✅ Updated Admin Dashboard URL: - Changed the Admin Dashboard access path from `/admin` to `/manage` in multiple files for consistency. ✅ Enhanced Middleware Authentication: - Updated middleware to protect new admin routes including `/manage` and `/dashboard`. ✅ Implemented CSRF Protection: - Added CSRF token generation and validation for login and session validation routes. ✅ Introduced Rate Limiting: - Added rate limiting for admin routes and CSRF token requests to enhance security. ✅ Refactored Admin Page: - Created a new admin management page with improved authentication handling and user feedback. 🎯 Overall Improvements: - Strengthened security measures for admin access. - Improved user experience with clearer navigation and feedback. - Streamlined authentication processes for better performance.
89 lines
3.4 KiB
TypeScript
89 lines
3.4 KiB
TypeScript
import { NextRequest, NextResponse } from 'next/server';
|
|
import { projectService } from '@/lib/prisma';
|
|
import { analyticsCache } from '@/lib/redis';
|
|
import { requireAdminAuth, checkRateLimit, getRateLimitHeaders } from '@/lib/auth';
|
|
|
|
export async function GET(request: NextRequest) {
|
|
try {
|
|
// Rate limiting
|
|
const ip = request.headers.get('x-forwarded-for') || request.headers.get('x-real-ip') || 'unknown';
|
|
if (!checkRateLimit(ip, 5, 60000)) { // 5 requests per minute
|
|
return new NextResponse(
|
|
JSON.stringify({ error: 'Rate limit exceeded' }),
|
|
{
|
|
status: 429,
|
|
headers: {
|
|
'Content-Type': 'application/json',
|
|
...getRateLimitHeaders(ip, 5, 60000)
|
|
}
|
|
}
|
|
);
|
|
}
|
|
|
|
// Check admin authentication
|
|
const authError = requireAdminAuth(request);
|
|
if (authError) {
|
|
return authError;
|
|
}
|
|
|
|
// Check cache first
|
|
const cachedStats = await analyticsCache.getOverallStats();
|
|
if (cachedStats) {
|
|
return NextResponse.json(cachedStats);
|
|
}
|
|
|
|
// Get analytics data
|
|
const projectsResult = await projectService.getAllProjects();
|
|
const projects = projectsResult.projects || projectsResult;
|
|
const performanceStats = await projectService.getPerformanceStats();
|
|
|
|
// Calculate analytics metrics
|
|
const analytics = {
|
|
overview: {
|
|
totalProjects: projects.length,
|
|
publishedProjects: projects.filter(p => p.published).length,
|
|
featuredProjects: projects.filter(p => p.featured).length,
|
|
totalViews: projects.reduce((sum, p) => sum + ((p.analytics as Record<string, unknown>)?.views as number || 0), 0),
|
|
totalLikes: projects.reduce((sum, p) => sum + ((p.analytics as Record<string, unknown>)?.likes as number || 0), 0),
|
|
totalShares: projects.reduce((sum, p) => sum + ((p.analytics as Record<string, unknown>)?.shares as number || 0), 0),
|
|
avgLighthouse: projects.length > 0
|
|
? Math.round(projects.reduce((sum, p) => sum + ((p.performance as Record<string, unknown>)?.lighthouse as number || 0), 0) / projects.length)
|
|
: 0
|
|
},
|
|
projects: projects.map(project => ({
|
|
id: project.id,
|
|
title: project.title,
|
|
category: project.category,
|
|
difficulty: project.difficulty,
|
|
views: (project.analytics as Record<string, unknown>)?.views as number || 0,
|
|
likes: (project.analytics as Record<string, unknown>)?.likes as number || 0,
|
|
shares: (project.analytics as Record<string, unknown>)?.shares as number || 0,
|
|
lighthouse: (project.performance as Record<string, unknown>)?.lighthouse as number || 0,
|
|
published: project.published,
|
|
featured: project.featured,
|
|
createdAt: project.createdAt,
|
|
updatedAt: project.updatedAt
|
|
})),
|
|
categories: performanceStats.byCategory,
|
|
difficulties: performanceStats.byDifficulty,
|
|
performance: {
|
|
avgLighthouse: performanceStats.avgLighthouse,
|
|
totalViews: performanceStats.totalViews,
|
|
totalLikes: performanceStats.totalLikes,
|
|
totalShares: performanceStats.totalShares
|
|
}
|
|
};
|
|
|
|
// Cache the results
|
|
await analyticsCache.setOverallStats(analytics);
|
|
|
|
return NextResponse.json(analytics);
|
|
} catch (error) {
|
|
console.error('Analytics dashboard error:', error);
|
|
return NextResponse.json(
|
|
{ error: 'Failed to fetch analytics data' },
|
|
{ status: 500 }
|
|
);
|
|
}
|
|
}
|