Merge pull request #449 from R0m1k3/1.1

Add alternative POST method for deleting advertisements to bypass res…
This commit is contained in:
LogiFlow authored and GitHub committed 2025-09-15 12:02:27 +02:00
commit 6762697cba
5 files changed
+274 -14

No files matched your search

+4
View File
@@ -15,6 +15,10 @@ run = ["npm", "run", "start"]
localPort = 5000
externalPort = 80
[[ports]]
localPort = 38151
externalPort = 3003
[[ports]]
localPort = 38343
externalPort = 3000
@@ -0,0 +1,201 @@
🔍 [PRODUCTION] Looking for user with username: admin
🔍 [PRODUCTION] Looking for user with username: admin
🔍 [PRODUCTION] Looking for user with username: admin_local
🔍 [PRODUCTION] User search result: Found
🔍 [PRODUCTION] User search result: Found
❌ [PRODUCTION] User not found with username: admin_local
🔍 [PRODUCTION] User search result: Not found
🎯 [PRODUCTION] Found announcements: 3
GET /api/announcements 304 in 84ms
GET /api/user 304 in 5ms
Orders API called with: {
startDate: undefined,
endDate: undefined,
storeId: '1',
userRole: 'admin'
}
🔍 Admin orders filtering by store: { storeId: '1', groupIds: [ 1 ], role: 'admin' }
Fetching all orders
Deliveries API called with: {
startDate: undefined,
endDate: undefined,
storeId: '1',
withBL: undefined,
userRole: 'admin'
}
🔍 Admin deliveries filtering by store: { storeId: '1', groupIds: [ 1 ], role: 'admin' }
Fetching all deliveries
📢 [SERVER] Fetching announcements for user: admin_local environment: production
Customer Orders API called with: { groupIds: [ 1 ], userRole: 'admin' }
🔗 PRODUCTION: getOrders() récupéré 69 commandes avec relations
Orders returned: 69 items
GET /api/orders 304 in 152ms
📢 [SERVER] User found: { username: 'admin', role: 'admin' }
🎯 [PRODUCTION] Using PostgreSQL DASHBOARD_MESSAGES table
🔗 PRODUCTION: getDeliveries() récupéré 97 livraisons avec relations
Deliveries returned: 97 items
GET /api/deliveries 200 in 187ms
Customer Orders returned: 12 items
🔍 [PRODUCTION] Raw messages from DB: 3 items: [
{
id: 17,
title: 'Module Avoir',
content: "Le module d'avoir est en place",
type: 'error',
storeId: 1,
createdBy: 'admin',
createdAt: 2025-09-09T07:47:47.650Z
},
{
id: 16,
title: 'Mise à jour Prix',
content: 'Merci de mettre vos prix a jour tous les matins, certain magasin ne le font pas.',
type: 'success',
storeId: null,
createdBy: 'admin',
createdAt: 2025-08-18T10:45:08.585Z
},
{
id: 8,
title: 'Bon de Livraison',
content: 'Lorsque vous rentrez un numéro de bon de livraison, faite le a l identique, même les majuscules. Pour My candy Shop, prendre le numéro de commande.',
type: 'info',
storeId: null,
createdBy: 'admin_local',
createdAt: 2025-08-07T11:04:38.123Z
}
]
🔍 [PRODUCTION] Looking for user with username: admin
🔍 [PRODUCTION] Looking for user with username: admin
🔍 [PRODUCTION] Looking for user with username: admin_local
GET /api/customer-orders 304 in 189ms
🔍 [PRODUCTION] User search result: Found
🔍 [PRODUCTION] User search result: Found
🔍 [PRODUCTION] User search result: Not found
🎯 [PRODUCTION] Found announcements: 3
❌ [PRODUCTION] User not found with username: admin_local
GET /api/announcements 304 in 190ms
GET /api/groups 304 in 187ms
GET /api/user 304 in 4ms
📋 API PUBLICITIES REQUEST: { year: '2025', filterYear: 2025, storeId: '1', userRole: 'admin' }
📋 CALLING storage.getPublicities: { filterYear: 2025, groupIds: [ 1 ] }
📋 PUBLICITES FETCHED: 29 résultats pour année 2025
🔍 PREMIERS RESULTATS: [
'1. N°2501 - Blanc',
'2. N°2502 - Moins de 1€ 2€ 3€ 4€ 5€',
'3. N°2503 - Imbattables'
]
📋 PUBLICITIES RETURNED: { count: 29 }
GET /api/publicities 304 in 8ms
📋 API PUBLICITIES REQUEST: { year: '2026', filterYear: 2026, storeId: '1', userRole: 'admin' }
📋 CALLING storage.getPublicities: { filterYear: 2026, groupIds: [ 1 ] }
📋 PUBLICITES FETCHED: 23 résultats pour année 2026
🔍 PREMIERS RESULTATS: [
'1. N°2601 - Blanc',
'2. N°2602 - Catalogue',
'3. N°2602 - Catalogue plein Air Moorea 124 pages'
]
📋 PUBLICITIES RETURNED: { count: 23 }
GET /api/publicities 304 in 7ms
HEAD /api/health 200 in 0ms
Binary file not shown.

