355 Commits
Author SHA1 Message Date
LogiFlowandClaude Opus 5.5 6760f43e87 feat(api) : gérer les clés de l'API externe depuis Paramètres (#570)
Nouvel onglet Paramètres > API externe (admin) : état de l'API, adresse,
création d'une clé nommée par outil (affichée une seule fois), liste avec
dernière utilisation, révocation immédiate.

- table external_api_keys (empreinte SHA-256 uniquement), créée par
  migrations.production.ts et init.sql
- l'API accepte les clés de Paramètres et toujours celles de
  EXTERNAL_API_KEYS ; 503 seulement si aucune clé active
- routes /api/external-api/keys (session + admin)
- documentation et .env.example mis à jour

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JrRFddV2BaqDCxGY1j52UJ
2026-10-10 09:53:41 +02:00
LogiFlowandClaude bd3bb5e64a feat(api): compléter la facture des fournisseurs en rapprochement automatique (#568)
Les livraisons d'un fournisseur en rapprochement automatique sont validées
d'office à la saisie du BL ; PATCH /api/ext/v1/deliveries/:id les refusait
donc (409) sauf à les dévalider. Pour ces fournisseurs, la référence, les
montants HT/TTC et l'échéance s'écrivent désormais directement, la livraison
restant validée.

- automaticReconciliation exposé sur chaque livraison renvoyée par l'API
- documentation mise à jour avec un exemple


Claude-Session: https://claude.ai/code/session_01LEhR8Cok79VpsxixhrKChM

Co-authored-by: Claude <noreply@anthropic.com>
2026-10-10 09:11:08 +02:00
MichaelandClaude Opus 5.5 6f1a39e4b2 feat(api): API externe de rapprochement BL / factures
Nouvelle API sous /api/ext/v1, authentifiée par clé (EXTERNAL_API_KEYS,
en-tête X-API-Key ou Authorization: Bearer), pour qu'un outil tiers
lise magasins, fournisseurs et livraisons livrées (n° BL) puis écrive
la référence, les montants et l'échéance de la facture, avec
validation/dévalidation optionnelle du rapprochement.

- normalizeDateString extrait dans server/dateUtils.ts pour être partagé
- /api/ext/ exempté du CSRF (pas de cookie de session)
- EXTERNAL_API_KEYS ajouté à .env.example et docker-compose.yml
- documentation : docs/API-RAPPROCHEMENT.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 15:14:45 +02:00
MichaelandClaude Opus 5.5 2274c9bb4a fix(reconciliation): auto-reconcile deliveries from automatic suppliers on validation
POST /api/deliveries/:id/validate never set reconciled=true for suppliers in
automatic reconciliation mode, so their deliveries showed in neither the
Manuels tab (auto suppliers excluded) nor Validées (reconciled=false).

- validate endpoint now marks reconciled + validatedAt for auto suppliers
- Validées tab includes all deliveries from auto suppliers
- migration backfills reconciled for existing delivered deliveries with BL

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-09 09:18:43 +02:00
Claude 944d99733c fix(meteo): afficher la réponse de l'API même si son enregistrement échoue
La température de l'an dernier disparaissait alors que Visual Crossing
répondait correctement (tableau de bord : requêtes réussies, 0 échec,
et l'URL d'historique testée dans le navigateur renvoie bien la journée).
Quand l'enregistrement de la réponse en cache échouait (par exemple une
contrainte d'unicité sur la date déjà occupée par la météo relevée ce
jour-là l'an dernier), la route relisait le cache, n'y trouvait rien et
jetait la donnée reçue : previousYear restait à null et l'API était
réinterrogée à chaque affichage.

