diff --git a/data/admin-content-draft.json b/data/admin-content-draft.json
index 8dac51b..2d76a58 100644
--- a/data/admin-content-draft.json
+++ b/data/admin-content-draft.json
@@ -17,17 +17,28 @@
"aboutShowP1": "Verse by Verse with Nate walks through Scripture passage by passage — unpacking the original context, drawing out the meaning, and connecting each verse to how we live today.",
"aboutShowP2": "Whether you're in the car, at the gym, or just looking for something to anchor your day, each episode is designed to feed your faith with solid, practical teaching.",
"aboutNate": "Nate Emmert is a husband, dad, and lifelong student of the Bible from Lynchburg, Va. He's not a pastor or a professor — just someone who fell in love with digging into Scripture and wanted to bring others along for the journey. He created Verse by Verse to make deep Bible study accessible to anyone, whether you've read the Bible your whole life or you're just getting started. No seminary required. No prior knowledge assumed. Just the Word, unpacked verse by verse.",
+ "aboutPhotoUrl": "/images/nate-photo.jpeg",
+ "aboutVerseArtUrl": "/images/hebrews-4-12-verse-art.png",
+ "contactPhotoUrl": "/images/nate-contact-photo.png",
"seriesLabel": "Now Playing",
"seriesTitle": "Study of Titus: Sound Doctrine",
"seriesDescription": "A deep-dive into Paul's letter to Titus — unpacking what it means to build a church and a life on sound doctrine.",
- "seriesImageUrl": "/images/titus-cover.png",
+ "seriesImageUrl": "/uploads/titus-series-1777568297943.png",
"seriesListenUrl": "https://open.spotify.com/show/0Gq1TzoJOdReSZ1gYQi8Xl",
"studyGuideTitle": "Companion Study Guide",
"studyGuideDescription": "Go deeper in your study with the official Verse by Verse companion guide — now available on Amazon.",
"studyGuideUrl": "https://a.co/d/01sG2tOJ",
"shareHeading": "Help one more person hear the Word this week.",
"shareP": "Scan the QR code or text the show link to a friend who needs encouragement today.",
- "customLinks": [],
+ "customLinks": [
+ {
+ "id": "molso9ow",
+ "label": "test",
+ "url": "/uploads/discussion_questions_post-1777565348551.png",
+ "imageUrl": "/uploads/discussion_questions_post-1777565348551.png",
+ "placement": "resources"
+ }
+ ],
"customBlocks": [],
"archivedSeries": [],
"redirects": [
@@ -97,5 +108,5 @@
]
}
},
- "updatedAt": "2026-04-27T20:24:22.589Z"
+ "updatedAt": "2026-04-30T18:06:00.013Z"
}
\ No newline at end of file
diff --git a/data/admin-content.json b/data/admin-content.json
index ecbb29e..5666ead 100644
--- a/data/admin-content.json
+++ b/data/admin-content.json
@@ -17,17 +17,28 @@
"aboutShowP1": "Verse by Verse with Nate walks through Scripture passage by passage — unpacking the original context, drawing out the meaning, and connecting each verse to how we live today.",
"aboutShowP2": "Whether you're in the car, at the gym, or just looking for something to anchor your day, each episode is designed to feed your faith with solid, practical teaching.",
"aboutNate": "Nate Emmert is a husband, dad, and lifelong student of the Bible from Lynchburg, Va. He's not a pastor or a professor — just someone who fell in love with digging into Scripture and wanted to bring others along for the journey. He created Verse by Verse to make deep Bible study accessible to anyone, whether you've read the Bible your whole life or you're just getting started. No seminary required. No prior knowledge assumed. Just the Word, unpacked verse by verse.",
+ "aboutPhotoUrl": "/images/nate-photo.jpeg",
+ "aboutVerseArtUrl": "/images/hebrews-4-12-verse-art.png",
+ "contactPhotoUrl": "/images/nate-contact-photo.png",
"seriesLabel": "Now Playing",
"seriesTitle": "Study of Titus: Sound Doctrine",
"seriesDescription": "A deep-dive into Paul's letter to Titus — unpacking what it means to build a church and a life on sound doctrine.",
- "seriesImageUrl": "/images/titus-cover.png",
+ "seriesImageUrl": "/uploads/titus-series-1777568297943.png",
"seriesListenUrl": "https://open.spotify.com/show/0Gq1TzoJOdReSZ1gYQi8Xl",
"studyGuideTitle": "Companion Study Guide",
"studyGuideDescription": "Go deeper in your study with the official Verse by Verse companion guide — now available on Amazon.",
"studyGuideUrl": "https://a.co/d/01sG2tOJ",
"shareHeading": "Help one more person hear the Word this week.",
"shareP": "Scan the QR code or text the show link to a friend who needs encouragement today.",
- "customLinks": [],
+ "customLinks": [
+ {
+ "id": "molso9ow",
+ "label": "test",
+ "url": "/uploads/discussion_questions_post-1777565348551.png",
+ "imageUrl": "/uploads/discussion_questions_post-1777565348551.png",
+ "placement": "resources"
+ }
+ ],
"customBlocks": [],
"archivedSeries": [],
"redirects": [
@@ -97,5 +108,5 @@
]
}
},
- "updatedAt": "2026-04-27T20:24:19.789Z"
+ "updatedAt": "2026-04-30T18:06:00.017Z"
}
\ No newline at end of file
diff --git a/data/uploads/discussion_questions_post-1777565348551.png b/data/uploads/discussion_questions_post-1777565348551.png
new file mode 100644
index 0000000..74e82e5
Binary files /dev/null and b/data/uploads/discussion_questions_post-1777565348551.png differ
diff --git a/data/uploads/titus-series-1777568297943.png b/data/uploads/titus-series-1777568297943.png
new file mode 100644
index 0000000..a1e353d
Binary files /dev/null and b/data/uploads/titus-series-1777568297943.png differ
diff --git a/server.js b/server.js
index b4c1ce0..a35dfd6 100644
--- a/server.js
+++ b/server.js
@@ -4,23 +4,31 @@ import { createHash, randomUUID } from 'node:crypto'
import path from 'node:path'
import { fileURLToPath } from 'node:url'
import { Resend } from 'resend'
-
-function escapeHtml(value) {
- return String(value)
- .replace(/&/g, '&')
- .replace(//g, '>')
- .replace(/"/g, '"')
- .replace(/'/g, ''')
-}
-
-function splitName(fullName) {
- const parts = fullName.trim().split(/\s+/).filter(Boolean)
- return {
- firstName: parts[0] ?? '',
- lastName: parts.slice(1).join(' '),
- }
-}
+import {
+ sanitizeSiteContent,
+ escapeHtml,
+ escapeXml,
+ buildAbsoluteUrl,
+ injectSeoIntoHtml,
+ normalizeAssetBaseName,
+ inferImageExtensionFromDataUrl,
+ getClientIp,
+ hasVisitorConsent,
+ setConsentCookie,
+ splitName,
+ parseCookies,
+} from './server/helpers.js'
+import {
+ isAdminPasswordConfigured,
+ isValidAdminSession,
+ requireAdminAuth,
+ setAdminSessionCookie,
+ clearAdminSessionCookie,
+ createAdminSession,
+ deleteAdminSession,
+ validateAdminPasswordSetup,
+ isAdminPasswordValid,
+} from './server/auth.js'
const __filename = fileURLToPath(import.meta.url)
const __dirname = path.dirname(__filename)
@@ -31,13 +39,16 @@ const HIT_STATS_FILE = path.join(DATA_DIR, 'hit-stats.json')
const VISITOR_STATS_FILE = path.join(DATA_DIR, 'visitor-stats.json')
const CONTACT_SUBMISSIONS_FILE = path.join(DATA_DIR, 'contact-submissions.json')
const QUESTIONS_FILE = path.join(DATA_DIR, 'questions.json')
+const DRAFT_QUESTIONS_FILE = path.join(DATA_DIR, 'questions-draft.json')
const CHATBOT_FILE = path.join(DATA_DIR, 'chatbot-content.json')
