This repository has been archived on 2026-03-21. You can view files and clone it, but cannot push or open issues or pull requests.
payfrit-biz/api/auth/login.cfm
John Mizerek bffca643b5 Restore API performance tracking and fix perf dashboard
- Add queryTimed(), logPerf(), flushPerfBuffer() to environment.cfm
- Auto-create ApiPerfLogs table on first flush
- Hook logPerf into Application.cfm apiAbort for automatic tracking
- Initialize request perf counters in Application.cfm
- Remove local apiAbort() overrides from 7 endpoints
- Instrument 12 high-traffic endpoints with logPerf calls
- Buffer metrics in application scope, batch INSERT every 100 requests
- 30-day auto-cleanup with probabilistic trigger

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-30 17:04:12 -08:00

117 lines
2.8 KiB
Text

<cfsetting showdebugoutput="false">
<cfsetting enablecfoutputonly="true">
<cfcontent type="application/json; charset=utf-8" reset="true">
<cfheader name="Cache-Control" value="no-store">
<cfscript>
/*
PATH:
C:\lucee\tomcat\webapps\ROOT\biz.payfrit.com\api\auth\login.cfm
INPUT (JSON):
{ "username": "...", "password": "..." }
OUTPUT (JSON):
{ OK:true, ERROR:"", UserID:123, FirstName:"...", Token:"..." }
Uses existing UserTokens table:
TokenID (auto), UserID, Token, CreatedAt (DEFAULT CURRENT_TIMESTAMP)
-> INSERT does NOT include CreatedAt.
*/
function apiAbort(required struct payload) {
writeOutput(serializeJSON(payload));
abort;
}
function readJsonBody() {
var raw = getHttpRequestData().content;
if (isNull(raw)) raw = "";
if (!len(trim(raw))) return {};
try {
var data = deserializeJSON(raw);
if (isStruct(data)) return data;
} catch (any e) {}
return {};
}
function normalizeUsername(required string u) {
var x = trim(arguments.u);
x = replace(x, " ", "", "all");
x = replace(x, "(", "", "all");
x = replace(x, ")", "", "all");
x = replace(x, "-", "", "all");
return x;
}
data = readJsonBody();
username = structKeyExists(data, "username") ? normalizeUsername("" & data.username) : "";
password = structKeyExists(data, "password") ? ("" & data.password) : "";
if (!len(username) || !len(password)) {
apiAbort({ "OK": false, "ERROR": "missing_fields" });
}
try {
q = queryExecute(
"
SELECT ID, FirstName
FROM Users
WHERE
(
(EmailAddress = ?) OR
(ContactNumber = ?)
)
AND Password = ?
AND IsEmailVerified = 1
AND IsContactVerified > 0
LIMIT 1
",
[
{ value = username, cfsqltype = "cf_sql_varchar" },
{ value = username, cfsqltype = "cf_sql_varchar" },
{ value = hash(password), cfsqltype = "cf_sql_varchar" }
],
{ datasource = "payfrit" }
);
if (q.recordCount NEQ 1) {
apiAbort({ "OK": false, "ERROR": "bad_credentials" });
}
token = replace(createUUID(), "-", "", "all");
queryExecute(
"INSERT INTO UserTokens (UserID, Token) VALUES (?, ?)",
[
{ value = q.ID, cfsqltype = "cf_sql_integer" },
{ value = token, cfsqltype = "cf_sql_varchar" }
],
{ datasource = "payfrit" }
);
// Optional: also set session for browser tools
lock timeout="15" throwontimeout="yes" type="exclusive" scope="session" {
session.UserID = q.ID;
}
request.UserID = q.ID;
try{logPerf(0);}catch(any e){}
writeOutput(serializeJSON({
"OK": true,
"ERROR": "",
"UserID": q.ID,
"FirstName": q.FirstName,
"Token": token
}));
abort;
} catch (any e) {
apiAbort({
"OK": false,
"ERROR": "server_error",
"MESSAGE": "DB error during login",
"DETAIL": e.message
});
}
</cfscript>