La route garde désormais la réponse de l'API pour l'affichage quand
l'enregistrement échoue (année en cours et année précédente), et
journalise une réponse d'historique vide. Reproduit sur un Postgres local
avec une contrainte UNIQUE (date, location) et une API simulée renvoyant
la réponse réelle : N-1 vide avant, 14,1° après ; sans contrainte, le
comportement est inchangé.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-05 14:22:44 +00:00
Claude 8a27b310d2 fix(meteo): repli sur la météo relevée l'an dernier pour la comparaison N-1
La comparaison avec l'année dernière disparaît quand Visual Crossing
refuse durablement l'historique (plan, quota) : le repli précédent ne
cherchait que des lignes N-1 déjà en cache (is_current_year = false) à
7 jours près, qui n'existent plus si l'historique échoue depuis plus
d'une semaine.

La table weather_data garde pourtant la météo relevée chaque jour l'an
dernier, quand ces dates étaient « aujourd'hui » (is_current_year =
true). La route l'utilise désormais en second repli, au jour le plus
proche de la date cible (7 jours max), et journalise l'absence totale de
donnée N-1.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-05 14:10:06 +00:00
Claude 6bb61cdbcc fix(db): ne plus arrêter le serveur quand Postgres coupe une connexion
Quand la base redémarre (redéploiement, restart du conteneur) ou que le
réseau coupe, pg-pool émet 'error' pour chaque connexion inactive
interrompue. Aucun écouteur n'était branché sur le pool de server/db.ts :
Node levait l'événement non géré et arrêtait tout le serveur, avec un
dump géant du client pg dans les logs. Le pool écarte déjà la connexion
fautive et en ouvre une neuve à la requête suivante : on se contente de
journaliser le code et le message.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-05 14:07:23 +00:00
Claude d384271a30 fix(meteo): rétablir les appels séquentiels à l'API météo
La comparaison avec l'année dernière avait disparu du widget météo depuis
l'optimisation des chargements. La route /api/weather/current interrogeait
Visual Crossing pour aujourd'hui et pour l'année dernière en parallèle :
la seconde requête d'une même clé peut alors être refusée (limite de
requêtes simultanées), laissant previousYear à null. Les deux appels
redeviennent séquentiels comme avant ; seules les lectures du cache local
restent en parallèle.

Le widget retrouve son comportement d'origine (plus de cache de 30
minutes ni de retry désactivé), pour qu'un échec ponctuel ne masque plus
la comparaison pendant une demi-heure. Les erreurs de l'API journalisent
désormais la raison renvoyée par Visual Crossing (quota, plan, clé).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-04 18:13:03 +00:00
Claude a5785f0244 perf(serveur): réponses API allégées, compression, cache des assets et index
- Fichiers statiques servis avant la session (plus de requêtes SQL par
  asset), /assets en cache immuable 1 an, index.html en no-cache, et
  compression gzip/brotli des réponses (dépendance compression, externe
  dans le bundle esbuild du Dockerfile).
- req.user (déjà chargé par deserializeUser) réutilisé dans les handlers
  au lieu de relire l'utilisateur et ses magasins à chaque appel ;
  GET /api/user ne refait plus de requête.
- Listes : le magasin joint est réduit aux champs lus par l'interface
  (plus de logo base64 ni de configuration SMTP/NocoDB dans chaque ligne),
  plus aucune empreinte de mot de passe dans les créateurs/auteurs ni dans
  /api/users.
- N+1 supprimés (/api/users, annonces, historique SAV, caches de
  vérification des factures), requêtes indépendantes en parallèle (stats,
  analytics, météo, getDelivery, getUserWithGroups), jointure
  multiplicative des statistiques par magasin corrigée.
- Échéancier limité au magasin demandé ; filtre status sur
  GET /api/deliveries.
- Index de performance créés en arrière-plan au démarrage
  (CREATE INDEX CONCURRENTLY, reliquats invalides purgés sans verrou
  exclusif).
- La connexion n'attend plus la sauvegarde quotidienne ; purge du cache
  des factures active en production ; logs volumineux retirés des
  chemins chauds ; NODE_ENV fixé dans l'image.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-03 04:29:51 +00:00
Claude 3eea2eb47b fix(meteo): fall back to nearest cached data when the history API fails
The dashboard widget lost the previous-year temperature and the difference:
when the day's previous-year row is not yet cached and the Visual Crossing
history call fails (quota exhausted, outage, or a plan without history
access), the route silently returned previousYear: null and the widget
hid the comparison.

