All files / src/routes admin-migrate.js

91.34% Statements 95/104
94.44% Branches 17/18
100% Functions 12/12
91.3% Lines 84/92

Press n or j to go to the next uncovered block, b, p or k for the previous block.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252                  3x 3x 3x 3x 3x 3x 3x     3x                                                       3x                         3x     26x   3x 3x 1x           2x 2x               1x         1x 1x 1x             650x 650x   650x 656x 652x   6x 6x 508x   6x 6x     646x             600x 598x     104x 104x 129x 129x 129x 12605x   129x     103x             240x 230x   230x 30x           30x                                 230x         1680x 1680x 1653x 827x 1653x       27x 27x       3x 30x 28x 2x     26x   26x 26x 24x     24x 240x 240x 230x 230x 50x   227x         24x 600x       24x 600x       24x 240x 240x             24x   826x 827x   24x         24x               2x 2x       3x  
/**
 * Admin route: Copy production Firestore data to dev.
 *
 * POST /admin/migrate-prod-data  — Wipe dev Firestore and copy all data from prod.
 *
 * Dev-only route. Requires admin auth and PROD_SERVICE_ACCOUNT_PATH env var
 * pointing to the prod Firebase service account JSON.
 */
 
const router = require('express').Router();
const { initializeApp, cert } = require('firebase-admin/app');
const { getFirestore } = require('firebase-admin/firestore');
const { db } = require('../utils/firebase');
const { clearBanCache } = require('../utils/bans');
const { requireAdmin } = require('../middleware/auth');
const log = require('../utils/log');
 
// Same collections the backup cron tracks, minus large operational ones (logs, alerts)
const TOP_LEVEL_COLLECTIONS = [
  'users',
  'rooms',
  'conversations',
  'config',
  'identityMap',
  'counters',
  'deviceBindings',
  'gifts',
  'giftRankings',
  'broadcasts',
  'coinPackages',
  'banners',
  'reports',
  'reportsArchive',
  'reportLocks',
  'suspensionAppeals',
  'adminAuditLog',
  'alertConfig',
  'otpCodes',
  'biometricKeys',
  'emailMetrics',
  'purchaseReceipts',
  'logConfig',
  'deviceBans',
  'networkBans',
];
 
const SUBCOLLECTIONS = [
  ['rooms', 'messages'],
  ['rooms', 'seatRequests'],
  ['conversations', 'messages'],
  ['conversations', 'userSettings'],
  ['conversations', 'mutes'],
  ['users', 'backpack'],
  ['users', 'warnings'],
  ['users', 'giftWall'],
  ['users', 'transactions'],
  ['users', 'stalkers'],
];
 
let prodDb = null;
 
function getProdDb() {
  if (prodDb) return prodDb;
 
  const prodSaPath = process.env.PROD_SERVICE_ACCOUNT_PATH;
  if (!prodSaPath) {
    throw new Error('PROD_SERVICE_ACCOUNT_PATH env var not set');
  }
 
  // firebase-admin 14 removed `admin.credential` and the App object's
  // `.firestore()` accessor; both now come from modular entry points.
  let credential;
  try {
    credential = cert(require(prodSaPath));
  } catch (cause) {
    // Node's MODULE_NOT_FOUND and JSON-parse messages embed the ABSOLUTE PATH of
    // the service-account file, and this error reaches the HTTP response body
    // (see the catch at the bottom of this route). Name the variable to fix
    // instead: it is all an operator needs, and it leaks nothing about where
    // prod credentials live on disk. `cause` keeps the detail for a stack trace
    // without putting it on the wire.
    throw new Error('PROD_SERVICE_ACCOUNT_PATH does not point to a readable service-account JSON', {
      cause,
    });
  }
 
  const prodApp = initializeApp({ credential }, 'prod-readonly');
  prodDb = getFirestore(prodApp);
  return prodDb;
}
 
/**
 * Delete all documents in a collection (in batches of 500).
 */
async function deleteCollection(firestore, collectionPath) {
  const collRef = firestore.collection(collectionPath);
  let deleted = 0;
 
  while (true) {
    const snapshot = await collRef.limit(500).get();
    if (snapshot.empty) break;
 
    const batch = firestore.batch();
    for (const doc of snapshot.docs) {
      batch.delete(doc.ref);
    }
    await batch.commit();
    deleted += snapshot.size;
  }
 
  return deleted;
}
 
/**
 * Copy all documents from one Firestore collection to another Firestore instance.
 */
async function copyCollection(srcDb, destDb, collectionName) {
  const snapshot = await srcDb.collection(collectionName).get();
  if (snapshot.empty) return 0;
 
