Shveiauto commited on
Commit
4e9cca7
·
verified ·
1 Parent(s): e62320e

Update app.py

Browse files
Files changed (1) hide show
  1. app.py +279 -409
app.py CHANGED
@@ -1,4 +1,4 @@
1
- from flask import Flask, render_template_string, request, redirect, url_for, jsonify, flash, send_from_directory
2
  import json
3
  import os
4
  import logging
@@ -20,31 +20,18 @@ app = Flask(__name__)
20
  app.secret_key = os.getenv("FLASK_SECRET_KEY", 'tontalent_secret_key_for_flash_messages_only')
21
  DATA_FILE = 'tontalent_data.json'
22
  SYNC_FILES = [DATA_FILE]
23
- UPLOAD_FOLDER = 'tontalent_uploads'
24
- ALLOWED_EXTENSIONS = {'png', 'jpg', 'jpeg', 'gif'}
25
- app.config['UPLOAD_FOLDER'] = UPLOAD_FOLDER
26
- app.config['MAX_CONTENT_LENGTH'] = 16 * 1024 * 1024
27
 
28
  REPO_ID = os.getenv("HF_REPO_ID", "Kgshop/tontalent2")
29
  HF_TOKEN_WRITE = os.getenv("HF_TOKEN_WRITE")
30
  HF_TOKEN_READ = os.getenv("HF_TOKEN_READ")
31
 
32
- TELEGRAM_BOT_TOKEN = "7549355625:AAGhdbf6x1JEzpH0mUtuxTF83Soi7MFVNZ8"
33
 
34
  DOWNLOAD_RETRIES = 3
35
  DOWNLOAD_DELAY = 5
36
 
37
  logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
38
 
39
- def allowed_file(filename):
40
- return '.' in filename and \
41
- filename.rsplit('.', 1)[1].lower() in ALLOWED_EXTENSIONS
42
-
43
- def ensure_upload_folder():
44
- if not os.path.exists(UPLOAD_FOLDER):
45
- os.makedirs(UPLOAD_FOLDER)
46
- logging.info(f"Created upload folder: {UPLOAD_FOLDER}")
47
-
48
  def download_db_from_hf(specific_file=None, retries=DOWNLOAD_RETRIES, delay=DOWNLOAD_DELAY):
49
  if not HF_TOKEN_READ and not HF_TOKEN_WRITE:
50
  logging.warning("HF_TOKEN_READ/HF_TOKEN_WRITE not set. Download might fail for private repos.")
@@ -209,12 +196,13 @@ def verify_telegram_auth_data(auth_data_str, bot_token):
209
  return False, None
210
  return False, None
211
 
 
212
  MAIN_APP_TEMPLATE = '''
213
  <!DOCTYPE html>
214
  <html lang="en">
215
  <head>
216
  <meta charset="UTF-8">
217
- <meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no">
218
  <title>TonTalent</title>
219
  <script src="https://telegram.org/js/telegram-web-app.js"></script>
220
  <style>
@@ -231,17 +219,9 @@ MAIN_APP_TEMPLATE = '''
231
  --tg-theme-section-header-text-color: #8e8e93;
232
  --tg-theme-destructive-text-color: #ff3b30;
233
  --tg-theme-accent-text-color: #007aff;
234
- --system-font: -apple-system, BlinkMacSystemFont, "Segoe UI", "Roboto", "Helvetica Neue", Arial, sans-serif;
235
- --border-radius-s: 8px;
236
- --border-radius-m: 12px;
237
- --spacing-xs: 4px;
238
- --spacing-s: 8px;
239
- --spacing-m: 12px;
240
- --spacing-l: 16px;
241
- --spacing-xl: 20px;
242
  }
243
  body {
244
- font-family: var(--system-font);
245
  margin: 0;
246
  padding: 0;
247
  background-color: var(--tg-theme-bg-color);
@@ -249,46 +229,44 @@ MAIN_APP_TEMPLATE = '''
249
  overscroll-behavior-y: none;
250
  -webkit-font-smoothing: antialiased;
251
  -moz-osx-font-smoothing: grayscale;
252
- line-height: 1.4;
 
 
 
253
  }
254
- .app-container { display: flex; flex-direction: column; min-height: 100vh; }
255
- .header {
256
  background-color: var(--tg-theme-header-bg-color);
257
- padding: var(--spacing-m) var(--spacing-l);
258
- text-align: center;
259
- font-weight: 600;
260
- font-size: 18px;
261
  border-bottom: 1px solid var(--tg-theme-secondary-bg-color);
262
  position: sticky;
263
  top: 0;
264
  z-index: 100;
265
  }
266
- .user-info-bar {
 
267
  display: flex;
268
  align-items: center;
269
- padding: var(--spacing-s) var(--spacing-l);
270
  background-color: var(--tg-theme-secondary-bg-color);
271
- border-bottom: 1px solid var(--tg-theme-secondary-bg-color);
272
  }
273
- .user-avatar {
274
- width: 36px;
275
- height: 36px;
276
  border-radius: 50%;
277
- margin-right: var(--spacing-m);
278
- background-color: var(--tg-theme-hint-color); /* Placeholder */
279
  object-fit: cover;
 
 
280
  }
281
- .user-details {
282
- font-size: 14px;
283
- color: var(--tg-theme-text-color);
284
- }
285
- .user-details strong { font-weight: 500; }
286
- .user-details span { color: var(--tg-theme-hint-color); font-size: 12px; }
287
 
288
- .tabs { display: flex; background-color: var(--tg-theme-bg-color); padding: var(--spacing-s); border-bottom: 1px solid var(--tg-theme-secondary-bg-color); }
289
  .tab-button {
290
  flex: 1;
291
- padding: var(--spacing-m);
292
  text-align: center;
293
  cursor: pointer;
294
  background: none;
@@ -297,55 +275,55 @@ MAIN_APP_TEMPLATE = '''
297
  font-size: 15px;
298
  font-weight: 500;
299
  border-bottom: 3px solid transparent;
300
- transition: color 0.2s ease, border-bottom-color 0.2s ease;
 
301
  }
302
- .tab-button.active { color: var(--tg-theme-link-color); border-bottom-color: var(--tg-theme-link-color); font-weight: 600; }
303
- .content { flex-grow: 1; padding: var(--spacing-l); overflow-x: hidden; }
304
- .content.entering { animation: fadeIn 0.3s ease-out; }
305
- .content.detail-view-entering { animation: slideInFromRight 0.3s ease-out; }
306
- .content.form-view-entering { animation: slideInFromRight 0.3s ease-out; }
307
-
308
- @keyframes fadeIn { from { opacity: 0; } to { opacity: 1; } }
309
- @keyframes slideInFromRight { from { opacity: 0; transform: translateX(20px); } to { opacity: 1; transform: translateX(0); } }
310
-
311
  .list-item {
312
  background-color: var(--tg-theme-section-bg-color);
313
- border-radius: var(--border-radius-m);
314
- padding: var(--spacing-m) var(--spacing-l);
315
- margin-bottom: var(--spacing-m);
316
- box-shadow: 0 2px 8px rgba(0,0,0,0.08);
317
  cursor: pointer;
318
- transition: transform 0.15s ease-out, background-color 0.15s ease-out;
319
  }
320
- .list-item:active { transform: scale(0.98); background-color: var(--tg-theme-secondary-bg-color); }
321
- .list-item-header { display: flex; align-items: center; margin-bottom: var(--spacing-s); }
322
- .list-item-image { width: 50px; height: 50px; border-radius: var(--border-radius-s); object-fit: cover; margin-right: var(--spacing-m); background-color: var(--tg-theme-secondary-bg-color); }
323
- .list-item-text h3 { margin: 0 0 var(--spacing-xs) 0; font-size: 17px; font-weight: 600; color: var(--tg-theme-text-color); }
324
- .list-item-text p { margin: 0 0 var(--spacing-xs) 0; font-size: 14px; color: var(--tg-theme-hint-color); }
325
- .list-item .meta { font-size: 12px; color: var(--tg-theme-hint-color); margin-top: var(--spacing-s); }
326
 
327
- .form-container { padding: var(--spacing-l); background-color: var(--tg-theme-section-bg-color); }
328
- .form-group { margin-bottom: var(--spacing-l); }
329
- .form-group label { display: block; font-size: 14px; color: var(--tg-theme-section-header-text-color); margin-bottom: var(--spacing-s); font-weight: 500; }
330
- .form-group input, .form-group textarea, .form-group input[type="file"] {
331
  width: 100%;
332
- padding: var(--spacing-m);
333
  border: 1px solid var(--tg-theme-secondary-bg-color);
334
- border-radius: var(--border-radius-s);
335
  font-size: 16px;
336
  background-color: var(--tg-theme-bg-color);
337
  color: var(--tg-theme-text-color);
338
  box-sizing: border-box;
339
- font-family: var(--system-font);
 
 
 
 
340
  }
341
- .form-group input[type="file"] { padding: var(--spacing-s); }
342
  .form-group textarea { min-height: 100px; resize: vertical; }
343
- .form-group input:focus, .form-group textarea:focus { border-color: var(--tg-theme-link-color); box-shadow: 0 0 0 2px var(--tg-theme-link-color-alpha, rgba(0,122,255,0.2)); outline: none; }
344
 
345
  .fab {
346
  position: fixed;
347
- bottom: var(--spacing-xl);
348
- right: var(--spacing-xl);
349
  width: 56px;
350
  height: 56px;
351
  background-color: var(--tg-theme-button-color);
@@ -360,30 +338,50 @@ MAIN_APP_TEMPLATE = '''
360
  cursor: pointer;
361
  z-index: 1000;
362
  border: none;
363
- transition: transform 0.2s ease;
 
