Compare commits

...

11 Commits

135 changed files with 14200 additions and 10544 deletions

12
.gitignore vendored
View File

@ -1,6 +1,6 @@
node_modules/ node_modules/
.env .env
uploads/ uploads/
documents/ documents/
logs/ logs/
*.log *.log

View File

@ -1,2 +1,2 @@
# privatarzt_software # privatarzt_software

View File

@ -1,2 +1,2 @@
const bcrypt = require("bcrypt"); const bcrypt = require("bcrypt");
bcrypt.hash("1234", 10).then(hash => console.log(hash)); bcrypt.hash("1234", 10).then(hash => console.log(hash));

View File

@ -1,231 +1,231 @@
/** /**
* import_medications.js * import_medications.js
* *
* Importiert Medikamente aus einer Word-Datei (.docx) * Importiert Medikamente aus einer Word-Datei (.docx)
* und speichert sie normalisiert in MySQL: * und speichert sie normalisiert in MySQL:
* - medications * - medications
* - medication_forms * - medication_forms
* - medication_variants * - medication_variants
* *
* JEDE Kombination aus * JEDE Kombination aus
* Medikament × Darreichungsform × Dosierung × Packung * Medikament × Darreichungsform × Dosierung × Packung
* wird als eigener Datensatz gespeichert. * wird als eigener Datensatz gespeichert.
*/ */
const mammoth = require("mammoth"); const mammoth = require("mammoth");
const mysql = require("mysql2/promise"); const mysql = require("mysql2/promise");
const path = require("path"); const path = require("path");
/* ============================== /* ==============================
KONFIGURATION KONFIGURATION
============================== */ ============================== */
// 🔹 Pfad zur Word-Datei (exakt!) // 🔹 Pfad zur Word-Datei (exakt!)
const WORD_FILE = path.join( const WORD_FILE = path.join(
__dirname, __dirname,
"MEDIKAMENTE 228.02.2024 docx.docx" "MEDIKAMENTE 228.02.2024 docx.docx"
); );
// 🔹 MySQL Zugangsdaten // 🔹 MySQL Zugangsdaten
const DB_CONFIG = { const DB_CONFIG = {
host: "85.215.63.122", host: "85.215.63.122",
user: "praxisuser", user: "praxisuser",
password: "praxisuser", password: "praxisuser",
database: "praxissoftware" database: "praxissoftware"
}; };
/* ============================== /* ==============================
HAUPTFUNKTION HAUPTFUNKTION
============================== */ ============================== */
async function importMedications() { async function importMedications() {
console.log("📄 Lese Word-Datei …"); console.log("📄 Lese Word-Datei …");
// 1⃣ Word-Datei lesen // 1⃣ Word-Datei lesen
const result = await mammoth.extractRawText({ path: WORD_FILE }); const result = await mammoth.extractRawText({ path: WORD_FILE });
// 2⃣ Text → saubere Zeilen // 2⃣ Text → saubere Zeilen
const lines = result.value const lines = result.value
.split("\n") .split("\n")
.map(l => l.trim()) .map(l => l.trim())
.filter(l => l.length > 0); .filter(l => l.length > 0);
console.log(`📑 ${lines.length} Zeilen gefunden`); console.log(`📑 ${lines.length} Zeilen gefunden`);
// 3⃣ DB verbinden // 3⃣ DB verbinden
const db = await mysql.createConnection(DB_CONFIG); const db = await mysql.createConnection(DB_CONFIG);
let currentMedication = null; let currentMedication = null;
// 4⃣ Zeilen verarbeiten // 4⃣ Zeilen verarbeiten
for (let i = 0; i < lines.length; i++) { for (let i = 0; i < lines.length; i++) {
const line = lines[i]; const line = lines[i];
/* ------------------------------ /* ------------------------------
Medikamentenname erkennen Medikamentenname erkennen
(keine Zahlen → Name) (keine Zahlen → Name)
------------------------------ */ ------------------------------ */
if (!/\d/.test(line)) { if (!/\d/.test(line)) {
currentMedication = line; currentMedication = line;
await insertMedication(db, currentMedication); await insertMedication(db, currentMedication);
continue; continue;
} }
/* ------------------------------ /* ------------------------------
Sicherheit: keine Basis Sicherheit: keine Basis
------------------------------ */ ------------------------------ */
if (!currentMedication) { if (!currentMedication) {
console.warn("⚠️ Überspringe Zeile ohne Medikament:", line); console.warn("⚠️ Überspringe Zeile ohne Medikament:", line);
continue; continue;
} }
/* ------------------------------ /* ------------------------------
Dosierungen splitten Dosierungen splitten
z.B. "50mg / 100mg" z.B. "50mg / 100mg"
------------------------------ */ ------------------------------ */
const dosages = line const dosages = line
.split("/") .split("/")
.map(d => d.trim()) .map(d => d.trim())
.filter(d => d.length > 0); .filter(d => d.length > 0);
/* ------------------------------ /* ------------------------------
Packungen splitten Packungen splitten
z.B. "30 Comp. / 100 Comp." z.B. "30 Comp. / 100 Comp."
------------------------------ */ ------------------------------ */
const rawPackage = lines[i + 1] || ""; const rawPackage = lines[i + 1] || "";
const packages = rawPackage const packages = rawPackage
.split("/") .split("/")
.map(p => p.trim()) .map(p => p.trim())
.filter(p => p.length > 0); .filter(p => p.length > 0);
if (packages.length === 0) { if (packages.length === 0) {
console.warn("⚠️ Keine Packung für:", currentMedication, line); console.warn("⚠️ Keine Packung für:", currentMedication, line);
continue; continue;
} }
/* ------------------------------ /* ------------------------------
Darreichungsform ermitteln Darreichungsform ermitteln
------------------------------ */ ------------------------------ */
const form = detectForm(rawPackage); const form = detectForm(rawPackage);
/* ------------------------------ /* ------------------------------
JEDE Kombination speichern JEDE Kombination speichern
------------------------------ */ ------------------------------ */
for (const dosage of dosages) { for (const dosage of dosages) {
for (const packageInfo of packages) { for (const packageInfo of packages) {
await insertVariant( await insertVariant(
db, db,
currentMedication, currentMedication,
dosage, dosage,
form, form,
packageInfo packageInfo
); );
} }
} }
i++; // Packungszeile überspringen i++; // Packungszeile überspringen
} }
await db.end(); await db.end();
console.log("✅ Import abgeschlossen"); console.log("✅ Import abgeschlossen");
} }
/* ============================== /* ==============================
HILFSFUNKTIONEN HILFSFUNKTIONEN
============================== */ ============================== */
async function insertMedication(db, name) { async function insertMedication(db, name) {
await db.execute( await db.execute(
"INSERT IGNORE INTO medications (name) VALUES (?)", "INSERT IGNORE INTO medications (name) VALUES (?)",
[name] [name]
); );
} }
async function insertVariant(db, medicationName, dosage, formName, packageInfo) { async function insertVariant(db, medicationName, dosage, formName, packageInfo) {
// Medikament-ID holen // Medikament-ID holen
const [[med]] = await db.execute( const [[med]] = await db.execute(
"SELECT id FROM medications WHERE name = ?", "SELECT id FROM medications WHERE name = ?",
[medicationName] [medicationName]
); );
if (!med) { if (!med) {
console.warn("⚠️ Medikament nicht gefunden:", medicationName); console.warn("⚠️ Medikament nicht gefunden:", medicationName);
return; return;
} }
// Darreichungsform anlegen falls neu // Darreichungsform anlegen falls neu
await db.execute( await db.execute(
"INSERT IGNORE INTO medication_forms (name) VALUES (?)", "INSERT IGNORE INTO medication_forms (name) VALUES (?)",
[formName] [formName]
); );
const [[form]] = await db.execute( const [[form]] = await db.execute(
"SELECT id FROM medication_forms WHERE name = ?", "SELECT id FROM medication_forms WHERE name = ?",
[formName] [formName]
); );
if (!form) { if (!form) {
console.warn("⚠️ Darreichungsform nicht gefunden:", formName); console.warn("⚠️ Darreichungsform nicht gefunden:", formName);
return; return;
} }
// Variante speichern // Variante speichern
await db.execute( await db.execute(
`INSERT INTO medication_variants `INSERT INTO medication_variants
(medication_id, form_id, dosage, package) (medication_id, form_id, dosage, package)
VALUES (?, ?, ?, ?)`, VALUES (?, ?, ?, ?)`,
[ [
med.id, med.id,
form.id, form.id,
normalizeDosage(dosage), normalizeDosage(dosage),
normalizePackage(packageInfo) normalizePackage(packageInfo)
] ]
); );
} }
/* ============================== /* ==============================
NORMALISIERUNG NORMALISIERUNG
============================== */ ============================== */
function normalizeDosage(text) { function normalizeDosage(text) {
return text return text
.replace(/\s+/g, " ") .replace(/\s+/g, " ")
.replace(/mg/gi, " mg") .replace(/mg/gi, " mg")
.replace(/ml/gi, " ml") .replace(/ml/gi, " ml")
.trim(); .trim();
} }
function normalizePackage(text) { function normalizePackage(text) {
return text return text
.replace(/\s+/g, " ") .replace(/\s+/g, " ")
.replace(/comp\.?/gi, "Comp.") .replace(/comp\.?/gi, "Comp.")
.replace(/tabl\.?/gi, "Tbl.") .replace(/tabl\.?/gi, "Tbl.")
.trim(); .trim();
} }
/* ============================== /* ==============================
DARREICHUNGSFORM ERKENNEN DARREICHUNGSFORM ERKENNEN
============================== */ ============================== */
function detectForm(text) { function detectForm(text) {
if (!text) return "Unbekannt"; if (!text) return "Unbekannt";
const t = text.toLowerCase(); const t = text.toLowerCase();
if (t.includes("tabl") || t.includes("comp")) return "Tabletten"; if (t.includes("tabl") || t.includes("comp")) return "Tabletten";
if (t.includes("caps")) return "Kapseln"; if (t.includes("caps")) return "Kapseln";
if (t.includes("saft") || t.includes("ml")) return "Saft"; if (t.includes("saft") || t.includes("ml")) return "Saft";
if (t.includes("creme") || t.includes("salbe")) return "Creme"; if (t.includes("creme") || t.includes("salbe")) return "Creme";
if (t.includes("inj")) return "Injektion"; if (t.includes("inj")) return "Injektion";
return "Unbekannt"; return "Unbekannt";
} }
/* ============================== /* ==============================
START START
============================== */ ============================== */
importMedications().catch(err => { importMedications().catch(err => {
console.error("❌ Fehler beim Import:", err); console.error("❌ Fehler beim Import:", err);
}); });

View File

@ -1,116 +1,116 @@
/** /**
* Excel → MySQL Import * Excel → MySQL Import
* - importiert ALLE Sheets * - importiert ALLE Sheets
* - Sheet-Name wird als Kategorie gespeichert * - Sheet-Name wird als Kategorie gespeichert
* - Preise robust (Number, "55,00 €", Text, leer) * - Preise robust (Number, "55,00 €", Text, leer)
*/ */
const xlsx = require("xlsx"); const xlsx = require("xlsx");
const db = require("./db"); const db = require("./db");
// =============================== // ===============================
// KONFIG // KONFIG
// =============================== // ===============================
const FILE_PATH = "2024091001 Preisliste PRAXIS.xlsx"; const FILE_PATH = "2024091001 Preisliste PRAXIS.xlsx";
// =============================== // ===============================
// HILFSFUNKTIONEN // HILFSFUNKTIONEN
// =============================== // ===============================
function getColumn(row, name) { function getColumn(row, name) {
const key = Object.keys(row).find(k => const key = Object.keys(row).find(k =>
k.toLowerCase().includes(name.toLowerCase()) k.toLowerCase().includes(name.toLowerCase())
); );
return key ? row[key] : undefined; return key ? row[key] : undefined;
} }
function parsePrice(value) { function parsePrice(value) {
if (value === undefined || value === null) return 0.00; if (value === undefined || value === null) return 0.00;
// Excel-Währungsfeld → Number // Excel-Währungsfeld → Number
if (typeof value === "number") { if (typeof value === "number") {
return value; return value;
} }
// String → Zahl extrahieren // String → Zahl extrahieren
if (typeof value === "string") { if (typeof value === "string") {
const cleaned = value const cleaned = value
.replace(",", ".") .replace(",", ".")
.replace(/[^\d.]/g, ""); .replace(/[^\d.]/g, "");
const parsed = parseFloat(cleaned); const parsed = parseFloat(cleaned);
return isNaN(parsed) ? 0.00 : parsed; return isNaN(parsed) ? 0.00 : parsed;
} }
return 0.00; return 0.00;
} }
// =============================== // ===============================
// START // START
// =============================== // ===============================
console.log("📄 Lese Excel-Datei …"); console.log("📄 Lese Excel-Datei …");
const workbook = xlsx.readFile(FILE_PATH); const workbook = xlsx.readFile(FILE_PATH);
const sheetNames = workbook.SheetNames; const sheetNames = workbook.SheetNames;
console.log(`📑 ${sheetNames.length} Sheets gefunden:`, sheetNames); console.log(`📑 ${sheetNames.length} Sheets gefunden:`, sheetNames);
// =============================== // ===============================
// IMPORT ALLER SHEETS // IMPORT ALLER SHEETS
// =============================== // ===============================
sheetNames.forEach(sheetName => { sheetNames.forEach(sheetName => {
console.log(`➡️ Importiere Sheet: "${sheetName}"`); console.log(`➡️ Importiere Sheet: "${sheetName}"`);
const sheet = workbook.Sheets[sheetName]; const sheet = workbook.Sheets[sheetName];
const rows = xlsx.utils.sheet_to_json(sheet); const rows = xlsx.utils.sheet_to_json(sheet);
console.log(` ↳ ${rows.length} Zeilen gefunden`); console.log(` ↳ ${rows.length} Zeilen gefunden`);
rows.forEach((row, index) => { rows.forEach((row, index) => {
// =============================== // ===============================
// TEXTFELDER // TEXTFELDER
// =============================== // ===============================
const name_de = getColumn(row, "deutsch") const name_de = getColumn(row, "deutsch")
? getColumn(row, "deutsch").toString().trim() ? getColumn(row, "deutsch").toString().trim()
: "--"; : "--";
const name_es = getColumn(row, "spanisch") const name_es = getColumn(row, "spanisch")
? getColumn(row, "spanisch").toString().trim() ? getColumn(row, "spanisch").toString().trim()
: "--"; : "--";
// =============================== // ===============================
// PREISE // PREISE
// =============================== // ===============================
const price = parsePrice(getColumn(row, "preis")); const price = parsePrice(getColumn(row, "preis"));
const price_c70 = parsePrice(getColumn(row, "c70")); const price_c70 = parsePrice(getColumn(row, "c70"));
// =============================== // ===============================
// INSERT // INSERT
// =============================== // ===============================
db.query( db.query(
` `
INSERT INTO services INSERT INTO services
(name_de, name_es, category, price, price_c70) (name_de, name_es, category, price, price_c70)
VALUES (?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?)
`, `,
[ [
name_de, name_de,
name_es, name_es,
sheetName, // 👈 Kategorie = Sheet-Name sheetName, // 👈 Kategorie = Sheet-Name
price, price,
price_c70 price_c70
], ],
err => { err => {
if (err) { if (err) {
console.error( console.error(
`❌ Fehler in Sheet "${sheetName}", Zeile ${index + 2}:`, `❌ Fehler in Sheet "${sheetName}", Zeile ${index + 2}:`,
err.message err.message
); );
} }
} }
); );
}); });
}); });
console.log("✅ Import aller Sheets abgeschlossen"); console.log("✅ Import aller Sheets abgeschlossen");

697
app.js
View File

@ -1,263 +1,434 @@
require("dotenv").config(); require("dotenv").config();
const express = require("express"); const express = require("express");
const session = require("express-session"); const session = require("express-session");
const helmet = require("helmet"); const helmet = require("helmet");
const mysql = require("mysql2/promise"); const fs = require("fs");
const fs = require("fs"); const path = require("path");
const path = require("path"); const expressLayouts = require("express-ejs-layouts");
// ✅ Verschlüsselte Config // ✅ DB + Session Store
const { configExists, saveConfig } = require("./config-manager"); const db = require("./db");
const { getSessionStore } = require("./config/session");
// ✅ Reset-Funktionen (Soft-Restart)
const db = require("./db"); // ✅ Setup Middleware + Setup Routes
const { getSessionStore, resetSessionStore } = require("./config/session"); const requireSetup = require("./middleware/requireSetup");
const setupRoutes = require("./routes/setup.routes");
// ✅ Deine Routes (unverändert)
const adminRoutes = require("./routes/admin.routes"); // ✅ Routes (deine)
const dashboardRoutes = require("./routes/dashboard.routes"); const adminRoutes = require("./routes/admin.routes");
const patientRoutes = require("./routes/patient.routes"); const dashboardRoutes = require("./routes/dashboard.routes");
const medicationRoutes = require("./routes/medications.routes"); const patientRoutes = require("./routes/patient.routes");
const patientMedicationRoutes = require("./routes/patientMedication.routes"); const medicationRoutes = require("./routes/medications.routes");
const waitingRoomRoutes = require("./routes/waitingRoom.routes"); const patientMedicationRoutes = require("./routes/patientMedication.routes");
const serviceRoutes = require("./routes/service.routes"); const waitingRoomRoutes = require("./routes/waitingRoom.routes");
const patientServiceRoutes = require("./routes/patientService.routes"); const serviceRoutes = require("./routes/service.routes");
const invoiceRoutes = require("./routes/invoice.routes"); const patientServiceRoutes = require("./routes/patientService.routes");
const patientFileRoutes = require("./routes/patientFile.routes"); const invoiceRoutes = require("./routes/invoice.routes");
const companySettingsRoutes = require("./routes/companySettings.routes"); const patientFileRoutes = require("./routes/patientFile.routes");
const authRoutes = require("./routes/auth.routes"); const companySettingsRoutes = require("./routes/companySettings.routes");
const authRoutes = require("./routes/auth.routes");
const app = express(); const reportRoutes = require("./routes/report.routes");
/* =============================== const app = express();
SETUP HTML
================================ */ /* ===============================
function setupHtml(error = "") { Seriennummer / Trial Konfiguration
return ` ================================ */
<!doctype html> const TRIAL_DAYS = 30;
<html lang="de">
<head> /* ===============================
<meta charset="utf-8" /> Seriennummer Helper Funktionen
<meta name="viewport" content="width=device-width, initial-scale=1" /> ================================ */
<title>Praxissoftware Setup</title> function normalizeSerial(input) {
<style> return (input || "")
body{font-family:Arial;background:#f4f4f4;padding:30px} .toUpperCase()
.card{max-width:520px;margin:auto;background:#fff;padding:22px;border-radius:14px} .replace(/[^A-Z0-9-]/g, "")
input{width:100%;padding:10px;margin:6px 0;border:1px solid #ccc;border-radius:8px} .trim();
button{padding:10px 14px;border:0;border-radius:8px;background:#111;color:#fff;cursor:pointer} }
.err{color:#b00020;margin:10px 0}
.hint{color:#666;font-size:13px;margin-top:12px} // Format: AAAAA-AAAAA-AAAAA-AAAAA
</style> function isValidSerialFormat(serial) {
</head> return /^[A-Z0-9]{5}(-[A-Z0-9]{5}){3}$/.test(serial);
<body> }
<div class="card">
<h2>🔧 Datenbank Einrichtung</h2> // Modulo-3 Check (Summe aller Zeichenwerte % 3 === 0)
${error ? `<div class="err">❌ ${error}</div>` : ""} function passesModulo3(serial) {
const raw = serial.replace(/-/g, "");
<form method="POST" action="/setup"> let sum = 0;
<label>DB Host</label>
<input name="host" placeholder="85.215.63.122" required /> for (const ch of raw) {
if (/[0-9]/.test(ch)) sum += parseInt(ch, 10);
<label>DB Benutzer</label> else sum += ch.charCodeAt(0) - 55; // A=10
<input name="user" placeholder="praxisuser" required /> }
<label>DB Passwort</label> return sum % 3 === 0;
<input name="password" type="password" required /> }
<label>DB Name</label> /* ===============================
<input name="name" placeholder="praxissoftware" required /> MIDDLEWARE
================================ */
<button type="submit"> Speichern</button> app.use(express.urlencoded({ extended: true }));
</form> app.use(express.json());
<div class="hint"> app.use(
Die Daten werden verschlüsselt gespeichert (<b>config.enc</b>).<br/> helmet({
Danach wirst du automatisch auf die Loginseite weitergeleitet. contentSecurityPolicy: {
</div> directives: {
</div> defaultSrc: ["'self'"],
</body> scriptSrc: ["'self'"],
</html> styleSrc: ["'self'", "'unsafe-inline'"],
`; imgSrc: ["'self'", "data:"],
} },
},
/* =============================== }),
MIDDLEWARE );
================================ */
app.use(express.urlencoded({ extended: true })); app.use(
app.use(express.json()); session({
app.use(helmet()); name: "praxis.sid",
secret: process.env.SESSION_SECRET || "dev-secret",
// ✅ SessionStore dynamisch (Setup: MemoryStore, normal: MySQLStore) store: getSessionStore(),
app.use( resave: false,
session({ saveUninitialized: false,
name: "praxis.sid", }),
secret: process.env.SESSION_SECRET, );
store: getSessionStore(),
resave: false, // ✅ i18n Middleware (SAFE)
saveUninitialized: false, app.use((req, res, next) => {
}), try {
); const lang = req.session.lang || "de";
const filePath = path.join(__dirname, "locales", `${lang}.json`);
// ✅ i18n Middleware
app.use((req, res, next) => { let data = {};
const lang = req.session.lang || "de"; // Standard DE if (fs.existsSync(filePath)) {
data = JSON.parse(fs.readFileSync(filePath, "utf-8"));
const filePath = path.join(__dirname, "locales", `${lang}.json`); }
const raw = fs.readFileSync(filePath, "utf-8");
res.locals.t = data;
res.locals.t = JSON.parse(raw); // t = translations res.locals.lang = lang;
res.locals.lang = lang; next();
} catch (err) {
next(); console.error("❌ i18n Fehler:", err.message);
}); res.locals.t = {};
res.locals.lang = "de";
const flashMiddleware = require("./middleware/flash.middleware"); next();
app.use(flashMiddleware); }
});
app.use(express.static("public"));
app.use("/uploads", express.static("uploads")); const flashMiddleware = require("./middleware/flash.middleware");
app.set("view engine", "ejs"); app.use(flashMiddleware);
app.use((req, res, next) => {
res.locals.user = req.session.user || null; app.use(express.static("public"));
next(); app.use("/uploads", express.static("uploads"));
});
app.set("view engine", "ejs");
/* =============================== app.set("views", path.join(__dirname, "views"));
SETUP ROUTES app.use(expressLayouts);
================================ */ app.set("layout", "layout");
// Setup-Seite app.use((req, res, next) => {
app.get("/setup", (req, res) => { res.locals.user = req.session.user || null;
if (configExists()) return res.redirect("/"); next();
return res.status(200).send(setupHtml()); });
});
/* ===============================
// Setup speichern + DB testen + Soft-Restart + Login redirect SETUP ROUTES + SETUP GATE
app.post("/setup", async (req, res) => { WICHTIG: /setup zuerst mounten, danach requireSetup
try { ================================ */
const { host, user, password, name } = req.body; app.use("/setup", setupRoutes);
app.use(requireSetup);
if (!host || !user || !password || !name) {
return res.status(400).send(setupHtml("Bitte alle Felder ausfüllen.")); /* ===============================
} LICENSE/TRIAL GATE
================================ */
// ✅ DB Verbindung testen app.use(async (req, res, next) => {
const conn = await mysql.createConnection({ try {
host, // Setup muss erreichbar bleiben
user, if (req.path.startsWith("/setup")) return next();
password,
database: name, // Login muss erreichbar bleiben
}); if (req.path === "/" || req.path.startsWith("/login")) return next();
await conn.query("SELECT 1"); // Serial Seiten müssen erreichbar bleiben
await conn.end(); if (req.path.startsWith("/serial-number")) return next();
if (req.path.startsWith("/admin/serial-number")) return next();
// ✅ verschlüsselt speichern
saveConfig({ // Sprache ändern erlauben
db: { host, user, password, name }, if (req.path.startsWith("/lang/")) return next();
});
// Nicht eingeloggt -> auth regelt das
// ✅ Soft-Restart (DB Pool + SessionStore neu laden) if (!req.session?.user) return next();
if (typeof db.resetPool === "function") {
db.resetPool(); const [rowsSettings] = await db.promise().query(
} `SELECT id, serial_number, trial_started_at
resetSessionStore(); FROM company_settings
ORDER BY id ASC
// ✅ automatisch zurück zur Loginseite LIMIT 1`,
return res.redirect("/"); );
} catch (err) {
return res const settings = rowsSettings?.[0];
.status(500)
.send(setupHtml("DB Verbindung fehlgeschlagen: " + err.message)); // ✅ Seriennummer vorhanden -> alles OK
} if (settings?.serial_number) return next();
});
// ✅ Trial Start setzen wenn leer
// Wenn keine config.enc → alles außer /setup auf Setup umleiten if (settings?.id && !settings?.trial_started_at) {
app.use((req, res, next) => { await db
if (!configExists() && req.path !== "/setup") { .promise()
return res.redirect("/setup"); .query(
} `UPDATE company_settings SET trial_started_at = NOW() WHERE id = ?`,
next(); [settings.id],
}); );
return next();
//Sprachen Route }
// ✅ i18n Middleware (Sprache pro Benutzer über Session)
app.use((req, res, next) => { // Wenn noch immer kein trial start: nicht blockieren
const lang = req.session.lang || "de"; // Standard: Deutsch if (!settings?.trial_started_at) return next();
let translations = {}; const trialStart = new Date(settings.trial_started_at);
try { const now = new Date();
const filePath = path.join(__dirname, "locales", `${lang}.json`); const diffDays = Math.floor((now - trialStart) / (1000 * 60 * 60 * 24));
translations = JSON.parse(fs.readFileSync(filePath, "utf-8"));
} catch (err) { // ✅ Trial läuft noch
console.error("❌ i18n Fehler:", err.message); if (diffDays < TRIAL_DAYS) return next();
}
// ❌ Trial abgelaufen
// ✅ In EJS verfügbar machen if (req.session.user.role === "admin") {
res.locals.t = translations; return res.redirect("/admin/serial-number");
res.locals.lang = lang; }
next(); return res.redirect("/serial-number");
}); } catch (err) {
console.error("❌ LicenseGate Fehler:", err.message);
app.get("/lang/:lang", (req, res) => { return next();
const newLang = req.params.lang; }
});
if (!["de", "es"].includes(newLang)) {
return res.redirect(req.get("Referrer") || "/dashboard"); /* ===============================
} Sprache ändern
================================ */
req.session.lang = newLang; app.get("/lang/:lang", (req, res) => {
const newLang = req.params.lang;
// ✅ WICHTIG: Session speichern bevor redirect
req.session.save((err) => { if (!["de", "es"].includes(newLang)) {
if (err) console.error("❌ Session save error:", err); return res.redirect(req.get("Referrer") || "/dashboard");
}
return res.redirect(req.get("Referrer") || "/dashboard");
}); req.session.lang = newLang;
});
req.session.save((err) => {
/* =============================== if (err) console.error("❌ Session save error:", err);
DEINE LOGIK (unverändert) return res.redirect(req.get("Referrer") || "/dashboard");
================================ */ });
});
app.use(companySettingsRoutes);
app.use("/", authRoutes); /* ===============================
app.use("/dashboard", dashboardRoutes); SERIAL PAGES
app.use("/admin", adminRoutes); ================================ */
app.get("/serial-number", async (req, res) => {
app.use("/patients", patientRoutes); try {
app.use("/patients", patientMedicationRoutes); if (!req.session?.user) return res.redirect("/");
app.use("/patients", patientServiceRoutes);
const [rowsSettings] = await db.promise().query(
app.use("/medications", medicationRoutes); `SELECT id, serial_number, trial_started_at
console.log("🧪 /medications Router mounted"); FROM company_settings
ORDER BY id ASC
app.use("/services", serviceRoutes); LIMIT 1`,
);
app.use("/", patientFileRoutes);
app.use("/", waitingRoomRoutes); const settings = rowsSettings?.[0];
app.use("/", invoiceRoutes);
// ✅ Seriennummer da -> ab ins Dashboard
app.get("/logout", (req, res) => { if (settings?.serial_number) return res.redirect("/dashboard");
req.session.destroy(() => res.redirect("/"));
}); // ✅ Trial Start setzen wenn leer
if (settings?.id && !settings?.trial_started_at) {
/* =============================== await db
ERROR HANDLING .promise()
================================ */ .query(
app.use((err, req, res, next) => { `UPDATE company_settings SET trial_started_at = NOW() WHERE id = ?`,
console.error(err); [settings.id],
res.status(500).send("Interner Serverfehler"); );
}); settings.trial_started_at = new Date();
}
/* ===============================
SERVER // ✅ Resttage berechnen
================================ */ let daysLeft = TRIAL_DAYS;
const PORT = process.env.PORT || 51777;
const HOST = "127.0.0.1"; if (settings?.trial_started_at) {
const trialStart = new Date(settings.trial_started_at);
app.listen(PORT, HOST, () => { const now = new Date();
console.log(`Server läuft auf http://${HOST}:${PORT}`); const diffDays = Math.floor((now - trialStart) / (1000 * 60 * 60 * 24));
}); daysLeft = Math.max(0, TRIAL_DAYS - diffDays);
}
// ❌ Trial abgelaufen
if (daysLeft <= 0) {
if (req.session.user.role === "admin") {
return res.redirect("/admin/serial-number");
}
return res.render("trial_expired", {
user: req.session.user,
lang: req.session.lang || "de",
});
}
// ✅ Trial aktiv
return res.render("serial_number_info", {
user: req.session.user,
lang: req.session.lang || "de",
daysLeft,
});
} catch (err) {
console.error(err);
return res.status(500).send("Interner Serverfehler");
}
});
app.get("/admin/serial-number", async (req, res) => {
try {
if (!req.session?.user) return res.redirect("/");
if (req.session.user.role !== "admin")
return res.status(403).send("Forbidden");
const [rowsSettings] = await db
.promise()
.query(
`SELECT serial_number FROM company_settings ORDER BY id ASC LIMIT 1`,
);
const currentSerial = rowsSettings?.[0]?.serial_number || "";
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial,
error: null,
success: null,
});
} catch (err) {
console.error(err);
return res.status(500).send("Interner Serverfehler");
}
});
app.post("/admin/serial-number", async (req, res) => {
try {
if (!req.session?.user) return res.redirect("/");
if (req.session.user.role !== "admin")
return res.status(403).send("Forbidden");
let serial = normalizeSerial(req.body.serial_number);
if (!serial) {
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial: "",
error: "Bitte Seriennummer eingeben.",
success: null,
});
}
if (!isValidSerialFormat(serial)) {
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial: serial,
error: "Ungültiges Format. Beispiel: ABC12-3DE45-FG678-HI901",
success: null,
});
}
if (!passesModulo3(serial)) {
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial: serial,
error: "Modulo-3 Prüfung fehlgeschlagen. Seriennummer ungültig.",
success: null,
});
}
await db
.promise()
.query(`UPDATE company_settings SET serial_number = ? WHERE id = 1`, [
serial,
]);
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial: serial,
error: null,
success: "✅ Seriennummer gespeichert!",
});
} catch (err) {
console.error(err);
let msg = "Fehler beim Speichern.";
if (err.code === "ER_DUP_ENTRY")
msg = "Diese Seriennummer ist bereits vergeben.";
return res.render("serial_number_admin", {
user: req.session.user,
lang: req.session.lang || "de",
active: "serialnumber",
currentSerial: req.body.serial_number || "",
error: msg,
success: null,
});
}
});
/* ===============================
DEINE ROUTES (unverändert)
================================ */
app.use(companySettingsRoutes);
app.use("/", authRoutes);
app.use("/dashboard", dashboardRoutes);
app.use("/admin", adminRoutes);
app.use("/patients", patientRoutes);
app.use("/patients", patientMedicationRoutes);
app.use("/patients", patientServiceRoutes);
app.use("/medications", medicationRoutes);
console.log("🧪 /medications Router mounted");
app.use("/services", serviceRoutes);
app.use("/", patientFileRoutes);
app.use("/", waitingRoomRoutes);
app.use("/invoices", invoiceRoutes);
app.use("/reportview", reportRoutes);
app.get("/logout", (req, res) => {
req.session.destroy(() => res.redirect("/"));
});
/* ===============================
ERROR HANDLING
================================ */
app.use((err, req, res, next) => {
console.error(err);
res.status(500).send("Interner Serverfehler");
});
/* ===============================
SERVER
================================ */
const PORT = process.env.PORT || 51777;
const HOST = process.env.HOST || "0.0.0.0";
app.listen(PORT, HOST, () => {
console.log(`Server läuft auf http://${HOST}:${PORT}`);
});

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

File diff suppressed because one or more lines are too long

View File

@ -1,71 +1,71 @@
const fs = require("fs"); const fs = require("fs");
const crypto = require("crypto"); const crypto = require("crypto");
const path = require("path"); const path = require("path");
const CONFIG_FILE = path.join(__dirname, "config.enc"); const CONFIG_FILE = path.join(__dirname, "config.enc");
function getKey() { function getKey() {
const key = process.env.CONFIG_KEY; const key = process.env.CONFIG_KEY;
if (!key) throw new Error("CONFIG_KEY fehlt in .env"); if (!key) throw new Error("CONFIG_KEY fehlt in .env");
// stabil auf 32 bytes // stabil auf 32 bytes
return crypto.createHash("sha256").update(key).digest(); return crypto.createHash("sha256").update(key).digest();
} }
function encryptConfig(obj) { function encryptConfig(obj) {
const key = getKey(); const key = getKey();
const iv = crypto.randomBytes(12); const iv = crypto.randomBytes(12);
const cipher = crypto.createCipheriv("aes-256-gcm", key, iv); const cipher = crypto.createCipheriv("aes-256-gcm", key, iv);
const json = JSON.stringify(obj); const json = JSON.stringify(obj);
const encrypted = Buffer.concat([ const encrypted = Buffer.concat([
cipher.update(json, "utf8"), cipher.update(json, "utf8"),
cipher.final(), cipher.final(),
]); ]);
const tag = cipher.getAuthTag(); const tag = cipher.getAuthTag();
return Buffer.concat([iv, tag, encrypted]).toString("base64"); return Buffer.concat([iv, tag, encrypted]).toString("base64");
} }
function decryptConfig(str) { function decryptConfig(str) {
const raw = Buffer.from(str, "base64"); const raw = Buffer.from(str, "base64");
const iv = raw.subarray(0, 12); const iv = raw.subarray(0, 12);
const tag = raw.subarray(12, 28); const tag = raw.subarray(12, 28);
const encrypted = raw.subarray(28); const encrypted = raw.subarray(28);
const key = getKey(); const key = getKey();
const decipher = crypto.createDecipheriv("aes-256-gcm", key, iv); const decipher = crypto.createDecipheriv("aes-256-gcm", key, iv);
decipher.setAuthTag(tag); decipher.setAuthTag(tag);
const decrypted = Buffer.concat([ const decrypted = Buffer.concat([
decipher.update(encrypted), decipher.update(encrypted),
decipher.final(), decipher.final(),
]); ]);
return JSON.parse(decrypted.toString("utf8")); return JSON.parse(decrypted.toString("utf8"));
} }
function configExists() { function configExists() {
return fs.existsSync(CONFIG_FILE); return fs.existsSync(CONFIG_FILE);
} }
function loadConfig() { function loadConfig() {
if (!configExists()) return null; if (!configExists()) return null;
const enc = fs.readFileSync(CONFIG_FILE, "utf8").trim(); const enc = fs.readFileSync(CONFIG_FILE, "utf8").trim();
if (!enc) return null; if (!enc) return null;
return decryptConfig(enc); return decryptConfig(enc);
} }
function saveConfig(obj) { function saveConfig(obj) {
const enc = encryptConfig(obj); const enc = encryptConfig(obj);
fs.writeFileSync(CONFIG_FILE, enc, "utf8"); fs.writeFileSync(CONFIG_FILE, enc, "utf8");
return true; return true;
} }
module.exports = { module.exports = {
configExists, configExists,
loadConfig, loadConfig,
saveConfig, saveConfig,
}; };

View File

@ -1 +1 @@
G/kDLEJ/LddnnNnginIGYSM4Ax0g5pJaF0lrdOXke51cz3jSTrZxP7rjTXRlqLcoUJhPaVLvjb/DcyNYB/C339a+PFWyIdWYjSb6G4aPkD8J21yFWDDLpc08bXvoAx2PeE+Fc9v5mJUGDVv2wQoDvkHqIpN8ewrfRZ6+JF3OfQ== 4PsgCvoOJLNXPpxOHOvm+KbVYz3pNxg8oOXO7zoH3MPffEhZLI7i5qf3o6oqZDI04us8xSSz9j3KIN+Atno/VFlYzSoq3ki1F+WSTz37LfcE3goPqhm6UaH8c9lHdulemH9tqgGq/DxgbKaup5t/ZJnLseaHHpdyTZok1jWULN0nlDuL/HvVVtqw5sboPqU=

