trails/apps/planner/app/routes/api.save-to-journal.ts
Ullrich Schäfer 3a1c34317d
route-surface-breakdown (Phase 1): Planner-path surface/waytype bars
Synchronous path + rendering for the surface/waytype breakdown:
- map-core `computeSurfaceBreakdown(coords, surfaces, highways)` → distance-
  weighted metres per surface + waytype category (unit-tested);
- `SurfaceBreakdownSchema` in @trails-cool/api;
- nullable `surfaceBreakdown` jsonb on routes + activities;
- Planner `SaveToJournalButton` computes it from the BRouter waytags already in
  routeData and sends it; `api.save-to-journal` forwards it; the journal route
  callback validates + persists (journal is the authoritative validator);
- `SurfaceBreakdown` component (stacked bars per dimension, map-core palettes,
  legend category · % · km largest-first, unknown → "other", hidden when empty)
  on route + activity detail; journal gains a @trails-cool/map-core dep;
- i18n journal.surface.* (en + de).

Phase 2 (async Overpass backfill + SSE for imports/uploads, and the e2e that
seeds a breakdown) follows in a separate PR.

Tests: computeSurfaceBreakdown unit (map-core 36); SurfaceBreakdown component
(jsdom, journal 326). typecheck + lint green; verified in the browser.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 18:46:49 +02:00

91 lines
3.6 KiB
TypeScript

// Server-side proxy for "Save to Journal". Looks up the session's
// callbackUrl + callbackToken (stored at /new time when the user came
// from the journal) and POSTs the GPX to the journal as a Bearer.
//
// Why this exists (planner-audit #2, Phase A): the previous flow had
// the browser fetch with the bearer token directly, exposing it in
// DevTools / to any XSS / browser extension. Now the token never
// leaves the planner's server-side trust boundary.
//
// Trust model: the same sessionId that grants Yjs membership grants
// save authority. Knowing the URL = ability to act. This matches the
// existing model — we're not strengthening or weakening it, just
// keeping the JWT off the wire to the browser.
import { data } from "react-router";
import type { Route } from "./+types/api.save-to-journal";
import { getSession } from "~/lib/sessions";
import { fetchWithTimeout } from "~/lib/http.server";
import { validateFetchUrl, getCallbackAllowedHosts } from "~/lib/url-validation.server";
interface SaveRequestBody {
sessionId?: unknown;
gpx?: unknown;
surfaceBreakdown?: unknown;
}
const MAX_GPX_BYTES = 5 * 1024 * 1024; // 5 MB — same ceiling as the Yjs doc cap
export async function action({ request }: Route.ActionArgs) {
if (request.method !== "POST") {
return data({ error: "Method not allowed" }, { status: 405 });
}
let body: SaveRequestBody;
try {
body = (await request.json()) as SaveRequestBody;
} catch {
return data({ error: "Invalid JSON" }, { status: 400 });
}
const sessionId = typeof body.sessionId === "string" ? body.sessionId : "";
const gpx = typeof body.gpx === "string" ? body.gpx : "";
// Optional, best-effort decoration — forwarded as-is; the journal callback is
// the authoritative validator (planner doesn't depend on @trails-cool/api).
const surfaceBreakdown =
body.surfaceBreakdown && typeof body.surfaceBreakdown === "object"
? body.surfaceBreakdown
: undefined;
if (!sessionId) return data({ error: "sessionId required" }, { status: 400 });
if (!gpx) return data({ error: "gpx required" }, { status: 400 });
if (gpx.length > MAX_GPX_BYTES) {
return data({ error: "gpx too large" }, { status: 413 });
}
const session = await getSession(sessionId);
if (!session) return data({ error: "session not found" }, { status: 404 });
if (!session.callbackUrl || !session.callbackToken) {
return data({ error: "session has no journal callback" }, { status: 400 });
}
// Defense in depth: re-validate immediately before the outbound fetch.
// Guards sessions persisted before callbackUrl validation existed, and
// narrows the window for a host that was public at create time but
// resolves private now.
const v = validateFetchUrl(session.callbackUrl, { allowedHosts: getCallbackAllowedHosts() });
if (!v.ok) {
return data({ error: "session callback URL is not allowed" }, { status: 400 });
}
let resp: Response;
try {
resp = await fetchWithTimeout(session.callbackUrl, {
method: "POST",
headers: {
"Content-Type": "application/json",
Authorization: `Bearer ${session.callbackToken}`,
},
body: JSON.stringify({ gpx, ...(surfaceBreakdown ? { surfaceBreakdown } : {}) }),
});
} catch {
return data({ error: "journal unreachable" }, { status: 502 });
}
// Forward the journal's response (status + body) so the client UI
// can render the same error/success it would have before.
const text = await resp.text();
let payload: unknown;
try { payload = JSON.parse(text); } catch { payload = { raw: text }; }
return data(payload, { status: resp.status });
}