364
  }
365
- .fab:active { transform: scale(0.95); }
366
-
367
- .detail-view { padding: var(--spacing-l); background-color: var(--tg-theme-section-bg-color); }
368
- .detail-view img.item-image-large { width: 100%; max-height: 300px; object-fit: cover; border-radius: var(--border-radius-m); margin-bottom: var(--spacing-l); background-color: var(--tg-theme-secondary-bg-color); }
369
- .detail-view h2 { margin-top: 0; font-size: 22px; font-weight: 600; color: var(--tg-theme-text-color); margin-bottom: var(--spacing-s); }
370
- .detail-view p { margin-bottom: var(--spacing-m); line-height: 1.6; font-size: 16px; }
371
- .detail-view strong { font-weight: 500; color: var(--tg-theme-section-header-text-color); }
372
- .detail-view .meta { font-size: 13px; color: var(--tg-theme-hint-color); margin-top: var(--spacing-l); }
373
  .detail-view a { color: var(--tg-theme-link-color); text-decoration: none; }
374
  .detail-view a:hover { text-decoration: underline; }
 
375
 
376
- .loading, .empty-state { text-align: center; padding: 50px var(--spacing-l); color: var(--tg-theme-hint-color); font-size: 16px; }
377
- .error-message { color: var(--tg-theme-destructive-text-color); font-size: 14px; margin-top: var(--spacing-s); }
378
- .image-preview { max-width: 100px; max-height: 100px; margin-top: var(--spacing-s); border-radius: var(--border-radius-s); }
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
379
  </style>
380
  </head>
381
  <body>
382
  <div class="app-container">
383
- <div class="header">TonTalent</div>
384
- <div class="user-info-bar" id="userInfoContainer">
385
- <img src="" alt="User Avatar" class="user-avatar" id="userAvatar" style="display:none;">
386
- <div class="user-details" id="userInfo">Loading user...</div>
 
 
 
 
 
387
  </div>
388
  <div class="tabs">
389
  <button class="tab-button active" data-tab="resumes">Resumes</button>
@@ -401,6 +399,10 @@ MAIN_APP_TEMPLATE = '''
401
  let currentUser = null;
402
  let currentView = 'resumes';
403
  let currentItem = null;
 
 
 
 
404
  const mainContentEl = document.getElementById('mainContent');
405
 
406
  function applyThemeParams() {
@@ -417,245 +419,196 @@ MAIN_APP_TEMPLATE = '''
417
  root.style.setProperty('--tg-theme-section-header-text-color', tg.themeParams.section_header_text_color || tg.themeParams.hint_color || '#8e8e93');
418
  root.style.setProperty('--tg-theme-destructive-text-color', tg.themeParams.destructive_text_color || '#ff3b30');
419
  root.style.setProperty('--tg-theme-accent-text-color', tg.themeParams.accent_text_color || tg.themeParams.link_color || '#007aff');
420
- root.style.setProperty('--tg-theme-link-color-alpha', (tg.themeParams.link_color || '#007aff') + '33');
421
  }
422
 
423
  async function apiCall(endpoint, method = 'GET', body = null) {
424
- const headers = {};
425
- if (!(body instanceof FormData)) {
426
- headers['Content-Type'] = 'application/json';
427
- }
428
  if (tg.initData) {
429
  headers['X-Telegram-Auth'] = tg.initData;
430
  }
431
  const options = { method, headers };
432
- if (body) {
433
- options.body = (body instanceof FormData) ? body : JSON.stringify(body);
434
- }
435
-
436
- tg.MainButton.showProgress();
437
  try {
438
  const response = await fetch(endpoint, options);
439
  if (!response.ok) {
440
- const errorData = await response.json().catch(() => ({ error: 'Request failed, server returned non-JSON response' }));
441
  throw new Error(errorData.error || `HTTP error ${response.status}`);
442
  }
443
  return response.json();
444
  } catch (error) {
445
  console.error('API Call Error:', error);
446
  tg.showAlert(error.message || 'An API error occurred.');
447
- tg.HapticFeedback.notificationOccurred('error');
448
  throw error;
449
- } finally {
450
- tg.MainButton.hideProgress();
451
  }
452
  }
453
 
454
  function renderList(items, type) {
455
- mainContentEl.classList.remove('detail-view-entering', 'form-view-entering');
456
- mainContentEl.classList.add('entering');
457
  if (!items || items.length === 0) {
458
- mainContentEl.innerHTML = `<div class="empty-state">No ${type} found. Be the first to add one!</div>`;
459
  return;
460
  }
461
- mainContentEl.innerHTML = items.map(item => `
462
  <div class="list-item" onclick="showDetailView('${type}', '${item.id}')">
463
- <div class="list-item-header">
464
- ${item.image_filename ? `<img src="/uploads/${item.image_filename}" class="list-item-image" alt="${item.title || item.name || 'Item image'}">` : `<div class="list-item-image"></div>`}
465
- <div class="list-item-text">
466
- <h3>${item.title || item.name || 'Untitled'}</h3>
467
- ${type === 'vacancies' && item.company_name ? `<p>${item.company_name}</p>` : ''}
468
- ${type === 'freelance_offers' && item.budget ? `<p>Budget: ${item.budget}</p>` : ''}
469
- </div>
470
- </div>
471
  <p class="meta">Posted by: @${item.user_telegram_username || 'anonymous'} on ${new Date(item.timestamp).toLocaleDateString()}</p>
472
  </div>
473
  `).join('');
474
- setTimeout(() => mainContentEl.classList.remove('entering'), 300);
475
  }
476
 
477
  function showDetailView(type, id) {
478
  tg.BackButton.show();
479
  tg.BackButton.onClick(() => {
480
  loadView(type);
481
- tg.HapticFeedback.impactOccurred('light');
482
  });
483
  tg.MainButton.hide();
484
  document.getElementById('fabButton').style.display = 'none';
485
- mainContentEl.classList.remove('entering', 'form-view-entering');
486
- mainContentEl.classList.add('detail-view-entering');
487
 
488
  apiCall(`/api/${type}/${id}`)
489
  .then(item => {
490
  currentItem = item;
491
- let detailsHtml = `<div class="detail-view">`;
492
- if (item.image_filename) {
493
- detailsHtml += `<img src="/uploads/${item.image_filename}" class="item-image-large" alt="${item.title || item.name}">`;
494
- }
495
- detailsHtml += `<h2>${item.title || item.name}</h2>`;
496
 
 
 
497
  if (type === 'resumes') {
498
  detailsHtml += `
499
- <p><strong>Skills:</strong> ${item.skills || 'N/A'}</p>
500
- <p><strong>Experience:</strong><br>${item.experience ? item.experience.replace(/\\n/g, '<br>') : 'N/A'}</p>
501
- <p><strong>Education:</strong><br>${item.education ? item.education.replace(/\\n/g, '<br>') : 'N/A'}</p>
502
  <p><strong>Contact:</strong> ${item.contact || `@${item.user_telegram_username}`}</p>
503
  ${item.portfolio_link ? `<p><strong>Portfolio:</strong> <a href="${item.portfolio_link}" target="_blank" rel="noopener noreferrer">${item.portfolio_link}</a></p>` : ''}
504
  `;
505
  } else if (type === 'vacancies') {
506
  detailsHtml += `
507
  <p><strong>Company:</strong> ${item.company_name || 'N/A'}</p>
508
- <p><strong>Description:</strong><br>${item.description ? item.description.replace(/\\n/g, '<br>') : 'N/A'}</p>
509
- <p><strong>Requirements:</strong><br>${item.requirements ? item.requirements.replace(/\\n/g, '<br>') : 'N/A'}</p>
510
  <p><strong>Salary:</strong> ${item.salary || 'N/A'}</p>
511
  <p><strong>Location:</strong> ${item.location || 'N/A'}</p>
512
- <p><strong>Contact/Apply:</strong> ${item.contact || `@${item.user_telegram_username}`}</p>
513
  `;
514
  } else if (type === 'freelance_offers') {
515
  detailsHtml += `
516
- <p><strong>Description:</strong><br>${item.description ? item.description.replace(/\\n/g, '<br>') : 'N/A'}</p>
517
  <p><strong>Budget:</strong> ${item.budget || 'N/A'}</p>
518
  <p><strong>Deadline:</strong> ${item.deadline || 'N/A'}</p>
519
- <p><strong>Skills Needed:</strong> ${item.skills_needed || 'N/A'}</p>
520
  <p><strong>Contact:</strong> ${item.contact || `@${item.user_telegram_username}`}</p>
521
  `;
522
  }
523
- detailsHtml += `<p class="meta">Posted by: @${item.user_telegram_username || 'anonymous'} on ${new Date(item.timestamp).toLocaleDateString()}</p></div>`;
524
- mainContentEl.innerHTML = detailsHtml;
525
- setTimeout(() => mainContentEl.classList.remove('detail-view-entering'), 300);
526
-
527
  if (currentUser && item.user_id === String(currentUser.id)) {
528
- tg.MainButton.setText('Edit My Post');
529
- tg.MainButton.onClick(() => {
530
- showForm(type, item);
531
- tg.HapticFeedback.impactOccurred('light');
532
- });
533
- tg.MainButton.show();
534
  }
 
 
 
535
  })
536
  .catch(err => {
537
- mainContentEl.innerHTML = `<div class="empty-state">Error loading details. Please try again.</div>`;
 
538
  });
539
  }
540
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
541
  function showForm(type, itemToEdit = null) {
542
  currentItem = itemToEdit;
543
  tg.BackButton.show();
544
  tg.BackButton.onClick(() => {
 
545
  if (itemToEdit) showDetailView(type, itemToEdit.id);
546
  else loadView(type);
547
- tg.HapticFeedback.impactOccurred('light');
548
  });
549
  document.getElementById('fabButton').style.display = 'none';
550
- mainContentEl.classList.remove('entering', 'detail-view-entering');
551
- mainContentEl.classList.add('form-view-entering');
552
 
553
- let formHtml = `<div class="form-container"><h2>${itemToEdit ? 'Edit' : 'New'} ${type.charAt(0).toUpperCase() + type.slice(1, -1)}</h2>`;
 
