Compare commits

...

35 Commits

Author SHA1 Message Date
Aiirondev_dev 6b9cf8a024 changes to th the authentification for the page
Release Inventarsystem / release-docker (push) Successful in 2m25s
2026-09-14 09:13:43 +02:00
Aiirondev_dev 69bb02b7dc changes to the fuplicate import
Release Inventarsystem / release-docker (push) Successful in 13m24s
2026-09-14 09:03:02 +02:00
Aiirondev_dev 6a3a5d6373 Changes to the library scanning function
Release Inventarsystem / release-docker (push) Successful in 3m11s
2026-09-10 19:42:32 +02:00
Aiirondev_dev 09efedad69 changes to the Mahnungssystem
Release Inventarsystem / release-docker (push) Successful in 9m58s
2026-09-09 20:36:08 +02:00
Aiirondev_dev b05d238a60 changes to the Schüler id getting
Release Inventarsystem / release-docker (push) Successful in 2m18s
2026-09-09 20:09:44 +02:00
Aiirondev_dev 63a7b64150 change to the Hinweis that is shown
Release Inventarsystem / release-docker (push) Successful in 2m19s
2026-09-09 19:02:19 +02:00
Aiirondev_dev d5f4558b70 fixes to the physical scanner functionality
Release Inventarsystem / release-docker (push) Successful in 3m15s
2026-09-09 18:50:14 +02:00
Aiirondev_dev 0e85337fc5 changes to the scanning functrionality
Release Inventarsystem / release-docker (push) Successful in 2m22s
2026-09-08 18:36:34 +02:00
Aiirondev_dev 0114fec928 changes to the physical scanner processing
Release Inventarsystem / release-docker (push) Successful in 12m48s
2026-09-08 18:19:40 +02:00
Aiirondev_dev b16ad56b98 New password option fo the tenant adding and heatlth check
Release Inventarsystem / release-docker (push) Successful in 3m16s
2026-08-27 11:31:07 +02:00
Aiirondev_dev d2c21bc519 New password option fo the tenant adding and heatlth check
Release Inventarsystem / release-docker (push) Successful in 3m9s
2026-08-26 22:55:56 +02:00
Aiirondev_dev 4461644cb6 New password option fo the tenant adding
Release Inventarsystem / release-docker (push) Successful in 3m22s
2026-08-25 19:47:29 +02:00
Aiirondev_dev 73db5c5fe0 changes to the removal process
Release Inventarsystem / release-docker (push) Successful in 2m15s
2026-08-25 00:07:06 +02:00
Aiirondev_dev d609775eb6 Implementation of the switch between Anzahl oder Code
Release Inventarsystem / release-docker (push) Successful in 3m7s
2026-08-24 18:24:32 +02:00
Aiirondev_dev c1a6a145dc The School year rollover button is placed in the school settings.
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 18:00:35 +02:00
Aiirondev_dev 1091854797 change of the manage_filters.html design and removal of irelevant csv info modal
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 17:27:49 +02:00
Aiirondev_dev a5954ce8cb Correction of the filter naming in the upload_admin.html and edit_library.html
Release Inventarsystem / release-docker (push) Successful in 2m15s
2026-08-24 17:16:59 +02:00
Aiirondev_dev 06318d0d2d Correction of the filter naming in the upload_admin.html and edit_library.html
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 17:16:15 +02:00
Aiirondev_dev 5ed3c906dd Correction of the implementation of the Filter_names in the manage_filters.html.
Release Inventarsystem / release-docker (push) Successful in 2m14s
2026-08-24 16:53:40 +02:00
Aiirondev_dev 8ce74d3e62 Correction of the implementation of the Filter_names in the manage_filters.html.
Release Inventarsystem / release-docker (push) Successful in 2m14s
2026-08-24 16:42:15 +02:00
Aiirondev_dev ee25c46ff3 Correction of the table library view
Release Inventarsystem / release-docker (push) Successful in 2m14s
2026-08-24 16:15:47 +02:00
Aiirondev_dev f7fe2fcc11 Correction of an Miss placed Label
Release Inventarsystem / release-docker (push) Successful in 2m14s
2026-08-24 16:13:04 +02:00
Aiirondev_dev 4449007a15 Default Filternames Changes for the main_admin.html
Release Inventarsystem / release-docker (push) Successful in 2m14s
2026-08-24 16:08:24 +02:00
Aiirondev_dev 6770d42f99 Default Filternames Changed
Release Inventarsystem / release-docker (push) Successful in 2m15s
2026-08-24 16:00:58 +02:00
Aiirondev_dev 333f9fc89a New Modal Overlay
Release Inventarsystem / release-docker (push) Successful in 2m18s
2026-08-24 15:45:08 +02:00
Aiirondev_dev a286236834 New Modal Overlay
Release Inventarsystem / release-docker (push) Successful in 2m17s
2026-08-24 15:41:33 +02:00
Aiirondev_dev 84cc8de833 Reverse of faulty changes
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 14:52:50 +02:00
Aiirondev_dev 4b3c7e646f Replaced the Browser side pop ups with custom ones from the site itsself
Release Inventarsystem / release-docker (push) Successful in 2m17s
2026-08-24 14:45:21 +02:00
Aiirondev_dev f9b013508c Change of the Schaden melden button to be correctly considert a button
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 14:12:28 +02:00
Aiirondev_dev 2a6c40eb5a Fix for the CRSF Token implementation callability
Release Inventarsystem / release-docker (push) Successful in 2m16s
2026-08-24 12:35:16 +02:00
Aiirondev_dev 432d6da798 Fix for the CRSF Token implementation
Release Inventarsystem / release-docker (push) Successful in 2m15s
2026-08-24 12:12:55 +02:00
Aiirondev_dev 2cdf0d2169 implementation of the export for users
Release Inventarsystem / release-docker (push) Successful in 3m8s
2026-08-24 11:56:03 +02:00
Aiirondev_dev 9a4d10def7 implementation of the Email add on check
Release Inventarsystem / release-docker (push) Successful in 2m19s
2026-08-23 22:14:54 +02:00
Aiirondev_dev 10ae98245c Make the Mahnungen accueally dependent on the student_ausleih_dauer
Release Inventarsystem / release-docker (push) Successful in 2m17s
2026-08-23 21:59:16 +02:00
Aiirondev_dev 359a8f8ab1 Make the Mahnungen accueally dependent on the student_ausleih_dauer
Release Inventarsystem / release-docker (push) Successful in 2m19s
2026-08-23 21:45:02 +02:00
13 changed files with 1013 additions and 330 deletions
+153 -99
View File
@@ -17,7 +17,6 @@ Features:
- Booking and reservation of items
"""
from random import random
from flask import Flask, render_template, request, redirect, url_for, session, flash, send_from_directory, get_flashed_messages, jsonify, Response, make_response, send_file, abort
from werkzeug.utils import secure_filename
from werkzeug.middleware.proxy_fix import ProxyFix
@@ -228,7 +227,6 @@ def rollover_student_card_classes(dry_run=False, *, max_class=None, graduate_lab
client.close()
# Admin route to trigger rollover manually
@app.route('/admin/trigger_school_year_rollover', methods=['POST'])
def admin_trigger_school_year_rollover():
if 'username' not in session:
@@ -543,7 +541,8 @@ def _enforce_module_access():
msg = {
'library': "Bibliotheks-Modul ist deaktiviert.",
'inventory': "Inventar-Modul ist deaktiviert.",
'student_cards': "Schülerausweis-Modul ist deaktiviert."
'student_cards': "Schülerausweis-Modul ist deaktiviert.",
'terminplaner': "Termin-Modul ist deaktiviert."
}.get(name, f"{name.capitalize()}-Modul ist deaktiviert.")
if request.path.startswith('/api/') or request.is_json:
@@ -555,6 +554,8 @@ def _enforce_module_access():
return redirect(url_for('home_admin'))
elif name != 'library' and cfg.MODULES.is_enabled('library'):
return redirect('/library')
elif name != 'terminplaner' and cfg.MODULES.is_enabled('terminplaner'):
return redirect('/terminplaner')
return redirect(url_for('my_borrowed_items'))
@@ -707,7 +708,7 @@ def _action_access_allowed(permissions, action_key):
def _permission_denied_fallback_endpoint(permissions, current_endpoint=None):
username = session.get('username')
for candidate in ('home_admin', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
for candidate in ('home_admin', 'library_view', 'terminplaner', 'my_borrowed_items', 'tutorial_page', 'notifications_view', 'impressum'):
if current_endpoint and candidate == current_endpoint:
continue
if _page_access_allowed(permissions, candidate):
@@ -1379,11 +1380,31 @@ def update_appointment_statuses():
activation_user = str(appointment.get('User') or '').strip()
activation_item_name = str(appointment.get('Item') or 'Termin')
# is_library_item expects an item document, not the stored item id.
item_doc_for_status = None
item_id_for_status = appointment.get('Item')
if item_id_for_status:
item_lookup = [{'_id': item_id_for_status}]
try:
item_lookup.insert(0, {'_id': ObjectId(str(item_id_for_status))})
except (InvalidId, TypeError):
pass
try:
item_doc_for_status = items_col.find_one(
{'$or': item_lookup},
{'ItemType': 1, 'is_library': 1}
)
except Exception as item_lookup_error:
app.logger.warning(
f"Could not resolve item type for appointment {appointment.get('_id')}: {item_lookup_error}"
)
item_is_library = it.is_library_item(item_doc_for_status)
# Aktuellen Status bestimmen
new_status = au.get_current_status(appointment, log_changes=True, user='scheduler')
# Wenn sich der Status geändert hat, aktualisiere in der Datenbank
if new_status != old_status and not it.is_library_item(appointment.get('Item')):
if new_status != old_status and not item_is_library:
extra_fields = {}
# --- Conflict resolver: planned → active transition ---
@@ -1481,15 +1502,22 @@ def update_appointment_statuses():
# -----------------------------------------------------------------
# Mahnlauf für Bibliotheksartikel (Prüfung auf Überfälligkeit)
# -----------------------------------------------------------------
elif it.is_library_item(appointment.get('Item')):
elif item_is_library:
appt = appointment # Verwende das aktuelle Dokument aus der Schleife
if appt.get('Status') != 'active':
continue
due_date_obj = appt.get('DueDate')
due_date_obj = appt.get('DueDate') or appt.get('End')
if not due_date_obj:
continue
# Backfill the deadline for loans created before DueDate was stored.
if not appt.get('DueDate') and appt.get('End'):
ausleihungen.update_one(
{'_id': appt['_id'], 'DueDate': {'$exists': False}},
{'$set': {'DueDate': due_date_obj}}
)
due_date_naive = due_date_obj.replace(tzinfo=None) if due_date_obj.tzinfo else due_date_obj
days_overdue = (current_time_naive - due_date_naive).days
@@ -1516,6 +1544,7 @@ def update_appointment_statuses():
student_card = _decrypt_student_card_doc(card) if '_decrypt_student_card_doc' in globals() else card
student_name = student_card.get('SchülerName', target_ausweis_id)
student_class = student_card.get('Klasse', '')
student_ausleih_dauer = student_card.get('StandardAusleihdauer', 14)
# Gegenstandsdetails laden
item_name = "Unbekannter Artikel"
@@ -1530,8 +1559,8 @@ def update_appointment_statuses():
except Exception:
pass
# STUFE 2: >= 28 Tage überfällig -> Ausweis sperren, Stufe 2 setzen & Admins benachrichtigen
if days_overdue >= 28 and mahnstufe < 2:
# STUFE 2: >= 2 * student_ausleih_dauer Tage überfällig -> Ausweis sperren, Stufe 2 setzen & Admins benachrichtigen
if days_overdue >= (int(student_ausleih_dauer) * 2) and mahnstufe < 2:
ausleihungen.update_one(
{'_id': appt['_id']},
{'$set': {'Mahnstufe': 2, 'LastUpdated': current_time}}
@@ -1563,17 +1592,10 @@ def update_appointment_statuses():
except Exception as n_err:
app.logger.warning(f"Fehler beim Erstellen der Admin-Notif (Stufe 2): {n_err}")
# 2. Web-Push Notification für Admins
if 'create_return_reminders' in globals():
try:
create_return_reminders(title=title, body=body, url=target_url)
except Exception as p_err:
app.logger.error(f"Fehler beim Senden der Admin-Push (Stufe 2): {p_err}")
app.logger.warning(f"Mahnstufe 2 & Ausweis-Sperre für Schülerausweis '{student_name}' ({target_ausweis_id}) gesetzt.")