const BACKUP_DIR = path.join(DATA_DIR, 'backups')
const UPLOADS_DIR = path.join(DATA_DIR, 'uploads')
+const UPLOADS_META_FILE = path.join(DATA_DIR, 'uploads-meta.json')
const DIST_DIR = path.join(__dirname, 'dist')
const INDEX_FILE = path.join(DIST_DIR, 'index.html')
const DIST_IMAGES_DIR = path.join(DIST_DIR, 'images')
const PUBLIC_IMAGES_DIR = path.join(__dirname, 'public', 'images')
+validateAdminPasswordSetup()
const TITUS_STUDY_FILE = process.env.TITUS_STUDY_FILE
? path.resolve(__dirname, process.env.TITUS_STUDY_FILE)
: path.join(__dirname, 'A_Study_of_Titus.pdf')
@@ -62,6 +73,50 @@ const DEFAULT_REDIRECT_RULES = [
statusCode: 301,
},
]
+
+function normalizeRedirectPath(value) {
+ if (typeof value !== 'string') return ''
+ const trimmed = value.trim()
+ if (!trimmed) return ''
+ const withSlash = trimmed.startsWith('/') ? trimmed : `/${trimmed}`
+ const normalized = withSlash.replace(/\/+/g, '/')
+ if (normalized === '/') return ''
+ if (normalized.startsWith('/api/') || normalized.startsWith('/admin')) return ''
+ return normalized
+}
+
+function sanitizeUrl(value) {
+ if (typeof value !== 'string') return ''
+ const trimmed = value.trim()
+ if (!trimmed) return ''
+ if (trimmed.startsWith('/')) return trimmed
+ if (/^https?:\/\//i.test(trimmed)) return trimmed
+ return ''
+}
+
+function sanitizeRedirectRules(value) {
+ const source = Array.isArray(value) ? value : []
+ const seen = new Set()
+ const out = []
+
+ for (const item of source) {
+ const pathValue = normalizeRedirectPath(item?.path)
+ const target = sanitizeUrl(item?.target)
+ const statusCode = Number(item?.statusCode) === 302 ? 302 : 301
+ if (!pathValue || !target) continue
+ if (seen.has(pathValue)) continue
+ seen.add(pathValue)
+ out.push({
+ id: typeof item?.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ path: pathValue,
+ target,
+ statusCode,
+ })
+ }
+
+ return out.length > 0 ? out : DEFAULT_REDIRECT_RULES
+}
+
const DEFAULT_SEO = {
title: 'Verse by Verse with Nate',
description: 'Verse by Verse with Nate explores Scripture one verse at a time with practical Bible teaching.',
@@ -95,130 +150,8 @@ const DEFAULT_PUBLISH_STATE = {
let cachedSiteContent = null
let cachedDraftSiteContent = null
let publishState = { ...DEFAULT_PUBLISH_STATE }
-
-function sanitizeUrl(value) {
- if (typeof value !== 'string') return ''
- const trimmed = value.trim()
- if (!trimmed) return ''
- if (trimmed.startsWith('/')) return trimmed
- if (/^https?:\/\//i.test(trimmed)) return trimmed
- return ''
-}
-
-function normalizeRedirectPath(value) {
- if (typeof value !== 'string') return ''
- const trimmed = value.trim()
- if (!trimmed) return ''
- const withSlash = trimmed.startsWith('/') ? trimmed : `/${trimmed}`
- const normalized = withSlash.replace(/\/+/g, '/')
- if (normalized === '/') return ''
- if (normalized.startsWith('/api/') || normalized.startsWith('/admin')) return ''
- return normalized
-}
-
-function normalizeSitemapPath(value) {
- if (typeof value !== 'string') return ''
- const trimmed = value.trim()
- if (!trimmed) return ''
- if (trimmed === '/') return '/'
- return normalizeRedirectPath(trimmed)
-}
-
-function sanitizeRedirectRules(value) {
- const source = Array.isArray(value) ? value : []
- const seen = new Set()
- const out = []
-
- for (const item of source) {
- const pathValue = normalizeRedirectPath(item?.path)
- const target = sanitizeUrl(item?.target)
- const statusCode = Number(item?.statusCode) === 302 ? 302 : 301
- if (!pathValue || !target) continue
- if (seen.has(pathValue)) continue
- seen.add(pathValue)
- out.push({
- id: typeof item?.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
- path: pathValue,
- target,
- statusCode,
- })
- }
-
- return out.length > 0 ? out : DEFAULT_REDIRECT_RULES
-}
-
-function sanitizeFeaturedLinks(value) {
- const source = Array.isArray(value) ? value : []
- return source
- .filter(item => item && typeof item === 'object')
- .map(item => {
- const discussionQuestions = Array.isArray(item.discussionQuestions)
- ? item.discussionQuestions
- .filter(question => typeof question === 'string')
- .map(question => question.trim())
- .filter(Boolean)
- .slice(0, 30)
- : []
-
- return {
- id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
- title: typeof item.title === 'string' ? item.title.trim().slice(0, 140) : '',
- episodeNumber: typeof item.episodeNumber === 'string' ? item.episodeNumber.trim().slice(0, 20) : '',
- summary: typeof item.summary === 'string' ? item.summary.trim().slice(0, 600) : '',
- url: sanitizeUrl(item.url),
- embedUrl: sanitizeUrl(item.embedUrl),
- showNotes: typeof item.showNotes === 'string' ? item.showNotes.trim().slice(0, 10000) : '',
- discussionQuestions,
- }
- })
- .filter(item => item.title || item.summary || item.url || item.embedUrl || item.showNotes || item.discussionQuestions.length > 0)
-}
-
-function sanitizeSiteContent(siteContent) {
- if (!siteContent || typeof siteContent !== 'object' || Array.isArray(siteContent)) return {}
-
- const seo = siteContent.seo && typeof siteContent.seo === 'object' ? siteContent.seo : {}
- const legal = siteContent.legal && typeof siteContent.legal === 'object' ? siteContent.legal : {}
-
- return {
- ...siteContent,
- redirects: sanitizeRedirectRules(siteContent.redirects),
- podcastFeaturedLinks: sanitizeFeaturedLinks(siteContent.podcastFeaturedLinks ?? DEFAULT_PODCAST_FEATURED_LINKS),
- seo: {
- title: typeof seo.title === 'string' && seo.title.trim() ? seo.title.trim().slice(0, 120) : DEFAULT_SEO.title,
- description: typeof seo.description === 'string' && seo.description.trim() ? seo.description.trim().slice(0, 240) : DEFAULT_SEO.description,
- ogTitle: typeof seo.ogTitle === 'string' && seo.ogTitle.trim() ? seo.ogTitle.trim().slice(0, 120) : DEFAULT_SEO.ogTitle,
- ogDescription: typeof seo.ogDescription === 'string' && seo.ogDescription.trim() ? seo.ogDescription.trim().slice(0, 240) : DEFAULT_SEO.ogDescription,
- ogImage: sanitizeUrl(seo.ogImage) || DEFAULT_SEO.ogImage,
- canonicalUrl: sanitizeUrl(seo.canonicalUrl) || DEFAULT_SEO.canonicalUrl,
- robotsPolicy: typeof seo.robotsPolicy === 'string' && seo.robotsPolicy.trim() ? seo.robotsPolicy.trim() : DEFAULT_SEO.robotsPolicy,
- sitemapPaths: Array.isArray(seo.sitemapPaths)
- ? seo.sitemapPaths
- .map(pathItem => normalizeSitemapPath(pathItem))
- .filter(Boolean)
- : [...DEFAULT_SEO.sitemapPaths],
- },
- legal: {
- privacyTitle: typeof legal.privacyTitle === 'string' && legal.privacyTitle.trim() ? legal.privacyTitle.trim().slice(0, 120) : DEFAULT_LEGAL.privacyTitle,
- privacyBody: Array.isArray(legal.privacyBody) && legal.privacyBody.length > 0
- ? legal.privacyBody.filter(line => typeof line === 'string').map(line => line.trim()).filter(Boolean).slice(0, 20)
- : [...DEFAULT_LEGAL.privacyBody],
- termsTitle: typeof legal.termsTitle === 'string' && legal.termsTitle.trim() ? legal.termsTitle.trim().slice(0, 120) : DEFAULT_LEGAL.termsTitle,
- termsBody: Array.isArray(legal.termsBody) && legal.termsBody.length > 0
