feat(m14): backup & admin (zip via fflate, admin guard, tests, e2e)

- BackupService (admin-only: createBackup zips DB+uploads via fflate to
  backups/backup-<ts>.zip, listBackups newest-first, getBackupPath with
  path-traversal guard)
- Admin backup APIs: GET/POST /api/admin/backups, GET /api/admin/backups/:filename
- Admin backups screen (admin-only) + BackupCreateButton
- Playwright globalSetup seeds a system_admin user for admin E2E
- add fflate dependency
- Unit tests (BackupService: zip content, list, admin guard, traversal) +
  e2e backup (create/list/download + non-admin 403)
This commit is contained in:
Ken Yasue
2026-06-25 02:35:35 +02:00
parent 384e61386a
commit 0026edd22b
9 changed files with 346 additions and 1 deletions

View File

@ -0,0 +1,47 @@
'use client';
import { useState } from 'react';
import { useRouter } from 'next/navigation';
export function BackupCreateButton() {
const router = useRouter();
const [loading, setLoading] = useState(false);
const [error, setError] = useState<string | null>(null);
async function onCreate() {
setLoading(true);
setError(null);
const res = await fetch('/api/admin/backups', { method: 'POST' });
setLoading(false);
if (res.ok) {
router.refresh();
} else {
const b = (await res.json().catch(() => null)) as {
error?: { message?: string };
} | null;
setError(b?.error?.message ?? '作成に失敗しました');
}
}
return (
<div className="rounded-lg border bg-white p-4 shadow-sm">
<p className="text-sm text-gray-600">
DBファイル + uploadsディレクトリをZIP化してバックアップを作成します
</p>
<button
type="button"
onClick={onCreate}
disabled={loading}
className="mt-2 rounded bg-blue-600 px-4 py-2 font-medium text-white hover:bg-blue-700 disabled:opacity-50"
data-testid="create-backup"
>
{loading ? '作成中...' : 'バックアップ作成'}
</button>
{error && (
<p className="mt-2 text-sm text-red-600" role="alert">
{error}
</p>
)}
</div>
);
}