
log.branding.error('Get branding error:', err); log.branding.error('Get branding error:', err);
+74 -1
View File
@@ -3,7 +3,7 @@ import crypto from 'crypto';
import { getDb } from '../config/database.js'; import { getDb } from '../config/database.js';
import { authenticateToken, getBaseUrl } from '../middleware/auth.js'; import { authenticateToken, getBaseUrl } from '../middleware/auth.js';
import { log } from '../config/logger.js'; import { log } from '../config/logger.js';
import { sendCalendarInviteEmail } from '../config/mailer.js'; import { sendCalendarInviteEmail, sendCalendarEventEmail } from '../config/mailer.js';
import { getAppName } from '../config/appName.js'; import { getAppName } from '../config/appName.js';
import { import {
isFederationEnabled, isFederationEnabled,
@@ -23,6 +23,16 @@ const SAFE_COLOR_RE = /^(?:#[0-9a-fA-F]{3,8}|hsl\(\d{1,3},\s*\d{1,3}%,\s*\d{1,3}
// Allowed reminder intervals in minutes // Allowed reminder intervals in minutes
const VALID_REMINDERS = new Set([5, 15, 30, 60, 120, 1440]); const VALID_REMINDERS = new Set([5, 15, 30, 60, 120, 1440]);
// Rate limit email invitations: each request may carry up to 50 addresses, so
// without a cap any registered account could be abused as an SMTP spam relay.
const calendarEmailInviteLimiter = rateLimit({
windowMs: 60 * 60 * 1000, // 1 hour
max: 10,
standardHeaders: true,
legacyHeaders: false,
message: { error: 'Too many email invitations. Please try again later.' },
});
// Rate limit for federation calendar receive // Rate limit for federation calendar receive
const calendarFederationLimiter = rateLimit({ const calendarFederationLimiter = rateLimit({
windowMs: 15 * 60 * 1000, windowMs: 15 * 60 * 1000,
@@ -581,6 +591,69 @@ router.post('/events/:id/federation', authenticateToken, async (req, res) => {
} }
}); });
// ── POST /api/calendar/events/:id/email — Send event invitation by email ────
router.post('/events/:id/email', authenticateToken, calendarEmailInviteLimiter, async (req, res) => {
try {
const { emails } = req.body;
if (!emails || !Array.isArray(emails) || !emails.length) {
return res.status(400).json({ error: 'At least one email address is required' });
}
if (emails.length > 50) {
return res.status(400).json({ error: 'Maximum 50 email addresses allowed' });
}
const emailRegex = /^[^\s@]+@[^\s@]+\.[^\s@]+$/;
for (const email of emails) {
if (typeof email !== 'string' || !emailRegex.test(email) || email.length > 254) {
return res.status(400).json({ error: `Invalid email address: ${email}` });
}
}
const db = getDb();
const event = await db.get(`
SELECT ce.*, COALESCE(NULLIF(u.display_name,''), u.name) as organizer_name, u.email as organizer_email
FROM calendar_events ce
JOIN users u ON ce.user_id = u.id
WHERE ce.id = ? AND ce.user_id = ?
`, [req.params.id, req.user.id]);
if (!event) return res.status(404).json({ error: 'Event not found or no permission' });
const baseUrl = getBaseUrl(req);
let joinUrl = null;
if (event.room_uid) {
joinUrl = `${baseUrl}/join/${event.room_uid}`;
}
const ics = generateICS(event, joinUrl || '', baseUrl);
const appName = await getAppName();
const fromUser = req.user.display_name || req.user.name;
const lang = req.user.language || 'en';
// Send emails (in parallel but collect errors)
const results = await Promise.allSettled(
emails.map(email =>
sendCalendarEventEmail(
email, fromUser, event.title, event.start_time, event.end_time,
event.description, joinUrl, ics, appName, lang
)
)
);
const failed = results.filter(r => r.status === 'rejected');
if (failed.length === emails.length) {
return res.status(500).json({ error: 'Failed to send all email invitations' });
}
if (failed.length > 0) {
log.server.warn(`${failed.length}/${emails.length} calendar email invitations failed`);
}
res.json({ success: true, sent: emails.length - failed.length, failed: failed.length });
} catch (err) {
log.server.error(`Calendar email invite error: ${err.message}`);
res.status(500).json({ error: err.message || 'Failed to send email invitations' });
}
});
// ── POST /receive-event or /calendar-event — Receive calendar event from remote ── // ── POST /receive-event or /calendar-event — Receive calendar event from remote ──
// '/receive-event' when mounted at /api/calendar // '/receive-event' when mounted at /api/calendar
// '/calendar-event' when mounted at /api/federation (for remote instance discovery) // '/calendar-event' when mounted at /api/federation (for remote instance discovery)
+1 -1
View File
@@ -41,7 +41,7 @@ export function wellKnownHandler(req, res) {
federation_api: '/api/federation', federation_api: '/api/federation',
public_key: getPublicKey(), public_key: getPublicKey(),
software: 'Redlight', software: 'Redlight',
version: '2.3.0', version: '2.5.0',
}); });
} }
+64 -1
View File
@@ -1,7 +1,9 @@
import { Router } from 'express'; import { Router, urlencoded } from 'express';
import jwt from 'jsonwebtoken';
import { authenticateToken } from '../middleware/auth.js'; import { authenticateToken } from '../middleware/auth.js';
import { getDb } from '../config/database.js'; import { getDb } from '../config/database.js';
import { log } from '../config/logger.js'; import { log } from '../config/logger.js';
import { isTranscriptionEnabled, requestTranscription } from '../config/transcription.js';
import { import {
getRecordings, getRecordings,
getRecordingByRecordId, getRecordingByRecordId,
@@ -9,6 +11,8 @@ import {
publishRecording, publishRecording,
} from '../config/bbb.js'; } from '../config/bbb.js';
const BBB_SECRET = process.env.BBB_SECRET || '';
const router = Router(); const router = Router();
/** /**
@@ -176,6 +180,65 @@ async function fetchAndSyncRecordings(meetingID, fallbackName) {
} }
} }
// POST /api/recordings/recording-ready - BBB recording-ready callback (unauthenticated)
// BBB posts `signed_parameters`, a JWT signed with the shared BBB secret.