- ? legal.termsBody.filter(line => typeof line === 'string').map(line => line.trim()).filter(Boolean).slice(0, 20)
- : [...DEFAULT_LEGAL.termsBody],
- },
- }
-}
-
-function escapeXml(value) {
- return String(value)
- .replace(/&/g, '&')
- .replace(//g, '>')
- .replace(/"/g, '"')
- .replace(/'/g, ''')
-}
+let draftQuestions = null
+let draftQuestionsWritePromise = Promise.resolve()
async function loadSiteContentFile(filePath) {
const raw = await readFile(filePath, 'utf8')
@@ -252,61 +185,50 @@ async function refreshContentCaches() {
}
}
-function buildAbsoluteUrl(baseUrl, maybeRelativePath) {
- const safeBase = typeof baseUrl === 'string' && baseUrl.trim() ? baseUrl.trim() : DEFAULT_SEO.canonicalUrl
- const root = safeBase.endsWith('/') ? safeBase.slice(0, -1) : safeBase
- if (typeof maybeRelativePath !== 'string' || !maybeRelativePath.trim()) return root
- const value = maybeRelativePath.trim()
- if (/^https?:\/\//i.test(value)) return value
- if (value.startsWith('/')) return `${root}${value}`
- return `${root}/${value}`
+async function loadDraftQuestionsFromDisk() {
+ return readFile(DRAFT_QUESTIONS_FILE, 'utf8')
+ .then(raw => {
+ const parsed = JSON.parse(raw)
+ if (Array.isArray(parsed)) {
+ draftQuestions = parsed.slice(0, MAX_QUESTIONS)
+ } else if (Array.isArray(parsed?.questions)) {
+ draftQuestions = parsed.questions.slice(0, MAX_QUESTIONS)
+ } else {
+ draftQuestions = null
+ }
+ if (typeof parsed?.updatedAt === 'string') {
+ publishState.draftUpdatedAt = parsed.updatedAt
+ }
+ })
+ .catch(() => {
+ draftQuestions = null
+ })
}
-function injectSeoIntoHtml(html, siteContent) {
- const seo = siteContent?.seo ?? DEFAULT_SEO
- const title = seo.title || DEFAULT_SEO.title
- const description = seo.description || DEFAULT_SEO.description
- const ogTitle = seo.ogTitle || title
- const ogDescription = seo.ogDescription || description
- const canonical = buildAbsoluteUrl(seo.canonicalUrl || DEFAULT_SEO.canonicalUrl, '/')
- const ogImage = buildAbsoluteUrl(canonical, seo.ogImage || DEFAULT_SEO.ogImage)
- const robots = seo.robotsPolicy || DEFAULT_SEO.robotsPolicy
-
- return html
- .replace(/
[\s\S]*?<\/title>/i, `${escapeHtml(title)}`)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
- .replace(//i, ``)
+function ensureDraftQuestions() {
+ if (draftQuestions !== null) return
+ draftQuestions = questions.slice(0, MAX_QUESTIONS)
}
-function normalizeAssetBaseName(name) {
- if (typeof name !== 'string') return `upload-${Date.now()}`
- const cleaned = name
- .toLowerCase()
- .replace(/[^a-z0-9._-]+/g, '-')
- .replace(/-+/g, '-')
- .replace(/^-|-$/g, '')
- return cleaned || `upload-${Date.now()}`
+async function readUploadsMetadata() {
+ try {
+ const raw = await readFile(UPLOADS_META_FILE, 'utf8')
+ return JSON.parse(raw)
+ } catch {
+ return {}
+ }
}
-function inferImageExtensionFromDataUrl(dataUrl) {
- if (typeof dataUrl !== 'string') return null
- if (dataUrl.startsWith('data:image/png;base64,')) return '.png'
- if (dataUrl.startsWith('data:image/jpeg;base64,')) return '.jpg'
- if (dataUrl.startsWith('data:image/webp;base64,')) return '.webp'
- if (dataUrl.startsWith('data:image/gif;base64,')) return '.gif'
- return null
+async function writeUploadsMetadata(metadata) {
+ await mkdir(DATA_DIR, { recursive: true })
+ await writeFile(UPLOADS_META_FILE, JSON.stringify(metadata, null, 2), 'utf8')
}
async function listUploadedAssets() {
await mkdir(UPLOADS_DIR, { recursive: true })
const files = await readdir(UPLOADS_DIR)
const imageFiles = files.filter(name => /\.(png|jpe?g|webp|gif)$/i.test(name)).sort()
+ const metadata = await readUploadsMetadata()
const withStats = await Promise.all(imageFiles.map(async filename => {
const info = await stat(path.join(UPLOADS_DIR, filename))
@@ -315,6 +237,7 @@ async function listUploadedAssets() {
url: `/uploads/${filename}`,
sizeBytes: info.size,
updatedAt: info.mtime.toISOString(),
+ tags: Array.isArray(metadata[filename]) ? metadata[filename].filter(tag => typeof tag === 'string') : [],
}
}))
@@ -362,13 +285,11 @@ let hitStatsWritePromise = Promise.resolve()
const VISITOR_COOKIE = 'vbn_vid'
const CONSENT_COOKIE = 'vbn_analytics_consent'
-const ADMIN_SESSION_COOKIE = 'vbn_admin_session'
const MAX_RECENT_VISITS = 1000
const VISITOR_RETENTION_DAYS_DEFAULT = 180
const BACKUP_RETENTION_DAYS = 30
const BACKUP_INTERVAL_MS = 24 * 60 * 60 * 1000
const ADMIN_SESSION_TTL_MS = 7 * 24 * 60 * 60 * 1000
-const ADMIN_PASSWORD = process.env.ADMIN_PASSWORD ?? 'change-me-admin-password'
const EMPTY_VISITOR_STATS = {
totalVisits: 0,
@@ -397,47 +318,6 @@ let lastHitStatsWrite = { ok: true, at: null, error: null }
let lastBackupStatus = { ok: true, at: null, error: null, file: null }
let lastCachePurgeStatus = { ok: true, at: null, error: null }
let lastDeployHookStatus = { ok: true, at: null, error: null }
-const adminSessions = new Map()
-
-function sha256(value) {
- return createHash('sha256').update(value).digest('hex')
-}
-
-function isAdminPasswordConfigured() {
- return ADMIN_PASSWORD !== 'change-me-admin-password'
-}
-
-function isValidAdminSession(req) {
- const cookies = parseCookies(req.headers.cookie)
- const sessionToken = cookies[ADMIN_SESSION_COOKIE]
- if (!sessionToken) return false
-
- const expiresAt = adminSessions.get(sessionToken)
- if (!expiresAt) return false
- if (expiresAt <= Date.now()) {
- adminSessions.delete(sessionToken)
- return false
- }
-
- adminSessions.set(sessionToken, Date.now() + ADMIN_SESSION_TTL_MS)
- return true
-}
-
-function setAdminSessionCookie(res, token) {
- res.append('Set-Cookie', `${ADMIN_SESSION_COOKIE}=${encodeURIComponent(token)}; Max-Age=${Math.floor(ADMIN_SESSION_TTL_MS / 1000)}; Path=/; HttpOnly; SameSite=Lax`)
-}
-
-function clearAdminSessionCookie(res) {
- res.append('Set-Cookie', `${ADMIN_SESSION_COOKIE}=; Max-Age=0; Path=/; HttpOnly; SameSite=Lax`)
-}
-
-function requireAdminAuth(req, res, next) {
- if (!isValidAdminSession(req)) {
- res.status(401).json({ message: 'Unauthorized' })
- return
- }
- next()
-}
function normalizeIp(rawIp) {
if (!rawIp) return 'unknown'
@@ -459,45 +339,6 @@ function normalizeIp(rawIp) {
return ip || 'unknown'
}
-function getClientIp(req) {
- const forwarded = req.headers['x-forwarded-for']
- if (forwarded) {
- return normalizeIp(forwarded)
- }
- return normalizeIp(req.ip)
-}
-
-function parseCookies(cookieHeader) {
- if (!cookieHeader) return {}
-
- return cookieHeader
- .split(';')
- .map(v => v.trim())
- .filter(Boolean)
- .reduce((acc, part) => {
- const idx = part.indexOf('=')
- if (idx === -1) return acc
- const key = part.slice(0, idx).trim()
- const value = part.slice(idx + 1).trim()
- try {
- acc[key] = decodeURIComponent(value)
- } catch {
- acc[key] = value
- }
- return acc
- }, {})
-}
-
-function hasVisitorConsent(req) {
- const cookies = parseCookies(req.headers.cookie)
- return cookies[CONSENT_COOKIE] === 'yes'
-}
-
-function setConsentCookie(res, consent) {
- const value = consent ? 'yes' : 'no'