View File

@ -1,31 +1,31 @@
const session = require("express-session"); const session = require("express-session");
const { configExists } = require("../config-manager"); const { configExists } = require("../config-manager");
let store = null; let store = null;
function getSessionStore() { function getSessionStore() {
if (store) return store; if (store) return store;
// ✅ Setup-Modus (keine DB) // ✅ Setup-Modus (keine DB)
if (!configExists()) { if (!configExists()) {
console.log("⚠️ Setup-Modus aktiv → SessionStore = MemoryStore"); console.log("⚠️ Setup-Modus aktiv → SessionStore = MemoryStore");
store = new session.MemoryStore(); store = new session.MemoryStore();
return store; return store;
} }
// ✅ Normalbetrieb (mit DB) // ✅ Normalbetrieb (mit DB)
const MySQLStore = require("express-mysql-session")(session); const MySQLStore = require("express-mysql-session")(session);
const db = require("../db"); const db = require("../db");
store = new MySQLStore({}, db); store = new MySQLStore({}, db);
return store; return store;
} }
function resetSessionStore() { function resetSessionStore() {
store = null; store = null;
} }
module.exports = { module.exports = {
getSessionStore, getSessionStore,
resetSessionStore, resetSessionStore,
}; };

View File

@ -1,330 +1,343 @@
const db = require("../db"); const db = require("../db");
const bcrypt = require("bcrypt"); const bcrypt = require("bcrypt");
const { const {
createUser, createUser,
getAllUsers, getAllUsers,
updateUserById, updateUserById,
} = require("../services/admin.service"); } = require("../services/admin.service");
async function listUsers(req, res) { async function listUsers(req, res) {
const { q } = req.query; const { q } = req.query;
try { try {
let users; let users;
if (q) { if (q) {
users = await getAllUsers(db, q); users = await getAllUsers(db, q);
} else { } else {
users = await getAllUsers(db); users = await getAllUsers(db);
} }
res.render("admin_users", { res.render("admin_users", {
users, title: "Benutzer",
currentUser: req.session.user, sidebarPartial: "partials/admin-sidebar",
query: { q }, active: "users",
});
} catch (err) { user: req.session.user,
console.error(err); lang: req.session.lang || "de",
res.send("Datenbankfehler");
} users,
} currentUser: req.session.user,
query: { q },
function showCreateUser(req, res) { });
res.render("admin_create_user", { } catch (err) {
error: null, console.error(err);
user: req.session.user, res.send("Datenbankfehler");
}); }
} }
async function postCreateUser(req, res) { function showCreateUser(req, res) {
let { res.render("admin_create_user", {
title, error: null,
first_name, user: req.session.user,
last_name, });
username, }
password,
role, async function postCreateUser(req, res) {
fachrichtung, let {
arztnummer, title,
} = req.body; first_name,
last_name,
title = title?.trim(); username,
first_name = first_name?.trim(); password,
last_name = last_name?.trim(); role,
username = username?.trim(); fachrichtung,
fachrichtung = fachrichtung?.trim(); arztnummer,
arztnummer = arztnummer?.trim(); } = req.body;
// 🔴 Grundvalidierung title = title?.trim();
if (!first_name || !last_name || !username || !password || !role) { first_name = first_name?.trim();
return res.render("admin_create_user", { last_name = last_name?.trim();
error: "Alle Pflichtfelder müssen ausgefüllt sein", username = username?.trim();
user: req.session.user, fachrichtung = fachrichtung?.trim();
}); arztnummer = arztnummer?.trim();
}
// 🔴 Grundvalidierung
// 🔴 Arzt-spezifische Validierung if (!first_name || !last_name || !username || !password || !role) {
if (role === "arzt") { return res.render("admin_create_user", {
if (!fachrichtung || !arztnummer) { error: "Alle Pflichtfelder müssen ausgefüllt sein",
return res.render("admin_create_user", { user: req.session.user,
error: "Für Ärzte sind Fachrichtung und Arztnummer Pflicht", });
user: req.session.user, }
});
} // 🔴 Arzt-spezifische Validierung
} else { if (role === "arzt") {
// Sicherheit: Mitarbeiter dürfen keine Arzt-Daten haben if (!fachrichtung || !arztnummer) {
fachrichtung = null; return res.render("admin_create_user", {
arztnummer = null; error: "Für Ärzte sind Fachrichtung und Arztnummer Pflicht",
title = null; user: req.session.user,
} });
}
try { } else {
await createUser( // Sicherheit: Mitarbeiter dürfen keine Arzt-Daten haben
db, fachrichtung = null;
title, arztnummer = null;
first_name, title = null;
last_name, }
username,
password, try {
role, await createUser(
fachrichtung, db,
arztnummer title,
); first_name,
last_name,
req.session.flash = { username,
type: "success", password,
message: "Benutzer erfolgreich angelegt", role,
}; fachrichtung,
arztnummer,
res.redirect("/admin/users"); );
} catch (error) {
res.render("admin_create_user", { req.session.flash = {
error, type: "success",
user: req.session.user, message: "Benutzer erfolgreich angelegt",
}); };
}
} res.redirect("/admin/users");
} catch (error) {
async function changeUserRole(req, res) { res.render("admin_create_user", {
const userId = req.params.id; error,
const { role } = req.body; user: req.session.user,
});
if (!["arzt", "mitarbeiter"].includes(role)) { }
req.session.flash = { type: "danger", message: "Ungültige Rolle" }; }
return res.redirect("/admin/users");
} async function changeUserRole(req, res) {
const userId = req.params.id;
db.query("UPDATE users SET role = ? WHERE id = ?", [role, userId], (err) => { const { role } = req.body;
if (err) {
console.error(err); if (!["arzt", "mitarbeiter"].includes(role)) {
req.session.flash = { req.session.flash = { type: "danger", message: "Ungültige Rolle" };
type: "danger", return res.redirect("/admin/users");
message: "Fehler beim Ändern der Rolle", }
};
} else { db.query("UPDATE users SET role = ? WHERE id = ?", [role, userId], (err) => {
req.session.flash = { if (err) {
type: "success", console.error(err);
message: "Rolle erfolgreich geändert", req.session.flash = {
}; type: "danger",
} message: "Fehler beim Ändern der Rolle",
res.redirect("/admin/users"); };
}); } else {
} req.session.flash = {
type: "success",
async function resetUserPassword(req, res) { message: "Rolle erfolgreich geändert",
const userId = req.params.id; };
const { password } = req.body; }
res.redirect("/admin/users");
if (!password || password.length < 4) { });
req.session.flash = { type: "warning", message: "Passwort zu kurz" }; }
return res.redirect("/admin/users");
} async function resetUserPassword(req, res) {
const userId = req.params.id;
const hash = await bcrypt.hash(password, 10); const { password } = req.body;
db.query( if (!password || password.length < 4) {
"UPDATE users SET password = ? WHERE id = ?", req.session.flash = { type: "warning", message: "Passwort zu kurz" };
[hash, userId], return res.redirect("/admin/users");
(err) => { }
if (err) {
console.error(err); const hash = await bcrypt.hash(password, 10);
req.session.flash = {
type: "danger", db.query(
message: "Fehler beim Zurücksetzen", "UPDATE users SET password = ? WHERE id = ?",
}; [hash, userId],
} else { (err) => {
req.session.flash = { if (err) {
type: "success", console.error(err);
message: "Passwort zurückgesetzt", req.session.flash = {
}; type: "danger",
} message: "Fehler beim Zurücksetzen",
res.redirect("/admin/users"); };
} } else {
); req.session.flash = {
} type: "success",
message: "Passwort zurückgesetzt",
function activateUser(req, res) { };
const userId = req.params.id; }
res.redirect("/admin/users");
db.query("UPDATE users SET active = 1 WHERE id = ?", [userId], (err) => { },
if (err) { );
console.error(err); }
req.session.flash = {
type: "danger", function activateUser(req, res) {
message: "Benutzer konnte nicht aktiviert werden", const userId = req.params.id;
};
} else { db.query("UPDATE users SET active = 1 WHERE id = ?", [userId], (err) => {
req.session.flash = { if (err) {
type: "success", console.error(err);
message: "Benutzer wurde aktiviert", req.session.flash = {
}; type: "danger",
} message: "Benutzer konnte nicht aktiviert werden",
res.redirect("/admin/users"); };
}); } else {
} req.session.flash = {
type: "success",
function deactivateUser(req, res) { message: "Benutzer wurde aktiviert",
const userId = req.params.id; };
}
db.query("UPDATE users SET active = 0 WHERE id = ?", [userId], (err) => { res.redirect("/admin/users");
if (err) { });
console.error(err); }
req.session.flash = {
type: "danger", function deactivateUser(req, res) {
message: "Benutzer konnte nicht deaktiviert werden", const userId = req.params.id;
};
} else { db.query("UPDATE users SET active = 0 WHERE id = ?", [userId], (err) => {
req.session.flash = { if (err) {
type: "success", console.error(err);
message: "Benutzer wurde deaktiviert", req.session.flash = {
}; type: "danger",
} message: "Benutzer konnte nicht deaktiviert werden",
res.redirect("/admin/users"); };
}); } else {
} req.session.flash = {
type: "success",
async function showInvoiceOverview(req, res) { message: "Benutzer wurde deaktiviert",
const search = req.query.q || ""; };
const view = req.query.view || "year"; }
const currentYear = new Date().getFullYear(); res.redirect("/admin/users");
const fromYear = req.query.fromYear || currentYear; });
const toYear = req.query.toYear || currentYear; }
try { async function showInvoiceOverview(req, res) {
const [yearly] = await db.promise().query(` const search = req.query.q || "";
SELECT const view = req.query.view || "year";
YEAR(invoice_date) AS year, const currentYear = new Date().getFullYear();
SUM(total_amount) AS total const fromYear = req.query.fromYear || currentYear;
FROM invoices const toYear = req.query.toYear || currentYear;
WHERE status IN ('paid','open')
GROUP BY YEAR(invoice_date) try {
ORDER BY year DESC const [yearly] = await db.promise().query(`
`); SELECT
YEAR(invoice_date) AS year,
const [quarterly] = await db.promise().query(` SUM(total_amount) AS total
SELECT FROM invoices
YEAR(invoice_date) AS year, WHERE status IN ('paid','open')
QUARTER(invoice_date) AS quarter, GROUP BY YEAR(invoice_date)
SUM(total_amount) AS total ORDER BY year DESC
FROM invoices `);
WHERE status IN ('paid','open')
GROUP BY YEAR(invoice_date), QUARTER(invoice_date) const [quarterly] = await db.promise().query(`
ORDER BY year DESC, quarter DESC SELECT
`); YEAR(invoice_date) AS year,
QUARTER(invoice_date) AS quarter,
const [monthly] = await db.promise().query(` SUM(total_amount) AS total
SELECT FROM invoices
DATE_FORMAT(invoice_date, '%Y-%m') AS month, WHERE status IN ('paid','open')
SUM(total_amount) AS total GROUP BY YEAR(invoice_date), QUARTER(invoice_date)
FROM invoices ORDER BY year DESC, quarter DESC
WHERE status IN ('paid','open') `);
GROUP BY month
ORDER BY month DESC const [monthly] = await db.promise().query(`
`); SELECT
DATE_FORMAT(invoice_date, '%Y-%m') AS month,
const [patients] = await db.promise().query( SUM(total_amount) AS total
` FROM invoices
SELECT WHERE status IN ('paid','open')
CONCAT(p.firstname, ' ', p.lastname) AS patient, GROUP BY month
SUM(i.total_amount) AS total ORDER BY month DESC
FROM invoices i `);
JOIN patients p ON p.id = i.patient_id
WHERE i.status IN ('paid','open') const [patients] = await db.promise().query(
AND CONCAT(p.firstname, ' ', p.lastname) LIKE ? `
GROUP BY p.id SELECT
ORDER BY total DESC CONCAT(p.firstname, ' ', p.lastname) AS patient,
`, SUM(i.total_amount) AS total
[`%${search}%`] FROM invoices i
); JOIN patients p ON p.id = i.patient_id
WHERE i.status IN ('paid','open')
res.render("admin/admin_invoice_overview", { AND CONCAT(p.firstname, ' ', p.lastname) LIKE ?
user: req.session.user, GROUP BY p.id
yearly, ORDER BY total DESC
quarterly, `,
monthly, [`%${search}%`],
patients, );
search,
fromYear, res.render("admin/admin_invoice_overview", {
toYear, title: "Rechnungsübersicht",
}); sidebarPartial: "partials/admin-sidebar", // ✅ keine Sidebar
} catch (err) { active: "invoices",
console.error(err);
res.status(500).send("Fehler beim Laden der Rechnungsübersicht"); user: req.session.user,
} lang: req.session.lang || "de",
}
yearly,
async function updateUser(req, res) { quarterly,
const userId = req.params.id; monthly,
patients,
let { title, first_name, last_name, username, role } = req.body; search,
fromYear,
title = title?.trim() || null; toYear,
first_name = first_name?.trim(); });
last_name = last_name?.trim(); } catch (err) {
username = username?.trim(); console.error(err);
role = role?.trim(); res.status(500).send("Fehler beim Laden der Rechnungsübersicht");
}
try { }
// ✅ Fehlende Felder aus DB holen (weil disabled inputs nicht gesendet werden)
const [rows] = await db async function updateUser(req, res) {
.promise() const userId = req.params.id;
.query("SELECT * FROM users WHERE id = ?", [userId]);
let { title, first_name, last_name, username, role } = req.body;
if (!rows.length) {
req.session.flash = { type: "danger", message: "User nicht gefunden" }; title = title?.trim() || null;
return res.redirect("/admin/users"); first_name = first_name?.trim();
} last_name = last_name?.trim();
username = username?.trim();
const current = rows[0]; role = role?.trim();
// ✅ Fallback: wenn Felder nicht gesendet wurden -> alte Werte behalten try {
const updatedData = { // ✅ Fehlende Felder aus DB holen (weil disabled inputs nicht gesendet werden)
title: title ?? current.title, const [rows] = await db
first_name: first_name ?? current.first_name, .promise()
last_name: last_name ?? current.last_name, .query("SELECT * FROM users WHERE id = ?", [userId]);
username: username ?? current.username,
role: role ?? current.role, if (!rows.length) {
}; req.session.flash = { type: "danger", message: "User nicht gefunden" };
return res.redirect("/admin/users");
await updateUserById(db, userId, updatedData); }
req.session.flash = { type: "success", message: "User aktualisiert ✅" }; const current = rows[0];
return res.redirect("/admin/users");
} catch (err) { // ✅ Fallback: wenn Felder nicht gesendet wurden -> alte Werte behalten
console.error(err); const updatedData = {
req.session.flash = { type: "danger", message: "Fehler beim Speichern" }; title: title ?? current.title,
return res.redirect("/admin/users"); first_name: first_name ?? current.first_name,
} last_name: last_name ?? current.last_name,
} username: username ?? current.username,
role: role ?? current.role,
module.exports = { };
listUsers,
showCreateUser, await updateUserById(db, userId, updatedData);
postCreateUser,
changeUserRole, req.session.flash = { type: "success", message: "User aktualisiert ✅" };
resetUserPassword, return res.redirect("/admin/users");
activateUser, } catch (err) {
deactivateUser, console.error(err);
showInvoiceOverview, req.session.flash = { type: "danger", message: "Fehler beim Speichern" };
updateUser, return res.redirect("/admin/users");
}; }
}
module.exports = {
listUsers,
showCreateUser,
postCreateUser,
changeUserRole,
resetUserPassword,
activateUser,
deactivateUser,
showInvoiceOverview,
updateUser,
};

View File

@ -1,32 +1,62 @@
const { loginUser } = require("../services/auth.service"); const { loginUser } = require("../services/auth.service");
const db = require("../db"); const db = require("../db");
const LOCK_TIME_MINUTES = 5; const LOCK_TIME_MINUTES = 5;
async function postLogin(req, res) { async function postLogin(req, res) {
const { username, password } = req.body; const { username, password } = req.body;
try { try {
const user = await loginUser( const user = await loginUser(db, username, password, LOCK_TIME_MINUTES);
db,
username, /* req.session.user = user;
password, res.redirect("/dashboard"); */
LOCK_TIME_MINUTES
); req.session.user = user;
req.session.user = user; // ✅ Trial Start setzen falls leer
res.redirect("/dashboard"); const [rowsSettings] = await db.promise().query(
`SELECT id, trial_started_at, serial_number
} catch (error) { FROM company_settings
res.render("login", { error }); ORDER BY id ASC
} LIMIT 1`,
} );
function getLogin(req, res) { const settingsTrail = rowsSettings?.[0];
res.render("login", { error: null });
} if (settingsTrail?.id && !settingsTrail.trial_started_at) {
await db
module.exports = { .promise()
getLogin, .query(
postLogin `UPDATE company_settings SET trial_started_at = NOW() WHERE id = ?`,
}; [settingsTrail.id],
);
}
// ✅ Direkt nach Login check:
const [rows] = await db
.promise()
.query(
`SELECT serial_number, trial_started_at FROM company_settings ORDER BY id ASC LIMIT 1`,
);
const settings = rows?.[0];
if (!settings?.serial_number) {
return res.redirect("/serial-number");
}
res.redirect("/dashboard");
} catch (error) {
res.render("login", { error });
}
}
function getLogin(req, res) {
res.render("login", { error: null });
}
module.exports = {
getLogin,
postLogin,
};

View File

@ -1,162 +1,175 @@
const db = require("../db"); const db = require("../db");
/** /**
* Helper: leere Strings NULL * Helper: leere Strings NULL
*/ */
const safe = (v) => { const safe = (v) => {
if (typeof v !== "string") return null; if (typeof v !== "string") return null;
const t = v.trim(); const t = v.trim();
return t.length > 0 ? t : null; return t.length > 0 ? t : null;
}; };
/** /**
* GET: Firmendaten anzeigen * GET: Firmendaten anzeigen
*/ */
async function getCompanySettings(req, res) { async function getCompanySettings(req, res) {
const [[company]] = await db.promise().query( try {
"SELECT * FROM company_settings LIMIT 1" const [[company]] = await db
); .promise()
.query("SELECT * FROM company_settings LIMIT 1");
res.render("admin/company-settings", {
user: req.user, res.render("admin/company-settings", {
company: company || {} layout: "layout", // 🔥 wichtig
}); title: "Firmendaten", // 🔥 DAS FEHLTE
} active: "companySettings", // 🔥 Sidebar aktiv
sidebarPartial: "partials/admin-sidebar",
/**
* POST: Firmendaten speichern (INSERT oder UPDATE) company: company || {},
*/
async function saveCompanySettings(req, res) { user: req.session.user, // 🔥 konsistent
try { lang: req.session.lang || "de"
const data = req.body; // t kommt aus res.locals
});
// 🔒 Pflichtfeld } catch (err) {
if (!data.company_name || data.company_name.trim() === "") { console.error(err);
return res.status(400).send("Firmenname darf nicht leer sein"); res.status(500).send("Datenbankfehler");
} }
}
// 🖼 Logo (optional)
let logoPath = null; /**
if (req.file) { * POST: Firmendaten speichern (INSERT oder UPDATE)
logoPath = "/images/" + req.file.filename; */
} async function saveCompanySettings(req, res) {
try {
// 🔍 Existierenden Datensatz laden const data = req.body;
const [[existing]] = await db.promise().query(
"SELECT * FROM company_settings LIMIT 1" // 🔒 Pflichtfeld
); if (!data.company_name || data.company_name.trim() === "") {
return res.status(400).send("Firmenname darf nicht leer sein");
const oldData = existing ? { ...existing } : null; }
if (existing) { // 🖼 Logo (optional)
// 🔁 UPDATE let logoPath = null;
await db.promise().query( if (req.file) {
` logoPath = "/images/" + req.file.filename;
UPDATE company_settings SET }
company_name = ?,
company_legal_form = ?, // 🔍 Existierenden Datensatz laden
company_owner = ?, const [[existing]] = await db.promise().query(
street = ?, "SELECT * FROM company_settings LIMIT 1"
house_number = ?, );
postal_code = ?,
city = ?, const oldData = existing ? { ...existing } : null;
country = ?,
phone = ?, if (existing) {
email = ?, // 🔁 UPDATE
vat_id = ?, await db.promise().query(
bank_name = ?, `
iban = ?, UPDATE company_settings SET
bic = ?, company_name = ?,
invoice_footer_text = ?, company_legal_form = ?,
invoice_logo_path = ? company_owner = ?,
WHERE id = ? street = ?,
`, house_number = ?,
[ postal_code = ?,
data.company_name.trim(), // NOT NULL city = ?,
safe(data.company_legal_form), country = ?,
safe(data.company_owner), phone = ?,
safe(data.street), email = ?,
safe(data.house_number), vat_id = ?,
safe(data.postal_code), bank_name = ?,
safe(data.city), iban = ?,
safe(data.country), bic = ?,
safe(data.phone), invoice_footer_text = ?,
safe(data.email), invoice_logo_path = ?
safe(data.vat_id), WHERE id = ?
safe(data.bank_name), `,
safe(data.iban), [
safe(data.bic), data.company_name.trim(), // NOT NULL
safe(data.invoice_footer_text), safe(data.company_legal_form),
logoPath || existing.invoice_logo_path, safe(data.company_owner),
existing.id safe(data.street),
] safe(data.house_number),
); safe(data.postal_code),
} else { safe(data.city),
// INSERT safe(data.country),
await db.promise().query( safe(data.phone),
` safe(data.email),
INSERT INTO company_settings ( safe(data.vat_id),
company_name, safe(data.bank_name),
company_legal_form, safe(data.iban),
company_owner, safe(data.bic),
street, safe(data.invoice_footer_text),
house_number, logoPath || existing.invoice_logo_path,
postal_code, existing.id
city, ]
country, );
phone, } else {
email, // INSERT
vat_id, await db.promise().query(
bank_name, `
iban, INSERT INTO company_settings (
bic, company_name,
invoice_footer_text, company_legal_form,
invoice_logo_path company_owner,
) VALUES (?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?) street,
`, house_number,
[ postal_code,
data.company_name.trim(), // NOT NULL city,
safe(data.company_legal_form), country,
safe(data.company_owner), phone,
safe(data.street), email,
safe(data.house_number), vat_id,
safe(data.postal_code), bank_name,
safe(data.city), iban,
safe(data.country), bic,
safe(data.phone), invoice_footer_text,
safe(data.email), invoice_logo_path
safe(data.vat_id), ) VALUES (?,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?)
safe(data.bank_name), `,
safe(data.iban), [
safe(data.bic), data.company_name.trim(), // NOT NULL
safe(data.invoice_footer_text), safe(data.company_legal_form),
logoPath safe(data.company_owner),
] safe(data.street),
); safe(data.house_number),
} safe(data.postal_code),
safe(data.city),
// 📝 Audit-Log safe(data.country),
await db.promise().query( safe(data.phone),
` safe(data.email),
INSERT INTO company_settings_logs (changed_by, old_data, new_data) safe(data.vat_id),
VALUES (?, ?, ?) safe(data.bank_name),
`, safe(data.iban),
[ safe(data.bic),
req.user.id, safe(data.invoice_footer_text),
JSON.stringify(oldData || {}), logoPath
JSON.stringify(data) ]
] );
); }
res.redirect("/admin/company-settings"); // 📝 Audit-Log
await db.promise().query(
} catch (err) { `
console.error("❌ COMPANY SETTINGS ERROR:", err); INSERT INTO company_settings_logs (changed_by, old_data, new_data)
res.status(500).send("Fehler beim Speichern der Firmendaten"); VALUES (?, ?, ?)
} `,
} [
req.user.id,
module.exports = { JSON.stringify(oldData || {}),
getCompanySettings, JSON.stringify(data)
saveCompanySettings ]
}; );
res.redirect("/admin/company-settings");
} catch (err) {
console.error("❌ COMPANY SETTINGS ERROR:", err);
res.status(500).send("Fehler beim Speichern der Firmendaten");
}
}
module.exports = {
getCompanySettings,
saveCompanySettings
};

View File

@ -1,22 +1,29 @@
const db = require("../db"); const db = require("../db");
const { const {
getWaitingPatients getWaitingPatients
} = require("../services/patient.service"); } = require("../services/patient.service");
async function showDashboard(req, res) { async function showDashboard(req, res) {
try { try {
const waitingPatients = await getWaitingPatients(db); const waitingPatients = await getWaitingPatients(db);
res.render("dashboard", { res.render("dashboard", {
user: req.session.user, layout: "layout", // 🔥 DAS FEHLTE
waitingPatients
}); title: "Dashboard",
} catch (err) { active: "dashboard",
console.error(err); sidebarPartial: "partials/sidebar",
res.send("Datenbankfehler");
} waitingPatients,
} user: req.session.user,
lang: req.session.lang || "de"
module.exports = { });
showDashboard } catch (err) {
}; console.error(err);
res.send("Datenbankfehler");
}
}
module.exports = {
showDashboard
};

View File

@ -0,0 +1,483 @@
const db = require("../db");
const path = require("path");
const { rgb } = require("pdf-lib");
const { addWatermark } = require("../utils/pdfWatermark");
const { createCreditPdf } = require("../utils/creditPdf");
exports.openInvoices = async (req, res) => {
try {
const [rows] = await db.promise().query(`
SELECT
i.id,
i.invoice_date,
i.total_amount,
i.status,
p.firstname,
p.lastname
FROM invoices i
JOIN patients p ON p.id = i.patient_id
WHERE i.status = 'open'
ORDER BY i.invoice_date DESC
`);
const invoices = rows.map((inv) => {
let formattedDate = "";
if (inv.invoice_date) {
let dateObj;
// Falls String aus DB
if (typeof inv.invoice_date === "string") {
dateObj = new Date(inv.invoice_date + "T00:00:00");
}
// Falls Date-Objekt
else if (inv.invoice_date instanceof Date) {
dateObj = inv.invoice_date;
}
if (dateObj && !isNaN(dateObj)) {
formattedDate = dateObj.toLocaleDateString("de-DE", {
day: "2-digit",
month: "2-digit",
year: "numeric",
});
}
}
return {
...inv,
invoice_date_formatted: formattedDate,
total_amount_formatted: Number(inv.total_amount || 0).toFixed(2),
};
});
res.render("invoices/open-invoices", {
// ✅ wichtig für Layout
title: "Offene Rechnungen",
active: "open_invoices",
sidebarPartial: "partials/sidebar-invoices",
user: req.session.user,
invoices,
});
} catch (err) {
console.error("❌ openInvoices Fehler:", err);
res.status(500).send("Fehler beim Laden der offenen Rechnungen");
}
};
// Als bezahlt markieren
exports.markAsPaid = async (req, res) => {
try {
const id = req.params.id;
const userId = req.session.user.id;
// PDF-Pfad holen
const [[invoice]] = await db
.promise()
.query("SELECT file_path FROM invoices WHERE id = ?", [id]);
await db.promise().query(
`
UPDATE invoices
SET
status='paid',
paid_at = NOW(),
paid_by = ?
WHERE id = ?
`,
[userId, id],
);
// Wasserzeichen setzen
if (invoice?.file_path) {
const fullPath = path.join(__dirname, "..", "public", invoice.file_path);
await addWatermark(
fullPath,
"BEZAHLT",
rgb(0, 0.7, 0), // Grün
);
}
res.redirect("/invoices/open");
} catch (err) {
console.error("❌ markAsPaid:", err);
res.status(500).send("Fehler");
}
};
// Stornieren
exports.cancelInvoice = async (req, res) => {
try {
const id = req.params.id;
const userId = req.session.user.id;
const [[invoice]] = await db
.promise()
.query("SELECT file_path FROM invoices WHERE id = ?", [id]);
await db.promise().query(
`
UPDATE invoices
SET
status='cancelled',
cancelled_at = NOW(),
cancelled_by = ?
WHERE id = ?
`,
[userId, id],
);
// Wasserzeichen setzen
if (invoice?.file_path) {
const fullPath = path.join(__dirname, "..", "public", invoice.file_path);
await addWatermark(
fullPath,
"STORNIERT",
rgb(0.8, 0, 0), // Rot
);
}
res.redirect("/invoices/open");
} catch (err) {
console.error("❌ cancelInvoice:", err);
res.status(500).send("Fehler");
}
};
// Stornierte Rechnungen anzeigen
exports.cancelledInvoices = async (req, res) => {
try {
// Jahr aus Query (?year=2024)
const year = req.query.year || new Date().getFullYear();
const [rows] = await db.promise().query(
`
SELECT
i.id,
i.invoice_date,
i.total_amount,
p.firstname,
p.lastname
FROM invoices i
JOIN patients p ON p.id = i.patient_id
WHERE
i.status = 'cancelled'
AND YEAR(i.invoice_date) = ?
ORDER BY i.invoice_date DESC
`,
[year],
);
// Formatieren
const invoices = rows.map((inv) => {
let formattedDate = "";
if (inv.invoice_date) {
let dateObj;
// Falls String aus DB
if (typeof inv.invoice_date === "string") {
dateObj = new Date(inv.invoice_date + "T00:00:00");
}
// Falls Date-Objekt
else if (inv.invoice_date instanceof Date) {
dateObj = inv.invoice_date;
}
if (dateObj && !isNaN(dateObj)) {
formattedDate = dateObj.toLocaleDateString("de-DE", {
day: "2-digit",
month: "2-digit",
year: "numeric",
});
}
}
return {
...inv,
invoice_date_formatted: formattedDate,
total_amount_formatted: Number(inv.total_amount || 0).toFixed(2),
};
});
// verfügbare Jahre laden (für Dropdown)
const [years] = await db.promise().query(`
SELECT DISTINCT YEAR(invoice_date) AS year
FROM invoices
WHERE status = 'cancelled'
ORDER BY year DESC
`);
res.render("invoices/cancelled-invoices", {
title: "Stornierte Rechnungen",
user: req.session.user,
invoices,
years: years.map((y) => y.year),
selectedYear: year,
sidebarPartial: "partials/sidebar-invoices",
active: "cancelled_invoices",
});
} catch (err) {
console.error("❌ cancelledInvoices:", err);
res.status(500).send("Fehler beim Laden der stornierten Rechnungen");
}
};
// Auflistung bezahlter Rechnungen
exports.paidInvoices = async (req, res) => {
try {
const year = parseInt(req.query.year) || new Date().getFullYear();
const quarter = parseInt(req.query.quarter) || 0;
let where = `WHERE i.status = 'paid' AND i.type = 'invoice' AND c.id IS NULL`;
const params = [];
if (year) {
where += " AND YEAR(i.invoice_date) = ?";
params.push(year);
}
if (quarter) {
where += " AND QUARTER(i.invoice_date) = ?";
params.push(quarter);
}
const [rows] = await db.promise().query(
`
SELECT
i.id,
i.invoice_date,
i.total_amount,
p.firstname,
p.lastname,
c.id AS credit_id
FROM invoices i
JOIN patients p ON p.id = i.patient_id
LEFT JOIN invoices c
ON c.parent_invoice_id = i.id
AND c.type = 'credit'
${where}
ORDER BY i.invoice_date DESC
`,
params,
);
// Datum + Betrag formatieren
const invoices = rows.map((inv) => {
const d = new Date(inv.invoice_date);
return {
...inv,
invoice_date_formatted: d.toLocaleDateString("de-DE"),
total_amount_formatted: Number(inv.total_amount).toFixed(2),
};
});
// Jahre laden
const [years] = await db.promise().query(`
SELECT DISTINCT YEAR(invoice_date) AS year
FROM invoices
WHERE status='paid'
ORDER BY year DESC
`);
res.render("invoices/paid-invoices", {
title: "Bezahlte Rechnungen",
user: req.session.user,
invoices,
years: years.map((y) => y.year),
selectedYear: year,
selectedQuarter: quarter,
sidebarPartial: "partials/sidebar-invoices",
active: "paid_invoices",
query: req.query,
});
} catch (err) {
console.error("❌ paidInvoices:", err);
res.status(500).send("Fehler");
}
};
exports.createCreditNote = async (req, res) => {
try {
const invoiceId = req.params.id;
const userId = req.session.user.id;
// Originalrechnung
const [[invoice]] = await db.promise().query(
`
SELECT i.*, p.firstname, p.lastname
FROM invoices i
JOIN patients p ON p.id = i.patient_id
WHERE i.id = ? AND i.status = 'paid' AND i.type = 'invoice'
`,
[invoiceId],
);
if (!invoice) {
return res.status(400).send("Ungültige Rechnung");
}
// Prüfen: Gibt es schon eine Gutschrift?
const [[existing]] = await db
.promise()
.query(
`SELECT id FROM invoices WHERE parent_invoice_id = ? AND type = 'credit'`,
[invoiceId],
);
if (existing) {
return res.redirect("/invoices/paid?error=already_credited");
}
// Gutschrift anlegen
const [result] = await db.promise().query(
`
INSERT INTO invoices
(
type,
parent_invoice_id,
patient_id,
invoice_date,
total_amount,
created_by,
status,
paid_at,
paid_by
)
VALUES
('credit', ?, ?, CURDATE(), ?, ?, 'paid', NOW(), ?)
`,
[
invoice.id,
invoice.patient_id,
-Math.abs(invoice.total_amount),
userId,
userId,
],
);
const creditId = result.insertId;
// PDF erzeugen
const pdfPath = await createCreditPdf({
creditId,
originalInvoice: invoice,
creditAmount: -Math.abs(invoice.total_amount),
patient: invoice,
});
// PDF-Pfad speichern
await db
.promise()
.query(`UPDATE invoices SET file_path = ? WHERE id = ?`, [
pdfPath,
creditId,
]);
res.redirect("/invoices/paid");
} catch (err) {
console.error("❌ createCreditNote:", err);
res.status(500).send("Fehler");
}
};
exports.creditOverview = async (req, res) => {
try {
const year = parseInt(req.query.year) || 0;
let where = "WHERE c.type = 'credit'";
const params = [];
if (year) {
where += " AND YEAR(c.invoice_date) = ?";
params.push(year);
}
const [rows] = await db.promise().query(
`
SELECT
i.id AS invoice_id,
i.invoice_date AS invoice_date,
i.file_path AS invoice_file,
i.total_amount AS invoice_amount,
c.id AS credit_id,
c.invoice_date AS credit_date,
c.file_path AS credit_file,
c.total_amount AS credit_amount,
p.firstname,
p.lastname
FROM invoices c
JOIN invoices i
ON i.id = c.parent_invoice_id
JOIN patients p
ON p.id = i.patient_id
${where}
ORDER BY c.invoice_date DESC
`,
params,
);
// Formatieren
const items = rows.map((r) => {
const formatDate = (d) =>
d ? new Date(d).toLocaleDateString("de-DE") : "";
return {
...r,
invoice_date_fmt: formatDate(r.invoice_date),
credit_date_fmt: formatDate(r.credit_date),
invoice_amount_fmt: Number(r.invoice_amount).toFixed(2),
credit_amount_fmt: Number(r.credit_amount).toFixed(2),
};
});
// Jahre laden
const [years] = await db.promise().query(`
SELECT DISTINCT YEAR(invoice_date) AS year
FROM invoices
WHERE type='credit'
ORDER BY year DESC
`);
res.render("invoices/credit-overview", {
title: "Gutschriften-Übersicht",
user: req.session.user,
items,
years: years.map((y) => y.year),
selectedYear: year,
sidebarPartial: "partials/sidebar-invoices",
active: "credits",
});
} catch (err) {
console.error("❌ creditOverview:", err);
res.status(500).send("Fehler");
}
};