// Fires once per playback format; the transcription request is only sent when
// the "video" format first becomes available and the room has the setting on.
router.post('/recording-ready', urlencoded({ extended: false }), async (req, res) => {
try {
const signed = req.body?.signed_parameters;
if (!signed || typeof signed !== 'string') {
return res.status(400).json({ error: 'signed_parameters is required' });
}
let payload;
try {
payload = jwt.verify(signed, BBB_SECRET, { algorithms: ['HS256'] });
} catch {
return res.status(403).json({ error: 'Invalid signature' });
}
const recordId = payload.record_id;
const meetingId = payload.meeting_id;
if (!recordId || !meetingId) {
return res.status(400).json({ error: 'record_id and meeting_id are required' });
}
// Always answer 200 from here on so BBB does not keep retrying —
// "nothing to do" is a valid outcome for this callback.
const db = getDb();
const room = await db.get('SELECT id, uid, name, recording_transcript FROM rooms WHERE uid = ?', [meetingId]);
if (!room || !room.recording_transcript || !isTranscriptionEnabled()) {
return res.json({});
}
const rec = await getRecordingByRecordId(recordId).catch(() => null);
if (!rec) return res.json({});
const formatted = formatBbbRecording(rec, room.name);
const hasVideo = formatted.formats.some(f => f.type === 'video');
// Cache the recording so the dedupe marker below has a row to live on
await upsertRecording(db, formatted);
if (!hasVideo) return res.json({});
// Dedupe: BBB fires the callback once per format
const cached = await db.get('SELECT transcript_requested_at FROM recordings WHERE record_id = ?', [recordId]);
if (cached?.transcript_requested_at) return res.json({});
const ok = await requestTranscription({ meetingId, recordingId: recordId });
if (ok) {
await db.run('UPDATE recordings SET transcript_requested_at = CURRENT_TIMESTAMP WHERE record_id = ?', [recordId]);
}
res.json({});
} catch (err) {
log.recordings.error(`Recording-ready callback error: ${err.message}`);
res.status(500).json({ error: 'Error processing recording-ready callback' });
}
});
// GET /api/recordings - Get recordings for a room (by meetingID/uid) // GET /api/recordings - Get recordings for a room (by meetingID/uid)
router.get('/', authenticateToken, async (req, res) => { router.get('/', authenticateToken, async (req, res) => {
try { try {
+11 -2
View File
@@ -193,6 +193,7 @@ router.post('/', authenticateToken, async (req, res) => {
record_meeting, record_meeting,
guest_access, guest_access,
moderator_code, moderator_code,
recording_transcript,
} = req.body; } = req.body;
if (!name || name.trim().length === 0) { if (!name || name.trim().length === 0) {
@@ -227,8 +228,8 @@ router.post('/', authenticateToken, async (req, res) => {
const db = getDb(); const db = getDb();
const result = await db.run(` const result = await db.run(`
INSERT INTO rooms (uid, name, user_id, welcome_message, max_participants, access_code, mute_on_join, require_approval, anyone_can_start, all_join_moderator, record_meeting, guest_access, moderator_code) INSERT INTO rooms (uid, name, user_id, welcome_message, max_participants, access_code, mute_on_join, require_approval, anyone_can_start, all_join_moderator, record_meeting, guest_access, moderator_code, recording_transcript)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, [ `, [
uid, uid,
name.trim(), name.trim(),
@@ -243,6 +244,8 @@ router.post('/', authenticateToken, async (req, res) => {
record_meeting !== false ? 1 : 0, record_meeting !== false ? 1 : 0,
guest_access ? 1 : 0, guest_access ? 1 : 0,
moderator_code || null, moderator_code || null,
// Transcription/AI summary requires recording to be enabled
(record_meeting !== false && recording_transcript) ? 1 : 0,
]); ]);
const room = await db.get('SELECT * FROM rooms WHERE id = ?', [result.lastInsertRowid]); const room = await db.get('SELECT * FROM rooms WHERE id = ?', [result.lastInsertRowid]);
@@ -277,6 +280,7 @@ router.put('/:uid', authenticateToken, async (req, res) => {
moderator_code, moderator_code,
learning_analytics, learning_analytics,
analytics_visibility, analytics_visibility,
recording_transcript,
} = req.body; } = req.body;
// M12: field length limits (same as create) // M12: field length limits (same as create)
@@ -303,6 +307,9 @@ router.put('/:uid', authenticateToken, async (req, res) => {
} }
} }
// Transcription/AI summary requires recording — force it off when recording ends up disabled
const effectiveRecordMeeting = record_meeting !== undefined ? !!record_meeting : !!room.record_meeting;
await db.run(` await db.run(`
UPDATE rooms SET UPDATE rooms SET
name = COALESCE(?, name), name = COALESCE(?, name),
@@ -318,6 +325,7 @@ router.put('/:uid', authenticateToken, async (req, res) => {
moderator_code = ?, moderator_code = ?,
learning_analytics = COALESCE(?, learning_analytics), learning_analytics = COALESCE(?, learning_analytics),
analytics_visibility = COALESCE(?, analytics_visibility), analytics_visibility = COALESCE(?, analytics_visibility),
recording_transcript = COALESCE(?, recording_transcript),
updated_at = CURRENT_TIMESTAMP updated_at = CURRENT_TIMESTAMP
WHERE uid = ? WHERE uid = ?
