mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
feat(securite): encrypt SMTP passwords and NocoDB tokens at rest, log supplier mails
Encryption (server/crypto.ts): - AES-256-GCM with a key derived from ENCRYPTION_KEY, falling back to SESSION_SECRET so existing deployments need no new configuration - stored format enc:v1:<iv>:<tag>:<data>; encryption is idempotent and decryption passes legacy plaintext through unchanged, so nothing breaks mid-migration - tampered data or a changed key raises an explicit error instead of returning garbage - encrypt/decrypt is confined to the storage layer: group writes encrypt smtpPassword (decrypted only in emailService at connection time, never sent to the client), NocoDB config writes encrypt apiToken and reads decrypt it so the invoice verification and the admin page behave as before - startup migration sweep encrypts secrets already stored in plaintext, idempotently; the active-config log line no longer prints the token Mail history (supplier_mail_logs): - every send attempt is recorded: delivery, store, supplier, recipient, subject, status sent/failed with error, message id, user id and name; a logging failure never fails the send itself - GET /api/supplier-mail-logs restricted to the user's stores (admin may filter by store) - on the reconciliation page the mail icon turns green once a request has been sent, with the date and sender in the tooltip; clicking again resends - table created in init.sql, versioned migrations and the production startup migration, with delivery/group indexes Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
This commit is contained in:
9 files changed
+433
-40
No files matched your search
@@ -985,6 +985,23 @@ export type WeatherSettings = typeof weatherSettings.$inferSelect;
|
||||
export type InsertWeatherSettings = z.infer<typeof insertWeatherSettingsSchema>;
|
||||
|
||||
// Configuration Webhook BAP
|
||||
// Historique des mails de relance envoyés aux fournisseurs (rapprochement)
|
||||
export const supplierMailLogs = pgTable("supplier_mail_logs", {
|
||||
id: serial("id").primaryKey(),
|
||||
deliveryId: integer("delivery_id").notNull(),
|
||||
groupId: integer("group_id").notNull(),
|
||||
supplierId: integer("supplier_id"),
|
||||
supplierName: varchar("supplier_name", { length: 255 }), // figé au moment de l'envoi
|
||||
sentTo: varchar("sent_to", { length: 255 }).notNull(), // adresse destinataire
|
||||
subject: text("subject"),
|
||||
status: varchar("status", { length: 20 }).notNull(), // 'sent' | 'failed'
|
||||
errorMessage: text("error_message"),
|
||||
messageId: varchar("message_id", { length: 255 }),
|
||||
sentBy: varchar("sent_by").notNull(), // id utilisateur
|
||||
sentByName: varchar("sent_by_name", { length: 255 }), // nom lisible, figé
|
||||
createdAt: timestamp("created_at").defaultNow(),
|
||||
});
|
||||
|
||||
export const webhookBapConfig = pgTable("webhook_bap_config", {
|
||||
id: serial("id").primaryKey(),
|
||||
name: varchar("name", { length: 100 }).notNull().default("Configuration BAP"),
|
||||
@@ -1005,3 +1022,11 @@ export const insertWebhookBapConfigSchema = createInsertSchema(webhookBapConfig)
|
||||
// Webhook BAP Types
|
||||
export type WebhookBapConfig = typeof webhookBapConfig.$inferSelect;
|
||||
export type InsertWebhookBapConfig = z.infer<typeof insertWebhookBapConfigSchema>;
|
||||
|
||||
// Supplier mail logs
|
||||
export const insertSupplierMailLogSchema = createInsertSchema(supplierMailLogs).omit({
|
||||
id: true,
|
||||
createdAt: true,
|
||||
});
|
||||
export type SupplierMailLog = typeof supplierMailLogs.$inferSelect;
|
||||
export type InsertSupplierMailLog = z.infer<typeof insertSupplierMailLogSchema>;
|
||||
Reference in new issue
Block a user