View File

@ -1,198 +1,198 @@
const db = require("../db"); const db = require("../db");
const ejs = require("ejs"); const ejs = require("ejs");
const path = require("path"); const path = require("path");
const htmlToPdf = require("html-pdf-node"); const htmlToPdf = require("html-pdf-node");
const fs = require("fs"); const fs = require("fs");
async function createInvoicePdf(req, res) { async function createInvoicePdf(req, res) {
const patientId = req.params.id; const patientId = req.params.id;
const connection = await db.promise().getConnection(); const connection = await db.promise().getConnection();
try { try {
await connection.beginTransaction(); await connection.beginTransaction();
const year = new Date().getFullYear(); const year = new Date().getFullYear();
// 🔒 Rechnungszähler sperren // 🔒 Rechnungszähler sperren
const [[counterRow]] = await connection.query( const [[counterRow]] = await connection.query(
"SELECT counter FROM invoice_counters WHERE year = ? FOR UPDATE", "SELECT counter FROM invoice_counters WHERE year = ? FOR UPDATE",
[year] [year]
); );
let counter; let counter;
if (!counterRow) { if (!counterRow) {
counter = 1; counter = 1;
await connection.query( await connection.query(
"INSERT INTO invoice_counters (year, counter) VALUES (?, ?)", "INSERT INTO invoice_counters (year, counter) VALUES (?, ?)",
[year, counter] [year, counter]
); );
} else { } else {
counter = counterRow.counter + 1; counter = counterRow.counter + 1;
await connection.query( await connection.query(
"UPDATE invoice_counters SET counter = ? WHERE year = ?", "UPDATE invoice_counters SET counter = ? WHERE year = ?",
[counter, year] [counter, year]
); );
} }
const invoiceNumber = `${year}-${String(counter).padStart(4, "0")}`; const invoiceNumber = `${year}-${String(counter).padStart(4, "0")}`;
// 🔹 Patient // 🔹 Patient
const [[patient]] = await connection.query( const [[patient]] = await connection.query(
"SELECT * FROM patients WHERE id = ?", "SELECT * FROM patients WHERE id = ?",
[patientId] [patientId]
); );
if (!patient) throw new Error("Patient nicht gefunden"); if (!patient) throw new Error("Patient nicht gefunden");
// 🔹 Leistungen // 🔹 Leistungen
const [rows] = await connection.query( const [rows] = await connection.query(
` `
SELECT SELECT
ps.quantity, ps.quantity,
COALESCE(ps.price_override, s.price) AS price, COALESCE(ps.price_override, s.price) AS price,
s.name_de AS name s.name_de AS name
FROM patient_services ps FROM patient_services ps
JOIN services s ON ps.service_id = s.id JOIN services s ON ps.service_id = s.id
WHERE ps.patient_id = ? WHERE ps.patient_id = ?
AND ps.invoice_id IS NULL AND ps.invoice_id IS NULL
`, `,
[patientId] [patientId]
); );
if (!rows.length) throw new Error("Keine Leistungen vorhanden"); if (!rows.length) throw new Error("Keine Leistungen vorhanden");
const services = rows.map((s) => ({ const services = rows.map((s) => ({
quantity: Number(s.quantity), quantity: Number(s.quantity),
name: s.name, name: s.name,
price: Number(s.price), price: Number(s.price),
total: Number(s.price) * Number(s.quantity), total: Number(s.price) * Number(s.quantity),
})); }));
const total = services.reduce((sum, s) => sum + s.total, 0); const total = services.reduce((sum, s) => sum + s.total, 0);
// 🔹 Arzt // 🔹 Arzt
const [[doctor]] = await connection.query( const [[doctor]] = await connection.query(
` `
SELECT first_name, last_name, fachrichtung, arztnummer SELECT first_name, last_name, fachrichtung, arztnummer
FROM users FROM users
WHERE id = ( WHERE id = (
SELECT created_by SELECT created_by
FROM patient_services FROM patient_services
WHERE patient_id = ? WHERE patient_id = ?
ORDER BY service_date DESC ORDER BY service_date DESC
LIMIT 1 LIMIT 1
) )
`, `,
[patientId] [patientId]
); );
// 🔹 Firma // 🔹 Firma
const [[company]] = await connection.query( const [[company]] = await connection.query(
"SELECT * FROM company_settings LIMIT 1" "SELECT * FROM company_settings LIMIT 1"
); );
// 🖼 Logo als Base64 // 🖼 Logo als Base64
let logoBase64 = null; let logoBase64 = null;
if (company && company.invoice_logo_path) { if (company && company.invoice_logo_path) {
const logoPath = path.join( const logoPath = path.join(
__dirname, __dirname,
"..", "..",
"public", "public",
company.invoice_logo_path company.invoice_logo_path
); );
if (fs.existsSync(logoPath)) { if (fs.existsSync(logoPath)) {
const buffer = fs.readFileSync(logoPath); const buffer = fs.readFileSync(logoPath);
const ext = path.extname(logoPath).toLowerCase(); const ext = path.extname(logoPath).toLowerCase();
const mime = const mime =
ext === ".jpg" || ext === ".jpeg" ? "image/jpeg" : "image/png"; ext === ".jpg" || ext === ".jpeg" ? "image/jpeg" : "image/png";
logoBase64 = `data:${mime};base64,${buffer.toString("base64")}`; logoBase64 = `data:${mime};base64,${buffer.toString("base64")}`;
} }
} }
// 📁 PDF-Pfad vorbereiten // 📁 PDF-Pfad vorbereiten
const invoiceDir = path.join( const invoiceDir = path.join(
__dirname, __dirname,
"..", "..",
"public", "public",
"invoices", "invoices",
String(year) String(year)
); );
if (!fs.existsSync(invoiceDir)) { if (!fs.existsSync(invoiceDir)) {
fs.mkdirSync(invoiceDir, { recursive: true }); fs.mkdirSync(invoiceDir, { recursive: true });
} }
const fileName = `invoice-${invoiceNumber}.pdf`; const fileName = `invoice-${invoiceNumber}.pdf`;
const absoluteFilePath = path.join(invoiceDir, fileName); const absoluteFilePath = path.join(invoiceDir, fileName);
const dbFilePath = `/invoices/${year}/${fileName}`; const dbFilePath = `/invoices/${year}/${fileName}`;
// 🔹 Rechnung speichern // 🔹 Rechnung speichern
const [result] = await connection.query( const [result] = await connection.query(
` `
INSERT INTO invoices INSERT INTO invoices
(patient_id, invoice_date, file_path, total_amount, created_by, status) (patient_id, invoice_date, file_path, total_amount, created_by, status)
VALUES (?, CURDATE(), ?, ?, ?, 'open') VALUES (?, CURDATE(), ?, ?, ?, 'open')
`, `,
[patientId, dbFilePath, total, req.session.user.id] [patientId, dbFilePath, total, req.session.user.id]
); );
const invoiceId = result.insertId; const invoiceId = result.insertId;
const invoice = { const invoice = {
number: invoiceNumber, number: invoiceNumber,
date: new Date().toLocaleDateString("de-DE"), date: new Date().toLocaleDateString("de-DE"),
}; };
// 🔹 HTML rendern // 🔹 HTML rendern
const html = await ejs.renderFile( const html = await ejs.renderFile(
path.join(__dirname, "../views/invoices/invoice.ejs"), path.join(__dirname, "../views/invoices/invoice.ejs"),
{ {
patient, patient,
services, services,
total, total,
invoice, invoice,
doctor, doctor,
company, company,
logoBase64, logoBase64,
} }
); );
// 🔹 PDF erzeugen // 🔹 PDF erzeugen
const pdfBuffer = await htmlToPdf.generatePdf( const pdfBuffer = await htmlToPdf.generatePdf(
{ content: html }, { content: html },
{ format: "A4", printBackground: true } { format: "A4", printBackground: true }
); );
// 💾 PDF speichern // 💾 PDF speichern
fs.writeFileSync(absoluteFilePath, pdfBuffer); fs.writeFileSync(absoluteFilePath, pdfBuffer);
// 🔗 Leistungen mit Rechnung verknüpfen // 🔗 Leistungen mit Rechnung verknüpfen
const [updateResult] = await connection.query( const [updateResult] = await connection.query(
` `
UPDATE patient_services UPDATE patient_services
SET invoice_id = ? SET invoice_id = ?
WHERE patient_id = ? WHERE patient_id = ?
AND invoice_id IS NULL AND invoice_id IS NULL
`, `,
[invoiceId, patientId] [invoiceId, patientId]
); );
const [[cid]] = await connection.query("SELECT CONNECTION_ID() AS cid"); const [[cid]] = await connection.query("SELECT CONNECTION_ID() AS cid");
console.log("🔌 INVOICE CID:", cid.cid); console.log("🔌 INVOICE CID:", cid.cid);
await connection.commit(); await connection.commit();
console.log("🔌 INVOICE CID:", cid.cid); console.log("🔌 INVOICE CID:", cid.cid);
// 📤 PDF anzeigen // 📤 PDF anzeigen
res.render("invoice_preview", { res.render("invoice_preview", {
pdfUrl: dbFilePath, pdfUrl: dbFilePath,
}); });
} catch (err) { } catch (err) {
await connection.rollback(); await connection.rollback();
console.error("❌ INVOICE ERROR:", err); console.error("❌ INVOICE ERROR:", err);
res.status(500).send(err.message || "Fehler beim Erstellen der Rechnung"); res.status(500).send(err.message || "Fehler beim Erstellen der Rechnung");
} finally { } finally {
connection.release(); connection.release();
} }
} }
module.exports = { createInvoicePdf }; module.exports = { createInvoicePdf };

View File

@ -1,109 +1,109 @@
const db = require("../db"); const db = require("../db");
const ejs = require("ejs"); const ejs = require("ejs");
const path = require("path"); const path = require("path");
const fs = require("fs"); const fs = require("fs");
const pdf = require("html-pdf-node"); const pdf = require("html-pdf-node");
async function createInvoicePdf(req, res) { async function createInvoicePdf(req, res) {
const patientId = req.params.id; const patientId = req.params.id;
try { try {
// 1⃣ Patient laden // 1⃣ Patient laden
const [[patient]] = await db.promise().query( const [[patient]] = await db.promise().query(
"SELECT * FROM patients WHERE id = ?", "SELECT * FROM patients WHERE id = ?",
[patientId] [patientId]
); );
if (!patient) { if (!patient) {
return res.status(404).send("Patient nicht gefunden"); return res.status(404).send("Patient nicht gefunden");
} }
// 2⃣ Leistungen laden (noch nicht abgerechnet) // 2⃣ Leistungen laden (noch nicht abgerechnet)
const [rows] = await db.promise().query(` const [rows] = await db.promise().query(`
SELECT SELECT
ps.quantity, ps.quantity,
COALESCE(ps.price_override, s.price) AS price, COALESCE(ps.price_override, s.price) AS price,
CASE CASE
WHEN UPPER(TRIM(?)) = 'ES' WHEN UPPER(TRIM(?)) = 'ES'
THEN COALESCE(NULLIF(s.name_es, ''), s.name_de) THEN COALESCE(NULLIF(s.name_es, ''), s.name_de)
ELSE s.name_de ELSE s.name_de
END AS name END AS name
FROM patient_services ps FROM patient_services ps
JOIN services s ON ps.service_id = s.id JOIN services s ON ps.service_id = s.id
WHERE ps.patient_id = ? WHERE ps.patient_id = ?
AND ps.invoice_id IS NULL AND ps.invoice_id IS NULL
`, [patient.country, patientId]); `, [patient.country, patientId]);
if (rows.length === 0) { if (rows.length === 0) {
return res.send("Keine Leistungen vorhanden"); return res.send("Keine Leistungen vorhanden");
} }
const services = rows.map(s => ({ const services = rows.map(s => ({
quantity: Number(s.quantity), quantity: Number(s.quantity),
name: s.name, name: s.name,
price: Number(s.price), price: Number(s.price),
total: Number(s.price) * Number(s.quantity) total: Number(s.price) * Number(s.quantity)
})); }));
const total = services.reduce((sum, s) => sum + s.total, 0); const total = services.reduce((sum, s) => sum + s.total, 0);
// 3⃣ HTML aus EJS erzeugen // 3⃣ HTML aus EJS erzeugen
const html = await ejs.renderFile( const html = await ejs.renderFile(
path.join(__dirname, "../views/invoices/invoice.ejs"), path.join(__dirname, "../views/invoices/invoice.ejs"),
{ patient, services, total } { patient, services, total }
); );
// 4⃣ PDF erzeugen // 4⃣ PDF erzeugen
const pdfBuffer = await pdf.generatePdf( const pdfBuffer = await pdf.generatePdf(
{ content: html }, { content: html },
{ format: "A4" } { format: "A4" }
); );
// 5⃣ Dateiname + Pfad // 5⃣ Dateiname + Pfad
const date = new Date().toISOString().split("T")[0]; // YYYY-MM-DD const date = new Date().toISOString().split("T")[0]; // YYYY-MM-DD
const fileName = `invoice_${patientId}_${date}.pdf`; const fileName = `invoice_${patientId}_${date}.pdf`;
const outputPath = path.join(__dirname, "..", "documents", fileName); const outputPath = path.join(__dirname, "..", "documents", fileName);
// 6⃣ PDF speichern // 6⃣ PDF speichern
fs.writeFileSync(outputPath, pdfBuffer); fs.writeFileSync(outputPath, pdfBuffer);
// 7⃣ OPTIONAL: Rechnung in DB speichern (empfohlen) // 7⃣ OPTIONAL: Rechnung in DB speichern (empfohlen)
const [invoiceResult] = await db.promise().query(` const [invoiceResult] = await db.promise().query(`
INSERT INTO invoices INSERT INTO invoices
(patient_id, invoice_date, total_amount, file_path, created_by, status) (patient_id, invoice_date, total_amount, file_path, created_by, status)
VALUES (?, CURDATE(), ?, ?, ?, 'open') VALUES (?, CURDATE(), ?, ?, ?, 'open')
`, [ `, [
patientId, patientId,
total, total,
`documents/${fileName}`, `documents/${fileName}`,
req.session.user.id req.session.user.id
]); ]);
const invoiceId = invoiceResult.insertId; const invoiceId = invoiceResult.insertId;
// 8⃣ Leistungen verknüpfen // 8⃣ Leistungen verknüpfen
await db.promise().query(` await db.promise().query(`
UPDATE patient_services UPDATE patient_services
SET invoice_id = ? SET invoice_id = ?
WHERE patient_id = ? WHERE patient_id = ?
AND invoice_id IS NULL AND invoice_id IS NULL
`, [invoiceId, patientId]); `, [invoiceId, patientId]);
// 9⃣ PDF anzeigen // 9⃣ PDF anzeigen
res.setHeader("Content-Type", "application/pdf"); res.setHeader("Content-Type", "application/pdf");
res.setHeader( res.setHeader(
"Content-Disposition", "Content-Disposition",
`inline; filename="${fileName}"` `inline; filename="${fileName}"`
); );
res.send(pdfBuffer); res.send(pdfBuffer);
} catch (err) { } catch (err) {
console.error("❌ PDF ERROR:", err); console.error("❌ PDF ERROR:", err);
res.status(500).send("Fehler beim Erstellen der Rechnung"); res.status(500).send("Fehler beim Erstellen der Rechnung");
} }
} }
module.exports = { createInvoicePdf }; module.exports = { createInvoicePdf };

View File

@ -1,137 +1,144 @@
const db = require("../db"); const db = require("../db");
// 📋 LISTE // 📋 LISTE
function listMedications(req, res, next) { function listMedications(req, res, next) {
const { q, onlyActive } = req.query; const { q, onlyActive } = req.query;
let sql = ` let sql = `
SELECT SELECT
v.id, v.id,
m.id AS medication_id, m.id AS medication_id,
m.name AS medication, m.name AS medication,
m.active, m.active,
f.name AS form, f.name AS form,
v.dosage, v.dosage,
v.package v.package
FROM medication_variants v FROM medication_variants v
JOIN medications m ON v.medication_id = m.id JOIN medications m ON v.medication_id = m.id
JOIN medication_forms f ON v.form_id = f.id JOIN medication_forms f ON v.form_id = f.id
WHERE 1=1 WHERE 1=1
`; `;
const params = []; const params = [];
if (q) { if (q) {
sql += ` sql += `
AND ( AND (
m.name LIKE ? m.name LIKE ?
OR f.name LIKE ? OR f.name LIKE ?
OR v.dosage LIKE ? OR v.dosage LIKE ?
OR v.package LIKE ? OR v.package LIKE ?
) )
`; `;
params.push(`%${q}%`, `%${q}%`, `%${q}%`, `%${q}%`); params.push(`%${q}%`, `%${q}%`, `%${q}%`, `%${q}%`);
} }
if (onlyActive === "1") { if (onlyActive === "1") {
sql += " AND m.active = 1"; sql += " AND m.active = 1";
} }
sql += " ORDER BY m.name, v.dosage"; sql += " ORDER BY m.name, v.dosage";
db.query(sql, params, (err, rows) => { db.query(sql, params, (err, rows) => {
if (err) return next(err); if (err) return next(err);
res.render("medications", { res.render("medications", {
rows, title: "Medikamentenübersicht",
query: { q, onlyActive },
user: req.session.user, // ✅ IMMER patient-sidebar verwenden
}); sidebarPartial: "partials/sidebar-empty",
}); active: "medications",
}
rows,
// 💾 UPDATE query: { q, onlyActive },
function updateMedication(req, res, next) { user: req.session.user,
const { medication, form, dosage, package: pkg } = req.body; lang: req.session.lang || "de",
const id = req.params.id; });
});
const sql = ` }
UPDATE medication_variants
SET // 💾 UPDATE
dosage = ?, function updateMedication(req, res, next) {
package = ? const { medication, form, dosage, package: pkg } = req.body;
WHERE id = ? const id = req.params.id;
`;
const sql = `
db.query(sql, [dosage, pkg, id], (err) => { UPDATE medication_variants
if (err) return next(err); SET
dosage = ?,
req.session.flash = { type: "success", message: "Medikament gespeichert" }; package = ?
res.redirect("/medications"); WHERE id = ?
}); `;
}
db.query(sql, [dosage, pkg, id], (err) => {
function toggleMedication(req, res, next) { if (err) return next(err);
const id = req.params.id;
req.session.flash = { type: "success", message: "Medikament gespeichert" };
db.query( res.redirect("/medications");
"UPDATE medications SET active = NOT active WHERE id = ?", });
[id], }
(err) => {
if (err) return next(err); function toggleMedication(req, res, next) {
res.redirect("/medications"); const id = req.params.id;
}
); db.query(
} "UPDATE medications SET active = NOT active WHERE id = ?",
[id],
function showCreateMedication(req, res) { (err) => {
const sql = "SELECT id, name FROM medication_forms ORDER BY name"; if (err) return next(err);
res.redirect("/medications");
db.query(sql, (err, forms) => { },
if (err) return res.send("DB Fehler"); );
}
res.render("medication_create", {
forms, function showCreateMedication(req, res) {
user: req.session.user, const sql = "SELECT id, name FROM medication_forms ORDER BY name";
error: null,
}); db.query(sql, (err, forms) => {
}); if (err) return res.send("DB Fehler");
}
res.render("medication_create", {
function createMedication(req, res) { forms,
const { name, form_id, dosage, package: pkg } = req.body; user: req.session.user,
error: null,
if (!name || !form_id || !dosage) { });
return res.send("Pflichtfelder fehlen"); });
} }
db.query( function createMedication(req, res) {
"INSERT INTO medications (name, active) VALUES (?, 1)", const { name, form_id, dosage, package: pkg } = req.body;
[name],
(err, result) => { if (!name || !form_id || !dosage) {
if (err) return res.send("Fehler Medikament"); return res.send("Pflichtfelder fehlen");
}
const medicationId = result.insertId;
db.query(
db.query( "INSERT INTO medications (name, active) VALUES (?, 1)",
`INSERT INTO medication_variants [name],
(medication_id, form_id, dosage, package) (err, result) => {
VALUES (?, ?, ?, ?)`, if (err) return res.send("Fehler Medikament");
[medicationId, form_id, dosage, pkg || null],
(err) => { const medicationId = result.insertId;
if (err) return res.send("Fehler Variante");
db.query(
res.redirect("/medications"); `INSERT INTO medication_variants
} (medication_id, form_id, dosage, package)
); VALUES (?, ?, ?, ?)`,
} [medicationId, form_id, dosage, pkg || null],
); (err) => {
} if (err) return res.send("Fehler Variante");
module.exports = { res.redirect("/medications");
listMedications, },
updateMedication, );
toggleMedication, },
showCreateMedication, );
createMedication, }
};
module.exports = {
listMedications,
updateMedication,
toggleMedication,
showCreateMedication,
createMedication,
};

File diff suppressed because it is too large Load Diff

View File

@ -1,56 +1,56 @@
const db = require("../db"); const db = require("../db");
function uploadPatientFile(req, res) { function uploadPatientFile(req, res) {
const patientId = req.params.id; const patientId = req.params.id;
console.log("📁 req.file:", req.file); console.log("📁 req.file:", req.file);
console.log("📁 req.body:", req.body); console.log("📁 req.body:", req.body);
if (!req.file) { if (!req.file) {
req.session.flash = { req.session.flash = {
type: "danger", type: "danger",
message: "Keine Datei ausgewählt" message: "Keine Datei ausgewählt"
}; };
return res.redirect("/patients"); return res.redirect("/patients");
} }
db.query(` db.query(`
INSERT INTO patient_files INSERT INTO patient_files
( (
patient_id, patient_id,
original_name, original_name,
file_name, file_name,
file_path, file_path,
mime_type, mime_type,
uploaded_by uploaded_by
) )
VALUES (?, ?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?, ?)
`, `,
[ [
patientId, patientId,
req.file.originalname, // 👈 Originaler Dateiname req.file.originalname, // 👈 Originaler Dateiname
req.file.filename, // 👈 Gespeicherter Name req.file.filename, // 👈 Gespeicherter Name
req.file.path, // 👈 Pfad req.file.path, // 👈 Pfad
req.file.mimetype, // 👈 MIME-Type req.file.mimetype, // 👈 MIME-Type
req.session.user.id req.session.user.id
], ],
err => { err => {
if (err) { if (err) {
console.error(err); console.error(err);
req.session.flash = { req.session.flash = {
type: "danger", type: "danger",
message: "Datei konnte nicht gespeichert werden" message: "Datei konnte nicht gespeichert werden"
}; };
return res.redirect("/patients"); return res.redirect("/patients");
} }
req.session.flash = { req.session.flash = {
type: "success", type: "success",
message: "📎 Datei erfolgreich hochgeladen" message: "📎 Datei erfolgreich hochgeladen"
}; };
res.redirect("/patients"); res.redirect("/patients");
} }
); );
} }
module.exports = { uploadPatientFile }; module.exports = { uploadPatientFile };

View File

@ -1,109 +1,109 @@
const db = require("../db"); const db = require("../db");
function addMedication(req, res) { function addMedication(req, res) {
const patientId = req.params.id; const patientId = req.params.id;
const returnTo = req.query.returnTo; const returnTo = req.query.returnTo;
const { const {
medication_variant_id, medication_variant_id,
dosage_instruction, dosage_instruction,
start_date, start_date,
end_date end_date
} = req.body; } = req.body;
if (!medication_variant_id) { if (!medication_variant_id) {
return res.send("Medikament fehlt"); return res.send("Medikament fehlt");
} }
db.query( db.query(
` `
INSERT INTO patient_medications INSERT INTO patient_medications
(patient_id, medication_variant_id, dosage_instruction, start_date, end_date) (patient_id, medication_variant_id, dosage_instruction, start_date, end_date)
VALUES (?, ?, ?, ?, ?) VALUES (?, ?, ?, ?, ?)
`, `,
[ [
patientId, patientId,
medication_variant_id, medication_variant_id,
dosage_instruction || null, dosage_instruction || null,
start_date || null, start_date || null,
end_date || null end_date || null
], ],
err => { err => {
if (err) return res.send("Fehler beim Speichern der Medikation"); if (err) return res.send("Fehler beim Speichern der Medikation");
if (returnTo === "overview") { if (returnTo === "overview") {
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
res.redirect(`/patients/${patientId}/medications`); res.redirect(`/patients/${patientId}/medications`);
} }
); );
} }
function endMedication(req, res) { function endMedication(req, res) {
const medicationId = req.params.id; const medicationId = req.params.id;
const returnTo = req.query.returnTo; const returnTo = req.query.returnTo;
db.query( db.query(
"SELECT patient_id FROM patient_medications WHERE id = ?", "SELECT patient_id FROM patient_medications WHERE id = ?",
[medicationId], [medicationId],
(err, results) => { (err, results) => {
if (err || results.length === 0) { if (err || results.length === 0) {
return res.send("Medikation nicht gefunden"); return res.send("Medikation nicht gefunden");
} }
const patientId = results[0].patient_id; const patientId = results[0].patient_id;
db.query( db.query(
"UPDATE patient_medications SET end_date = CURDATE() WHERE id = ?", "UPDATE patient_medications SET end_date = CURDATE() WHERE id = ?",
[medicationId], [medicationId],
err => { err => {
if (err) return res.send("Fehler beim Beenden der Medikation"); if (err) return res.send("Fehler beim Beenden der Medikation");
if (returnTo === "overview") { if (returnTo === "overview") {
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
res.redirect(`/patients/${patientId}/medications`); res.redirect(`/patients/${patientId}/medications`);
} }
); );
} }
); );
} }
function deleteMedication(req, res) { function deleteMedication(req, res) {
const medicationId = req.params.id; const medicationId = req.params.id;
const returnTo = req.query.returnTo; const returnTo = req.query.returnTo;
db.query( db.query(
"SELECT patient_id FROM patient_medications WHERE id = ?", "SELECT patient_id FROM patient_medications WHERE id = ?",
[medicationId], [medicationId],
(err, results) => { (err, results) => {
if (err || results.length === 0) { if (err || results.length === 0) {
return res.send("Medikation nicht gefunden"); return res.send("Medikation nicht gefunden");
} }
const patientId = results[0].patient_id; const patientId = results[0].patient_id;
db.query( db.query(
"DELETE FROM patient_medications WHERE id = ?", "DELETE FROM patient_medications WHERE id = ?",
[medicationId], [medicationId],
err => { err => {
if (err) return res.send("Fehler beim Löschen der Medikation"); if (err) return res.send("Fehler beim Löschen der Medikation");
if (returnTo === "overview") { if (returnTo === "overview") {
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
res.redirect(`/patients/${patientId}/medications`); res.redirect(`/patients/${patientId}/medications`);
} }
); );
} }
); );
} }
module.exports = { module.exports = {
addMedication, addMedication,
endMedication, endMedication,
deleteMedication deleteMedication
}; };

View File

@ -1,102 +1,102 @@
const db = require("../db"); const db = require("../db");
function addPatientService(req, res) { function addPatientService(req, res) {
const patientId = req.params.id; const patientId = req.params.id;
const { service_id, quantity } = req.body; const { service_id, quantity } = req.body;
if (!service_id) { if (!service_id) {
req.session.flash = { req.session.flash = {
type: "warning", type: "warning",
message: "Bitte eine Leistung auswählen" message: "Bitte eine Leistung auswählen"
}; };
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
db.query( db.query(
"SELECT price FROM services WHERE id = ?", "SELECT price FROM services WHERE id = ?",
[service_id], [service_id],
(err, results) => { (err, results) => {
if (err || results.length === 0) { if (err || results.length === 0) {
req.session.flash = { req.session.flash = {
type: "danger", type: "danger",
message: "Leistung nicht gefunden" message: "Leistung nicht gefunden"
}; };
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
const price = results[0].price; const price = results[0].price;
db.query( db.query(
`INSERT INTO patient_services `INSERT INTO patient_services
(patient_id, service_id, quantity, price, service_date, created_by) (patient_id, service_id, quantity, price, service_date, created_by)
VALUES (?, ?, ?, ?, CURDATE(), ?) `, VALUES (?, ?, ?, ?, CURDATE(), ?) `,
[ [
patientId, patientId,
service_id, service_id,
quantity || 1, quantity || 1,
price, price,
req.session.user.id // behandelnder Arzt req.session.user.id // behandelnder Arzt
], ],
err => { err => {
if (err) { if (err) {
req.session.flash = { req.session.flash = {
type: "danger", type: "danger",
message: "Fehler beim Speichern der Leistung" message: "Fehler beim Speichern der Leistung"
}; };
return res.redirect(`/patients/${patientId}/overview`); return res.redirect(`/patients/${patientId}/overview`);
} }
req.session.flash = { req.session.flash = {
type: "success", type: "success",
message: "Leistung hinzugefügt" message: "Leistung hinzugefügt"
}; };
res.redirect(`/patients/${patientId}/overview`); res.redirect(`/patients/${patientId}/overview`);
} }
); );
} }
); );
} }
function deletePatientService(req, res) { function deletePatientService(req, res) {
const id = req.params.id; const id = req.params.id;
db.query( db.query(
"DELETE FROM patient_services WHERE id = ?", "DELETE FROM patient_services WHERE id = ?",
[id], [id],
() => res.redirect("/services/open") () => res.redirect("/services/open")
); );
} }
function updatePatientServicePrice(req, res) { function updatePatientServicePrice(req, res) {
const id = req.params.id; const id = req.params.id;
const { price } = req.body; const { price } = req.body;
db.query( db.query(
"UPDATE patient_services SET price_override = ? WHERE id = ?", "UPDATE patient_services SET price_override = ? WHERE id = ?",
[price, id], [price, id],
() => res.redirect("/services/open") () => res.redirect("/services/open")
); );
} }
function updatePatientServiceQuantity(req, res) { function updatePatientServiceQuantity(req, res) {
const id = req.params.id; const id = req.params.id;
const { quantity } = req.body; const { quantity } = req.body;
if (!quantity || quantity < 1) { if (!quantity || quantity < 1) {
return res.redirect("/services/open"); return res.redirect("/services/open");
} }
db.query( db.query(
"UPDATE patient_services SET quantity = ? WHERE id = ?", "UPDATE patient_services SET quantity = ? WHERE id = ?",
[quantity, id], [quantity, id],
() => res.redirect("/services/open") () => res.redirect("/services/open")
); );
} }
module.exports = { module.exports = {
addPatientService, addPatientService,
deletePatientService, deletePatientService,
updatePatientServicePrice, updatePatientServicePrice,
updatePatientServiceQuantity updatePatientServiceQuantity
}; };

View File

@ -0,0 +1,59 @@
const db = require("../db");
exports.statusReport = async (req, res) => {
try {
// Filter aus URL
const year = parseInt(req.query.year) || new Date().getFullYear();
const quarter = parseInt(req.query.quarter) || 0; // 0 = alle
// WHERE-Teil dynamisch bauen
let where = "WHERE 1=1";
const params = [];
if (year) {
where += " AND YEAR(invoice_date) = ?";
params.push(year);
}
if (quarter) {
where += " AND QUARTER(invoice_date) = ?";
params.push(quarter);
}
// Report-Daten
const [stats] = await db.promise().query(`
SELECT
CONCAT(type, '_', status) AS status,
SUM(total_amount) AS total
FROM invoices
GROUP BY type, status
`);
// Verfügbare Jahre
const [years] = await db.promise().query(`
SELECT DISTINCT YEAR(invoice_date) AS year
FROM invoices
ORDER BY year DESC
`);
res.render("reportview", {
title: "Abrechnungsreport",
user: req.session.user,
stats,
years: years.map((y) => y.year),
selectedYear: year,
selectedQuarter: quarter,
sidebarPartial: "partials/sidebar-invoices",
active: "reports",
});
} catch (err) {
console.error("❌ Report:", err);
res.status(500).send("Fehler beim Report");
}
};

View File

@ -1,319 +1,342 @@
const db = require("../db"); const db = require("../db");
function listServices(req, res) { function listServices(req, res) {
const { q, onlyActive, patientId } = req.query; const { q, onlyActive, patientId } = req.query;
// 🔹 Standard: Deutsch // 🔹 Standard: Deutsch
let serviceNameField = "name_de"; let serviceNameField = "name_de";
const loadServices = () => { const loadServices = () => {
let sql = ` let sql = `
SELECT id, ${serviceNameField} AS name, category, price, active SELECT id, ${serviceNameField} AS name, category, price, active
FROM services FROM services
WHERE 1=1 WHERE 1=1
`; `;
const params = []; const params = [];
if (q) { if (q) {
sql += ` sql += `
AND ( AND (
name_de LIKE ? name_de LIKE ?
OR name_es LIKE ? OR name_es LIKE ?
OR category LIKE ? OR category LIKE ?
) )
`; `;
params.push(`%${q}%`, `%${q}%`, `%${q}%`); params.push(`%${q}%`, `%${q}%`, `%${q}%`);
} }
if (onlyActive === "1") { if (onlyActive === "1") {
sql += " AND active = 1"; sql += " AND active = 1";
} }
sql += ` ORDER BY ${serviceNameField}`; sql += ` ORDER BY ${serviceNameField}`;
db.query(sql, params, (err, services) => { db.query(sql, params, (err, services) => {
if (err) return res.send("Datenbankfehler"); if (err) return res.send("Datenbankfehler");
res.render("services", { res.render("services", {
services, title: "Leistungen",
user: req.session.user, sidebarPartial: "partials/sidebar-empty",
query: { q, onlyActive, patientId } active: "services",
});
}); services,
}; user: req.session.user,
lang: req.session.lang || "de",
// 🔹 Wenn Patient angegeben → Country prüfen query: { q, onlyActive, patientId },
if (patientId) { });
db.query( });
"SELECT country FROM patients WHERE id = ?", };
[patientId],
(err, rows) => { // 🔹 Wenn Patient angegeben → Country prüfen
if (!err && rows.length && rows[0].country === "ES") { if (patientId) {
serviceNameField = "name_es"; db.query(
} "SELECT country FROM patients WHERE id = ?",
loadServices(); [patientId],
} (err, rows) => {
); if (!err && rows.length && rows[0].country === "ES") {
} else { serviceNameField = "name_es";
// 🔹 Kein Patient → Deutsch }
loadServices(); loadServices();
} },
} );
} else {
function listServicesAdmin(req, res) { // 🔹 Kein Patient → Deutsch
const { q, onlyActive } = req.query; loadServices();
}
let sql = ` }
SELECT
id, function listServicesAdmin(req, res) {
name_de, const { q, onlyActive } = req.query;
name_es,
category, let sql = `
price, SELECT
price_c70, id,
active name_de,
FROM services name_es,
WHERE 1=1 category,
`; price,
const params = []; price_c70,
active
if (q) { FROM services
sql += ` WHERE 1=1
AND ( `;
name_de LIKE ? const params = [];
OR name_es LIKE ?
OR category LIKE ? if (q) {
) sql += `
`; AND (
params.push(`%${q}%`, `%${q}%`, `%${q}%`); name_de LIKE ?
} OR name_es LIKE ?
OR category LIKE ?
if (onlyActive === "1") { )
sql += " AND active = 1"; `;
} params.push(`%${q}%`, `%${q}%`, `%${q}%`);
}
sql += " ORDER BY name_de";
if (onlyActive === "1") {
db.query(sql, params, (err, services) => { sql += " AND active = 1";
if (err) return res.send("Datenbankfehler"); }
res.render("services", { sql += " ORDER BY name_de";
services,
user: req.session.user, db.query(sql, params, (err, services) => {
query: { q, onlyActive } if (err) return res.send("Datenbankfehler");
});
}); res.render("services", {
} title: "Leistungen (Admin)",
sidebarPartial: "partials/admin-sidebar",
function showCreateService(req, res) { active: "services",
res.render("service_create", {
user: req.session.user, services,
error: null user: req.session.user,
}); lang: req.session.lang || "de",
} query: { q, onlyActive },
});
function createService(req, res) { });
const { name_de, name_es, category, price, price_c70 } = req.body; }
const userId = req.session.user.id;
function showCreateService(req, res) {
if (!name_de || !price) { res.render("service_create", {
return res.render("service_create", { title: "Leistung anlegen",
user: req.session.user, sidebarPartial: "partials/sidebar-empty",
error: "Bezeichnung (DE) und Preis sind Pflichtfelder" active: "services",
});
} user: req.session.user,
lang: req.session.lang || "de",
db.query( error: null,
` });
INSERT INTO services }
(name_de, name_es, category, price, price_c70, active)
VALUES (?, ?, ?, ?, ?, 1) function createService(req, res) {
`, const { name_de, name_es, category, price, price_c70 } = req.body;
[name_de, name_es || "--", category || "--", price, price_c70 || 0], const userId = req.session.user.id;
(err, result) => {
if (err) return res.send("Fehler beim Anlegen der Leistung"); if (!name_de || !price) {
return res.render("service_create", {
db.query( title: "Leistung anlegen",
` sidebarPartial: "partials/sidebar-empty",
INSERT INTO service_logs active: "services",
(service_id, user_id, action, new_value)
VALUES (?, ?, 'CREATE', ?) user: req.session.user,
`, lang: req.session.lang || "de",
[result.insertId, userId, JSON.stringify(req.body)] error: "Bezeichnung (DE) und Preis sind Pflichtfelder",
); });
}
res.redirect("/services");
} db.query(
); `
} INSERT INTO services
(name_de, name_es, category, price, price_c70, active)
function updateServicePrice(req, res) { VALUES (?, ?, ?, ?, ?, 1)
const serviceId = req.params.id; `,
const { price, price_c70 } = req.body; [name_de, name_es || "--", category || "--", price, price_c70 || 0],
const userId = req.session.user.id; (err, result) => {
if (err) return res.send("Fehler beim Anlegen der Leistung");
db.query(
"SELECT price, price_c70 FROM services WHERE id = ?", db.query(
[serviceId], `
(err, oldRows) => { INSERT INTO service_logs
if (err || oldRows.length === 0) return res.send("Service nicht gefunden"); (service_id, user_id, action, new_value)
VALUES (?, ?, 'CREATE', ?)
const oldData = oldRows[0]; `,
[result.insertId, userId, JSON.stringify(req.body)],
db.query( );
"UPDATE services SET price = ?, price_c70 = ? WHERE id = ?",
[price, price_c70, serviceId], res.redirect("/services");
err => { },
if (err) return res.send("Update fehlgeschlagen"); );
}
db.query(
` function updateServicePrice(req, res) {
INSERT INTO service_logs const serviceId = req.params.id;
(service_id, user_id, action, old_value, new_value) const { price, price_c70 } = req.body;
VALUES (?, ?, 'UPDATE_PRICE', ?, ?) const userId = req.session.user.id;
`,
[ db.query(
serviceId, "SELECT price, price_c70 FROM services WHERE id = ?",
userId, [serviceId],
JSON.stringify(oldData), (err, oldRows) => {
JSON.stringify({ price, price_c70 }) if (err || oldRows.length === 0)
] return res.send("Service nicht gefunden");
);
const oldData = oldRows[0];
res.redirect("/services");
} db.query(
); "UPDATE services SET price = ?, price_c70 = ? WHERE id = ?",
} [price, price_c70, serviceId],
); (err) => {
} if (err) return res.send("Update fehlgeschlagen");
function toggleService(req, res) { db.query(
const serviceId = req.params.id; `
const userId = req.session.user.id; INSERT INTO service_logs
(service_id, user_id, action, old_value, new_value)
db.query( VALUES (?, ?, 'UPDATE_PRICE', ?, ?)
"SELECT active FROM services WHERE id = ?", `,
[serviceId], [
(err, rows) => { serviceId,
if (err || rows.length === 0) return res.send("Service nicht gefunden"); userId,
JSON.stringify(oldData),
const oldActive = rows[0].active; JSON.stringify({ price, price_c70 }),
const newActive = oldActive ? 0 : 1; ],
);
db.query(
"UPDATE services SET active = ? WHERE id = ?", res.redirect("/services");
[newActive, serviceId], },
err => { );
if (err) return res.send("Update fehlgeschlagen"); },
);
db.query( }
`
INSERT INTO service_logs function toggleService(req, res) {
(service_id, user_id, action, old_value, new_value) const serviceId = req.params.id;
VALUES (?, ?, 'TOGGLE_ACTIVE', ?, ?) const userId = req.session.user.id;
`,
[serviceId, userId, oldActive, newActive] db.query(
); "SELECT active FROM services WHERE id = ?",
[serviceId],
res.redirect("/services"); (err, rows) => {
} if (err || rows.length === 0) return res.send("Service nicht gefunden");
);
} const oldActive = rows[0].active;
); const newActive = oldActive ? 0 : 1;
}
db.query(
async function listOpenServices(req, res, next) { "UPDATE services SET active = ? WHERE id = ?",
res.set("Cache-Control", "no-store, no-cache, must-revalidate, private"); [newActive, serviceId],
res.set("Pragma", "no-cache"); (err) => {
res.set("Expires", "0"); if (err) return res.send("Update fehlgeschlagen");
const sql = ` db.query(
SELECT `
p.id AS patient_id, INSERT INTO service_logs
p.firstname, (service_id, user_id, action, old_value, new_value)
p.lastname, VALUES (?, ?, 'TOGGLE_ACTIVE', ?, ?)
p.country, `,
ps.id AS patient_service_id, [serviceId, userId, oldActive, newActive],
ps.quantity, );
COALESCE(ps.price_override, s.price) AS price,
CASE res.redirect("/services");
WHEN UPPER(TRIM(p.country)) = 'ES' },
THEN COALESCE(NULLIF(s.name_es, ''), s.name_de) );
ELSE s.name_de },
END AS name );
FROM patient_services ps }
JOIN patients p ON ps.patient_id = p.id
JOIN services s ON ps.service_id = s.id async function listOpenServices(req, res, next) {
WHERE ps.invoice_id IS NULL res.set("Cache-Control", "no-store, no-cache, must-revalidate, private");
ORDER BY p.lastname, p.firstname, name res.set("Pragma", "no-cache");
`; res.set("Expires", "0");
let connection; const sql = `
SELECT
try { p.id AS patient_id,
// 🔌 EXAKT EINE Connection holen p.firstname,
connection = await db.promise().getConnection(); p.lastname,
p.country,
// 🔒 Isolation Level für DIESE Connection ps.id AS patient_service_id,
await connection.query( ps.quantity,
"SET SESSION TRANSACTION ISOLATION LEVEL READ COMMITTED" COALESCE(ps.price_override, s.price) AS price,
); CASE
WHEN UPPER(TRIM(p.country)) = 'ES'
const [[cid]] = await connection.query( THEN COALESCE(NULLIF(s.name_es, ''), s.name_de)
"SELECT CONNECTION_ID() AS cid" ELSE s.name_de
); END AS name
console.log("🔌 OPEN SERVICES CID:", cid.cid); FROM patient_services ps
JOIN patients p ON ps.patient_id = p.id
const [rows] = await connection.query(sql); JOIN services s ON ps.service_id = s.id
WHERE ps.invoice_id IS NULL
console.log("🧾 OPEN SERVICES ROWS:", rows.length); ORDER BY p.lastname, p.firstname, name
`;
res.render("open_services", {
rows, let connection;
user: req.session.user
}); try {
connection = await db.promise().getConnection();
} catch (err) {
next(err); await connection.query(
} finally { "SET SESSION TRANSACTION ISOLATION LEVEL READ COMMITTED",
if (connection) connection.release(); );
}
} const [[cid]] = await connection.query("SELECT CONNECTION_ID() AS cid");
console.log("🔌 OPEN SERVICES CID:", cid.cid);
const [rows] = await connection.query(sql);
function showServiceLogs(req, res) {
db.query( console.log("🧾 OPEN SERVICES ROWS:", rows.length);
`
SELECT res.render("open_services", {
l.created_at, title: "Offene Leistungen",
u.username, sidebarPartial: "partials/sidebar-invoices",
l.action, active: "services",
l.old_value,
l.new_value rows,
FROM service_logs l user: req.session.user,
JOIN users u ON l.user_id = u.id lang: req.session.lang || "de",
ORDER BY l.created_at DESC });
`, } catch (err) {
(err, logs) => { next(err);
if (err) return res.send("Datenbankfehler"); } finally {
if (connection) connection.release();
res.render("admin_service_logs", { }
logs, }
user: req.session.user
}); function showServiceLogs(req, res) {
} db.query(
); `
} SELECT
l.created_at,
u.username,
module.exports = { l.action,
listServices, l.old_value,
showCreateService, l.new_value
createService, FROM service_logs l
updateServicePrice, JOIN users u ON l.user_id = u.id
toggleService, ORDER BY l.created_at DESC
listOpenServices, `,
showServiceLogs, (err, logs) => {
listServicesAdmin if (err) return res.send("Datenbankfehler");
};
res.render("admin_service_logs", {
title: "Service Logs",
sidebarPartial: "partials/admin-sidebar",
active: "services",
logs,
user: req.session.user,
lang: req.session.lang || "de",
});
},
);
}
module.exports = {
listServices,
showCreateService,
createService,
updateServicePrice,
toggleService,
listOpenServices,
showServiceLogs,
listServicesAdmin,
};