`, [ `, [
@@ -334,6 +342,7 @@ router.put('/:uid', authenticateToken, async (req, res) => {
moderator_code !== undefined ? (moderator_code || null) : room.moderator_code, moderator_code !== undefined ? (moderator_code || null) : room.moderator_code,
learning_analytics !== undefined ? (learning_analytics ? 1 : 0) : null, learning_analytics !== undefined ? (learning_analytics ? 1 : 0) : null,
analytics_visibility && ['owner', 'shared'].includes(analytics_visibility) ? analytics_visibility : null, analytics_visibility && ['owner', 'shared'].includes(analytics_visibility) ? analytics_visibility : null,
!effectiveRecordMeeting ? 0 : (recording_transcript !== undefined ? (recording_transcript ? 1 : 0) : null),
req.params.uid, req.params.uid,
]); ]);
+4
View File
@@ -9,6 +9,8 @@ import Home from './pages/Home';
import Login from './pages/Login'; import Login from './pages/Login';
import Register from './pages/Register'; import Register from './pages/Register';
import VerifyEmail from './pages/VerifyEmail'; import VerifyEmail from './pages/VerifyEmail';
import ForgotPassword from './pages/ForgotPassword';
import ResetPassword from './pages/ResetPassword';
import Dashboard from './pages/Dashboard'; import Dashboard from './pages/Dashboard';
import RoomDetail from './pages/RoomDetail'; import RoomDetail from './pages/RoomDetail';
import Settings from './pages/Settings'; import Settings from './pages/Settings';
@@ -52,6 +54,8 @@ export default function App() {
<Route path="/login" element={user ? <Navigate to="/dashboard" /> : <Login />} /> <Route path="/login" element={user ? <Navigate to="/dashboard" /> : <Login />} />
<Route path="/register" element={user ? <Navigate to="/dashboard" /> : <Register />} /> <Route path="/register" element={user ? <Navigate to="/dashboard" /> : <Register />} />
<Route path="/verify-email" element={<VerifyEmail />} /> <Route path="/verify-email" element={<VerifyEmail />} />
<Route path="/forgot-password" element={user ? <Navigate to="/dashboard" /> : <ForgotPassword />} />
<Route path="/reset-password" element={<ResetPassword />} />
<Route path="/oauth/callback" element={<OAuthCallback />} /> <Route path="/oauth/callback" element={<OAuthCallback />} />
<Route path="/join/:uid" element={<GuestJoin />} /> <Route path="/join/:uid" element={<GuestJoin />} />
+4 -4
View File
@@ -42,10 +42,10 @@ export default function Modal({ title, children, onClose, maxWidth = 'max-w-lg'
aria-modal="true" aria-modal="true"
aria-labelledby={titleId} aria-labelledby={titleId}
tabIndex={-1} tabIndex={-1}
className={`relative bg-th-card rounded-2xl border border-th-border shadow-2xl w-full ${maxWidth} focus:outline-hidden`} className={`relative bg-th-card rounded-2xl border border-th-border shadow-2xl w-full ${maxWidth} max-h-[calc(100vh-2rem)] flex flex-col focus:outline-hidden`}
> >
{/* Header */} {/* Header */}
<div className="flex items-center justify-between px-6 py-4 border-b border-th-border rounded-t-2xl"> <div className="flex items-center justify-between px-6 py-4 border-b border-th-border rounded-t-2xl shrink-0">
<h2 id={titleId} className="text-lg font-semibold text-th-text">{title}</h2> <h2 id={titleId} className="text-lg font-semibold text-th-text">{title}</h2>
<button <button
type="button" type="button"
@@ -56,8 +56,8 @@ export default function Modal({ title, children, onClose, maxWidth = 'max-w-lg'
<X size={20} /> <X size={20} />
</button> </button>
</div> </div>
{/* Body */} {/* Body — scrolls inside the card instead of overflowing the viewport */}
<div className="p-6"> <div className="p-6 overflow-y-auto min-h-0">
{children} {children}
</div> </div>
</div> </div>
+22 -3
View File
@@ -102,6 +102,22 @@
"oauthNoToken": "Kein Authentifizierungstoken erhalten.", "oauthNoToken": "Kein Authentifizierungstoken erhalten.",
"oauthLoginFailed": "Anmeldung konnte nicht abgeschlossen werden. Bitte versuche es erneut.", "oauthLoginFailed": "Anmeldung konnte nicht abgeschlossen werden. Bitte versuche es erneut.",
"oauthRedirecting": "Du wirst angemeldet...", "oauthRedirecting": "Du wirst angemeldet...",
"forgotPassword": "Passwort vergessen?",
"forgotPasswordTitle": "Passwort zurücksetzen",
"forgotPasswordSubtitle": "Gib deine E-Mail-Adresse ein. Wir senden dir einen Link zum Zurücksetzen deines Passworts.",
"forgotPasswordSubmit": "Link senden",
"forgotPasswordSent": "Wenn ein Konto für diese Adresse existiert, haben wir dir eine E-Mail zum Zurücksetzen des Passworts gesendet.",
"forgotPasswordSentTitle": "Prüfe dein Postfach",
"forgotPasswordFailed": "Anfrage konnte nicht gesendet werden. Bitte versuche es erneut.",
"resetPasswordTitle": "Neues Passwort festlegen",
"resetPasswordSubtitle": "Wähle ein neues Passwort für dein Konto.",
"newPassword": "Neues Passwort",
"resetPasswordSubmit": "Passwort zurücksetzen",
"resetPasswordSuccess": "Dein Passwort wurde zurückgesetzt. Du kannst dich jetzt anmelden.",
"resetPasswordSuccessTitle": "Passwort zurückgesetzt",
"resetPasswordFailed": "Passwort konnte nicht zurückgesetzt werden.",
"resetTokenMissing": "Kein Token zum Zurücksetzen vorhanden.",
"passwordMinLength": "Passwort muss mindestens 8 Zeichen lang sein",
"2fa": { "2fa": {
"title": "Zwei-Faktor-Authentifizierung", "title": "Zwei-Faktor-Authentifizierung",
"prompt": "Gib den 6-stelligen Code aus deiner Authenticator-App ein.", "prompt": "Gib den 6-stelligen Code aus deiner Authenticator-App ein.",
@@ -193,6 +209,7 @@
