Make the Generator's server-name lists editable, add themes, import names from Skatteverket

Name lists now live in settings instead of the web bundle. Admins edit them under
Settings -> Names (add/remove names, create/rename/delete lists, reset a built-in
list). Names are folded to hostname-safe form (a-z, 0-9, hyphen) and validated on
the server; saves are audited.

Adds Swedish boy names, Pixar, Norse mythology and Astrid Lindgren lists, and
lengthens the Swedish girl and Disney lists. "Mixed" is now every list with each
name counted once.

Admins can preview and import the most common Swedish names from Skatteverket's
open "Namn pa nyfodda" data (girls or boys, latest 1-5 full years); nothing is
stored until the editor is saved. The old comment that credited SCB statistics is
gone: SCB stopped publishing name statistics after 2023.

Privacy page, README and ROLES updated for the new outbound call and page.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
bobbanandClaude Sonnet 5.5 committed 2026-10-03 01:53:31 +02:00
1 parent 447f33fff6
commit 3035d7fc08
14 files changed
+980 -44

No files matched your search

+2
View File
@@ -30,6 +30,7 @@ import { privacyRouter } from "./routes/privacy.js";
import { tagsRouter } from "./routes/tags.js";
import { portsRouter } from "./routes/ports.js";
import { alertsRouter } from "./routes/alerts.js";
import { generatorRouter } from "./routes/generator.js";
import { initSecretExpiryScheduler } from "./services/secretExpiryScheduler.js";
import { initTailscaleKeyExpiryScheduler } from "./services/tailscaleKeyExpiryScheduler.js";
import { initLogRetentionScheduler } from "./services/logRetentionScheduler.js";
@@ -106,6 +107,7 @@ app.use("/api/privacy", privacyRouter);
app.use("/api/tags", tagsRouter);
app.use("/api/ports", portsRouter);
app.use("/api/alerts", alertsRouter);
app.use("/api/generator", generatorRouter);
if (existsSync(webDist)) {
app.use(express.static(webDist));
+128
View File
@@ -0,0 +1,128 @@
import { Router } from "express";
import { z } from "zod";
import { requireAuth, requireRole } from "../auth/middleware.js";
import { recordAudit } from "../services/audit.js";
import { getSettings, updateSettings } from "../services/settingsStore.js";
import {
DEFAULT_THEME_IDS,
InvalidThemesError,
MAX_NAME_LENGTH,
cleanThemes,
defaultThemes,
importSkatteverketNames,
readStoredThemes,
type NameTheme,
type NameThemeSource,
} from "../services/nameThemes.js";
import { asyncHandler } from "../utils/asyncHandler.js";
export const generatorRouter = Router();
generatorRouter.use(requireAuth);
async function currentThemes(): Promise<NameTheme[]> {
return readStoredThemes((await getSettings()).nameGenerator.themes);
}
// Read by everyone signed in — the Generator page needs the lists to pick from. Editing them is a Settings matter.