The weather cache accumulates one previous-year row per day, so the route
now falls back to the nearest cached previous-year entry within 7 days of
the weekday-aligned target date, keeping the comparison on screen through
API failures. The exact API error remains logged server-side
(🌤️ [ERROR] / [FETCH-HISTORY]) for diagnosis.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-15 21:08:44 +00:00
Claude 4220131432 fix(types): bring real code to zero TypeScript errors, fix three latent bugs
Continues the cleanup from 164 errors down to 88, all of which now sit in
MemStorage — the in-memory dev mock — documented as known debt. Production
server code and the entire client are at zero errors.

Three genuine defects surfaced by the types and fixed:
- deleteAnnouncement returned void while routes check the result and answer
  404 "not found" on falsy: deleting an announcement succeeded in DB but the
  API reported failure on the fallback paths; it now returns a real boolean
- AnnouncementMemoryStorage declared getAnnouncement twice; the first
  implementation was dead at runtime (second definition wins) and is removed
- one route called storage.getDeliveryById(), a method that does not exist,
  crashing with a TypeError whenever hit; it now calls getDelivery()

Everything else is type-level only (annotations, null-to-undefined for
inline styles, honest signatures for markClientCalled's comment parameter
and the invoice verification result's invoiceAmountTTC field), verified
behavior-neutral: client build, production server bundle and the SMTP
end-to-end test all pass unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:42:24 +00:00
Claude 0a816fa881 fix(securite): lock down the two unauthenticated emergency endpoints
- POST /api/emergency-admin-reset accepted a fallback secret hardcoded in
  the repository, letting anyone who read the source reset the production
  admin account to admin/admin (EMERGENCY_SECRET is not set in the shipped
  docker-compose, so the fallback was live). The route now returns 404
  unless EMERGENCY_SECRET is explicitly configured, and invalid attempts
  are logged.
- POST /api/admin/emergency-migration ran database migrations with no
  authentication at all; it now requires an authenticated admin.

A sweep of the remaining API surface found no other unauthenticated
mutation or read routes beyond /api/health. .env.example documents
EMERGENCY_SECRET and ENCRYPTION_KEY.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:21:40 +00:00
Claude 37a8d2b40c fix(logs): redact secrets from request-body logs, cut render-time debug noise
- POST /api/groups logged the full request body, which now carries the
  store's SMTP password; a redactBody() helper masks smtpPassword, apiToken
  and password in the six log sites that print request bodies
- Groups.tsx logged a debug object on every render; removed
- BLReconciliation's auto-fill mutation logged five lines per verified
  delivery; collapsed to one DEV-gated line, keeping console.error

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:20:29 +00:00
Claude af3800aa09 chore: remove committed session cookies, debug artifacts and dead code
Repo hygiene pass:
- cookie.txt / cookies.txt held real session cookies and must never be
  committed; .gitignore now blocks them along with .env files
- half a megabyte of debug screenshots, one-shot production hotfix scripts
  (all superseded by the automatic startup migrations), scratch files and
  the unused attached_assets folder (with its dangling @assets vite alias)
- dead code: server/storage-old.ts (unreferenced, 167 of the project's 430
  TypeScript errors) and five client pages no route ever imported
  (BLReconciliationNative, Avoirs_backup, TasksSimplified, TasksListSimple,
  TasksProductionSimple)

TypeScript error count drops from 430 to 261 with no behavior change; the
client build is unaffected.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:14:45 +00:00
Claude 9de717387f feat(securite): encrypt SMTP passwords and NocoDB tokens at rest, log supplier mails
Encryption (server/crypto.ts):
- AES-256-GCM with a key derived from ENCRYPTION_KEY, falling back to
  SESSION_SECRET so existing deployments need no new configuration
- stored format enc:v1:<iv>:<tag>:<data>; encryption is idempotent and
  decryption passes legacy plaintext through unchanged, so nothing breaks
  mid-migration
- tampered data or a changed key raises an explicit error instead of
  returning garbage
- encrypt/decrypt is confined to the storage layer: group writes encrypt
  smtpPassword (decrypted only in emailService at connection time, never sent
  to the client), NocoDB config writes encrypt apiToken and reads decrypt it
  so the invoice verification and the admin page behave as before
- startup migration sweep encrypts secrets already stored in plaintext,
  idempotently; the active-config log line no longer prints the token