# STUFE 1: >= 14 Tage überfällig -> Stufe 1 setzen & Admins benachrichtigen
elif days_overdue >= 14 and mahnstufe == 0:
elif days_overdue >= int(student_ausleih_dauer) and mahnstufe == 0:
ausleihungen.update_one(
{'_id': appt['_id']},
{'$set': {'Mahnstufe': 1, 'LastUpdated': current_time}}
@@ -1594,13 +1616,6 @@ def update_appointment_statuses():
except Exception as n_err:
app.logger.warning(f"Fehler beim Erstellen der Admin-Notif (Stufe 1): {n_err}")
# 2. Web-Push Notification für Admins
if 'create_return_reminders' in globals():
try:
create_return_reminders(title=title, body=body, url=target_url)
except Exception as p_err:
app.logger.error(f"Fehler beim Senden der Admin-Push (Stufe 1): {p_err}")
app.logger.info(f"Mahnstufe 1 für Schülerausweis '{student_name}' ({target_ausweis_id}) gesetzt.")
if updated_count > 0:
@@ -3037,42 +3052,6 @@ def optimized_image(filename):
app.logger.error(f"Error serving optimized image {filename}: {str(e)}")
return Response("Optimized image not found", status=404)
# @app.route('/QRCodes/<filename>')
# def qrcode_file(filename):
# """
# Serve QR code files from the QRCodes directory.
#
# Args:
# filename (str): Name of the QR code file to serve
#
# Returns:
# flask.Response: The requested QR code file or placeholder image if not found
# """
# try:
# # Check production path first
# prod_path = "/var/Inventarsystem/Web/QRCodes"
# dev_path = app.config['QR_CODE_FOLDER']
# if os.path.exists(os.path.join(prod_path, filename)):
# return send_from_directory(prod_path, filename)
# if os.path.exists(os.path.join(dev_path, filename)):
# return send_from_directory(dev_path, filename)
#
# # Use a placeholder image if file not found - first try SVG, then PNG
# svg_placeholder_path = os.path.join(app.static_folder, 'img', 'no-image.svg')
# png_placeholder_path = os.path.join(app.static_folder, 'img', 'no-image.png')
#
# if os.path.exists(svg_placeholder_path):
# return send_from_directory(app.static_folder, 'img/no-image.svg')
# elif os.path.exists(png_placeholder_path):
# return send_from_directory(app.static_folder, 'img/no-image.png')
# else:
# return send_from_directory(app.static_folder, 'favicon.ico')
# except Exception as e:
# print(f"Error serving QR code {filename}: {str(e)}")
# return Response("QR code not found", status=404)
@app.route('/<path:filename>')
def catch_all_files(filename):
"""
@@ -3135,32 +3114,6 @@ def test_connection():
"""
return {'status': 'success', 'message': 'Connection successful', 'status_code': 200}
""" if sucess in deployment the funktion can be removed
@app.route('/user_status')
def user_status():
API endpoint to get the current user's status (username, admin status).
Used by JavaScript in templates to personalize the UI.
Returns:
JSON: User status information or error if not authenticated
if 'username' in session:
is_admin = us.check_admin(session['username'])
return jsonify({
'authenticated': True,
'username': session['username'],
'is_admin': is_admin
})
else:
return jsonify({
'authenticated': False,
'error': 'Not logged in'
}), 401
"""
##################################################### changes to be made to account for the new account permison managment system ##############################
@app.route('/')
def home():
@@ -3202,6 +3155,8 @@ def home_admin():
flash('Ihnen ist es nicht gestattet auf dieser Internetanwendung, die eben besuchte Adrrese zu nutzen, versuchen sie es erneut nach dem sie sich mit einem berechtigten Nutzer angemeldet haben!', 'error')
return redirect(url_for('library_view'))
filter_names = it.get_filter_names()
return render_template(
'main_admin.html',
username=session['username'],
@@ -3211,6 +3166,7 @@ def home_admin():
student_default_borrow_days=cfg.STUDENT_DEFAULT_BORROW_DAYS,
student_max_borrow_days=cfg.STUDENT_MAX_BORROW_DAYS,
school_info=_get_school_info_for_export(),
filter_names=filter_names,
open_item=request.args.get('open_item')
)
@@ -3716,7 +3672,10 @@ def mahnungen_admin():
overdue_records = list(ausleihungen_col.find({
'Status': 'active',
'DueDate': {'$lt': current_time}
'$or': [
{'DueDate': {'$lt': current_time}},
{'DueDate': {'$exists': False}, 'End': {'$lt': current_time}},
]
}).sort('DueDate', 1))
overdue_list = []
@@ -3751,8 +3710,6 @@ def mahnungen_admin():
item_name = item_doc.get('Name', item_id)
item_code = item_doc.get('Code_4', '')
# ENTFERNT: item_name = f"{item_name} ({item_code})" - Wir übergeben es separat ans Frontend
raw_user = str(record.get('User') or '')
decrypted_user = decrypt_text(raw_user)
ausweis_id = (decrypted_user if decrypted_user else raw_user).strip().upper()
@@ -3763,7 +3720,7 @@ def mahnungen_admin():
student_email = student_card.get('email') or student_card.get('Email', '')
is_blocked = student_card.get('is_blocked', False)
due_date_obj = record.get('DueDate')
due_date_obj = record.get('DueDate') or record.get('End')
if due_date_obj:
due_date_naive = due_date_obj.replace(tzinfo=None) if due_date_obj.tzinfo else due_date_obj
days_overdue = (current_time_naive - due_date_naive).days
@@ -3796,6 +3753,7 @@ def mahnungen_admin():
overdue_items=overdue_list,
library_module_enabled=cfg.MODULES.is_enabled('library'),
student_cards_module_enabled=cfg.MODULES.is_enabled('student_cards'),
email_service_enabled=cfg.EMAIL_ENABLED
)
@app.route('/mahnungen_reset', methods=['POST'])
@@ -4399,7 +4357,13 @@ def api_library_scan_action():
due_date = now + datetime.timedelta(days=borrow_duration_days)
it.update_item_status(item_id, False, borrower_name)
au.add_ausleihung(item_id, borrower_name, now, due_date)
au.add_ausleihung(
item_id,
borrower_name,
now,
end_date=due_date,
due_date=due_date,
)
_append_audit_event_standalone(
event_type='ausleihung_borrowed',
@@ -4707,12 +4671,15 @@ def upload_admin():
if not _action_access_allowed(permissions, 'can_insert'):
flash('Ihnen ist es nicht gestattet auf dieser Internetanwendung, die eben besuchte Adrrese zu nutzen, versuchen sie es erneut nach dem sie sich mit einem berechtigten Nutzer angemeldet haben!', 'error')
return redirect(url_for('login'))
filter_names = it.get_filter_names()
return render_template(
'upload_admin.html',
username=session['username'],
library_module_enabled=cfg.MODULES.is_enabled('library'),
student_cards_module_enabled=cfg.MODULES.is_enabled('student_cards'),
filter_names=filter_names,
show_library_features=False,
upload_mode='item',
page_title='Artikel hochladen',
@@ -5194,7 +5161,6 @@ def student_card_class_barcode_download():
"""
Download PDF with student card barcodes filtered by a specific class from dropdown.
"""
from flask import request, session, redirect, url_for, send_file, flash
if 'username' not in session:
return redirect(url_for('login'))
@@ -5388,7 +5354,7 @@ def student_card_single_barcode_download(card_id):
return redirect(url_for('login'))
current_permissions = us.get_effective_permissions(session['username'])
if not current_permissions['actions'].get('can_manage_users', False):
if not current_permissions['actions'].get('can_manage_settings', False):
flash('Ihnen fehlen die nötigen Berechtigungen, um diese Aktion auszuführen.', 'error')
return redirect(url_for('library_view'))
if not cfg.MODULES.is_enabled('student_cards'):
@@ -7005,12 +6971,15 @@ def item_edit(id):
current_item['IndividualCodes'] = '\n'.join(individual_codes)
filter_names = it.get_filter_names()
return render_template(
'edit_library.html',
username=session['username'],
item=current_item,
show_library_features=show_library_features,
library_module_enabled=library_module_active,
filter_names=filter_names,
page_title=f"Bearbeiten: {current_item.get('Name', '')}"
)
@@ -7592,7 +7561,13 @@ def ausleihen(id):
for unit in selected_units:
unit_id = str(unit.get('_id'))
it.update_item_status(unit_id, False, effective_borrower)
au.add_ausleihung(unit_id, effective_borrower, start_date, end_date=end_date)
au.add_ausleihung(
unit_id,
effective_borrower,
start_date,
end_date=end_date,
due_date=end_date if is_library_item else None,
)
_append_audit_event_standalone(
event_type='ausleihung_returned',
@@ -7683,7 +7658,13 @@ def ausleihen(id):
if total_exemplare <= 1:
it.update_item_status(id, False, effective_borrower)
start_date = datetime.datetime.now(ZoneInfo("Europe/Berlin"))
au.add_ausleihung(id, effective_borrower, start_date, end_date=end_date)
au.add_ausleihung(
id,
effective_borrower,
start_date,
end_date=end_date,
due_date=end_date if is_library_item else None,
)
_append_audit_event_standalone(
event_type='ausleihung_returned',
payload={
@@ -7728,10 +7709,17 @@ def ausleihen(id):
start_date = datetime.datetime.now(ZoneInfo("Europe/Berlin"))
for exemplar in new_borrowed_exemplars:
exemplar_id = f"{id}_{exemplar['number']}"
au.add_ausleihung(exemplar_id, effective_borrower, start_date, end_date=end_date, exemplar_data={
au.add_ausleihung(
exemplar_id,
effective_borrower,
start_date,
end_date=end_date,
due_date=end_date if is_library_item else None,
exemplar_data={
'parent_id': id,
'exemplar_number': exemplar['number']
})
}
)
_append_audit_event_standalone(
event_type='ausleihung_returned',
@@ -8628,6 +8616,72 @@ def register_csv():
mimetype='application/pdf'
)
@app.route('/export_users_csv', methods=['POST'])
def export_users_csv():
"""
Exports a filtered list of users to a CSV file.
Receives a JSON array of usernames from the frontend.
