const express = require('express'); const router = express.Router(); const ApiKey = require('../models/ApiKey'); // Note: In production, these routes should be protected by admin authentication // For now, they are unprotected for initial setup // POST /api/admin/api-keys - Create new API key router.post('/', async (req, res) => { try { const { name, description, createdBy, expiresAt, rateLimit, allowedIps } = req.body; if (!name) { return res.status(400).json({ success: false, error: 'name is required' }); } const apiKey = await ApiKey.create({ name, description, createdBy, expiresAt, rateLimit, allowedIps }); res.status(201).json({ success: true, data: apiKey, warning: 'Save this key securely. It will not be shown again.' }); } catch (error) { console.error('Error creating API key:', error); res.status(500).json({ success: false, error: error.message }); } }); // GET /api/admin/api-keys - List all API keys router.get('/', async (req, res) => { try { const keys = await ApiKey.getAll(); res.json({ success: true, data: keys }); } catch (error) { console.error('Error getting API keys:', error); res.status(500).json({ success: false, error: error.message }); } }); // GET /api/admin/api-keys/:id - Get specific API key router.get('/:id', async (req, res) => { try { const key = await ApiKey.getById(req.params.id); if (!key) { return res.status(404).json({ success: false, error: 'API key not found' }); } res.json({ success: true, data: key }); } catch (error) { console.error('Error getting API key:', error); res.status(500).json({ success: false, error: error.message }); } }); // PUT /api/admin/api-keys/:id - Update API key status router.put('/:id', async (req, res) => { try { const { isActive } = req.body; if (isActive === undefined) { return res.status(400).json({ success: false, error: 'isActive is required' }); } const key = await ApiKey.updateStatus(req.params.id, isActive); if (!key) { return res.status(404).json({ success: false, error: 'API key not found' }); } res.json({ success: true, data: key }); } catch (error) { console.error('Error updating API key:', error); res.status(500).json({ success: false, error: error.message }); } }); // DELETE /api/admin/api-keys/:id - Delete API key router.delete('/:id', async (req, res) => { try { const deleted = await ApiKey.delete(req.params.id); if (!deleted) { return res.status(404).json({ success: false, error: 'API key not found' }); } res.json({ success: true, message: 'API key deleted successfully' }); } catch (error) { console.error('Error deleting API key:', error); res.status(500).json({ success: false, error: error.message }); } }); module.exports = router;