554
 
555
- const commonFields = `
556
- <div class="form-group">
557
- <label for="item_image">Image (Optional)</label>
558
- <input type="file" id="item_image" name="item_image" accept="image/png, image/jpeg, image/gif">
559
- ${itemToEdit && itemToEdit.image_filename ? `<img src="/uploads/${itemToEdit.image_filename}" class="image-preview" alt="Current image">` : ''}
560
- </div>
561
- `;
562
-
563
  if (type === 'resumes') {
564
  formHtml += `
565
- <div class="form-group">
566
- <label for="name">Full Name*</label>
567
- <input type="text" id="name" value="${itemToEdit?.name || ''}" required>
568
- </div>
569
- <div class="form-group">
570
- <label for="title">Job Title / Desired Position*</label>
571
- <input type="text" id="title" value="${itemToEdit?.title || ''}" required>
572
- </div>
573
- <div class="form-group">
574
- <label for="skills">Skills (comma separated)</label>
575
- <textarea id="skills">${itemToEdit?.skills || ''}</textarea>
576
- </div>
577
- <div class="form-group">
578
- <label for="experience">Experience</label>
579
- <textarea id="experience">${itemToEdit?.experience || ''}</textarea>
580
- </div>
581
- <div class="form-group">
582
- <label for="education">Education</label>
583
- <textarea id="education">${itemToEdit?.education || ''}</textarea>
584
- </div>
585
- <div class="form-group">
586
- <label for="contact">Contact Info (e.g., email, or blank for Telegram)</label>
587
- <input type="text" id="contact" value="${itemToEdit?.contact || ''}">
588
- </div>
589
- <div class="form-group">
590
- <label for="portfolio_link">Portfolio Link (optional)</label>
591
- <input type="url" id="portfolio_link" value="${itemToEdit?.portfolio_link || ''}">
592
- </div>
593
- ${commonFields}
594
  `;
595
  } else if (type === 'vacancies') {
596
  formHtml += `
597
- <div class="form-group">
598
- <label for="company_name">Company Name*</label>
599
- <input type="text" id="company_name" value="${itemToEdit?.company_name || ''}" required>
600
- </div>
601
- <div class="form-group">
602
- <label for="title">Job Title*</label>
603
- <input type="text" id="title" value="${itemToEdit?.title || ''}" required>
604
- </div>
605
- <div class="form-group">
606
- <label for="description">Description</label>
607
- <textarea id="description">${itemToEdit?.description || ''}</textarea>
608
- </div>
609
- <div class="form-group">
610
- <label for="requirements">Requirements</label>
611
- <textarea id="requirements">${itemToEdit?.requirements || ''}</textarea>
612
- </div>
613
- <div class="form-group">
614
- <label for="salary">Salary/Compensation</label>
615
- <input type="text" id="salary" value="${itemToEdit?.salary || ''}">
616
- </div>
617
- <div class="form-group">
618
- <label for="location">Location (e.g., Remote, City)</label>
619
- <input type="text" id="location" value="${itemToEdit?.location || ''}">
620
- </div>
621
- <div class="form-group">
622
- <label for="contact">Contact Info / How to Apply</label>
623
- <textarea id="contact">${itemToEdit?.contact || ''}</textarea>
624
- </div>
625
- ${commonFields}
626
  `;
627
  } else if (type === 'freelance_offers') {
628
  formHtml += `
629
- <div class="form-group">
630
- <label for="title">Project Title*</label>
631
- <input type="text" id="title" value="${itemToEdit?.title || ''}" required>
632
- </div>
633
- <div class="form-group">
634
- <label for="description">Description of Work</label>
635
- <textarea id="description">${itemToEdit?.description || ''}</textarea>
636
- </div>
637
- <div class="form-group">
638
- <label for="budget">Budget</label>
639
- <input type="text" id="budget" value="${itemToEdit?.budget || ''}">
640
- </div>
641
- <div class="form-group">
642
- <label for="deadline">Expected Deadline</label>
643
- <input type="text" id="deadline" value="${itemToEdit?.deadline || ''}">
644
- </div>
645
- <div class="form-group">
646
- <label for="skills_needed">Skills Needed (comma separated)</label>
647
- <textarea id="skills_needed">${itemToEdit?.skills_needed || ''}</textarea>
648
- </div>
649
- <div class="form-group">
650
- <label for="contact">Contact Info (or blank for Telegram)</label>
651
- <input type="text" id="contact" value="${itemToEdit?.contact || ''}">
652
- </div>
653
- ${commonFields}
654
  `;
655
  }
656
  formHtml += `<div id="formError" class="error-message"></div></div>`;
657
- mainContentEl.innerHTML = formHtml;
658
- setTimeout(() => mainContentEl.classList.remove('form-view-entering'), 300);
659
 
660
  tg.MainButton.setText(itemToEdit ? 'Save Changes' : 'Post');
661
  tg.MainButton.show();
@@ -696,31 +649,26 @@ MAIN_APP_TEMPLATE = '''
696
  }
697
 
698
  if (!isValid) {
699
- document.getElementById('formError').textContent = 'Please fill in all required fields (marked with *).';
700
  tg.HapticFeedback.notificationOccurred('error');
701
  return;
702
  }
703
 
704
- const formData = new FormData();
705
- for (const key in payload) {
706
- formData.append(key, payload[key]);
707
- }
708
- const imageInput = document.getElementById('item_image');
709
- if (imageInput && imageInput.files[0]) {
710
- formData.append('item_image', imageInput.files[0]);
711
- }
712
 
713
  const method = itemId ? 'PUT' : 'POST';
714
  const endpoint = itemId ? `/api/${type}/${itemId}` : `/api/${type}`;
715
 
716
- apiCall(endpoint, method, formData)
717
  .then(response => {
718
  tg.HapticFeedback.notificationOccurred('success');
 
719
  loadView(type);
720
  })
721
  .catch(err => {
722
  tg.HapticFeedback.notificationOccurred('error');
723
- document.getElementById('formError').textContent = err.message || 'Failed to submit. Please try again.';
 
724
  });
725
  }
726
 
@@ -730,6 +678,7 @@ MAIN_APP_TEMPLATE = '''
730
  document.querySelector(`.tab-button[data-tab="${tabName}"]`).classList.add('active');
731
 
732
  mainContentEl.innerHTML = `<div class="loading">Loading ${tabName}...</div>`;
 
733
  tg.BackButton.hide();
734
  tg.MainButton.hide();
735
  document.getElementById('fabButton').style.display = 'block';
@@ -737,89 +686,74 @@ MAIN_APP_TEMPLATE = '''
737
  apiCall(`/api/${tabName}`)
738
  .then(data => renderList(data, tabName))
739
  .catch(err => {
740
- mainContentEl.innerHTML = `<div class="empty-state">Error loading ${tabName}. Please check your connection.</div>`;
 
741
  });
742
  }
743
 
744
- let touchstartX = 0;
745
- let touchendX = 0;
746
- let touchstartY = 0;
747
- let touchendY = 0;
748
- const swipeThreshold = 75;
749
- const swipeArea = mainContentEl;
750
-
751
- swipeArea.addEventListener('touchstart', function(event) {
752
  touchstartX = event.changedTouches[0].screenX;
753
- touchstartY = event.changedTouches[0].screenY;
754
  }, { passive: true });
755
 
756
- swipeArea.addEventListener('touchend', function(event) {
757
  touchendX = event.changedTouches[0].screenX;
758
- touchendY = event.changedTouches[0].screenY;
759
- handleSwipe();
760
  }, { passive: true });
761
 
762
- function handleSwipe() {
763
- const deltaX = touchendX - touchstartX;
764
- const deltaY = Math.abs(touchendY - touchstartY);
765
-
766
- if (Math.abs(deltaX) > swipeThreshold && deltaY < Math.abs(deltaX) / 2) { // Horizontal swipe, not too vertical
767
- const tabs = ['resumes', 'vacancies', 'freelance_offers'];
768
- let currentIndex = tabs.indexOf(currentView);
769
- if (deltaX < 0) { // Swiped left
770
- currentIndex = (currentIndex + 1) % tabs.length;
771
- } else { // Swiped right
772
- currentIndex = (currentIndex - 1 + tabs.length) % tabs.length;
773
- }
774
- if (tabs[currentIndex] !== currentView) {
775
- loadView(tabs[currentIndex]);
776
  tg.HapticFeedback.selectionChanged();
777
  }
778
  }
779
  }
780
 
781
- function displayUserInfo(user) {
782
- const userInfoDiv = document.getElementById('userInfo');
783
- const userAvatarEl = document.getElementById('userAvatar');
784
- let displayName = user.first_name || 'User';
785
- if (user.last_name) displayName += ' ' + user.last_name;
786
- let usernameString = user.username ? `(@${user.username})` : '(anonymous)';
787
-
788
- if (user.photo_url) {
789
- userAvatarEl.src = user.photo_url;
790
- userAvatarEl.style.display = 'inline-block';
791
- } else {
792
- userAvatarEl.style.display = 'none';
793
- }
794
- userInfoDiv.innerHTML = `<strong>${displayName}</strong><br><span>${usernameString}</span>`;
795
- }
796
-
797
  async function init() {
798
  tg.ready();
799
  applyThemeParams();
 
800
  tg.expand();
801
  tg.enableClosingConfirmation();
802
-
803
- const tgUser = tg.initDataUnsafe.user;
804
- if (tgUser) {
805
- displayUserInfo({
806
- first_name: tgUser.first_name,
807
- last_name: tgUser.last_name,
808
- username: tgUser.username,
809
- photo_url: tgUser.photo_url
810
- });
811
- }
812
 
813
  try {
814
  const authResponse = await apiCall('/api/auth_user', 'POST', { init_data: tg.initData });
815
  currentUser = authResponse.user;
816
  if (currentUser) {
817
- displayUserInfo(currentUser);
818
- }
 
