2 Commits
3 changed files with 7 additions and 6 deletions

No files matched your search

+1 -1
View File
@@ -80,7 +80,7 @@ router.get('/agents', async (req, res) => {
const isGlobalUser = effectiveRole === 'SUPER_ADMIN' || effectiveRole === 'EXECUTIVE'; const isGlobalUser = effectiveRole === 'SUPER_ADMIN' || effectiveRole === 'EXECUTIVE';
const requestedSiteUuid = req.headers['x-backone-site-uuid']; const requestedSiteUuid = req.headers['x-backone-site-uuid'];
if (isGlobalUser && requestedSiteUuid) { if (isGlobalUser && requestedSiteUuid && requestedSiteUuid !== 'all') {
query.site_uuid = { $in: [requestedSiteUuid, 'global'] }; query.site_uuid = { $in: [requestedSiteUuid, 'global'] };
} else if (effectiveRole === 'TENANT_ADMIN') { } else if (effectiveRole === 'TENANT_ADMIN') {
query.site_uuid = { $in: [req.user.site_uuid, 'global'] }; query.site_uuid = { $in: [req.user.site_uuid, 'global'] };
+3 -1
View File
@@ -40,9 +40,11 @@ router.get('/summary', async (req, res) => {
} else { } else {
// ── Site-Level Summary (default) ───────────────────────────────────────── // ── Site-Level Summary (default) ─────────────────────────────────────────
const agentQuery = { const agentQuery = {
site_uuid: baseWithoutTime.site_uuid || { $in: await Summary.distinct('site_uuid') },
agent_uuid: { $ne: null } agent_uuid: { $ne: null }
}; };
if (baseWithoutTime.site_uuid) {
agentQuery.site_uuid = baseWithoutTime.site_uuid;
}
if (timeFilter) agentQuery.timestamp = timeFilter; if (timeFilter) agentQuery.timestamp = timeFilter;
const allAgentSummaries = await Summary.find(agentQuery).lean(); const allAgentSummaries = await Summary.find(agentQuery).lean();
+3 -4
View File
@@ -152,12 +152,11 @@ app.use((err, req, res, next) => {
}); });
// ─── Start Server ───────────────────────────────────────────────────────────── // ─── Start Server ─────────────────────────────────────────────────────────────
// Bind to 127.0.0.1 in production to prevent direct external access to port 3001. // Use BIND_HOST from environment or default to 0.0.0.0 for Docker compatibility
// All external traffic must go through the reverse proxy (Apache/Nginx) at port 80/443. const BIND_HOST = process.env.BIND_HOST || '0.0.0.0';
const BIND_HOST = process.env.NODE_ENV === 'production' ? '127.0.0.1' : '0.0.0.0';
app.listen(PORT, BIND_HOST, () => { app.listen(PORT, BIND_HOST, () => {
console.log(`\n🚀 BackOne API Server berjalan di http://${BIND_HOST}:${PORT}`); console.log(`\n🚀 BackOne API Server berjalan di http://${BIND_HOST}:${PORT}`);
console.log(`🔌 API Health : http://${BIND_HOST}:${PORT}/api/health`); console.log(`🔌 API Health : http://${BIND_HOST}:${PORT}/api/health`);
console.log(`📡 Mode : READ-ONLY dari MongoDB (data dikirim oleh Proxy Server)`); console.log(`📡 Mode : READ-ONLY dari MongoDB (data dikirim oleh Proxy Server)`);
console.log(`🔒 Security : Bound to ${BIND_HOST} (internal only in production)\n`); console.log(`🔒 Security : Bound to ${BIND_HOST}\n`);
}); });