Mail history (supplier_mail_logs):
- every send attempt is recorded: delivery, store, supplier, recipient,
  subject, status sent/failed with error, message id, user id and name;
  a logging failure never fails the send itself
- GET /api/supplier-mail-logs restricted to the user's stores (admin may
  filter by store)
- on the reconciliation page the mail icon turns green once a request has
  been sent, with the date and sender in the tooltip; clicking again resends
- table created in init.sql, versioned migrations and the production
  startup migration, with delivery/group indexes

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:02:55 +00:00
Claude 012024a293 feat(mails): send supplier document requests over each store's own SMTP
Replaces the mailto: link with a server-side send, so the message carries the
store's signature and logo instead of depending on each workstation's Outlook.

Store record (groups):
- address, phone and logo (data URI, 200 KB cap) feed the mail signature
- per-store SMTP settings: host, port, SSL/STARTTLS, credentials, sender
  address and display name, with an enable switch
- "test connection" button verifies the server without sending anything
- the empty-form literal, previously repeated five times, becomes one constant

Sending:
- nodemailer transport built per store from its own settings
- multipart mail: plain-text alternative plus HTML whose signature embeds the
  logo as an inline CID attachment, which Outlook renders without the remote
  image blocking that a data: URI would hit
- delivery details are HTML-escaped
- Reply-To set to the store address; the row shows a spinner and refuses a
  second click while a send is in flight

Credentials:
- the SMTP password is never returned to the client; a response-layer
  sanitizer strips it from every /api payload and replaces it with a
  smtpPasswordSet flag, covering the ten-plus queries that join full group
  rows into deliveries, orders and user relations
- an empty password field on save keeps the stored one rather than clearing it

Verified end-to-end against a local SMTP server: transport, auth, From/Reply-To,
multipart structure and the inline logo attachment.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 15:25:00 +00:00
MichaelandClaude Fable 5 753b301066 perf: add missing indexes and remove N+1 queries
The app degraded progressively over a year of data growth. Four causes,
all cumulative:

1. No indexes. Apart from primary keys, unique constraints and
   session.expire, no table carried an index. PostgreSQL does not index
   foreign keys automatically, so every filter and join on group_id,
   supplier_id, order_id and the date columns did a sequential scan.
   Worst offender: user_groups.user_id, read by getUserWithGroups() on
   every authenticated request.

2. N+1 in the order and delivery listings. getOrders,
   getOrdersByDateRange, getDeliveries and getDeliveriesByDateRange
   issued one to two queries per row to load relations. Relations are now
   loaded in bulk and grouped in Node: three queries regardless of volume.

3. /api/sync-order-delivery-status reloaded the whole deliveries table on
   every iteration of its loop over orders. It now uses the deliveries
   getOrders() already attaches.

4. clearExpiredCache() was implemented but never called, so
   invoice_verification_cache grew without bound. Now scheduled every 6h.

Also replaces the full-history downloads on the Groups and Suppliers
pages, which fetched every order and delivery with nested relations only
to count rows, with aggregate endpoints that count in the database.

Indexes are created via scripts/auto-migrate-production.sh, the script
that actually runs at deploy time, using CREATE INDEX CONCURRENTLY so no
write lock is taken. Note that server/migrations.ts explicitly ignores
the migrations/ directory and runs only hardcoded migrations; the SQL
file added there is for reference and manual application.