 
 
 
 
 
 
 
819
  } catch (error) {
820
  console.error("Auth error:", error);
821
- document.getElementById('userInfo').innerHTML = `<strong>Authentication Failed</strong><br><span>Limited functionality</span>`;
822
- tg.showAlert("Authentication with the server failed. Some features might not work correctly.");
 
 
 
 
 
 
823
  }
824
 
825
  document.querySelectorAll('.tab-button').forEach(button => {
@@ -835,7 +769,6 @@ MAIN_APP_TEMPLATE = '''
835
 
836
  loadView('resumes');
837
  }
838
-
839
  init();
840
  </script>
841
  </body>
@@ -858,7 +791,6 @@ ADMIN_TEMPLATE = '''
858
  .item:last-child { border-bottom: none; }
859
  .item h3 { margin: 0 0 5px 0; }
860
  .item p { margin: 3px 0; font-size: 0.9em; color: #555; }
861
- .item img { max-width: 100px; max-height: 100px; border-radius: 4px; margin-top: 5px;}
862
  .button { padding: 8px 15px; border: none; border-radius: 4px; cursor: pointer; font-size: 0.9em; margin-right: 5px; }
863
  .button-primary { background-color: #007bff; color: white; }
864
  .button-danger { background-color: #dc3545; color: white; }
@@ -892,7 +824,7 @@ ADMIN_TEMPLATE = '''
892
  <button type="submit" class="button button-secondary">Download DB from HF</button>
893
  </form>
894
  </div>
895
- <p style="font-size: 0.8em; color: #666;">Automatic backup runs every 30 minutes if HF_TOKEN_WRITE is set. Images are NOT synced to HF, only their references in the database.</p>
896
  </div>
897
 
898
  <div class="section">
@@ -902,9 +834,6 @@ ADMIN_TEMPLATE = '''
902
  <h3>{{ resume.name }} - {{ resume.title }}</h3>
903
  <p>User ID: {{ resume.user_id }} (@{{ resume.user_telegram_username }})</p>
904
  <p>Posted: {{ resume.timestamp }}</p>
905
- {% if resume.image_filename %}
906
- <img src="{{ url_for('uploaded_file', filename=resume.image_filename) }}" alt="Resume image">
907
- {% endif %}
908
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this resume?');">
909
  <input type="hidden" name="item_type" value="resumes">
910
  <input type="hidden" name="item_id" value="{{ resume.id }}">
@@ -923,9 +852,6 @@ ADMIN_TEMPLATE = '''
923
  <h3>{{ vacancy.title }} - {{ vacancy.company_name }}</h3>
924
  <p>User ID: {{ vacancy.user_id }} (@{{ vacancy.user_telegram_username }})</p>
925
  <p>Posted: {{ vacancy.timestamp }}</p>
926
- {% if vacancy.image_filename %}
927
- <img src="{{ url_for('uploaded_file', filename=vacancy.image_filename) }}" alt="Vacancy image">
928
- {% endif %}
929
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this vacancy?');">
930
  <input type="hidden" name="item_type" value="vacancies">
931
  <input type="hidden" name="item_id" value="{{ vacancy.id }}">
@@ -945,9 +871,6 @@ ADMIN_TEMPLATE = '''
945
  <p>User ID: {{ offer.user_id }} (@{{ offer.user_telegram_username }})</p>
946
  <p>Budget: {{ offer.budget }}</p>
947
  <p>Posted: {{ offer.timestamp }}</p>
948
- {% if offer.image_filename %}
949
- <img src="{{ url_for('uploaded_file', filename=offer.image_filename) }}" alt="Offer image">
950
- {% endif %}
951
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this freelance offer?');">
952
  <input type="hidden" name="item_type" value="freelance_offers">
953
  <input type="hidden" name="item_id" value="{{ offer.id }}">
@@ -967,10 +890,6 @@ ADMIN_TEMPLATE = '''
967
  def main_app_view():
968
  return render_template_string(MAIN_APP_TEMPLATE)
969
 
970
- @app.route('/uploads/<path:filename>')
971
- def uploaded_file(filename):
972
- return send_from_directory(app.config['UPLOAD_FOLDER'], filename)
973
-
974
  @app.route('/api/auth_user', methods=['POST'])
975
  def auth_user():
976
  auth_data_str = request.headers.get('X-Telegram-Auth')
@@ -981,50 +900,40 @@ def auth_user():
981
  else:
982
  return jsonify({"error": "Authentication data not provided"}), 401
983
 
984
- is_valid, user_data_from_tg = verify_telegram_auth_data(auth_data_str, TELEGRAM_BOT_TOKEN)
985
 
986
- if not is_valid or not user_data_from_tg:
987
  return jsonify({"error": "Invalid authentication data"}), 403
988
 
989
  data = load_data()
990
  users = data.get('users', {})
991
- user_id_str = str(user_data_from_tg.get('id'))
992
 
993
  if user_id_str not in users:
994
  users[user_id_str] = {
995
- 'id': user_data_from_tg.get('id'),
996
- 'first_name': user_data_from_tg.get('first_name'),
997
- 'last_name': user_data_from_tg.get('last_name'),
998
- 'username': user_data_from_tg.get('username'),
999
- 'language_code': user_data_from_tg.get('language_code'),
1000
- 'photo_url': user_data_from_tg.get('photo_url'),
1001
  'first_seen': datetime.now().isoformat()
1002
  }
1003
- else: # Update user data if it changed in TG
1004
- users[user_id_str].update({
1005
- 'first_name': user_data_from_tg.get('first_name'),
1006
- 'last_name': user_data_from_tg.get('last_name'),
1007
- 'username': user_data_from_tg.get('username'),
1008
- 'language_code': user_data_from_tg.get('language_code'),
1009
- 'photo_url': user_data_from_tg.get('photo_url'),
1010
- })
1011
-
1012
  users[user_id_str]['last_seen'] = datetime.now().isoformat()
 
 
1013
  data['users'] = users
1014
  save_data(data)
1015
 
1016
  return jsonify({"message": "User authenticated", "user": users[user_id_str]}), 200
1017
 
1018
- def get_authenticated_user(request_obj):
1019
- auth_data_str = request_obj.headers.get('X-Telegram-Auth')
1020
  if not auth_data_str:
1021
  return None
1022
  is_valid, user_data = verify_telegram_auth_data(auth_data_str, TELEGRAM_BOT_TOKEN)
1023
  if is_valid and user_data:
1024
- data = load_data()
1025
- # Return the user data stored in our system, which might have more/different info
1026
- # or fallback to TG provided data if user not in our DB (should not happen after auth_user)
1027
- return data.get('users', {}).get(str(user_data.get('id')), user_data)
1028
  return None
1029
 
1030
  @app.route('/api/<item_type>', methods=['GET'])
@@ -1047,32 +956,24 @@ def get_item(item_type, item_id):
1047
 
1048
  @app.route('/api/<item_type>', methods=['POST'])
1049
  def create_item(item_type):
1050
- user = get_authenticated_user(request)
1051
  if not user:
1052
  return jsonify({"error": "Authentication required"}), 401
1053
 
1054
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
1055
  return jsonify({"error": "Invalid item type"}), 400
1056
 
1057
- if not request.form:
1058
- return jsonify({"error": "No form data provided"}), 400
 
1059
 
1060
  new_item = {
1061
  "id": str(uuid.uuid4()),
1062
- "user_id": str(user.get('id')),
1063
  "user_telegram_username": user.get('username', 'unknown'),
1064
  "timestamp": datetime.now().isoformat(),
1065
- "image_filename": None
1066
  }
1067
 
1068
- image_file = request.files.get('item_image')
1069
- if image_file and allowed_file(image_file.filename):
1070
- filename = secure_filename(f"{new_item['id']}_{image_file.filename}")
1071
- image_file.save(os.path.join(app.config['UPLOAD_FOLDER'], filename))
1072
- new_item["image_filename"] = filename
1073
-
1074
- req_data = request.form
1075
-
1076
  if item_type == 'resumes':
1077
  required_fields = ['name', 'title']
1078
  for field in required_fields:
@@ -1110,13 +1011,14 @@ def create_item(item_type):
1110
 
1111
  @app.route('/api/<item_type>/<item_id>', methods=['PUT'])
1112
  def update_item(item_type, item_id):
1113
- user = get_authenticated_user(request)
1114
  if not user: return jsonify({"error": "Authentication required"}), 401
1115
 
1116
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
1117
  return jsonify({"error": "Invalid item type"}), 400
1118
 
1119
- if not request.form: return jsonify({"error": "No form data provided"}), 400
 
1120
 
1121
  data = load_data()
1122
  items_list = data.get(item_type, [])
@@ -1129,26 +1031,12 @@ def update_item(item_type, item_id):
1129
  if item_index == -1: return jsonify({"error": "Item not found"}), 404
1130
 
1131
  original_item = items_list[item_index]
1132
- if str(original_item.get('user_id')) != str(user.get('id')):
 
1133
  return jsonify({"error": "Forbidden: You can only edit your own items"}), 403
1134
 
1135
  updated_item = original_item.copy()
1136
  updated_item['updated_timestamp'] = datetime.now().isoformat()
1137
-
1138
- req_data = request.form
1139
-
1140
- image_file = request.files.get('item_image')
1141
- if image_file and allowed_file(image_file.filename):
1142
- if original_item.get("image_filename"):
1143
- try:
1144
- os.remove(os.path.join(app.config['UPLOAD_FOLDER'], original_item["image_filename"]))
1145
- except OSError as e:
1146
- logging.error(f"Error deleting old image {original_item['image_filename']}: {e}")
1147
-
1148
- filename = secure_filename(f"{item_id}_{image_file.filename}")
1149
- image_file.save(os.path.join(app.config['UPLOAD_FOLDER'], filename))
1150
- updated_item["image_filename"] = filename
1151
-
1152
 
