feat: scaffold klarbild foundation (astro+postgres+s3, auth, migrations, health)

- Astro 5 SSR (node standalone) + React, OKLCH tokens (no tailwind)
- migrations/001_init.sql: full schema per 03-datenmodell-api
- lib: db+migrations, crypto (AES-256-GCM), auth (argon2+signed session, ratelimit),
  storage (S3/MinIO, presigned URLs), openrouter (POST /v1/images, cost)
- middleware: init-once + session guard + admin gate; /api/health (db+storage)
- login + studio placeholder; seeds (till/lea, default recipes); Dockerfile
- verified: astro build passes
This commit is contained in:
2026-07-23 11:11:08 +00:00
commit b46dbbe889
26 changed files with 9651 additions and 0 deletions
+33
View File
@@ -0,0 +1,33 @@
import type { APIRoute } from 'astro';
import { login, makeSessionCookie, rateLimited, noteFailure, clearFailures } from '../../../lib/auth';
export const prerender = false;
export const POST: APIRoute = async ({ request, clientAddress }) => {
const ip = clientAddress || 'unknown';
if (rateLimited(ip)) {
return new Response(JSON.stringify({ error: 'Zu viele Versuche. Bitte in 15 Minuten erneut.' }),
{ status: 429, headers: { 'Content-Type': 'application/json' } });
}
let username = '', password = '';
const ct = request.headers.get('content-type') || '';
if (ct.includes('application/json')) {
const b = await request.json().catch(() => ({}));
username = b.username || ''; password = b.password || '';
} else {
const f = await request.formData();
username = String(f.get('username') || ''); password = String(f.get('password') || '');
}
const user = await login(username.trim(), password);
if (!user) {
noteFailure(ip);
return new Response(JSON.stringify({ error: 'Benutzername oder Passwort falsch.' }),
{ status: 401, headers: { 'Content-Type': 'application/json' } });
}
clearFailures(ip);
return new Response(JSON.stringify({ ok: true, role: user.role }), {
status: 200,
headers: { 'Content-Type': 'application/json', 'Set-Cookie': makeSessionCookie(user) },
});
};
+10
View File
@@ -0,0 +1,10 @@
import type { APIRoute } from 'astro';
import { clearSessionCookie } from '../../../lib/auth';
export const prerender = false;
export const POST: APIRoute = async () =>
new Response(JSON.stringify({ ok: true }), {
status: 200,
headers: { 'Content-Type': 'application/json', 'Set-Cookie': clearSessionCookie() },
});
+26
View File
@@ -0,0 +1,26 @@
import type { APIRoute } from 'astro';
import { pool } from '../../lib/db';
import { s3 } from '../../lib/storage';
import { HeadBucketCommand } from '@aws-sdk/client-s3';
export const prerender = false;
export const GET: APIRoute = async () => {
const out: Record<string, string> = { service: 'klarbild' };
let ok = true;
try { await pool.query('SELECT 1'); out.db = 'ok'; }
catch { out.db = 'fehler'; ok = false; }
try {
await s3.send(new HeadBucketCommand({ Bucket: process.env.S3_BUCKET || 'klarbild' }));
out.storage = 'ok';
} catch { out.storage = 'fehler'; ok = false; }
out.queue = 'todo'; // wird mit pg-boss-Phase geprüft
out.status = ok ? 'ok' : 'degraded';
return new Response(JSON.stringify(out), {
status: ok ? 200 : 503,
headers: { 'Content-Type': 'application/json' },
});
};