Verified: typecheck baseline 440 errors, 430 after, none new in the
changed code; vite build passes; server boots; functional test confirms
the aggregate endpoints match the source data including the delivered
count.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-14 11:55:49 +02:00
MichaelandClaude Sonnet 4.6 693d9460cb feat(contacts): add company field to free contacts
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-15 11:29:56 +02:00
MichaelandClaude Sonnet 4.6 b8ecacee3b merge(main): resolve conflicts keeping codefou + email on suppliers
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-15 11:14:35 +02:00
MichaelandClaude Sonnet 4.6 805664dc32 feat(contacts): add contacts page with per-store management and supplier email field
- New contacts table (group_id, name, role, phone, email, notes) per store
- Suppliers table: add email field with form and card display
- Page /contacts: two-column layout (suppliers read-only / free contacts CRUD)
- Permissions: read all roles, create/edit/delete admin + directeur + manager
- Admin can filter contacts by store; other roles see their own stores only
- Migration SQL: 20260515_add_contacts_and_supplier_email.sql

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-15 10:44:39 +02:00
Michael 3cdd76e223 feat: add BAP webhook configuration and testing routes to server API 2026-04-29 12:11:16 +02:00
Michael 79cd5d4f61 feat: implement date normalization utility and add BAP webhook configuration management routes 2026-04-29 12:02:21 +02:00
Michael 0255dc4aba feat: add BAP file upload functionality to sidebar with processing status modal 2026-04-02 14:58:17 +02:00
Michael 55191c511b feat: implement BAP webhook configuration management and customer order tracking support 2026-04-02 12:52:20 +02:00
Michael a91027c10b feat: implement DLC tracking page with EAN lookup and CRUD operations for product expiration management 2026-04-02 09:46:59 +02:00
Michael 44950d2239 feat: implement supplier management module with CRUD operations and optimistic updates 2026-04-02 09:38:30 +02:00
Michael 1488accbdb feat: implement mobile-optimized DLC management page with EAN lookup and status-based filtering 2026-04-02 09:28:46 +02:00
Michael 40cf456a64 fix(backup): resolve real admin user ID instead of hardcoded 'system' for automatic backups
Fixes FK violation: database_backups.created_by -> users.id
The 'system' user does not exist in the users table, causing
INSERT failures every hour for scheduled backups.
2026-02-10 09:41:12 +01:00
Michael cb1a1a933c fix(dlc): filter stockEpuise products from DLC stats and invalidate stats cache 2026-02-10 09:37:02 +01:00
Michael 16ef17957d fix(db): increase connection pool size and timeout to handle concurrent verifications 2026-01-13 16:54:26 +01:00
Michael 03cb562866 fix(server): resolve duplicate fetch declaration in invoice proxy 2026-01-13 16:44:46 +01:00
Michael 443093573a chore(server): add logging for webhook url in invoice proxy 2026-01-13 16:41:47 +01:00
Michael 65eb74a96e fix(server): use createRequire for form-data to resolve dynamic import issues 2026-01-13 16:36:46 +01:00
Michael 9c0ba9559d fix(server): fix form-data dynamic import for webhook invoice sending 2026-01-13 16:27:35 +01:00
Michael 0f8920f326 feat(security): ameliorations securite - CSRF, sanitization validator.js, eval removal 2026-01-12 14:29:02 +01:00
Michael 78adc2c5ae feat(BAP): remplacer destinataire Celia par Jeremy 2026-01-12 14:13:21 +01:00
Michael 8772e7e0b2 feat(BAP): remplacer destinataire Celia par Jeremy 2026-01-12 14:09:25 +01:00
Michael 78b53f576b feat: Implement new dashboard, publicity management, and calendar pages with corresponding server routes. 2026-01-06 11:39:28 +01:00
michaelschal cca262230e Remove Multer dependency and implement custom multipart form data parsing
Replace Multer with a custom multipart form data parser in the invoice sending route to handle file uploads manually.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 06ccc22f-0202-44ef-842e-1398da8ca1f8
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: c4f6adde-b136-457f-ac0c-fcdc03a680db
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/06ccc22f-0202-44ef-842e-1398da8ca1f8/leGOKHM
2025-11-04 16:42:20 +00:00
michaelschal 881a747ebc Update invoice sending to use Multer for file uploads
Replace Busboy with Multer for handling multipart/form-data uploads for the invoice sending API endpoint in `server/routes.ts`.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 06ccc22f-0202-44ef-842e-1398da8ca1f8
