import { query, insertReturning, execute } from '../../utils/db' import { getClientIp } from '../../utils/ip' interface LoginBody { email: string name: string } /** * 이메일+이름 로그인 (임시) * POST /api/auth/login */ export default defineEventHandler(async (event) => { const body = await readBody(event) const clientIp = getClientIp(event) if (!body.email || !body.name) { throw createError({ statusCode: 400, message: '이메일과 이름을 입력해주세요.' }) } // 이메일 형식 검증 const emailRegex = /^[^\s@]+@[^\s@]+\.[^\s@]+$/ if (!emailRegex.test(body.email)) { throw createError({ statusCode: 400, message: '올바른 이메일 형식이 아닙니다.' }) } const emailLower = body.email.toLowerCase() const nameTrimmed = body.name.trim() // 기존 직원 조회 let employee = await query(` SELECT * FROM wr_employee_info WHERE employee_email = $1 `, [emailLower]) let employeeData = employee[0] if (employeeData) { // 기존 직원 - 이름이 다르면 업데이트 if (employeeData.employee_name !== nameTrimmed) { await execute(` UPDATE wr_employee_info SET employee_name = $1, updated_at = NOW(), updated_ip = $2, updated_email = $3 WHERE employee_id = $4 `, [nameTrimmed, clientIp, emailLower, employeeData.employee_id]) employeeData.employee_name = nameTrimmed } } else { // 신규 직원 자동 등록 employeeData = await insertReturning(` INSERT INTO wr_employee_info (employee_name, employee_email, created_ip, created_email, updated_ip, updated_email) VALUES ($1, $2, $3, $2, $3, $2) RETURNING * `, [nameTrimmed, emailLower, clientIp]) } // 로그인 이력 추가 const loginHistory = await insertReturning(` INSERT INTO wr_login_history (employee_id, login_ip, login_email) VALUES ($1, $2, $3) RETURNING history_id `, [employeeData.employee_id, clientIp, emailLower]) // 쿠키에 사용자 정보 저장 setCookie(event, 'user_id', String(employeeData.employee_id), { httpOnly: true, maxAge: 60 * 60 * 24 * 7, path: '/' }) setCookie(event, 'login_history_id', String(loginHistory.history_id), { httpOnly: true, maxAge: 60 * 60 * 24 * 7, path: '/' }) return { success: true, user: { employeeId: employeeData.employee_id, employeeName: employeeData.employee_name, employeeEmail: employeeData.employee_email, employeePosition: employeeData.employee_position } } })