Nouvelle API sous /api/ext/v1, authentifiée par clé (EXTERNAL_API_KEYS,
en-tête X-API-Key ou Authorization: Bearer), pour qu'un outil tiers
lise magasins, fournisseurs et livraisons livrées (n° BL) puis écrive
la référence, les montants et l'échéance de la facture, avec
validation/dévalidation optionnelle du rapprochement.
- normalizeDateString extrait dans server/dateUtils.ts pour être partagé
- /api/ext/ exempté du CSRF (pas de cookie de session)
- EXTERNAL_API_KEYS ajouté à .env.example et docker-compose.yml
- documentation : docs/API-RAPPROCHEMENT.md
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
POST /api/deliveries/:id/validate never set reconciled=true for suppliers in
automatic reconciliation mode, so their deliveries showed in neither the
Manuels tab (auto suppliers excluded) nor Validées (reconciled=false).
- validate endpoint now marks reconciled + validatedAt for auto suppliers
- Validées tab includes all deliveries from auto suppliers
- migration backfills reconciled for existing delivered deliveries with BL
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The app degraded progressively over a year of data growth. Four causes,
all cumulative:
1. No indexes. Apart from primary keys, unique constraints and
session.expire, no table carried an index. PostgreSQL does not index
foreign keys automatically, so every filter and join on group_id,
supplier_id, order_id and the date columns did a sequential scan.
Worst offender: user_groups.user_id, read by getUserWithGroups() on
every authenticated request.
2. N+1 in the order and delivery listings. getOrders,
getOrdersByDateRange, getDeliveries and getDeliveriesByDateRange
issued one to two queries per row to load relations. Relations are now
loaded in bulk and grouped in Node: three queries regardless of volume.
3. /api/sync-order-delivery-status reloaded the whole deliveries table on
every iteration of its loop over orders. It now uses the deliveries
getOrders() already attaches.
4. clearExpiredCache() was implemented but never called, so
invoice_verification_cache grew without bound. Now scheduled every 6h.
Also replaces the full-history downloads on the Groups and Suppliers
pages, which fetched every order and delivery with nested relations only
to count rows, with aggregate endpoints that count in the database.
Indexes are created via scripts/auto-migrate-production.sh, the script
that actually runs at deploy time, using CREATE INDEX CONCURRENTLY so no
write lock is taken. Note that server/migrations.ts explicitly ignores
the migrations/ directory and runs only hardcoded migrations; the SQL
file added there is for reference and manual application.
Verified: typecheck baseline 440 errors, 430 after, none new in the
changed code; vite build passes; server boots; functional test confirms
the aggregate endpoints match the source data including the delivered
count.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- New contacts table (group_id, name, role, phone, email, notes) per store
- Suppliers table: add email field with form and card display
- Page /contacts: two-column layout (suppliers read-only / free contacts CRUD)
- Permissions: read all roles, create/edit/delete admin + directeur + manager
- Admin can filter contacts by store; other roles see their own stores only
- Migration SQL: 20260515_add_contacts_and_supplier_email.sql
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Fixes FK violation: database_backups.created_by -> users.id
The 'system' user does not exist in the users table, causing
INSERT failures every hour for scheduled backups.