1153
  if item_type == 'resumes':
1154
  updated_item.update({
@@ -1186,7 +1074,7 @@ def update_item(item_type, item_id):
1186
 
1187
  @app.route('/api/<item_type>/<item_id>', methods=['DELETE'])
1188
  def delete_item(item_type, item_id):
1189
- user = get_authenticated_user(request)
1190
  if not user: return jsonify({"error": "Authentication required"}), 401
1191
 
1192
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
@@ -1194,23 +1082,18 @@ def delete_item(item_type, item_id):
1194
 
1195
  data = load_data()
1196
  items_list = data.get(item_type, [])
 
1197
 
1198
  item_to_delete = next((i for i in items_list if i['id'] == item_id), None)
1199
  if not item_to_delete: return jsonify({"error": "Item not found"}), 404
1200
 
1201
- if str(item_to_delete.get('user_id')) != str(user.get('id')):
 
1202
  return jsonify({"error": "Forbidden: You can only delete your own items"}), 403
1203
-
1204
- original_length = len(items_list)
1205
  data[item_type] = [i for i in items_list if i['id'] != item_id]
1206
 
1207
  if len(data[item_type]) < original_length:
1208
- if item_to_delete.get("image_filename"):
1209
- try:
1210
- os.remove(os.path.join(app.config['UPLOAD_FOLDER'], item_to_delete["image_filename"]))
1211
- logging.info(f"Deleted image {item_to_delete['image_filename']} for item {item_id}")
1212
- except OSError as e:
1213
- logging.error(f"Error deleting image {item_to_delete['image_filename']}: {e}")
1214
  save_data(data)
1215
  return jsonify({"message": "Item deleted successfully"}), 200
1216
  return jsonify({"error": "Item not found or deletion failed"}), 404
@@ -1235,22 +1118,10 @@ def admin_delete_item():
1235
 
1236
  data = load_data()
1237
  items_list = data.get(item_type, [])
1238
-
1239
- item_to_delete = next((i for i in items_list if i['id'] == item_id), None)
1240
- if not item_to_delete:
1241
- flash('Item not found or already deleted.', 'warning')
1242
- return redirect(url_for('admin_panel'))
1243
-
1244
  original_length = len(items_list)
1245
  data[item_type] = [i for i in items_list if i['id'] != item_id]
1246
 
1247
  if len(data[item_type]) < original_length:
1248
- if item_to_delete.get("image_filename"):
1249
- try:
1250
- os.remove(os.path.join(app.config['UPLOAD_FOLDER'], item_to_delete["image_filename"]))
1251
- logging.info(f"Admin deleted image {item_to_delete['image_filename']} for item {item_id}")
1252
- except OSError as e:
1253
- logging.error(f"Admin error deleting image {item_to_delete['image_filename']}: {e}")
1254
  save_data(data)
1255
  flash(f'{item_type.capitalize()[:-1]} deleted successfully.', 'success')
1256
  else:
@@ -1284,7 +1155,6 @@ def force_download_admin():
1284
 
1285
 
1286
  if __name__ == '__main__':
1287
- ensure_upload_folder()
1288
  logging.info("Application starting up. Performing initial data load/download...")
1289
  download_db_from_hf()
1290
  load_data()
 
1
+ from flask import Flask, render_template_string, request, redirect, url_for, jsonify, flash
2
  import json
3
  import os
4
  import logging
 
20
  app.secret_key = os.getenv("FLASK_SECRET_KEY", 'tontalent_secret_key_for_flash_messages_only')
21
  DATA_FILE = 'tontalent_data.json'
22
  SYNC_FILES = [DATA_FILE]
 
 
 
 
23
 
24
  REPO_ID = os.getenv("HF_REPO_ID", "Kgshop/tontalent2")
25
  HF_TOKEN_WRITE = os.getenv("HF_TOKEN_WRITE")
26
  HF_TOKEN_READ = os.getenv("HF_TOKEN_READ")
27
 
28
+ TELEGRAM_BOT_TOKEN = "7549355625:AAGhdbf6x1JEzpH0mUtuxTF83Soi7MFVNZ8" # User-provided
29
 
30
  DOWNLOAD_RETRIES = 3
31
  DOWNLOAD_DELAY = 5
32
 
33
  logging.basicConfig(level=logging.INFO, format='%(asctime)s - %(levelname)s - %(message)s')
34
 
 
 
 
 
 
 
 
 
 
35
  def download_db_from_hf(specific_file=None, retries=DOWNLOAD_RETRIES, delay=DOWNLOAD_DELAY):
36
  if not HF_TOKEN_READ and not HF_TOKEN_WRITE:
37
  logging.warning("HF_TOKEN_READ/HF_TOKEN_WRITE not set. Download might fail for private repos.")
 
196
  return False, None
197
  return False, None
198
 
199
+
200
  MAIN_APP_TEMPLATE = '''
201
  <!DOCTYPE html>
202
  <html lang="en">
203
  <head>
204
  <meta charset="UTF-8">
205
+ <meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=no, viewport-fit=cover">
206
  <title>TonTalent</title>
207
  <script src="https://telegram.org/js/telegram-web-app.js"></script>
208
  <style>
 
219
  --tg-theme-section-header-text-color: #8e8e93;
220
  --tg-theme-destructive-text-color: #ff3b30;
221
  --tg-theme-accent-text-color: #007aff;
 
 
 
 
 
 
 
 
222
  }
223
  body {
224
+ font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", "Roboto", "Helvetica Neue", Arial, sans-serif;
225
  margin: 0;
226
  padding: 0;
227
  background-color: var(--tg-theme-bg-color);
 
229
  overscroll-behavior-y: none;
230
  -webkit-font-smoothing: antialiased;
231
  -moz-osx-font-smoothing: grayscale;
232
+ display: flex;
233
+ flex-direction: column;
234
+ min-height: 100vh;
235
+ min-height: calc(100vh - env(safe-area-inset-bottom)); /* iOS notch */
236
  }
237
+ .app-container { display: flex; flex-direction: column; flex-grow: 1; }
238
+ .app-header {
239
  background-color: var(--tg-theme-header-bg-color);
240
+ padding: 10px 15px;
 
 
 
241
  border-bottom: 1px solid var(--tg-theme-secondary-bg-color);
242
  position: sticky;
243
  top: 0;
244
  z-index: 100;
245
  }
246
+ .app-header-title { text-align: center; font-weight: 600; font-size: 17px; color: var(--tg-theme-text-color); }
247
+ .profile-header {
248
  display: flex;
249
  align-items: center;
250
+ padding: 10px 15px;
251
  background-color: var(--tg-theme-secondary-bg-color);
 
252
  }
253
+ .profile-header img {
254
+ width: 44px;
255
+ height: 44px;
256
  border-radius: 50%;
257
+ margin-right: 12px;
 
258
  object-fit: cover;
259
+ border: 1px solid var(--tg-theme-hint-color);
260
+ background-color: var(--tg-theme-bg-color); /* Placeholder bg */
261
  }
262
+ .profile-header div { display: flex; flex-direction: column; justify-content: center; }
263
+ #profileName { font-weight: 500; font-size: 16px; color: var(--tg-theme-text-color); }
264
+ #profileUsername { font-size: 13px; color: var(--tg-theme-hint-color); }
 
 
 
265
 
266
+ .tabs { display: flex; background-color: var(--tg-theme-secondary-bg-color); padding: 5px; border-bottom: 1px solid var(--tg-theme-secondary-bg-color); }
267
  .tab-button {
268
  flex: 1;
269
+ padding: 12px 5px;
270
  text-align: center;
271
  cursor: pointer;
272
  background: none;
 
275
  font-size: 15px;
276
  font-weight: 500;
277
  border-bottom: 3px solid transparent;
278
+ transition: color 0.2s, border-bottom-color 0.2s;
279
+ -webkit-tap-highlight-color: transparent;
280
  }
281
+ .tab-button.active { color: var(--tg-theme-link-color); border-bottom-color: var(--tg-theme-link-color); }
282
+ .content {
283
+ flex-grow: 1; padding: 15px;
284
+ transition: opacity 0.25s ease-in-out;
285
+ overflow-y: auto; /* Enable scrolling for content */
286
+ -webkit-overflow-scrolling: touch; /* Smooth scrolling on iOS */
287
+ }
288
+ .content.loading-state { opacity: 0.5; }
 
289
  .list-item {
290
  background-color: var(--tg-theme-section-bg-color);
291
+ border-radius: 10px;
292
+ padding: 12px 15px;
293
+ margin-bottom: 10px;
294
+ box-shadow: 0 2px 6px rgba(0,0,0,0.08);
295
  cursor: pointer;
296
+ transition: background-color 0.2s, transform 0.1s;
297
  }
298
+ .list-item:active { background-color: var(--tg-theme-secondary-bg-color); transform: scale(0.99); }
299
+ .list-item h3 { margin: 0 0 5px 0; font-size: 17px; font-weight: 600; color: var(--tg-theme-text-color); }
300
+ .list-item p { margin: 0 0 4px 0; font-size: 14px; color: var(--tg-theme-text-color); opacity: 0.8; }
301
+ .list-item .meta { font-size: 12px; color: var(--tg-theme-hint-color); margin-top: 8px; }
 
 
302
 
303
+ .form-container { padding: 15px; background-color: var(--tg-theme-section-bg-color); }
304
+ .form-group { margin-bottom: 18px; }
305
+ .form-group label { display: block; font-size: 14px; color: var(--tg-theme-section-header-text-color); margin-bottom: 6px; font-weight: 500; }
306
+ .form-group input, .form-group textarea {
307
  width: 100%;
308
+ padding: 12px;
309
  border: 1px solid var(--tg-theme-secondary-bg-color);
310
+ border-radius: 8px;
311
  font-size: 16px;
312
  background-color: var(--tg-theme-bg-color);
313
  color: var(--tg-theme-text-color);
314
  box-sizing: border-box;
315
+ transition: border-color 0.2s;
316
+ }
317
+ .form-group input:focus, .form-group textarea:focus {
318
+ border-color: var(--tg-theme-link-color);
319
+ outline: none;
320
  }
 