- res.append('Set-Cookie', `${CONSENT_COOKIE}=${value}; Max-Age=31536000; Path=/; SameSite=Lax`)
-}
-
function isPrivateOrLocalIp(ip) {
return (
ip === '127.0.0.1'
@@ -1214,6 +1055,17 @@ app.post('/api/admin-content/publish', requireAdminAuth, async (_req, res) => {
cachedSiteContent = source.siteContent
publishState.publishedAt = publishedAt
+
+ if (draftQuestions !== null) {
+ questions = draftQuestions.slice(0, MAX_QUESTIONS)
+ await mkdir(DATA_DIR, { recursive: true })
+ await writeFile(
+ QUESTIONS_FILE,
+ JSON.stringify({ questions, updatedAt: publishedAt }, null, 2),
+ 'utf8',
+ )
+ }
+
await createBackupSnapshot('post-publish')
res.json({ ok: true, publishedAt })
@@ -1254,6 +1106,9 @@ app.post('/api/admin-assets', requireAdminAuth, async (req, res) => {
await mkdir(UPLOADS_DIR, { recursive: true })
await writeFile(path.join(UPLOADS_DIR, finalName), buffer)
+ const metadata = await readUploadsMetadata()
+ metadata[finalName] = []
+ await writeUploadsMetadata(metadata)
res.json({ ok: true, asset: { filename: finalName, url: `/uploads/${finalName}` } })
} catch {
@@ -1261,6 +1116,31 @@ app.post('/api/admin-assets', requireAdminAuth, async (req, res) => {
}
})
+app.patch('/api/admin-assets/:filename', requireAdminAuth, async (req, res) => {
+ try {
+ const { filename } = req.params
+ if (typeof filename !== 'string' || filename.includes('/') || filename.includes('..')) {
+ res.status(400).json({ message: 'Invalid filename.' })
+ return
+ }
+
+ const tags = Array.isArray(req.body?.tags)
+ ? req.body.tags.filter(tag => typeof tag === 'string').map(tag => tag.trim()).filter(Boolean)
+ : []
+
+ const filePath = path.join(UPLOADS_DIR, filename)
+ await stat(filePath)
+
+ const metadata = await readUploadsMetadata()
+ metadata[filename] = tags
+ await writeUploadsMetadata(metadata)
+
+ res.json({ ok: true, tags })
+ } catch {
+ res.status(404).json({ message: 'Asset not found.' })
+ }
+})
+
app.delete('/api/admin-assets/:filename', requireAdminAuth, async (req, res) => {
try {
const { filename } = req.params
@@ -1270,6 +1150,9 @@ app.delete('/api/admin-assets/:filename', requireAdminAuth, async (req, res) =>
}
await unlink(path.join(UPLOADS_DIR, filename))
+ const metadata = await readUploadsMetadata()
+ delete metadata[filename]
+ await writeUploadsMetadata(metadata)
res.json({ ok: true })
} catch {
res.status(404).json({ message: 'Asset not found.' })
@@ -1415,6 +1298,23 @@ function queueQuestionsWrite() {
})
}
+function queueDraftQuestionsWrite() {
+ if (draftQuestions === null) return
+ draftQuestionsWritePromise = draftQuestionsWritePromise
+ .then(async () => {
+ await mkdir(DATA_DIR, { recursive: true })
+ await writeFile(
+ DRAFT_QUESTIONS_FILE,
+ JSON.stringify({ questions: draftQuestions, updatedAt: new Date().toISOString() }, null, 2),
+ 'utf8',
+ )
+ publishState.draftUpdatedAt = new Date().toISOString()
+ })
+ .catch(err => {
+ console.error('[draft-questions] failed to write draft questions:', err)
+ })
+}
+
function loadQuestionsFromDisk() {
return readFile(QUESTIONS_FILE, 'utf8')
.then(raw => {
@@ -1446,13 +1346,12 @@ app.post('/api/admin-auth/login', (req, res) => {
return
}
- if (sha256(password) !== sha256(ADMIN_PASSWORD)) {
+ if (!isAdminPasswordValid(password)) {
res.status(401).json({ message: 'Invalid password.' })
return
}
- const sessionToken = randomUUID()
- adminSessions.set(sessionToken, Date.now() + ADMIN_SESSION_TTL_MS)
+ const sessionToken = createAdminSession()
setAdminSessionCookie(res, sessionToken)
res.json({ ok: true })
})
@@ -1460,9 +1359,7 @@ app.post('/api/admin-auth/login', (req, res) => {
app.post('/api/admin-auth/logout', (req, res) => {
const cookies = parseCookies(req.headers.cookie)
const sessionToken = cookies[ADMIN_SESSION_COOKIE]
- if (sessionToken) {
- adminSessions.delete(sessionToken)
- }
+ deleteAdminSession(sessionToken)
clearAdminSessionCookie(res)
res.json({ ok: true })
})
@@ -1728,6 +1625,70 @@ app.post('/api/study-downloads/titus', studyDownloadRateLimit, async (req, res)
}
})
+app.post('/api/resource-download', studyDownloadRateLimit, async (req, res) => {
+ try {
+ const { resourceId, firstName, lastName, email, subscribe, _honey } = req.body ?? {}
+
+ if (_honey) {
+ res.json({ ok: true })
+ return
+ }
+
+ if (!resourceId || typeof resourceId !== 'string') {
+ res.status(400).json({ message: 'Resource ID is required.' })
+ return
+ }
+
+ const published = await loadSiteContentFile(DATA_FILE)
+ const resource = Array.isArray(published?.siteContent?.customLinks)
+ ? published.siteContent.customLinks.find(link => link.id === resourceId && link.placement === 'resources')
+ : undefined
+
+ if (!resource || typeof resource.url !== 'string' || !resource.url.trim()) {
+ res.status(400).json({ message: 'Resource not found.' })
+ return
+ }
+
+ if (!firstName || typeof firstName !== 'string' || firstName.trim().length < 1 || firstName.trim().length > 100) {
+ res.status(400).json({ message: 'First name is required.' })
+ return
+ }
+
+ if (!lastName || typeof lastName !== 'string' || lastName.trim().length < 1 || lastName.trim().length > 100) {
+ res.status(400).json({ message: 'Last name is required.' })
+ return
+ }
+
+ if (!email || typeof email !== 'string' || !/^[^\s@]+@[^\s@]+\.[^\s@]+$/.test(email.trim())) {
+ res.status(400).json({ message: 'A valid email address is required.' })
+ return
+ }
+
+ const trimmedFirstName = firstName.trim()
+ const trimmedLastName = lastName.trim()
+ const trimmedName = `${trimmedFirstName} ${trimmedLastName}`.trim()
+ const trimmedEmail = email.trim()
+ const wantsSubscribe = subscribe !== false
+
+ addContactSubmission({
+ name: trimmedName,
+ email: trimmedEmail,
+ message: `Requested resource download: ${resource.label ?? resource.url}`,
+ messageType: 'general',
+ subscribe: wantsSubscribe,
+ })
+
+ if (wantsSubscribe) {
+ await syncContactToResend(trimmedName, trimmedEmail)
+ }
+
+ res.json({ ok: true, downloadUrl: resource.url.trim() })
+ } catch (err) {
+ console.error('[resource-download] request error:', err)
+ res.status(500).json({ message: 'Failed to process your request. Please try again.' })
+ }
+})
+
app.get('/api/study-downloads/titus/file', async (req, res) => {
const token = typeof req.query?.token === 'string' ? req.query.token : ''
if (!token || !consumeTitusDownloadToken(token)) {
@@ -1808,6 +1769,11 @@ app.post('/api/contact', contactRateLimit, async (req, res) => {
}
questions.unshift(question)
questions = questions.slice(0, MAX_QUESTIONS)
+ if (draftQuestions !== null) {
+ draftQuestions.unshift(question)
+ draftQuestions = draftQuestions.slice(0, MAX_QUESTIONS)
+ queueDraftQuestionsWrite()
+ }
queueQuestionsWrite()
}
const resend = new Resend(process.env.RESEND_API_KEY)
@@ -1874,7 +1840,7 @@ app.post('/api/contact', contactRateLimit, async (req, res) => {
// Get all questions (for admin)
app.get('/api/admin-questions', requireAdminAuth, (_req, res) => {
- res.json({ questions })
+ res.json({ questions: draftQuestions ?? questions })
})
// Get only approved public questions (for homepage)