"""
if 'username' not in session:
flash('Ihnen ist es nicht gestattet, diese Aktion auszuführen.', 'error')
return redirect(url_for('login'))
usernames_json = request.form.get('usernames')
if not usernames_json:
flash('Keine Benutzer zum Exportieren ausgewählt.', 'error')
return redirect(url_for('user_del'))
try:
target_usernames = json.loads(usernames_json)
except json.JSONDecodeError:
flash('Ungültige Daten beim Export übermittelt.', 'error')
return redirect(url_for('user_del'))
# Fetch all users
all_users = us.get_all_users()
# Create CSV in memory
si = io.StringIO()
# Delimiter set to semicolon (standard for Excel in German locales)
cw = csv.writer(si, delimiter=';')
# Write headers
cw.writerow(['Benutzername', 'Vorname', 'Nachname', 'Administrator', 'Rechte-Preset'])
for user in all_users:
encrypted_username = user.get('Username')
if not encrypted_username:
continue
uname = decrypt_text(encrypted_username)
# Only process users that were present in the frontend's filtered view
if uname in target_usernames:
try:
permissions_payload = us.get_effective_permissions(uname)
preset = permissions_payload.get('preset', 'standard_user')
except Exception:
preset = 'standard_user'
try:
name = us.get_name(uname) or ""
last_name = us.get_last_name(uname) or ""
except Exception:
name = ""
last_name = ""
admin_status = "Ja" if user.get('Admin', False) else "Nein"
cw.writerow([uname, name, last_name, admin_status, preset])
# Prefix with BOM (Byte Order Mark) to ensure Excel reads UTF-8 (Umlauts) correctly
output = '\ufeff' + si.getvalue()
return Response(
output,
mimetype="text/csv",
headers={"Content-disposition": "attachment; filename=benutzer_export.csv"}
)
@app.route('/user_del', methods=['GET'])
def user_del():
@@ -13151,7 +13205,7 @@ def get_optimal_image_quality(img, target_size_kb=80):
@app.route('/health')
def health_check():
return 'OK', 200
return jsonify({"status": "healthy"}), 200
@app.route('/api/push/subscribe', methods=['POST'])
+3 -3
View File
@@ -911,9 +911,9 @@ def get_filter_names():
if names_doc and 'names' in names_doc:
return names_doc['names']
return {
'1': 'Fach/Kategorie',
'2': 'System/Bereich',
'3': 'Typ/Art'
'1': 'Jahrgangsstufe',
'2': 'Fachgebiet',
'3': 'Schlagwort'
}
def set_filter_name(filter_num, name):
+1 -1
View File
@@ -685,7 +685,7 @@ def student_card_exists(student_card_id):
client = MongoClient(cfg.MONGODB_HOST, cfg.MONGODB_PORT)
db = _get_tenant_db(client)
users = db['student_cards']
exists = users.find_one({'SchülerName': normalized}) is not None
exists = users.find_one({'AusweisId': normalized}) is not None
client.close()
return exists
+86 -6
View File
@@ -78,15 +78,15 @@
<div class="form-row">
<div class="form-group">
<label for="filter_name_1">Name Filter 1</label>
<input type="text" id="filter_name_1" name="filter_name_1" value="{{ filter_names.get('1', 'Fach/Kategorie') }}" placeholder="z. B. Fach/Kategorie">
<input type="text" id="filter_name_1" name="filter_name_1" value="{{ filter_names.get('1', 'Klassenstufe') }}" placeholder="z. B. Klassenstufe">
</div>
<div class="form-group">
<label for="filter_name_2">Name Filter 2</label>
<input type="text" id="filter_name_2" name="filter_name_2" value="{{ filter_names.get('2', 'System/Bereich') }}" placeholder="z. B. System/Bereich">
<input type="text" id="filter_name_2" name="filter_name_2" value="{{ filter_names.get('2', 'Fach') }}" placeholder="z. B. Fach">
</div>
<div class="form-group">
<label for="filter_name_3">Name Filter 3</label>
<input type="text" id="filter_name_3" name="filter_name_3" value="{{ filter_names.get('3', 'Typ/Art') }}" placeholder="z. B. Typ/Art">
<input type="text" id="filter_name_3" name="filter_name_3" value="{{ filter_names.get('3', 'Schlagwort') }}" placeholder="z. B. Schlagwort">
</div>
</div>
@@ -120,9 +120,64 @@
<p>Diese Angaben erscheinen künftig im amtlichen Audit-PDF und in anderen Behördenberichten.</p>
</div>
</div>
<!-- Danger Zone: Schuljahreswechsel -->
<div class="card danger-zone" style="grid-column: 1 / -1; border-color: #fca5a5;">
<div class="card-header" style="background: #fef2f2; border-bottom: 1px solid #fca5a5;">
<h2 style="color: #991b1b;">Erweiterte Aktionen</h2>
</div>
<div class="card-body" style="display: flex; justify-content: space-between; align-items: center; flex-wrap: wrap; gap: 15px;">
<div>
<strong style="color: #7f1d1d; display: block; font-size: 1.05rem; margin-bottom: 4px;">Schuljahreswechsel durchführen</strong>
<span style="color: #991b1b; font-size: 0.9rem;">Diese Aktion bereitet das System auf das neue Schuljahr vor (z. B. Hochstufen von Klassen).</span>
</div>
<button type="button"
id="btn-rollover"
class="btn btn-danger"
onclick="triggerSchoolYearRollover()">
Schuljahreswechsel auslösen
</button>
</div>
</div>
</div>
</div>
<script>
async function triggerSchoolYearRollover() {
if (!confirm('Möchtest du den Schuljahreswechsel wirklich durchführen? Dies kann nicht rückgängig gemacht werden!')) {
return;
}
const btn = document.getElementById('btn-rollover');
btn.disabled = true;
btn.textContent = 'Wird ausgeführt...';
try {
const response = await fetch('/admin/trigger_school_year_rollover', {
method: 'POST',
headers: {
'Content-Type': 'application/json'
}
});
const data = await response.json();
if (response.ok && data.ok) {
alert('Schuljahreswechsel erfolgreich durchgeführt!\n\nZusammenfassung:\n' + JSON.stringify(data.summary, null, 2));
location.reload();
} else {
alert('Fehler: ' + (data.message || 'Schuljahreswechsel konnte nicht durchgeführt werden.'));
}
} catch (error) {
console.error('Rollover error:', error);
alert('Netzwerk- oder Serverfehler beim Ausführen des Schuljahreswechsels.');
} finally {
btn.disabled = false;
btn.textContent = 'Schuljahreswechsel auslösen';
}
}
</script>
<style>
.container {
max-width: 1100px;
@@ -245,12 +300,17 @@
cursor: pointer;
}
.btn:disabled {
opacity: 0.6;
cursor: not-allowed;
}
.btn-primary {
background: #2563eb;
color: #fff;
}
.btn-primary:hover {
.btn-primary:hover:not(:disabled) {
background: #1d4ed8;
color: #fff;
}
@@ -261,11 +321,21 @@
border-color: #d1d5db;
}
.btn-secondary:hover {
.btn-secondary:hover:not(:disabled) {
background: #e5e7eb;
color: #111827;
}
.btn-danger {
background: #ef4444;
color: #fff;
}
.btn-danger:hover:not(:disabled) {
background: #dc2626;
color: #fff;
}
.preview-card p {
margin: 0 0 10px;
line-height: 1.45;
@@ -283,5 +353,15 @@
grid-template-columns: 1fr;
}
}
@media (max-width: 600px) {
.danger-zone .card-body {
flex-direction: column;
align-items: flex-start;
}
.danger-zone .btn {
width: 100%;
}
}
</style>
{% endblock %}
{% endblock %}
+3 -3
View File
@@ -274,7 +274,7 @@
{% if not show_library_features %}
<!-- ================= SYSTEM FILTERS 1-3 (INVENTORY / OTHER ITEMS ONLY) ================= -->
<div class="filter-inputs">
<h3>Unterrichtsfach (Filter 1):</h3>
<h3>{{ filter_names.get('1', 'Jahrgangsstufe') }}</h3>
<div class="multi-filter">
{% for idx in range(4) %}
<div class="form-group">
@@ -286,7 +286,7 @@
{% endfor %}
</div>
<h3>Jahrgangsstufe (Filter 2):</h3>
<h3>{{ filter_names.get('2', 'Fachgebiet') }}</h3>
<div class="multi-filter">
{% for idx in range(4) %}
<div class="form-group">
@@ -298,7 +298,7 @@
{% endfor %}
</div>
<h3>Schlagwort (Filter 3):</h3>
<h3>{{ filter_names.get('3', 'Schlagwort') }}</h3>
<div class="multi-filter">
{% for idx in range(4) %}
<div class="form-group">
+28 -2
View File
@@ -122,7 +122,7 @@
letter-spacing: 0.04em;
color: #64748b;
background: var(--ui-surface-soft);
user-select: none; /* Verhindert Textmarkierung beim Klicken */
user-select: none;
}
.library-table tr:hover td {
@@ -151,7 +151,7 @@
.badge-open { background: #fee2e2; color: #991b1b; }
.badge-paid { background: #dcfce7; color: #166534; }
.badge-damaged { background: #fee2e2; color: #991b1b; }
.badge-class { background: #f1f5f9; color: #475569; border: 1px solid #cbd5e1; } /* Neues Badge für Klasse */
.badge-class { background: #f1f5f9; color: #475569; border: 1px solid #cbd5e1; }
.row-actions {
display: flex;
@@ -168,6 +168,32 @@
white-space: nowrap;
}
.row-actions .btn-outline-danger {
color: #dc2626;
background-color: #fef2f2; /* Light red tint so it doesn't blend into the white table */
border: 2px solid #dc2626; /* Thicker, clear border */
padding: 6px 14px;
border-radius: 6px;
font-weight: bold;
font-size: 0.85rem;
cursor: pointer;
box-shadow: 0 2px 4px rgba(220, 38, 38, 0.1); /* Subtle shadow for depth */
transition: all 0.2s ease;
}
.row-actions .btn-outline-danger:hover {
background-color: #dc2626;
color: #ffffff;
box-shadow: 0 4px 8px rgba(220, 38, 38, 0.25);
transform: translateY(-1px); /* Slight lift effect on hover */
}
.row-actions .btn-outline-danger:active {
transform: translateY(0);
box-shadow: 0 1px 2px rgba(220, 38, 38, 0.15); /* Pressed state */
}
/* ------------------------------------------------------ */
.muted {
color: #6b7280;
font-size: 0.92rem;
+432 -49
View File
@@ -451,6 +451,27 @@
height: 100%;
}
.physical-scanner-modal {
z-index: 1100;
}
.physical-scanner-modal .modal-content {
max-width: 520px;
text-align: center;
}
.physical-scanner-code {
min-height: 28px;
margin: 18px 0 8px;
padding: 12px;
border: 1px dashed #cbd5e1;
border-radius: 6px;
color: var(--ui-text);
font-family: monospace;
font-size: 1.2em;
letter-spacing: 2px;
}
.detail-gallery-container {
display: flex;
@@ -518,10 +539,9 @@
<input type="text" id="manualItemCode" placeholder="Manueller Mediencode (optional)" style="min-width:180px;">
<button id="resetCardBtn" class="button" type="button">Feld zurücksetzen</button>
<button id="toggleScannerBtn" class="button" type="button">Scanner starten</button>
<label style="display:flex; align-items:center; gap:8px; margin-left:6px;">
<input type="checkbox" id="keyboardScannerToggle">
<span style="font-size:0.9em;">Physischer Scanner</span>
</label>
<button id="physicalScannerBtn" class="button" type="button" style="margin-left:6px;">
Physischer Scanner starten
</button>
<button id="manualActionBtn" class="button" type="button" style="margin-left:6px; background:#4f46e5; color:white;">Code verarbeiten</button>
</div>
<div class="library-scan-reader-wrap" id="scanReaderWrap" style="display: none; margin-top: 15px;">
@@ -612,8 +632,211 @@
<div id="detailContent"></div>
</div>
</div>
<div id="physicalScannerModal" class="modal physical-scanner-modal" style="display: none;" role="dialog" aria-modal="true" aria-labelledby="physicalScannerTitle">
<div class="modal-content">
<span class="close" id="closePhysicalScannerBtn" role="button" tabindex="0" aria-label="Physischen Scanner schließen">&times;</span>
<h2 id="physicalScannerTitle">Physischer Scanner</h2>
<p id="physicalScannerInstruction">Scanner ist bereit. Bitte den angezeigten Code scannen.</p>
<div id="physicalScannerCode" class="physical-scanner-code" tabindex="0" aria-label="Eingehender Scan" aria-live="polite"></div>
