#!/bin/bash
# Live deploy for leave.gventure.co.in from the SVN trunk.
# Repo checkout: /var/www/html/websites/leave.gventure.co.in
#   trunk/angular   Angular portal
#   trunk/node      Node API
#   trunk/config    Apache vhosts
#
# Run on the server as root, from the trunk checkout:
#   bash /var/www/html/websites/leave.gventure.co.in/trunk/deploy.sh

set -euo pipefail

# This script lives in trunk. Use its directory so the deploy follows
# the checkout path (/var/www/html/websites/leave.gventure.co.in/trunk).
TRUNK="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
REPO_ROOT="$(dirname "${TRUNK}")"
DOMAIN="leave.gventure.co.in"
API_PORT="3131"
SVN_USER="${SVN_USER:-vikas}"
SVN_PASS="${SVN_PASS:-aklaverma}"
FRONTEND_URL="https://${DOMAIN}"

APACHE_AVAILABLE="/etc/apache2/sites-available"
CONF_HTTP="${APACHE_AVAILABLE}/${DOMAIN}.conf"
CONF_SSL="${APACHE_AVAILABLE}/${DOMAIN}-le-ssl.conf"

log() { printf '\n==> %s\n' "$*"; }

if [[ -d "${REPO_ROOT}/.svn" ]]; then
  SVN_DIR="${REPO_ROOT}"
elif [[ -d "${TRUNK}/.svn" ]]; then
  SVN_DIR="${TRUNK}"
else
  echo "SVN working copy not found at ${REPO_ROOT} or ${TRUNK}"
  exit 1
fi

log "SVN update (${SVN_USER}) in ${SVN_DIR}"
svn cleanup "${SVN_DIR}" || true
svn update "${SVN_DIR}" \
  --username "${SVN_USER}" \
  --password "${SVN_PASS}" \
  --non-interactive \
  --no-auth-cache

if [[ ! -f "${TRUNK}/node/.env" ]]; then
  echo "Missing ${TRUNK}/node/.env — copy it onto the server before the API can start."
  exit 1
fi

log "Build API (trunk/node)"
cd "${TRUNK}/node"
npm install
npx prisma generate
npx prisma migrate deploy
npm run build

log "Restart API on port ${API_PORT}"
export FRONTEND_URL
export NODE_ENV="${NODE_ENV:-production}"
if command -v pm2 >/dev/null 2>&1; then
  pm2 delete leave-api >/dev/null 2>&1 || true
  pm2 start dist/index.js --name leave-api --cwd "${TRUNK}/node"
  pm2 save || true
else
  mkdir -p "${TRUNK}/node/logs"
  if [[ -f "${TRUNK}/node/leave-api.pid" ]]; then
    old_pid="$(cat "${TRUNK}/node/leave-api.pid" || true)"
    if [[ -n "${old_pid}" ]]; then
      kill "${old_pid}" >/dev/null 2>&1 || true
    fi
  fi
  if command -v fuser >/dev/null 2>&1; then
    fuser -k "${API_PORT}/tcp" >/dev/null 2>&1 || true
  fi
  nohup node dist/index.js >> "${TRUNK}/node/logs/leave-api.log" 2>&1 &
  echo $! > "${TRUNK}/node/leave-api.pid"
fi

log "Build Angular portal (trunk/angular)"
cd "${TRUNK}/angular"
npm install
npm run build

if [[ ! -f "${TRUNK}/angular/dist/frontend/browser/index.html" ]]; then
  echo "Angular build did not produce trunk/angular/dist/frontend/browser/index.html"
  exit 1
fi

log "Install Apache vhosts"
install -m 644 "${TRUNK}/config/apache/${DOMAIN}.conf" "${CONF_HTTP}"
install -m 644 "${TRUNK}/config/apache/${DOMAIN}-le-ssl.conf" "${CONF_SSL}"

a2enmod rewrite proxy proxy_http headers ssl >/dev/null
a2ensite "${DOMAIN}.conf" >/dev/null
a2ensite "${DOMAIN}-le-ssl.conf" >/dev/null

if [[ ! -f "/etc/letsencrypt/live/${DOMAIN}/fullchain.pem" ]]; then
  echo "SSL certificate is missing: /etc/letsencrypt/live/${DOMAIN}/fullchain.pem"
  echo "Issue it once with: certbot --apache -d ${DOMAIN}"
  exit 1
fi

apache2ctl configtest
systemctl reload apache2

log "Deployed https://${DOMAIN} from trunk (API 127.0.0.1:${API_PORT})"