@@ -1893,7 +1859,8 @@ app.post('/api/admin-questions/:id/answer', requireAdminAuth, (req, res) => {
return
}
- const question = questions.find(q => q.id === id)
+ ensureDraftQuestions()
+ const question = draftQuestions.find(q => q.id === id)
if (!question) {
res.status(404).json({ message: 'Question not found.' })
return
@@ -1901,7 +1868,7 @@ app.post('/api/admin-questions/:id/answer', requireAdminAuth, (req, res) => {
question.answer = answer.trim()
question.answeredAt = new Date().toISOString()
- queueQuestionsWrite()
+ queueDraftQuestionsWrite()
res.json({ ok: true, question })
})
@@ -1911,7 +1878,8 @@ app.post('/api/admin-questions/:id/approve', requireAdminAuth, (req, res) => {
const { id } = req.params
const { approved } = req.body ?? {}
- const question = questions.find(q => q.id === id)
+ ensureDraftQuestions()
+ const question = draftQuestions.find(q => q.id === id)
if (!question) {
res.status(404).json({ message: 'Question not found.' })
return
@@ -1919,7 +1887,7 @@ app.post('/api/admin-questions/:id/approve', requireAdminAuth, (req, res) => {
question.isApproved = approved === true
question.approvedAt = approved === true ? new Date().toISOString() : null
- queueQuestionsWrite()
+ queueDraftQuestionsWrite()
res.json({ ok: true, question })
})
@@ -1927,15 +1895,16 @@ app.post('/api/admin-questions/:id/approve', requireAdminAuth, (req, res) => {
// Delete a question (admin)
app.delete('/api/admin-questions/:id', requireAdminAuth, (req, res) => {
const { id } = req.params
- const index = questions.findIndex(q => q.id === id)
+ ensureDraftQuestions()
+ const index = draftQuestions.findIndex(q => q.id === id)
if (index === -1) {
res.status(404).json({ message: 'Question not found.' })
return
}
- questions.splice(index, 1)
- queueQuestionsWrite()
+ draftQuestions.splice(index, 1)
+ queueDraftQuestionsWrite()
res.json({ ok: true })
})
@@ -2091,6 +2060,7 @@ Promise.all([
loadVisitorStatsFromDisk(),
loadContactSubmissionsFromDisk(),
loadQuestionsFromDisk(),
+ loadDraftQuestionsFromDisk(),
loadChatbotFromDisk(),
refreshContentCaches(),
])
diff --git a/server/auth.js b/server/auth.js
new file mode 100644
index 0000000..b1f8225
--- /dev/null
+++ b/server/auth.js
@@ -0,0 +1,85 @@
+import { createHash, randomUUID } from 'node:crypto'
+import { parseCookies } from './helpers.js'
+
+const ADMIN_SESSION_COOKIE = 'vbn_admin_session'
+const ADMIN_SESSION_TTL_MS = 7 * 24 * 60 * 60 * 1000
+const ADMIN_PASSWORD = process.env.ADMIN_PASSWORD
+const adminSessions = new Map()
+
+function cookieFlags() {
+ return process.env.NODE_ENV === 'production' ? '; Secure' : ''
+}
+
+export function sha256(value) {
+ return createHash('sha256').update(String(value)).digest('hex')
+}
+
+export function isAdminPasswordConfigured() {
+ return Boolean(ADMIN_PASSWORD)
+}
+
+export function validateAdminPasswordSetup() {
+ if (!isAdminPasswordConfigured() && process.env.NODE_ENV === 'production') {
+ throw new Error('ADMIN_PASSWORD is required in production.')
+ }
+
+ if (!isAdminPasswordConfigured()) {
+ console.warn('ADMIN_PASSWORD is not configured; admin routes will remain disabled until the environment is configured.')
+ }
+}
+
+export function isAdminPasswordValid(password) {
+ if (!isAdminPasswordConfigured()) return false
+ return sha256(password) === sha256(ADMIN_PASSWORD)
+}
+
+export function createAdminSession() {
+ const token = randomUUID()
+ adminSessions.set(token, Date.now() + ADMIN_SESSION_TTL_MS)
+ return token
+}
+
+export function deleteAdminSession(token) {
+ if (token) {
+ adminSessions.delete(token)
+ }
+}
+
+export function isValidAdminSession(req) {
+ if (!isAdminPasswordConfigured()) return false
+
+ const cookies = parseCookies(req.headers.cookie)
+ const sessionToken = cookies[ADMIN_SESSION_COOKIE]
+ if (!sessionToken) return false
+
+ const expiresAt = adminSessions.get(sessionToken)
+ if (!expiresAt || expiresAt <= Date.now()) {
+ adminSessions.delete(sessionToken)
+ return false
+ }
+
+ adminSessions.set(sessionToken, Date.now() + ADMIN_SESSION_TTL_MS)
+ return true
+}
+
+export function setAdminSessionCookie(res, token) {
+ res.append(
+ 'Set-Cookie',
+ `${ADMIN_SESSION_COOKIE}=${encodeURIComponent(token)}; Max-Age=${Math.floor(ADMIN_SESSION_TTL_MS / 1000)}; Path=/; HttpOnly; SameSite=Lax${cookieFlags()}`,
+ )
+}
+
+export function clearAdminSessionCookie(res) {
+ res.append(
+ 'Set-Cookie',
+ `${ADMIN_SESSION_COOKIE}=; Max-Age=0; Path=/; HttpOnly; SameSite=Lax${cookieFlags()}`,
+ )
+}
+
+export function requireAdminAuth(req, res, next) {
+ if (!isValidAdminSession(req)) {
+ res.status(401).json({ message: 'Unauthorized' })
+ return
+ }
+ next()
+}
diff --git a/server/helpers.js b/server/helpers.js
new file mode 100644
index 0000000..aad6fdf
--- /dev/null
+++ b/server/helpers.js
@@ -0,0 +1,412 @@
+import { randomUUID } from 'node:crypto'
+
+export const DEFAULT_REDIRECT_RULES = [
+ {
+ id: 'spotify',
+ path: '/spotify',
+ target: 'https://open.spotify.com/show/0Gq1TzoJOdReSZ1gYQi8Xl',
+ statusCode: 301,
+ },
+ {
+ id: 'apple',
+ path: '/apple',
+ target: 'https://podcasts.apple.com/search?term=Verse+by+Verse+with+Nate',
+ statusCode: 301,
+ },
+ {
+ id: 'amazon',
+ path: '/amazon',
+ target: 'https://music.amazon.com/podcasts/202322bf-db86-4e7d-9a6b-4db7cbccbccf/verse-by-verse-with-nate',
+ statusCode: 301,
+ },
+]
+
+export const DEFAULT_SEO = {
+ title: 'Verse by Verse with Nate',
+ description: 'Verse by Verse with Nate explores Scripture one verse at a time with practical Bible teaching.',
+ ogTitle: 'Verse by Verse with Nate',
+ ogDescription: 'A Journey Through Scripture - verse by verse, nugget by nugget.',
+ ogImage: '/images/podcast-art.jpeg',
+ canonicalUrl: 'https://versebyversewithnate.us/',
+ robotsPolicy: 'index,follow',
+ sitemapPaths: ['/', '/start-here', '/questions', '/privacy', '/terms'],
+}
+
+export const DEFAULT_LEGAL = {
+ privacyTitle: 'Privacy Policy',
+ privacyBody: [
+ 'We respect your privacy and collect limited data to operate and improve this site.',
+ 'If you consent to analytics cookies, we may store masked IP-based location signals and returning visitor activity.',
+ 'Contact form details are used only to respond to your message and ministry communication requests.',
+ ],
+ termsTitle: 'Terms',
+ termsBody: [
+ 'Content on this site is for informational and ministry purposes.',
+ 'External links are provided for convenience and are subject to third-party policies.',
+ 'By using this site, you agree to lawful use and respectful communication.',
+ ],
+}
+
+export const DEFAULT_PODCAST_FEATURED_LINKS = []
+export const DEFAULT_PUBLISH_STATE = {
+ draftUpdatedAt: null,
+ publishedAt: null,
+}
+
+export function escapeHtml(value) {
+ return String(value)
+ .replace(/&/g, '&')
+ .replace(//g, '>')
+ .replace(/"/g, '"')
+ .replace(/'/g, ''')
+}
+
+export function splitName(fullName) {
+ const parts = String(fullName).trim().split(/\s+/).filter(Boolean)
+ return {
+ firstName: parts[0] ?? '',