generatorRouter.get("/themes", asyncHandler(async (_req, res) => {
res.json({ themes: await currentThemes(), builtinIds: DEFAULT_THEME_IDS });
}));
generatorRouter.get("/themes/defaults", requireRole("admin"), (_req, res) => {
res.json({ themes: defaultThemes() });
});
const sourceSchema = z.object({
kind: z.literal("skatteverket"),
sex: z.enum(["girls", "boys"]),
years: z.array(z.number().int()).max(10),
count: z.number().int(),
importedAt: z.string().max(40),
});
const saveSchema = z.object({
themes: z
.array(
z.object({
id: z.string().max(40).optional(),
label: z.string().max(200),
names: z.array(z.string().max(MAX_NAME_LENGTH * 3)).max(10000),
lastImport: sourceSchema.optional(),
}),
)
.max(100),
});
/** A short, readable account of what an edit changed, for the audit log. */
function describeThemeChanges(before: NameTheme[], after: NameTheme[]) {
const beforeById = new Map(before.map((t) => [t.id, t]));
const afterIds = new Set(after.map((t) => t.id));
const created = after.filter((t) => !beforeById.has(t.id)).map((t) => `${t.label} (${t.names.length} names)`);
const deleted = before.filter((t) => !afterIds.has(t.id)).map((t) => t.label);
const edited: { list: string; renamedFrom?: string; added: number; removed: number }[] = [];
for (const t of after) {
const old = beforeById.get(t.id);
if (!old) continue;
const had = new Set(old.names);
const has = new Set(t.names);
const added = t.names.filter((n) => !had.has(n)).length;
const removed = old.names.filter((n) => !has.has(n)).length;
if (added || removed || old.label !== t.label) edited.push({ list: t.label, ...(old.label !== t.label ? { renamedFrom: old.label } : {}), added, removed });
}
return { created, deleted, edited };
}
generatorRouter.put("/themes", requireRole("admin"), asyncHandler(async (req, res) => {
const parsed = saveSchema.safeParse(req.body);
if (!parsed.success) return res.status(400).json({ error: "invalid_body", message: "That doesn't look like a set of name lists.", details: parsed.error.flatten() });
let themes: NameTheme[];
try {
themes = cleanThemes(parsed.data.themes);
} catch (err) {
if (err instanceof InvalidThemesError) return res.status(400).json({ error: "invalid_names", message: err.message, invalid: err.invalid });
throw err;
}
const before = await currentThemes();
const changes = describeThemeChanges(before, themes);
await updateSettings({ nameGenerator: { themes } });
if (changes.created.length || changes.deleted.length || changes.edited.length) {
await recordAudit({
actor: req.currentUser!,
category: "settings",
action: "update_name_lists",
targetType: "name_generator",
detail: changes,
});
}
res.json({ themes });
}));
const importSchema = z.object({
sex: z.enum(["girls", "boys"]),
years: z.number().int().min(1).max(5),
count: z.number().int().min(10).max(500),
});
// Only fetches and returns a preview — nothing is stored until the editor's own Save, so an import can be looked at (and
// thrown away) first. The address is fixed; none of the request's values go into it unchecked.
generatorRouter.post("/themes/import", requireRole("admin"), asyncHandler(async (req, res) => {
const parsed = importSchema.safeParse(req.body);
if (!parsed.success) return res.status(400).json({ error: "invalid_body", message: "Pick girls or boys, 1–5 years and 10–500 names.", details: parsed.error.flatten() });
try {
const result = await importSkatteverketNames(parsed.data.sex, parsed.data.years, parsed.data.count);
const source: NameThemeSource = {
kind: "skatteverket",
sex: parsed.data.sex,
years: result.years,
count: parsed.data.count,
importedAt: new Date().toISOString(),
};
res.json({ names: result.names, source, missingYears: result.missingYears, skipped: result.skipped });
} catch (err) {
res.status(502).json({ error: "import_failed", message: err instanceof Error ? err.message : String(err) });
}
}));
+294
View File
@@ -0,0 +1,294 @@
/**
* The name lists behind Operations → Generator's server-name picker.
*
* The built-in lists below are hand-picked, not taken from any official source — they're a starting point. Admins can
* edit every list under Settings → Names, and can replace a Swedish list with real statistics from Skatteverket.
*/
export interface NameThemeSource {
kind: "skatteverket";
sex: "girls" | "boys";
/** Birth years that were combined. */
years: number[];
/** How many names the import asked for. */
count: number;
importedAt: string;
}
export interface NameTheme {
id: string;
label: string;
names: string[];
/** The last import into this list, if there's been one. Editing the list by hand doesn't clear it. */
lastImport?: NameThemeSource;
}
export const MAX_THEMES = 20;
export const MAX_NAMES_PER_THEME = 2000;
export const MAX_LABEL_LENGTH = 40;
export const MAX_NAME_LENGTH = 30;
/**
* Names end up as server names and hostnames, so they're kept to lowercase a–z, digits and inner hyphens. Accents are
* folded away first (Åsa → asa, José → jose) so a pasted Swedish name isn't rejected over its å, ä or ö.