<p id="physicalScannerStatus" class="library-scan-status" aria-live="polite">Warte auf Scan...</p>
<button id="stopPhysicalScannerBtn" class="button" type="button">Scanner schließen</button>
</div>
</div>
<script src="https://cdn.jsdelivr.net/npm/@ericblade/quagga2/dist/quagga.js"></script>
<script>
// =========================================================================
// CUSTOM MODAL HELPERS (Replaces native browser alert, confirm & prompt)
// =========================================================================
function createModalOverlay() {
const overlay = document.createElement('div');
overlay.style.position = 'fixed';
overlay.style.top = '0';
overlay.style.left = '0';
overlay.style.width = '100vw';
overlay.style.height = '100vh';
overlay.style.backgroundColor = 'rgba(0, 0, 0, 0.6)';
overlay.style.display = 'flex';
overlay.style.alignItems = 'center';
overlay.style.justifyContent = 'center';
overlay.style.zIndex = '999999';
return overlay;
}
function createModalBox() {
const box = document.createElement('div');
box.style.backgroundColor = '#fff';
box.style.padding = '24px';
box.style.borderRadius = '8px';
box.style.boxShadow = '0 10px 25px rgba(0,0,0,0.2)';
box.style.fontFamily = 'sans-serif';
box.style.minWidth = '320px';
box.style.maxWidth = '90%';
box.style.textAlign = 'left';
box.style.color = '#333';
return box;
}
function customAlert(message) {
return new Promise((resolve) => {
const overlay = createModalOverlay();
const box = createModalBox();
const text = document.createElement('p');
text.textContent = message;
text.style.marginBottom = '20px';
text.style.lineHeight = '1.5';
text.style.whiteSpace = 'pre-wrap';
const btnContainer = document.createElement('div');
btnContainer.style.display = 'flex';
btnContainer.style.justifyContent = 'flex-end';
const btn = document.createElement('button');
btn.textContent = 'OK';
btn.style.padding = '8px 16px';
btn.style.cursor = 'pointer';
btn.style.border = 'none';
btn.style.backgroundColor = '#007bff';
btn.style.color = '#fff';
btn.style.borderRadius = '4px';
btn.onclick = () => {
document.body.removeChild(overlay);
resolve();
};
btnContainer.appendChild(btn);
box.appendChild(text);
box.appendChild(btnContainer);
overlay.appendChild(box);
document.body.appendChild(overlay);
btn.focus();
});
}
function customConfirm(message) {
return new Promise((resolve) => {
const overlay = createModalOverlay();
const box = createModalBox();
const text = document.createElement('p');
text.textContent = message;
text.style.marginBottom = '20px';
text.style.lineHeight = '1.5';
text.style.whiteSpace = 'pre-wrap';
const btnContainer = document.createElement('div');
btnContainer.style.display = 'flex';
btnContainer.style.justifyContent = 'flex-end';
btnContainer.style.gap = '10px';
const cancelBtn = document.createElement('button');
cancelBtn.textContent = 'Abbrechen';
cancelBtn.style.padding = '8px 16px';
cancelBtn.style.cursor = 'pointer';
cancelBtn.style.border = '1px solid #ccc';
cancelBtn.style.backgroundColor = '#f8f9fa';
cancelBtn.style.color = '#333';
cancelBtn.style.borderRadius = '4px';
const okBtn = document.createElement('button');
okBtn.textContent = 'OK';
okBtn.style.padding = '8px 16px';
okBtn.style.cursor = 'pointer';
okBtn.style.border = 'none';
okBtn.style.backgroundColor = '#007bff';
okBtn.style.color = '#fff';
okBtn.style.borderRadius = '4px';
const closeAndResolve = (val) => {
document.body.removeChild(overlay);
resolve(val);
};
cancelBtn.onclick = () => closeAndResolve(false);
okBtn.onclick = () => closeAndResolve(true);
btnContainer.appendChild(cancelBtn);
btnContainer.appendChild(okBtn);
box.appendChild(text);
box.appendChild(btnContainer);
overlay.appendChild(box);
document.body.appendChild(overlay);
okBtn.focus();
});
}
function customPrompt(message, defaultValue = '') {
return new Promise((resolve) => {
const overlay = createModalOverlay();
const box = createModalBox();
const text = document.createElement('p');
text.textContent = message;
text.style.marginBottom = '15px';
text.style.lineHeight = '1.5';
text.style.whiteSpace = 'pre-wrap';
const input = document.createElement('input');
input.type = 'text';
input.value = defaultValue;
input.style.width = '100%';
input.style.marginBottom = '20px';
input.style.padding = '10px';
input.style.boxSizing = 'border-box';
input.style.border = '1px solid #ccc';
input.style.borderRadius = '4px';
const btnContainer = document.createElement('div');
btnContainer.style.display = 'flex';
btnContainer.style.justifyContent = 'flex-end';
btnContainer.style.gap = '10px';
const cancelBtn = document.createElement('button');
cancelBtn.textContent = 'Abbrechen';
cancelBtn.style.padding = '8px 16px';
cancelBtn.style.cursor = 'pointer';
cancelBtn.style.border = '1px solid #ccc';
cancelBtn.style.backgroundColor = '#f8f9fa';
cancelBtn.style.color = '#333';
cancelBtn.style.borderRadius = '4px';
const okBtn = document.createElement('button');
okBtn.textContent = 'OK';
okBtn.style.padding = '8px 16px';
okBtn.style.cursor = 'pointer';
okBtn.style.border = 'none';
okBtn.style.backgroundColor = '#007bff';
okBtn.style.color = '#fff';
okBtn.style.borderRadius = '4px';
const closeAndResolve = (val) => {
document.body.removeChild(overlay);
resolve(val);
};
cancelBtn.onclick = () => closeAndResolve(null);
okBtn.onclick = () => closeAndResolve(input.value);
input.onkeydown = (e) => {
if (e.key === 'Enter') closeAndResolve(input.value);
if (e.key === 'Escape') closeAndResolve(null);
};
btnContainer.appendChild(cancelBtn);
btnContainer.appendChild(okBtn);
box.appendChild(text);
box.appendChild(input);
box.appendChild(btnContainer);
overlay.appendChild(box);
document.body.appendChild(overlay);
input.focus();
input.select();
});
}
// =========================================================================
// 1. GLOBAL STATE DEFINITIONS
// =========================================================================
@@ -649,7 +872,10 @@
let keyboardScannerEnabled = false;
let keyboardScanBuffer = '';
let keyboardLastKeyAt = 0;
const KEYBOARD_SCAN_INTERCHAR_MS = 100; // max time between keystrokes to consider them one scan
let physicalScannerModalOpen = false;
const KEYBOARD_SCAN_INTERCHAR_MS = 500; // max time between slower scanner keystrokes
const physicalScanQueue = [];
let keyboardScanProcessing = false;
let editLibraryState = {
itemId: '',
seriesGroupId: '',
@@ -884,7 +1110,7 @@
name: "Live",
type: "LiveStream",
// This MUST match the inner div where the video should appear
target: document.querySelector('.library-scan-reader'),
target: document.querySelector('.library-scan-reader'),
constraints: {
width: 640,
height: 480,
@@ -897,7 +1123,7 @@
},
decoder: {
// Keep only the barcode types you actually use to improve performance
readers: ["code_128_reader", "ean_reader", "code_39_reader"]
readers: ["code_128_reader", "ean_reader", "code_39_reader"]
},
locate: true
}, function(err) {
@@ -991,29 +1217,86 @@
// =========================================================================
// Keyboard scanner handling (physical scanners that send chars then Enter)
// =========================================================================
function getPhysicalScannerInstruction() {
const mode = document.getElementById('scanModeSelect')?.value || 'card_only';
if (mode === 'return_only') return 'Hinweis: Benötigt wird ein Mediencode zur Rückgabe.';
if (mode === 'card_only') return 'Hinweis: Benötigt wird ein Bibliotheksausweis.';
if (mode === 'quick_toggle' && !activeStudentCardId) {
return 'Hinweis: Zuerst wird ein Bibliotheksausweis benötigt.';
}
if (mode === 'quick_toggle') return 'Hinweis: Jetzt wird ein Mediencode benötigt.';
if (mode === 'continuous' && !activeStudentCardId) {
return 'Hinweis: Zuerst wird ein Bibliotheksausweis benötigt.';
}
return 'Hinweis: Jetzt wird der nächste Mediencode benötigt.';
}
function updatePhysicalScannerModal(message, kind = '') {
const instruction = document.getElementById('physicalScannerInstruction');
const status = document.getElementById('physicalScannerStatus');
if (instruction) instruction.textContent = getPhysicalScannerInstruction();
if (status) {
status.textContent = message;
status.classList.remove('ok', 'warn', 'error');
if (kind) status.classList.add(kind);
}
}
function openPhysicalScannerModal() {
const modal = document.getElementById('physicalScannerModal');
if (!modal) return;
physicalScannerModalOpen = true;
keyboardScannerEnabled = true;
keyboardScanBuffer = '';
keyboardLastKeyAt = 0;
modal.style.display = 'flex';
updatePhysicalScannerModal('Warte auf Scan...', 'warn');
document.addEventListener('keydown', keyboardScanKeydownHandler);
document.getElementById('physicalScannerCode')?.focus();
}
function closePhysicalScannerModal() {
physicalScannerModalOpen = false;
keyboardScannerEnabled = false;
keyboardScanBuffer = '';
keyboardLastKeyAt = 0;
document.removeEventListener('keydown', keyboardScanKeydownHandler);
const modal = document.getElementById('physicalScannerModal');
if (modal) modal.style.display = 'none';
const code = document.getElementById('physicalScannerCode');
if (code) code.textContent = '';
}
function keyboardScanKeydownHandler(e) {
// Only active when explicitly enabled
if (!keyboardScannerEnabled) return;
if (!keyboardScannerEnabled || !physicalScannerModalOpen) return;
// Ignore if focus is in an input/textarea/contenteditable to avoid interfering with typing
const active = document.activeElement;
if (active && (active.tagName === 'INPUT' || active.tagName === 'TEXTAREA' || active.isContentEditable)) return;
if (e.key === 'Escape') {
e.preventDefault();
closePhysicalScannerModal();
return;
}
const now = Date.now();
// If Enter/Return pressed -> finalize buffer
if (e.key === 'Enter') {
e.preventDefault();
const code = keyboardScanBuffer.trim();
keyboardScanBuffer = '';
keyboardLastKeyAt = 0;
if (!code) return;
// Process exactly like a camera scan - centralized logic handles the rest!
handleScanSuccess(code);
// Scanner keystrokes must not be submitted into the focused form field.
const displayCode = document.getElementById('physicalScannerCode');
if (displayCode) displayCode.textContent = code;
updatePhysicalScannerModal('Enter erkannt. Code wird verarbeitet...', 'warn');
processPhysicalScan(code);
return;
}
// Only accept common printable characters; ignore modifier keys
// Accept all printable scanner characters, including letters and punctuation.
if (e.key.length === 1) {
// If time gap too big, start new buffer
if (keyboardLastKeyAt && (now - keyboardLastKeyAt) > KEYBOARD_SCAN_INTERCHAR_MS) {
@@ -1021,12 +1304,32 @@
}
keyboardScanBuffer += e.key;
keyboardLastKeyAt = now;
// Prevent default so scanner input doesn't accidentally move focus or trigger shortcuts
const displayCode = document.getElementById('physicalScannerCode');
if (displayCode) displayCode.textContent = keyboardScanBuffer;
// Prevent default so scanner input is captured even while an input has focus.