+ lastName: parts.slice(1).join(' '),
+ }
+}
+
+export function sanitizeUrl(value) {
+ if (typeof value !== 'string') return ''
+ const trimmed = value.trim()
+ if (!trimmed) return ''
+ if (trimmed.startsWith('/')) return trimmed
+ if (/^https?:\/\//i.test(trimmed)) return trimmed
+ return ''
+}
+
+export function normalizeRedirectPath(value) {
+ if (typeof value !== 'string') return ''
+ const trimmed = value.trim()
+ if (!trimmed) return ''
+ const withSlash = trimmed.startsWith('/') ? trimmed : `/${trimmed}`
+ const normalized = withSlash.replace(/\/+/g, '/')
+ if (normalized === '/') return ''
+ if (normalized.startsWith('/api/') || normalized.startsWith('/admin')) return ''
+ return normalized
+}
+
+export function normalizeSitemapPath(value) {
+ if (typeof value !== 'string') return ''
+ const trimmed = value.trim()
+ if (!trimmed) return ''
+ if (trimmed === '/') return '/'
+ return normalizeRedirectPath(trimmed)
+}
+
+export function sanitizeRedirectRules(value) {
+ const source = Array.isArray(value) ? value : []
+ const seen = new Set()
+ const out = []
+
+ for (const item of source) {
+ const pathValue = normalizeRedirectPath(item?.path)
+ const target = sanitizeUrl(item?.target)
+ const statusCode = Number(item?.statusCode) === 302 ? 302 : 301
+ if (!pathValue || !target) continue
+ if (seen.has(pathValue)) continue
+ seen.add(pathValue)
+ out.push({
+ id: typeof item?.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ path: pathValue,
+ target,
+ statusCode,
+ })
+ }
+
+ return out.length > 0 ? out : DEFAULT_REDIRECT_RULES
+}
+
+export function sanitizeFeaturedLinks(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => {
+ const discussionQuestions = Array.isArray(item.discussionQuestions)
+ ? item.discussionQuestions
+ .filter(question => typeof question === 'string')
+ .map(question => question.trim())
+ .filter(Boolean)
+ .slice(0, 30)
+ : []
+
+ return {
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ title: typeof item.title === 'string' ? item.title.trim().slice(0, 140) : '',
+ episodeNumber: typeof item.episodeNumber === 'string' ? item.episodeNumber.trim().slice(0, 20) : '',
+ summary: typeof item.summary === 'string' ? item.summary.trim().slice(0, 600) : '',
+ url: sanitizeUrl(item.url),
+ embedUrl: sanitizeUrl(item.embedUrl),
+ showNotes: typeof item.showNotes === 'string' ? item.showNotes.trim().slice(0, 10000) : '',
+ discussionQuestions,
+ }
+ })
+ .filter(
+ item =>
+ item.title ||
+ item.summary ||
+ item.url ||
+ item.embedUrl ||
+ item.showNotes ||
+ item.discussionQuestions.length > 0,
+ )
+}
+
+function sanitizeCustomLinks(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => {
+ const placement =
+ item?.placement === 'platforms' || item?.placement === 'footer' || item?.placement === 'resources'
+ ? item.placement
+ : 'footer'
+
+ return {
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ label: typeof item.label === 'string' ? item.label.trim().slice(0, 140) : '',
+ url: sanitizeUrl(item.url),
+ imageUrl: sanitizeUrl(item.imageUrl),
+ placement,
+ }
+ })
+ .filter(item => item.label && item.url)
+}
+
+function sanitizeCustomBlocks(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => ({
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ heading: typeof item.heading === 'string' ? item.heading.trim().slice(0, 140) : '',
+ body: typeof item.body === 'string' ? item.body.trim().slice(0, 4000) : '',
+ }))
+ .filter(item => item.heading || item.body)
+}
+
+function sanitizeArchivedSeriesResourceLinks(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => ({
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ label: typeof item.label === 'string' ? item.label.trim().slice(0, 120) : '',
+ url: sanitizeUrl(item.url),
+ }))
+ .filter(item => item.label && item.url)
+}
+
+function sanitizeArchivedSeriesNotes(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => ({
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ heading: typeof item.heading === 'string' ? item.heading.trim().slice(0, 140) : '',
+ body: typeof item.body === 'string' ? item.body.trim().slice(0, 4000) : '',
+ }))
+ .filter(item => item.heading || item.body)
+}
+
+function sanitizeArchivedSeries(value) {
+ const source = Array.isArray(value) ? value : []
+ return source
+ .filter(item => item && typeof item === 'object')
+ .map(item => ({
+ id: typeof item.id === 'string' && item.id.trim() ? item.id.trim() : randomUUID(),
+ label: typeof item.label === 'string' ? item.label.trim().slice(0, 140) : '',
+ title: typeof item.title === 'string' ? item.title.trim().slice(0, 200) : '',
+ description: typeof item.description === 'string' ? item.description.trim().slice(0, 1000) : '',
+ imageUrl: sanitizeUrl(item.imageUrl),
+ listenUrl: sanitizeUrl(item.listenUrl),
+ studyGuideTitle: typeof item.studyGuideTitle === 'string' ? item.studyGuideTitle.trim().slice(0, 140) : '',
+ studyGuideDescription: typeof item.studyGuideDescription === 'string' ? item.studyGuideDescription.trim().slice(0, 4000) : '',
+ studyGuideUrl: sanitizeUrl(item.studyGuideUrl),
+ resourceLinks: sanitizeArchivedSeriesResourceLinks(item.resourceLinks),
+ notes: sanitizeArchivedSeriesNotes(item.notes),
+ }))
+ .filter(
+ item =>
+ item.title ||
+ item.description ||
+ item.resourceLinks.length > 0 ||
+ item.notes.length > 0,
+ )
+}
+
+export function sanitizeSiteContent(siteContent) {
+ if (!siteContent || typeof siteContent !== 'object' || Array.isArray(siteContent)) return {}
+
+ const seo = siteContent.seo && typeof siteContent.seo === 'object' ? siteContent.seo : {}
+ const legal = siteContent.legal && typeof siteContent.legal === 'object' ? siteContent.legal : {}
+
+ return {
+ ...siteContent,
+ customLinks: sanitizeCustomLinks(siteContent.customLinks),
+ customBlocks: sanitizeCustomBlocks(siteContent.customBlocks),
+ archivedSeries: sanitizeArchivedSeries(siteContent.archivedSeries),
+ redirects: sanitizeRedirectRules(siteContent.redirects),
+ podcastFeaturedLinks: sanitizeFeaturedLinks(siteContent.podcastFeaturedLinks ?? DEFAULT_PODCAST_FEATURED_LINKS),
+ seo: {
+ title: typeof seo.title === 'string' && seo.title.trim() ? seo.title.trim().slice(0, 120) : DEFAULT_SEO.title,
+ description: typeof seo.description === 'string' && seo.description.trim() ? seo.description.trim().slice(0, 240) : DEFAULT_SEO.description,
+ ogTitle: typeof seo.ogTitle === 'string' && seo.ogTitle.trim() ? seo.ogTitle.trim().slice(0, 120) : DEFAULT_SEO.ogTitle,
+ ogDescription: typeof seo.ogDescription === 'string' && seo.ogDescription.trim() ? seo.ogDescription.trim().slice(0, 240) : DEFAULT_SEO.ogDescription,
+ ogImage: sanitizeUrl(seo.ogImage) || DEFAULT_SEO.ogImage,
+ canonicalUrl: sanitizeUrl(seo.canonicalUrl) || DEFAULT_SEO.canonicalUrl,
+ robotsPolicy: typeof seo.robotsPolicy === 'string' && seo.robotsPolicy.trim() ? seo.robotsPolicy.trim() : DEFAULT_SEO.robotsPolicy,
+ sitemapPaths: Array.isArray(seo.sitemapPaths)
+ ? seo.sitemapPaths.map(pathItem => normalizeSitemapPath(pathItem)).filter(Boolean)
