| 0b4b582 | | | 1 | import fs from "fs"; |
| 0b4b582 | | | 2 | import fsp from "fs/promises"; |
| 0b4b582 | | | 3 | import path from "path"; |
| 0b4b582 | | | 4 | import * as Y from "yjs"; |
| 0b4b582 | | | 5 | |
| 0b4b582 | | | 6 | // Sanitize user-supplied IDs to prevent path traversal |
| 0b4b582 | | | 7 | export function safeId(id: string): string { |
| 0b4b582 | | | 8 | return String(id) |
| 0b4b582 | | | 9 | .replace(/[^a-zA-Z0-9_-]/g, "_") |
| 0b4b582 | | | 10 | .slice(0, 128); |
| 0b4b582 | | | 11 | } |
| 0b4b582 | | | 12 | |
| 0b4b582 | | | 13 | export interface CollabNote { |
| 0b4b582 | | | 14 | id: string; |
| 0b4b582 | | | 15 | author: string; |
| 0b4b582 | | | 16 | text: string; |
| 0b4b582 | | | 17 | x?: number; |
| 0b4b582 | | | 18 | y?: number; |
| 0b4b582 | | | 19 | diagramId: string; |
| 0b4b582 | | | 20 | diagramTitle?: string; |
| 0b4b582 | | | 21 | targetNode?: string | null; |
| 0b4b582 | | | 22 | timestamp: string; |
| 0b4b582 | | | 23 | editedAt?: string; |
| 0b4b582 | | | 24 | } |
| 0b4b582 | | | 25 | |
| 0b4b582 | | | 26 | export interface CollabUser { |
| 0b4b582 | | | 27 | id: string; |
| 0b4b582 | | | 28 | name: string; |
| 0b4b582 | | | 29 | color: string; |
| 0b4b582 | | | 30 | cursor: { x: number; y: number } | null; |
| 0b4b582 | | | 31 | activeTab: string | null; |
| 0b4b582 | | | 32 | } |
| 0b4b582 | | | 33 | |
| 0b4b582 | | | 34 | export interface Room { |
| 0b4b582 | | | 35 | notes: Record<string, CollabNote[]>; |
| 0b4b582 | | | 36 | users: Record<string, CollabUser>; |
| 0b4b582 | | | 37 | ydocs: Record<string, Y.Doc & { _persistTimer?: ReturnType<typeof setTimeout> }>; |
| 0b4b582 | | | 38 | } |
| 0b4b582 | | | 39 | |
| 0b4b582 | | | 40 | // In-memory store per room (keyed by "owner/repo") |
| 0b4b582 | | | 41 | const rooms: Record<string, Room> = {}; |
| 0b4b582 | | | 42 | |
| 0b4b582 | | | 43 | export function getRoom(key: string): Room { |
| 0b4b582 | | | 44 | if (!rooms[key]) { |
| 0b4b582 | | | 45 | rooms[key] = { notes: {}, users: {}, ydocs: {} }; |
| 0b4b582 | | | 46 | } |
| 0b4b582 | | | 47 | return rooms[key]; |
| 0b4b582 | | | 48 | } |
| 0b4b582 | | | 49 | |
| 0b4b582 | | | 50 | export function roomKey(owner: string, repo: string): string { |
| 0b4b582 | | | 51 | return `${safeId(owner)}/${safeId(repo)}`; |
| 0b4b582 | | | 52 | } |
| 0b4b582 | | | 53 | |
| 0b4b582 | | | 54 | // Persistence: repo-scoped data on disk |
| 0b4b582 | | | 55 | const DATA_DIR = process.env.DATA_DIR || path.join(process.cwd(), "collab-data"); |
| 0b4b582 | | | 56 | if (!fs.existsSync(DATA_DIR)) fs.mkdirSync(DATA_DIR, { recursive: true }); |
| 0b4b582 | | | 57 | |
| 0b4b582 | | | 58 | function repoDataDir(owner: string, repo: string): string { |