125
db.js
View File

@ -1,62 +1,63 @@
const mysql = require("mysql2"); const mysql = require("mysql2");
const { loadConfig } = require("./config-manager"); const { loadConfig } = require("./config-manager");
let pool = null; let pool = null;
function initPool() { function initPool() {
const config = loadConfig(); const config = loadConfig();
// ✅ Setup-Modus: noch keine config.enc → kein Pool // ✅ Setup-Modus: noch keine config.enc → kein Pool
if (!config || !config.db) return null; if (!config || !config.db) return null;
return mysql.createPool({ return mysql.createPool({
host: config.db.host, host: config.db.host,
user: config.db.user, port: config.db.port || 3306,
password: config.db.password, user: config.db.user,
database: config.db.name, password: config.db.password,
waitForConnections: true, database: config.db.name,
connectionLimit: 10, waitForConnections: true,
queueLimit: 0, connectionLimit: 10,
}); queueLimit: 0,
} });
}
function getPool() {
if (!pool) pool = initPool(); function getPool() {
return pool; if (!pool) pool = initPool();
} return pool;
}
function resetPool() {
pool = null; function resetPool() {
} pool = null;
}
/**
* Proxy damit alter Code weitergeht: /**
* const db = require("../db"); * Proxy damit alter Code weitergeht:
* await db.query(...) * const db = require("../db");
*/ * await db.query(...)
const dbProxy = new Proxy( */
{}, const dbProxy = new Proxy(
{ {},
get(target, prop) { {
const p = getPool(); get(target, prop) {
const p = getPool();
if (!p) {
throw new Error( if (!p) {
"❌ DB ist noch nicht konfiguriert (config.enc fehlt). Bitte zuerst Setup ausführen: http://127.0.0.1:51777/setup", throw new Error(
); "❌ DB ist noch nicht konfiguriert (config.enc fehlt). Bitte zuerst Setup ausführen: http://127.0.0.1:51777/setup",
} );
}
const value = p[prop];
const value = p[prop];
if (typeof value === "function") {
return value.bind(p); if (typeof value === "function") {
} return value.bind(p);
}
return value;
}, return value;
}, },
); },
);
module.exports = dbProxy;
module.exports.getPool = getPool; module.exports = dbProxy;
module.exports.resetPool = resetPool; module.exports.getPool = getPool;
module.exports.resetPool = resetPool;

View File

@ -1,208 +1,208 @@
<!DOCTYPE html> <!DOCTYPE html>
<html lang="de"> <html lang="de">
<head> <head>
<meta charset="UTF-8"> <meta charset="UTF-8">
<style> <style>
body { body {
font-family: Arial, Helvetica, sans-serif; font-family: Arial, Helvetica, sans-serif;
font-size: 12px; font-size: 12px;
color: #000; color: #000;
} }
.header { .header {
display: flex; display: flex;
justify-content: space-between; justify-content: space-between;
align-items: flex-start; align-items: flex-start;
} }
.logo { .logo {
width: 160px; width: 160px;
} }
h1 { h1 {
text-align: center; text-align: center;
margin: 30px 0 20px; margin: 30px 0 20px;
} }
table { table {
width: 100%; width: 100%;
border-collapse: collapse; border-collapse: collapse;
margin-top: 10px; margin-top: 10px;
page-break-inside: auto; page-break-inside: auto;
} }
th, td { th, td {
border: 1px solid #333; border: 1px solid #333;
padding: 6px; padding: 6px;
} }
th { th {
background: #f0f0f0; background: #f0f0f0;
} }
.no-border td { .no-border td {
border: none; border: none;
padding: 4px 2px; padding: 4px 2px;
} }
.total { .total {
margin-top: 15px; margin-top: 15px;
font-size: 14px; font-size: 14px;
font-weight: bold; font-weight: bold;
text-align: right; text-align: right;
} }
.footer { .footer {
margin-top: 30px; margin-top: 30px;
font-size: 10px; font-size: 10px;
} }
tr { tr {
page-break-inside: avoid; page-break-inside: avoid;
page-break-after: auto; page-break-after: auto;
} }
.page-break { .page-break {
page-break-before: always; page-break-before: always;
} }
</style> </style>
</head> </head>
<body> <body>
<!-- HEADER --> <!-- HEADER -->
<div class="header"> <div class="header">
<!-- LOGO --> <!-- LOGO -->
<div> <div>
<!-- HIER LOGO EINBINDEN --> <!-- HIER LOGO EINBINDEN -->
<!-- <img src="file:///ABSOLUTER/PFAD/logo.png" class="logo"> --> <!-- <img src="file:///ABSOLUTER/PFAD/logo.png" class="logo"> -->
</div> </div>
<!-- ADRESSE --> <!-- ADRESSE -->
<div> <div>
<strong>MedCenter Tenerife S.L.</strong><br> <strong>MedCenter Tenerife S.L.</strong><br>
C.I.F. B76766302<br><br> C.I.F. B76766302<br><br>
Praxis El Médano<br> Praxis El Médano<br>
Calle Teobaldo Power 5<br> Calle Teobaldo Power 5<br>
38612 El Médano<br> 38612 El Médano<br>
Fon: 922 157 527 / 657 497 996<br><br> Fon: 922 157 527 / 657 497 996<br><br>
Praxis Los Cristianos<br> Praxis Los Cristianos<br>
Avenida de Suecia 10<br> Avenida de Suecia 10<br>
38650 Los Cristianos<br> 38650 Los Cristianos<br>
Fon: 922 157 527 / 654 520 717 Fon: 922 157 527 / 654 520 717
</div> </div>
</div> </div>
<h1>RECHNUNG / FACTURA</h1> <h1>RECHNUNG / FACTURA</h1>
<!-- RECHNUNGSDATEN --> <!-- RECHNUNGSDATEN -->
<table class="no-border"> <table class="no-border">
<tr> <tr>
<td><strong>Factura número</strong></td> <td><strong>Factura número</strong></td>
<td></td> <td></td>
<td><strong>Fecha</strong></td> <td><strong>Fecha</strong></td>
<td>7.1.2026</td> <td>7.1.2026</td>
</tr> </tr>
<tr> <tr>
<td><strong>Rechnungsnummer</strong></td> <td><strong>Rechnungsnummer</strong></td>
<td></td> <td></td>
<td><strong>Datum</strong></td> <td><strong>Datum</strong></td>
<td>7.1.2026</td> <td>7.1.2026</td>
</tr> </tr>
<tr> <tr>
<td><strong>N.I.E. / DNI</strong></td> <td><strong>N.I.E. / DNI</strong></td>
<td></td> <td></td>
<td><strong>Geburtsdatum</strong></td> <td><strong>Geburtsdatum</strong></td>
<td> <td>
9.11.1968 9.11.1968
</td> </td>
</tr> </tr>
</table> </table>
<br> <br>
<!-- PATIENT --> <!-- PATIENT -->
<strong>Patient:</strong><br> <strong>Patient:</strong><br>
Cay Joksch<br> Cay Joksch<br>
Calle la Fuente 24<br> Calle la Fuente 24<br>
38628 San Miguel de Abina 38628 San Miguel de Abina
<br><br> <br><br>
<!-- DIAGNOSE --> <!-- DIAGNOSE -->
<strong>Diagnosis / Diagnose:</strong><br> <strong>Diagnosis / Diagnose:</strong><br>
<br><br> <br><br>
<!-- LEISTUNGEN --> <!-- LEISTUNGEN -->
<p>Für unsere Leistungen erlauben wir uns Ihnen folgendes in Rechnung zu stellen:</p> <p>Für unsere Leistungen erlauben wir uns Ihnen folgendes in Rechnung zu stellen:</p>
<table> <table>
<thead> <thead>
<tr> <tr>
<th>Menge</th> <th>Menge</th>
<th>Terapia / Behandlung</th> <th>Terapia / Behandlung</th>
<th>Preis (€)</th> <th>Preis (€)</th>
<th>Summe (€)</th> <th>Summe (€)</th>
</tr> </tr>
</thead> </thead>
<tbody> <tbody>
<tr> <tr>
<td>1</td> <td>1</td>
<td>1 x Ampulle Benerva 100 mg (Vitamin B1)</td> <td>1 x Ampulle Benerva 100 mg (Vitamin B1)</td>
<td>3.00</td> <td>3.00</td>
<td>3.00</td> <td>3.00</td>
</tr> </tr>
</tbody> </tbody>
</table> </table>
<div class="total"> <div class="total">
T O T A L: 3.00 € T O T A L: 3.00 €
</div> </div>
<br> <br>
<div class="page-break"></div> <div class="page-break"></div>
<!-- ARZT --> <!-- ARZT -->
<strong>Behandelnder Arzt / Médico tratante:</strong><br> <strong>Behandelnder Arzt / Médico tratante:</strong><br>
Cay Joksch<br> Cay Joksch<br>
<strong>Fachrichtung / Especialidad:</strong> <strong>Fachrichtung / Especialidad:</strong>
Homoopath<br> Homoopath<br>
<strong>Arztnummer / Nº colegiado:</strong> <strong>Arztnummer / Nº colegiado:</strong>
6514.651.651.<br> 6514.651.651.<br>
<br> <br>
<!-- ZAHLUNGSART --> <!-- ZAHLUNGSART -->
<strong>Forma de pago / Zahlungsform:</strong><br> <strong>Forma de pago / Zahlungsform:</strong><br>
Efectivo □ &nbsp;&nbsp; Tarjeta □<br> Efectivo □ &nbsp;&nbsp; Tarjeta □<br>
Barzahlung &nbsp;&nbsp; EC/Kreditkarte Barzahlung &nbsp;&nbsp; EC/Kreditkarte
<br><br> <br><br>
<!-- BANK --> <!-- BANK -->
<strong>Santander</strong><br> <strong>Santander</strong><br>
IBAN: ES37 0049 4507 8925 1002 3301<br> IBAN: ES37 0049 4507 8925 1002 3301<br>
BIC: BSCHESMMXXX BIC: BSCHESMMXXX
<div class="footer"> <div class="footer">
Privatärztliche Rechnung gemäß spanischem und deutschem Recht Privatärztliche Rechnung gemäß spanischem und deutschem Recht
</div> </div>
</body> </body>
</html> </html>

View File

@ -1,26 +1,132 @@
{ {
"global": { "global": {
"save": "Speichern", "save": "Speichern",
"cancel": "Abbrechen", "cancel": "Abbrechen",
"search": "Suchen", "search": "Suchen",
"reset": "Reset", "reset": "Reset",
"dashboard": "Dashboard" "dashboard": "Dashboard",
}, "logout": "Logout",
"sidebar": { "title": "Titel",
"patients": "Patienten", "firstname": "Vorname",
"medications": "Medikamente", "lastname": "Nachname",
"servicesOpen": "Offene Leistungen", "username": "Username",
"billing": "Abrechnung", "role": "Rolle",
"admin": "Verwaltung", "action": "Aktionen",
"logout": "Logout" "status": "Status",
}, "you": "Du Selbst",
"dashboard": { "newuser": "Neuer benutzer",
"welcome": "Willkommen", "inactive": "inaktive",
"waitingRoom": "Wartezimmer-Monitor", "active": "aktive",
"noWaitingPatients": "Keine Patienten im Wartezimmer." "closed": "gesperrt",
}, "filter": "Filtern",
"adminSidebar": { "yearcash": "Jahresumsatz",
"users": "Userverwaltung", "monthcash": "Monatsumsatz",
"database": "Datenbankverwaltung" "quartalcash": "Quartalsumsatz",
} "year": "Jahr",
} "nodata": "keine Daten",
"month": "Monat",
"patientcash": "Umsatz pro Patient",
"patient": "Patient",
"systeminfo": "Systeminformationen",
"table": "Tabelle",
"lines": "Zeilen",
"size": "Grösse",
"errordatabase": "Fehler beim Auslesen der Datenbankinfos:",
"welcome": "Willkommen",
"waitingroomtext": "Wartezimmer-Monitor",
"waitingroomtextnopatient": "Keine Patienten im Wartezimmer.",
"gender": "Geschlecht",
"birthday": "Geburtstag",
"email": "E-Mail",
"phone": "Telefon",
"address": "Adresse",
"country": "Land",
"notice": "Notizen",
"create": "Erstellt",
"change": "Geändert",
"reset2": "Zurücksetzen",
"edit": "Bearbeiten",
"selection": "Auswahl",
"waiting": "Wartet bereits",
"towaitingroom": "Ins Wartezimmer",
"overview": "Übersicht",
"upload": "Hochladen",
"lock": "Sperren",
"unlock": "Enrsperren",
"name": "Name",
"return": "Zurück",
"fileupload": "Hochladen"
},
"sidebar": {
"patients": "Patienten",
"medications": "Medikamente",
"servicesOpen": "Patienten Rechnungen",
"billing": "Abrechnung",
"admin": "Verwaltung",
"logout": "Logout"
},
"dashboard": {
"welcome": "Willkommen",
"waitingRoom": "Wartezimmer-Monitor",
"noWaitingPatients": "Keine Patienten im Wartezimmer.",
"title": "Dashboard"
},
"adminSidebar": {
"users": "Userverwaltung",
"database": "Datenbankverwaltung",
"user": "Benutzer",
"invocieoverview": "Rechnungsübersicht",
"seriennumber": "Seriennummer",
"databasetable": "Datenbank",
"companysettings": "Firmendaten"
},
"adminuseroverview": {
"useroverview": "Benutzerübersicht",
"usermanagement": "Benutzer Verwaltung",
"user": "Benutzer",
"invocieoverview": "Rechnungsübersicht",
"seriennumber": "Seriennummer",
"databasetable": "Datenbank"
},
"seriennumber": {
"seriennumbertitle": "Seriennummer eingeben",
"seriennumbertext": "Bitte gib deine Lizenz-Seriennummer ein um die Software dauerhaft freizuschalten.",
"seriennumbershort": "Seriennummer (AAAAA-AAAAA-AAAAA-AAAAA)",
"seriennumberdeclaration": "Nur Buchstaben + Zahlen. Format: 4×5 Zeichen, getrennt mit „-“. ",
"saveseriennumber": "Seriennummer Speichern"
},
"databaseoverview": {
"title": "Datenbank Konfiguration",
"text": "Hier kannst du die DB-Verbindung testen und speichern. ",
"host": "Host",
"port": "Port",
"database": "Datenbank",
"password": "Password",
"connectiontest": "Verbindung testen",
"tablecount": "Anzahl Tabellen",
"databasesize": "Datenbankgrösse",
"tableoverview": "Tabellenübersicht"
},
"patienteoverview": {
"patienttitle": "Patientenübersicht",
"newpatient": "Neuer Patient",
"nopatientfound": "Keine Patienten gefunden",
"closepatient": "Patient sperren ( inaktiv)",
"openpatient": "Patient entsperren (Aktiv)"
},
"openinvoices": {
"openinvoices": "Offene Rechnungen",
"canceledinvoices": "Stornierte Rechnungen",
"report": "Umsatzreport",
"payedinvoices": "Bezahlte Rechnungen",
"creditoverview": "Gutschrift Übersicht"
}
}

View File

@ -1,27 +1,132 @@
{ {
"global": { "global": {
"save": "Guardar", "save": "Guardar",
"cancel": "Cancelar", "cancel": "Cancelar",
"search": "Buscar", "search": "Buscar",
"reset": "Resetear", "reset": "Resetear",
"dashboard": "Panel" "dashboard": "Panel",
}, "logout": "cerrar sesión",
"sidebar": { "title": "Título",
"patients": "Pacientes", "firstname": "Nombre",
"medications": "Medicamentos", "lastname": "apellido",
"servicesOpen": "Servicios abiertos", "username": "Nombre de usuario",
"billing": "Facturación", "role": "desempeñar",
"admin": "Administración", "action": "acción",
"logout": "Cerrar sesión" "status": "Estado",
}, "you": "su mismo",
"dashboard": { "newuser": "Nuevo usuario",
"welcome": "Bienvenido", "inactive": "inactivo",
"waitingRoom": "Monitor sala de espera", "active": "activo",
"noWaitingPatients": "No hay pacientes en la sala de espera." "closed": "bloqueado",
}, "filter": "Filtro",
"yearcash": "volumen de negocios anual",
"adminSidebar": { "monthcash": "volumen de negocios mensual",
"users": "Administración de usuarios", "quartalcash": "volumen de negocios trimestral",
"database": "Administración de base de datos" "year": "ano",
} "nodata": "sin datos",
} "month": "mes",
"patientcash": "Ingresos por paciente",
"patient": "paciente",
"systeminfo": "Información del sistema",
"table": "tablas",
"lines": "líneas",
"size": "Tamaño",
"errordatabase": "Error al leer la información de la base de datos:",
"welcome": "Bienvenido",
"waitingroomtext": "Monitor de sala de espera",
"waitingroomtextnopatient": "No hay pacientes en la sala de espera.",
"gender": "Sexo",
"birthday": "Fecha de nacimiento",
"email": "Correo electrónico",
"phone": "Teléfono",
"address": "Dirección",
"country": "País",
"notice": "Notas",
"create": "Creado",
"change": "Modificado",
"reset2": "Restablecer",
"edit": "Editar",
"selection": "Selección",
"waiting": "Ya está esperando",
"towaitingroom": "A la sala de espera",
"overview": "Resumen",
"upload": "Subir archivo",
"lock": "bloquear",
"unlock": "desbloquear",
"name": "Nombre",
"return": "Atrás",
"fileupload": "Cargar"
},
"sidebar": {
"patients": "Pacientes",
"medications": "Medicamentos",
"servicesOpen": "Servicios abiertos",
"billing": "Facturación",
"admin": "Administración",
"logout": "Cerrar sesión"
},
"dashboard": {
"welcome": "Bienvenido",
"waitingRoom": "Monitor sala de espera",
"noWaitingPatients": "No hay pacientes en la sala de espera.",
"title": "Dashboard"
},
"adminSidebar": {
"users": "Administración de usuarios",
"database": "Administración de base de datos",
"user": "usuario",
"invocieoverview": "Resumen de facturas",
"seriennumber": "número de serie",
"databasetable": "base de datos",
"companysettings": "Datos de la empresa"
},
"adminuseroverview": {
"useroverview": "Resumen de usuarios",
"usermanagement": "Administración de usuarios",
"user": "usuario",
"invocieoverview": "Resumen de facturas",
"seriennumber": "número de serie",
"databasetable": "base de datos"
},
"seriennumber": {
"seriennumbertitle": "Introduce el número de serie",
"seriennumbertext": "Introduce el número de serie de tu licencia para activar el software de forma permanente.",
"seriennumbershort": "Número de serie (AAAAA-AAAAA-AAAAA-AAAAA)",
"seriennumberdeclaration": "Solo letras y números. Formato: 4×5 caracteres, separados por «-». ",
"saveseriennumber": "Guardar número de serie"
},
"databaseoverview": {
"title": "Configuración de la base de datos",
"host": "Host",
"port": "Puerto",
"database": "Base de datos",
"password": "Contraseña",
"connectiontest": "Probar conexión",
"text": "Aquí puedes probar y guardar la conexión a la base de datos. ",
"tablecount": "Número de tablas",
"databasesize": "Tamaño de la base de datos",
"tableoverview": "Resumen de tablas"
},
"patienteoverview": {
"patienttitle": "Resumen de pacientes",
"newpatient": "Paciente nuevo",
"nopatientfound": "No se han encontrado pacientes.",
"closepatient": "Bloquear paciente (inactivo)",
"openpatient": "Desbloquear paciente (activo)"
},
"openinvoices": {
"openinvoices": "Facturas de pacientes",
"canceledinvoices": "Facturas canceladas",
"report": "Informe de ventas",
"payedinvoices": "Facturas pagadas",
"creditoverview": "Resumen de abonos"
}
}

View File

@ -1,54 +1,54 @@
function requireLogin(req, res, next) { function requireLogin(req, res, next) {
if (!req.session.user) { if (!req.session.user) {
return res.redirect("/"); return res.redirect("/");
} }
req.user = req.session.user; req.user = req.session.user;
next(); next();
} }
// ✅ NEU: Arzt-only (das war früher dein requireAdmin) // ✅ NEU: Arzt-only (das war früher dein requireAdmin)
function requireArzt(req, res, next) { function requireArzt(req, res, next) {
console.log("ARZT CHECK:", req.session.user); console.log("ARZT CHECK:", req.session.user);
if (!req.session.user) { if (!req.session.user) {
return res.redirect("/"); return res.redirect("/");
} }
if (req.session.user.role !== "arzt") { if (req.session.user.role !== "arzt") {
return res return res
.status(403) .status(403)
.send( .send(
"⛔ Kein Zugriff (Arzt erforderlich). Rolle: " + req.session.user.role, "⛔ Kein Zugriff (Arzt erforderlich). Rolle: " + req.session.user.role,
); );
} }
req.user = req.session.user; req.user = req.session.user;
next(); next();
} }
// ✅ NEU: Admin-only // ✅ NEU: Admin-only
function requireAdmin(req, res, next) { function requireAdmin(req, res, next) {
console.log("ADMIN CHECK:", req.session.user); console.log("ADMIN CHECK:", req.session.user);
if (!req.session.user) { if (!req.session.user) {
return res.redirect("/"); return res.redirect("/");
} }
if (req.session.user.role !== "admin") { if (req.session.user.role !== "admin") {
return res return res
.status(403) .status(403)
.send( .send(
"⛔ Kein Zugriff (Admin erforderlich). Rolle: " + req.session.user.role, "⛔ Kein Zugriff (Admin erforderlich). Rolle: " + req.session.user.role,
); );
} }
req.user = req.session.user; req.user = req.session.user;
next(); next();
} }
module.exports = { module.exports = {
requireLogin, requireLogin,
requireArzt, requireArzt,
requireAdmin, requireAdmin,
}; };

View File

@ -1,7 +1,7 @@
function flashMiddleware(req, res, next) { function flashMiddleware(req, res, next) {
res.locals.flash = req.session.flash || null; res.locals.flash = req.session.flash || null;
req.session.flash = null; req.session.flash = null;
next(); next();
} }
module.exports = flashMiddleware; module.exports = flashMiddleware;

View File

@ -0,0 +1,52 @@
const db = require("../db");
const TRIAL_DAYS = 30;
async function licenseGate(req, res, next) {
// Login-Seiten immer erlauben
if (req.path === "/" || req.path.startsWith("/login")) return next();
// Seriennummer-Seite immer erlauben
if (req.path.startsWith("/serial-number")) return next();
// Wenn nicht eingeloggt -> normal weiter (auth middleware macht das)
if (!req.session?.user) return next();
const [rows] = await db
.promise()
.query(
`SELECT serial_number, trial_started_at FROM company_settings ORDER BY id ASC LIMIT 1`,
);
const settings = rows?.[0];
// Wenn Seriennummer vorhanden -> alles ok
if (settings?.serial_number) return next();
// Wenn keine Trial gestartet: jetzt starten
if (!settings?.trial_started_at) {
await db
.promise()
.query(
`UPDATE company_settings SET trial_started_at = NOW() WHERE id = ?`,
[settings?.id || 1],
);
return next(); // Trial läuft ab jetzt
}
// Trial prüfen
const trialStart = new Date(settings.trial_started_at);
const now = new Date();
const diffMs = now - trialStart;
const diffDays = Math.floor(diffMs / (1000 * 60 * 60 * 24));
if (diffDays < TRIAL_DAYS) {
return next(); // Trial ist noch gültig
}
// ❌ Trial abgelaufen -> nur noch Seriennummer Seite
return res.redirect("/serial-number");
}
module.exports = { licenseGate };

View File

@ -0,0 +1,47 @@
const { configExists, loadConfig } = require("../config-manager");
/**
* Leitet beim ersten Programmstart automatisch zu /setup um,
* solange config.enc fehlt oder DB-Daten unvollständig sind.
*/
module.exports = function requireSetup(req, res, next) {
// ✅ Setup immer erlauben
if (req.path.startsWith("/setup")) return next();
// ✅ Static niemals blockieren
if (req.path.startsWith("/public")) return next();
if (req.path.startsWith("/css")) return next();
if (req.path.startsWith("/js")) return next();
if (req.path.startsWith("/images")) return next();
if (req.path.startsWith("/uploads")) return next();
if (req.path.startsWith("/favicon")) return next();
// ✅ Login/Logout erlauben
if (req.path.startsWith("/login")) return next();
if (req.path.startsWith("/logout")) return next();
// ✅ Wenn config.enc fehlt -> Setup erzwingen
if (!configExists()) {
return res.redirect("/setup");
}
// ✅ Wenn config existiert aber DB Daten fehlen -> Setup erzwingen
let cfg = null;
try {
cfg = loadConfig();
} catch (e) {
cfg = null;
}
const ok =
cfg?.db?.host &&
cfg?.db?.user &&
cfg?.db?.password &&
cfg?.db?.name;
if (!ok) {
return res.redirect("/setup");
}
next();
};

View File

@ -1,26 +1,26 @@
const multer = require("multer"); const multer = require("multer");
const path = require("path"); const path = require("path");
const fs = require("fs"); const fs = require("fs");
const storage = multer.diskStorage({ const storage = multer.diskStorage({
destination: (req, file, cb) => { destination: (req, file, cb) => {
const patientId = req.params.id; const patientId = req.params.id;
const dir = path.join("uploads", "patients", String(patientId)); const dir = path.join("uploads", "patients", String(patientId));
fs.mkdirSync(dir, { recursive: true }); fs.mkdirSync(dir, { recursive: true });
cb(null, dir); cb(null, dir);
}, },
filename: (req, file, cb) => { filename: (req, file, cb) => {
const safeName = file.originalname.replace(/\s+/g, "_"); const safeName = file.originalname.replace(/\s+/g, "_");
cb(null, Date.now() + "_" + safeName); cb(null, Date.now() + "_" + safeName);
} }
}); });
const upload = multer({ const upload = multer({
storage, storage,
limits: { fileSize: 20 * 1024 * 1024 } // 20 MB limits: { fileSize: 20 * 1024 * 1024 } // 20 MB
}); });
module.exports = upload; module.exports = upload;

View File

@ -1,24 +1,24 @@
const multer = require("multer"); const multer = require("multer");
const path = require("path"); const path = require("path");
const fs = require("fs"); const fs = require("fs");
// 🔑 Zielordner: public/images // 🔑 Zielordner: public/images
const uploadDir = path.join(__dirname, "../public/images"); const uploadDir = path.join(__dirname, "../public/images");
// Ordner sicherstellen // Ordner sicherstellen
if (!fs.existsSync(uploadDir)) { if (!fs.existsSync(uploadDir)) {
fs.mkdirSync(uploadDir, { recursive: true }); fs.mkdirSync(uploadDir, { recursive: true });
} }
const storage = multer.diskStorage({ const storage = multer.diskStorage({
destination: (req, file, cb) => { destination: (req, file, cb) => {
cb(null, uploadDir); cb(null, uploadDir);
}, },
filename: (req, file, cb) => { filename: (req, file, cb) => {
// immer gleicher Name // immer gleicher Name
cb(null, "logo" + path.extname(file.originalname)); cb(null, "logo" + path.extname(file.originalname));
} }
}); });
module.exports = multer({ storage }); module.exports = multer({ storage });

Binary file not shown.

