48 lines
1.5 KiB
TypeScript
48 lines
1.5 KiB
TypeScript
import "dotenv/config";
|
|
import { PrismaClient } from "@prisma/client";
|
|
import { hash } from "bcrypt";
|
|
import { seedRbac } from "./rbac-seed";
|
|
import { validPassword } from "../src/lib/security";
|
|
const db = new PrismaClient();
|
|
async function main() {
|
|
await seedRbac(db);
|
|
if (
|
|
await db.user.count({
|
|
where: { roles: { some: { roleId: "system-admin" } } },
|
|
})
|
|
) {
|
|
console.log("Administrator vorhanden; Bootstrap übersprungen.");
|
|
return;
|
|
}
|
|
const email = process.env.BOOTSTRAP_EMAIL?.trim().toLowerCase();
|
|
const password = process.env.BOOTSTRAP_PASSWORD;
|
|
if (!email || !password || !validPassword(password))
|
|
throw new Error(
|
|
"BOOTSTRAP_EMAIL und sicheres BOOTSTRAP_PASSWORD erforderlich (12 Zeichen, maximal 72 Bytes)",
|
|
);
|
|
await db.$transaction(async (tx) => {
|
|
await tx.$queryRaw`SELECT pg_advisory_xact_lock(822100)::text`;
|
|
if (
|
|
await tx.user.count({
|
|
where: { roles: { some: { roleId: "system-admin" } } },
|
|
})
|
|
)
|
|
return;
|
|
await tx.user.create({
|
|
data: {
|
|
email,
|
|
name: "Administrator",
|
|
password: await hash(password, 12),
|
|
role: "ADMIN",
|
|
mustChangePassword: true,
|
|
memberships: { create: { groupId: "legacy" } },
|
|
roles: { create: { roleId: "system-admin", scope: "GLOBAL" } },
|
|
},
|
|
});
|
|
});
|
|
console.log(
|
|
"Administrator angelegt. Passwortänderung bei erster Anmeldung erforderlich.",
|
|
);
|
|
}
|
|
main().finally(() => db.$disconnect());
|