"anyoneCanStart": "Jeder kann das Meeting starten", "anyoneCanStart": "Jeder kann das Meeting starten",
"allJoinModerator": "Alle Teilnehmer als Moderator", "allJoinModerator": "Alle Teilnehmer als Moderator",
"allowRecording": "Aufnahme erlauben", "allowRecording": "Aufnahme erlauben",
"enableTranscript": "KI-Zusammenfassung / Transkript für Aufnahmen",
"noAccessCode": "Kein Zugangscode", "noAccessCode": "Kein Zugangscode",
"emptyNoCode": "Leer = kein Code", "emptyNoCode": "Leer = kein Code",
"settingsSaved": "Einstellungen gespeichert", "settingsSaved": "Einstellungen gespeichert",
@@ -627,9 +644,11 @@
"invitationPending": "Einladung ausstehend", "invitationPending": "Einladung ausstehend",
"pendingInvitations": "Ausstehende Einladungen", "pendingInvitations": "Ausstehende Einladungen",
"accepted": "Angenommen", "accepted": "Angenommen",
"sendFederated": "An Remote senden", "sendFederated": "Remote einladen",
"sendFederatedTitle": "Event an Remote-Instanz senden", "sendFederatedTitle": "Termin-Einladung senden",
"sendFederatedDesc": "Sende dieses Kalender-Event an einen Benutzer auf einer anderen Redlight-Instanz. Der Empfänger muss die Einladung zuerst annehmen, bevor das Event in seinem Kalender erscheint.", "sendFederatedDesc": "Sende dieses Kalender-Event an einen Benutzer auf einer anderen Redlight-Instanz oder an eine beliebige E-Mail-Adresse. Remote-Empfänger müssen die Einladung zuerst annehmen, bevor das Event in ihrem Kalender erscheint; E-Mail-Empfänger erhalten die Termindetails mit einer .ics-Datei im Anhang.",
"inviteSection": "Einladungen versenden (optional)",
"inviteSectionHint": "Lade Personen per E-Mail ein oder sende das Event an einen Benutzer auf einer anderen Redlight-Instanz.",
"send": "Senden", "send": "Senden",
"fedSent": "Kalendereinladung gesendet! Der Empfänger muss diese zuerst annehmen.", "fedSent": "Kalendereinladung gesendet! Der Empfänger muss diese zuerst annehmen.",
"fedFailed": "Event konnte nicht an Remote-Instanz gesendet werden", "fedFailed": "Event konnte nicht an Remote-Instanz gesendet werden",
+22 -3
View File
@@ -102,6 +102,22 @@
"oauthNoToken": "No authentication token received.", "oauthNoToken": "No authentication token received.",
"oauthLoginFailed": "Could not complete sign in. Please try again.", "oauthLoginFailed": "Could not complete sign in. Please try again.",
"oauthRedirecting": "Signing you in...", "oauthRedirecting": "Signing you in...",
"forgotPassword": "Forgot password?",
"forgotPasswordTitle": "Reset your password",
"forgotPasswordSubtitle": "Enter your email address and we'll send you a link to reset your password.",
"forgotPasswordSubmit": "Send link",
"forgotPasswordSent": "If an account exists for that address, we've sent you a password reset email.",
"forgotPasswordSentTitle": "Check your inbox",
"forgotPasswordFailed": "Could not send the request. Please try again.",
"resetPasswordTitle": "Set a new password",
"resetPasswordSubtitle": "Choose a new password for your account.",
"newPassword": "New password",
"resetPasswordSubmit": "Reset password",
"resetPasswordSuccess": "Your password has been reset. You can now sign in.",
"resetPasswordSuccessTitle": "Password reset",
"resetPasswordFailed": "Could not reset password.",
"resetTokenMissing": "No reset token provided.",
"passwordMinLength": "Password must be at least 8 characters",
"2fa": { "2fa": {
"title": "Two-Factor Authentication", "title": "Two-Factor Authentication",
"prompt": "Enter the 6-digit code from your authenticator app.", "prompt": "Enter the 6-digit code from your authenticator app.",
@@ -193,6 +209,7 @@
"anyoneCanStart": "Anyone can start the meeting", "anyoneCanStart": "Anyone can start the meeting",
"allJoinModerator": "All participants as moderator", "allJoinModerator": "All participants as moderator",
"allowRecording": "Allow recording", "allowRecording": "Allow recording",
"enableTranscript": "AI summary / transcript for recordings",
"noAccessCode": "No access code", "noAccessCode": "No access code",
"emptyNoCode": "Empty = no code", "emptyNoCode": "Empty = no code",
"settingsSaved": "Settings saved", "settingsSaved": "Settings saved",
@@ -627,9 +644,11 @@
"invitationPending": "Invitation pending", "invitationPending": "Invitation pending",
"pendingInvitations": "Pending Invitations", "pendingInvitations": "Pending Invitations",
"accepted": "Accepted", "accepted": "Accepted",
"sendFederated": "Send to remote", "sendFederated": "Invite remote",
"sendFederatedTitle": "Send Event to Remote Instance", "sendFederatedTitle": "Send Event Invitation",
"sendFederatedDesc": "Send this calendar event to a user on another Redlight instance. The recipient must accept the invitation before the event appears in their calendar.", "sendFederatedDesc": "Send this calendar event to a user on another Redlight instance or to any email address. Remote recipients must accept the invitation before the event appears in their calendar; email recipients receive the event details with an .ics attachment.",
"inviteSection": "Send invitations (optional)",
"inviteSectionHint": "Invite people by email or send the event to a user on another Redlight instance.",
"send": "Send", "send": "Send",
"fedSent": "Calendar invitation sent! The recipient must accept it first.", "fedSent": "Calendar invitation sent! The recipient must accept it first.",
"fedFailed": "Could not send event to remote instance", "fedFailed": "Could not send event to remote instance",