*/
export function normalizeName(raw: string): string | null {
const folded = raw
.normalize("NFD")
.replace(/[̀-ͯ]/g, "")
.trim()
.toLowerCase();
return /^[a-z0-9](?:[a-z0-9-]{0,28}[a-z0-9])?$/.test(folded) ? folded : null;
}
export function slugifyId(label: string): string {
return (
label
.normalize("NFD")
.replace(/[̀-ͯ]/g, "")
.toLowerCase()
.replace(/[^a-z0-9]+/g, "-")
.replace(/^-+|-+$/g, "")
.slice(0, 40) || "list"
);
}
function words(text: string): string[] {
return text.split(/\s+/).filter(Boolean);
}
const SWEDISH_GIRLS = words(`
freja elsa alice maja wilma alma ebba lilly ella saga agnes stella selma vera ingrid astrid linnea nova sara emma
julia olivia isabelle klara nellie elin signe tuva moa tyra hedda nora amanda anna elvira iris matilda molly sofia
thea vilma cornelia filippa livia meja ronja sigrid tilde greta hilda leia lovisa siri jasmine felicia ida lina
mira mimmi lykke ellen ellie emelie hanna jenny josefin kajsa karin lisa lotta maria märta nathalie pia
rebecka sanna sally stina svea tindra ylva yvonne
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
const SWEDISH_BOYS = words(`
noah liam hugo lucas oliver elias oscar william adam alfred nils axel arvid vincent theo leo ludvig filip viktor
albin gustav melvin sixten love ivar edvin otto wilmer malte valter folke sigge algot ebbe noel benjamin felix isak
jonathan anton erik emil johan karl lars anders mattias henrik jakob sebastian daniel samuel alex max rasmus
tage olle tobias simon kasper julius ture vidar viggo vilgot ville lennart gunnar bertil sten stig bo björn
rolf ulf kurt mats magnus mikael peter per pontus
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
const DISNEY = words(`
moana elsa anna belle ariel jasmine aurora cinderella rapunzel mulan tiana merida pocahontas mickey minnie simba
nala stitch lilo olaf baymax dory nemo woody buzz genie aladdin eric flynn kristoff sven pumbaa timon mufasa scar
ursula maleficent gaston hercules meg tinkerbell wendy pinocchio bambi dumbo thumper flounder sebastian iago abu
pascal maximus heihei goofy donald daisy pluto chip dale bagheera baloo mowgli rafiki zazu piglet tigger eeyore
pooh hades phil jafar rajah tarzan jane kida milo pacha kuzco yzma bolt judy nick gazelle mirabel bruno luisa
isabela cruella dodger tramp lady jiminy figaro cleo shenzi banzai kronk vanellope ralph esmeralda quasimodo
megara belle gus jaq
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
const PIXAR = words(`
jessie rex hamm slinky bo lotso flik heimlich mike sulley boo randall marlin crush bruce gill remy linguini colette
walle eve carl russell dug kevin lightning mater sally doc luigi guido fillmore joy sadness anger fear disgust bing
arlo spot miguel hector dante ian barley luca alberto giulia mei ming elastigirl dash violet jack edna syndrome
forky gabby ducky bunny duke ember wade bing-bong riley
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
const NORSE = words(`
odin thor loki freya frigg baldur tyr heimdall idun bragi njord freyr sif hel ymir fenrir sleipnir ran aegir skadi
vidar vali ullr forseti hermod sigyn nanna jord eir fulla gefjon mimir yggdrasil asgard midgard valhalla bifrost
ragnarok jormungandr hugin munin audhumla surtr
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
const LINDGREN = words(`
pippi emil ida lotta madicken mio ronja birk mattis borka karlsson lillebror rasmus tengil katla skorpan jonatan
nangijala bullerbyn vimmerby lonneberga junibacken villekulla kalle
`)
.map((n) => normalizeName(n))
.filter((n): n is string => n !== null);
function dedupe(list: string[]): string[] {
return [...new Set(list)];
}
/** What a fresh install starts with, and what "restore" puts back. */
export function defaultThemes(): NameTheme[] {
return [
{ id: "swedish-girls", label: "Swedish girl names", names: dedupe(SWEDISH_GIRLS) },
{ id: "swedish-boys", label: "Swedish boy names", names: dedupe(SWEDISH_BOYS) },
{ id: "disney", label: "Disney characters", names: dedupe(DISNEY) },
{ id: "pixar", label: "Pixar characters", names: dedupe(PIXAR) },
{ id: "norse", label: "Norse mythology", names: dedupe(NORSE) },
{ id: "lindgren", label: "Astrid Lindgren", names: dedupe(LINDGREN) },
];
}
export const DEFAULT_THEME_IDS = defaultThemes().map((t) => t.id);
// ─── Validating an edit ──────────────────────────────────────────────────────
export interface InvalidName {
theme: string;
name: string;
}
export class InvalidThemesError extends Error {
constructor(
message: string,
public readonly invalid: InvalidName[] = [],
) {
super(message);
}
}
/**
* Turns whatever the editor sent into clean themes, or throws with a message that says what to fix. Names are folded
* and de-duplicated; a name that can't be made into a hostname-safe one is reported, never silently dropped.