199
package-lock.json generated
View File

@ -11,10 +11,12 @@
"bcrypt": "^6.0.0", "bcrypt": "^6.0.0",
"bootstrap": "^5.3.8", "bootstrap": "^5.3.8",
"bootstrap-icons": "^1.13.1", "bootstrap-icons": "^1.13.1",
"chart.js": "^4.5.1",
"docxtemplater": "^3.67.6", "docxtemplater": "^3.67.6",
"dotenv": "^17.2.3", "dotenv": "^17.2.3",
"ejs": "^3.1.10", "ejs": "^3.1.10",
"express": "^4.19.2", "express": "^4.19.2",
"express-ejs-layouts": "^2.5.1",
"express-mysql-session": "^3.0.3", "express-mysql-session": "^3.0.3",
"express-session": "^1.18.2", "express-session": "^1.18.2",
"fs-extra": "^11.3.3", "fs-extra": "^11.3.3",
@ -22,6 +24,8 @@
"html-pdf-node": "^1.0.8", "html-pdf-node": "^1.0.8",
"multer": "^2.0.2", "multer": "^2.0.2",
"mysql2": "^3.16.0", "mysql2": "^3.16.0",
"node-ssh": "^13.2.1",
"pdf-lib": "^1.17.1",
"xlsx": "^0.18.5" "xlsx": "^0.18.5"
}, },
"devDependencies": { "devDependencies": {
@ -1036,6 +1040,12 @@
"@jridgewell/sourcemap-codec": "^1.4.14" "@jridgewell/sourcemap-codec": "^1.4.14"
} }
}, },
"node_modules/@kurkle/color": {
"version": "0.3.4",
"resolved": "https://registry.npmjs.org/@kurkle/color/-/color-0.3.4.tgz",
"integrity": "sha512-M5UknZPHRu3DEDWoipU6sE8PdkZ6Z/S+v4dD+Ke8IaNlpdSQah50lz1KtcFBa2vsdOnwbbnxJwVM4wty6udA5w==",
"license": "MIT"
},
"node_modules/@napi-rs/wasm-runtime": { "node_modules/@napi-rs/wasm-runtime": {
"version": "0.2.12", "version": "0.2.12",
"resolved": "https://registry.npmjs.org/@napi-rs/wasm-runtime/-/wasm-runtime-0.2.12.tgz", "resolved": "https://registry.npmjs.org/@napi-rs/wasm-runtime/-/wasm-runtime-0.2.12.tgz",
@ -1072,6 +1082,24 @@
"@noble/hashes": "^1.1.5" "@noble/hashes": "^1.1.5"
} }
}, },
"node_modules/@pdf-lib/standard-fonts": {
"version": "1.0.0",
"resolved": "https://registry.npmjs.org/@pdf-lib/standard-fonts/-/standard-fonts-1.0.0.tgz",
"integrity": "sha512-hU30BK9IUN/su0Mn9VdlVKsWBS6GyhVfqjwl1FjZN4TxP6cCw0jP2w7V3Hf5uX7M0AZJ16vey9yE0ny7Sa59ZA==",
"license": "MIT",
"dependencies": {
"pako": "^1.0.6"
}
},
"node_modules/@pdf-lib/upng": {
"version": "1.0.1",
"resolved": "https://registry.npmjs.org/@pdf-lib/upng/-/upng-1.0.1.tgz",
"integrity": "sha512-dQK2FUMQtowVP00mtIksrlZhdFXQZPC+taih1q4CvPZ5vqdxR/LKBaFg0oAfzd1GlHZXXSPdQfzQnt+ViGvEIQ==",
"license": "MIT",
"dependencies": {
"pako": "^1.0.10"
}
},
"node_modules/@pkgjs/parseargs": { "node_modules/@pkgjs/parseargs": {
"version": "0.11.0", "version": "0.11.0",
"resolved": "https://registry.npmjs.org/@pkgjs/parseargs/-/parseargs-0.11.0.tgz", "resolved": "https://registry.npmjs.org/@pkgjs/parseargs/-/parseargs-0.11.0.tgz",
@ -1647,6 +1675,14 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/asn1": {
"version": "0.2.6",
"resolved": "https://registry.npmjs.org/asn1/-/asn1-0.2.6.tgz",
"integrity": "sha512-ix/FxPn0MDjeyJ7i/yoHGFt/EX6LyNbxSEhPPXODPL+KB0VPk86UYfL0lMdy+KCnv+fmvIzySwaK5COwqVbWTQ==",
"dependencies": {
"safer-buffer": "~2.1.0"
}
},
"node_modules/async": { "node_modules/async": {
"version": "3.2.6", "version": "3.2.6",
"resolved": "https://registry.npmjs.org/async/-/async-3.2.6.tgz", "resolved": "https://registry.npmjs.org/async/-/async-3.2.6.tgz",
@ -1834,6 +1870,14 @@
"node": ">= 18" "node": ">= 18"
} }
}, },
"node_modules/bcrypt-pbkdf": {
"version": "1.0.2",
"resolved": "https://registry.npmjs.org/bcrypt-pbkdf/-/bcrypt-pbkdf-1.0.2.tgz",
"integrity": "sha512-qeFIXtP4MSoi6NLqO12WfqARWWuCKi2Rn/9hJLEmtB5yTNr9DqFWkJRCf2qShWzPeAMRnOgCrq0sg/KLv5ES9w==",
"dependencies": {
"tweetnacl": "^0.14.3"
}
},
"node_modules/binary-extensions": { "node_modules/binary-extensions": {
"version": "2.3.0", "version": "2.3.0",
"resolved": "https://registry.npmjs.org/binary-extensions/-/binary-extensions-2.3.0.tgz", "resolved": "https://registry.npmjs.org/binary-extensions/-/binary-extensions-2.3.0.tgz",
@ -2061,6 +2105,15 @@
"integrity": "sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==", "integrity": "sha512-E+XQCRwSbaaiChtv6k6Dwgc+bx+Bs6vuKJHHl5kox/BaKbhiXzqQOwK4cO22yElGp2OCmjwVhT3HmxgyPGnJfQ==",
"license": "MIT" "license": "MIT"
}, },
"node_modules/buildcheck": {
"version": "0.0.7",
"resolved": "https://registry.npmjs.org/buildcheck/-/buildcheck-0.0.7.tgz",
"integrity": "sha512-lHblz4ahamxpTmnsk+MNTRWsjYKv965MwOrSJyeD588rR3Jcu7swE+0wN5F+PbL5cjgu/9ObkhfzEPuofEMwLA==",
"optional": true,
"engines": {
"node": ">=10.0.0"
}
},
"node_modules/busboy": { "node_modules/busboy": {
"version": "1.6.0", "version": "1.6.0",
"resolved": "https://registry.npmjs.org/busboy/-/busboy-1.6.0.tgz", "resolved": "https://registry.npmjs.org/busboy/-/busboy-1.6.0.tgz",
@ -2214,6 +2267,18 @@
"node": ">=10" "node": ">=10"
} }
}, },
"node_modules/chart.js": {
"version": "4.5.1",
"resolved": "https://registry.npmjs.org/chart.js/-/chart.js-4.5.1.tgz",
"integrity": "sha512-GIjfiT9dbmHRiYi6Nl2yFCq7kkwdkp1W/lp2J99rX0yo9tgJGn3lKQATztIjb5tVtevcBtIdICNWqlq5+E8/Pw==",
"license": "MIT",
"dependencies": {
"@kurkle/color": "^0.3.0"
},
"engines": {
"pnpm": ">=8"
}
},
"node_modules/cheerio": { "node_modules/cheerio": {
"version": "0.22.0", "version": "0.22.0",
"resolved": "https://registry.npmjs.org/cheerio/-/cheerio-0.22.0.tgz", "resolved": "https://registry.npmjs.org/cheerio/-/cheerio-0.22.0.tgz",
@ -2513,6 +2578,20 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/cpu-features": {
"version": "0.0.10",
"resolved": "https://registry.npmjs.org/cpu-features/-/cpu-features-0.0.10.tgz",
"integrity": "sha512-9IkYqtX3YHPCzoVg1Py+o9057a3i0fp7S530UWokCSaFVTc7CwXPRiOjRjBQQ18ZCNafx78YfnG+HALxtVmOGA==",
"hasInstallScript": true,
"optional": true,
"dependencies": {
"buildcheck": "~0.0.6",
"nan": "^2.19.0"
},
"engines": {
"node": ">=10.0.0"
}
},
"node_modules/crc-32": { "node_modules/crc-32": {
"version": "1.2.2", "version": "1.2.2",
"resolved": "https://registry.npmjs.org/crc-32/-/crc-32-1.2.2.tgz", "resolved": "https://registry.npmjs.org/crc-32/-/crc-32-1.2.2.tgz",
@ -3045,6 +3124,11 @@
"url": "https://opencollective.com/express" "url": "https://opencollective.com/express"
} }
}, },
"node_modules/express-ejs-layouts": {
"version": "2.5.1",
"resolved": "https://registry.npmjs.org/express-ejs-layouts/-/express-ejs-layouts-2.5.1.tgz",
"integrity": "sha512-IXROv9n3xKga7FowT06n1Qn927JR8ZWDn5Dc9CJQoiiaaDqbhW5PDmWShzbpAa2wjWT1vJqaIM1S6vJwwX11gA=="
},
"node_modules/express-mysql-session": { "node_modules/express-mysql-session": {
"version": "3.0.3", "version": "3.0.3",
"resolved": "https://registry.npmjs.org/express-mysql-session/-/express-mysql-session-3.0.3.tgz", "resolved": "https://registry.npmjs.org/express-mysql-session/-/express-mysql-session-3.0.3.tgz",
@ -4105,7 +4189,6 @@
"version": "2.0.1", "version": "2.0.1",
"resolved": "https://registry.npmjs.org/is-stream/-/is-stream-2.0.1.tgz", "resolved": "https://registry.npmjs.org/is-stream/-/is-stream-2.0.1.tgz",
"integrity": "sha512-hFoiJiTl63nn+kstHGBtewWSKnQLpyb155KHheA1l39uvtO9nWIop1p3udqPcUd/xbF1VLMO4n7OI6p7RbngDg==", "integrity": "sha512-hFoiJiTl63nn+kstHGBtewWSKnQLpyb155KHheA1l39uvtO9nWIop1p3udqPcUd/xbF1VLMO4n7OI6p7RbngDg==",
"dev": true,
"license": "MIT", "license": "MIT",
"engines": { "engines": {
"node": ">=8" "node": ">=8"
@ -5293,6 +5376,12 @@
"node": ">=8.0.0" "node": ">=8.0.0"
} }
}, },
"node_modules/nan": {
"version": "2.25.0",
"resolved": "https://registry.npmjs.org/nan/-/nan-2.25.0.tgz",
"integrity": "sha512-0M90Ag7Xn5KMLLZ7zliPWP3rT90P6PN+IzVFS0VqmnPktBk3700xUVv8Ikm9EUaUE5SDWdp/BIxdENzVznpm1g==",
"optional": true
},
"node_modules/napi-postinstall": { "node_modules/napi-postinstall": {
"version": "0.3.4", "version": "0.3.4",
"resolved": "https://registry.npmjs.org/napi-postinstall/-/napi-postinstall-0.3.4.tgz", "resolved": "https://registry.npmjs.org/napi-postinstall/-/napi-postinstall-0.3.4.tgz",
@ -5374,6 +5463,44 @@
"dev": true, "dev": true,
"license": "MIT" "license": "MIT"
}, },
"node_modules/node-ssh": {
"version": "13.2.1",
"resolved": "https://registry.npmjs.org/node-ssh/-/node-ssh-13.2.1.tgz",
"integrity": "sha512-rfl4GWMygQfzlExPkQ2LWyya5n2jOBm5vhEnup+4mdw7tQhNpJWbP5ldr09Jfj93k5SfY5lxcn8od5qrQ/6mBg==",
"dependencies": {
"is-stream": "^2.0.0",
"make-dir": "^3.1.0",
"sb-promise-queue": "^2.1.0",
"sb-scandir": "^3.1.0",
"shell-escape": "^0.2.0",
"ssh2": "^1.14.0"
},
"engines": {
"node": ">= 10"
}
},
"node_modules/node-ssh/node_modules/make-dir": {
"version": "3.1.0",
"resolved": "https://registry.npmjs.org/make-dir/-/make-dir-3.1.0.tgz",
"integrity": "sha512-g3FeP20LNwhALb/6Cz6Dd4F2ngze0jz7tbzrD2wAV+o9FeNHe4rL+yK2md0J/fiSf1sa1ADhXqi5+oVwOM/eGw==",
"dependencies": {
"semver": "^6.0.0"
},
"engines": {
"node": ">=8"
},
"funding": {
"url": "https://github.com/sponsors/sindresorhus"
}
},
"node_modules/node-ssh/node_modules/semver": {
"version": "6.3.1",
"resolved": "https://registry.npmjs.org/semver/-/semver-6.3.1.tgz",
"integrity": "sha512-BR7VvDCVHO+q2xBEWskxS6DJE1qRnb7DxzUrogb71CWoSficBxYsiAGd+Kl0mmq/MprG9yArRkyrQxTO6XjMzA==",
"bin": {
"semver": "bin/semver.js"
}
},
"node_modules/nodemon": { "node_modules/nodemon": {
"version": "3.1.11", "version": "3.1.11",
"resolved": "https://registry.npmjs.org/nodemon/-/nodemon-3.1.11.tgz", "resolved": "https://registry.npmjs.org/nodemon/-/nodemon-3.1.11.tgz",
@ -5585,6 +5712,12 @@
"dev": true, "dev": true,
"license": "BlueOak-1.0.0" "license": "BlueOak-1.0.0"
}, },
"node_modules/pako": {
"version": "1.0.11",
"resolved": "https://registry.npmjs.org/pako/-/pako-1.0.11.tgz",
"integrity": "sha512-4hLB8Py4zZce5s4yd9XzopqwVv/yGNhV1Bl8NTmCq1763HeK2+EwVTv+leGeL13Dnh2wfbqowVPXCIO0z4taYw==",
"license": "(MIT AND Zlib)"
},
"node_modules/parse-json": { "node_modules/parse-json": {
"version": "5.2.0", "version": "5.2.0",
"resolved": "https://registry.npmjs.org/parse-json/-/parse-json-5.2.0.tgz", "resolved": "https://registry.npmjs.org/parse-json/-/parse-json-5.2.0.tgz",
@ -5671,6 +5804,24 @@
"integrity": "sha512-RA1GjUVMnvYFxuqovrEqZoxxW5NUZqbwKtYz/Tt7nXerk0LbLblQmrsgdeOxV5SFHf0UDggjS/bSeOZwt1pmEQ==", "integrity": "sha512-RA1GjUVMnvYFxuqovrEqZoxxW5NUZqbwKtYz/Tt7nXerk0LbLblQmrsgdeOxV5SFHf0UDggjS/bSeOZwt1pmEQ==",
"license": "MIT" "license": "MIT"
}, },
"node_modules/pdf-lib": {
"version": "1.17.1",
"resolved": "https://registry.npmjs.org/pdf-lib/-/pdf-lib-1.17.1.tgz",
"integrity": "sha512-V/mpyJAoTsN4cnP31vc0wfNA1+p20evqqnap0KLoRUN0Yk/p3wN52DOEsL4oBFcLdb76hlpKPtzJIgo67j/XLw==",
"license": "MIT",
"dependencies": {
"@pdf-lib/standard-fonts": "^1.0.0",
"@pdf-lib/upng": "^1.0.1",
"pako": "^1.0.11",
"tslib": "^1.11.1"
}
},
"node_modules/pdf-lib/node_modules/tslib": {
"version": "1.14.1",
"resolved": "https://registry.npmjs.org/tslib/-/tslib-1.14.1.tgz",
"integrity": "sha512-Xni35NKzjgMrwevysHTCArtLDpPvye8zV/0E4EyYn43P7/7qvQwPh9BGkHewbMulVntbigmcT7rdX3BNo9wRJg==",
"license": "0BSD"
},
"node_modules/pend": { "node_modules/pend": {
"version": "1.2.0", "version": "1.2.0",
"resolved": "https://registry.npmjs.org/pend/-/pend-1.2.0.tgz", "resolved": "https://registry.npmjs.org/pend/-/pend-1.2.0.tgz",
@ -6030,6 +6181,25 @@
"integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==", "integrity": "sha512-YZo3K82SD7Riyi0E1EQPojLz7kpepnSQI9IyPbHHg1XXXevb5dJI7tpyN2ADxGcQbHG7vcyRHk0cbwqcQriUtg==",
"license": "MIT" "license": "MIT"
}, },
"node_modules/sb-promise-queue": {
"version": "2.1.1",
"resolved": "https://registry.npmjs.org/sb-promise-queue/-/sb-promise-queue-2.1.1.tgz",
"integrity": "sha512-qXfdcJQMxMljxmPprn4Q4hl3pJmoljSCzUvvEBa9Kscewnv56n0KqrO6yWSrGLOL9E021wcGdPa39CHGKA6G0w==",
"engines": {
"node": ">= 8"
}
},
"node_modules/sb-scandir": {
"version": "3.1.1",
"resolved": "https://registry.npmjs.org/sb-scandir/-/sb-scandir-3.1.1.tgz",
"integrity": "sha512-Q5xiQMtoragW9z8YsVYTAZcew+cRzdVBefPbb9theaIKw6cBo34WonP9qOCTKgyAmn/Ch5gmtAxT/krUgMILpA==",
"dependencies": {
"sb-promise-queue": "^2.1.0"
},
"engines": {
"node": ">= 8"
}
},
"node_modules/semver": { "node_modules/semver": {
"version": "7.7.3", "version": "7.7.3",
"resolved": "https://registry.npmjs.org/semver/-/semver-7.7.3.tgz", "resolved": "https://registry.npmjs.org/semver/-/semver-7.7.3.tgz",
@ -6131,6 +6301,11 @@
"node": ">=8" "node": ">=8"
} }
}, },
"node_modules/shell-escape": {
"version": "0.2.0",
"resolved": "https://registry.npmjs.org/shell-escape/-/shell-escape-0.2.0.tgz",
"integrity": "sha512-uRRBT2MfEOyxuECseCZd28jC1AJ8hmqqneWQ4VWUTgCAFvb3wKU1jLqj6egC4Exrr88ogg3dp+zroH4wJuaXzw=="
},
"node_modules/side-channel": { "node_modules/side-channel": {
"version": "1.1.0", "version": "1.1.0",
"resolved": "https://registry.npmjs.org/side-channel/-/side-channel-1.1.0.tgz", "resolved": "https://registry.npmjs.org/side-channel/-/side-channel-1.1.0.tgz",
@ -6305,6 +6480,23 @@
"node": ">=0.8" "node": ">=0.8"
} }
}, },
"node_modules/ssh2": {
"version": "1.17.0",
"resolved": "https://registry.npmjs.org/ssh2/-/ssh2-1.17.0.tgz",
"integrity": "sha512-wPldCk3asibAjQ/kziWQQt1Wh3PgDFpC0XpwclzKcdT1vql6KeYxf5LIt4nlFkUeR8WuphYMKqUA56X4rjbfgQ==",
"hasInstallScript": true,
"dependencies": {
"asn1": "^0.2.6",
"bcrypt-pbkdf": "^1.0.2"
},
"engines": {
"node": ">=10.16.0"
},
"optionalDependencies": {
"cpu-features": "~0.0.10",
"nan": "^2.23.0"
}
},
"node_modules/stack-utils": { "node_modules/stack-utils": {
"version": "2.0.6", "version": "2.0.6",
"resolved": "https://registry.npmjs.org/stack-utils/-/stack-utils-2.0.6.tgz", "resolved": "https://registry.npmjs.org/stack-utils/-/stack-utils-2.0.6.tgz",
@ -6720,6 +6912,11 @@
"license": "0BSD", "license": "0BSD",
"optional": true "optional": true
}, },
"node_modules/tweetnacl": {
"version": "0.14.5",
"resolved": "https://registry.npmjs.org/tweetnacl/-/tweetnacl-0.14.5.tgz",
"integrity": "sha512-KXXFFdAbFXY4geFIwoyNK+f5Z1b7swfXABfL7HXCmoIWMKU3dmS26672A4EeQtDzLKy7SXmfBu51JolvEKwtGA=="
},
"node_modules/type-detect": { "node_modules/type-detect": {
"version": "4.0.8", "version": "4.0.8",
"resolved": "https://registry.npmjs.org/type-detect/-/type-detect-4.0.8.tgz", "resolved": "https://registry.npmjs.org/type-detect/-/type-detect-4.0.8.tgz",

View File

@ -15,10 +15,12 @@
"bcrypt": "^6.0.0", "bcrypt": "^6.0.0",
"bootstrap": "^5.3.8", "bootstrap": "^5.3.8",
"bootstrap-icons": "^1.13.1", "bootstrap-icons": "^1.13.1",
"chart.js": "^4.5.1",
"docxtemplater": "^3.67.6", "docxtemplater": "^3.67.6",
"dotenv": "^17.2.3", "dotenv": "^17.2.3",
"ejs": "^3.1.10", "ejs": "^3.1.10",
"express": "^4.19.2", "express": "^4.19.2",
"express-ejs-layouts": "^2.5.1",
"express-mysql-session": "^3.0.3", "express-mysql-session": "^3.0.3",
"express-session": "^1.18.2", "express-session": "^1.18.2",
"fs-extra": "^11.3.3", "fs-extra": "^11.3.3",
@ -26,6 +28,8 @@
"html-pdf-node": "^1.0.8", "html-pdf-node": "^1.0.8",
"multer": "^2.0.2", "multer": "^2.0.2",
"mysql2": "^3.16.0", "mysql2": "^3.16.0",
"node-ssh": "^13.2.1",
"pdf-lib": "^1.17.1",
"xlsx": "^0.18.5" "xlsx": "^0.18.5"
}, },
"devDependencies": { "devDependencies": {

View File

@ -1,80 +1,310 @@
/* ========================= /* =========================
WARTEZIMMER MONITOR WARTEZIMMER MONITOR
========================= */ ========================= */
.waiting-monitor { .waiting-monitor {
border: 3px solid #343a40; border: 3px solid #343a40;
border-radius: 10px; border-radius: 10px;
padding: 15px; padding: 15px;
min-height: 45vh; /* untere Hälfte */ min-height: 45vh; /* untere Hälfte */
background-color: #f8f9fa; background-color: #f8f9fa;
} }
.waiting-grid { .waiting-grid {
display: grid; display: grid;
grid-template-columns: repeat(7, 1fr); grid-template-columns: repeat(7, 1fr);
grid-template-rows: repeat(3, 1fr); grid-template-rows: repeat(3, 1fr);
gap: 10px; gap: 10px;
height: 100%; height: 100%;
} }
.waiting-slot { .waiting-slot {
border: 2px dashed #adb5bd; border: 2px dashed #adb5bd;
border-radius: 6px; border-radius: 6px;
padding: 10px; padding: 10px;
background-color: #ffffff; background-color: #ffffff;
display: flex; display: flex;
flex-direction: column; flex-direction: column;
justify-content: center; justify-content: center;
align-items: center; align-items: center;
text-align: center; text-align: center;
} }
.waiting-slot.occupied { .waiting-slot.occupied {
border-style: solid; border-style: solid;
border-color: #198754; border-color: #198754;
background-color: #e9f7ef; background-color: #e9f7ef;
} }
.waiting-slot .name { .waiting-slot .name {
font-weight: bold; font-weight: bold;
} }
.waiting-slot .birthdate { .waiting-slot .birthdate {
font-size: 0.8rem; font-size: 0.8rem;
color: #6c757d; color: #6c757d;
} }
.waiting-slot .placeholder { .waiting-slot .placeholder {
color: #adb5bd; color: #adb5bd;
font-style: italic; font-style: italic;
} }
.waiting-slot.empty { .waiting-slot.empty {
display: flex; display: flex;
align-items: center; align-items: center;
justify-content: center; justify-content: center;
background: #f8f9fa; background: #f8f9fa;
} }
.chair-icon { .chair-icon {
width: 48px; width: 48px;
opacity: 0.4; opacity: 0.4;
} }
.auto-hide-flash { /* ✅ Wartezimmer: Slots klickbar machen (wenn <a> benutzt wird) */
animation: flashFadeOut 3s forwards; .waiting-slot.clickable {
} cursor: pointer;
transition: 0.15s ease;
@keyframes flashFadeOut { text-decoration: none; /* ❌ kein Link-Unterstrich */
0% { color: inherit; /* ✅ Textfarbe wie normal */
opacity: 1; }
}
70% { /* ✅ Hover Effekt */
opacity: 1; .waiting-slot.clickable:hover {
} transform: scale(1.03);
100% { box-shadow: 0 0 0 2px #2563eb;
opacity: 0; }
visibility: hidden;
} /* ✅ damit der Link wirklich den ganzen Block klickbar macht */
} a.waiting-slot {
display: flex;
}
.auto-hide-flash {
animation: flashFadeOut 3s forwards;
}
@keyframes flashFadeOut {
0% {
opacity: 1;
}
70% {
opacity: 1;
}
100% {
opacity: 0;
visibility: hidden;
}
}
/* =========================================================
PAGE HEADER (global)
- Höhe ca. 4cm
- Hintergrund schwarz
- Text in der Mitte
- Button + Datum/Uhrzeit rechts
========================================================= */
/* ✅ Der komplette Header-Container */
.page-header {
height: 150px; /* ca. 4cm */
background: #000; /* Schwarz */
color: #fff; /* Weiße Schrift */
/* Wir nutzen Grid, damit Center wirklich immer mittig bleibt */
display: grid;
/* 3 Spalten:
1) links = leer/optional
2) mitte = Text (center)
3) rechts = Dashboard + Uhrzeit
*/
grid-template-columns: 1fr 2fr 1fr;
align-items: center; /* vertikal mittig */
padding: 0 20px; /* links/rechts Abstand */
box-sizing: border-box;
}
/* ✅ Linke Header-Spalte (kann leer bleiben oder später Logo) */
.page-header-left {
justify-self: start; /* ganz links */
}
/* ✅ Mittlere Header-Spalte (Text zentriert) */
.page-header-center {
justify-self: center; /* wirklich zentriert in der Mitte */
text-align: center;
display: flex;
flex-direction: column; /* Username oben, Titel darunter */
gap: 6px; /* Abstand zwischen den Zeilen */
}
/* ✅ Rechte Header-Spalte (Button + Uhrzeit rechts) */
.page-header-right {
justify-self: end; /* ganz rechts */
display: flex;
flex-direction: column; /* Button oben, Uhrzeit unten */
align-items: flex-end; /* alles rechts ausrichten */
gap: 10px; /* Abstand Button / Uhrzeit */
}
/* ✅ Username-Zeile (z.B. Willkommen, admin) */
.page-header-username {
font-size: 22px;
font-weight: 600;
margin: 0;
}
/* ✅ Titel-Zeile (z.B. Seriennummer) */
.page-header-title {
font-size: 18px;
opacity: 0.9;
}
/* ✅ Subtitle Bereich (optional) */
.page-header-subtitle {
opacity: 0.75;
}
/* ✅ Uhrzeit (oben rechts unter dem Button) */
.page-header-datetime {
font-size: 24px;
opacity: 0.85;
}
/* ✅ Dashboard Button (weißer Rahmen) */
.page-header .btn-outline-light {
border-color: #fff !important;
color: #fff !important;
}
/* ✅ Dashboard Button: keine Unterstreichung + Rahmen + rund */
.page-header a.btn {
text-decoration: none !important; /* keine Unterstreichung */
border: 2px solid #fff !important; /* Rahmen */
border-radius: 12px; /* abgerundete Ecken */
padding: 6px 12px; /* schöner Innenabstand */
display: inline-block; /* saubere Button-Form */
}
/* ✅ Dashboard Button (Hovereffekt) */
.page-header a.btn:hover {
background: #fff !important;
color: #000 !important;
}
/* ✅ Sidebar Lock: verhindert Klick ohne Inline-JS (Helmet CSP safe) */
.nav-item.locked {
opacity: 0.5;
cursor: not-allowed;
pointer-events: none; /* verhindert klicken komplett */
}
/* =========================================================
Admin Sidebar
- Hintergrund schwarz
========================================================= */
.layout {
display: flex;
min-height: 100vh;
}
.sidebar {
width: 260px;
background: #111;
color: #fff;
padding: 20px;
}
.nav-item {
display: flex;
gap: 10px;
padding: 10px;
text-decoration: none;
color: #ddd;
}
.nav-item:hover {
background: #222;
color: #fff;
}
.nav-item.active {
background: #0d6efd;
color: #fff;
}
.main {
flex: 1;
}
/* =========================================================
Leere Sidebar
- Hintergrund schwarz
========================================================= */
/* ✅ Leere Sidebar (nur schwarzer Balken) */
.sidebar-empty {
background: #000;
width: 260px; /* gleiche Breite wie normale Sidebar */
padding: 0;
}
/* =========================================================
Logo Sidebar
- links oben
========================================================= */
.logo {
font-size: 18px;
font-weight: 700;
color: #fff;
margin-bottom: 15px;
}
/* =========================================================
Patientendaten maximal so breit wie die maximalen Daten sind
========================================================= */
.patient-data-box {
max-width: 900px; /* ✅ maximale Breite (kannst du ändern) */
width: 100%;
margin: 0 auto; /* ✅ zentriert */
}
/* ✅ Button im Wartezimmer-Monitor soll aussehen wie ein Link-Block */
.waiting-btn {
width: 100%;
border: none;
background: transparent;
padding: 10px; /* genau wie waiting-slot vorher */
margin: 0;
text-align: center;
cursor: pointer;
}
/* ✅ Entfernt Focus-Rahmen (falls Browser blau umrandet) */
.waiting-btn:focus {
outline: none;
box-shadow: none;
}
/* ✅ Legende im Report */
.chart-legend {
margin-top: 20px;
text-align: left;
}
.legend-row {
display: flex;
align-items: center;
gap: 8px;
margin-bottom: 6px;
}
.legend-color {
width: 14px;
height: 14px;
border-radius: 3px;
}
.legend-text {
font-size: 14px;
}

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

Binary file not shown.

View File

@ -1,15 +1,15 @@
document.addEventListener("DOMContentLoaded", function () { document.addEventListener("DOMContentLoaded", function () {
const roleSelect = document.getElementById("roleSelect"); const roleSelect = document.getElementById("roleSelect");
const arztFields = document.getElementById("arztFields"); const arztFields = document.getElementById("arztFields");
if (!roleSelect || !arztFields) return; if (!roleSelect || !arztFields) return;
function toggleArztFields() { function toggleArztFields() {
arztFields.style.display = roleSelect.value === "arzt" ? "block" : "none"; arztFields.style.display = roleSelect.value === "arzt" ? "block" : "none";
} }
roleSelect.addEventListener("change", toggleArztFields); roleSelect.addEventListener("change", toggleArztFields);
// Beim Laden prüfen // Beim Laden prüfen
toggleArztFields(); toggleArztFields();
}); });

14
public/js/chart.js Normal file

File diff suppressed because one or more lines are too long

21
public/js/datetime.js Normal file
View File

@ -0,0 +1,21 @@
(function () {
function updateDateTime() {
const el = document.getElementById("datetime");
if (!el) return;
const now = new Date();
const date = now.toLocaleDateString("de-DE");
const time = now.toLocaleTimeString("de-DE", {
hour: "2-digit",
minute: "2-digit",
second: "2-digit",
});
el.textContent = `${date} - ${time}`;
}
updateDateTime();
setInterval(updateDateTime, 1000);
})();

View File

@ -0,0 +1,16 @@
document.addEventListener("DOMContentLoaded", () => {
const alerts = document.querySelectorAll(".auto-hide-flash");
if (!alerts.length) return;
setTimeout(() => {
alerts.forEach((el) => {
el.classList.add("flash-hide");
// nach der Animation aus dem DOM entfernen
setTimeout(() => {
el.remove();
}, 700);
});
}, 3000); // ✅ 3 Sekunden
});

View File

@ -1,15 +1,15 @@
/* document.addEventListener("DOMContentLoaded", () => { /* document.addEventListener("DOMContentLoaded", () => {
const invoiceForms = document.querySelectorAll(".invoice-form"); const invoiceForms = document.querySelectorAll(".invoice-form");
invoiceForms.forEach(form => { invoiceForms.forEach(form => {
form.addEventListener("submit", () => { form.addEventListener("submit", () => {
console.log("🧾 Rechnung erstellt Reload folgt"); console.log("🧾 Rechnung erstellt Reload folgt");
// kleiner Delay, damit Backend committen kann // kleiner Delay, damit Backend committen kann
setTimeout(() => { setTimeout(() => {
window.location.reload(); window.location.reload();
}, 1200); }, 1200);
}); });
}); });
}); });
*/ */

View File

@ -0,0 +1,25 @@
document.addEventListener("DOMContentLoaded", () => {
const rows = document.querySelectorAll(".invoice-row");
const btn = document.getElementById("creditBtn");
const form = document.getElementById("creditForm");
let selectedId = null;
rows.forEach((row) => {
row.addEventListener("click", () => {
// Alte Markierung entfernen
rows.forEach((r) => r.classList.remove("table-active"));
// Neue markieren
row.classList.add("table-active");
selectedId = row.dataset.id;
// Button aktivieren
btn.disabled = false;
// Ziel setzen
form.action = `/invoices/${selectedId}/credit`;
});
});
});

View File

@ -0,0 +1,24 @@
document.addEventListener("DOMContentLoaded", () => {
const radios = document.querySelectorAll(".patient-radio");
if (!radios || radios.length === 0) return;
radios.forEach((radio) => {
radio.addEventListener("change", async () => {
const patientId = radio.value;
try {
await fetch("/patients/select", {
method: "POST",
headers: { "Content-Type": "application/x-www-form-urlencoded" },
body: new URLSearchParams({ patientId }),
});
// ✅ neu laden -> Sidebar wird neu gerendert & Bearbeiten wird aktiv
window.location.reload();
} catch (err) {
console.error("❌ patient-select Fehler:", err);
}
});
});
});

View File

@ -0,0 +1,124 @@
document.addEventListener("DOMContentLoaded", () => {
const radios = document.querySelectorAll(".patient-radio");
const sidebarPatientInfo = document.getElementById("sidebarPatientInfo");
const sbOverview = document.getElementById("sbOverview");
const sbHistory = document.getElementById("sbHistory");
const sbEdit = document.getElementById("sbEdit");
const sbMeds = document.getElementById("sbMeds");
const sbWaitingRoomWrapper = document.getElementById("sbWaitingRoomWrapper");
const sbActiveWrapper = document.getElementById("sbActiveWrapper");
const sbUploadForm = document.getElementById("sbUploadForm");
const sbUploadInput = document.getElementById("sbUploadInput");
const sbUploadBtn = document.getElementById("sbUploadBtn");
if (
!radios.length ||
!sidebarPatientInfo ||
!sbOverview ||
!sbHistory ||
!sbEdit ||
!sbMeds ||
!sbWaitingRoomWrapper ||
!sbActiveWrapper ||
!sbUploadForm ||
!sbUploadInput ||
!sbUploadBtn
) {
return;
}
// ✅ Sicherheit: Upload blocken falls nicht aktiv
sbUploadForm.addEventListener("submit", (e) => {
if (!sbUploadForm.action || sbUploadForm.action.endsWith("#")) {
e.preventDefault();
}
});
radios.forEach((radio) => {
radio.addEventListener("change", () => {
const id = radio.value;
const firstname = radio.dataset.firstname;
const lastname = radio.dataset.lastname;
const waiting = radio.dataset.waiting === "1";
const active = radio.dataset.active === "1";
// ✅ Patient Info
sidebarPatientInfo.innerHTML = `
<div class="patient-name">
<strong>${firstname} ${lastname}</strong>
</div>
<div class="patient-meta text-muted">
ID: ${id}
</div>
`;
// ✅ Übersicht
sbOverview.href = "/patients/" + id;
sbOverview.classList.remove("disabled");
// ✅ Verlauf
sbHistory.href = "/patients/" + id + "/overview";
sbHistory.classList.remove("disabled");
// ✅ Bearbeiten
sbEdit.href = "/patients/edit/" + id;
sbEdit.classList.remove("disabled");
// ✅ Medikamente
sbMeds.href = "/patients/" + id + "/medications";
sbMeds.classList.remove("disabled");
// ✅ Wartezimmer (NUR wenn Patient aktiv ist)
if (!active) {
sbWaitingRoomWrapper.innerHTML = `
<div class="nav-item disabled">
<i class="bi bi-door-open"></i> Ins Wartezimmer (Patient inaktiv)
</div>
`;
} else if (waiting) {
sbWaitingRoomWrapper.innerHTML = `
<div class="nav-item disabled">
<i class="bi bi-hourglass-split"></i> Wartet bereits
</div>
`;
} else {
sbWaitingRoomWrapper.innerHTML = `
<form method="POST" action="/patients/waiting-room/${id}" style="margin:0;">
<button type="submit" class="nav-item nav-btn">
<i class="bi bi-door-open"></i> Ins Wartezimmer
</button>
</form>
`;
}
// ✅ Sperren / Entsperren
if (active) {
sbActiveWrapper.innerHTML = `
<form method="POST" action="/patients/deactivate/${id}" style="margin:0;">
<button type="submit" class="nav-item nav-btn">
<i class="bi bi-lock-fill"></i> Sperren
</button>
</form>
`;
} else {
sbActiveWrapper.innerHTML = `
<form method="POST" action="/patients/activate/${id}" style="margin:0;">
<button type="submit" class="nav-item nav-btn">
<i class="bi bi-unlock-fill"></i> Entsperren
</button>
</form>
`;
}
// ✅ Upload nur aktiv wenn Patient ausgewählt
sbUploadForm.action = "/patients/" + id + "/files";
sbUploadInput.disabled = false;
sbUploadBtn.disabled = false;
});
});
});

101
public/js/reports.js Normal file
View File

@ -0,0 +1,101 @@
document.addEventListener("DOMContentLoaded", () => {
const canvas = document.getElementById("statusChart");
const dataEl = document.getElementById("stats-data");
const legendEl = document.getElementById("custom-legend");
if (!canvas || !dataEl || !legendEl) {
console.error("❌ Chart, Daten oder Legende fehlen");
return;
}
let data;
try {
data = JSON.parse(dataEl.textContent);
} catch (err) {
console.error("❌ JSON Fehler:", err);
return;
}
console.log("📊 REPORT DATA:", data);
// Labels & Werte vorbereiten
const labels = data.map((d) => d.status.replace("_", " ").toUpperCase());
const values = data.map((d) => Number(d.total));
// Euro Format
const formatEuro = (value) =>
value.toLocaleString("de-DE", {
style: "currency",
currency: "EUR",
});
// Farben passend zu Status
const colors = [
"#ffc107", // open
"#28a745", // paid
"#dc3545", // cancelled
"#6c757d", // credit
];
// Chart erzeugen
const chart = new Chart(canvas, {
type: "pie",
data: {
labels,
datasets: [
{
data: values,
backgroundColor: colors,
},
],
},
options: {
responsive: true,
plugins: {
// ❗ Eigene Legende → Chart-Legende aus
legend: {
display: false,
},
tooltip: {
callbacks: {
label(context) {
return formatEuro(context.parsed);
},
},
},
},
},
});
// ----------------------------
// Eigene Legende bauen (HTML)
// ----------------------------
legendEl.innerHTML = "";
labels.forEach((label, i) => {
const row = document.createElement("div");
row.className = "legend-row";
row.innerHTML = `
<span
class="legend-color"
style="background:${colors[i]}"
></span>
<span class="legend-text">
${label}: ${formatEuro(values[i])}
</span>
`;
legendEl.appendChild(row);
});
});

View File

@ -1,14 +1,14 @@
document.addEventListener("DOMContentLoaded", () => { document.addEventListener("DOMContentLoaded", () => {
const searchInput = document.getElementById("serviceSearch"); const searchInput = document.getElementById("serviceSearch");
const select = document.getElementById("serviceSelect"); const select = document.getElementById("serviceSelect");
if (!searchInput || !select) return; if (!searchInput || !select) return;
searchInput.addEventListener("input", function () { searchInput.addEventListener("input", function () {
const filter = this.value.toLowerCase(); const filter = this.value.toLowerCase();
Array.from(select.options).forEach(option => { Array.from(select.options).forEach(option => {
option.hidden = !option.text.toLowerCase().includes(filter); option.hidden = !option.text.toLowerCase().includes(filter);
}); });
}); });
}); });

View File

@ -1,28 +1,28 @@
document.addEventListener("DOMContentLoaded", () => { document.addEventListener("DOMContentLoaded", () => {
document.querySelectorAll(".lock-btn").forEach(btn => { document.querySelectorAll(".lock-btn").forEach(btn => {
btn.addEventListener("click", () => { btn.addEventListener("click", () => {
const row = btn.closest("tr"); const row = btn.closest("tr");
// Alle Zeilen sperren // Alle Zeilen sperren
document.querySelectorAll("tr").forEach(r => { document.querySelectorAll("tr").forEach(r => {
r.querySelectorAll("input").forEach(i => i.disabled = true); r.querySelectorAll("input").forEach(i => i.disabled = true);
const save = r.querySelector(".save-btn"); const save = r.querySelector(".save-btn");
if (save) save.disabled = true; if (save) save.disabled = true;
}); });
// Aktuelle Zeile entsperren // Aktuelle Zeile entsperren
row.querySelectorAll("input").forEach(i => i.disabled = false); row.querySelectorAll("input").forEach(i => i.disabled = false);
row.querySelector(".save-btn").disabled = false; row.querySelector(".save-btn").disabled = false;
// Button ändern // Button ändern
btn.textContent = "🔒"; btn.textContent = "🔒";
btn.title = "Bearbeitung gesperrt"; btn.title = "Bearbeitung gesperrt";
// Fokus // Fokus
const firstInput = row.querySelector("input"); const firstInput = row.querySelector("input");
if (firstInput) firstInput.focus(); if (firstInput) firstInput.focus();
}); });
}); });
}); });

