// routes/appSettings.js — Admin-only editor for the application settings that // used to live in .env (see services/appSettingsStore.js). GET returns the // current raw values; PUT updates one or more of them. Changes take effect // immediately (the store reloads its in-memory cache on write). 'use strict'; const express = require('express'); const router = express.Router(); const { verifyToken, verifyUserAdmin } = require('../middleware/auth'); const settings = require('../services/appSettingsStore'); const mailer = require('../services/mailer'); router.get('/', verifyToken, verifyUserAdmin, (req, res) => { res.json({ success: true, data: settings.getAll() }); }); router.put('/', verifyToken, verifyUserAdmin, async (req, res) => { try { const updated = await settings.setMany(req.body || {}, req.user?.username); res.json({ success: true, data: updated }); } catch (err) { res.status(500).json({ success: false, message: err.message }); } }); // Verify SMTP connectivity/credentials without sending anything — used by // the "Test Connection" button in Admin Settings. router.get('/test-email/verify', verifyToken, verifyUserAdmin, async (req, res) => { const r = await mailer.verifyConnection(); res.json({ success: r.ok, message: r.ok ? 'SMTP connection OK' : r.message }); }); // Send an actual test email to a chosen address — used by the "Send Test // Email" button in Admin Settings, so an admin can confirm delivery end to // end (not just that SMTP accepted the connection). router.post('/test-email', verifyToken, verifyUserAdmin, async (req, res) => { const to = String(req.body?.to || '').trim(); if (!to) return res.status(400).json({ success: false, message: 'Recipient email is required' }); if (!mailer.isConfigured()) return res.status(400).json({ success: false, message: 'SMTP_HOST is not set in .env — configure SMTP first' }); const sent = await mailer.sendMail({ to, subject: 'SAP ERP Portal — Test Email', html: `
This is a test email from the SAP ERP Portal's Production module notifications.
Sent by ${req.user?.username || ''} at ${new Date().toLocaleString()}.
`, }); if (sent) res.json({ success: true, message: `Test email sent to ${to} — check the inbox (and spam folder).` }); else res.status(500).json({ success: false, message: 'Send failed — check server console logs ([MAILER] ...) for the exact SMTP error.' }); }); module.exports = router;