Compare commits

...

7 Commits

Author SHA1 Message Date
dc1ba4def3 chore: bump version to 2.3.22-rc.1
Some checks failed
Build & Deploy / 🔍 Prepare (push) Successful in 9s
Build & Deploy / 🧪 QA (push) Successful in 1m15s
Build & Deploy / 🚀 Deploy (push) Successful in 19s
Build & Deploy / 🏗️ Build (push) Successful in 4m47s
Build & Deploy / 🧪 Post-Deploy Verification (push) Failing after 4m57s
Build & Deploy / 🔔 Notify (push) Successful in 2s
2026-04-21 19:26:30 +02:00
f87c714402 fix(e2e): implement automatic cleanup of test form submissions with authorized secret header 2026-04-21 19:26:06 +02:00
f989e0604f 2.3.21
All checks were successful
Build & Deploy / 🔍 Prepare (push) Successful in 6s
Build & Deploy / 🧪 QA (push) Successful in 1m18s
Build & Deploy / 🏗️ Build (push) Successful in 3m57s
Build & Deploy / 🚀 Deploy (push) Successful in 14s
Build & Deploy / 🧪 Post-Deploy Verification (push) Successful in 6m9s
Build & Deploy / 🔔 Notify (push) Successful in 4s
2026-04-21 19:19:08 +02:00
4a2d094cbd fix(i18n): update navigation term from AGB to AVB 2026-04-21 19:19:06 +02:00
77181fc983 2.3.20
All checks were successful
Build & Deploy / 🔍 Prepare (push) Successful in 6s
Build & Deploy / 🧪 QA (push) Successful in 1m43s
Build & Deploy / 🏗️ Build (push) Successful in 3m6s
Build & Deploy / 🚀 Deploy (push) Successful in 16s
Build & Deploy / 🧪 Post-Deploy Verification (push) Successful in 6m23s
Build & Deploy / 🔔 Notify (push) Successful in 1s
2026-04-21 18:57:38 +02:00
32b56696a6 feat(pdf): use static avb pdf for agbs route 2026-04-21 18:57:35 +02:00
9b28dd20d9 chore: update avb assets for april 2026
Some checks failed
Build & Deploy / 🔍 Prepare (push) Successful in 8s
Build & Deploy / 🧪 QA (push) Successful in 1m59s
Build & Deploy / 🏗️ Build (push) Successful in 3m1s
Build & Deploy / 🚀 Deploy (push) Successful in 14s
Build & Deploy / 🧪 Post-Deploy Verification (push) Failing after 5m9s
Build & Deploy / 🔔 Notify (push) Successful in 2s
2026-04-21 18:47:48 +02:00
8 changed files with 58 additions and 15 deletions

View File

@@ -532,6 +532,7 @@ jobs:
env:
NEXT_PUBLIC_BASE_URL: ${{ needs.prepare.outputs.next_public_url }}
GATEKEEPER_PASSWORD: ${{ secrets.GATEKEEPER_PASSWORD || 'klz2026' }}
PAYLOAD_SECRET: ${{ secrets.PAYLOAD_SECRET || vars.PAYLOAD_SECRET }}
PUPPETEER_EXECUTABLE_PATH: /usr/bin/chromium
run: pnpm run check:forms

View File

@@ -4,11 +4,28 @@ import configPromise from '@payload-config';
import { renderToStream } from '@react-pdf/renderer';
import React from 'react';
import { PDFPage } from '@/lib/pdf-page';
import fs from 'fs';
import path from 'path';
export async function GET(req: NextRequest, { params }: { params: Promise<{ slug: string }> }) {
try {
const { slug } = await params;
// Hardcoded bypass for AGBs to use the original uploaded PDF.
if (slug === 'agbs') {
const filePath = path.join(process.cwd(), 'public', 'AVB-KLZ-4-2026.pdf');
if (fs.existsSync(filePath)) {
const fileBuffer = fs.readFileSync(filePath);
return new NextResponse(fileBuffer, {
status: 200,
headers: {
'Content-Type': 'application/pdf',
'Content-Disposition': `attachment; filename="AVB-KLZ-4-2026.pdf"`,
},
});
}
}
// Get Payload App
const payload = await getPayload({ config: configPromise });

View File

@@ -73,7 +73,7 @@
"legalNoticeSlug": "impressum",
"privacyPolicy": "Datenschutz",
"privacyPolicySlug": "datenschutz",
"terms": "AGB",
"terms": "AVB",
"termsSlug": "terms",
"products": "Produkte",
"lowVoltage": "Niederspannungskabel",

View File

@@ -139,7 +139,7 @@
"prepare": "husky",
"preinstall": "npx only-allow pnpm"
},
"version": "2.3.18",
"version": "2.3.22-rc.1",
"pnpm": {
"onlyBuiltDependencies": [
"@parcel/watcher",

BIN
public/AVB-KLZ-4-2026.docx Normal file

Binary file not shown.