*/
export function cleanThemes(input: { id?: string; label: string; names: string[]; lastImport?: NameThemeSource }[]): NameTheme[] {
if (input.length > MAX_THEMES) throw new InvalidThemesError(`At most ${MAX_THEMES} lists.`);
const usedIds = new Set<string>();
const invalid: InvalidName[] = [];
const out: NameTheme[] = [];
for (const raw of input) {
const label = raw.label.trim();
if (!label) throw new InvalidThemesError("Every list needs a name.");
if (label.length > MAX_LABEL_LENGTH) throw new InvalidThemesError(`“${label}” — list names can be at most ${MAX_LABEL_LENGTH} characters.`);
let id = raw.id && /^[a-z0-9-]{1,40}$/.test(raw.id) ? raw.id : slugifyId(label);
for (let n = 2; usedIds.has(id); n++) id = `${slugifyId(label)}-${n}`;
usedIds.add(id);
const names: string[] = [];
for (const entry of raw.names) {
if (!entry.trim()) continue;
const clean = normalizeName(entry);
if (clean === null) invalid.push({ theme: label, name: entry.trim() });
else names.push(clean);
}
const unique = dedupe(names);
if (unique.length > MAX_NAMES_PER_THEME) throw new InvalidThemesError(`“${label}” has ${unique.length} names — at most ${MAX_NAMES_PER_THEME} per list.`);
out.push({ id, label, names: unique, ...(raw.lastImport ? { lastImport: raw.lastImport } : {}) });
}
if (invalid.length > 0) {
const shown = invalid.slice(0, 5).map((i) => `“${i.name}”`).join(", ");
throw new InvalidThemesError(
`${invalid.length} name${invalid.length === 1 ? " isn't" : "s aren't"} usable as a server name (${shown}${invalid.length > 5 ? ", …" : ""}). Use letters, digits and hyphens, no spaces.`,
invalid,
);
}
return out;
}
/** Reads themes back out of settings defensively — a backup restore or hand-edited row must not be able to break the Generator. */
export function readStoredThemes(stored: unknown): NameTheme[] {
if (!Array.isArray(stored)) return defaultThemes();
const themes: NameTheme[] = [];
for (const t of stored) {
if (!t || typeof t !== "object") continue;
const { id, label, names, lastImport } = t as Partial<NameTheme>;
if (typeof id !== "string" || typeof label !== "string" || !Array.isArray(names)) continue;
themes.push({
id,
label,
names: names.filter((n): n is string => typeof n === "string"),
...(lastImport && typeof lastImport === "object" ? { lastImport } : {}),
});
}
return themes;
}
// ─── Importing from Skatteverket ────────────────────────────────────────────
/**
* Skatteverket's open-data API for "Namn på nyfödda": the most common given names of babies, by sex and birth year,
* for the whole country ("Total"). It needs no key. Statistics Sweden (SCB), which used to publish this, stopped
* after 2023 and points to Skatteverket.
