import { NextResponse } from 'next/server'; import { getServerSession } from 'next-auth'; import { authOptions } from '@/app/api/auth/[...nextauth]/route'; import { DOMParser } from '@xmldom/xmldom'; import { Buffer } from 'buffer'; import { PrismaClient } from '@prisma/client'; import { prisma } from '@/lib/prisma'; // Cache for folder structure and credentials const folderCache = new Map(); const credentialsCache = new Map(); // Cache for Nextcloud connectivity check let lastConnectivityCheck = 0; let isNextcloudAccessible = false; async function sleep(ms: number) { return new Promise(resolve => setTimeout(resolve, ms)); } async function checkNextcloudConnectivity(nextcloudUrl: string): Promise { const now = Date.now(); if (now - lastConnectivityCheck < 5 * 60 * 1000) { // 5 minutes cache return isNextcloudAccessible; } try { const testResponse = await fetch(`${nextcloudUrl}/status.php`); isNextcloudAccessible = testResponse.ok; lastConnectivityCheck = now; return isNextcloudAccessible; } catch (error) { console.error('Nextcloud connectivity check failed:', error); isNextcloudAccessible = false; lastConnectivityCheck = now; return false; } } async function parseXMLResponse(response: Response): Promise { const text = await response.text(); const parser = new DOMParser(); const xmlDoc = parser.parseFromString(text, 'text/xml'); // Check for parsing errors const parserError = xmlDoc.getElementsByTagName('parsererror'); if (parserError.length > 0) { console.error('XML Parsing Error:', parserError[0].textContent); throw new Error('Failed to parse XML response'); } const result: any = {}; const root = xmlDoc.documentElement; if (root && root.nodeName === 'ocs') { const data = root.getElementsByTagName('data')[0]; if (data) { const children = data.childNodes; for (let i = 0; i < children.length; i++) { const child = children[i]; if (child.nodeType === 1) { // Element node result[child.nodeName] = child.textContent; } } } } return result; } async function createFolder(nextcloudUrl: string, username: string, password: string, folderPath: string) { try { // First check if folder exists const checkResponse = await fetch(`${nextcloudUrl}/remote.php/dav/files/${encodeURIComponent(username)}/${folderPath}`, { method: 'PROPFIND', headers: { 'Authorization': `Basic ${Buffer.from(`${username}:${password}`).toString('base64')}`, 'Depth': '0', }, }); if (checkResponse.ok) { console.log(`Folder ${folderPath} already exists`); return; } // If folder doesn't exist, create it const response = await fetch(`${nextcloudUrl}/remote.php/dav/files/${encodeURIComponent(username)}/${folderPath}`, { method: 'MKCOL', headers: { 'Authorization': `Basic ${Buffer.from(`${username}:${password}`).toString('base64')}`, }, }); if (!response.ok && response.status !== 405) { // 405 means folder already exists const errorText = await response.text(); console.error(`Failed to create folder ${folderPath}:`, { status: response.status, statusText: response.statusText, error: errorText, url: `${nextcloudUrl}/remote.php/dav/files/${encodeURIComponent(username)}/${folderPath}` }); throw new Error(`Failed to create folder ${folderPath}: ${response.status} ${response.statusText}`); } } catch (error) { console.error(`Error creating folder ${folderPath}:`, error); throw error; } } async function ensureFolderStructure(nextcloudUrl: string, username: string, password: string) { try { // First, ensure the Private folder exists await createFolder(nextcloudUrl, username, password, 'Private'); // Create all required subfolders const subfolders = [ 'Private/Diary', 'Private/Health', 'Private/Contacts', 'Private/Notes' ]; for (const folder of subfolders) { await createFolder(nextcloudUrl, username, password, folder); } } catch (error) { console.error('Error creating folder structure:', error); // Don't throw the error, just log it // This way we don't trigger password regeneration } } async function getWebDAVCredentials(nextcloudUrl: string, username: string, adminUsername: string, adminPassword: string, userId: string) { try { // First check if user exists in Nextcloud const userInfoResponse = await fetch(`${nextcloudUrl}/ocs/v1.php/cloud/users/${encodeURIComponent(username)}`, { headers: { 'Authorization': `Basic ${Buffer.from(`${adminUsername}:${adminPassword}`).toString('base64')}`, 'OCS-APIRequest': 'true', }, }); if (userInfoResponse.status === 404) { console.log(`User ${username} does not exist in Nextcloud`); throw new Error(`User ${username} does not exist in Nextcloud`); } if (!userInfoResponse.ok) { throw new Error(`Failed to get user info: ${userInfoResponse.status} ${userInfoResponse.statusText}`); } // Check database for existing credentials const existingCredentials = await prisma.webDAVCredentials.findUnique({ where: { userId } }); if (existingCredentials) { // Verify if the existing credentials still work const verifyResponse = await fetch(`${nextcloudUrl}/remote.php/dav/files/${encodeURIComponent(username)}/`, { method: 'PROPFIND', headers: { 'Authorization': `Basic ${Buffer.from(`${username}:${existingCredentials.password}`).toString('base64')}`, 'Depth': '1', 'Content-Type': 'application/xml', }, body: '', }); if (verifyResponse.ok) { console.log('Using existing credentials from database'); // Update cache credentialsCache.set(userId, { password: existingCredentials.password, timestamp: Date.now() }); return existingCredentials.password; } // If verification failed, delete the invalid credentials console.log('Existing credentials verification