321
  .form-group textarea { min-height: 100px; resize: vertical; }
 
322
 
323
  .fab {
324
  position: fixed;
325
+ bottom: calc(20px + env(safe-area-inset-bottom));
326
+ right: 20px;
327
  width: 56px;
328
  height: 56px;
329
  background-color: var(--tg-theme-button-color);
 
338
  cursor: pointer;
339
  z-index: 1000;
340
  border: none;
341
+ transition: transform 0.15s ease-out, background-color 0.2s;
342
+ -webkit-tap-highlight-color: transparent;
343
  }
344
+ .fab:active { transform: scale(0.92); background-color: color-mix(in srgb, var(--tg-theme-button-color) 90%, black); }
345
+
346
+ .detail-view { padding: 15px; background-color: var(--tg-theme-section-bg-color); }
347
+ .detail-view h2 { margin-top: 0; font-size: 22px; font-weight: 600; color: var(--tg-theme-text-color); margin-bottom: 15px;}
348
+ .detail-view p { margin-bottom: 10px; line-height: 1.6; font-size: 16px; color: var(--tg-theme-text-color); }
349
+ .detail-view strong { font-weight: 600; color: var(--tg-theme-section-header-text-color); }
 
 
350
  .detail-view a { color: var(--tg-theme-link-color); text-decoration: none; }
351
  .detail-view a:hover { text-decoration: underline; }
352
+ .detail-view .meta { font-size: 13px; color: var(--tg-theme-hint-color); margin-top: 15px; }
353
 
354
+ .action-buttons { margin-top: 25px; display: flex; gap: 12px; }
355
+ .action-buttons button {
356
+ flex-grow: 1;
357
+ padding: 12px 15px;
358
+ border-radius: 8px;
359
+ font-size: 16px;
360
+ font-weight: 500;
361
+ cursor: pointer;
362
+ border: none;
363
+ transition: background-color 0.2s, transform 0.1s;
364
+ -webkit-tap-highlight-color: transparent;
365
+ }
366
+ .action-buttons button:active { transform: scale(0.98); }
367
+ .button-edit { background-color: var(--tg-theme-button-color); color: var(--tg-theme-button-text-color); }
368
+ .button-delete { background-color: var(--tg-theme-destructive-text-color); color: var(--tg-theme-button-text-color); }
369
+
370
+ .loading, .empty-state { text-align: center; padding: 50px 15px; color: var(--tg-theme-hint-color); font-size: 16px; }
371
+ .error-message { color: var(--tg-theme-destructive-text-color); font-size: 14px; margin-top: 10px; text-align: center;}
372
  </style>
373
  </head>
374
  <body>
375
  <div class="app-container">
376
+ <div class="app-header">
377
+ <div class="app-header-title">TonTalent</div>
378
+ </div>
379
+ <div class="profile-header">
380
+ <img id="userAvatar" src="#" alt="User Avatar" style="display: none;">
381
+ <div>
382
+ <span id="profileName">Loading...</span>
383
+ <span id="profileUsername"></span>
384
+ </div>
385
  </div>
386
  <div class="tabs">
387
  <button class="tab-button active" data-tab="resumes">Resumes</button>
 
399
  let currentUser = null;
400
  let currentView = 'resumes';
401
  let currentItem = null;
402
+
403
+ let touchstartX = 0;
404
+ let touchendX = 0;
405
+ const swipeThreshold = 75;
406
  const mainContentEl = document.getElementById('mainContent');
407
 
408
  function applyThemeParams() {
 
419
  root.style.setProperty('--tg-theme-section-header-text-color', tg.themeParams.section_header_text_color || tg.themeParams.hint_color || '#8e8e93');
420
  root.style.setProperty('--tg-theme-destructive-text-color', tg.themeParams.destructive_text_color || '#ff3b30');
421
  root.style.setProperty('--tg-theme-accent-text-color', tg.themeParams.accent_text_color || tg.themeParams.link_color || '#007aff');
 
422
  }
423
 
424
  async function apiCall(endpoint, method = 'GET', body = null) {
425
+ const headers = { 'Content-Type': 'application/json' };
 
 
 
426
  if (tg.initData) {
427
  headers['X-Telegram-Auth'] = tg.initData;
428
  }
429
  const options = { method, headers };
430
+ if (body) options.body = JSON.stringify(body);
 
 
 
 
431
  try {
432
  const response = await fetch(endpoint, options);
433
  if (!response.ok) {
434
+ const errorData = await response.json().catch(() => ({ error: 'Request failed with status: ' + response.status }));
435
  throw new Error(errorData.error || `HTTP error ${response.status}`);
436
  }
437
  return response.json();
438
  } catch (error) {
439
  console.error('API Call Error:', error);
440
  tg.showAlert(error.message || 'An API error occurred.');
 
441
  throw error;
 
 
442
  }
443
  }
444
 
445
  function renderList(items, type) {
446
+ const contentDiv = document.getElementById('mainContent');
447
+ contentDiv.classList.remove('loading-state');
448
  if (!items || items.length === 0) {
449
+ contentDiv.innerHTML = `<div class="empty-state">No ${type} found. Be the first to add one!</div>`;
450
  return;
451
  }
452
+ contentDiv.innerHTML = items.map(item => `
453
  <div class="list-item" onclick="showDetailView('${type}', '${item.id}')">
454
+ <h3>${item.title || item.name || 'Untitled'}</h3>
455
+ ${type === 'vacancies' && item.company_name ? `<p><strong>Company:</strong> ${item.company_name}</p>` : ''}
456
+ ${type === 'freelance_offers' && item.budget ? `<p><strong>Budget:</strong> ${item.budget}</p>` : ''}
 
 
 
 
 
457
  <p class="meta">Posted by: @${item.user_telegram_username || 'anonymous'} on ${new Date(item.timestamp).toLocaleDateString()}</p>
458
  </div>
459
  `).join('');
 
460
  }
461
 
462
  function showDetailView(type, id) {
463
  tg.BackButton.show();
464
  tg.BackButton.onClick(() => {
465
  loadView(type);
466
+ tg.HapticFeedback.selectionChanged();
467
  });
468
  tg.MainButton.hide();
469
  document.getElementById('fabButton').style.display = 'none';
470
+ mainContentEl.classList.add('loading-state');
 
471
 
472
  apiCall(`/api/${type}/${id}`)
473
  .then(item => {
474
  currentItem = item;
475
+ mainContentEl.classList.remove('loading-state');
476
+ const contentDiv = document.getElementById('mainContent');
477
+ let detailsHtml = `<div class="detail-view"><h2>${item.title || item.name}</h2>`;
 
 
478
 
479
+ const formatText = (text) => text ? String(text).replace(/\\n/g, '<br>').replace(/\n/g, '<br>') : 'N/A';
480
+
481
  if (type === 'resumes') {
482
  detailsHtml += `
483
+ <p><strong>Skills:</strong> ${formatText(item.skills)}</p>
484
+ <p><strong>Experience:</strong><br>${formatText(item.experience)}</p>
485
+ <p><strong>Education:</strong><br>${formatText(item.education)}</p>
486
  <p><strong>Contact:</strong> ${item.contact || `@${item.user_telegram_username}`}</p>
487
  ${item.portfolio_link ? `<p><strong>Portfolio:</strong> <a href="${item.portfolio_link}" target="_blank" rel="noopener noreferrer">${item.portfolio_link}</a></p>` : ''}
488
  `;
489
  } else if (type === 'vacancies') {
490
  detailsHtml += `
491
  <p><strong>Company:</strong> ${item.company_name || 'N/A'}</p>
492
+ <p><strong>Description:</strong><br>${formatText(item.description)}</p>
493
+ <p><strong>Requirements:</strong><br>${formatText(item.requirements)}</p>
494
  <p><strong>Salary:</strong> ${item.salary || 'N/A'}</p>
495
  <p><strong>Location:</strong> ${item.location || 'N/A'}</p>
496
+ <p><strong>Contact/Apply:</strong> ${formatText(item.contact) || `@${item.user_telegram_username}`}</p>
497
  `;
498
  } else if (type === 'freelance_offers') {
499
  detailsHtml += `
500
+ <p><strong>Description:</strong><br>${formatText(item.description)}</p>
501
  <p><strong>Budget:</strong> ${item.budget || 'N/A'}</p>
502
  <p><strong>Deadline:</strong> ${item.deadline || 'N/A'}</p>
503
+ <p><strong>Skills Needed:</strong> ${formatText(item.skills_needed)}</p>
504
  <p><strong>Contact:</strong> ${item.contact || `@${item.user_telegram_username}`}</p>
505
  `;
506
  }
507
+ detailsHtml += `<p class="meta">Posted by: @${item.user_telegram_username || 'anonymous'} on ${new Date(item.timestamp).toLocaleDateString()}</p>`;
508
+
509
+ let actionButtonsHtml = '';
 
510
  if (currentUser && item.user_id === String(currentUser.id)) {
511
+ actionButtonsHtml = `
512
+ <div class="action-buttons">
513
+ <button class="button-edit" onclick="handleEditItem('${type}', '${item.id}')">Edit</button>
514
+ <button class="button-delete" onclick="handleDeleteItemPrompt('${type}', '${item.id}')">Delete</button>
515
+ </div>
516
+ `;
517
  }
518
+ detailsHtml += actionButtonsHtml;
519
+ detailsHtml += `</div>`;
520
+ contentDiv.innerHTML = detailsHtml;
521
  })
522
  .catch(err => {
523
+ mainContentEl.classList.remove('loading-state');
524
+ document.getElementById('mainContent').innerHTML = `<div class="empty-state">Error loading details. Please try again.</div>`;
525
  });
526
  }
527
 
