Dev-only bulk delete all campaigns; deleteCollection SQL bulk + gates
Feature: debug button to wipe all campaigns/encounters/logs in dev builds.
Previously bulk delete fetched all logs per campaign, client-filtered,
batchWrite — 30s+/campaign. Now SQL bulk DELETE, no fetch.
Server (server/db.js, server/index.js):
- deleteCollection(collPath, {where}) — SQL DELETE FROM docs WHERE parent=?,
optional where-filter. Broadcasts deletions to WS subscribers.
- DELETE /api/collection endpoint
- Gate: ALLOW_DEV_ENDPOINTS=1 env OR createServer({allowDevEndpoints:true})
- createServer accepts allowDevEndpoints param (tests bypass env)
Storage (src/storage/server.js, src/storage/firebase.js):
- deleteCollection(path, whereField, whereValue) both adapters
- Firebase: fetch matching + batch-delete (firestore no bulk), 500-chunk
- Gate: throws if NODE_ENV not development/test
- Contract-tested both backends
App (src/App.js):
- deleteCampaignCascade refactored (reusable, no try/catch split)
- handleDeleteAllCampaigns: Promise.all per campaign, deleteCollection for
encounters (no fetch), deleteCollection logs once globally, parallel
- Button dev-gated (NODE_ENV), confirm modal, hidden when no campaigns
Mock fixes (surfaced by new tests):
- firebase firestore mock: added where() export, getDocs applies constraints
(was returning all docs ignoring query constraints — pre-existing gap)
Tests:
- contract: deleteCollection (bulk, where-filter, empty) both backends
- server-contract: live deleteCollection (bulk, where, 403 gate)
- runStorageContract via makeStorage({allowDevEndpoints:true})
Safety (3 layers):
- UI button hidden in prod (NODE_ENV gate)
- storage method throws in prod (NODE_ENV gate)
- HTTP endpoint 403 in prod (env/param gate)
This commit is contained in:
+16
-1
@@ -11,7 +11,7 @@ const crypto = require('crypto');
|
||||
const { WebSocketServer } = require('ws');
|
||||
const { openDb, makeStore } = require('./db');
|
||||
|
||||
function createServer({ dbPath, port, corsOrigin } = {}) {
|
||||
function createServer({ dbPath, port, corsOrigin, allowDevEndpoints = false } = {}) {
|
||||
const db = openDb(dbPath || './data/tracker.sqlite');
|
||||
const app = express();
|
||||
app.use(cors({ origin: corsOrigin || '*' }));
|
||||
@@ -103,6 +103,21 @@ function createServer({ dbPath, port, corsOrigin } = {}) {
|
||||
res.json({ ok: true });
|
||||
});
|
||||
|
||||
// DELETE /api/collection?path=...&whereField=...&whereValue=...
|
||||
// Bulk delete whole collection or filtered. No fetch. SQL DELETE.
|
||||
// DEV ONLY: requires ALLOW_DEV_ENDPOINTS=1 env on server.
|
||||
app.delete('/api/collection', (req, res) => {
|
||||
if (!allowDevEndpoints && process.env.ALLOW_DEV_ENDPOINTS !== '1') {
|
||||
return res.status(403).json({ error: 'bulk delete disabled (dev only)' });
|
||||
}
|
||||
const { path: p, whereField, whereOp, whereValue } = req.query;
|
||||
if (!p) return res.status(400).json({ error: 'path required' });
|
||||
const opts = {};
|
||||
if (whereField) opts.where = { field: whereField, op: whereOp || '==', value: whereValue };
|
||||
const deleted = store.deleteCollection(p, opts);
|
||||
res.json({ ok: true, deleted });
|
||||
});
|
||||
|
||||
// POST /api/collection body: { path, data } (addDoc: auto-id under collection)
|
||||
app.post('/api/collection', (req, res) => {
|
||||
const { path: collPath, data } = req.body || {};
|
||||
|
||||
Reference in New Issue
Block a user