+ : [...DEFAULT_SEO.sitemapPaths],
+ },
+ legal: {
+ privacyTitle: typeof legal.privacyTitle === 'string' && legal.privacyTitle.trim() ? legal.privacyTitle.trim().slice(0, 120) : DEFAULT_LEGAL.privacyTitle,
+ privacyBody: Array.isArray(legal.privacyBody) && legal.privacyBody.length > 0
+ ? legal.privacyBody.filter(line => typeof line === 'string').map(line => line.trim()).filter(Boolean).slice(0, 20)
+ : [...DEFAULT_LEGAL.privacyBody],
+ termsTitle: typeof legal.termsTitle === 'string' && legal.termsTitle.trim() ? legal.termsTitle.trim().slice(0, 120) : DEFAULT_LEGAL.termsTitle,
+ termsBody: Array.isArray(legal.termsBody) && legal.termsBody.length > 0
+ ? legal.termsBody.filter(line => typeof line === 'string').map(line => line.trim()).filter(Boolean).slice(0, 20)
+ : [...DEFAULT_LEGAL.termsBody],
+ },
+ }
+}
+
+export function escapeXml(value) {
+ return String(value)
+ .replace(/&/g, '&')
+ .replace(//g, '>')
+ .replace(/"/g, '"')
+ .replace(/'/g, ''')
+}
+
+export function buildAbsoluteUrl(baseUrl, maybeRelativePath) {
+ const safeBase = typeof baseUrl === 'string' && baseUrl.trim() ? baseUrl.trim() : DEFAULT_SEO.canonicalUrl
+ const root = safeBase.endsWith('/') ? safeBase.slice(0, -1) : safeBase
+ if (typeof maybeRelativePath !== 'string' || !maybeRelativePath.trim()) return root
+ const value = maybeRelativePath.trim()
+ if (/^https?:\/\//i.test(value)) return value
+ if (value.startsWith('/')) return `${root}${value}`
+ return `${root}/${value}`
+}
+
+export function injectSeoIntoHtml(html, siteContent) {
+ const seo = siteContent?.seo ?? DEFAULT_SEO
+ const title = seo.title || DEFAULT_SEO.title
+ const description = seo.description || DEFAULT_SEO.description
+ const ogTitle = seo.ogTitle || title
+ const ogDescription = seo.ogDescription || description
+ const canonical = buildAbsoluteUrl(seo.canonicalUrl || DEFAULT_SEO.canonicalUrl, '/')
+ const ogImage = buildAbsoluteUrl(canonical, seo.ogImage || DEFAULT_SEO.ogImage)
+ const robots = seo.robotsPolicy || DEFAULT_SEO.robotsPolicy
+
+ return html
+ .replace(/[\s\S]*?<\/title>/i, `${escapeHtml(title)}`)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+ .replace(//i, ``)
+}
+
+export function normalizeAssetBaseName(name) {
+ if (typeof name !== 'string') return `upload-${Date.now()}`
+ const cleaned = name
+ .toLowerCase()
+ .replace(/[^a-z0-9._-]+/g, '-')
+ .replace(/-+/g, '-')
+ .replace(/^-|-$/g, '')
+ return cleaned || `upload-${Date.now()}`
+}
+
+export function inferImageExtensionFromDataUrl(dataUrl) {
+ if (typeof dataUrl !== 'string') return null
+ if (dataUrl.startsWith('data:image/png;base64,')) return '.png'
+ if (dataUrl.startsWith('data:image/jpeg;base64,')) return '.jpg'
+ if (dataUrl.startsWith('data:image/webp;base64,')) return '.webp'
+ if (dataUrl.startsWith('data:image/gif;base64,')) return '.gif'
+ return null
+}
+
+export function normalizeIp(rawIp) {
+ if (!rawIp) return 'unknown'
+
+ let ip = String(rawIp).trim()
+
+ if (ip.includes(',')) {
+ ip = ip.split(',')[0].trim()
+ }
+
+ if (ip.startsWith('::ffff:')) {
+ ip = ip.slice(7)
+ }
+
+ if (ip === '::1') {
+ ip = '127.0.0.1'
+ }
+
+ return ip || 'unknown'
+}
+
+export function getClientIp(req) {
+ const forwarded = req.headers['x-forwarded-for']
+ if (forwarded) {
+ return normalizeIp(forwarded)
+ }
+ return normalizeIp(req.ip)
+}
+
+export function parseCookies(cookieHeader) {
+ if (!cookieHeader) return {}
+
+ return cookieHeader
+ .split(';')
+ .map(v => v.trim())
+ .filter(Boolean)
+ .reduce((acc, part) => {
+ const idx = part.indexOf('=')
+ if (idx === -1) return acc
+ const key = part.slice(0, idx).trim()
+ const value = part.slice(idx + 1).trim()
+ try {
+ acc[key] = decodeURIComponent(value)
+ } catch {
+ acc[key] = value
+ }
+ return acc
+ }, {})
+}
+
+export function hasVisitorConsent(req) {
+ const cookies = parseCookies(req.headers.cookie)
+ return cookies['vbn_analytics_consent'] === 'yes'
+}
+
+export function setConsentCookie(res, consent) {
+ const value = consent ? 'yes' : 'no'
+ const secureFlag = process.env.NODE_ENV === 'production' ? '; Secure' : ''
+ res.append('Set-Cookie', `vbn_analytics_consent=${value}; Max-Age=31536000; Path=/; SameSite=Lax${secureFlag}`)
+}
+
+export function isPrivateOrLocalIp(ip) {
+ return (
+ ip === '127.0.0.1' ||
+ ip === 'localhost' ||
+ ip.startsWith('10.') ||
+ ip.startsWith('192.168.') ||
+ /^172\.(1[6-9]|2[0-9]|3[0-1])\./.test(ip) ||
+ ip.startsWith('fc') ||
+ ip.startsWith('fd') ||
+ ip.startsWith('fe80:') ||
+ ip === 'unknown'
+ )
+}
diff --git a/src/AdminPage.tsx b/src/AdminPage.tsx
index 762b033..55f116c 100644
--- a/src/AdminPage.tsx
+++ b/src/AdminPage.tsx
@@ -1,8 +1,8 @@
import { useEffect, useState } from 'react'
import type { ChangeEvent } from 'react'
import { Link } from 'react-router-dom'
-import type { SiteContent, CustomLink, CustomBlock, ArchivedSeries, ArchivedSeriesResourceLink, ArchivedSeriesNote, RedirectRule, PodcastFeaturedLink, SeoSettings, LegalSettings } from './App'
-import { DEFAULTS } from './App'
+import type { SiteContent, CustomLink, CustomBlock, ArchivedSeries, ArchivedSeriesResourceLink, ArchivedSeriesNote, RedirectRule, PodcastFeaturedLink, SeoSettings, LegalSettings } from './content'
+import { DEFAULTS } from './content'
interface Props {
content: SiteContent
@@ -66,6 +66,7 @@ interface AdminAsset {
url: string
sizeBytes: number
updatedAt: string
+ tags?: string[]
}
interface PublishState {
@@ -94,7 +95,7 @@ interface Question {
}
type StringField = Exclude
-type MainContentSection = 'hero' | 'start-here' | 'about' | 'series' | 'share'
+type MainContentSection = 'hero' | 'start-here' | 'about' | 'contact' | 'series' | 'share'
const MAIN_CONTENT_SECTIONS: Array<{ id: MainContentSection; title: string; description: string }> = [
{
@@ -110,7 +111,12 @@ const MAIN_CONTENT_SECTIONS: Array<{ id: MainContentSection; title: string; desc
{
id: 'about',
title: 'About Section',
- description: 'Manage the main show description and Nate bio content.',
+ description: 'Manage the main show description, Nate bio, and about images.',
+ },
+ {
+ id: 'contact',
+ title: 'Contact Section',
+ description: 'Manage the contact page profile image and contact copy.',
},
{
id: 'series',
@@ -178,6 +184,9 @@ const FIELDS: Array<{ key: StringField; label: string; multiline?: boolean; sect
{ key: 'aboutShowP1', label: 'About Show — Paragraph 1', multiline: true, section: 'about' },
{ key: 'aboutShowP2', label: 'About Show — Paragraph 2', multiline: true, section: 'about' },
{ key: 'aboutNate', label: 'About Nate', multiline: true, section: 'about' },
+ { key: 'aboutPhotoUrl', label: 'About Section Photo URL', section: 'about' },
+ { key: 'aboutVerseArtUrl', label: 'About Verse Art Image URL', section: 'about' },
+ { key: 'contactPhotoUrl', label: 'Contact Profile Photo URL', section: 'contact' },
{ key: 'seriesLabel', label: 'Series Label (e.g. "Now Playing")', section: 'series' },
{ key: 'seriesTitle', label: 'Series Title', section: 'series' },