After

Width:  |  Height:  |  Size: 314 KiB

+35 -9
View File
@@ -94,16 +94,42 @@ export default function Publicities() {
const deleteMutation = useMutation({
mutationFn: async (id: number) => {
const response = await fetch(`/api/publicities/${id}`, { method: 'DELETE' });
if (!response.ok) {
const error = await response.json();
throw new Error(error.message || 'Erreur lors de la suppression');
// Try POST first (for production environments that block DELETE)
console.log(`🗑️ [Frontend] Attempting to delete publicity ${id} using POST method`);
try {
const response = await fetch(`/api/publicities/${id}/delete`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({})
});
if (response.ok) {
console.log(`✅ [Frontend] Successfully deleted publicity ${id} using POST`);
return response.json();
} else if (response.status === 404) {
// Route not found, try DELETE method as fallback (for dev environment)
console.log(`⚠️ [Frontend] POST route not found, trying DELETE method`);
const deleteResponse = await fetch(`/api/publicities/${id}`, { method: 'DELETE' });
if (!deleteResponse.ok) {
const error = await deleteResponse.json();
throw new Error(error.message || 'Erreur lors de la suppression');
}
// Handle empty response (204 No Content)
if (deleteResponse.status === 204) {
return { message: "Publicity deleted successfully" };
}
return deleteResponse.json();
} else {
const error = await response.json();
throw new Error(error.message || 'Erreur lors de la suppression');
}
} catch (error) {
console.error(`❌ [Frontend] Failed to delete publicity ${id}:`, error);
throw error;
}
// Handle empty response (204 No Content) in production
if (response.status === 204) {
return { message: "Publicity deleted successfully" };
}
return response.json();
},
onSuccess: () => {
queryClient.invalidateQueries({ queryKey: ['/api/publicities'] });
+34 -5
View File
@@ -3563,15 +3563,44 @@ export async function registerRoutes(app: Express): Promise<Server> {
}
});
// Alternative DELETE route using POST (for production environments that block DELETE)
app.post('/api/publicities/:id/delete', isAuthenticated, async (req: any, res) => {
const publicityId = req.params.id;
console.log(`🗑️ [API-POST] DELETE via POST request received for publicity ID: ${publicityId}`);
console.log(`🗑️ [API-POST] User info:`, {
hasUser: !!req.user,
userId: req.user?.id || req.user?.claims?.sub,
method: req.method,
url: req.url
});
try {
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
if (!user) {
console.log(`❌ [API-POST] User not found for publicity deletion: ${publicityId}`);
return res.status(404).json({ message: "User not found" });
}
console.log(`🗑️ [API-POST] User found:`, { id: user.id, role: user.role, name: user.name });
// Check permissions (admin only for deletion)
if (user.role !== 'admin') {
console.log(`❌ [API-POST] Insufficient permissions for publicity deletion: ${publicityId}, user role: ${user.role}`);
return res.status(403).json({ message: "Insufficient permissions" });
}
const id = parseInt(publicityId);
console.log(`🗑️ [API-POST] Admin ${user.name} (${user.id}) attempting to delete publicity ${id} via POST`);
await storage.deletePublicity(id);
console.log(`✅ [API-POST] Successfully deleted publicity ${id} by admin ${user.name} via POST`);
res.json({ message: "Publicity deleted successfully" });
} catch (error) {
console.error(`❌ [API-POST] Error deleting publicity ${publicityId} via POST:`, error);
res.status(500).json({ message: "Failed to delete publicity", error: error.message });
}
});
// Schema logging route for production debugging
app.get('/api/debug/log-schema', isAuthenticated, async (req: any, res) => {