e.preventDefault();
}
}
function handleScanSuccess(decodedText) {
async function processPhysicalScan(code) {
physicalScanQueue.push(code);
if (keyboardScanProcessing) return;
keyboardScanProcessing = true;
try {
while (physicalScanQueue.length > 0) {
await handleScanSuccess(physicalScanQueue.shift());
if (physicalScannerModalOpen) {
const displayCode = document.getElementById('physicalScannerCode');
if (displayCode) displayCode.textContent = '';
}
}
} finally {
keyboardScanProcessing = false;
}
}
async function handleScanSuccess(decodedText) {
const scannedCode = typeof normalizeScannedCode === "function" ? normalizeScannedCode(decodedText) : decodedText;
if (!scannedCode) return;
@@ -1042,26 +1345,28 @@
// 1. Modus: Nur Rückgabe
if (mode === 'return_only') {
returnByCode(scannedCode);
await returnByCode(scannedCode);
return;
}
// 2. Modus: Nur Ausweis
if (mode === 'card_only') {
setActiveStudentCard(scannedCode);
setScanStatus(`Ausweis gesetzt: ${activeStudentCardId}`, 'ok');
setScanStatus(`Ausweis gesetzt: ${activeStudentCardId}. Bitte den nächsten Ausweis scannen.`, 'ok');
showSmallConfirm(`Ausweis erkannt: ${activeStudentCardId}. Sie können den nächsten scannen.`, 'ok');
updatePhysicalScannerModal(`Ausweis erkannt. Bereit für den nächsten Scan.`, 'ok');
return;
}
// 3. Modus: Schnellmodus (1x Ausweis, 1x Buch)
if (mode === 'quick_toggle') {
processQuickToggleScan(scannedCode);
await processQuickToggleScan(scannedCode);
return;
}
// 4. Modus: Dauermodus (1x Ausweis, Nx Bücher)
if (mode === 'continuous') {
processContinuousScan(scannedCode);
await processContinuousScan(scannedCode);
return;
}
}
@@ -1075,9 +1380,10 @@
setActiveStudentCard(scannedCode);
setScanStatus(`Neuer Ausweis gesetzt: ${activeStudentCardId}. Bitte Medien scannen.`, 'ok');
showSmallConfirm(`Benutzer gewechselt zu: ${activeStudentCardId}`, 'ok');
updatePhysicalScannerModal('Ausweis erkannt. Jetzt Mediencodes scannen.', 'ok');
setTimeout(() => {
if (document.getElementById('scanModeSelect').value === 'continuous') {
if (!physicalScannerModalOpen && document.getElementById('scanModeSelect').value === 'continuous') {
startScanner();
}
}, 1000);
@@ -1087,9 +1393,10 @@
if (!activeStudentCardId) {
setScanStatus('Kein Ausweis aktiv! Bitte zuerst einen Schülerausweis scannen.', 'error');
showSmallConfirm('Bitte zuerst Ausweis scannen', 'error');
updatePhysicalScannerModal('Kein Ausweis aktiv. Bitte zuerst den Ausweis scannen.', 'error');
setTimeout(() => {
if (document.getElementById('scanModeSelect').value === 'continuous') {
if (!physicalScannerModalOpen && document.getElementById('scanModeSelect').value === 'continuous') {
startScanner();
}
}, 2000);
@@ -1115,15 +1422,22 @@
if (!response.ok || !result.ok) {
setScanStatus(result.message || 'Scan-Aktion fehlgeschlagen.', 'error');
showSmallConfirm(result.message || 'Aktion fehlgeschlagen.', 'error');
updatePhysicalScannerModal(result.message || 'Scan-Aktion fehlgeschlagen.', 'error');
} else if (result.action === 'borrowed') {
setScanStatus(`Ausgeliehen: ${result.item_name}`, 'ok');
showSmallConfirm(`Ausgeliehen: ${result.item_name}`, 'ok');
showSmallConfirm(`Ausgeliehen: ${result.item_name}`, 'ok', {
actionLabel: 'Mit nächstem Ausweis starten',
onAction: startNextStudentCardScan
});
updatePhysicalScannerModal('Ausleihe erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
} else if (result.action === 'returned') {
setScanStatus(`Zurückgegeben: ${result.item_name}`, 'ok');
showSmallConfirm(`Zurückgegeben: ${result.item_name}`, 'ok');
updatePhysicalScannerModal('Rückgabe erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
} else {
setScanStatus(result.message || 'Aktion durchgeführt.', 'ok');
showSmallConfirm(result.message || 'Erfolgreich', 'ok');
updatePhysicalScannerModal('Aktion erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
}
// Tabellen-Ansicht aktualisieren
@@ -1134,10 +1448,11 @@
console.error('Continuous scan action failed:', err);
setScanStatus('Fehler beim Verarbeiten des Scans.', 'error');
showSmallConfirm('Fehler im Netzwerk/System', 'error');
updatePhysicalScannerModal('Fehler beim Verarbeiten. Bitte erneut scannen.', 'error');
}
setTimeout(() => {
if (document.getElementById('scanModeSelect').value === 'continuous') {
if (!physicalScannerModalOpen && document.getElementById('scanModeSelect').value === 'continuous') {
startScanner();
}
}, 1500);
@@ -1148,7 +1463,9 @@
// 2. Wenn kein Ausweis gesetzt ist, wird der Code als Ausweis interpretiert
if (!activeStudentCardId) {
setActiveStudentCard(scannedCode);
setScanStatus(`Ausweis gesetzt: ${activeStudentCardId}`, 'ok');
setScanStatus(`Ausweis gesetzt: ${activeStudentCardId}. Bitte den nächsten Mediencode scannen.`, 'ok');
showSmallConfirm(`Ausweis erkannt: ${activeStudentCardId}. Bitte jetzt den nächsten Mediencode scannen.`, 'ok');
updatePhysicalScannerModal('Ausweis erkannt. Jetzt den Mediencode scannen.', 'ok');
return;
}
@@ -1157,7 +1474,11 @@
setScanStatus('Verarbeite Mediencode...', 'warn');
const response = await fetch('/api/library_scan_action', {
method: 'POST',
headers: {'Content-Type': 'application/json'},
headers: {
'Content-Type': 'application/json',
'X-CSRFToken': '{{ csrf_token }}',
'X-CSRF-Token': '{{ csrf_token }}'
},
body: JSON.stringify({
student_card_id: activeStudentCardId,
item_code: scannedCode
@@ -1167,24 +1488,32 @@
const result = await response.json();
if (!response.ok || !result.ok) {
setScanStatus(result.message || 'Scan-Aktion fehlgeschlagen.', 'error');
updatePhysicalScannerModal(result.message || 'Scan-Aktion fehlgeschlagen.', 'error');
return;
}
if (result.action === 'borrowed') {
setScanStatus(`Ausgeliehen: ${result.item_name}`, 'ok');
showSmallConfirm(`Ausgeliehen: ${result.item_name}`, 'ok');
showSmallConfirm(`Ausgeliehen: ${result.item_name}`, 'ok', {
actionLabel: 'Mit nächstem Ausweis starten',
onAction: startNextStudentCardScan
});
updatePhysicalScannerModal('Ausleihe erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
} else if (result.action === 'returned') {
setScanStatus(`Zurückgegeben: ${result.item_name}`, 'ok');
showSmallConfirm(`Zurückgegeben: ${result.item_name}`, 'ok');
updatePhysicalScannerModal('Rückgabe erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
} else {
setScanStatus(result.message || 'Aktion durchgeführt.', 'ok');
showSmallConfirm(result.message || 'Aktion durchgeführt.', 'ok');
updatePhysicalScannerModal('Aktion erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
}
await loadLibraryItems();
} catch (err) {
console.error('Quick scan action failed:', err);
setScanStatus('Fehler beim Verarbeiten des Scans.', 'error');
updatePhysicalScannerModal('Fehler beim Verarbeiten. Bitte erneut scannen.', 'error');
}
}
@@ -1194,23 +1523,30 @@
try {
const resp = await fetch('/api/library_return_by_code', {
method: 'POST',
headers: {'Content-Type': 'application/json'},
headers: {
'Content-Type': 'application/json',
'X-CSRFToken': '{{ csrf_token }}',
'X-CSRF-Token': '{{ csrf_token }}'
},
body: JSON.stringify({ item_code: code })
});
const result = await resp.json();
if (!resp.ok || !result.ok) {
setScanStatus(result.message || 'Rückgabe fehlgeschlagen.', 'error');
showSmallConfirm(result.message || 'Rückgabe fehlgeschlagen.', 'error');
updatePhysicalScannerModal(result.message || 'Rückgabe fehlgeschlagen.', 'error');
return false;
}
setScanStatus(result.message || `Zurückgegeben: ${result.item_name || ''}`, 'ok');
showSmallConfirm(result.message || `Zurückgegeben: ${result.item_name || ''}`, 'ok');
updatePhysicalScannerModal('Rückgabe erfolgreich. Bereit für den nächsten Mediencode.', 'ok');
await loadLibraryItems();
return true;
} catch (err) {
console.error('Return by code failed:', err);
setScanStatus('Fehler bei Rückgabe.', 'error');
showSmallConfirm('Fehler bei Rückgabe.', 'error');
updatePhysicalScannerModal('Fehler bei Rückgabe. Bitte erneut scannen.', 'error');
return false;
}
}
@@ -1243,31 +1579,39 @@
// =========================================================================
// 4. UI INTERACTIONS & UTILITIES
// =========================================================================
function borrowItem(itemId) {
async function borrowItem(itemId) {
const selectedItem = (libraryItems || []).find(item => item._id === itemId);
if (selectedItem && selectedItem.LibraryDisplayStatus === 'damaged') {
alert('Dieses Medium ist als defekt/zerstört markiert und kann nicht ausgeliehen werden.');
await customAlert('Dieses Medium ist als defekt/zerstört markiert und kann nicht ausgeliehen werden.');
return;
}
const defaultCardId = activeStudentCardId || '';
const cardId = (window.prompt('Bitte Bibliotheksausweis-ID eingeben:', defaultCardId) || '').trim().toUpperCase();
const promptCardResult = await customPrompt('Bitte Bibliotheksausweis-ID eingeben:', defaultCardId);
if (promptCardResult === null) return;
const cardId = promptCardResult.trim().toUpperCase();
if (!cardId) {
alert('Ausleihe abgebrochen: Für Bibliotheksmedien ist eine gültige Bibliotheksausweis-ID erforderlich.');
await customAlert('Ausleihe abgebrochen: Für Bibliotheksmedien ist eine gültige Bibliotheksausweis-ID erforderlich.');
return;
}
setActiveStudentCard(cardId);
const durationInput = (window.prompt('Ausleihdauer in Tagen (optional):') || '').trim();
const promptDurationResult = await customPrompt('Ausleihdauer in Tagen (optional):');
if (promptDurationResult === null) return;
const durationInput = promptDurationResult.trim();
const maxAvailable = Math.max(1, parseInt(selectedItem?.AvailableGroupedCount || selectedItem?.Quantity || 1, 10) || 1);
const countPrompt = (window.prompt(`Anzahl ausleihen? (Standard: 1, verfügbar: ${maxAvailable})`, '1') || '').trim();
let borrowCount = parseInt(countPrompt || '1', 10);
const countPromptResult = await customPrompt(`Anzahl ausleihen? (Standard: 1, verfügbar: ${maxAvailable})`, '1');
if (countPromptResult === null) return;
let borrowCount = parseInt(countPromptResult.trim() || '1', 10);
if (!Number.isFinite(borrowCount) || borrowCount < 1) {
borrowCount = 1;
}
if (borrowCount > maxAvailable) {
alert(`Es sind nur ${maxAvailable} Exemplar(e) verfügbar.`);
await customAlert(`Es sind nur ${maxAvailable} Exemplar(e) verfügbar.`);
return;
}
@@ -1319,21 +1663,51 @@
if (kind) el.classList.add(kind);
}
function showSmallConfirm(message, kind='ok') {
function showSmallConfirm(message, kind='ok', action = null) {
// Append the small helper text in German
const helper = 'Sie können fortfahren. Dies ist nur eine kleine Benachrichtigung.';
const el = document.createElement('div');
el.className = `small-popup ${kind === 'error' ? 'error' : 'ok'}`;
el.innerHTML = `<div>${escapeHtml(String(message || ''))}</div><div style="opacity:0.9; margin-left:8px; font-size:0.85em;">${helper}</div><div class="close-x">&times;</div>`;
el.innerHTML = `<div>${escapeHtml(String(message || ''))}</div><div style="opacity:0.9; margin-left:8px; font-size:0.85em;">${helper}</div>`;
if (action && typeof action.onAction === 'function') {
const actionButton = document.createElement('button');
actionButton.type = 'button';
actionButton.textContent = action.actionLabel || 'Weiter';
actionButton.style.marginLeft = '8px';
actionButton.style.padding = '6px 10px';
actionButton.style.cursor = 'pointer';
actionButton.addEventListener('click', () => {
if (el.parentNode) el.parentNode.removeChild(el);
action.onAction();
});
el.appendChild(actionButton);
}
const closeButton = document.createElement('div');
closeButton.className = 'close-x';
closeButton.innerHTML = '&times;';
el.appendChild(closeButton);
document.body.appendChild(el);
// close handler
el.querySelector('.close-x').addEventListener('click', () => {
closeButton.addEventListener('click', () => {
if (el && el.parentNode) el.parentNode.removeChild(el);
});
// auto remove after 3 seconds
setTimeout(() => { try { if (el && el.parentNode) el.parentNode.removeChild(el); } catch(e){} }, 3000);
}
async function startNextStudentCardScan() {
setActiveStudentCard('');
setScanStatus('Bereit für den nächsten Ausweis.', 'warn');
updatePhysicalScannerModal('Bereit für den nächsten Ausweis.', 'warn');
const mode = document.getElementById('scanModeSelect')?.value;
if (!physicalScannerModalOpen && (mode === 'quick_toggle' || mode === 'continuous') && !scannerRunning) {
await startScanner();
}
}
function setActiveStudentCard(cardId) {