+138 -12
View File
@@ -42,8 +42,13 @@ export default function Calendar() {
const [sharedUsers, setSharedUsers] = useState([]); const [sharedUsers, setSharedUsers] = useState([]);
const [pendingInvitations, setPendingInvitations] = useState([]); const [pendingInvitations, setPendingInvitations] = useState([]);
const [fedAddress, setFedAddress] = useState(''); const [fedAddress, setFedAddress] = useState('');
const [fedEmails, setFedEmails] = useState('');
const [fedSending, setFedSending] = useState(false); const [fedSending, setFedSending] = useState(false);
// Invitations sent right after creating an event
const [inviteFedAddress, setInviteFedAddress] = useState('');
const [inviteEmails, setInviteEmails] = useState('');
// Load events on month change // Load events on month change
useEffect(() => { useEffect(() => {
fetchEvents(); fetchEvents();
@@ -159,6 +164,8 @@ export default function Calendar() {
end_time: toLocalDateTimeStr(end), end_time: toLocalDateTimeStr(end),
room_uid: '', color: '#6366f1', reminder_minutes: null, room_uid: '', color: '#6366f1', reminder_minutes: null,
}); });
setInviteFedAddress('');
setInviteEmails('');
setEditingEvent(null); setEditingEvent(null);
setShowCreate(true); setShowCreate(true);
}; };
@@ -178,8 +185,41 @@ export default function Calendar() {
setShowCreate(true); setShowCreate(true);
}; };
const isValidFedAddress = (address) => {
const normalized = address.startsWith('@') ? address.slice(1) : address;
return normalized.includes('@') && !normalized.endsWith('@');
};
// Send invitations for an event; shows a toast per outcome (non-fatal on failure)
const sendEventInvites = async (eventId, address, emailsStr) => {
const addr = address.trim();
if (addr) {
try {
await api.post(`/calendar/events/${eventId}/federation`, { to: addr });
toast.success(t('calendar.fedSent'));
} catch (err) {
toast.error(err.response?.data?.error || t('calendar.fedFailed'));
}
}
const emailList = emailsStr.split(',').map(s => s.trim()).filter(Boolean);
if (emailList.length > 0) {
try {
await api.post(`/calendar/events/${eventId}/email`, { emails: emailList });
toast.success(t('federation.emailSent'));
} catch (err) {
toast.error(err.response?.data?.error || t('federation.emailSendFailed'));
}
}
};
const handleSave = async (e) => { const handleSave = async (e) => {
e.preventDefault(); e.preventDefault();
if (!editingEvent && inviteFedAddress.trim() && !isValidFedAddress(inviteFedAddress.trim())) {
toast.error(t('federation.addressHint'));
return;
}
setSaving(true); setSaving(true);
try { try {
const data = { const data = {
@@ -192,11 +232,17 @@ export default function Calendar() {
await api.put(`/calendar/events/${editingEvent.id}`, data); await api.put(`/calendar/events/${editingEvent.id}`, data);
toast.success(t('calendar.eventUpdated')); toast.success(t('calendar.eventUpdated'));
} else { } else {
await api.post('/calendar/events', data); const res = await api.post('/calendar/events', data);
toast.success(t('calendar.eventCreated')); toast.success(t('calendar.eventCreated'));
const created = res.data.event;
if (created && (inviteFedAddress.trim() || inviteEmails.trim())) {
await sendEventInvites(created.id, inviteFedAddress, inviteEmails);
}
} }
setShowCreate(false); setShowCreate(false);
setEditingEvent(null); setEditingEvent(null);
setInviteFedAddress('');
setInviteEmails('');
fetchEvents(); fetchEvents();
} catch (err) { } catch (err) {
toast.error(err.response?.data?.error || t('calendar.saveFailed')); toast.error(err.response?.data?.error || t('calendar.saveFailed'));
@@ -328,19 +374,41 @@ export default function Calendar() {
const handleFedSend = async (e) => { const handleFedSend = async (e) => {
e.preventDefault(); e.preventDefault();
if (!showFedShare) return; if (!showFedShare) return;
const normalized = fedAddress.startsWith('@') ? fedAddress.slice(1) : fedAddress; const hasAddress = fedAddress.trim().length > 0;
if (!normalized.includes('@') || normalized.endsWith('@')) { const hasEmails = fedEmails.trim().length > 0;
if (!hasAddress && !hasEmails) {
toast.error(t('federation.addressHint')); toast.error(t('federation.addressHint'));
return; return;
} }
setFedSending(true); setFedSending(true);
try { try {
await api.post(`/calendar/events/${showFedShare.id}/federation`, { to: fedAddress }); if (hasAddress) {
toast.success(t('calendar.fedSent')); // Federation address mode
if (!isValidFedAddress(fedAddress.trim())) {
toast.error(t('federation.addressHint'));
setFedSending(false);
return;
}
await api.post(`/calendar/events/${showFedShare.id}/federation`, { to: fedAddress });
toast.success(t('calendar.fedSent'));
} else {
// Email mode
const emailList = fedEmails.split(',').map(s => s.trim()).filter(Boolean);
if (emailList.length === 0) {
toast.error(t('federation.emailHint'));
setFedSending(false);
return;
}
await api.post(`/calendar/events/${showFedShare.id}/email`, { emails: emailList });
toast.success(t('federation.emailSent'));
}
setShowFedShare(null); setShowFedShare(null);
setFedAddress(''); setFedAddress('');
setFedEmails('');
} catch (err) { } catch (err) {
toast.error(err.response?.data?.error || t('calendar.fedFailed')); toast.error(err.response?.data?.error || t(hasAddress ? 'calendar.fedFailed' : 'federation.emailSendFailed'));
} finally { } finally {
setFedSending(false); setFedSending(false);
} }
@@ -378,6 +446,8 @@ export default function Calendar() {
end_time: toLocalDateTimeStr(end), end_time: toLocalDateTimeStr(end),