failed, removing from database'); await prisma.webDAVCredentials.delete({ where: { userId } }); } // If we get here, we need to generate a new password const newPassword = Math.random().toString(36).slice(-12); console.log('Setting new password for user'); // Set the user's password in Nextcloud const setPasswordResponse = await fetch(`${nextcloudUrl}/ocs/v1.php/cloud/users/${encodeURIComponent(username)}`, { method: 'PUT', headers: { 'Authorization': `Basic ${Buffer.from(`${adminUsername}:${adminPassword}`).toString('base64')}`, 'OCS-APIRequest': 'true', 'Content-Type': 'application/x-www-form-urlencoded', }, body: new URLSearchParams({ key: 'password', value: newPassword, }).toString(), }); if (!setPasswordResponse.ok) { throw new Error(`Failed to set password: ${setPasswordResponse.status} ${setPasswordResponse.statusText}`); } // Store the new credentials in the database await prisma.webDAVCredentials.upsert({ where: { userId }, update: { username: username, password: newPassword }, create: { userId, username: username, password: newPassword } }); // Update cache credentialsCache.set(userId, { password: newPassword, timestamp: Date.now() }); return newPassword; } catch (error) { console.error('Error in getWebDAVCredentials:', error); throw error; } } async function getFolderStructure(nextcloudUrl: string, username: string, password: string): Promise { try { const webdavUrl = `${nextcloudUrl}/remote.php/dav/files/${encodeURIComponent(username)}/Private/`; console.log('Fetching folders from:', webdavUrl); const foldersResponse = await fetch(webdavUrl, { method: 'PROPFIND', headers: { 'Authorization': `Basic ${Buffer.from(`${username}:${password}`).toString('base64')}`, 'Depth': '1', 'Content-Type': 'application/xml', }, body: '', }); console.log('Folders response status:', foldersResponse.status); if (foldersResponse.status === 429) { // Rate limited, wait and retry const retryAfter = foldersResponse.headers.get('Retry-After'); console.log('Rate limited, retrying after:', retryAfter); await sleep((retryAfter ? parseInt(retryAfter) : 5) * 1000); return getFolderStructure(nextcloudUrl, username, password); } if (!foldersResponse.ok) { console.error('Failed to fetch folders:', { status: foldersResponse.status, statusText: foldersResponse.statusText, url: webdavUrl }); throw new Error(`Failed to fetch folders: ${foldersResponse.status} ${foldersResponse.statusText}`); } const folderData = await foldersResponse.text(); console.log('Folder data:', folderData); // Parse the XML response to get folder names const parser = new DOMParser(); const xmlDoc = parser.parseFromString(folderData, 'text/xml'); const responses = Array.from(xmlDoc.getElementsByTagName('d:response')); const folders: string[] = []; for (const response of responses) { const resourceType = response.getElementsByTagName('d:resourcetype')[0]; const isCollection = resourceType?.getElementsByTagName('d:collection').length > 0; if (isCollection) { const href = response.getElementsByTagName('d:href')[0]?.textContent; if (href) { // Extract folder name from href const parts = href.split('/').filter(Boolean); const folderName = decodeURIComponent(parts[parts.length - 1]); if (folderName && folderName !== 'Private') { folders.push(folderName); } } } } console.log('Parsed folders:', folders); return folders; } catch (error) { console.error('Error getting folder structure:', error); throw error; } } export async function GET() { try { const session = await getServerSession(authOptions); if (!session?.user?.email || !session?.user?.id || !session?.accessToken) { return NextResponse.json({ error: 'Unauthorized' }, { status: 401 }); } const nextcloudUrl = process.env.NEXTCLOUD_URL; const adminUsername = process.env.NEXTCLOUD_ADMIN_USERNAME; const adminPassword = process.env.NEXTCLOUD_ADMIN_PASSWORD; if (!nextcloudUrl || !adminUsername || !adminPassword) { console.error('Missing Nextcloud configuration'); return NextResponse.json({ error: 'Nextcloud configuration is missing' }, { status: 500 }); } // Check Nextcloud connectivity with caching const isAccessible = await checkNextcloudConnectivity(nextcloudUrl); if (!isAccessible) { return NextResponse.json({ error: "Nextcloud n'est pas accessible" }, { status: 503 }); } // Use the Keycloak ID as the Nextcloud username const nextcloudUsername = `cube-${session.user.id}`; console.log('Using Nextcloud username:', nextcloudUsername); // Check cache first const cachedData = folderCache.get(nextcloudUsername); if (cachedData) { const cacheAge = Date.now() - cachedData.timestamp; if (cacheAge < 5 * 60 * 1000) { // 5 minutes cache return NextResponse.json({ isConnected: true, folders: cachedData.folders }); } } // Get or create WebDAV credentials const webdavPassword = await getWebDAVCredentials( nextcloudUrl, nextcloudUsername, adminUsername, adminPassword, session.user.id ); if (!webdavPassword) { throw new Error('Failed to get WebDAV credentials'); } // Ensure the folder structure exists await ensureFolderStructure(nextcloudUrl, nextcloudUsername, webdavPassword); // Get folder structure const folders = await getFolderStructure(nextcloudUrl, nextcloudUsername, webdavPassword); // Update cache folderCache.set(nextcloudUsername, { folders, timestamp: Date.now() }); return NextResponse.json({ isConnected: true, folders }); } catch (error) { console.error('Error in Nextcloud status endpoint:', error); return NextResponse.json( { error: error instanceof Error ? error.message : 'An error occurred' }, { status: 500 } ); } }