  // Write in batches of 500 (Firestore limit)
  const docs = snapshot.docs;
  for (let i = 0; i < docs.length; i += 500) {
    const batch = destDb.batch();
    const chunk = docs.slice(i, i + 500);
    for (const doc of chunk) {
      batch.set(destDb.collection(collectionName).doc(doc.id), doc.data());
    }
    await batch.commit();
  }
 
  return docs.length;
}
 
/**
 * Copy subcollection documents from all parent docs.
 */
async function copySubcollection(srcDb, destDb, parentCollection, subName) {
  const parents = await srcDb.collection(parentCollection).listDocuments();
  let total = 0;
 
  for (const parentRef of parents) {
    const subSnapshot = await srcDb
      .collection(parentCollection)
      .doc(parentRef.id)
      .collection(subName)
      .get();
 
    Eif (subSnapshot.empty) continue;
 
    const docs = subSnapshot.docs;
    for (let i = 0; i < docs.length; i += 500) {
      const batch = destDb.batch();
      const chunk = docs.slice(i, i + 500);
      for (const doc of chunk) {
        batch.set(
          destDb.collection(parentCollection).doc(parentRef.id).collection(subName).doc(doc.id),
          doc.data(),
        );
      }
      await batch.commit();
    }
    total += docs.length;
  }
 
  return total;
}
 
/** Run a migration phase operation, logging and capturing errors. */
async function runMigrationOp(results, collectionName, phase, fn) {
  try {
    const count = await fn();
    if (phase === 'delete') results.deleted[collectionName] = count;
    else results.copied[collectionName] = count;
    log.info('admin-migrate', `${phase === 'delete' ? 'Deleted' : 'Copied'} ${collectionName}`, {
      count,
    });
  } catch (err) {
    results.errors.push({ collection: collectionName, phase, error: err.message });
    log.error('admin-migrate', `Failed to ${phase} ${collectionName}`, { error: err.message });
  }
}
 
router.post('/admin/migrate-prod-data', async (req, res) => {
  if (await requireAdmin(req, res)) return;
  if (process.env.NODE_ENV === 'production') {
    return res.status(403).json({ error: 'This endpoint is disabled in production' });
  }
 
  log.info('admin-migrate', 'Starting prod → dev data migration', { adminUid: req.auth.uniqueId });
 
  try {
    const srcDb = getProdDb();
    const results = { deleted: {}, copied: {}, errors: [] };
 
    // Phase 1: Delete subcollections in dev first
    for (const [parent, sub] of SUBCOLLECTIONS) {
      await runMigrationOp(results, `${parent}/${sub}`, 'delete', async () => {
        const parentDocs = await db.collection(parent).listDocuments();
        let subDeleted = 0;
        for (const parentRef of parentDocs) {
          subDeleted += await deleteCollection(db, `${parent}/${parentRef.id}/${sub}`);
        }
        return subDeleted;
      });
    }
 
    // Phase 2: Delete top-level collections in dev
    for (const name of TOP_LEVEL_COLLECTIONS) {
      await runMigrationOp(results, name, 'delete', () => deleteCollection(db, name));
    }
 
    // Phase 3: Copy top-level collections from prod
    for (const name of TOP_LEVEL_COLLECTIONS) {
      await runMigrationOp(results, name, 'copy', () => copyCollection(srcDb, db, name));
    }
 
    // Phase 4: Copy subcollections from prod
    for (const [parent, sub] of SUBCOLLECTIONS) {
      await runMigrationOp(results, `${parent}/${sub}`, 'copy', () =>
        copySubcollection(srcDb, db, parent, sub),
      );
    }
 
    // The migration wholesale replaces deviceBans/networkBans. Without this,
    // a ban just copied in would not bite for up to the cache TTL, and a ban
    // just deleted would keep blocking (SHY-0149).
    clearBanCache();
 
    const totalDeleted = Object.values(results.deleted).reduce((a, b) => a + b, 0);
    const totalCopied = Object.values(results.copied).reduce((a, b) => a + b, 0);
 
    log.info('admin-migrate', 'Migration complete', {
      totalDeleted,
      totalCopied,
      errors: results.errors.length,
    });
    res.json({
      success: true,
      totalDeleted,
      totalCopied,
      errors: results.errors,
      details: results,
    });
  } catch (err) {
    log.error('admin-migrate', 'Migration failed', { error: err.message });
    res.status(500).json({ error: err.message });
  }
});
 
module.exports = router;