528
+ function handleEditItem(type, id) {
529
+ tg.HapticFeedback.impactOccurred('light');
530
+ if (currentItem && currentItem.id === id) {
531
+ showForm(type, currentItem);
532
+ } else {
533
+ apiCall(`/api/${type}/${id}`).then(itemData => {
534
+ currentItem = itemData;
535
+ showForm(type, itemData);
536
+ }).catch(err => tg.showAlert('Could not load item for editing.'));
537
+ }
538
+ }
539
+
540
+ function handleDeleteItemPrompt(type, id) {
541
+ tg.HapticFeedback.impactOccurred('light');
542
+ tg.showConfirm(`Are you sure you want to delete this ${type.slice(0,-1)}? This action cannot be undone.`, (confirmed) => {
543
+ if (confirmed) {
544
+ tg.HapticFeedback.impactOccurred('heavy');
545
+ actuallyDeleteItem(type, id);
546
+ }
547
+ });
548
+ }
549
+
550
+ function actuallyDeleteItem(type, id) {
551
+ tg.MainButton.setText('Deleting...').showProgress().disable();
552
+ apiCall(`/api/${type}/${id}`, 'DELETE')
553
+ .then(response => {
554
+ tg.MainButton.hideProgress().enable().hide();
555
+ tg.HapticFeedback.notificationOccurred('success');
556
+ tg.showAlert(response.message || `${type.slice(0,-1)} deleted successfully.`);
557
+ loadView(type);
558
+ })
559
+ .catch(err => {
560
+ tg.MainButton.hideProgress().enable().hide();
561
+ tg.HapticFeedback.notificationOccurred('error');
562
+ tg.showAlert(err.message || `Failed to delete ${type.slice(0,-1)}.`);
563
+ });
564
+ }
565
+
566
  function showForm(type, itemToEdit = null) {
567
  currentItem = itemToEdit;
568
  tg.BackButton.show();
569
  tg.BackButton.onClick(() => {
570
+ tg.HapticFeedback.selectionChanged();
571
  if (itemToEdit) showDetailView(type, itemToEdit.id);
572
  else loadView(type);
 
573
  });
574
  document.getElementById('fabButton').style.display = 'none';
575
+ mainContentEl.classList.remove('loading-state');
 
576
 
577
+ const contentDiv = document.getElementById('mainContent');
578
+ let formHtml = `<div class="form-container"><h2>${itemToEdit ? 'Edit' : 'New'} ${type.slice(0, -1)}</h2>`;
579
 
 
 
 
 
 
 
 
 
580
  if (type === 'resumes') {
581
  formHtml += `
582
+ <div class="form-group"><label for="name">Full Name</label><input type="text" id="name" value="${itemToEdit?.name || ''}" required></div>
583
+ <div class="form-group"><label for="title">Job Title / Desired Position</label><input type="text" id="title" value="${itemToEdit?.title || ''}" required></div>
584
+ <div class="form-group"><label for="skills">Skills (comma separated)</label><textarea id="skills">${itemToEdit?.skills || ''}</textarea></div>
585
+ <div class="form-group"><label for="experience">Experience</label><textarea id="experience">${itemToEdit?.experience || ''}</textarea></div>
586
+ <div class="form-group"><label for="education">Education</label><textarea id="education">${itemToEdit?.education || ''}</textarea></div>
587
+ <div class="form-group"><label for="contact">Contact Info (e.g., email, or leave blank to use Telegram)</label><input type="text" id="contact" value="${itemToEdit?.contact || ''}"></div>
588
+ <div class="form-group"><label for="portfolio_link">Portfolio Link (optional)</label><input type="url" id="portfolio_link" value="${itemToEdit?.portfolio_link || ''}"></div>
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
589
  `;
590
  } else if (type === 'vacancies') {
591
  formHtml += `
592
+ <div class="form-group"><label for="company_name">Company Name</label><input type="text" id="company_name" value="${itemToEdit?.company_name || ''}" required></div>
593
+ <div class="form-group"><label for="title">Job Title</label><input type="text" id="title" value="${itemToEdit?.title || ''}" required></div>
594
+ <div class="form-group"><label for="description">Description</label><textarea id="description">${itemToEdit?.description || ''}</textarea></div>
595
+ <div class="form-group"><label for="requirements">Requirements</label><textarea id="requirements">${itemToEdit?.requirements || ''}</textarea></div>
596
+ <div class="form-group"><label for="salary">Salary/Compensation</label><input type="text" id="salary" value="${itemToEdit?.salary || ''}"></div>
597
+ <div class="form-group"><label for="location">Location (e.g., Remote, City)</label><input type="text" id="location" value="${itemToEdit?.location || ''}"></div>
598
+ <div class="form-group"><label for="contact">Contact Info / How to Apply</label><textarea id="contact">${itemToEdit?.contact || ''}</textarea></div>
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
599
  `;
600
  } else if (type === 'freelance_offers') {
601
  formHtml += `
602
+ <div class="form-group"><label for="title">Project Title</label><input type="text" id="title" value="${itemToEdit?.title || ''}" required></div>
603
+ <div class="form-group"><label for="description">Description of Work</label><textarea id="description">${itemToEdit?.description || ''}</textarea></div>
604
+ <div class="form-group"><label for="budget">Budget</label><input type="text" id="budget" value="${itemToEdit?.budget || ''}"></div>
605
+ <div class="form-group"><label for="deadline">Expected Deadline</label><input type="text" id="deadline" value="${itemToEdit?.deadline || ''}"></div>
606
+ <div class="form-group"><label for="skills_needed">Skills Needed (comma separated)</label><textarea id="skills_needed">${itemToEdit?.skills_needed || ''}</textarea></div>
607
+ <div class="form-group"><label for="contact">Contact Info (or leave blank to use Telegram)</label><input type="text" id="contact" value="${itemToEdit?.contact || ''}"></div>
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
608
  `;
609
  }
610
  formHtml += `<div id="formError" class="error-message"></div></div>`;
611
+ contentDiv.innerHTML = formHtml;
 
612
 
613
  tg.MainButton.setText(itemToEdit ? 'Save Changes' : 'Post');
614
  tg.MainButton.show();
 
649
  }
650
 
651
  if (!isValid) {
652
+ document.getElementById('formError').textContent = 'Please fill in all required fields.';
653
  tg.HapticFeedback.notificationOccurred('error');
654
  return;
655
  }
656
 
657
+ tg.MainButton.showProgress().disable();
 
 
 
 
 
 
 
658
 
659
  const method = itemId ? 'PUT' : 'POST';
660
  const endpoint = itemId ? `/api/${type}/${itemId}` : `/api/${type}`;
661
 
662
+ apiCall(endpoint, method, payload)
663
  .then(response => {
664
  tg.HapticFeedback.notificationOccurred('success');
665
+ tg.MainButton.hideProgress().enable();
666
  loadView(type);
667
  })
668
  .catch(err => {
669
  tg.HapticFeedback.notificationOccurred('error');
670
+ tg.MainButton.hideProgress().enable();
671
+ document.getElementById('formError').textContent = err.message || 'Failed to submit.';
672
  });
673
  }
674
 
 
678
  document.querySelector(`.tab-button[data-tab="${tabName}"]`).classList.add('active');
679
 
680
  mainContentEl.innerHTML = `<div class="loading">Loading ${tabName}...</div>`;
681
+ mainContentEl.classList.add('loading-state');
682
  tg.BackButton.hide();
683
  tg.MainButton.hide();
684
  document.getElementById('fabButton').style.display = 'block';
 
686
  apiCall(`/api/${tabName}`)
687
  .then(data => renderList(data, tabName))
688
  .catch(err => {
689
+ mainContentEl.classList.remove('loading-state');
690
+ mainContentEl.innerHTML = `<div class="empty-state">Error loading ${tabName}. Please try again.</div>`;
691
  });
692
  }
693
 
694
+ mainContentEl.addEventListener('touchstart', function(event) {
 
 
 
 
 
 
 
695
  touchstartX = event.changedTouches[0].screenX;
 
696
  }, { passive: true });
697
 
698
+ mainContentEl.addEventListener('touchend', function(event) {
699
  touchendX = event.changedTouches[0].screenX;
700
+ handleSwipeGesture();
 
701
  }, { passive: true });
702
 
703
+ function handleSwipeGesture() {
704
+ const tabs = ['resumes', 'vacancies', 'freelance_offers'];
705
+ const currentIndex = tabs.indexOf(currentView);
706
+ let direction = 0;
707
+
708
+ if (touchendX < touchstartX - swipeThreshold) { direction = 1; } // Swiped left
709
+ if (touchendX > touchstartX + swipeThreshold) { direction = -1; } // Swiped right
710
+
711
+ if (direction !== 0) {
712
+ const nextIndex = currentIndex + direction;
713
+ if (nextIndex >= 0 && nextIndex < tabs.length) {
714
+ loadView(tabs[nextIndex]);
 
 
715
  tg.HapticFeedback.selectionChanged();
716
  }
717
  }
718
  }
719
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
720
  async function init() {
721
  tg.ready();
722
  applyThemeParams();
723
+ tg.onEvent('themeChanged', applyThemeParams);
724
  tg.expand();
725
  tg.enableClosingConfirmation();
726
+ tg.setHeaderColor(tg.themeParams.secondary_bg_color || '#f0f0f0');
727
+
728
+
729
+ const profileNameEl = document.getElementById('profileName');
730
+ const profileUsernameEl = document.getElementById('profileUsername');
731
+ const userAvatarEl = document.getElementById('userAvatar');
 
 
 