room_uid: '', color: '#6366f1', room_uid: '', color: '#6366f1',
}); });
setInviteFedAddress('');
setInviteEmails('');
setEditingEvent(null); setEditingEvent(null);
setShowCreate(true); setShowCreate(true);
}} className="btn-primary"> }} className="btn-primary">
@@ -616,6 +686,41 @@ export default function Calendar() {
</div> </div>
</div> </div>
{!editingEvent && (
<div className="pt-4 border-t border-th-border space-y-4">
<div>
<p className="text-sm font-medium text-th-text">{t('calendar.inviteSection')}</p>
<p className="text-xs text-th-text-s mt-0.5">{t('calendar.inviteSectionHint')}</p>
</div>
<div>
<label htmlFor="calendar-invite-emails" className="block text-sm font-medium text-th-text mb-1.5">{t('federation.emailLabel')}</label>
<input
id="calendar-invite-emails"
type="text"
value={inviteEmails}
onChange={e => setInviteEmails(e.target.value)}
className="input-field"
placeholder={t('federation.emailPlaceholder')}
/>
<p className="text-xs text-th-text-s mt-1">{t('federation.emailHint')}</p>
</div>
<div>
<label htmlFor="calendar-invite-fed-address" className="block text-sm font-medium text-th-text mb-1.5">{t('federation.addressLabel')}</label>
<input
id="calendar-invite-fed-address"
type="text"
value={inviteFedAddress}
onChange={e => setInviteFedAddress(e.target.value)}
className="input-field"
placeholder={t('federation.addressPlaceholder')}
/>
<p className="text-xs text-th-text-s mt-1">{t('federation.addressHint')}</p>
</div>
</div>
)}
<div className="flex items-center gap-3 pt-4 border-t border-th-border"> <div className="flex items-center gap-3 pt-4 border-t border-th-border">
<button type="button" onClick={() => { setShowCreate(false); setEditingEvent(null); }} className="btn-secondary flex-1"> <button type="button" onClick={() => { setShowCreate(false); setEditingEvent(null); }} className="btn-secondary flex-1">
{t('common.cancel')} {t('common.cancel')}
@@ -827,9 +932,9 @@ export default function Calendar() {
</Modal> </Modal>
)} )}
{/* Federation Share Modal */} {/* Federation/Email Share Modal */}
{showFedShare && ( {showFedShare && (
<Modal title={t('calendar.sendFederatedTitle')} onClose={() => setShowFedShare(null)}> <Modal title={t('calendar.sendFederatedTitle')} onClose={() => { setShowFedShare(null); setFedAddress(''); setFedEmails(''); }}>
<p className="text-sm text-th-text-s mb-4">{t('calendar.sendFederatedDesc')}</p> <p className="text-sm text-th-text-s mb-4">{t('calendar.sendFederatedDesc')}</p>
<form onSubmit={handleFedSend} className="space-y-4"> <form onSubmit={handleFedSend} className="space-y-4">
<div> <div>
@@ -838,18 +943,39 @@ export default function Calendar() {
id="calendar-fed-share-address" id="calendar-fed-share-address"
type="text" type="text"
value={fedAddress} value={fedAddress}
onChange={e => setFedAddress(e.target.value)} onChange={e => { setFedAddress(e.target.value); if (e.target.value) setFedEmails(''); }}
className="input-field" className="input-field"
placeholder={t('federation.addressPlaceholder')} placeholder={t('federation.addressPlaceholder')}
required disabled={fedEmails.trim().length > 0}
/> />
<p className="text-xs text-th-text-s mt-1">{t('federation.addressHint')}</p> <p className="text-xs text-th-text-s mt-1">{t('federation.addressHint')}</p>
</div> </div>
<div className="flex items-center gap-3 my-2">
<div className="flex-1 border-t border-th-border" />
<span className="text-xs text-th-text-s uppercase">{t('common.or')}</span>
<div className="flex-1 border-t border-th-border" />
</div>
<div>
<label htmlFor="calendar-fed-share-emails" className="block text-sm font-medium text-th-text mb-1.5">{t('federation.emailLabel')}</label>
<input
id="calendar-fed-share-emails"
type="text"
value={fedEmails}
onChange={e => { setFedEmails(e.target.value); if (e.target.value) setFedAddress(''); }}
className="input-field"
placeholder={t('federation.emailPlaceholder')}
disabled={fedAddress.trim().length > 0}
/>
<p className="text-xs text-th-text-s mt-1">{t('federation.emailHint')}</p>
</div>
<div className="flex items-center gap-3 pt-2 border-t border-th-border"> <div className="flex items-center gap-3 pt-2 border-t border-th-border">
<button type="button" onClick={() => setShowFedShare(null)} className="btn-secondary flex-1"> <button type="button" onClick={() => { setShowFedShare(null); setFedAddress(''); setFedEmails(''); }} className="btn-secondary flex-1">
{t('common.cancel')} {t('common.cancel')}
</button> </button>
<button type="submit" disabled={fedSending} className="btn-primary flex-1"> <button type="submit" disabled={fedSending || (!fedAddress.trim() && !fedEmails.trim())} className="btn-primary flex-1">
{fedSending ? <Loader2 size={16} className="animate-spin" /> : <Send size={16} />} {fedSending ? <Loader2 size={16} className="animate-spin" /> : <Send size={16} />}
{t('calendar.send')} {t('calendar.send')}
</button> </button>
+104
View File
@@ -0,0 +1,104 @@
import { useState } from 'react';
import { Link } from 'react-router-dom';
import { useLanguage } from '../contexts/LanguageContext';
import { Mail, ArrowRight, Loader2, CheckCircle } from 'lucide-react';
import BrandLogo from '../components/BrandLogo';
import api from '../services/api';
import toast from 'react-hot-toast';
export default function ForgotPassword() {
const [email, setEmail] = useState('');
const [loading, setLoading] = useState(false);
const [sent, setSent] = useState(false);
const { t } = useLanguage();
