feat(m14): backup & admin (zip via fflate, admin guard, tests, e2e)

- BackupService (admin-only: createBackup zips DB+uploads via fflate to
  backups/backup-<ts>.zip, listBackups newest-first, getBackupPath with
  path-traversal guard)
- Admin backup APIs: GET/POST /api/admin/backups, GET /api/admin/backups/:filename
- Admin backups screen (admin-only) + BackupCreateButton
- Playwright globalSetup seeds a system_admin user for admin E2E
- add fflate dependency
- Unit tests (BackupService: zip content, list, admin guard, traversal) +
  e2e backup (create/list/download + non-admin 403)
This commit is contained in:
Ken Yasue
2026-06-25 02:35:35 +02:00
parent 384e61386a
commit 0026edd22b
9 changed files with 346 additions and 1 deletions

2
package-lock.json generated
View File

@ -11,6 +11,7 @@
"dependencies": {
"bcrypt": "^5.1.1",
"better-sqlite3": "^11.3.0",
"fflate": "^0.8.3",
"next": "^15.1.0",
"react": "^19.0.0",
"react-dom": "^19.0.0",
@ -5058,7 +5059,6 @@
"version": "0.8.3",
"resolved": "https://registry.npmjs.org/fflate/-/fflate-0.8.3.tgz",
"integrity": "sha512-tbZNuJrLwGUp3zshBtdy4W+ORxZuIh8a5ilyIEQDC5rY1f3U20JMry0Ll3WBzU58EZKsEuJFXhb5gwv8CsPvgA==",
"dev": true,
"license": "MIT"
},
"node_modules/file-entry-cache": {