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 57dda692-8f64-40f3-b873-418a8c7efa67
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/06ccc22f-0202-44ef-842e-1398da8ca1f8/leGOKHM
2025-11-04 16:38:21 +00:00
michaelschal 1b34e274b9 Add file upload capability to the system
Integrate Busboy to handle multipart/form-data requests for file uploads.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 06ccc22f-0202-44ef-842e-1398da8ca1f8
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: bfef1078-7f0e-4c03-aedc-d4660547e68a
2025-11-04 15:40:15 +00:00
michaelschal ca576dc289 Improve invoice sending by proxying requests through the backend
Introduces a new backend API endpoint to proxy invoice sending requests, resolving CORS issues and enhancing error handling.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: df58cf24-9a7e-4197-bdbe-786d56d0c35e
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/qOJ89TE
2025-11-04 15:26:40 +00:00
michaelschal e3785d4457 Update invoice sending to directly use webhook URL and add timeout
Replaced the backend proxy route for sending invoices with a direct fetch to the webhook URL, incorporating a 60-second timeout using AbortController. Also added 'busboy' and '@types/busboy' to package.json.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: ca0ae43e-5b56-4b02-8cb5-0e76adf608ba
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/qOJ89TE
2025-11-04 15:21:16 +00:00
michaelschal 89211e4f28 Improve invoice sending by proxying through backend
Replaces direct webhook calls for invoice sending with a backend API endpoint, utilizing multer for file uploads and form-data for robust data transmission. Includes improved error handling and logging.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: e89da884-7d51-4b3d-8af5-22493ce6f2c1
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/qOJ89TE
2025-11-04 15:17:17 +00:00
michaelschal fb6c06d150 Update file upload handling to use native Node.js FormData
Migrate from the 'form-data' npm package to Node.js's built-in 'node:buffer' module for FormData, File, and Blob to resolve dynamic require errors and improve compatibility with newer Node.js versions.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: fb46322f-df17-46db-ba41-3f694e6331a9
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 15:08:20 +00:00
michaelschal e9827c333d Add ability to upload files to external webhooks
Import and utilize the 'form-data' library in server/routes.ts to construct and send multipart/form-data payloads to external webhooks.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 181f13b7-a0a2-4b4f-989d-214861ea2c19
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 14:54:28 +00:00
michaelschal cbcef39aa2 Enable admins and directors to send invoices via webhook
Introduce a new backend route `/api/reconciliation/send-invoice-webhook` to proxy invoice data to external webhooks, converting files to base64 and handling CORS issues.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 6f3c3694-5a67-4b47-b27c-af49da7ad447
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 14:49:08 +00:00
michaelschal c55ee2aabe Update product sorting to show active items first
Modify the database query in `server/storage.ts` to prioritize active products (status not 'valides' and not processed/stock épuisé) to appear before processed, stock épuisé, or valides products in the results.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 427b5397-73ab-43e6-8938-8421d3c5aef4
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 14:31:01 +00:00
michaelschal 42a7c494f2 Display processed products first and visually indicate their status
Adjusted product display logic to prioritize and style products that have been processed or validated, ensuring they appear at the beginning of the list with a distinct visual treatment.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 7b704198-c867-4dc2-bcfa-f3fd0e9ea029
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 14:24:37 +00:00
michaelschal 5f30c68676 Improve DCL product sorting logic to show active items first
Update DCL product sorting in DatabaseStorage to prioritize active products (status 'valides', not out of stock, not processed) by assigning them a lower CASE value, and then sort by expiryDate.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: d092b7f6-df07-4bbf-8198-16c2b8bfdfa4
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
2025-11-04 14:20:48 +00:00