const handleSubmit = async (e) => {
e.preventDefault();
setLoading(true);
try {
await api.post('/auth/forgot-password', { email });
setSent(true);
} catch (err) {
toast.error(err.response?.data?.error || t('auth.forgotPasswordFailed'));
} finally {
setLoading(false);
}
};
return (
<div className="min-h-screen flex items-center justify-center p-6 relative overflow-hidden">
{/* Animated background */}
<div className="absolute inset-0 bg-th-bg">
<div className="absolute inset-0 opacity-30">
<div className="absolute top-1/4 left-1/4 w-96 h-96 bg-th-accent rounded-full blur-[128px] animate-pulse" />
<div className="absolute bottom-1/4 right-1/4 w-80 h-80 bg-purple-500 rounded-full blur-[128px] animate-pulse" style={{ animationDelay: '2s' }} />
<div className="absolute top-1/2 left-1/2 -translate-x-1/2 -translate-y-1/2 w-64 h-64 bg-pink-500 rounded-full blur-[128px] animate-pulse" style={{ animationDelay: '4s' }} />
</div>
</div>
<div className="relative w-full max-w-md">
<div className="card p-8 backdrop-blur-xl bg-th-card/80 border border-th-border shadow-2xl rounded-2xl">
<div className="flex justify-center mb-8">
<BrandLogo size="lg" />
</div>
{sent ? (
<div className="text-center space-y-4">
<CheckCircle size={48} className="mx-auto text-green-400" />
<h2 className="text-2xl font-bold text-th-text">{t('auth.forgotPasswordSentTitle')}</h2>
<p className="text-th-text-s">{t('auth.forgotPasswordSent')}</p>
<Link to="/login" className="btn-primary inline-flex items-center gap-2 mt-4">
{t('auth.login')}
</Link>
</div>
) : (
<>
<div className="mb-8">
<h2 className="text-2xl font-bold text-th-text mb-2">{t('auth.forgotPasswordTitle')}</h2>
<p className="text-th-text-s">{t('auth.forgotPasswordSubtitle')}</p>
</div>
<form onSubmit={handleSubmit} className="space-y-5">
<div>
<label htmlFor="forgot-email" className="block text-sm font-medium text-th-text mb-1.5">{t('auth.email')}</label>
<div className="relative">
<Mail size={18} className="absolute left-3.5 top-1/2 -translate-y-1/2 text-th-text-s" aria-hidden="true" />
<input
id="forgot-email"
type="email"
autoComplete="email"
value={email}
onChange={e => setEmail(e.target.value)}
className="input-field pl-11"
placeholder={t('auth.emailPlaceholder')}
required
/>
</div>
</div>
<button
type="submit"
disabled={loading}
className="btn-primary w-full py-3"
>
{loading ? (
<Loader2 size={18} className="animate-spin" />
) : (
<>
{t('auth.forgotPasswordSubmit')}
<ArrowRight size={18} />
</>
)}
</button>
</form>
</>
)}
<Link to="/login" className="block mt-6 text-center text-sm text-th-text-s hover:text-th-text transition-colors">
{t('auth.backToLogin')}
</Link>
</div>
</div>
</div>
);
}
+5
View File
@@ -220,6 +220,11 @@ export default function Login() {
required required
/> />
</div> </div>
<div className="mt-1.5 text-right">
<Link to="/forgot-password" className="text-sm text-th-accent hover:underline">
{t('auth.forgotPassword')}
</Link>
</div>
</div> </div>
<button <button
+147
View File
@@ -0,0 +1,147 @@
import { useState } from 'react';
import { Link, useSearchParams, useNavigate } from 'react-router-dom';
import { useLanguage } from '../contexts/LanguageContext';
import { Lock, ArrowRight, Loader2, CheckCircle, XCircle } from 'lucide-react';
import BrandLogo from '../components/BrandLogo';
import api from '../services/api';
import toast from 'react-hot-toast';
const MIN_PASSWORD_LENGTH = 8;
export default function ResetPassword() {
const [searchParams] = useSearchParams();
const token = searchParams.get('token');
const { t } = useLanguage();
const navigate = useNavigate();
const [password, setPassword] = useState('');
const [confirm, setConfirm] = useState('');
const [loading, setLoading] = useState(false);
const [done, setDone] = useState(false);
const handleSubmit = async (e) => {
e.preventDefault();
if (password.length < MIN_PASSWORD_LENGTH) {
toast.error(t('auth.passwordMinLength'));
return;
}
if (password !== confirm) {
toast.error(t('auth.passwordMismatch'));
return;
}
setLoading(true);
try {
await api.post('/auth/reset-password', { token, password });
setDone(true);
toast.success(t('auth.resetPasswordSuccess'));
setTimeout(() => navigate('/login'), 2500);
} catch (err) {
toast.error(err.response?.data?.error || t('auth.resetPasswordFailed'));
} finally {
setLoading(false);
}
};
return (
<div className="min-h-screen flex items-center justify-center p-6 relative overflow-hidden">
{/* Animated background */}
<div className="absolute inset-0 bg-th-bg">
<div className="absolute inset-0 opacity-30">
<div className="absolute top-1/4 left-1/4 w-96 h-96 bg-th-accent rounded-full blur-[128px] animate-pulse" />
<div className="absolute bottom-1/4 right-1/4 w-80 h-80 bg-purple-500 rounded-full blur-[128px] animate-pulse" style={{ animationDelay: '2s' }} />
<div className="absolute top-1/2 left-1/2 -translate-x-1/2 -translate-y-1/2 w-64 h-64 bg-pink-500 rounded-full blur-[128px] animate-pulse" style={{ animationDelay: '4s' }} />
</div>
</div>
<div className="relative w-full max-w-md">
<div className="card p-8 backdrop-blur-xl bg-th-card/80 border border-th-border shadow-2xl rounded-2xl">
<div className="flex justify-center mb-8">
<BrandLogo size="lg" />
</div>
{!token ? (
<div className="text-center space-y-4">
<XCircle size={48} className="mx-auto text-red-400" />
<h2 className="text-2xl font-bold text-th-text">{t('auth.resetPasswordFailed')}</h2>
<p className="text-th-text-s">{t('auth.resetTokenMissing')}</p>
