pipeline {
    agent any

    environment {
        DEPLOY_HOST = "192.168.178.180"
        DEPLOY_USER = "ubuntu"
        APP_DIR = "/srv/mitm-webserver"
    }

    stages {
        stage('Checkout') {
            steps {
                git branch: 'main', url: 'http://192.168.178.96:3000/marcus/mitm-webserver.git'
            }
        }

        stage('Build Frontend') {
            steps {
                dir('frontend') {
                    sh 'npm ci'
                    sh 'npm run build'
                }
            }
        }

        stage('Prepare Backend') {
            steps {
                dir('backend') {
                    sh '''
                    python3 -m venv venv
                    ./venv/bin/pip install --upgrade pip
                    ./venv/bin/pip install -r requirements.txt
                    '''
                }
            }
        }

        stage('Deploy to VM') {
            steps {
                // Use Jenkins credentials (username + password)
                withCredentials([usernamePassword(credentialsId: 'deploy-pass-id', usernameVariable: 'USER', passwordVariable: 'PASS')]) {
                    // Install sshpass if not available
                    sh '''
                    if ! command -v sshpass >/dev/null 2>&1; then
                        echo "Installing sshpass..."
                        sudo apt-get update -y && sudo apt-get install -y sshpass
                    fi
                    '''

                    // Upload frontend build
                    sh '''
                    sshpass -p "$PASS" rsync -avz --delete \
                        -e "ssh -o StrictHostKeyChecking=no" \
                        frontend/dist/ $USER@$DEPLOY_HOST:$APP_DIR/frontend/dist/
                    '''

                    // Upload backend code
                    sh '''
                    sshpass -p "$PASS" rsync -avz --delete \
                        -e "ssh -o StrictHostKeyChecking=no" \
                        backend/ $USER@$DEPLOY_HOST:$APP_DIR/backend/
                    '''

                    // Restart backend service
                    sh '''
                    sshpass -p "$PASS" ssh -o StrictHostKeyChecking=no \
                        $USER@$DEPLOY_HOST "
                            cd $APP_DIR/backend &&
                            source venv/bin/activate &&
                            sudo systemctl restart mitm-webserver-backend.service
                        "
                    '''
                }
            }
        }
    }

    post {
        success {
            echo '✅ Deployment successful (password-based SSH)!'
        }
        failure {
            echo '❌ Deployment failed!'
        }
    }
}