{ key: 'seriesDescription', label: 'Series Description', multiline: true, section: 'series' },
@@ -195,8 +204,8 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
const [lastSavedSnapshot, setLastSavedSnapshot] = useState(() => JSON.stringify(content))
const [status, setStatus] = useState<'idle' | 'saving' | 'saved' | 'error'>('idle')
const [errorMsg, setErrorMsg] = useState('')
- const [adminTab, setAdminTab] = useState<'content' | 'episodes' | 'settings' | 'publish' | 'analytics' | 'questions' | 'brand'>('content')
- const [contentTab, setContentTab] = useState<'main' | 'custom'>('main')
+ const [adminTab, setAdminTab] = useState<'content' | 'episodes' | 'settings' | 'analytics' | 'questions' | 'brand' | 'assets'>('content')
+ const [contentTab, setContentTab] = useState<'main' | 'resources' | 'custom'>('main')
const [stats, setStats] = useState(null)
const [statsStatus, setStatsStatus] = useState<'loading' | 'ready' | 'error'>('loading')
const [maintenanceMsg, setMaintenanceMsg] = useState('')
@@ -206,6 +215,7 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
const [selectedBackupPreview, setSelectedBackupPreview] = useState(null)
const [publishState, setPublishState] = useState({ draftUpdatedAt: null, publishedAt: null })
const [assets, setAssets] = useState([])
+ const [assetTagEdits, setAssetTagEdits] = useState>({})
const [opsStatus, setOpsStatus] = useState(null)
const [assetUploadPending, setAssetUploadPending] = useState(false)
@@ -274,13 +284,7 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
})
.catch(() => {})
- fetch('/api/admin-assets')
- .then(r => (r.ok ? r.json() : Promise.reject(new Error('Failed to load assets'))))
- .then(data => {
- const list = Array.isArray((data as { assets?: unknown }).assets) ? (data as { assets: AdminAsset[] }).assets : []
- setAssets(list)
- })
- .catch(() => {})
+ void reloadAssets()
fetch('/api/admin-ops/status')
.then(r => (r.ok ? r.json() : Promise.reject(new Error('Failed to load operations status'))))
@@ -346,7 +350,12 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
const r = await fetch('/api/admin-assets')
if (!r.ok) throw new Error('Could not refresh assets')
const data = await r.json() as { assets?: AdminAsset[] }
- setAssets(Array.isArray(data.assets) ? data.assets : [])
+ const incomingAssets = Array.isArray(data.assets) ? data.assets : []
+ setAssets(incomingAssets)
+ setAssetTagEdits(incomingAssets.reduce>((memo, asset) => {
+ memo[asset.filename] = (asset.tags ?? []).join(', ')
+ return memo
+ }, {}))
}
async function reloadOpsStatus() {
@@ -371,6 +380,7 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
}
const data = await res.json() as { updatedAt?: string }
setPublishState(prev => ({ ...prev, draftUpdatedAt: data.updatedAt ?? new Date().toISOString() }))
+ setLastSavedSnapshot(JSON.stringify(form))
setStatus('saved')
setTimeout(() => setStatus('idle'), 3500)
} catch (err) {
@@ -564,6 +574,30 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
}
}
+ function handleAssetTagChange(filename: string, value: string) {
+ setAssetTagEdits(prev => ({ ...prev, [filename]: value }))
+ }
+
+ async function handleSaveAssetTags(filename: string) {
+ const tagsText = assetTagEdits[filename] ?? ''
+ const tags = tagsText.split(',').map(tag => tag.trim()).filter(Boolean)
+ try {
+ const res = await fetch(`/api/admin-assets/${encodeURIComponent(filename)}`, {
+ method: 'PATCH',
+ headers: { 'Content-Type': 'application/json' },
+ body: JSON.stringify({ tags }),
+ })
+ if (!res.ok) {
+ const data = await res.json().catch(() => ({}))
+ throw new Error((data as { message?: string }).message ?? 'Save failed')
+ }
+ await reloadAssets()
+ setOpsMsg('Asset tags saved.')
+ } catch (err) {
+ setOpsMsg(err instanceof Error ? err.message : 'Save failed.')
+ }
+ }
+
async function handlePurgeCache() {
try {
const res = await fetch('/api/admin-ops/purge-cache', { method: 'POST' })
@@ -701,18 +735,43 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
setForm(f => ({ ...f, [key]: value }))
}
+ function renderImageAssetSelector(value: string | null | undefined, onChange: (value: string) => void, fieldId: string) {
+ const assetOptions = [...assets.map(asset => ({ label: asset.filename, value: asset.url }))]
+ const currentValue = value?.trim() ?? ''
+
+ if (currentValue && !assetOptions.some(item => item.value === currentValue)) {
+ assetOptions.unshift({ label: `Current image (${currentValue})`, value: currentValue })
+ }
+
+ if (assetOptions.length === 0) return null
+
+ return (
+
+
+
+
+ )
+ }
+
function confirmLeaveUnsavedChanges() {
if (!isDirty) return true
return confirm('You have unsaved changes. Leave this section without saving?')
}
- function handleAdminTabChange(nextTab: 'content' | 'episodes' | 'settings' | 'publish' | 'analytics' | 'questions' | 'brand') {
+ function handleAdminTabChange(nextTab: 'content' | 'episodes' | 'settings' | 'analytics' | 'questions' | 'brand' | 'assets') {
if (nextTab === adminTab) return
if (!confirmLeaveUnsavedChanges()) return
setAdminTab(nextTab)
}
- function handleContentTabChange(nextTab: 'main' | 'custom') {
+ function handleContentTabChange(nextTab: 'main' | 'resources' | 'custom') {
if (nextTab === contentTab) return
if (!confirmLeaveUnsavedChanges()) return
setContentTab(nextTab)
@@ -723,12 +782,22 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
...f,
customLinks: [
...(f.customLinks ?? []),
- { id: Date.now().toString(36), label: '', url: '', placement: 'platforms' as const },
+ { id: Date.now().toString(36), label: '', url: '', imageUrl: '', placement: 'platforms' as const },
],
}))
}
- function updateLink(id: string, field: keyof CustomLink, value: string) {
+ function addResource() {
+ setForm(f => ({
+ ...f,
+ customLinks: [
+ ...(f.customLinks ?? []),
+ { id: Date.now().toString(36), label: '', url: '', imageUrl: '', placement: 'resources' as const },
+ ],
+ }))
+ }
+
+ function updateLink(id: string, field: keyof CustomLink, value: string | string[]) {
setForm(f => ({
...f,
customLinks: (f.customLinks ?? []).map(l => l.id === id ? { ...l, [field]: value } : l),
@@ -985,29 +1054,6 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {
setContentTab('custom')
}
- async function handleSave() {
- setStatus('saving')
- setErrorMsg('')
- try {
- const res = await fetch('/api/admin-content', {
- method: 'PUT',
- headers: { 'Content-Type': 'application/json' },
- body: JSON.stringify({ siteContent: form }),
- })
- if (!res.ok) {
- const data = await res.json().catch(() => ({}))
- throw new Error((data as { message?: string }).message ?? 'Save failed')
- }
- onSave(form)
- setLastSavedSnapshot(JSON.stringify(form))
- setStatus('saved')
- setTimeout(() => setStatus('idle'), 3500)
- } catch (err) {
- setErrorMsg(err instanceof Error ? err.message : 'Unknown error')
- setStatus('error')
- }
- }
-
function handleReset() {
if (confirm('Reset all fields to defaults?')) {
setForm(DEFAULTS)
@@ -1147,11 +1193,11 @@ export default function AdminPage({ content, onSave, onLogout }: Props) {