| 0b4b582 | | | 59 | return path.join(DATA_DIR, "repos", safeId(owner), safeId(repo)); |
| 0b4b582 | | | 60 | } |
| 0b4b582 | | | 61 | |
| 0b4b582 | | | 62 | // ── Diagram catalog (per-repo) ── |
| 0b4b582 | | | 63 | const DIAGRAMS_DEFAULT_PATH = path.join(process.cwd(), "server", "diagrams-default.json"); |
| 0b4b582 | | | 64 | |
| 0b4b582 | | | 65 | export function loadDiagrams( |
| 0b4b582 | | | 66 | owner: string, |
| 0b4b582 | | | 67 | repo: string |
| 0b4b582 | | | 68 | ): { sections: any[]; diagrams: any[] } { |
| 0b4b582 | | | 69 | const dir = repoDataDir(owner, repo); |
| 0b4b582 | | | 70 | const repoPath = path.join(dir, "diagrams.json"); |
| 0b4b582 | | | 71 | if (fs.existsSync(repoPath)) { |
| 0b4b582 | | | 72 | try { |
| 0b4b582 | | | 73 | return JSON.parse(fs.readFileSync(repoPath, "utf-8")); |
| 0b4b582 | | | 74 | } catch (e: any) { |
| 0b4b582 | | | 75 | console.error(`[diagrams] Failed to parse ${repoPath}:`, e.message); |
| 0b4b582 | | | 76 | } |
| 0b4b582 | | | 77 | } |
| 0b4b582 | | | 78 | // Seed from default catalog for new repos |
| 0b4b582 | | | 79 | if (fs.existsSync(DIAGRAMS_DEFAULT_PATH)) { |
| 0b4b582 | | | 80 | const data = fs.readFileSync(DIAGRAMS_DEFAULT_PATH, "utf-8"); |
| 0b4b582 | | | 81 | fs.mkdirSync(dir, { recursive: true }); |
| 0b4b582 | | | 82 | fs.writeFileSync(repoPath, data); |
| 0b4b582 | | | 83 | return JSON.parse(data); |
| 0b4b582 | | | 84 | } |
| 0b4b582 | | | 85 | return { sections: [], diagrams: [] }; |
| 0b4b582 | | | 86 | } |
| 0b4b582 | | | 87 | |
| 0b4b582 | | | 88 | export function persistRoom(owner: string, repo: string): void { |
| 0b4b582 | | | 89 | const key = roomKey(owner, repo); |
| 0b4b582 | | | 90 | const room = rooms[key]; |
| 0b4b582 | | | 91 | if (!room) return; |
| 0b4b582 | | | 92 | const dir = repoDataDir(owner, repo); |
| 0b4b582 | | | 93 | fs.mkdirSync(dir, { recursive: true }); |
| 0b4b582 | | | 94 | const filePath = path.join(dir, "notes.json"); |
| 0b4b582 | | | 95 | fsp |
| 0b4b582 | | | 96 | .writeFile(filePath, JSON.stringify(room.notes, null, 2)) |
| 0b4b582 | | | 97 | .catch((e) => |
| 0b4b582 | | | 98 | console.error(`[persist] Failed to write ${filePath}:`, e.message) |
| 0b4b582 | | | 99 | ); |
| 0b4b582 | | | 100 | } |
| 0b4b582 | | | 101 | |
| 0b4b582 | | | 102 | export function loadRoom(owner: string, repo: string): Record<string, CollabNote[]> { |
| 0b4b582 | | | 103 | const filePath = path.join(repoDataDir(owner, repo), "notes.json"); |
| 0b4b582 | | | 104 | if (fs.existsSync(filePath)) { |
| 0b4b582 | | | 105 | try { |
| 0b4b582 | | | 106 | return JSON.parse(fs.readFileSync(filePath, "utf-8")); |
| 0b4b582 | | | 107 | } catch { |
| 0b4b582 | | | 108 | return {}; |
| 0b4b582 | | | 109 | } |