*/
const SKATTEVERKET_DATASET = "https://skatteverket.entryscape.net/rowstore/dataset/da2556d0-c717-45e8-a1d8-3320161d3a7d";
const PAGE_SIZE = 500;
const MAX_PAGES = 4;
const FETCH_TIMEOUT_MS = 20_000;
export interface NameImport {
names: string[];
years: number[];
/** Years that had no data (yet) and were left out. */
missingYears: number[];
/** Names Skatteverket lists that can't be used as a server name (a space, an unusual letter) and were left out. */
skipped: string[];
}
interface Row {
namn?: string;
antal?: string;
rangordning?: string;
}
async function fetchYear(sex: "girls" | "boys", year: number): Promise<Row[]> {
const rows: Row[] = [];
for (let page = 0; page < MAX_PAGES; page++) {
const url = `${SKATTEVERKET_DATASET}?gruppering=Total&fodelsear=${year}&k%C3%B6n=${sex === "girls" ? "Kvinna" : "Man"}&_limit=${PAGE_SIZE}&_offset=${page * PAGE_SIZE}`;
const res = await fetch(url, { signal: AbortSignal.timeout(FETCH_TIMEOUT_MS), headers: { Accept: "application/json" } });
if (!res.ok) throw new Error(`Skatteverket's name service answered ${res.status}.`);
const body = (await res.json()) as { results?: Row[] };
const results = Array.isArray(body.results) ? body.results : [];
rows.push(...results);
if (results.length < PAGE_SIZE) break;
}
return rows;
}
/**
* The most common names over the last `yearCount` full calendar years (the running year is only partly counted, so it's
* skipped). Counts are added up across years, so one unusually popular year doesn't decide the list.
*/
export async function importSkatteverketNames(sex: "girls" | "boys", yearCount: number, count: number, now = new Date()): Promise<NameImport> {
const wanted = Array.from({ length: yearCount }, (_, i) => now.getUTCFullYear() - 1 - i);
const totals = new Map<string, number>();
const skipped = new Set<string>();
const years: number[] = [];
const missingYears: number[] = [];
for (const year of wanted) {
let rows: Row[];
try {
rows = await fetchYear(sex, year);
} catch (err) {
if (err instanceof Error && err.name === "TimeoutError") throw new Error("Skatteverket's name service didn't answer in time.");
throw err;
}
if (rows.length === 0) {
missingYears.push(year);
continue;
}
years.push(year);
for (const row of rows) {
const raw = (row.namn ?? "").trim();
const amount = Number(row.antal);
if (!raw || !Number.isFinite(amount)) continue;
const clean = normalizeName(raw);
if (clean === null) {
skipped.add(raw);
continue;
}
totals.set(clean, (totals.get(clean) ?? 0) + amount);
}
}
if (years.length === 0) throw new Error("Skatteverket has no name statistics for those years.");
const names = [...totals.entries()]
.sort((a, b) => b[1] - a[1] || a[0].localeCompare(b[0], "sv"))
.slice(0, count)
.map(([name]) => name);
return { names, years: years.sort((a, b) => a - b), missingYears, skipped: [...skipped].sort((a, b) => a.localeCompare(b, "sv")) };
}
+8
View File
@@ -1,6 +1,7 @@
import { sql } from "drizzle-orm";
import { db } from "../db/client.js";
import { settings } from "../db/schema.js";
import { defaultThemes, type NameTheme } from "./nameThemes.js";
export interface GotifySettings {
enabled: boolean;
@@ -99,6 +100,11 @@ export interface ConsistencySettings {
excludedRanges: string[];
}
export interface NameGeneratorSettings {
/** The lists the Generator picks server names from — edited under Settings → Names. */
themes: NameTheme[];
}
export interface AppSettings {
gotify: GotifySettings;
ntfy: NtfySettings;
@@ -112,6 +118,7 @@ export interface AppSettings {
quietHours: QuietHoursSettings;
healthChecks: HealthCheckSettings;
consistency: ConsistencySettings;
nameGenerator: NameGeneratorSettings;
}
const DEFAULTS: AppSettings = {
@@ -145,6 +152,7 @@ const DEFAULTS: AppSettings = {
// Docker's default bridge (172.17.0.0/16) and the pool it hands custom networks from (172.18–31) live here, and every
// Docker host repeats them. Shown on the Consistency page, where it can be removed if 172.16/12 is used as a real LAN.
consistency: { excludedRanges: ["172.16.0.0/12"] },
nameGenerator: { themes: defaultThemes() },
};
const KEYS = Object.keys(DEFAULTS) as (keyof AppSettings)[];