activeStudentCardId = (cardId || '').trim().toUpperCase();
const input = document.getElementById('activeStudentCard');
@@ -1448,7 +1822,7 @@
const toggleBtn = document.getElementById('toggleScannerBtn');
const resetBtn = document.getElementById('resetCardBtn');
const modeSelect = document.getElementById('scanModeSelect');
const keyboardToggle = document.getElementById('keyboardScannerToggle');
const physicalScannerBtn = document.getElementById('physicalScannerBtn');
if (toggleBtn) {
toggleBtn.addEventListener('click', async () => {
@@ -1469,6 +1843,9 @@
if (modeSelect) {
modeSelect.addEventListener('change', () => {
if (physicalScannerModalOpen) {
updatePhysicalScannerModal('Warte auf Scan...', 'warn');
}
if (modeSelect.value === 'quick_toggle' && !activeStudentCardId) {
setScanStatus('Schnellmodus: zuerst Bibliotheksausweis scannen.', 'warn');
} else if (modeSelect.value === 'card_only') {
@@ -1477,18 +1854,24 @@
});
}
if (keyboardToggle) {
keyboardToggle.addEventListener('change', () => {
keyboardScannerEnabled = !!keyboardToggle.checked;
if (keyboardScannerEnabled) {
document.addEventListener('keydown', keyboardScanKeydownHandler);
setScanStatus('Physischer Scanner aktiv (Schnellmodus empfohlen).', 'ok');
} else {
document.removeEventListener('keydown', keyboardScanKeydownHandler);
setScanStatus('Physischer Scanner deaktiviert.', 'warn');
if (physicalScannerBtn) {
physicalScannerBtn.addEventListener('click', openPhysicalScannerModal);
}
const closePhysicalScannerBtn = document.getElementById('closePhysicalScannerBtn');
const stopPhysicalScannerBtn = document.getElementById('stopPhysicalScannerBtn');
if (closePhysicalScannerBtn) {
closePhysicalScannerBtn.addEventListener('click', closePhysicalScannerModal);
closePhysicalScannerBtn.addEventListener('keydown', (event) => {
if (event.key === 'Enter' || event.key === ' ') {
event.preventDefault();
closePhysicalScannerModal();
}
});
}
if (stopPhysicalScannerBtn) {
stopPhysicalScannerBtn.addEventListener('click', closePhysicalScannerModal);
}
}
// Run when DOM structure is entirely ready
+7 -2
View File
@@ -179,10 +179,12 @@
</td>
<td class="text-end">
<div class="btn-group" role="group">
{% if mail_service_enabled %}
<button type="button" class="btn btn-sm btn-outline-primary"
onclick="openEmailModal('{{ item.id }}', '{{ item.schueler_name }}', '{{ item.email }}')">
<i class="bi bi-envelope"></i> E-Mail
</button>
{% endif %}
<button type="button" class="btn btn-sm btn-outline-warning text-dark"
onclick="resetMahnung('{{ item.id }}', '{{ item.schueler_name }}')">
<i class="bi bi-arrow-counterclockwise"></i> Zurücksetzen
@@ -254,6 +256,7 @@ function submitEmailMahnung() {
const loanId = document.getElementById('modalLoanId').value;
const email = document.getElementById('modalEmail').value;
const message = document.getElementById('modalMessage').value;
const csrfToken = document.querySelector('meta[name="csrf-token"]')?.content || '';
if (!email) {
alert('Bitte geben Sie eine gültige E-Mail-Adresse ein.');
@@ -262,7 +265,7 @@ function submitEmailMahnung() {
fetch('/mahnungen_send_email', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
headers: { 'Content-Type': 'application/json', 'X-CSRFToken': csrfToken },
body: JSON.stringify({ loan_id: loanId, email: email, message: message })
})
.then(response => response.json())
@@ -287,9 +290,11 @@ function resetMahnung(loanId, studentName) {
return;
}
const csrfToken = document.querySelector('meta[name="csrf-token"]')?.content || '';
fetch('/mahnungen_reset', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
headers: { 'Content-Type': 'application/json', 'X-CSRFToken': csrfToken },
body: JSON.stringify({ loan_id: loanId })
})
.then(response => response.json())
+24 -14
View File
@@ -2343,7 +2343,7 @@ document.addEventListener('DOMContentLoaded', ()=>{
<div class="filter-container">
<div class="filter-group">
<div class="filter-header">
<label>Unterrichtsfach:</label>
<label>{{ filter_names.get('2', 'Fach') }}</label>
<button type="button" class="filter-toggle" onclick="toggleFilterDropdown('filter1-dropdown')"></button>
<button type="button" class="clear-filter" onclick="clearFilter(1)">Clear</button>
</div>
@@ -2357,7 +2357,7 @@ document.addEventListener('DOMContentLoaded', ()=>{
<div class="filter-group">
<div class="filter-header">
<label>Jahrgangsstufe:</label>
<label>{{ filter_names.get('1', 'Klassenstufe') }}</label>
<button type="button" class="filter-toggle" onclick="toggleFilterDropdown('filter2-dropdown')"></button>
<button type="button" class="clear-filter" onclick="clearFilter(2)">Clear</button>
</div>
@@ -2371,7 +2371,7 @@ document.addEventListener('DOMContentLoaded', ()=>{
<div class="filter-group">
<div class="filter-header">
<label>Schlagwort:</label>
<label>{{ filter_names.get('3', 'Schlagwort') }}</label>
<button type="button" class="filter-toggle" onclick="toggleFilterDropdown('filter3-dropdown')"></button>
<button type="button" class="clear-filter" onclick="clearFilter(3)">Clear</button>
</div>
@@ -2420,9 +2420,9 @@ document.addEventListener('DOMContentLoaded', ()=>{
<div id="table-view-header" class="table-view-header" aria-hidden="true">
<span>Name</span>
<span>Ort</span>
<span>Unterrichtsfach</span>
<span>Jahrgangsstufe</span>
<span>Schlagwort</span>
<span>{{ filter_names.get('2', 'Fach') }}</span>
<span>{{ filter_names.get('1', 'Jahrgangsstufe') }}</span>
<span>{{ filter_names.get('3', 'Schlagwort') }}</span>
<span>Barcode</span>
<span>Anzahl</span>
</div>
@@ -3418,14 +3418,24 @@ document.addEventListener('DOMContentLoaded', ()=>{
`<form method="POST" action="{{ url_for('ausleihen', id='') }}${item._id}">
${isGroupedItem ? `
<div class="grouped-borrow-controls" style="display:flex; gap:8px; flex-wrap:wrap; margin-bottom:8px; align-items:center;">
<label style="font-size:0.85rem; margin:0;">Anzahl:</label>
<input type="number" name="exemplare_count" min="1" max="${availableGroupedCount}" value="1" style="width:74px; padding:4px;">
<label style="font-size:0.85rem; margin:0;">oder Code:</label>
<select id="specific-item-card-${item._id}" name="specific_item_id" style="max-width:190px; padding:4px;">
<option value="">Automatisch wählen</option>
${groupedAvailableUnits.map(unit => `<option value="${unit.id}">${unit.code}</option>`).join('')}
</select>
</div>` : ''}
<label style="font-size:0.85rem; margin:0;">Anzahl:</label>
<input type="number"
name="exemplare_count"
min="1"
max="${availableGroupedCount}"
value="1"
style="width:74px; padding:4px;"
oninput="if(this.value){ this.form.querySelector('[name=specific_item_id]').value = ''; }">
<label style="font-size:0.85rem; margin:0;">oder Code:</label>
<select id="specific-item-card-${item._id}"
name="specific_item_id"
style="max-width:190px; padding:4px;"
onchange="if(this.value !== ''){ this.form.querySelector('[name=exemplare_count]').value = '1'; }">
<option value="">Automatisch wählen</option>
${groupedAvailableUnits.map(unit => `<option value="${unit.id}">${unit.code}</option>`).join('')}
</select>
</div>` : ''}
<button class="ausleihen" type="submit">Ausleihen</button>
</form>`
: isBorrowedByMe ?
+105 -67
View File
@@ -1,135 +1,173 @@
<!--
Copyright 2025-2026 AIIrondev
Licensed under the Inventarsystem EULA (Endbenutzer-Lizenzvertrag).
See Legal/LICENSE for the full license text.
Unauthorized commercial use, SaaS hosting, or removal of branding is prohibited.
For commercial licensing inquiries: https://github.com/AIIrondev
-->
{% extends "base.html" %}
{% block title %}Filter verwalten{% endblock %}
{% block content %}
<div class="container">
<h1 class="mb-4">Filterwerte verwalten</h1>
<div class="row">
<!-- Filter 1 -->
<div class="col-md-4">
<div class="card mb-4">
<div class="card-header">
<h2 class="card-title h5 mb-0">{{ filter_names.get('1', 'Jahrgang') }} (Filter 1)</h2>
<div class="container py-4">
<div class="d-flex flex-column flex-md-row justify-content-between align-items-md-center pb-3 mb-4 border-bottom gap-3">
<div>
<h1 class="h2 fw-bold mb-1">Filterwerte verwalten</h1>
<p class="text-muted mb-0">Verwalten und Bearbeiten Sie die Zuordnungswerte für das Inventar.</p>
</div>
<div>
<a href="{{ url_for('home_admin') }}" class="btn btn-outline-secondary d-inline-flex align-items-center">
<i class="bi bi-arrow-left me-2"></i> Zurück zur Admin-Übersicht
</a>
</div>
</div>
<div class="row g-4">
<div class="col-lg-6">
<div class="card shadow-sm border-0 h-100 rounded-3">
<div class="card-header bg-white border-bottom py-3 d-flex justify-content-between align-items-center">
<h2 class="card-title h5 mb-0 fw-semibold text-primary">
<i class="bi bi-funnel me-2"></i>{{ filter_names.get('1', 'Jahrgangsstufe') }}
</h2>
<span class="badge bg-primary-subtle text-primary rounded-pill">Filter 1</span>
</div>
<div class="card-body">
<div class="card-body p-4">
<form method="POST" action="{{ url_for('add_filter_value', filter_num=1) }}" class="mb-4">
<label class="form-label fw-medium text-secondary">Neuen Wert hinzufügen</label>
<div class="input-group">
<input type="text" name="value" class="form-control" placeholder="Neuer Wert..." required>
<button type="submit" class="btn btn-primary">Hinzufügen</button>
<input type="text" name="value" class="form-control" placeholder="Wert eingeben..." required>
<button type="submit" class="btn btn-primary d-inline-flex align-items-center">
<i class="bi bi-plus-lg me-1"></i> Hinzufügen
</button>
</div>
</form>
<h5 class="mb-3">Vorhandene Werte</h5>
<div class="d-flex justify-content-between align-items-center mb-3">
<h3 class="h6 text-uppercase text-muted fw-bold mb-0">Vorhandene Werte</h3>
<span class="badge bg-secondary rounded-pill">{{ filter1_values|length if filter1_values else 0 }}</span>
</div>
{% if filter1_values %}
<div class="list-group">
<div class="list-group list-group-flush border rounded-3 overflow-hidden">
{% for value in filter1_values %}
<div class="list-group-item">
<div class="d-flex justify-content-between align-items-center mb-2">
<span>{{ value }}</span>
<div>
<button type="button" class="btn btn-sm btn-secondary me-1" onclick="toggleEdit('edit-1-{{ loop.index }}')">Bearbeiten</button>
<div class="list-group-item p-3">
<div class="d-flex justify-content-between align-items-center">
<span class="fw-medium">{{ value }}</span>
<div class="btn-group btn-group-sm">
<button type="button" class="btn btn-outline-secondary" onclick="toggleEdit('edit-1-{{ loop.index }}')">
<i class="bi bi-pencil me-1"></i> Bearbeiten
</button>
<form method="POST" action="{{ url_for('remove_filter_value', filter_num=1, value=value) }}" class="d-inline">
<button type="submit" class="btn btn-sm btn-danger"
<button type="submit" class="btn btn-outline-danger"
onclick="return confirm('Sind Sie sicher, dass Sie den Wert \"' + '{{ value }}'.replace(/'/g, '\\\'') + '\" löschen möchten?');">
Entfernen
<i class="bi bi-trash me-1"></i> Entfernen
</button>
</form>
</div>
</div>
<form id="edit-1-{{ loop.index }}" method="POST" action="{{ url_for('edit_filter_value', filter_num=1, old_value=value) }}" style="display: none;" class="mt-2">
<form id="edit-1-{{ loop.index }}" method="POST" action="{{ url_for('edit_filter_value', filter_num=1, old_value=value) }}" style="display: none;" class="mt-3 pt-3 border-top">
<div class="input-group input-group-sm">
<input type="text" name="new_value" class="form-control" value="{{ value }}" required>
<button type="submit" class="btn btn-primary" onclick="return confirm('Tipp: Das Ändern des Namens aktualisiert auch alle Einträge in der Datenbank, die diesen Filter verwenden. Fortfahren?');">Speichern</button>
<button type="button" class="btn btn-secondary" onclick="toggleEdit('edit-1-{{ loop.index }}')">Abbrechen</button>
<button type="submit" class="btn btn-success" onclick="return confirm('Tipp: Das Ändern des Namens aktualisiert auch alle Einträge in der Datenbank, die diesen Filter verwenden. Fortfahren?');">
<i class="bi bi-check-lg me-1"></i> Speichern
</button>
<button type="button" class="btn btn-outline-secondary" onclick="toggleEdit('edit-1-{{ loop.index }}')">
Abbrechen
</button>
</div>
</form>
</div>
{% endfor %}
</div>
{% else %}
<div class="alert alert-info">Keine Werte definiert.</div>
<div class="alert alert-light border text-center text-muted mb-0">
<i class="bi bi-info-circle me-1"></i> Keine Werte definiert.