| 0b4b582 | | | 110 | } |
| 0b4b582 | | | 111 | return {}; |
| 0b4b582 | | | 112 | } |
| 0b4b582 | | | 113 | |
| 0b4b582 | | | 114 | // ── Yjs document management ── |
| 0b4b582 | | | 115 | export function getYDoc(owner: string, repo: string, diagramId: string): Y.Doc { |
| 0b4b582 | | | 116 | const key = roomKey(owner, repo); |
| 0b4b582 | | | 117 | const room = getRoom(key); |
| 0b4b582 | | | 118 | if (!room.ydocs[diagramId]) { |
| 0b4b582 | | | 119 | const ydoc = new Y.Doc() as Y.Doc & { _persistTimer?: ReturnType<typeof setTimeout> }; |
| 0b4b582 | | | 120 | room.ydocs[diagramId] = ydoc; |
| 0b4b582 | | | 121 | const yFilePath = path.join( |
| 0b4b582 | | | 122 | repoDataDir(owner, repo), |
| 0b4b582 | | | 123 | `ydoc_${safeId(diagramId)}.bin` |
| 0b4b582 | | | 124 | ); |
| 0b4b582 | | | 125 | if (fs.existsSync(yFilePath)) { |
| 0b4b582 | | | 126 | try { |
| 0b4b582 | | | 127 | const data = fs.readFileSync(yFilePath); |
| 0b4b582 | | | 128 | Y.applyUpdate(ydoc, new Uint8Array(data)); |
| 0b4b582 | | | 129 | } catch (e: any) { |
| 0b4b582 | | | 130 | console.error(`[yjs] Failed to load ${yFilePath}:`, e.message); |
| 0b4b582 | | | 131 | } |
| 0b4b582 | | | 132 | } |
| 0b4b582 | | | 133 | } |
| 0b4b582 | | | 134 | return room.ydocs[diagramId]; |
| 0b4b582 | | | 135 | } |
| 0b4b582 | | | 136 | |
| 0b4b582 | | | 137 | export function persistYDoc( |
| 0b4b582 | | | 138 | owner: string, |
| 0b4b582 | | | 139 | repo: string, |
| 0b4b582 | | | 140 | diagramId: string |
| 0b4b582 | | | 141 | ): void { |
| 0b4b582 | | | 142 | const key = roomKey(owner, repo); |
| 0b4b582 | | | 143 | const room = rooms[key]; |
| 0b4b582 | | | 144 | if (!room || !room.ydocs[diagramId]) return; |
| 0b4b582 | | | 145 | const ydoc = room.ydocs[diagramId]; |
| 0b4b582 | | | 146 | const dir = repoDataDir(owner, repo); |
| 0b4b582 | | | 147 | fs.mkdirSync(dir, { recursive: true }); |
| 0b4b582 | | | 148 | const yFilePath = path.join(dir, `ydoc_${safeId(diagramId)}.bin`); |
| 0b4b582 | | | 149 | const state = Y.encodeStateAsUpdate(ydoc); |
| 0b4b582 | | | 150 | fsp |
| 0b4b582 | | | 151 | .writeFile(yFilePath, Buffer.from(state)) |
| 0b4b582 | | | 152 | .catch((e) => |
| 0b4b582 | | | 153 | console.error(`[persist] Failed to write ${yFilePath}:`, e.message) |
| 0b4b582 | | | 154 | ); |
| 0b4b582 | | | 155 | } |
| 0b4b582 | | | 156 | |
| 0b4b582 | | | 157 | // ── Repo access control (delegated to grove-api) ── |
| 0b4b582 | | | 158 | const GROVE_API_URL = |
| 0b4b582 | | | 159 | process.env.GROVE_API_URL || "http://localhost:4000"; |
| 0b4b582 | | | 160 | |
| 0b4b582 | | | 161 | const accessCache = new Map< |
| 0b4b582 | | | 162 | string, |
| 0b4b582 | | | 163 | { allowed: boolean; expiresAt: number } |
| 0b4b582 | | | 164 | >(); |