View File

@ -1,382 +1,512 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const mysql = require("mysql2/promise"); const mysql = require("mysql2/promise");
const fs = require("fs"); const fs = require("fs");
const path = require("path"); const path = require("path");
const { exec } = require("child_process"); const { exec } = require("child_process");
const multer = require("multer"); const multer = require("multer");
const { NodeSSH } = require("node-ssh");
// ✅ Upload Ordner für Restore Dumps const uploadLogo = require("../middleware/uploadLogo");
const upload = multer({ dest: path.join(__dirname, "..", "uploads_tmp") });
const { // ✅ Upload Ordner für Restore Dumps
listUsers, const upload = multer({ dest: path.join(__dirname, "..", "uploads_tmp") });
showCreateUser,
postCreateUser, const {
changeUserRole, listUsers,
resetUserPassword, showCreateUser,
activateUser, postCreateUser,
deactivateUser, changeUserRole,
showInvoiceOverview, resetUserPassword,
updateUser, activateUser,
} = require("../controllers/admin.controller"); deactivateUser,
showInvoiceOverview,
const { requireArzt, requireAdmin } = require("../middleware/auth.middleware"); updateUser,
} = require("../controllers/admin.controller");
// ✅ config.enc Manager
const { loadConfig, saveConfig } = require("../config-manager"); const { requireArzt, requireAdmin } = require("../middleware/auth.middleware");
// ✅ DB (für resetPool) // ✅ config.enc Manager
const db = require("../db"); const { loadConfig, saveConfig } = require("../config-manager");
/* ========================== // ✅ DB (für resetPool)
VERWALTUNG (NUR ADMIN) const db = require("../db");
========================== */
router.get("/users", requireAdmin, listUsers); // ✅ Firmendaten
router.get("/create-user", requireAdmin, showCreateUser); const {
router.post("/create-user", requireAdmin, postCreateUser); getCompanySettings,
saveCompanySettings
router.post("/users/change-role/:id", requireAdmin, changeUserRole); } = require("../controllers/companySettings.controller");
router.post("/users/reset-password/:id", requireAdmin, resetUserPassword);
router.post("/users/activate/:id", requireAdmin, activateUser);
router.post("/users/deactivate/:id", requireAdmin, deactivateUser); /* ==========================
router.post("/users/update/:id", requireAdmin, updateUser); VERWALTUNG (NUR ADMIN)
========================== */
/* ========================== router.get("/users", requireAdmin, listUsers);
DATENBANKVERWALTUNG (NUR ADMIN) router.get("/create-user", requireAdmin, showCreateUser);
========================== */ router.post("/create-user", requireAdmin, postCreateUser);
// ✅ Seite anzeigen + aktuelle DB Config aus config.enc anzeigen router.post("/users/change-role/:id", requireAdmin, changeUserRole);
router.get("/database", requireAdmin, async (req, res) => { router.post("/users/reset-password/:id", requireAdmin, resetUserPassword);
const cfg = loadConfig(); router.post("/users/activate/:id", requireAdmin, activateUser);
router.post("/users/deactivate/:id", requireAdmin, deactivateUser);
const backupDir = path.join(__dirname, "..", "backups"); router.post("/users/update/:id", requireAdmin, updateUser);
let backupFiles = []; /* ==========================
try { DATENBANKVERWALTUNG (NUR ADMIN)
if (fs.existsSync(backupDir)) { ========================== */
backupFiles = fs
.readdirSync(backupDir) // ✅ Seite anzeigen + aktuelle DB Config aus config.enc anzeigen
.filter((f) => f.toLowerCase().endsWith(".sql")) router.get("/database", requireAdmin, async (req, res) => {
.sort() const cfg = loadConfig();
.reverse(); // ✅ neueste zuerst
} const backupDir = path.join(__dirname, "..", "backups");
} catch (err) {
console.error("❌ Backup Ordner Fehler:", err); let backupFiles = [];
} try {
if (fs.existsSync(backupDir)) {
let systemInfo = null; backupFiles = fs
.readdirSync(backupDir)
try { .filter((f) => f.toLowerCase().endsWith(".sql"))
if (cfg?.db) { .sort()
const conn = await mysql.createConnection({ .reverse(); // ✅ neueste zuerst
host: cfg.db.host, }
user: cfg.db.user, } catch (err) {
password: cfg.db.password, console.error("❌ Backup Ordner Fehler:", err);
database: cfg.db.name, }
});
let systemInfo = null;
// ✅ Version
const [v] = await conn.query("SELECT VERSION() AS version"); try {
if (cfg?.db) {
// ✅ Anzahl Tabellen const conn = await mysql.createConnection({
const [tablesCount] = await conn.query( host: cfg.db.host,
"SELECT COUNT(*) AS count FROM information_schema.tables WHERE table_schema = ?", port: Number(cfg.db.port || 3306), // ✅ WICHTIG: Port nutzen
[cfg.db.name], user: cfg.db.user,
); password: cfg.db.password,
database: cfg.db.name,
// ✅ DB Größe (Bytes) });
const [dbSize] = await conn.query(
` // ✅ Version
SELECT IFNULL(SUM(data_length + index_length),0) AS bytes const [v] = await conn.query("SELECT VERSION() AS version");
FROM information_schema.tables
WHERE table_schema = ? // ✅ Anzahl Tabellen
`, const [tablesCount] = await conn.query(
[cfg.db.name], "SELECT COUNT(*) AS count FROM information_schema.tables WHERE table_schema = ?",
); [cfg.db.name],
);
// ✅ Tabellen Details
const [tables] = await conn.query( // ✅ DB Größe (Bytes)
` const [dbSize] = await conn.query(
SELECT `
table_name AS name, SELECT IFNULL(SUM(data_length + index_length),0) AS bytes
table_rows AS row_count, FROM information_schema.tables
ROUND((data_length + index_length) / 1024 / 1024, 2) AS size_mb WHERE table_schema = ?
FROM information_schema.tables `,
WHERE table_schema = ? [cfg.db.name],
ORDER BY (data_length + index_length) DESC );
`,
[cfg.db.name], // ✅ Tabellen Details
); const [tables] = await conn.query(
`
await conn.end(); SELECT
table_name AS name,
systemInfo = { table_rows AS row_count,
version: v?.[0]?.version || "unbekannt", ROUND((data_length + index_length) / 1024 / 1024, 2) AS size_mb
tableCount: tablesCount?.[0]?.count || 0, FROM information_schema.tables
dbSizeMB: WHERE table_schema = ?
Math.round(((dbSize?.[0]?.bytes || 0) / 1024 / 1024) * 100) / 100, ORDER BY (data_length + index_length) DESC
tables, `,
}; [cfg.db.name],
} );
} catch (err) {
console.error("❌ SYSTEMINFO ERROR:", err); await conn.end();
systemInfo = {
error: err.message, systemInfo = {
}; version: v?.[0]?.version || "unbekannt",
} tableCount: tablesCount?.[0]?.count || 0,
dbSizeMB:
res.render("admin/database", { Math.round(((dbSize?.[0]?.bytes || 0) / 1024 / 1024) * 100) / 100,
user: req.session.user, tables,
dbConfig: cfg?.db || null, };
testResult: null, }
backupFiles, } catch (err) {
systemInfo, // ✅ DAS HAT GEFEHLT console.error("❌ SYSTEMINFO ERROR:", err);
}); systemInfo = {
}); error: err.message,
};
// ✅ Nur testen (ohne speichern) }
router.post("/database/test", requireAdmin, async (req, res) => {
try { res.render("admin/database", {
const { host, user, password, name } = req.body; user: req.session.user,
dbConfig: cfg?.db || null,
if (!host || !user || !password || !name) { testResult: null,
const cfg = loadConfig(); backupFiles,
return res.render("admin/database", { systemInfo,
user: req.session.user, });
dbConfig: cfg?.db || null, });
testResult: { ok: false, message: "❌ Bitte alle Felder ausfüllen." },
}); // ✅ Nur testen (ohne speichern)
} router.post("/database/test", requireAdmin, async (req, res) => {
const backupDir = path.join(__dirname, "..", "backups");
const conn = await mysql.createConnection({
host, function getBackupFiles() {
user, try {
password, if (fs.existsSync(backupDir)) {
database: name, return fs
}); .readdirSync(backupDir)
.filter((f) => f.toLowerCase().endsWith(".sql"))
await conn.query("SELECT 1"); .sort()
await conn.end(); .reverse();
}
return res.render("admin/database", { } catch (err) {
user: req.session.user, console.error("❌ Backup Ordner Fehler:", err);
dbConfig: { host, user, password, name }, }
testResult: { ok: true, message: "✅ Verbindung erfolgreich!" }, return [];
}); }
} catch (err) {
console.error("❌ DB TEST ERROR:", err); try {
const { host, port, user, password, name } = req.body;
return res.render("admin/database", {
user: req.session.user, if (!host || !port || !user || !password || !name) {
dbConfig: req.body, const cfg = loadConfig();
testResult: { return res.render("admin/database", {
ok: false, user: req.session.user,
message: "❌ Verbindung fehlgeschlagen: " + err.message, dbConfig: cfg?.db || null,
}, testResult: { ok: false, message: "❌ Bitte alle Felder ausfüllen." },
}); backupFiles: getBackupFiles(),
} systemInfo: null,
}); });
}
// ✅ DB Settings speichern + Verbindung testen
router.post("/database", requireAdmin, async (req, res) => { const conn = await mysql.createConnection({
try { host,
const { host, user, password, name } = req.body; port: Number(port),
user,
if (!host || !user || !password || !name) { password,
req.flash("error", "❌ Bitte alle Felder ausfüllen."); database: name,
return res.redirect("/admin/database"); });
}
await conn.query("SELECT 1");
const conn = await mysql.createConnection({ await conn.end();
host,
user, return res.render("admin/database", {
password, user: req.session.user,
database: name, dbConfig: { host, port: Number(port), user, password, name }, // ✅ PORT bleibt drin!
}); testResult: { ok: true, message: "✅ Verbindung erfolgreich!" },
backupFiles: getBackupFiles(),
await conn.query("SELECT 1"); systemInfo: null,
await conn.end(); });
} catch (err) {
// ✅ Speichern in config.enc console.error("❌ DB TEST ERROR:", err);
const current = loadConfig() || {};
current.db = { host, user, password, name }; return res.render("admin/database", {
saveConfig(current); user: req.session.user,
dbConfig: req.body,
// ✅ DB Pool resetten (falls vorhanden) testResult: {
if (typeof db.resetPool === "function") { ok: false,
db.resetPool(); message: "❌ Verbindung fehlgeschlagen: " + err.message,
} },
backupFiles: getBackupFiles(),
req.flash( systemInfo: null,
"success", });
"✅ DB Einstellungen gespeichert + Verbindung erfolgreich getestet.", }
); });
return res.redirect("/admin/database");
} catch (err) { // ✅ DB Settings speichern + Verbindung testen
console.error("❌ DB UPDATE ERROR:", err); router.post("/database", requireAdmin, async (req, res) => {
req.flash("error", "❌ Verbindung fehlgeschlagen: " + err.message); function flashSafe(type, msg) {
return res.redirect("/admin/database"); if (typeof req.flash === "function") {
} req.flash(type, msg);
}); return;
}
/* ========================== req.session.flash = req.session.flash || [];
BACKUP (NUR ADMIN) req.session.flash.push({ type, message: msg });
========================== */ }
router.post("/database/backup", requireAdmin, (req, res) => {
// ✅ Flash Safe (funktioniert auch ohne req.flash) const backupDir = path.join(__dirname, "..", "backups");
function flashSafe(type, msg) {
if (typeof req.flash === "function") { // ✅ backupFiles immer bereitstellen
req.flash(type, msg); function getBackupFiles() {
return; try {
} if (fs.existsSync(backupDir)) {
return fs
req.session.flash = req.session.flash || []; .readdirSync(backupDir)
req.session.flash.push({ type, message: msg }); .filter((f) => f.toLowerCase().endsWith(".sql"))
.sort()
console.log(`[FLASH-${type}]`, msg); .reverse();
} }
} catch (err) {
try { console.error("❌ Backup Ordner Fehler:", err);
const cfg = loadConfig(); }
return [];
if (!cfg?.db) { }
flashSafe("danger", "❌ Keine DB Config gefunden (config.enc fehlt).");
return res.redirect("/admin/database"); try {
} const { host, port, user, password, name } = req.body;
const { host, user, password, name } = cfg.db; if (!host || !port || !user || !password || !name) {
flashSafe("danger", "❌ Bitte alle Felder ausfüllen.");
const backupDir = path.join(__dirname, "..", "backups"); return res.render("admin/database", {
if (!fs.existsSync(backupDir)) fs.mkdirSync(backupDir); user: req.session.user,
dbConfig: req.body,
const stamp = new Date() testResult: { ok: false, message: "❌ Bitte alle Felder ausfüllen." },
.toISOString() backupFiles: getBackupFiles(),
.replace(/T/, "_") systemInfo: null,
.replace(/:/g, "-") });
.split(".")[0]; }
const fileName = `${name}_${stamp}.sql`; // ✅ Verbindung testen
const filePath = path.join(backupDir, fileName); const conn = await mysql.createConnection({
host,
// ✅ mysqldump.exe im Root port: Number(port),
const mysqldumpPath = path.join(__dirname, "..", "mysqldump.exe"); user,
password,
// ✅ plugin Ordner im Root (muss existieren) database: name,
const pluginDir = path.join(__dirname, "..", "plugin"); });
if (!fs.existsSync(mysqldumpPath)) { await conn.query("SELECT 1");
flashSafe("danger", "❌ mysqldump.exe nicht gefunden: " + mysqldumpPath); await conn.end();
return res.redirect("/admin/database");
} // ✅ Speichern inkl. Port
const current = loadConfig() || {};
if (!fs.existsSync(pluginDir)) { current.db = {
flashSafe("danger", "❌ plugin Ordner nicht gefunden: " + pluginDir); host,
return res.redirect("/admin/database"); port: Number(port),
} user,
password,
const cmd = `"${mysqldumpPath}" --plugin-dir="${pluginDir}" -h ${host} -u ${user} -p${password} ${name} > "${filePath}"`; name,
};
exec(cmd, (error, stdout, stderr) => { saveConfig(current);
if (error) {
console.error("❌ BACKUP ERROR:", error); // ✅ Pool reset
console.error("STDERR:", stderr); if (typeof db.resetPool === "function") {
db.resetPool();
flashSafe( }
"danger",
"❌ Backup fehlgeschlagen: " + (stderr || error.message), flashSafe("success", "✅ DB Einstellungen gespeichert!");
);
return res.redirect("/admin/database"); // ✅ DIREKT NEU LADEN aus config.enc (damit wirklich die gespeicherten Werte drin stehen)
} const freshCfg = loadConfig();
flashSafe("success", `✅ Backup erstellt: ${fileName}`); return res.render("admin/database", {
return res.redirect("/admin/database"); user: req.session.user,
}); dbConfig: freshCfg?.db || null,
} catch (err) { testResult: {
console.error("❌ BACKUP ERROR:", err); ok: true,
flashSafe("danger", "❌ Backup fehlgeschlagen: " + err.message); message: "✅ Gespeichert und Verbindung getestet.",
return res.redirect("/admin/database"); },
} backupFiles: getBackupFiles(),
}); systemInfo: null,
});
/* ========================== } catch (err) {
RESTORE (NUR ADMIN) console.error("❌ DB UPDATE ERROR:", err);
========================== */ flashSafe("danger", "❌ Verbindung fehlgeschlagen: " + err.message);
router.post("/database/restore", requireAdmin, (req, res) => {
function flashSafe(type, msg) { return res.render("admin/database", {
if (typeof req.flash === "function") { user: req.session.user,
req.flash(type, msg); dbConfig: req.body,
return; testResult: {
} ok: false,
req.session.flash = req.session.flash || []; message: "❌ Verbindung fehlgeschlagen: " + err.message,
req.session.flash.push({ type, message: msg }); },
console.log(`[FLASH-${type}]`, msg); backupFiles: getBackupFiles(),
} systemInfo: null,
});
try { }
const cfg = loadConfig(); });
if (!cfg?.db) { /* ==========================
flashSafe("danger", "❌ Keine DB Config gefunden (config.enc fehlt)."); BACKUP (NUR ADMIN)
return res.redirect("/admin/database"); ========================== */
} router.post("/database/backup", requireAdmin, async (req, res) => {
function flashSafe(type, msg) {
const { host, user, password, name } = cfg.db; if (typeof req.flash === "function") return req.flash(type, msg);
req.session.flash = req.session.flash || [];
const backupDir = path.join(__dirname, "..", "backups"); req.session.flash.push({ type, message: msg });
const selectedFile = req.body.backupFile; console.log(`[FLASH-${type}]`, msg);
}
if (!selectedFile) {
flashSafe("danger", "❌ Bitte ein Backup auswählen."); try {
return res.redirect("/admin/database"); const cfg = loadConfig();
} if (!cfg?.db) {
flashSafe("danger", "❌ Keine DB Config gefunden (config.enc fehlt).");
const fullPath = path.join(backupDir, selectedFile); return res.redirect("/admin/database");
}
if (!fs.existsSync(fullPath)) {
flashSafe("danger", "❌ Backup Datei nicht gefunden: " + selectedFile); const { host, port, user, password, name } = cfg.db;
return res.redirect("/admin/database");
} // ✅ Programmserver Backup Dir
const backupDir = path.join(__dirname, "..", "backups");
// ✅ mysql.exe im Root if (!fs.existsSync(backupDir)) fs.mkdirSync(backupDir);
const mysqlPath = path.join(__dirname, "..", "mysql.exe");
const pluginDir = path.join(__dirname, "..", "plugin"); // ✅ SSH Ziel (DB-Server)
const sshHost = process.env.DBSERVER_HOST;
if (!fs.existsSync(mysqlPath)) { const sshUser = process.env.DBSERVER_USER;
flashSafe("danger", "❌ mysql.exe nicht gefunden im Root: " + mysqlPath); const sshPort = Number(process.env.DBSERVER_PORT || 22);
return res.redirect("/admin/database");
} if (!sshHost || !sshUser) {
flashSafe("danger", "❌ SSH Config fehlt (DBSERVER_HOST / DBSERVER_USER).");
const cmd = `"${mysqlPath}" --plugin-dir="${pluginDir}" -h ${host} -u ${user} -p${password} ${name} < "${fullPath}"`; return res.redirect("/admin/database");
}
exec(cmd, (error, stdout, stderr) => {
if (error) { const stamp = new Date()
console.error("❌ RESTORE ERROR:", error); .toISOString()
console.error("STDERR:", stderr); .replace(/T/, "_")
.replace(/:/g, "-")
flashSafe( .split(".")[0];
"danger",
"❌ Restore fehlgeschlagen: " + (stderr || error.message), const fileName = `${name}_${stamp}.sql`;
);
return res.redirect("/admin/database"); // ✅ Datei wird zuerst auf DB-Server erstellt (tmp)
} const remoteTmpPath = `/tmp/${fileName}`;
flashSafe( // ✅ Datei wird dann lokal (Programmserver) gespeichert
"success", const localPath = path.join(backupDir, fileName);
"✅ Restore erfolgreich abgeschlossen: " + selectedFile,
); const ssh = new NodeSSH();
return res.redirect("/admin/database"); await ssh.connect({
}); host: sshHost,
} catch (err) { username: sshUser,
console.error("❌ RESTORE ERROR:", err); port: sshPort,
flashSafe("danger", "❌ Restore fehlgeschlagen: " + err.message); privateKeyPath: "/home/cay/.ssh/id_ed25519",
return res.redirect("/admin/database"); });
}
}); // ✅ 1) Dump auf DB-Server erstellen
const dumpCmd =
/* ========================== `mysqldump -h "${host}" -P "${port || 3306}" -u "${user}" -p'${password}' "${name}" > "${remoteTmpPath}"`;
ABRECHNUNG (NUR ARZT)
========================== */ const dumpRes = await ssh.execCommand(dumpCmd);
router.get("/invoices", requireArzt, showInvoiceOverview);
if (dumpRes.code !== 0) {
module.exports = router; ssh.dispose();
flashSafe("danger", "❌ Backup fehlgeschlagen: " + (dumpRes.stderr || "mysqldump Fehler"));
return res.redirect("/admin/database");
}
// ✅ 2) Dump Datei vom DB-Server auf Programmserver kopieren
await ssh.getFile(localPath, remoteTmpPath);
// ✅ 3) Temp Datei auf DB-Server löschen
await ssh.execCommand(`rm -f "${remoteTmpPath}"`);
ssh.dispose();
flashSafe("success", `✅ Backup gespeichert (Programmserver): ${fileName}`);
return res.redirect("/admin/database");
} catch (err) {
console.error("❌ BACKUP SSH ERROR:", err);
flashSafe("danger", "❌ Backup fehlgeschlagen: " + err.message);
return res.redirect("/admin/database");
}
});
/* ==========================
RESTORE (NUR ADMIN)
========================== */
router.post("/database/restore", requireAdmin, async (req, res) => {
function flashSafe(type, msg) {
if (typeof req.flash === "function") return req.flash(type, msg);
req.session.flash = req.session.flash || [];
req.session.flash.push({ type, message: msg });
console.log(`[FLASH-${type}]`, msg);
}
const ssh = new NodeSSH();
try {
const cfg = loadConfig();
if (!cfg?.db) {
flashSafe("danger", "❌ Keine DB Config gefunden (config.enc fehlt).");
return res.redirect("/admin/database");
}
const { host, port, user, password, name } = cfg.db;
const backupFile = req.body.backupFile;
if (!backupFile) {
flashSafe("danger", "❌ Kein Backup ausgewählt.");
return res.redirect("/admin/database");
}
if (backupFile.includes("..") || backupFile.includes("/") || backupFile.includes("\\")) {
flashSafe("danger", "❌ Ungültiger Dateiname.");
return res.redirect("/admin/database");
}
const backupDir = path.join(__dirname, "..", "backups");
const localPath = path.join(backupDir, backupFile);
if (!fs.existsSync(localPath)) {
flashSafe("danger", "❌ Datei nicht gefunden (Programmserver): " + backupFile);
return res.redirect("/admin/database");
}
const sshHost = process.env.DBSERVER_HOST;
const sshUser = process.env.DBSERVER_USER;
const sshPort = Number(process.env.DBSERVER_PORT || 22);
if (!sshHost || !sshUser) {
flashSafe("danger", "❌ SSH Config fehlt (DBSERVER_HOST / DBSERVER_USER).");
return res.redirect("/admin/database");
}
const remoteTmpPath = `/tmp/${backupFile}`;
await ssh.connect({
host: sshHost,
username: sshUser,
port: sshPort,
privateKeyPath: "/home/cay/.ssh/id_ed25519",
});
await ssh.putFile(localPath, remoteTmpPath);
const restoreCmd =
`mysql -h "${host}" -P "${port || 3306}" -u "${user}" -p'${password}' "${name}" < "${remoteTmpPath}"`;
const restoreRes = await ssh.execCommand(restoreCmd);
await ssh.execCommand(`rm -f "${remoteTmpPath}"`);
if (restoreRes.code !== 0) {
flashSafe("danger", "❌ Restore fehlgeschlagen: " + (restoreRes.stderr || "mysql Fehler"));
return res.redirect("/admin/database");
}
flashSafe("success", `✅ Restore erfolgreich: ${backupFile}`);
return res.redirect("/admin/database");
} catch (err) {
console.error("❌ RESTORE SSH ERROR:", err);
flashSafe("danger", "❌ Restore fehlgeschlagen: " + err.message);
return res.redirect("/admin/database");
} finally {
try {
ssh.dispose();
} catch (e) {}
}
});
/* ==========================
ABRECHNUNG (NUR ARZT)
========================== */
router.get("/invoices", requireAdmin, showInvoiceOverview);
/* ==========================
Firmendaten
========================== */
router.get(
"/company-settings",
requireAdmin,
getCompanySettings
);
router.post(
"/company-settings",
requireAdmin,
uploadLogo.single("logo"),
saveCompanySettings
);
module.exports = router;

View File

@ -1,11 +1,11 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { const {
getLogin, getLogin,
postLogin postLogin
} = require("../controllers/auth.controller"); } = require("../controllers/auth.controller");
router.get("/", getLogin); router.get("/", getLogin);
router.post("/login", postLogin); router.post("/login", postLogin);
module.exports = router; module.exports = router;

View File

@ -1,19 +1,21 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireArzt } = require("../middleware/auth.middleware"); const { requireAdmin } = require("../middleware/auth.middleware");
const uploadLogo = require("../middleware/uploadLogo"); const uploadLogo = require("../middleware/uploadLogo");
const { const {
getCompanySettings, getCompanySettings,
saveCompanySettings, saveCompanySettings,
} = require("../controllers/companySettings.controller"); } = require("../controllers/companySettings.controller");
router.get("/admin/company-settings", requireArzt, getCompanySettings); // ✅ NUR der relative Pfad
router.get("/company-settings", requireAdmin, getCompanySettings);
router.post(
"/admin/company-settings", router.post(
requireArzt, "/company-settings",
uploadLogo.single("logo"), // 🔑 MUSS VOR DEM CONTROLLER KOMMEN requireAdmin,
saveCompanySettings, uploadLogo.single("logo"),
); saveCompanySettings
);
module.exports = router;
module.exports = router;

View File

@ -1,14 +1,14 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { const {
showDashboard showDashboard
} = require("../controllers/dashboard.controller"); } = require("../controllers/dashboard.controller");
const { const {
requireLogin requireLogin
} = require("../middleware/auth.middleware"); } = require("../middleware/auth.middleware");
router.get("/", requireLogin, showDashboard); router.get("/", requireLogin, showDashboard);
module.exports = router; module.exports = router;

View File

@ -1,8 +1,40 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireArzt } = require("../middleware/auth.middleware");
const { createInvoicePdf } = require("../controllers/invoicePdf.controller"); const { requireArzt } = require("../middleware/auth.middleware");
const { createInvoicePdf } = require("../controllers/invoicePdf.controller");
router.post("/patients/:id/create-invoice", requireArzt, createInvoicePdf); const {
openInvoices,
module.exports = router; markAsPaid,
cancelInvoice,
cancelledInvoices,
paidInvoices,
createCreditNote,
creditOverview,
} = require("../controllers/invoice.controller");
// ✅ NEU: Offene Rechnungen anzeigen
router.get("/open", requireArzt, openInvoices);
// Bezahlt
router.post("/:id/pay", requireArzt, markAsPaid);
// Storno
router.post("/:id/cancel", requireArzt, cancelInvoice);
// Bestehend
router.post("/patients/:id/create-invoice", requireArzt, createInvoicePdf);
// Stornierte Rechnungen mit Jahr
router.get("/cancelled", requireArzt, cancelledInvoices);
// Bezahlte Rechnungen
router.get("/paid", requireArzt, paidInvoices);
// Gutschrift erstellen
router.post("/:id/credit", requireArzt, createCreditNote);
// Gutschriften-Übersicht
router.get("/credit-overview", requireArzt, creditOverview);
module.exports = router;

View File

@ -1,29 +1,29 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireLogin } = require("../middleware/auth.middleware"); const { requireLogin } = require("../middleware/auth.middleware");
const { const {
listMedications, listMedications,
updateMedication, updateMedication,
toggleMedication, toggleMedication,
showCreateMedication, showCreateMedication,
createMedication, createMedication,
} = require("../controllers/medication.controller"); } = require("../controllers/medication.controller");
console.log("✅ medication.routes geladen"); console.log("✅ medication.routes geladen");
router.get("/", requireLogin, listMedications); router.get("/", requireLogin, listMedications);
// 🆕 Formular anzeigen // 🆕 Formular anzeigen
router.get("/create", requireLogin, showCreateMedication); router.get("/create", requireLogin, showCreateMedication);
// 🆕 Speichern // 🆕 Speichern
router.post("/create", requireLogin, createMedication); router.post("/create", requireLogin, createMedication);
// 🆕 UPDATE pro Zeile // 🆕 UPDATE pro Zeile
router.post("/update/:id", requireLogin, updateMedication); router.post("/update/:id", requireLogin, updateMedication);
// 🆕 Toggle // 🆕 Toggle
router.post("/toggle/:id", requireLogin, toggleMedication); router.post("/toggle/:id", requireLogin, toggleMedication);
module.exports = router; module.exports = router;

View File

@ -1,42 +1,89 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireLogin, requireArzt } = require("../middleware/auth.middleware"); const {
listPatients,
const { showCreatePatient,
listPatients, createPatient,
showCreatePatient, showEditPatient,
createPatient, updatePatient,
showEditPatient, showPatientMedications,
updatePatient, moveToWaitingRoom,
showPatientMedications, showWaitingRoom,
moveToWaitingRoom, showPatientOverview,
showPatientOverview, addPatientNote,
addPatientNote, callFromWaitingRoom,
callFromWaitingRoom, dischargePatient,
dischargePatient, showMedicationPlan,
showMedicationPlan, movePatientToWaitingRoom,
deactivatePatient, deactivatePatient,
activatePatient, activatePatient,
showPatientOverviewDashborad, showPatientOverviewDashborad,
assignMedicationToPatient, assignMedicationToPatient,
} = require("../controllers/patient.controller"); } = require("../controllers/patient.controller");
router.get("/", requireLogin, listPatients); // ✅ WICHTIG: middleware export ist ein Object → destructuring!
router.get("/create", requireLogin, showCreatePatient); const { requireLogin } = require("../middleware/auth.middleware");
router.post("/create", requireLogin, createPatient);
router.get("/edit/:id", requireLogin, showEditPatient); /* =========================================
router.post("/edit/:id", requireLogin, updatePatient); PATIENT SELECT (Radiobutton -> Session)
router.get("/:id/medications", requireLogin, showPatientMedications); ========================================= */
router.post("/waiting-room/:id", requireLogin, moveToWaitingRoom); router.post("/select", requireLogin, (req, res) => {
router.get("/:id/overview", requireLogin, showPatientOverview); try {
router.post("/:id/notes", requireLogin, addPatientNote); const patientId = req.body.patientId;
router.post("/waiting-room/call/:id", requireArzt, callFromWaitingRoom);
router.post("/:id/discharge", requireLogin, dischargePatient); if (!patientId) {
router.get("/:id/plan", requireLogin, showMedicationPlan); req.session.selectedPatientId = null;
router.post("/deactivate/:id", requireLogin, deactivatePatient); return res.json({ ok: true, selectedPatientId: null });
router.post("/activate/:id", requireLogin, activatePatient); }
router.get("/:id", requireLogin, showPatientOverviewDashborad);
router.post("/:id/medications/assign", requireLogin, assignMedicationToPatient); req.session.selectedPatientId = parseInt(patientId, 10);
module.exports = router; return res.json({
ok: true,
selectedPatientId: req.session.selectedPatientId,
});
} catch (err) {
console.error("❌ Fehler /patients/select:", err);
return res.status(500).json({ ok: false });
}
});
/* =========================================
PATIENT ROUTES
========================================= */
router.get("/", requireLogin, listPatients);
router.get("/create", requireLogin, showCreatePatient);
router.post("/create", requireLogin, createPatient);
router.get("/waiting-room", requireLogin, showWaitingRoom);
router.post("/waiting-room/:id", requireLogin, moveToWaitingRoom);
router.post(
"/:id/back-to-waiting-room",
requireLogin,
movePatientToWaitingRoom,
);
router.get("/edit/:id", requireLogin, showEditPatient);
router.post("/update/:id", requireLogin, updatePatient);
router.get("/:id/medications", requireLogin, showPatientMedications);
router.post("/:id/medications", requireLogin, assignMedicationToPatient);
router.get("/:id/overview", requireLogin, showPatientOverview);
router.post("/:id/notes", requireLogin, addPatientNote);
router.get("/:id/plan", requireLogin, showMedicationPlan);
router.post("/:id/call", requireLogin, callFromWaitingRoom);
router.post("/:id/discharge", requireLogin, dischargePatient);
router.post("/deactivate/:id", requireLogin, deactivatePatient);
router.post("/activate/:id", requireLogin, activatePatient);
// ✅ Patient Dashboard
router.get("/:id", requireLogin, showPatientOverviewDashborad);
module.exports = router;

View File

@ -1,19 +1,19 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const upload = require("../middleware/upload.middleware"); const upload = require("../middleware/upload.middleware");
const { requireLogin } = require("../middleware/auth.middleware"); const { requireLogin } = require("../middleware/auth.middleware");
const { uploadPatientFile } = require("../controllers/patientFile.controller"); const { uploadPatientFile } = require("../controllers/patientFile.controller");
router.post( router.post(
"/patients/:id/files", "/patients/:id/files",
requireLogin, requireLogin,
(req, res, next) => { (req, res, next) => {
console.log("📥 UPLOAD ROUTE GETROFFEN"); console.log("📥 UPLOAD ROUTE GETROFFEN");
next(); next();
}, },
upload.single("file"), upload.single("file"),
uploadPatientFile uploadPatientFile
); );
module.exports = router; module.exports = router;

View File

@ -1,15 +1,15 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireArzt } = require("../middleware/auth.middleware"); const { requireArzt } = require("../middleware/auth.middleware");
const { const {
addMedication, addMedication,
endMedication, endMedication,
deleteMedication, deleteMedication,
} = require("../controllers/patientMedication.controller"); } = require("../controllers/patientMedication.controller");
router.post("/:id/medications", requireArzt, addMedication); router.post("/:id/medications", requireArzt, addMedication);
router.post("/patient-medications/end/:id", requireArzt, endMedication); router.post("/patient-medications/end/:id", requireArzt, endMedication);
router.post("/patient-medications/delete/:id", requireArzt, deleteMedication); router.post("/patient-medications/delete/:id", requireArzt, deleteMedication);
module.exports = router; module.exports = router;

View File

@ -1,21 +1,21 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireLogin, requireArzt } = require("../middleware/auth.middleware"); const { requireLogin, requireArzt } = require("../middleware/auth.middleware");
const { const {
addPatientService, addPatientService,
deletePatientService, deletePatientService,
updatePatientServicePrice, updatePatientServicePrice,
updatePatientServiceQuantity, updatePatientServiceQuantity,
} = require("../controllers/patientService.controller"); } = require("../controllers/patientService.controller");
router.post("/:id/services", requireLogin, addPatientService); router.post("/:id/services", requireLogin, addPatientService);
router.post("/services/delete/:id", requireArzt, deletePatientService); router.post("/services/delete/:id", requireArzt, deletePatientService);
router.post( router.post(
"/services/update-price/:id", "/services/update-price/:id",
requireArzt, requireArzt,
updatePatientServicePrice, updatePatientServicePrice,
); );
router.post("/services/update-quantity/:id", updatePatientServiceQuantity); router.post("/services/update-quantity/:id", updatePatientServiceQuantity);
module.exports = router; module.exports = router;

8
routes/report.routes.js Normal file
View File

@ -0,0 +1,8 @@
const express = require("express");
const router = express.Router();
const { requireArzt } = require("../middleware/auth.middleware");
const { statusReport } = require("../controllers/report.controller");
router.get("/", requireArzt, statusReport);
module.exports = router;

View File

@ -1,25 +1,25 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireLogin, requireArzt } = require("../middleware/auth.middleware"); const { requireLogin, requireArzt } = require("../middleware/auth.middleware");
const { const {
listServices, listServices,
showCreateService, showCreateService,
createService, createService,
updateServicePrice, updateServicePrice,
toggleService, toggleService,
listOpenServices, listOpenServices,
showServiceLogs, showServiceLogs,
listServicesAdmin, listServicesAdmin,
} = require("../controllers/service.controller"); } = require("../controllers/service.controller");
router.get("/", requireLogin, listServicesAdmin); router.get("/", requireLogin, listServicesAdmin);
router.get("/", requireArzt, listServices); router.get("/", requireArzt, listServices);
router.get("/create", requireArzt, showCreateService); router.get("/create", requireArzt, showCreateService);
router.post("/create", requireArzt, createService); router.post("/create", requireArzt, createService);
router.post("/:id/update-price", requireArzt, updateServicePrice); router.post("/:id/update-price", requireArzt, updateServicePrice);
router.post("/:id/toggle", requireArzt, toggleService); router.post("/:id/toggle", requireArzt, toggleService);
router.get("/open", requireLogin, listOpenServices); router.get("/open", requireLogin, listOpenServices);
router.get("/logs", requireArzt, showServiceLogs); router.get("/logs", requireArzt, showServiceLogs);
module.exports = router; module.exports = router;

139
routes/setup.routes.js Normal file
View File

@ -0,0 +1,139 @@
const express = require("express");
const router = express.Router();
const mysql = require("mysql2/promise");
// ✅ nutzt deinen bestehenden config-manager (NICHT utils/config!)
const { configExists, saveConfig } = require("../config-manager");
// ✅ DB + Session Reset (wie in deiner app.js)
const db = require("../db");
const { resetSessionStore } = require("../config/session");
/**
* Setup darf nur laufen, wenn config.enc NICHT existiert
* (sonst könnte jeder die DB später überschreiben)
*/
function blockIfInstalled(req, res, next) {
if (configExists()) {
return res.redirect("/");
}
next();
}
/**
* Setup Form anzeigen
*/
router.get("/", blockIfInstalled, (req, res) => {
return res.render("setup/index", {
title: "Erstinstallation",
defaults: {
host: "127.0.0.1",
port: 3306,
user: "",
password: "",
name: "",
},
});
});
/**
* Verbindung testen (AJAX)
*/
router.post("/test", blockIfInstalled, async (req, res) => {
try {
const { host, port, user, password, name } = req.body;
if (!host || !user || !name) {
return res.status(400).json({
ok: false,
message: "Bitte Host, Benutzer und Datenbankname ausfüllen.",
});
}
const connection = await mysql.createConnection({
host,
port: Number(port || 3306),
user,
password,
database: name,
connectTimeout: 5000,
});
await connection.query("SELECT 1");
await connection.end();
return res.json({ ok: true, message: "✅ Verbindung erfolgreich!" });
} catch (err) {
return res.status(500).json({
ok: false,
message: "❌ Verbindung fehlgeschlagen: " + err.message,
});
}
});
/**
* Setup speichern (DB Daten in config.enc)
*/
router.post("/", blockIfInstalled, async (req, res) => {
try {
const { host, port, user, password, name } = req.body;
if (!host || !user || !name) {
req.session.flash = req.session.flash || [];
req.session.flash.push({
type: "danger",
message: "❌ Bitte Host, Benutzer und Datenbankname ausfüllen.",
});
return res.redirect("/setup");
}
// ✅ Verbindung testen bevor speichern
const connection = await mysql.createConnection({
host,
port: Number(port || 3306),
user,
password,
database: name,
connectTimeout: 5000,
});
await connection.query("SELECT 1");
await connection.end();
// ✅ speichern
saveConfig({
db: {
host,
port: Number(port || 3306),
user,
password,
name,
},
});
// ✅ DB Pool neu starten (damit neue config sofort aktiv ist)
if (typeof db.resetPool === "function") {
db.resetPool();
}
// ✅ Session Store neu starten
resetSessionStore();
req.session.flash = req.session.flash || [];
req.session.flash.push({
type: "success",
message: "✅ Setup abgeschlossen. Du kannst dich jetzt einloggen.",
});
return res.redirect("/login");
} catch (err) {
req.session.flash = req.session.flash || [];
req.session.flash.push({
type: "danger",
message: "❌ Setup fehlgeschlagen: " + err.message,
});
return res.redirect("/setup");
}
});
module.exports = router;