 
732
 
733
  try {
734
  const authResponse = await apiCall('/api/auth_user', 'POST', { init_data: tg.initData });
735
  currentUser = authResponse.user;
736
  if (currentUser) {
737
+ profileNameEl.textContent = `${currentUser.first_name || ''} ${currentUser.last_name || ''}`.trim() || 'User';
738
+ if (currentUser.username) profileUsernameEl.textContent = `@${currentUser.username}`;
739
+ else profileUsernameEl.textContent = 'Authenticated';
740
+
741
+ if (currentUser.photo_url) {
742
+ userAvatarEl.src = currentUser.photo_url;
743
+ userAvatarEl.style.display = 'block';
744
+ userAvatarEl.onerror = () => { userAvatarEl.style.display = 'none'; };
745
+ } else { userAvatarEl.style.display = 'none'; }
746
+ } else { throw new Error("No user data from auth"); }
747
  } catch (error) {
748
  console.error("Auth error:", error);
749
+ const unsafeUser = tg.initDataUnsafe.user;
750
+ profileNameEl.textContent = `${unsafeUser?.first_name || ''} ${unsafeUser?.last_name || ''}`.trim() || 'User';
751
+ if (unsafeUser?.username) profileUsernameEl.textContent = `@${unsafeUser.username}`;
752
+ else profileUsernameEl.textContent = 'Guest (Limited Access)';
753
+ userAvatarEl.style.display = 'none';
754
+ if (error.message !== "No user data from auth") { // Avoid double alert if it's just missing data
755
+ tg.showAlert("Authentication with the server failed. Some features might be limited.");
756
+ }
757
  }
758
 
759
  document.querySelectorAll('.tab-button').forEach(button => {
 
769
 
770
  loadView('resumes');
771
  }
 
772
  init();
773
  </script>
774
  </body>
 
791
  .item:last-child { border-bottom: none; }
792
  .item h3 { margin: 0 0 5px 0; }
793
  .item p { margin: 3px 0; font-size: 0.9em; color: #555; }
 
794
  .button { padding: 8px 15px; border: none; border-radius: 4px; cursor: pointer; font-size: 0.9em; margin-right: 5px; }
795
  .button-primary { background-color: #007bff; color: white; }
796
  .button-danger { background-color: #dc3545; color: white; }
 
824
  <button type="submit" class="button button-secondary">Download DB from HF</button>
825
  </form>
826
  </div>
827
+ <p style="font-size: 0.8em; color: #666;">Automatic backup runs every 30 minutes if HF_TOKEN_WRITE is set.</p>
828
  </div>
829
 
830
  <div class="section">
 
834
  <h3>{{ resume.name }} - {{ resume.title }}</h3>
835
  <p>User ID: {{ resume.user_id }} (@{{ resume.user_telegram_username }})</p>
836
  <p>Posted: {{ resume.timestamp }}</p>
 
 
 
837
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this resume?');">
838
  <input type="hidden" name="item_type" value="resumes">
839
  <input type="hidden" name="item_id" value="{{ resume.id }}">
 
852
  <h3>{{ vacancy.title }} - {{ vacancy.company_name }}</h3>
853
  <p>User ID: {{ vacancy.user_id }} (@{{ vacancy.user_telegram_username }})</p>
854
  <p>Posted: {{ vacancy.timestamp }}</p>
 
 
 
855
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this vacancy?');">
856
  <input type="hidden" name="item_type" value="vacancies">
857
  <input type="hidden" name="item_id" value="{{ vacancy.id }}">
 
871
  <p>User ID: {{ offer.user_id }} (@{{ offer.user_telegram_username }})</p>
872
  <p>Budget: {{ offer.budget }}</p>
873
  <p>Posted: {{ offer.timestamp }}</p>
 
 
 
874
  <form method="POST" action="{{ url_for('admin_delete_item') }}" style="display:inline;" onsubmit="return confirm('Delete this freelance offer?');">
875
  <input type="hidden" name="item_type" value="freelance_offers">
876
  <input type="hidden" name="item_id" value="{{ offer.id }}">
 
890
  def main_app_view():
891
  return render_template_string(MAIN_APP_TEMPLATE)
892
 
 
 
 
 
893
  @app.route('/api/auth_user', methods=['POST'])
894
  def auth_user():
895
  auth_data_str = request.headers.get('X-Telegram-Auth')
 
900
  else:
901
  return jsonify({"error": "Authentication data not provided"}), 401
902
 
903
+ is_valid, user_data_from_auth = verify_telegram_auth_data(auth_data_str, TELEGRAM_BOT_TOKEN)
904
 
905
+ if not is_valid or not user_data_from_auth:
906
  return jsonify({"error": "Invalid authentication data"}), 403
907
 
908
  data = load_data()
909
  users = data.get('users', {})
910
+ user_id_str = str(user_data_from_auth.get('id'))
911
 
912
  if user_id_str not in users:
913
  users[user_id_str] = {
914
+ 'id': user_data_from_auth.get('id'), # This is an int
915
+ 'first_name': user_data_from_auth.get('first_name'),
916
+ 'last_name': user_data_from_auth.get('last_name'),
917
+ 'username': user_data_from_auth.get('username'),
918
+ 'language_code': user_data_from_auth.get('language_code'),
919
+ 'photo_url': user_data_from_auth.get('photo_url'),
920
  'first_seen': datetime.now().isoformat()
921
  }
 
 
 
 
 
 
 
 
 
922
  users[user_id_str]['last_seen'] = datetime.now().isoformat()
923
+ if user_data_from_auth.get('photo_url'): # Update photo_url if changed
924
+ users[user_id_str]['photo_url'] = user_data_from_auth.get('photo_url')
925
  data['users'] = users
926
  save_data(data)
927
 
928
  return jsonify({"message": "User authenticated", "user": users[user_id_str]}), 200
929
 
930
+ def get_authenticated_user(request_headers):
931
+ auth_data_str = request_headers.get('X-Telegram-Auth')
932
  if not auth_data_str:
933
  return None
934
  is_valid, user_data = verify_telegram_auth_data(auth_data_str, TELEGRAM_BOT_TOKEN)
935
  if is_valid and user_data:
936
+ return user_data # user_data['id'] is an int here
 
 
 
937
  return None
938
 
939
  @app.route('/api/<item_type>', methods=['GET'])
 
956
 
957
  @app.route('/api/<item_type>', methods=['POST'])
958
  def create_item(item_type):
959
+ user = get_authenticated_user(request.headers) # user['id'] is int
960
  if not user:
961
  return jsonify({"error": "Authentication required"}), 401
962
 
963
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
964
  return jsonify({"error": "Invalid item type"}), 400
965
 
966
+ req_data = request.json
967
+ if not req_data:
968
+ return jsonify({"error": "No data provided"}), 400
969
 
970
  new_item = {
971
  "id": str(uuid.uuid4()),
972
+ "user_id": str(user.get('id')), # Store as string
973
  "user_telegram_username": user.get('username', 'unknown'),
974
  "timestamp": datetime.now().isoformat(),
 
975
  }
976
 
 
 
 
 
 
 
 
 
977
  if item_type == 'resumes':
978
  required_fields = ['name', 'title']
979
  for field in required_fields:
 
1011
 
1012
  @app.route('/api/<item_type>/<item_id>', methods=['PUT'])
1013
  def update_item(item_type, item_id):
1014
+ user = get_authenticated_user(request.headers) # user['id'] is int
1015
  if not user: return jsonify({"error": "Authentication required"}), 401
1016
 
1017
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
1018
  return jsonify({"error": "Invalid item type"}), 400
1019
 
1020
+ req_data = request.json
1021
+ if not req_data: return jsonify({"error": "No data provided"}), 400
1022
 
1023
  data = load_data()
1024
  items_list = data.get(item_type, [])
 
1031
  if item_index == -1: return jsonify({"error": "Item not found"}), 404
1032
 
1033
  original_item = items_list[item_index]
1034
+ # original_item['user_id'] is string, user.get('id') is int
1035
+ if original_item.get('user_id') != str(user.get('id')):
1036
  return jsonify({"error": "Forbidden: You can only edit your own items"}), 403
1037
 
1038
  updated_item = original_item.copy()
1039
  updated_item['updated_timestamp'] = datetime.now().isoformat()
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1040
 
1041
  if item_type == 'resumes':
1042
  updated_item.update({
 
1074
 
1075
  @app.route('/api/<item_type>/<item_id>', methods=['DELETE'])
1076
  def delete_item(item_type, item_id):
1077
+ user = get_authenticated_user(request.headers) # user['id'] is int
1078
  if not user: return jsonify({"error": "Authentication required"}), 401
1079
 
1080
  if item_type not in ['resumes', 'vacancies', 'freelance_offers']:
 
1082
 
1083
  data = load_data()
1084
  items_list = data.get(item_type, [])
1085
+ original_length = len(items_list)
1086
 
1087
  item_to_delete = next((i for i in items_list if i['id'] == item_id), None)
1088
  if not item_to_delete: return jsonify({"error": "Item not found"}), 404
1089
 
1090
+ # item_to_delete['user_id'] is string, user.get('id') is int
1091
+ if item_to_delete.get('user_id') != str(user.get('id')):
1092
  return jsonify({"error": "Forbidden: You can only delete your own items"}), 403
1093
+
 
1094
  data[item_type] = [i for i in items_list if i['id'] != item_id]
1095
 
1096
  if len(data[item_type]) < original_length:
 
 
 
 
 
 
1097
  save_data(data)
1098
  return jsonify({"message": "Item deleted successfully"}), 200
1099
  return jsonify({"error": "Item not found or deletion failed"}), 404
 
1118
 
1119
  data = load_data()
1120
  items_list = data.get(item_type, [])
 
 
 
 
 
 
1121
  original_length = len(items_list)
1122
  data[item_type] = [i for i in items_list if i['id'] != item_id]
1123
 
1124
  if len(data[item_type]) < original_length:
 
 
 
 
 
 
1125
  save_data(data)
1126
  flash(f'{item_type.capitalize()[:-1]} deleted successfully.', 'success')
1127
  else:
 
1155
 
1156
 
1157
  if __name__ == '__main__':
 
1158
  logging.info("Application starting up. Performing initial data load/download...")
1159
  download_db_from_hf()
1160
  load_data()