</div>
{% endif %}
</div>
</div>
</div>
<!-- Filter 2 -->
<div class="col-md-4">
<div class="card mb-4">
<div class="card-header">
<h2 class="card-title h5 mb-0">{{ filter_names.get('2', 'Fach') }} (Filter 2)</h2>
<div class="col-lg-6">
<div class="card shadow-sm border-0 h-100 rounded-3">
<div class="card-header bg-white border-bottom py-3 d-flex justify-content-between align-items-center">
<h2 class="card-title h5 mb-0 fw-semibold text-primary">
<i class="bi bi-funnel me-2"></i>{{ filter_names.get('2', 'Fachgebiet') }}
</h2>
<span class="badge bg-primary-subtle text-primary rounded-pill">Filter 2</span>
</div>
<div class="card-body">
<div class="card-body p-4">
<form method="POST" action="{{ url_for('add_filter_value', filter_num=2) }}" class="mb-4">
<label class="form-label fw-medium text-secondary">Neuen Wert hinzufügen</label>
<div class="input-group">
<input type="text" name="value" class="form-control" placeholder="Neuer Wert..." required>
<button type="submit" class="btn btn-primary">Hinzufügen</button>
<input type="text" name="value" class="form-control" placeholder="Wert eingeben..." required>
<button type="submit" class="btn btn-primary d-inline-flex align-items-center">
<i class="bi bi-plus-lg me-1"></i> Hinzufügen
</button>
</div>
</form>
<h5 class="mb-3">Vorhandene Werte</h5>
<div class="d-flex justify-content-between align-items-center mb-3">
<h3 class="h6 text-uppercase text-muted fw-bold mb-0">Vorhandene Werte</h3>
<span class="badge bg-secondary rounded-pill">{{ filter2_values|length if filter2_values else 0 }}</span>
</div>
{% if filter2_values %}
<div class="list-group">
<div class="list-group list-group-flush border rounded-3 overflow-hidden">
{% for value in filter2_values %}
<div class="list-group-item">
<div class="d-flex justify-content-between align-items-center mb-2">
<span>{{ value }}</span>
<div>
<button type="button" class="btn btn-sm btn-secondary me-1" onclick="toggleEdit('edit-2-{{ loop.index }}')">Bearbeiten</button>
<div class="list-group-item p-3">
<div class="d-flex justify-content-between align-items-center">
<span class="fw-medium">{{ value }}</span>
<div class="btn-group btn-group-sm">
<button type="button" class="btn btn-outline-secondary" onclick="toggleEdit('edit-2-{{ loop.index }}')">
<i class="bi bi-pencil me-1"></i> Bearbeiten
</button>
<form method="POST" action="{{ url_for('remove_filter_value', filter_num=2, value=value) }}" class="d-inline">
<button type="submit" class="btn btn-sm btn-danger"
<button type="submit" class="btn btn-outline-danger"
onclick="return confirm('Sind Sie sicher, dass Sie den Wert \"' + '{{ value }}'.replace(/'/g, '\\\'') + '\" löschen möchten?');">
Entfernen
<i class="bi bi-trash me-1"></i> Entfernen
</button>
</form>
</div>
</div>
<form id="edit-2-{{ loop.index }}" method="POST" action="{{ url_for('edit_filter_value', filter_num=2, old_value=value) }}" style="display: none;" class="mt-2">
<form id="edit-2-{{ loop.index }}" method="POST" action="{{ url_for('edit_filter_value', filter_num=2, old_value=value) }}" style="display: none;" class="mt-3 pt-3 border-top">
<div class="input-group input-group-sm">
<input type="text" name="new_value" class="form-control" value="{{ value }}" required>
<button type="submit" class="btn btn-primary" onclick="return confirm('Tipp: Das Ändern des Namens aktualisiert auch alle Einträge in der Datenbank, die diesen Filter verwenden. Fortfahren?');">Speichern</button>
<button type="button" class="btn btn-secondary" onclick="toggleEdit('edit-2-{{ loop.index }}')">Abbrechen</button>
<button type="submit" class="btn btn-success" onclick="return confirm('Tipp: Das Ändern des Namens aktualisiert auch alle Einträge in der Datenbank, die diesen Filter verwenden. Fortfahren?');">
<i class="bi bi-check-lg me-1"></i> Speichern
</button>
<button type="button" class="btn btn-outline-secondary" onclick="toggleEdit('edit-2-{{ loop.index }}')">
Abbrechen
</button>
</div>
</form>
</div>
{% endfor %}
</div>
{% else %}
<div class="alert alert-info">Keine Werte definiert.</div>
<div class="alert alert-light border text-center text-muted mb-0">
<i class="bi bi-info-circle me-1"></i> Keine Werte definiert.
</div>
{% endif %}
</div>
</div>
</div>
</div>
<div class="alert alert-warning">
<strong>Hinweis:</strong> Beim Entfernen eines Filterwertes wird dieser nicht aus bestehenden Objekten entfernt.
Bereits verwendete Werte bleiben in den Objekten erhalten.
</div>
<div class="mt-4">
<a href="{{ url_for('home_admin') }}" class="btn btn-secondary">Zurück zur Admin-Übersicht</a>
<div class="alert alert-warning border-0 shadow-sm d-flex align-items-center mt-4 rounded-3" role="alert">
<i class="bi bi-exclamation-triangle-fill fs-4 me-3 text-warning"></i>
<div>
<strong>Hinweis:</strong> Beim Entfernen eines Filterwertes wird dieser nicht automatisch aus bestehenden Objekten gelöscht. Bereits zugewiesene Werte bleiben in bestehenden Datensätzen erhalten.
</div>
</div>
</div>
<script>
function toggleEdit(id) {
const el = document.getElementById(id);
if (el.style.display === 'none') {
if (el.style.display === 'none' || el.style.display === '') {
el.style.display = 'block';
const input = el.querySelector('input[type="text"]');
if (input) input.focus();
} else {
el.style.display = 'none';
}
}
</script>
{% endblock %}
{% endblock %}
+3 -4
View File
@@ -670,7 +670,6 @@
<form method="POST" action="{{ url_for('upload_inventory_excel') }}" enctype="multipart/form-data" style="display:flex; gap:10px; flex-wrap:wrap; align-items:center;">
<input type="file" name="inventory_excel" accept=".xlsx,.csv" required>
<button type="button" class="btn btn-link" onclick="downloadSampleCsv('inventory')">Beispiel-CSV herunterladen</button>
<button type="button" class="btn btn-outline-secondary" title="Format-Hilfe" onclick="showCsvHelp('inventory')">?</button>
<button type="submit" class="btn btn-secondary" name="excel_action" value="validate">Nur validieren</button>
<button type="submit" class="btn btn-primary" name="excel_action" value="import">Inventar importieren</button>
</form>
@@ -781,7 +780,7 @@
{% else %}
<!-- Normal Item Mode: Standard Filters -->
<div class="filter-inputs">
<h3>Unterrichtsfach:</h3>
<h3>{{ filter_names.get('1', 'Jahrgangsstufe') }}</h3>
<div class="multi-filter">
<div class="form-group">
<label for="filter1-1">Wert 1:</label>
@@ -813,7 +812,7 @@
</div>
</div>
<h3>Jahrgangsstufe:</h3>
<h3>{{ filter_names.get('2', 'Fachgebiet') }}</h3>
<div class="multi-filter">
<div class="form-group">
<label for="filter2-1">Wert 1:</label>
@@ -845,7 +844,7 @@
</div>
</div>
<h3>Schlagwort:</h3>
<h3>{{ filter_names.get('3', 'Schlagwort') }}</h3>
<div class="multi-filter">
<div class="form-group">
<label for="filter3-1">Wert 1:</label>
+62 -8
View File
@@ -53,8 +53,11 @@
<option value="desc">Absteigend</option>
</select>
</div>
<div class="col-md-2">
<button class="btn btn-secondary w-100" onclick="resetFilters()">Filter zurücksetzen</button>
<div class="col-md-3">
<div class="d-flex gap-2">
<button class="btn btn-secondary flex-grow-1" onclick="resetFilters()">Zurücksetzen</button>
<button class="btn btn-success flex-grow-1" onclick="exportFilteredUsers()">Exportieren</button>
</div>
</div>
</div>
<div class="mt-2 text-muted small" id="filter-count"></div>
@@ -82,19 +85,20 @@
<td>{{ permission_presets.get(user.permission_preset, {}).get('label', user.permission_preset) }}</td>
<td class="actions">
<form method="POST" action="{{ url_for('delete_user') }}" class="d-inline">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<input type="hidden" name="username" value="{{ user.username }}">
<button type="submit" class="btn btn-danger btn-sm" onclick="return confirm('Sind Sie sicher, dass Sie den Benutzer {{ user.username }} löschen möchten?')">
Löschen
</button>
</form>
<button type="button" class="btn btn-primary btn-sm"
<button type="button" class="btn btn-primary btn-sm"
data-username="{{ user.username }}"
data-firstname="{{ user.name if user.name else '' }}"
data-lastname="{{ user.last_name if user.last_name else '' }}"
onclick="openEditUserModal(this)">
Bearbeiten
</button>
<button type="button" class="btn btn-warning btn-sm"
<button type="button" class="btn btn-warning btn-sm"
onclick="openResetPasswordModal('{{ user.username }}')">
Passwort zurücksetzen
</button>
@@ -124,6 +128,7 @@
<button type="button" class="btn-close" data-bs-dismiss="modal" aria-label="Close"></button>
</div>
<form method="POST" action="{{ url_for('admin_update_user_permissions') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<div class="modal-body permissions-modal-body">
<input type="hidden" id="perm-username" name="username">
<div class="mb-3">
@@ -180,6 +185,7 @@
<button type="button" class="btn-close" data-bs-dismiss="modal" aria-label="Close"></button>
</div>
<form method="POST" action="{{ url_for('admin_update_user_name') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<div class="modal-body">
<input type="hidden" id="edit-username" name="username">
<div class="mb-3">
@@ -213,6 +219,7 @@
<button type="button" class="btn-close" data-bs-dismiss="modal" aria-label="Close"></button>
</div>
<form method="POST" action="{{ url_for('admin_reset_user_password') }}">
<input type="hidden" name="csrf_token" value="{{ csrf_token }}">
<div class="modal-body">
<input type="hidden" id="reset-username" name="username">
<div class="mb-3">
@@ -313,6 +320,54 @@
applyFilters();
}
function exportFilteredUsers() {
var table = document.getElementById('user-table');
var tbody = table.querySelector('tbody');