<Link to="/forgot-password" className="btn-primary inline-flex items-center gap-2 mt-4">
{t('auth.forgotPasswordTitle')}
</Link>
</div>
) : done ? (
<div className="text-center space-y-4">
<CheckCircle size={48} className="mx-auto text-green-400" />
<h2 className="text-2xl font-bold text-th-text">{t('auth.resetPasswordSuccessTitle')}</h2>
<p className="text-th-text-s">{t('auth.resetPasswordSuccess')}</p>
<Link to="/login" className="btn-primary inline-flex items-center gap-2 mt-4">
{t('auth.login')}
</Link>
</div>
) : (
<>
<div className="mb-8">
<h2 className="text-2xl font-bold text-th-text mb-2">{t('auth.resetPasswordTitle')}</h2>
<p className="text-th-text-s">{t('auth.resetPasswordSubtitle')}</p>
</div>
<form onSubmit={handleSubmit} className="space-y-5">
<div>
<label htmlFor="reset-password" className="block text-sm font-medium text-th-text mb-1.5">{t('auth.newPassword')}</label>
<div className="relative">
<Lock size={18} className="absolute left-3.5 top-1/2 -translate-y-1/2 text-th-text-s" aria-hidden="true" />
<input
id="reset-password"
type="password"
autoComplete="new-password"
value={password}
onChange={e => setPassword(e.target.value)}
className="input-field pl-11"
placeholder={t('auth.passwordPlaceholder')}
required
/>
</div>
</div>
<div>
<label htmlFor="reset-confirm" className="block text-sm font-medium text-th-text mb-1.5">{t('auth.confirmPassword')}</label>
<div className="relative">
<Lock size={18} className="absolute left-3.5 top-1/2 -translate-y-1/2 text-th-text-s" aria-hidden="true" />
<input
id="reset-confirm"
type="password"
autoComplete="new-password"
value={confirm}
onChange={e => setConfirm(e.target.value)}
className="input-field pl-11"
placeholder={t('auth.passwordPlaceholder')}
required
/>
</div>
</div>
<button
type="submit"
disabled={loading}
className="btn-primary w-full py-3"
>
{loading ? (
<Loader2 size={18} className="animate-spin" />
) : (
<>
{t('auth.resetPasswordSubmit')}
<ArrowRight size={18} />
</>
)}
</button>
</form>
</>
)}
<Link to="/login" className="block mt-6 text-center text-sm text-th-text-s hover:text-th-text transition-colors">
{t('auth.backToLogin')}
</Link>
</div>
</div>
</div>
);
}
+21 -1
View File
@@ -10,6 +10,7 @@ import Modal from '../components/Modal';
import api from '../services/api'; import api from '../services/api';
import { isCurrentThemeDark } from '../themes'; import { isCurrentThemeDark } from '../themes';
import { useAuth } from '../contexts/AuthContext'; import { useAuth } from '../contexts/AuthContext';
import { useBranding } from '../contexts/BrandingContext';
import { useLanguage } from '../contexts/LanguageContext'; import { useLanguage } from '../contexts/LanguageContext';
import RecordingList from '../components/RecordingList'; import RecordingList from '../components/RecordingList';
import AnalyticsList from '../components/AnalyticsList'; import AnalyticsList from '../components/AnalyticsList';
@@ -19,6 +20,7 @@ export default function RoomDetail() {
const { uid } = useParams(); const { uid } = useParams();
const navigate = useNavigate(); const navigate = useNavigate();
const { user } = useAuth(); const { user } = useAuth();
const { transcriptionEnabled } = useBranding();
const { t } = useLanguage(); const { t } = useLanguage();
const [room, setRoom] = useState(null); const [room, setRoom] = useState(null);
@@ -203,6 +205,7 @@ export default function RoomDetail() {
moderator_code: editRoom.moderator_code, moderator_code: editRoom.moderator_code,
learning_analytics: !!editRoom.learning_analytics, learning_analytics: !!editRoom.learning_analytics,
analytics_visibility: editRoom.analytics_visibility || 'owner', analytics_visibility: editRoom.analytics_visibility || 'owner',
recording_transcript: !!editRoom.record_meeting && !!editRoom.recording_transcript,
}); });
setRoom(res.data.room); setRoom(res.data.room);
setEditRoom(res.data.room); setEditRoom(res.data.room);
@@ -671,11 +674,28 @@ export default function RoomDetail() {
<input <input
type="checkbox" type="checkbox"
checked={!!editRoom.record_meeting} checked={!!editRoom.record_meeting}
onChange={e => setEditRoom({ ...editRoom, record_meeting: e.target.checked })} onChange={e => setEditRoom({
...editRoom,
record_meeting: e.target.checked,
// Transcription/AI summary requires recording — clear it when recording is turned off
recording_transcript: e.target.checked ? editRoom.recording_transcript : false,
})}
className="w-4 h-4 rounded-sm border-th-border text-th-accent focus:ring-th-ring" className="w-4 h-4 rounded-sm border-th-border text-th-accent focus:ring-th-ring"
/> />
<span className="text-sm text-th-text">{t('room.allowRecording')}</span> <span className="text-sm text-th-text">{t('room.allowRecording')}</span>
</label> </label>
{transcriptionEnabled && (
<label className={`flex items-center gap-3 ${editRoom.record_meeting ? 'cursor-pointer' : 'opacity-50 cursor-not-allowed'}`}>
<input
type="checkbox"
checked={!!editRoom.recording_transcript}
disabled={!editRoom.record_meeting}
onChange={e => setEditRoom({ ...editRoom, recording_transcript: e.target.checked })}
className="w-4 h-4 rounded-sm border-th-border text-th-accent focus:ring-th-ring"
/>
<span className="text-sm text-th-text">{t('room.enableTranscript')}</span>
</label>
)}
<label className="flex items-center gap-3 cursor-pointer"> <label className="flex items-center gap-3 cursor-pointer">
<input <input
type="checkbox" type="checkbox"