View File

@ -1,12 +1,12 @@
const express = require("express"); const express = require("express");
const router = express.Router(); const router = express.Router();
const { requireLogin } = require("../middleware/auth.middleware"); const { requireLogin } = require("../middleware/auth.middleware");
const { const {
showWaitingRoom, showWaitingRoom,
movePatientToWaitingRoom movePatientToWaitingRoom
} = require("../controllers/patient.controller"); } = require("../controllers/patient.controller");
router.get("/waiting-room", requireLogin, showWaitingRoom); router.get("/waiting-room", requireLogin, showWaitingRoom);
router.post( "/patients/:id/waiting-room", requireLogin, movePatientToWaitingRoom); router.post( "/patients/:id/waiting-room", requireLogin, movePatientToWaitingRoom);
module.exports = router; module.exports = router;

View File

@ -1,93 +1,93 @@
const bcrypt = require("bcrypt"); const bcrypt = require("bcrypt");
async function createUser( async function createUser(
db, db,
title, title,
first_name, first_name,
last_name, last_name,
username, username,
password, password,
role, role,
fachrichtung, fachrichtung,
arztnummer arztnummer
) { ) {
const hash = await bcrypt.hash(password, 10); const hash = await bcrypt.hash(password, 10);
return new Promise((resolve, reject) => { return new Promise((resolve, reject) => {
db.query( db.query(
`INSERT INTO users `INSERT INTO users
(title, first_name, last_name, username, password, role, fachrichtung, arztnummer, active) (title, first_name, last_name, username, password, role, fachrichtung, arztnummer, active)
VALUES (?, ?, ?, ?, ?, ?, ?, ?, 1)`, VALUES (?, ?, ?, ?, ?, ?, ?, ?, 1)`,
[ [
title, title,
first_name, first_name,
last_name, last_name,
username, username,
hash, hash,
role, role,
fachrichtung, fachrichtung,
arztnummer, arztnummer,
], ],
(err) => { (err) => {
if (err) { if (err) {
if (err.code === "ER_DUP_ENTRY") { if (err.code === "ER_DUP_ENTRY") {
return reject("Benutzername existiert bereits"); return reject("Benutzername existiert bereits");
} }
return reject("Datenbankfehler"); return reject("Datenbankfehler");
} }
resolve(); resolve();
} }
); );
}); });
} }
async function getAllUsers(db, search = null) { async function getAllUsers(db, search = null) {
let sql = ` let sql = `
SELECT * SELECT *
FROM users FROM users
WHERE 1=1 WHERE 1=1
`; `;
const params = []; const params = [];
if (search) { if (search) {
sql += ` sql += `
AND ( AND (
first_name LIKE ? first_name LIKE ?
OR last_name LIKE ? OR last_name LIKE ?
OR username LIKE ? OR username LIKE ?
) )
`; `;
const q = `%${search}%`; const q = `%${search}%`;
params.push(q, q, q); params.push(q, q, q);
} }
sql += " ORDER BY last_name, first_name"; sql += " ORDER BY last_name, first_name";
const [rows] = await db.promise().query(sql, params); const [rows] = await db.promise().query(sql, params);
return rows; return rows;
} }
async function updateUserById(db, userId, data) { async function updateUserById(db, userId, data) {
const { title, first_name, last_name, username, role } = data; const { title, first_name, last_name, username, role } = data;
const [result] = await db.promise().query( const [result] = await db.promise().query(
` `
UPDATE users UPDATE users
SET title = ?, SET title = ?,
first_name = ?, first_name = ?,
last_name = ?, last_name = ?,
username = ?, username = ?,
role = ? role = ?
WHERE id = ? WHERE id = ?
`, `,
[title, first_name, last_name, username, role, userId] [title, first_name, last_name, username, role, userId]
); );
return result; return result;
} }
module.exports = { module.exports = {
createUser, createUser,
getAllUsers, getAllUsers,
updateUserById, updateUserById,
}; };

View File

@ -1,50 +1,53 @@
const bcrypt = require("bcrypt"); const bcrypt = require("bcrypt");
async function loginUser(db, username, password, lockTimeMinutes) { async function loginUser(db, username, password, lockTimeMinutes) {
return new Promise((resolve, reject) => { return new Promise((resolve, reject) => {
db.query( db.query(
"SELECT * FROM users WHERE username = ?", "SELECT * FROM users WHERE username = ?",
[username], [username],
async (err, results) => { async (err, results) => {
if (err || results.length === 0) { if (err || results.length === 0) {
return reject("Login fehlgeschlagen"); return reject("Login fehlgeschlagen");
} }
const user = results[0]; const user = results[0];
const now = new Date(); const now = new Date();
if (user.active === 0) { if (user.active === 0) {
return reject("Account deaktiviert"); return reject("Account deaktiviert");
} }
if (user.lock_until && new Date(user.lock_until) > now) { if (user.lock_until && new Date(user.lock_until) > now) {
return reject(`Account gesperrt bis ${user.lock_until}`); return reject(`Account gesperrt bis ${user.lock_until}`);
} }
const match = await bcrypt.compare(password, user.password); const match = await bcrypt.compare(password, user.password);
if (!match) { if (!match) {
let sql = "failed_attempts = failed_attempts + 1"; let sql = "failed_attempts = failed_attempts + 1";
if (user.failed_attempts + 1 >= 3) { if (user.failed_attempts + 1 >= 3) {
sql += `, lock_until = DATE_ADD(NOW(), INTERVAL ${lockTimeMinutes} MINUTE)`; sql += `, lock_until = DATE_ADD(NOW(), INTERVAL ${lockTimeMinutes} MINUTE)`;
} }
db.query(`UPDATE users SET ${sql} WHERE id = ?`, [user.id]); db.query(`UPDATE users SET ${sql} WHERE id = ?`, [user.id]);
return reject("Falsches Passwort"); return reject("Falsches Passwort");
} }
db.query( db.query(
"UPDATE users SET failed_attempts = 0, lock_until = NULL WHERE id = ?", "UPDATE users SET failed_attempts = 0, lock_until = NULL WHERE id = ?",
[user.id] [user.id]
); );
resolve({ resolve({
id: user.id, id: user.id,
username: user.username, username: user.username,
role: user.role role: user.role,
}); title: user.title,
} firstname: user.first_name,
); lastname: user.last_name
}); });
} }
);
module.exports = { loginUser }; });
}
module.exports = { loginUser };

View File

@ -1,21 +1,21 @@
function getWaitingPatients(db) { function getWaitingPatients(db) {
return new Promise((resolve, reject) => { return new Promise((resolve, reject) => {
db.query( db.query(
` `
SELECT id, firstname, lastname, birthdate SELECT id, firstname, lastname, birthdate
FROM patients FROM patients
WHERE waiting_room = 1 WHERE waiting_room = 1
AND active = 1 AND active = 1
ORDER BY updated_at ASC ORDER BY updated_at ASC
`, `,
(err, rows) => { (err, rows) => {
if (err) return reject(err); if (err) return reject(err);
resolve(rows); resolve(rows);
} }
); );
}); });
} }
module.exports = { module.exports = {
getWaitingPatients getWaitingPatients
}; };

8
ssh_fuer_db_Server Normal file
View File

@ -0,0 +1,8 @@
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABDgIWJidh
WoA1VkDl2ScVZmAAAAGAAAAAEAAAAzAAAAC3NzaC1lZDI1NTE5AAAAIM0AYnTTnboA6hm+
zQcoG121zH1s0Jv2eOAuk+BS1UbfAAAAoJyvcKBc26mTti/T2iAbdEATM15fgtMs9Nlsi4
itZSVPfQ7OdYY2QMQpaiw0whrcQIdWlxUrbcYpmwPj7DATYUP00szFN2KbdRdsarfPqHFQ
zi8P2p9bj7/naRyLIENsfTj8JERxItd4xHvwL01keBmTty2hnprXcZHw4SkyIOIZyigTgS
7gkivG/j9jIOn4g0p0J1eaHdFNvJScpIs19SI=
-----END OPENSSH PRIVATE KEY-----

1
ssh_fuer_db_Server.pub Normal file
View File

@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIM0AYnTTnboA6hm+zQcoG121zH1s0Jv2eOAuk+BS1Ubf cay@Cay-Workstation-VM

View File

@ -1,17 +1,17 @@
const { loginUser } = require("../services/auth.service"); const { loginUser } = require("../services/auth.service");
test("loginUser wirft Fehler bei falschem Passwort", async () => { test("loginUser wirft Fehler bei falschem Passwort", async () => {
const fakeDb = { const fakeDb = {
query: (_, __, cb) => cb(null, [{ query: (_, __, cb) => cb(null, [{
id: 1, id: 1,
username: "test", username: "test",
password: "$2b$10$invalid", password: "$2b$10$invalid",
active: 1, active: 1,
failed_attempts: 0 failed_attempts: 0
}]) }])
}; };
await expect( await expect(
loginUser(fakeDb, "test", "wrong", 5) loginUser(fakeDb, "test", "wrong", 5)
).rejects.toBeDefined(); ).rejects.toBeDefined();
}); });

52
utils/config.js Normal file
View File

@ -0,0 +1,52 @@
const fs = require("fs");
const path = require("path");
const crypto = require("crypto");
const CONFIG_PATH = path.join(__dirname, "..", "config.enc");
function getKey() {
const raw = process.env.CONFIG_KEY;
if (!raw) {
throw new Error("CONFIG_KEY fehlt in .env");
}
return crypto.createHash("sha256").update(raw).digest(); // 32 bytes
}
function encrypt(obj) {
const iv = crypto.randomBytes(12);
const key = getKey();
const cipher = crypto.createCipheriv("aes-256-gcm", key, iv);
const data = Buffer.from(JSON.stringify(obj), "utf8");
const enc = Buffer.concat([cipher.update(data), cipher.final()]);
const tag = cipher.getAuthTag();
// [iv(12)] + [tag(16)] + [encData]
return Buffer.concat([iv, tag, enc]);
}
function decrypt(buf) {
const iv = buf.subarray(0, 12);
const tag = buf.subarray(12, 28);
const enc = buf.subarray(28);
const key = getKey();
const decipher = crypto.createDecipheriv("aes-256-gcm", key, iv);
decipher.setAuthTag(tag);
const data = Buffer.concat([decipher.update(enc), decipher.final()]);
return JSON.parse(data.toString("utf8"));
}
function loadConfig() {
if (!fs.existsSync(CONFIG_PATH)) return null;
const buf = fs.readFileSync(CONFIG_PATH);
return decrypt(buf);
}
function saveConfig(cfg) {
const buf = encrypt(cfg);
fs.writeFileSync(CONFIG_PATH, buf);
}
module.exports = { loadConfig, saveConfig, CONFIG_PATH };

70
utils/creditPdf.js Normal file
View File

@ -0,0 +1,70 @@
const fs = require("fs");
const path = require("path");
const { PDFDocument, StandardFonts, rgb } = require("pdf-lib");
exports.createCreditPdf = async ({
creditId,
originalInvoice,
creditAmount,
patient,
}) => {
const pdfDoc = await PDFDocument.create();
const page = pdfDoc.addPage([595, 842]); // A4
const font = await pdfDoc.embedFont(StandardFonts.Helvetica);
const bold = await pdfDoc.embedFont(StandardFonts.HelveticaBold);
let y = 800;
const draw = (text, size = 12, boldFont = false) => {
page.drawText(text, {
x: 50,
y,
size,
font: boldFont ? bold : font,
color: rgb(0, 0, 0),
});
y -= size + 6;
};
draw("GUTSCHRIFT", 20, true);
y -= 20;
draw(`Gutschrift-Nr.: ${creditId}`, 12, true);
draw(`Bezieht sich auf Rechnung Nr.: ${originalInvoice.id}`);
y -= 10;
draw(`Patient: ${patient.firstname} ${patient.lastname}`);
draw(`Rechnungsdatum: ${originalInvoice.invoice_date_formatted}`);
y -= 20;
draw("Gutschriftbetrag:", 12, true);
draw(`${creditAmount.toFixed(2)}`, 14, true);
// Wasserzeichen
page.drawText("GUTSCHRIFT", {
x: 150,
y: 400,
size: 80,
rotate: { type: "degrees", angle: -30 },
color: rgb(0.8, 0, 0),
opacity: 0.2,
});
const pdfBytes = await pdfDoc.save();
const dir = path.join(
__dirname,
"..",
"public",
"invoices",
new Date().getFullYear().toString(),
);
if (!fs.existsSync(dir)) fs.mkdirSync(dir, { recursive: true });
const filePath = `/invoices/${new Date().getFullYear()}/credit-${creditId}.pdf`;
fs.writeFileSync(path.join(__dirname, "..", "public", filePath), pdfBytes);
return filePath;
};

View File

@ -1,25 +1,25 @@
module.exports = async function generateInvoiceNumber(db) { module.exports = async function generateInvoiceNumber(db) {
const year = new Date().getFullYear(); const year = new Date().getFullYear();
const [rows] = await db.promise().query( const [rows] = await db.promise().query(
"SELECT counter FROM invoice_counters WHERE year = ?", "SELECT counter FROM invoice_counters WHERE year = ?",
[year] [year]
); );
let counter = 1; let counter = 1;
if (rows.length === 0) { if (rows.length === 0) {
await db.promise().query( await db.promise().query(
"INSERT INTO invoice_counters (year, counter) VALUES (?, 1)", "INSERT INTO invoice_counters (year, counter) VALUES (?, 1)",
[year] [year]
); );
} else { } else {
counter = rows[0].counter + 1; counter = rows[0].counter + 1;
await db.promise().query( await db.promise().query(
"UPDATE invoice_counters SET counter = ? WHERE year = ?", "UPDATE invoice_counters SET counter = ? WHERE year = ?",
[counter, year] [counter, year]
); );
} }
return `R-${year}-${String(counter).padStart(5, "0")}`; return `R-${year}-${String(counter).padStart(5, "0")}`;
}; };

34
utils/pdfWatermark.js Normal file
View File

@ -0,0 +1,34 @@
const fs = require("fs");
const { PDFDocument, rgb, degrees } = require("pdf-lib");
exports.addWatermark = async (filePath, text, color) => {
try {
const existingPdfBytes = fs.readFileSync(filePath);
const pdfDoc = await PDFDocument.load(existingPdfBytes);
const pages = pdfDoc.getPages();
pages.forEach((page) => {
const { width, height } = page.getSize();
page.drawText(text, {
x: width / 4,
y: height / 2,
size: 80,
rotate: degrees(-30),
color,
opacity: 0.25,
});
});
const pdfBytes = await pdfDoc.save();
fs.writeFileSync(filePath, pdfBytes);
} catch (err) {
console.error("❌ PDF Watermark Fehler:", err);
}
};

View File

@ -1,233 +1,213 @@
<!DOCTYPE html> <!-- ✅ Header -->
<html lang="de"> <%- include("../partials/page-header", {
<head> user,
<meta charset="UTF-8" /> title: t.adminSidebar.invocieoverview,
<title>Rechnungsübersicht</title> subtitle: "",
<meta name="viewport" content="width=device-width, initial-scale=1" /> showUserName: true
}) %>
<link rel="stylesheet" href="/css/bootstrap.min.css" />
<link rel="stylesheet" href="/bootstrap-icons/bootstrap-icons.min.css" /> <div class="content p-4">
</head>
<!-- FILTER: JAHR VON / BIS -->
<body class="bg-light"> <div class="container-fluid mt-2">
<!-- =========================
NAVBAR <form method="get" class="row g-2 mb-4">
========================== --> <div class="col-auto">
<nav class="navbar navbar-dark bg-dark position-relative px-3"> <input
<div type="number"
class="position-absolute top-50 start-50 translate-middle d-flex align-items-center gap-2 text-white" name="fromYear"
> class="form-control"
<i class="bi bi-calculator fs-4"></i> placeholder="Von Jahr"
<span class="fw-semibold fs-5">Rechnungsübersicht</span> value="<%= fromYear %>"
</div> />
</div>
<!-- 🔵 RECHTS: DASHBOARD -->
<div class="ms-auto"> <div class="col-auto">
<a href="/dashboard" class="btn btn-outline-primary btn-sm"> <input
⬅️ Dashboard type="number"
</a> name="toYear"
</div> class="form-control"
</nav> placeholder="Bis Jahr"
value="<%= toYear %>"
<!-- ========================= />
FILTER: JAHR VON / BIS </div>
========================== -->
<div class="container-fluid mt-4"> <div class="col-auto">
<form method="get" class="row g-2 mb-4"> <button class="btn btn-outline-secondary"><%= t.global.filter %></button>
<div class="col-auto"> </div>
<input </form>
type="number"
name="fromYear" <!-- GRID 4 SPALTEN -->
class="form-control" <div class="row g-3">
placeholder="Von Jahr"
value="<%= fromYear %>" <!-- JAHRESUMSATZ -->
/> <div class="col-xl-3 col-lg-6">
</div> <div class="card h-100">
<div class="card-header fw-semibold"><%= t.global.yearcash%></div>
<div class="col-auto"> <div class="card-body p-0">
<input <table class="table table-sm table-striped mb-0">
type="number" <thead>
name="toYear" <tr>
class="form-control" <th><%= t.global.year%></th>
placeholder="Bis Jahr" <th class="text-end">€</th>
value="<%= toYear %>" </tr>
/> </thead>
</div> <tbody>
<% if (!yearly || yearly.length === 0) { %>
<div class="col-auto"> <tr>
<button class="btn btn-outline-secondary">Filtern</button> <td colspan="2" class="text-center text-muted">
</div> <%= t.global.nodata%>
</form> </td>
</tr>
<!-- ========================= <% } %>
GRID 4 SPALTEN
========================== --> <% (yearly || []).forEach(y => { %>
<div class="row g-3"> <tr>
<!-- ========================= <td><%= y.year %></td>
JAHRESUMSATZ <td class="text-end fw-semibold">
========================== --> <%= Number(y.total).toFixed(2) %>
<div class="col-xl-3 col-lg-6"> </td>
<div class="card h-100"> </tr>
<div class="card-header fw-semibold">Jahresumsatz</div> <% }) %>
<div class="card-body p-0"> </tbody>
<table class="table table-sm table-striped mb-0"> </table>
<thead> </div>
<tr> </div>
<th>Jahr</th> </div>
<th class="text-end">€</th>
</tr> <!-- QUARTALSUMSATZ -->
</thead> <div class="col-xl-3 col-lg-6">
<tbody> <div class="card h-100">
<% if (yearly.length === 0) { %> <div class="card-header fw-semibold"><%= t.global.quartalcash%></div>
<tr> <div class="card-body p-0">
<td colspan="2" class="text-center text-muted"> <table class="table table-sm table-striped mb-0">
Keine Daten <thead>
</td> <tr>
</tr> <th><%= t.global.year%></th>
<% } %> <% yearly.forEach(y => { %> <th>Q</th>
<tr> <th class="text-end">€</th>
<td><%= y.year %></td> </tr>
<td class="text-end fw-semibold"> </thead>
<%= Number(y.total).toFixed(2) %> <tbody>
</td> <% if (!quarterly || quarterly.length === 0) { %>
</tr> <tr>
<% }) %> <td colspan="3" class="text-center text-muted">
</tbody> <%= t.global.nodata%>
</table> </td>
</div> </tr>
</div> <% } %>
</div>
<% (quarterly || []).forEach(q => { %>
<!-- ========================= <tr>
QUARTALSUMSATZ <td><%= q.year %></td>
========================== --> <td>Q<%= q.quarter %></td>
<div class="col-xl-3 col-lg-6"> <td class="text-end fw-semibold">
<div class="card h-100"> <%= Number(q.total).toFixed(2) %>
<div class="card-header fw-semibold">Quartalsumsatz</div> </td>
<div class="card-body p-0"> </tr>
<table class="table table-sm table-striped mb-0"> <% }) %>
<thead> </tbody>
<tr> </table>
<th>Jahr</th> </div>
<th>Q</th> </div>
<th class="text-end">€</th> </div>
</tr>
</thead> <!-- MONATSUMSATZ -->
<tbody> <div class="col-xl-3 col-lg-6">
<% if (quarterly.length === 0) { %> <div class="card h-100">
<tr> <div class="card-header fw-semibold"><%= t.global.monthcash%></div>
<td colspan="3" class="text-center text-muted"> <div class="card-body p-0">
Keine Daten <table class="table table-sm table-striped mb-0">
</td> <thead>
</tr> <tr>
<% } %> <% quarterly.forEach(q => { %> <th><%= t.global.month%></th>
<tr> <th class="text-end">€</th>
<td><%= q.year %></td> </tr>
<td>Q<%= q.quarter %></td> </thead>
<td class="text-end fw-semibold"> <tbody>
<%= Number(q.total).toFixed(2) %> <% if (!monthly || monthly.length === 0) { %>
</td> <tr>
</tr> <td colspan="2" class="text-center text-muted">
<% }) %> <%= t.global.nodata%>
</tbody> </td>
</table> </tr>
</div> <% } %>
</div>
</div> <% (monthly || []).forEach(m => { %>
<tr>
<!-- ========================= <td><%= m.month %></td>
MONATSUMSATZ <td class="text-end fw-semibold">
========================== --> <%= Number(m.total).toFixed(2) %>
<div class="col-xl-3 col-lg-6"> </td>
<div class="card h-100"> </tr>
<div class="card-header fw-semibold">Monatsumsatz</div> <% }) %>
<div class="card-body p-0"> </tbody>
<table class="table table-sm table-striped mb-0"> </table>
<thead> </div>
<tr> </div>
<th>Monat</th> </div>
<th class="text-end">€</th>
</tr> <!-- UMSATZ PRO PATIENT -->
</thead> <div class="col-xl-3 col-lg-6">
<tbody> <div class="card h-100">
<% if (monthly.length === 0) { %> <div class="card-header fw-semibold"><%= t.global.patientcash%></div>
<tr> <div class="card-body p-2">
<td colspan="2" class="text-center text-muted">
Keine Daten <!-- Suche -->
</td> <form method="get" class="mb-2 d-flex gap-2">
</tr> <input type="hidden" name="fromYear" value="<%= fromYear %>" />
<% } %> <% monthly.forEach(m => { %> <input type="hidden" name="toYear" value="<%= toYear %>" />
<tr>
<td><%= m.month %></td> <input
<td class="text-end fw-semibold"> type="text"
<%= Number(m.total).toFixed(2) %> name="q"
</td> value="<%= search %>"
</tr> class="form-control form-control-sm"
<% }) %> placeholder="Patient suchen..."
</tbody> />
</table>
</div> <button class="btn btn-sm btn-outline-primary"><%= t.global.search%></button>
</div>
</div> <a
href="/admin/invoices?fromYear=<%= fromYear %>&toYear=<%= toYear %>"
<!-- ========================= class="btn btn-sm btn-outline-secondary"
UMSATZ PRO PATIENT >
========================== --> <%= t.global.reset%>
<div class="col-xl-3 col-lg-6"> </a>
<div class="card h-100"> </form>
<div class="card-header fw-semibold">Umsatz pro Patient</div>
<div class="card-body p-2"> <table class="table table-sm table-striped mb-0">
<!-- 🔍 Suche --> <thead>
<form method="get" class="mb-2 d-flex gap-2"> <tr>
<input type="hidden" name="fromYear" value="<%= fromYear %>" /> <th><%= t.global.patient%></th>
<input type="hidden" name="toYear" value="<%= toYear %>" /> <th class="text-end">€</th>
</tr>
<input </thead>
type="text" <tbody>
name="q" <% if (!patients || patients.length === 0) { %>
value="<%= search %>" <tr>
class="form-control form-control-sm" <td colspan="2" class="text-center text-muted">
placeholder="Patient suchen..." <%= t.global.nodata%>
/> </td>
</tr>
<button class="btn btn-sm btn-outline-primary">Suchen</button> <% } %>
<a <% (patients || []).forEach(p => { %>
href="/admin/invoices?fromYear=<%= fromYear %>&toYear=<%= toYear %>" <tr>
class="btn btn-sm btn-outline-secondary" <td><%= p.patient %></td>
> <td class="text-end fw-semibold">
Reset <%= Number(p.total).toFixed(2) %>
</a> </td>
</form> </tr>
<% }) %>
<table class="table table-sm table-striped mb-0"> </tbody>
<thead> </table>
<tr>
<th>Patient</th> </div>
<th class="text-end">€</th> </div>
</tr> </div>
</thead>
<tbody> </div>
<% if (patients.length === 0) { %> </div>
<tr>
<td colspan="2" class="text-center text-muted"> </div>
Keine Daten
</td>
</tr>
<% } %> <% patients.forEach(p => { %>
<tr>
<td><%= p.patient %></td>
<td class="text-end fw-semibold">
<%= Number(p.total).toFixed(2) %>
</td>
</tr>
<% }) %>
</tbody>
</table>
</div>
</div>
</div>
</div>
</div>
</body>
</html>

View File

@ -1,132 +1,196 @@
<!DOCTYPE html> <%- include("../partials/page-header", {
<html lang="de"> user,
<head> title,
<meta charset="UTF-8"> subtitle: "",
<title>Firmendaten</title> showUserName: true
<link rel="stylesheet" href="/css/bootstrap.min.css"> }) %>
</head>
<body class="bg-light"> <div class="content p-4">
<div class="container mt-4"> <%- include("../partials/flash") %>
<h3 class="mb-4">🏢 Firmendaten</h3>
<div class="container-fluid">
<form method="POST" action="/admin/company-settings" enctype="multipart/form-data">
<div class="card shadow-sm">
<div class="row g-3"> <div class="card-body">
<div class="col-md-6"> <h5 class="mb-4">
<label class="form-label">Firmenname</label> <i class="bi bi-building"></i>
<input class="form-control" name="company_name" <%= title %>
value="<%= company.company_name || '' %>" required> </h5>
</div>
<form
<div class="col-md-6"> method="POST"
<label class="form-label">Rechtsform</label> action="/admin/company-settings"
<input class="form-control" name="company_legal_form" enctype="multipart/form-data"
value="<%= company.company_legal_form || '' %>"> >
</div>
<div class="row g-3">
<div class="col-md-6">
<label class="form-label">Inhaber / Geschäftsführer</label> <div class="col-md-6">
<input class="form-control" name="company_owner" <label class="form-label">Firmenname</label>
value="<%= company.company_owner || '' %>"> <input
</div> class="form-control"
name="company_name"
<div class="col-md-6"> value="<%= settings.company_name || '' %>"
<label class="form-label">E-Mail</label> required
<input class="form-control" name="email" >
value="<%= company.email || '' %>"> </div>
</div>
<div class="col-md-6">
<div class="col-md-8"> <label class="form-label">Rechtsform</label>
<label class="form-label">Straße</label> <input
<input class="form-control" name="street" class="form-control"
value="<%= company.street || '' %>"> name="company_legal_form"
</div> value="<%= settings.company_legal_form || '' %>"
>
<div class="col-md-4"> </div>
<label class="form-label">Hausnummer</label>
<input class="form-control" name="house_number" <div class="col-md-6">
value="<%= company.house_number || '' %>"> <label class="form-label">Inhaber / Geschäftsführer</label>
</div> <input
class="form-control"
<div class="col-md-4"> name="company_owner"
<label class="form-label">PLZ</label> value="<%= settings.company_owner || '' %>"
<input class="form-control" name="postal_code" >
value="<%= company.postal_code || '' %>"> </div>
</div>
<div class="col-md-6">
<div class="col-md-8"> <label class="form-label">E-Mail</label>
<label class="form-label">Ort</label> <input
<input class="form-control" name="city" class="form-control"
value="<%= company.city || '' %>"> name="email"
</div> value="<%= settings.email || '' %>"
>
<div class="col-md-6"> </div>
<label class="form-label">Land</label>
<input class="form-control" name="country" <div class="col-md-8">
value="<%= company.country || 'Deutschland' %>"> <label class="form-label">Straße</label>
</div> <input
class="form-control"
<div class="col-md-6"> name="street"
<label class="form-label">USt-ID / Steuernummer</label> value="<%= settings.street || '' %>"
<input class="form-control" name="vat_id" >
value="<%= company.vat_id || '' %>"> </div>
</div>
<div class="col-md-4">
<div class="col-md-6"> <label class="form-label">Hausnummer</label>
<label class="form-label">Bank</label> <input
<input class="form-control" name="bank_name" class="form-control"
value="<%= company.bank_name || '' %>"> name="house_number"
</div> value="<%= settings.house_number || '' %>"
>
<div class="col-md-6"> </div>
<label class="form-label">IBAN</label>
<input class="form-control" name="iban" <div class="col-md-4">
value="<%= company.iban || '' %>"> <label class="form-label">PLZ</label>
</div> <input
class="form-control"
<div class="col-md-6"> name="postal_code"
<label class="form-label">BIC</label> value="<%= settings.postal_code || '' %>"
<input class="form-control" name="bic" >
value="<%= company.bic || '' %>"> </div>
</div>
<div class="col-md-8">
<div class="col-12"> <label class="form-label">Ort</label>
<label class="form-label">Rechnungs-Footer</label> <input
<textarea class="form-control" rows="3" class="form-control"
name="invoice_footer_text"><%= company.invoice_footer_text || '' %></textarea> name="city"
</div> value="<%= settings.city || '' %>"
>
<div class="col-12"> </div>
<label class="form-label">Firmenlogo</label>
<input <div class="col-md-6">
type="file" <label class="form-label">Land</label>
name="logo" <input
class="form-control" class="form-control"
accept="image/png, image/jpeg" name="country"
> value="<%= settings.country || 'Deutschland' %>"
>
<% if (company.invoice_logo_path) { %> </div>
<div class="mt-2">
<small class="text-muted">Aktuelles Logo:</small><br> <div class="col-md-6">
<img <label class="form-label">USt-ID / Steuernummer</label>
src="<%= company.invoice_logo_path %>" <input
style="max-height:80px; border:1px solid #ccc; padding:4px;" class="form-control"
> name="vat_id"
</div> value="<%= settings.vat_id || '' %>"
<% } %> >
</div> </div>
</div> <div class="col-md-6">
<label class="form-label">Bank</label>
<div class="mt-4"> <input
<button class="btn btn-primary">💾 Speichern</button> class="form-control"
<a href="/dashboard" class="btn btn-secondary">Zurück</a> name="bank_name"
</div> value="<%= settings.bank_name || '' %>"
>
</form> </div>
</div>
<div class="col-md-6">
</body> <label class="form-label">IBAN</label>
</html> <input
class="form-control"
name="iban"
value="<%= settings.iban || '' %>"
>
</div>
<div class="col-md-6">
<label class="form-label">BIC</label>
<input
class="form-control"
name="bic"
value="<%= settings.bic || '' %>"
>
</div>
<div class="col-12">
<label class="form-label">Rechnungs-Footer</label>
<textarea
class="form-control"
rows="3"
name="invoice_footer_text"
><%= settings.invoice_footer_text || '' %></textarea>
</div>
<div class="col-12">
<label class="form-label">Firmenlogo</label>
<input
type="file"
name="logo"
class="form-control"
accept="image/png, image/jpeg"
>
<% if (settings.invoice_logo_path) { %>
<div class="mt-2">
<small class="text-muted">Aktuelles Logo:</small><br>
<img
src="<%= settings.invoice_logo_path %>"
style="max-height:80px; border:1px solid #ccc; padding:4px;"
>
</div>
<% } %>
</div>
</div>
<div class="mt-4 d-flex gap-2">
<button class="btn btn-primary">
<i class="bi bi-save"></i>
<%= t.global.save %>
</button>
<a href="/dashboard" class="btn btn-secondary">
Zurück
</a>
</div>
</form>
</div>
</div>
</div>
</div>