var rows = Array.from(tbody.querySelectorAll('tr'));
var visibleUsernames = [];
// Sammle alle Benutzernamen, die durch den Filter aktuell NICHT versteckt sind
rows.forEach(function(row) {
if (row.style.display !== 'none') {
var cells = row.querySelectorAll('td');
if (cells.length > 0) {
visibleUsernames.push(cells[0].textContent.trim());
}
}
});
if (visibleUsernames.length === 0) {
alert('Keine Benutzer zum Exportieren vorhanden.');
return;
}
// Dynamisches Formular erstellen
var form = document.createElement('form');
form.method = 'POST';
form.action = "{{ url_for('export_users_csv') }}";
// 1. CSRF-Token als Wert (ohne Klammern) übergeben
var csrfInput = document.createElement('input');
csrfInput.type = 'hidden';
csrfInput.name = 'csrf_token';
csrfInput.value = "{{ csrf_token }}";
form.appendChild(csrfInput);
// 2. Gefilterte Benutzernamen hinzufügen
var input = document.createElement('input');
input.type = 'hidden';
input.name = 'usernames';
input.value = JSON.stringify(visibleUsernames);
form.appendChild(input);
document.body.appendChild(form);
form.submit();
// Aufräumen
document.body.removeChild(form);
}
document.addEventListener('DOMContentLoaded', function() {
applyFilters();
document.getElementById('filter-search').addEventListener('input', applyFilters);
@@ -332,12 +387,12 @@
var username = button.getAttribute('data-username');
var name = button.getAttribute('data-firstname');
var lastName = button.getAttribute('data-lastname');
document.getElementById('edit-username').value = username;
document.getElementById('edit-username-display').value = username;
document.getElementById('edit-name').value = name;
document.getElementById('edit-last-name').value = lastName;
var modal = new bootstrap.Modal(document.getElementById('editUserModal'));
modal.show();
}
@@ -345,8 +400,7 @@
function openResetPasswordModal(username) {
document.getElementById('reset-username').value = username;
document.getElementById('username-display').value = username;
// Open modal using Bootstrap
var modal = new bootstrap.Modal(document.getElementById('resetPasswordModal'));
modal.show();
}
+106 -72
View File
@@ -430,6 +430,7 @@ PY
initialize_tenant_database() {
local tenant_id="$1"
local mode="$2"
local admin_password="${3:-admin123}"
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
if [ -z "$APP_CONTAINER" ]; then
@@ -438,7 +439,8 @@ initialize_tenant_database() {
return 0
fi
docker exec -i "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
# Fix: We inject the password securely via a temporary environment variable (-e ADMIN_PASS)
docker exec -i -e ADMIN_PASS="$admin_password" "$APP_CONTAINER" python3 - "$tenant_id" "$mode" <<'PY'
import sys, os, re, datetime, hashlib
sys.path.insert(0, "/app")
sys.path.insert(0, "/app/Web")
@@ -449,6 +451,13 @@ import Web.modules.database.user as us
tenant_id = sys.argv[1].lower()
mode = sys.argv[2]
# Fix: Read the password directly from the environment variable instead of sys.argv
admin_password = os.environ.get("ADMIN_PASS", "admin123")
# Failsafe in case of empty string
if not admin_password.strip():
admin_password = "admin123"
sanitized = "".join(c for c in tenant_id if c.isalnum() or c == "_")
db_name = f"inventar_{sanitized}" if sanitized else settings.MONGODB_DB
@@ -458,7 +467,7 @@ users = db["users"]
permission_defaults = us.build_default_permission_payload("full_access")
admin_doc = {
"Username": "admin",
"Password": us.hashing("admin123"),
"Password": us.hashing(admin_password),
"Admin": True,
"active_ausleihung": None,
"name": dp.encrypt_text("admin"),
@@ -488,7 +497,7 @@ if mode == "trial":
client.close()
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / admin123")
print(f"Tenant {sys.argv[1]} database initialized. Default admin: admin / {admin_password}")
PY
}
@@ -812,12 +821,26 @@ case "$COMMAND" in
exit 1
fi
PORT_ARG="${3:-}"
if [ -n "$PORT_ARG" ]; then
if ! printf '%s\n' "$PORT_ARG" | grep -qE '^[0-9]+$'; then
echo "Error: Port must be a numeric value."
exit 1
ARG3="${3:-}"
ARG4="${4:-}"
PORT_ARG=""
PASSWORD_ARG="admin123"
# Check if the 3rd argument is numeric (Port) or text (Password)
if [ -n "$ARG3" ]; then
if printf '%s\n' "$ARG3" | grep -qE '^[0-9]+$'; then
PORT_ARG="$ARG3"
if [ -n "$ARG4" ]; then
PASSWORD_ARG="$ARG4"
fi
else
# If ARG3 is not numeric, treat it as the password without setting a port
PASSWORD_ARG="$ARG3"
fi
fi
if [ -n "$PORT_ARG" ]; then
register_tenant_port "$TENANT_ID" "$PORT_ARG"
update_runtime_ports "$PORT_ARG"
sync_tenant_port_map
@@ -829,11 +852,9 @@ case "$COMMAND" in
fi
fi
echo "Adding new tenant '$TENANT_ID'..."
echo "Initializing database for $TENANT_ID..."
initialize_tenant_database "$TENANT_ID" "standard"
initialize_tenant_database "$TENANT_ID" "standard" "$PASSWORD_ARG"
echo "Tenant '$TENANT_ID' successfully added. Ready to use."
;;
@@ -872,81 +893,94 @@ case "$COMMAND" in
;;
remove)
FORCE_REMOVE=false
TENANT_ARG="${2:-}"
FORCE_REMOVE=false
if [ "$TENANT_ARG" = "--yes" ] || [ "$TENANT_ARG" = "-y" ]; then
FORCE_REMOVE=true
TENANT_ID="${3:-}"
else
TENANT_ID="$TENANT_ARG"
# Fix: Prüfe sowohl Position 2 als auch 3 auf das -y Flag
if [ "${2:-}" = "--yes" ] || [ "${2:-}" = "-y" ]; then
FORCE_REMOVE=true
TENANT_ID="${3:-}"
elif [ "${3:-}" = "--yes" ] || [ "${3:-}" = "-y" ]; then
FORCE_REMOVE=true
TENANT_ID="${2:-}"
else
TENANT_ID="${2:-}"
fi
if [ -z "$TENANT_ID" ]; then
echo "Error: Please provide a tenant_id to remove."
exit 1
fi
if [ "$FORCE_REMOVE" != true ]; then
echo -n "WARNING: Are you sure you want to permanently delete all data for tenant '$TENANT_ID'? (y/N) "
read confirm
if [ "$confirm" != "y" ] && [ "$confirm" != "Y" ]; then
echo "Removal canceled."
exit 0
fi
fi
if [ -z "$TENANT_ID" ]; then
echo "Error: Please provide a tenant_id to remove."
exit 1
fi
echo "Removing tenant '$TENANT_ID'..."
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
port_to_remove=""
if [ "$FORCE_REMOVE" != true ]; then
echo -n "WARNING: Are you sure you want to permanently delete all data for tenant '$TENANT_ID'? (y/N) "
read confirm
if [ "$confirm" != "y" ] && [ "$confirm" != "Y" ]; then
echo "Removal canceled."
exit 0
fi
fi
if [ -n "$APP_CONTAINER" ]; then
# MongoDB-Datenbank via PyMongo direkt im Container droppen
# Fix 1: Wir hängen '|| true' an, damit das Skript nicht abstürzt, falls der Befehl fehlschlägt.
docker exec -i "$APP_CONTAINER" python3 -c '
import sys, os
try:
import pymongo
tenant_id = sys.argv[1]
# In Docker Compose heißt der Host oft "mongodb" statt "localhost"
mongo_uri = os.environ.get("MONGO_URI", "mongodb://mongodb:27017/")
client = pymongo.MongoClient(mongo_uri, serverSelectionTimeoutMS=2000)
echo "Removing tenant '$TENANT_ID'..."
APP_CONTAINER=$(docker ps -qf "name=app" | head -n 1)
port_to_remove=""
# Fix 2: Wir versuchen beide Formate zu löschen, da "list" zeigt, dass sie "test" und nicht "inventar_test" heißen.
dbs_to_drop = [f"inventar_{tenant_id}", tenant_id]
existing_dbs = client.list_database_names()
if [ -n "$APP_CONTAINER" ]; then
# MongoDB-Datenbank via PyMongo direkt im Container droppen
docker exec -i "$APP_CONTAINER" python3 -c '
import sys, os
try:
import pymongo
tenant_id = sys.argv[1]
mongo_uri = os.environ.get("MONGO_URI", "mongodb://localhost:27017/")
client = pymongo.MongoClient(mongo_uri, serverSelectionTimeoutMS=2000)
db_name = f"inventar_{tenant_id}"
if db_name in client.list_database_names():
for db_name in dbs_to_drop:
if db_name in existing_dbs:
client.drop_database(db_name)
print(f"Dropped database: {db_name}")
except Exception as e:
print(f"Error dropping database: {e}", file=sys.stderr)
' "$TENANT_ID" > /dev/null 2>&1
except Exception as e:
print(f"Error dropping database: {e}", file=sys.stderr)
' "$TENANT_ID" > /dev/null 2>&1 || true
# Konfiguration und Port via Host-Funktion bereinigen und Port ermitteln
if port_to_remove="$(remove_tenant_port "$TENANT_ID" 2>/dev/null)"; then
:
else
port_to_remove=""
fi
echo "Tenant '$TENANT_ID' database and config removed."
# Konfiguration und Port via Host-Funktion bereinigen und Port ermitteln
if port_to_remove="$(remove_tenant_port "$TENANT_ID" 2>/dev/null)"; then
:
else
echo "Warning: Application container not running. Tenant database may still exist in MongoDB."
if port_to_remove="$(remove_tenant_port "$TENANT_ID" 2>/dev/null)"; then
:
else
echo "Warning: tenant '$TENANT_ID' was not configured in config.json or could not be removed."
fi
port_to_remove=""
fi
if [ -n "$port_to_remove" ]; then
remove_runtime_port "$port_to_remove"
fi
remove_tenant_nginx_config "$TENANT_ID"
sync_tenant_port_map
if [ -n "$(docker ps -qf 'name=app' | head -n 1)" ]; then
restart_app_container
fi
if [ -n "$port_to_remove" ]; then
echo "Removed tenant '$TENANT_ID' and cleaned runtime port $port_to_remove."
echo "Tenant '$TENANT_ID' database and config removed."
else
echo "Warning: Application container not running. Tenant database may still exist in MongoDB."
if port_to_remove="$(remove_tenant_port "$TENANT_ID" 2>/dev/null)"; then
:
else
echo "Removed tenant '$TENANT_ID'. No port mapping was present."
echo "Warning: tenant '$TENANT_ID' was not configured in config.json or could not be removed."
fi
fi
if [ -n "$port_to_remove" ]; then
remove_runtime_port "$port_to_remove" 2>/dev/null || true
fi
remove_tenant_nginx_config "$TENANT_ID"
sync_tenant_port_map
if [ -n "$(docker ps -qf 'name=app' | head -n 1)" ]; then
restart_app_container || true
fi
if [ -n "$port_to_remove" ]; then
echo "Removed tenant '$TENANT_ID' and cleaned runtime port $port_to_remove."
else
echo "Removed tenant '$TENANT_ID'. No port mapping was present."
fi
;;
restart-tenant)