BIN
public/AVB-KLZ-4-2026.pdf Normal file

Binary file not shown.

View File

@@ -348,13 +348,23 @@ async function main() {
// 5. Cleanup: Delete test submissions from Payload CMS
console.log(`\n🧹 Starting cleanup of test submissions...`);
const payloadSecret = process.env.PAYLOAD_SECRET;
if (!payloadSecret) {
console.warn(` ⚠️ PAYLOAD_SECRET not found in environment. Cleanup will likely fail with 403.`);
}
try {
const apiUrl = `${targetUrl.replace(/\/$/, '')}/api/form-submissions`;
const searchUrl = `${apiUrl}?where[email][equals]=testing@mintel.me`;
// We fetch ALL submissions matching the test email to clean up potential lefovers from previous runs
const searchUrl = `${apiUrl}?where[email][equals]=testing@mintel.me&limit=100`;
// Fetch test submissions
// Fetch test submissions with bypass header
const searchResponse = await axios.get(searchUrl, {
headers: { Cookie: `klz_gatekeeper_session=${gatekeeperPassword}` },
headers: {
Cookie: `klz_gatekeeper_session=${gatekeeperPassword}`,
'x-e2e-secret': payloadSecret || '',
},
});
const testSubmissions = searchResponse.data.docs || [];
@@ -363,25 +373,30 @@ async function main() {
for (const doc of testSubmissions) {
try {
await axios.delete(`${apiUrl}/${doc.id}`, {
headers: { Cookie: `klz_gatekeeper_session=${gatekeeperPassword}` },
headers: {
Cookie: `klz_gatekeeper_session=${gatekeeperPassword}`,
'x-e2e-secret': payloadSecret || '',
},
});
console.log(` ✅ Deleted submission: ${doc.id}`);
console.log(` ✅ Deleted submission: ${doc.id} (${doc.name})`);
} catch (delErr: any) {
// Log but don't fail, 403s on Directus / Payload APIs for guest Gatekeeper sessions are normal
console.warn(
` ⚠️ Cleanup attempt on ${doc.id} returned an error, typically due to API Auth separation: ${delErr.message}`,
` ⚠️ Cleanup attempt on ${doc.id} failed: ${delErr.message}`,
);
}
}
if (testSubmissions.length > 0) {
console.log(`✅ Cleanup completed successfully.`);
}
} catch (err: any) {
if (err.response?.status === 403) {
console.warn(
` ⚠️ Cleanup fetch failed with 403 Forbidden. This is expected if the runner lacks admin API credentials. Test submissions remain in the database.`,
console.error(
` Cleanup failed with 403 Forbidden. Ensure FormSubmissions access control and PAYLOAD_SECRET are aligned.`,
);
} else {
console.error(` ❌ Cleanup fetch failed: ${err.message}`);
}
// Don't mark the whole test as failed just because cleanup failed
}
await browser.close();

View File

@@ -9,9 +9,19 @@ export const FormSubmissions: CollectionConfig = {
},
access: {
// Only Admins can view and delete leads via dashboard.
read: ({ req: { user } }) => Boolean(user) || process.env.NODE_ENV === 'development',
update: ({ req: { user } }) => Boolean(user) || process.env.NODE_ENV === 'development',
delete: ({ req: { user } }) => Boolean(user) || process.env.NODE_ENV === 'development',
// E2E scripts can bypass if they provide the correct secret header.
read: ({ req }) => {
const isE2E = req.headers.get('x-e2e-secret') === process.env.PAYLOAD_SECRET;
return Boolean(req.user) || isE2E || process.env.NODE_ENV === 'development';
},
update: ({ req }) => {
const isE2E = req.headers.get('x-e2e-secret') === process.env.PAYLOAD_SECRET;
return Boolean(req.user) || isE2E || process.env.NODE_ENV === 'development';
},
delete: ({ req }) => {
const isE2E = req.headers.get('x-e2e-secret') === process.env.PAYLOAD_SECRET;
return Boolean(req.user) || isE2E || process.env.NODE_ENV === 'development';
},
// Next.js server actions handle secure inserts natively. No public client create access.
create: () => false,
},