| 0b4b582 | | | 165 | const ACCESS_CACHE_TTL = 60 * 1000; |
| 0b4b582 | | | 166 | |
| 0b4b582 | | | 167 | export async function canAccessRepo( |
| 0b4b582 | | | 168 | owner: string, |
| 0b4b582 | | | 169 | repo: string, |
| 0b4b582 | | | 170 | token: string | null |
| 0b4b582 | | | 171 | ): Promise<boolean> { |
| 0b4b582 | | | 172 | const cacheKey = `${token ? token.slice(-8) : "anon"}:${owner}/${repo}`; |
| 0b4b582 | | | 173 | const cached = accessCache.get(cacheKey); |
| 0b4b582 | | | 174 | if (cached && cached.expiresAt > Date.now()) return cached.allowed; |
| 0b4b582 | | | 175 | try { |
| 0b4b582 | | | 176 | const headers: Record<string, string> = token |
| 0b4b582 | | | 177 | ? { Authorization: `Bearer ${token}` } |
| 0b4b582 | | | 178 | : {}; |
| 0b4b582 | | | 179 | const res = await fetch( |
| 0b4b582 | | | 180 | `${GROVE_API_URL}/api/repos/${encodeURIComponent(owner)}/${encodeURIComponent(repo)}`, |
| 0b4b582 | | | 181 | { headers } |
| 0b4b582 | | | 182 | ); |
| 0b4b582 | | | 183 | const allowed = res.ok; |
| 0b4b582 | | | 184 | accessCache.set(cacheKey, { |
| 0b4b582 | | | 185 | allowed, |
| 0b4b582 | | | 186 | expiresAt: Date.now() + ACCESS_CACHE_TTL, |
| 0b4b582 | | | 187 | }); |
| 0b4b582 | | | 188 | return allowed; |
| 0b4b582 | | | 189 | } catch (e: any) { |
| 0b4b582 | | | 190 | console.error(`[access] Failed to check repo access:`, e.message); |
| 0b4b582 | | | 191 | return false; |
| 0b4b582 | | | 192 | } |
| 0b4b582 | | | 193 | } |
| 0b4b582 | | | 194 | |
| 0b4b582 | | | 195 | // ── User colors ── |
| 0b4b582 | | | 196 | export const USER_COLORS = [ |
| 0b4b582 | | | 197 | "#e74c3c", |
| 0b4b582 | | | 198 | "#3498db", |
| 0b4b582 | | | 199 | "#2ecc71", |
| 0b4b582 | | | 200 | "#f39c12", |
| 0b4b582 | | | 201 | "#9b59b6", |
| 0b4b582 | | | 202 | "#1abc9c", |
| 0b4b582 | | | 203 | "#e67e22", |
| 0b4b582 | | | 204 | "#e84393", |
| 0b4b582 | | | 205 | "#00b894", |
| 0b4b582 | | | 206 | "#6c5ce7", |
| 0b4b582 | | | 207 | ]; |
| 0b4b582 | | | 208 | |
| 0b4b582 | | | 209 | export function pickColor(room: Room): string { |
| 0b4b582 | | | 210 | const used = new Set(Object.values(room.users).map((u) => u.color)); |
| 0b4b582 | | | 211 | for (const c of USER_COLORS) { |
| 0b4b582 | | | 212 | if (!used.has(c)) return c; |
| 0b4b582 | | | 213 | } |
| 0b4b582 | | | 214 | const counts: Record<string, number> = {}; |
| 0b4b582 | | | 215 | for (const c of USER_COLORS) counts[c] = 0; |
| 0b4b582 | | | 216 | for (const u of Object.values(room.users)) { |
| 0b4b582 | | | 217 | if (counts[u.color] != null) counts[u.color]++; |
| 0b4b582 | | | 218 | } |
| 0b4b582 | | | 219 | return USER_COLORS.reduce((a, b) => (counts[a] <= counts[b] ? a : b)); |
| 0b4b582 | | | 220 | } |