View File

@ -1,466 +1,263 @@
<!DOCTYPE html> <div class="layout">
<html lang="de">
<head> <!-- ✅ SIDEBAR (wie Dashboard, aber Admin Sidebar) -->
<meta charset="UTF-8" /> <%- include("../partials/admin-sidebar", { user, active: "database", lang }) %>
<title>Datenbankverwaltung</title>
<meta name="viewport" content="width=device-width, initial-scale=1"> <!-- ✅ MAIN -->
<div class="main">
<link rel="stylesheet" href="/css/bootstrap.min.css">
<link rel="stylesheet" href="/css/style.css"> <!-- ✅ HEADER (wie Dashboard) -->
<link rel="stylesheet" href="/bootstrap-icons/bootstrap-icons.min.css"> <%- include("../partials/page-header", {
<script src="/js/bootstrap.bundle.min.js"></script> user,
title: t.adminSidebar.database,
<style> subtitle: "",
body { showUserName: true,
margin: 0; hideDashboardButton: true
background: #f4f6f9; }) %>
font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Ubuntu;
} <div class="content p-4">
.layout { <!-- Flash Messages -->
display: flex; <%- include("../partials/flash") %>
min-height: 100vh;
} <div class="container-fluid p-0">
<div class="row g-3">
/* Sidebar */
.sidebar { <!-- ✅ DB Konfiguration -->
width: 240px; <div class="col-12">
background: #111827; <div class="card shadow mb-3">
color: white; <div class="card-body">
padding: 20px;
display: flex; <h4 class="mb-3">
flex-direction: column; <i class="bi bi-sliders"></i> <%= t.databaseoverview.title%>
} </h4>
.logo { <p class="text-muted mb-4">
font-size: 18px; <%= t.databaseoverview.tittexte%>
font-weight: 700; </p>
margin-bottom: 30px;
display: flex; <!-- ✅ TEST + SPEICHERN -->
align-items: center; <form method="POST" action="/admin/database/test" class="row g-3 mb-3" autocomplete="off">
gap: 10px;
} <div class="col-md-6">
<label class="form-label"><%= t.databaseoverview.host%> / IP</label>
.nav-item { <input
display: flex; type="text"
align-items: center; name="host"
gap: 12px; class="form-control"
padding: 12px 15px; value="<%= (typeof dbConfig !== 'undefined' && dbConfig && dbConfig.host) ? dbConfig.host : '' %>"
border-radius: 8px; autocomplete="off"
color: #cbd5e1; required
text-decoration: none; >
margin-bottom: 6px; </div>
font-size: 14px;
} <div class="col-md-3">
<label class="form-label"><%= t.databaseoverview.port%></label>
.nav-item:hover { <input
background: #1f2937; type="number"
color: white; name="port"
} class="form-control"
value="<%= (typeof dbConfig !== 'undefined' && dbConfig && dbConfig.port) ? dbConfig.port : 3306 %>"
.nav-item.active { autocomplete="off"
background: #2563eb; required
color: white; >
} </div>
.sidebar .spacer { <div class="col-md-3">
flex: 1; <label class="form-label"><%= t.databaseoverview.database%></label>
} <input
type="text"
.nav-item.locked { name="name"
opacity: 0.5; class="form-control"
cursor: not-allowed; value="<%= (typeof dbConfig !== 'undefined' && dbConfig && dbConfig.name) ? dbConfig.name : '' %>"
} autocomplete="off"
.nav-item.locked:hover { required
background: transparent; >
color: #cbd5e1; </div>
}
<div class="col-md-6">
/* Main */ <label class="form-label"><%= t.global.user%></label>
.main { <input
flex: 1; type="text"
padding: 24px; name="user"
overflow: auto; class="form-control"
} value="<%= (typeof dbConfig !== 'undefined' && dbConfig && dbConfig.user) ? dbConfig.user : '' %>"
autocomplete="off"
/* ✅ Systeminfo Tabelle kompakt */ required
.table-systeminfo { >
table-layout: auto; </div>
width: 100%;
font-size: 13px; <div class="col-md-6">
} <label class="form-label"><%= t.databaseoverview.password%></label>
<input
.table-systeminfo th, type="password"
.table-systeminfo td { name="password"
padding: 6px 8px; class="form-control"
} value="<%= (typeof dbConfig !== 'undefined' && dbConfig && dbConfig.password) ? dbConfig.password : '' %>"
autocomplete="off"
.table-systeminfo th:first-child, required
.table-systeminfo td:first-child { >
width: 1%; </div>
white-space: nowrap;
} <div class="col-12 d-flex flex-wrap gap-2">
</style>
</head> <button type="submit" class="btn btn-outline-primary">
<i class="bi bi-plug"></i> <%= t.databaseoverview.connectiontest%>
<body> </button>
<div class="layout"> <button
type="submit"
<!-- ✅ ADMIN SIDEBAR --> class="btn btn-success"
<%- include("../partials/admin-sidebar", { user, active: "database" }) %> formaction="/admin/database"
>
<!-- ✅ MAIN CONTENT --> <i class="bi bi-save"></i> <%= t.global.save%>
<div class="main"> </button>
<nav class="navbar navbar-dark bg-dark position-relative px-3 rounded mb-4"> </div>
<div class="position-absolute top-50 start-50 translate-middle d-flex align-items-center gap-2 text-white"> </form>
<i class="bi bi-hdd-stack fs-4"></i>
<span class="fw-semibold fs-5">Datenbankverwaltung</span> <% if (typeof testResult !== "undefined" && testResult) { %>
</div> <div class="alert <%= testResult.ok ? 'alert-success' : 'alert-danger' %> mb-0">
<%= testResult.message %>
<div class="ms-auto"> </div>
<a href="/dashboard" class="btn btn-outline-light btn-sm">⬅️ Dashboard</a> <% } %>
</div>
</nav> </div>
</div>
<div class="container-fluid"> </div>
<!-- ✅ Flash Messages --> <!-- ✅ System Info -->
<%- include("../partials/flash") %> <div class="col-12">
<div class="card shadow mb-3">
<!-- ✅ Statusanzeige (Verbindung OK / Fehler) --> <div class="card-body">
<% if (testResult) { %>
<div class="alert <%= testResult.ok ? 'alert-success' : 'alert-danger' %>"> <h4 class="mb-3">
<%= testResult.message %> <i class="bi bi-info-circle"></i> <%=t.global.systeminfo%>
</div> </h4>
<% } %>
<% if (typeof systemInfo !== "undefined" && systemInfo && systemInfo.error) { %>
<div class="card shadow">
<div class="card-body"> <div class="alert alert-danger mb-0">
❌ <%=t.global.errordatabase%>
<h4 class="mb-3">Datenbank Tools</h4> <div class="mt-2"><code><%= systemInfo.error %></code></div>
</div>
<div class="alert alert-warning">
<b>Hinweis:</b> Diese Funktionen sind nur für <b>Admins</b> sichtbar und sollten mit Vorsicht benutzt werden. <% } else if (typeof systemInfo !== "undefined" && systemInfo) { %>
</div>
<div class="row g-3">
<!-- ✅ DB Einstellungen --> <div class="col-md-4">
<div class="card border mb-4"> <div class="border rounded p-3 h-100">
<div class="card-body"> <div class="text-muted small">MySQL Version</div>
<div class="fw-bold"><%= systemInfo.version %></div>
<div class="mb-3"> </div>
<h5 class="card-title m-0">🔧 Datenbankverbindung ändern</h5> </div>
</div>
<div class="col-md-4">
<% if (!dbConfig) { %> <div class="border rounded p-3 h-100">
<div class="alert alert-danger"> <div class="text-muted small"><%=t.databaseoverview.tablecount%></div>
❌ Keine Datenbank-Konfiguration gefunden (config.enc fehlt oder ungültig). <div class="fw-bold"><%= systemInfo.tableCount %></div>
</div> </div>
<% } %> </div>
<!-- ✅ Speichern + testen --> <div class="col-md-4">
<form id="dbForm" method="POST" action="/admin/database" class="row g-3"> <div class="border rounded p-3 h-100">
<div class="text-muted small"><%=t.databaseoverview.databasesize%></div>
<div class="col-md-6"> <div class="fw-bold"><%= systemInfo.dbSizeMB %> MB</div>
<label class="form-label">DB Host</label> </div>
<input </div>
type="text" </div>
name="host"
class="form-control db-input" <% if (systemInfo.tables && systemInfo.tables.length > 0) { %>
value="<%= dbConfig?.host || '' %>" <hr>
required
disabled <h6 class="mb-2"><%=t.databaseoverview.tableoverview%></h6>
/>
</div> <div class="table-responsive">
<table class="table table-sm table-bordered table-hover align-middle">
<div class="col-md-6"> <thead class="table-dark">
<label class="form-label">DB Name</label> <tr>
<input <th><%=t.global.table%></th>
type="text" <th class="text-end"><%=t.global.lines%></th>
name="name" <th class="text-end"><%=t.global.size%> (MB)</th>
class="form-control db-input" </tr>
value="<%= dbConfig?.name || '' %>" </thead>
required
disabled <tbody>
/> <% systemInfo.tables.forEach(t => { %>
</div> <tr>
<td><%= t.name %></td>
<div class="col-md-6"> <td class="text-end"><%= t.row_count %></td>
<label class="form-label">DB User</label> <td class="text-end"><%= t.size_mb %></td>
<input </tr>
type="text" <% }) %>
name="user" </tbody>
class="form-control db-input" </table>
value="<%= dbConfig?.user || '' %>" </div>
required <% } %>
disabled
/> <% } else { %>
</div>
<div class="alert alert-warning mb-0">
<div class="col-md-6"> ⚠️ Keine Systeminfos verfügbar (DB ist evtl. nicht konfiguriert oder Verbindung fehlgeschlagen).
<label class="form-label">DB Passwort</label> </div>
<input
type="password" <% } %>
name="password"
class="form-control db-input" </div>
value="<%= dbConfig?.password || '' %>" </div>
required </div>
disabled
/> <!-- ✅ Backup & Restore -->
</div> <div class="col-12">
<div class="card shadow">
<!-- ✅ BUTTON LEISTE --> <div class="card-body">
<div class="col-12 d-flex align-items-center gap-2 flex-wrap">
<h4 class="mb-3">
<!-- 🔒 Bearbeiten --> <i class="bi bi-hdd-stack"></i> Backup & Restore
<button id="toggleEditBtn" type="button" class="btn btn-outline-warning"> </h4>
<i class="bi bi-lock-fill"></i> Bearbeiten
</button> <div class="d-flex flex-wrap gap-3">
<!-- ✅ Speichern --> <!-- ✅ Backup erstellen -->
<button id="saveBtn" class="btn btn-primary" disabled> <form action="/admin/database/backup" method="POST">
✅ Speichern & testen <button type="submit" class="btn btn-primary">
</button> <i class="bi bi-download"></i> Backup erstellen
</button>
<!-- 🔍 Nur testen --> </form>
<button id="testBtn" type="button" class="btn btn-outline-success" disabled>
🔍 Nur testen <!-- ✅ Restore auswählen -->
</button> <form action="/admin/database/restore" method="POST">
<div class="input-group">
<!-- ↩ Zurücksetzen direkt neben "Nur testen" -->
<a href="/admin/database" class="btn btn-outline-secondary ms-2"> <select name="backupFile" class="form-select" required>
Zurücksetzen <option value="">Backup auswählen...</option>
</a>
</div> <% (typeof backupFiles !== "undefined" && backupFiles ? backupFiles : []).forEach(file => { %>
<option value="<%= file %>"><%= file %></option>
<div class="col-12"> <% }) %>
<div class="text-muted small"> </select>
Standardmäßig sind die Felder gesperrt. Erst auf <b>Bearbeiten</b> klicken.
</div> <button type="submit" class="btn btn-warning">
</div> <i class="bi bi-upload"></i> Restore starten
</form> </button>
</div>
<!-- ✅ Hidden Form für Test --> </form>
<form id="testForm" method="POST" action="/admin/database/test"></form>
</div>
</div>
</div> <% if (typeof backupFiles === "undefined" || !backupFiles || backupFiles.length === 0) { %>
<div class="alert alert-secondary mt-3 mb-0">
<!-- ✅ Backup + Restore + Systeminfo --> Noch keine Backups vorhanden.
<div class="row g-3"> </div>
<% } %>
<!-- ✅ Backup -->
<div class="col-md-6"> </div>
<div class="card border"> </div>
<div class="card-body"> </div>
<h5 class="card-title">📦 Backup</h5>
<p class="text-muted small mb-3"> </div>
Erstellt ein SQL Backup der kompletten Datenbank. </div>
</p>
</div>
<form method="POST" action="/admin/database/backup"> </div>
<button class="btn btn-outline-primary"> </div>
Backup erstellen
</button>
</form>
</div>
</div>
</div>
<!-- ✅ Restore -->
<div class="col-md-6">
<div class="card border">
<div class="card-body">
<h5 class="card-title">♻️ Restore</h5>
<p class="text-muted small mb-3">
Wähle ein Backup aus dem Ordner <b>/backups</b> und stelle die Datenbank wieder her.
</p>
<% if (!backupFiles || backupFiles.length === 0) { %>
<div class="alert alert-secondary mb-2">
Keine Backups im Ordner <b>/backups</b> gefunden.
</div>
<% } %>
<form method="POST" action="/admin/database/restore">
<!-- ✅ Scroll Box -->
<div
class="border rounded p-2 mb-2"
style="max-height: 210px; overflow-y: auto; background: #fff;"
>
<% (backupFiles || []).forEach((f, index) => { %>
<label
class="d-flex align-items-center gap-2 p-2 rounded"
style="cursor:pointer;"
>
<input
type="radio"
name="backupFile"
value="<%= f %>"
<%= index === 0 ? "checked" : "" %>
<%= (!backupFiles || backupFiles.length === 0) ? "disabled" : "" %>
/>
<span style="font-size: 14px;"><%= f %></span>
</label>
<% }) %>
</div>
<button
class="btn btn-outline-danger"
onclick="return confirm('⚠️ Achtung! Restore überschreibt Datenbankdaten. Wirklich fortfahren?');"
<%= (!backupFiles || backupFiles.length === 0) ? "disabled" : "" %>
>
Restore starten
</button>
</form>
<div class="text-muted small mt-2">
Es werden die neuesten Backups zuerst angezeigt. Wenn mehr vorhanden sind, kannst du scrollen.
</div>
</div>
</div>
</div>
<!-- ✅ Systeminfo (kompakt wie gewünscht) -->
<div class="col-md-12">
<div class="card border">
<div class="card-body">
<h5 class="card-title">🔍 Systeminfo</h5>
<% if (!systemInfo) { %>
<p class="text-muted small mb-0">Keine Systeminfos verfügbar.</p>
<% } else if (systemInfo.error) { %>
<div class="alert alert-danger">
❌ Systeminfo konnte nicht geladen werden: <%= systemInfo.error %>
</div>
<% } else { %>
<div class="row g-3">
<!-- ✅ LINKS: Quick Infos -->
<div class="col-lg-4">
<div class="border rounded p-3 bg-white h-100">
<div class="mb-3">
<div class="text-muted small">DB Version</div>
<div class="fw-semibold"><%= systemInfo.version %></div>
</div>
<div class="mb-3">
<div class="text-muted small">Tabellen</div>
<div class="fw-semibold"><%= systemInfo.tableCount %></div>
</div>
<div>
<div class="text-muted small">DB Größe</div>
<div class="fw-semibold"><%= systemInfo.dbSizeMB %> MB</div>
</div>
</div>
</div>
<!-- ✅ RECHTS: Tabellenübersicht -->
<div class="col-lg-8">
<div class="border rounded p-3 bg-white h-100">
<div class="text-muted small mb-2">Tabellenübersicht</div>
<div style="max-height: 220px; overflow-y: auto;">
<table class="table table-sm table-bordered align-middle mb-0 table-systeminfo">
<thead class="table-light">
<tr>
<th>Tabellenname</th>
<th style="width: 90px;" class="text-end">Rows</th>
<th style="width: 110px;" class="text-end">MB</th>
</tr>
</thead>
<tbody>
<% systemInfo.tables.forEach(t => { %>
<tr>
<td><%= t.name %></td>
<td class="text-end"><%= t.row_count %></td>
<td class="text-end"><%= t.size_mb %></td>
</tr>
<% }) %>
</tbody>
</table>
</div>
</div>
</div>
</div>
<% } %>
</div>
</div>
</div>
</div> <!-- row g-3 -->
</div>
</div>
</div>
</div>
</div>
<script>
(function () {
const toggleBtn = document.getElementById("toggleEditBtn");
const inputs = document.querySelectorAll(".db-input");
const saveBtn = document.getElementById("saveBtn");
const testBtn = document.getElementById("testBtn");
const testForm = document.getElementById("testForm");
let editMode = false;
function updateUI() {
inputs.forEach((inp) => {
inp.disabled = !editMode;
});
saveBtn.disabled = !editMode;
testBtn.disabled = !editMode;
if (editMode) {
toggleBtn.innerHTML = '<i class="bi bi-unlock-fill"></i> Sperren';
toggleBtn.classList.remove("btn-outline-warning");
toggleBtn.classList.add("btn-outline-success");
} else {
toggleBtn.innerHTML = '<i class="bi bi-lock-fill"></i> Bearbeiten';
toggleBtn.classList.remove("btn-outline-success");
toggleBtn.classList.add("btn-outline-warning");
}
}
toggleBtn.addEventListener("click", () => {
editMode = !editMode;
updateUI();
});
// ✅ „Nur testen“ Button -> hidden form füllen -> submit
testBtn.addEventListener("click", () => {
testForm.querySelectorAll("input[type='hidden']").forEach((x) => x.remove());
inputs.forEach((inp) => {
const hidden = document.createElement("input");
hidden.type = "hidden";
hidden.name = inp.name;
hidden.value = inp.value;
testForm.appendChild(hidden);
});
testForm.submit();
});
updateUI();
})();
</script>
</body>
</html>

View File

@ -1,108 +1,108 @@
<!DOCTYPE html> <!DOCTYPE html>
<html lang="de"> <html lang="de">
<head> <head>
<meta charset="UTF-8" /> <meta charset="UTF-8" />
<title>Benutzer anlegen</title> <title>Benutzer anlegen</title>
<link rel="stylesheet" href="/css/bootstrap.min.css" /> <link rel="stylesheet" href="/css/bootstrap.min.css" />
</head> </head>
<body class="bg-light"> <body class="bg-light">
<div class="container mt-5"> <div class="container mt-5">
<%- include("partials/flash") %> <%- include("partials/flash") %>
<div class="card shadow mx-auto" style="max-width: 500px"> <div class="card shadow mx-auto" style="max-width: 500px">
<div class="card-body"> <div class="card-body">
<h3 class="text-center mb-3">Benutzer anlegen</h3> <h3 class="text-center mb-3">Benutzer anlegen</h3>
<% if (error) { %> <% if (error) { %>
<div class="alert alert-danger"><%= error %></div> <div class="alert alert-danger"><%= error %></div>
<% } %> <% } %>
<form method="POST" action="/admin/create-user"> <form method="POST" action="/admin/create-user">
<!-- VORNAME --> <!-- VORNAME -->
<input <input
class="form-control mb-3" class="form-control mb-3"
name="first_name" name="first_name"
placeholder="Vorname" placeholder="Vorname"
required required
/> />
<!-- NACHNAME --> <!-- NACHNAME -->
<input <input
class="form-control mb-3" class="form-control mb-3"
name="last_name" name="last_name"
placeholder="Nachname" placeholder="Nachname"
required required
/> />
<!-- TITEL --> <!-- TITEL -->
<input <input
class="form-control mb-3" class="form-control mb-3"
name="title" name="title"
placeholder="Titel (z.B. Dr., Prof.)" placeholder="Titel (z.B. Dr., Prof.)"
/> />
<!-- BENUTZERNAME (LOGIN) --> <!-- BENUTZERNAME (LOGIN) -->
<input <input
class="form-control mb-3" class="form-control mb-3"
name="username" name="username"
placeholder="Benutzername (Login)" placeholder="Benutzername (Login)"
required required
/> />
<!-- PASSWORT --> <!-- PASSWORT -->
<input <input
class="form-control mb-3" class="form-control mb-3"
type="password" type="password"
name="password" name="password"
placeholder="Passwort" placeholder="Passwort"
required required
/> />
<!-- ROLLE --> <!-- ROLLE -->
<select <select
class="form-select mb-3" class="form-select mb-3"
name="role" name="role"
id="roleSelect" id="roleSelect"
required required
> >
<option value="">Rolle wählen</option> <option value="">Rolle wählen</option>
<option value="mitarbeiter">Mitarbeiter</option> <option value="mitarbeiter">Mitarbeiter</option>
<option value="arzt">Arzt</option> <option value="arzt">Arzt</option>
</select> </select>
<!-- ARZT-FELDER --> <!-- ARZT-FELDER -->
<div id="arztFields" style="display: none"> <div id="arztFields" style="display: none">
<input <input
class="form-control mb-3" class="form-control mb-3"
name="fachrichtung" name="fachrichtung"
placeholder="Fachrichtung" placeholder="Fachrichtung"
/> />
<input <input
class="form-control mb-3" class="form-control mb-3"
name="arztnummer" name="arztnummer"
placeholder="Arztnummer" placeholder="Arztnummer"
/> />
</div> </div>
<button class="btn btn-primary w-100">Benutzer erstellen</button> <button class="btn btn-primary w-100">Benutzer erstellen</button>
</form> </form>
<div class="text-center mt-3"> <div class="text-center mt-3">
<a href="/dashboard">Zurück</a> <a href="/dashboard">Zurück</a>
</div> </div>
</div> </div>
</div> </div>
</div> </div>
<script> <script>
document document
.getElementById("roleSelect") .getElementById("roleSelect")
.addEventListener("change", function () { .addEventListener("change", function () {
const arztFields = document.getElementById("arztFields"); const arztFields = document.getElementById("arztFields");
arztFields.style.display = this.value === "arzt" ? "block" : "none"; arztFields.style.display = this.value === "arzt" ? "block" : "none";
}); });
</script> </script>
<script src="/js/admin_create_user.js" defer></script> <script src="/js/admin_create_user.js" defer></script>
</body> </body>
</html> </html>

View File

@ -1,58 +1,59 @@
<!DOCTYPE html> <!DOCTYPE html>
<html lang="de"> <html lang="de">
<head> <head>
<meta charset="UTF-8"> <meta charset="UTF-8">
<title>Service-Logs</title> <title>Service-Logs</title>
<link rel="stylesheet" href="/css/bootstrap.min.css"> <link rel="stylesheet" href="/css/bootstrap.min.css">
</head> </head>
<body> <body>
<nav class="navbar navbar-dark bg-dark position-relative px-3"> <nav class="navbar navbar-dark bg-dark position-relative px-3">
<!-- 🟢 ZENTRIERTER TITEL --> <!-- 🟢 ZENTRIERTER TITEL -->
<div class="position-absolute top-50 start-50 translate-middle <div class="position-absolute top-50 start-50 translate-middle
d-flex align-items-center gap-2 text-white"> d-flex align-items-center gap-2 text-white">
<span style="font-size:1.3rem;">📜</span> <span style="font-size:1.3rem;">📜</span>
<span class="fw-semibold fs-5">Service-Änderungsprotokoll</span> <span class="fw-semibold fs-5">Service-Änderungsprotokoll</span>
</div> </div>
<!-- 🔵 RECHTS: DASHBOARD --> <!-- 🔵 RECHTS: DASHBOARD -->
<div class="ms-auto"> <div class="ms-auto">
<a href="/dashboard" class="btn btn-outline-light btn-sm"> <a href="/dashboard" class="btn btn-outline-light btn-sm">
⬅️ Dashboard ⬅️ Dashboard
</a> </a>
</div> </div>
</nav> </nav>
<div class="container mt-4"> <div class="container mt-4">
<table class="table table-sm table-bordered"> <table class="table table-sm table-bordered">
<thead class="table-light"> <thead class="table-light">
<tr> <tr>
<th>Datum</th> <th>Datum</th>
<th>User</th> <th>User</th>
<th>Aktion</th> <th>Aktion</th>
<th>Vorher</th> <th>Vorher</th>
<th>Nachher</th> <th>Nachher</th>
</tr> </tr>
</thead> </thead>
<tbody> <tbody>
<% logs.forEach(l => { %> <% logs.forEach(l => { %>
<tr> <tr>
<td><%= new Date(l.created_at).toLocaleString("de-DE") %></td> <td><%= new Date(l.created_at).toLocaleString("de-DE") %></td>
<td><%= l.username %></td> <td><%= l.username %></td>
<td><%= l.action %></td> <td><%= l.action %></td>
<td><pre><%= l.old_value || "-" %></pre></td> <td><pre><%= l.old_value || "-" %></pre></td>
<td><pre><%= l.new_value || "-" %></pre></td> <td><pre><%= l.new_value || "-" %></pre></td>
</tr> </tr>
<% }) %> <% }) %>
</tbody>
</table> </tbody>
</table>
</div> <br>
</body> </div>
</html> </body>
</html>

View File

@ -1,440 +1,130 @@
<!DOCTYPE html> <div class="layout">
<html lang="de">
<head> <div class="main">
<meta charset="UTF-8" />
<title>User Verwaltung</title> <!-- ✅ HEADER -->
<meta name="viewport" content="width=device-width, initial-scale=1"> <%- include("partials/page-header", {
user,
<link rel="stylesheet" href="/css/bootstrap.min.css"> title: t.adminuseroverview.usermanagement,
<link rel="stylesheet" href="/css/style.css"> subtitle: "",
<link rel="stylesheet" href="/bootstrap-icons/bootstrap-icons.min.css"> showUserName: true
<script src="/js/bootstrap.bundle.min.js"></script> }) %>
<!-- ✅ Inline Edit --> <div class="content">
<script src="/js/services-lock.js"></script>
<%- include("partials/flash") %>
<style>
body { <div class="container-fluid">
margin: 0;
background: #f4f6f9; <div class="card shadow-sm">
font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Ubuntu; <div class="card-body">
}
<div class="d-flex align-items-center justify-content-between mb-3">
.layout { <h4 class="mb-0"><%= t.adminuseroverview.useroverview %></h4>
display: flex;
min-height: 100vh; <a href="/admin/create-user" class="btn btn-primary">
} <i class="bi bi-plus-circle"></i>
<%= t.global.newuser %>
.main { </a>
flex: 1; </div>
padding: 24px;
overflow: auto; <!-- ✅ Tabelle -->
} <div class="table-responsive">
<table class="table table-bordered table-hover table-sm align-middle mb-0">
/* ✅ Header */ <thead>
.page-header { <tr>
display: flex; <th>ID</th>
justify-content: space-between; <th><%= t.global.title %></th>
align-items: center; <th><%= t.global.firstname %></th>
background: #111827; <th><%= t.global.lastname %></th>
color: #fff; <th><%= t.global.username %></th>
border-radius: 12px; <th><%= t.global.role %></th>
padding: 14px 16px; <th class="text-center"><%= t.global.status %></th>
margin-bottom: 18px; <th><%= t.global.action %></th>
} </tr>
</thead>
.page-header .title {
display: flex; <tbody>
align-items: center; <% users.forEach(u => { %>
gap: 10px; <tr class="<%= u.active ? '' : 'table-secondary' %>">
font-size: 18px;
font-weight: 600; <!-- ✅ Update Form -->
} <form method="POST" action="/admin/users/update/<%= u.id %>">
.page-header .title i { <td class="fw-semibold"><%= u.id %></td>
font-size: 20px;
} <td>
<input type="text" name="title" value="<%= u.title || '' %>" class="form-control form-control-sm" disabled />
/* ✅ Tabelle optisch besser */ </td>
.table thead th {
background: #111827 !important; <td>
color: #fff !important; <input type="text" name="first_name" value="<%= u.first_name %>" class="form-control form-control-sm" disabled />
font-weight: 600; </td>
font-size: 13px;
white-space: nowrap; <td>
} <input type="text" name="last_name" value="<%= u.last_name %>" class="form-control form-control-sm" disabled />
</td>
.table td {
vertical-align: middle; <td>
font-size: 13px; <input type="text" name="username" value="<%= u.username %>" class="form-control form-control-sm" disabled />
} </td>
/* ✅ Inline edit Inputs */ <td>
input.form-control { <select name="role" class="form-select form-select-sm" disabled>
box-shadow: none !important; <option value="mitarbeiter" <%= u.role === "mitarbeiter" ? "selected" : "" %>>Mitarbeiter</option>
font-size: 13px; <option value="arzt" <%= u.role === "arzt" ? "selected" : "" %>>Arzt</option>
} <option value="admin" <%= u.role === "admin" ? "selected" : "" %>>Admin</option>
</select>
input.form-control:disabled { </td>
background-color: transparent !important;
border: none !important; <td class="text-center">
padding-left: 0 !important; <% if (u.active === 0) { %>
padding-right: 0 !important; <span class="badge bg-secondary"><%= t.global.inactive %></span>
color: #111827 !important; <% } else if (u.lock_until && new Date(u.lock_until) > new Date()) { %>
} <span class="badge bg-danger"><%= t.global.closed %></span>
<% } else { %>
select.form-select { <span class="badge bg-success"><%= t.global.active %></span>
font-size: 13px; <% } %>
} </td>
select.form-select:disabled { <td class="d-flex gap-2 align-items-center">
background-color: transparent !important;
border: none !important; <!-- Save -->
padding-left: 0 !important; <button class="btn btn-outline-success btn-sm save-btn" disabled>
padding-right: 0 !important; <i class="bi bi-save"></i>
color: #111827 !important; </button>
appearance: none;
-webkit-appearance: none; <!-- Edit -->
-moz-appearance: none; <button type="button" class="btn btn-outline-warning btn-sm lock-btn">
} <i class="bi bi-pencil-square"></i>
</button>
/* ✅ Inaktive User rot */
tr.table-secondary > td { </form>
background-color: #f8d7da !important;
} <!-- Aktiv/Deaktiv -->
<% if (u.id !== currentUser.id) { %>
/* ✅ Icon Buttons */ <form method="POST" action="/admin/users/<%= u.active ? 'deactivate' : 'activate' %>/<%= u.id %>">
.icon-btn { <button class="btn btn-sm <%= u.active ? 'btn-outline-danger' : 'btn-outline-success' %>">
width: 34px; <i class="bi <%= u.active ? 'bi-person-x' : 'bi-person-check' %>"></i>
height: 34px; </button>
display: inline-flex; </form>
align-items: center; <% } else { %>
justify-content: center; <span class="badge bg-light text-dark border">👤 <%= t.global.you %></span>
border-radius: 8px; <% } %>
padding: 0;
} </td>
</tr>
.badge-soft { <% }) %>
font-size: 12px; </tbody>
padding: 6px 10px;
border-radius: 999px; </table>
} </div>
/* ✅ Tabelle soll sich an Inhalt anpassen */ </div>
.table-auto { </div>
table-layout: auto !important;
width: auto !important; </div>
}
</div>
.table-auto th, </div>
.table-auto td { </div>
white-space: nowrap;
}
/* ✅ Inputs sollen nicht zu klein werden */
.table-auto td input,
.table-auto td select {
min-width: 110px;
}
/* Username darf umbrechen wenn extrem lang */
.table-auto td:nth-child(5) {
white-space: normal;
}
/* ✅ Wrapper: sorgt dafür dass Suche & Tabelle exakt gleich breit sind */
.table-wrapper {
width: fit-content;
max-width: 100%;
margin: 0 auto;
}
.toolbar {
width: 100%;
display: flex;
justify-content: space-between;
align-items: center;
gap: 12px;
flex-wrap: wrap;
margin-bottom: 14px;
}
.searchbar {
flex: 1;
display: flex;
gap: 10px;
align-items: center;
min-width: 320px;
}
.searchbar input {
flex: 1;
}
.sidebar {
width: 240px;
background: #111827;
color: white;
padding: 20px;
display: flex;
flex-direction: column;
}
.logo {
font-size: 18px;
font-weight: 700;
margin-bottom: 30px;
display: flex;
align-items: center;
gap: 10px;
}
.nav-item {
display: flex;
align-items: center;
gap: 12px;
padding: 12px 15px;
border-radius: 8px;
color: #cbd5e1;
text-decoration: none;
margin-bottom: 6px;
font-size: 14px;
}
.nav-item:hover {
background: #1f2937;
color: white;
}
.nav-item.active {
background: #2563eb;
color: white;
}
.sidebar .spacer {
flex: 1;
}
.nav-item.locked {
opacity: 0.5;
cursor: not-allowed;
}
.nav-item.locked:hover {
background: transparent;
color: #cbd5e1;
}
</style>
</head>
<body>
<div class="layout">
<!-- ✅ ADMIN SIDEBAR -->
<%- include("partials/admin-sidebar", { active: "users" }) %>
<div class="main">
<!-- ✅ TOP HEADER -->
<div class="page-header">
<div class="title">
<i class="bi bi-shield-lock"></i>
User Verwaltung
</div>
<div>
<a href="/dashboard" class="btn btn-outline-light btn-sm">
⬅️ Dashboard
</a>
</div>
</div>
<div class="container-fluid p-0">
<%- include("partials/flash") %>
<div class="card shadow border-0 rounded-3">
<div class="card-body">
<h4 class="mb-3">Benutzerübersicht</h4>
<!-- ✅ Suche + Tabelle zusammen breit -->
<div class="table-wrapper">
<!-- ✅ Toolbar: Suche links, Button rechts -->
<div class="toolbar">
<form method="GET" action="/admin/users" class="searchbar">
<input
type="text"
name="q"
class="form-control"
placeholder="🔍 Benutzer suchen (Name oder Username)"
value="<%= query?.q || '' %>"
>
<button class="btn btn-outline-primary">
<i class="bi bi-search"></i>
Suchen
</button>
<% if (query?.q) { %>
<a href="/admin/users" class="btn btn-outline-secondary">
Reset
</a>
<% } %>
</form>
<div class="actions">
<a href="/admin/create-user" class="btn btn-primary">
<i class="bi bi-plus-circle"></i>
Neuer Benutzer
</a>
</div>
</div>
<!-- ✅ Tabelle -->
<div class="table-responsive">
<table class="table table-bordered table-hover table-sm align-middle mb-0 table-auto">
<thead>
<tr>
<th style="width: 60px;">ID</th>
<th>Titel</th>
<th>Vorname</th>
<th>Nachname</th>
<th>Username</th>
<th style="width: 180px;">Rolle</th>
<th style="width: 110px;" class="text-center">Status</th>
<th style="width: 200px;">Aktionen</th>
</tr>
</thead>
<tbody>
<% users.forEach(u => { %>
<tr class="<%= u.active ? '' : 'table-secondary' %>">
<!-- ✅ Update Form -->
<form method="POST" action="/admin/users/update/<%= u.id %>">
<td class="fw-semibold"><%= u.id %></td>
<td>
<input
type="text"
name="title"
value="<%= u.title || '' %>"
class="form-control form-control-sm"
disabled
>
</td>
<td>
<input
type="text"
name="first_name"
value="<%= u.first_name %>"
class="form-control form-control-sm"
disabled
>
</td>
<td>
<input
type="text"
name="last_name"
value="<%= u.last_name %>"
class="form-control form-control-sm"
disabled
>
</td>
<td>
<input
type="text"
name="username"
value="<%= u.username %>"
class="form-control form-control-sm"
disabled
>
</td>
<td>
<select name="role" class="form-select form-select-sm" disabled>
<option value="mitarbeiter" <%= u.role === "mitarbeiter" ? "selected" : "" %>>
Mitarbeiter
</option>
<option value="arzt" <%= u.role === "arzt" ? "selected" : "" %>>
Arzt
</option>
<option value="admin" <%= u.role === "admin" ? "selected" : "" %>>
Admin
</option>
</select>
</td>
<td class="text-center">
<% if (u.active === 0) { %>
<span class="badge bg-secondary badge-soft">Inaktiv</span>
<% } else if (u.lock_until && new Date(u.lock_until) > new Date()) { %>
<span class="badge bg-danger badge-soft">Gesperrt</span>
<% } else { %>
<span class="badge bg-success badge-soft">Aktiv</span>
<% } %>
</td>
<td class="d-flex gap-2 align-items-center">
<!-- ✅ Save -->
<button
class="btn btn-outline-success icon-btn save-btn"
disabled
title="Speichern"
>
<i class="bi bi-save"></i>
</button>
<!-- ✅ Unlock -->
<button
type="button"
class="btn btn-outline-warning icon-btn lock-btn"
title="Bearbeiten aktivieren"
>
<i class="bi bi-pencil-square"></i>
</button>
</form>
<!-- ✅ Aktiv / Deaktiv -->
<% if (u.id !== currentUser.id) { %>
<form method="POST" action="/admin/users/<%= u.active ? "deactivate" : "activate" %>/<%= u.id %>">
<button
class="btn icon-btn <%= u.active ? "btn-outline-danger" : "btn-outline-success" %>"
title="<%= u.active ? "Deaktivieren" : "Aktivieren" %>"
>
<i class="bi <%= u.active ? "bi-person-x" : "bi-person-check" %>"></i>
</button>
</form>
<% } else { %>
<span class="badge bg-light text-dark border">
👤 Du selbst
</span>
<% } %>
</td>
</tr>
<% }) %>
</tbody>
</table>
</div>
</div><!-- /table-wrapper -->
</div>
</div>
</div>
</div>
</div>
</body>
</html>

View File

@ -1,213 +1,43 @@
<!DOCTYPE html> <!-- KEIN layout, KEINE sidebar, KEIN main -->
<html lang="de">
<head> <%- include("partials/page-header", {
<meta charset="UTF-8" /> user,
<title>Praxis System</title> title: t.dashboard.title,
<meta name="viewport" content="width=device-width, initial-scale=1" /> subtitle: "",
showUserName: true,
<link rel="stylesheet" href="/css/bootstrap.min.css" /> hideDashboardButton: true
<link rel="stylesheet" href="/bootstrap-icons/bootstrap-icons.min.css" /> }) %>
<style> <div class="content p-4">
body {
margin: 0; <%- include("partials/flash") %>
background: #f4f6f9;
font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", <div class="waiting-monitor">
Roboto, Ubuntu; <h5 class="mb-3">🪑 <%= t.dashboard.waitingRoom %></h5>
}
<div class="waiting-grid">
.layout { <% if (waitingPatients && waitingPatients.length > 0) { %>
display: flex; <% waitingPatients.forEach(p => { %>
min-height: 100vh;
} <% if (user.role === "arzt") { %>
<form method="POST" action="/patients/<%= p.id %>/call">
/* Sidebar */ <button class="waiting-slot occupied clickable">
.sidebar { <div><%= p.firstname %> <%= p.lastname %></div>
width: 240px; </button>
background: #111827; </form>
color: white; <% } else { %>
padding: 20px; <div class="waiting-slot occupied">
display: flex; <div><%= p.firstname %> <%= p.lastname %></div>
flex-direction: column; </div>
} <% } %>
.logo { <% }) %>
font-size: 18px; <% } else { %>
font-weight: 700; <div class="text-muted">
margin-bottom: 30px; <%= t.dashboard.noWaitingPatients %>
display: flex; </div>
align-items: center; <% } %>
gap: 10px; </div>
} </div>
.nav-item { </div>
display: flex;
align-items: center;
gap: 12px;
padding: 12px 15px;
border-radius: 8px;
color: #cbd5e1;
text-decoration: none;
margin-bottom: 6px;
font-size: 14px;
}
.nav-item:hover {
background: #1f2937;
color: white;
}
.nav-item.active {
background: #2563eb;
color: white;
}
.sidebar .spacer {
flex: 1;
}
/* Main */
.main {
flex: 1;
padding: 25px 30px;
}
.topbar {
display: flex;
justify-content: space-between;
align-items: center;
margin-bottom: 25px;
}
.topbar h3 {
margin: 0;
}
.main {
flex: 1;
padding: 24px;
background: #f4f6f9;
overflow: hidden;
display: flex;
flex-direction: column;
}
.waiting-monitor {
flex: 1;
display: flex;
flex-direction: column;
margin-top: 10px;
}
.waiting-grid {
display: grid;
grid-template-columns: repeat(7, 1fr);
grid-auto-rows: 80px;
gap: 12px;
width: 100%;
}
.waiting-slot {
border: 2px dashed #cbd5e1;
border-radius: 10px;
background: #f8fafc;
height: 100%;
display: flex;
align-items: center;
justify-content: center;
overflow: hidden;
text-decoration: none;
color: inherit;
}
.waiting-slot.occupied {
border-style: solid;
background: #eefdf5;
}
.patient-text {
display: flex;
flex-direction: column;
align-items: center;
gap: 4px;
}
.waiting-slot.clickable {
cursor: pointer;
transition: 0.15s ease;
}
.waiting-slot.clickable:hover {
transform: scale(1.03);
box-shadow: 0 0 0 2px #2563eb;
}
.nav-item.locked {
opacity: 0.5;
cursor: not-allowed;
}
.nav-item.locked:hover {
background: transparent;
color: #cbd5e1;
}
</style>
</head>
<body>
<div class="layout">
<!-- ✅ SIDEBAR ausgelagert -->
<%- include("partials/sidebar", { user, active: "patients" }) %>
<!-- MAIN CONTENT -->
<div class="main">
<div class="topbar">
<h3>Willkommen, <%= user.username %></h3>
</div>
<!-- Flash Messages -->
<%- include("partials/flash") %>
<!-- =========================
WARTEZIMMER MONITOR
========================= -->
<div class="waiting-monitor">
<h5 class="mb-3">🪑 Wartezimmer-Monitor</h5>
<div class="waiting-grid">
<% if (waitingPatients && waitingPatients.length > 0) { %>
<% waitingPatients.forEach(p => { %>
<% if (user.role === 'arzt') { %>
<a href="/patients/<%= p.id %>/overview" class="waiting-slot occupied clickable">
<div class="patient-text">
<div class="name"><%= p.firstname %> <%= p.lastname %></div>
<div class="birthdate">
<%= new Date(p.birthdate).toLocaleDateString("de-DE") %>
</div>
</div>
</a>
<% } else { %>
<div class="waiting-slot occupied">
<div class="patient-text">
<div class="name"><%= p.firstname %> <%= p.lastname %></div>
<div class="birthdate">
<%= new Date(p.birthdate).toLocaleDateString("de-DE") %>
</div>
</div>
</div>
<% } %>
<% }) %>
<% } else { %>
<div class="text-muted">Keine Patienten im Wartezimmer.</div>
<% } %>
</div>
</div>
</div>
</div>
</body>
</html>

View File

@ -1,31 +1,31 @@
<!DOCTYPE html> <!DOCTYPE html>
<html lang="de"> <html lang="de">
<head> <head>
<meta charset="UTF-8"> <meta charset="UTF-8">
<title>Rechnung anzeigen</title> <title>Rechnung anzeigen</title>
<link rel="stylesheet" href="/css/bootstrap.min.css"> <link rel="stylesheet" href="/css/bootstrap.min.css">
</head> </head>
<body> <body>
<div class="container-fluid mt-3"> <div class="container-fluid mt-3">
<!-- ACTION BAR --> <!-- ACTION BAR -->
<div class="d-flex justify-content-between align-items-center mb-2"> <div class="d-flex justify-content-between align-items-center mb-2">
<h5 class="mb-0">🧾 Rechnung</h5> <h5 class="mb-0">🧾 Rechnung</h5>
<a href="/services/open" class="btn btn-primary"> <a href="/services/open" class="btn btn-primary">
⬅️ Zurück zu offenen Leistungen ⬅️ Zurück zu offenen Leistungen
</a> </a>
</div> </div>
<!-- PDF VIEW --> <!-- PDF VIEW -->
<iframe <iframe
src="<%= pdfUrl %>" src="<%= pdfUrl %>"
style="width:100%; height:92vh; border:none;" style="width:100%; height:92vh; border:none;"
title="Rechnung PDF"> title="Rechnung PDF">
</iframe> </iframe>
</div> </div>
</body> </body>
</html> </html>

Some files were not shown because too many files have changed in this diff Show More