Continues the cleanup from 164 errors down to 88, all of which now sit in
MemStorage — the in-memory dev mock — documented as known debt. Production
server code and the entire client are at zero errors.
Three genuine defects surfaced by the types and fixed:
- deleteAnnouncement returned void while routes check the result and answer
404 "not found" on falsy: deleting an announcement succeeded in DB but the
API reported failure on the fallback paths; it now returns a real boolean
- AnnouncementMemoryStorage declared getAnnouncement twice; the first
implementation was dead at runtime (second definition wins) and is removed
- one route called storage.getDeliveryById(), a method that does not exist,
crashing with a TypeError whenever hit; it now calls getDelivery()
Everything else is type-level only (annotations, null-to-undefined for
inline styles, honest signatures for markClientCalled's comment parameter
and the invoice verification result's invoiceAmountTTC field), verified
behavior-neutral: client build, production server bundle and the SMTP
end-to-end test all pass unchanged.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
Encryption (server/crypto.ts):
- AES-256-GCM with a key derived from ENCRYPTION_KEY, falling back to
SESSION_SECRET so existing deployments need no new configuration
- stored format enc:v1:<iv>:<tag>:<data>; encryption is idempotent and
decryption passes legacy plaintext through unchanged, so nothing breaks
mid-migration
- tampered data or a changed key raises an explicit error instead of
returning garbage
- encrypt/decrypt is confined to the storage layer: group writes encrypt
smtpPassword (decrypted only in emailService at connection time, never sent
to the client), NocoDB config writes encrypt apiToken and reads decrypt it
so the invoice verification and the admin page behave as before
- startup migration sweep encrypts secrets already stored in plaintext,
idempotently; the active-config log line no longer prints the token
Mail history (supplier_mail_logs):
- every send attempt is recorded: delivery, store, supplier, recipient,
subject, status sent/failed with error, message id, user id and name;
a logging failure never fails the send itself
- GET /api/supplier-mail-logs restricted to the user's stores (admin may
filter by store)
- on the reconciliation page the mail icon turns green once a request has
been sent, with the date and sender in the tooltip; clicking again resends
- table created in init.sql, versioned migrations and the production
startup migration, with delivery/group indexes
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
The app degraded progressively over a year of data growth. Four causes,
all cumulative:
1. No indexes. Apart from primary keys, unique constraints and
session.expire, no table carried an index. PostgreSQL does not index
foreign keys automatically, so every filter and join on group_id,
supplier_id, order_id and the date columns did a sequential scan.
Worst offender: user_groups.user_id, read by getUserWithGroups() on
every authenticated request.
2. N+1 in the order and delivery listings. getOrders,
getOrdersByDateRange, getDeliveries and getDeliveriesByDateRange
issued one to two queries per row to load relations. Relations are now
loaded in bulk and grouped in Node: three queries regardless of volume.
3. /api/sync-order-delivery-status reloaded the whole deliveries table on
every iteration of its loop over orders. It now uses the deliveries
getOrders() already attaches.
4. clearExpiredCache() was implemented but never called, so
invoice_verification_cache grew without bound. Now scheduled every 6h.
Also replaces the full-history downloads on the Groups and Suppliers
pages, which fetched every order and delivery with nested relations only
to count rows, with aggregate endpoints that count in the database.
Indexes are created via scripts/auto-migrate-production.sh, the script
that actually runs at deploy time, using CREATE INDEX CONCURRENTLY so no
write lock is taken. Note that server/migrations.ts explicitly ignores
the migrations/ directory and runs only hardcoded migrations; the SQL
file added there is for reference and manual application.
Verified: typecheck baseline 440 errors, 430 after, none new in the
changed code; vite build passes; server boots; functional test confirms
the aggregate endpoints match the source data including the delivered
count.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- New contacts table (group_id, name, role, phone, email, notes) per store
- Suppliers table: add email field with form and card display
- Page /contacts: two-column layout (suppliers read-only / free contacts CRUD)
- Permissions: read all roles, create/edit/delete admin + directeur + manager
- Admin can filter contacts by store; other roles see their own stores only
- Migration SQL: 20260515_add_contacts_and_supplier_email.sql
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Modify the database query in `server/storage.ts` to prioritize active products (status not 'valides' and not processed/stock épuisé) to appear before processed, stock épuisé, or valides products in the results.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 427b5397-73ab-43e6-8938-8421d3c5aef4
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/LXHtbOp
Update DLC module logic to exclude products marked as processedUntilExpiry from expiring soon and expired alerts in the connection modal, and modify server-side storage to filter out these products from 'expires_soon' and 'expires' status queries.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: e4489986-7b4d-4830-9be8-9e32c2bf8e2e
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/oKSi9br
Update invoice verification service and database storage to include and process `invoiceAmountTTC` (total invoice amount). Modify routes to conditionally save TTC amount and adjust related schemas and cache definitions. Remove commented-out code and unused imports related to SAV ticket history.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 87886fa2-6eb3-432f-a67f-dd9d21591981
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/5hnOUe4
Modify DatabaseStorage and MemStorage classes to incorporate new fields: supplierName, invoiceReference, invoiceAmount, dueDate, and isReconciled, enhancing data persistence and retrieval for invoice management.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 521a9239-53be-4766-99e6-a59de73ba301
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/gTQvEeF
Refactor database storage to use direct value substitution for WHERE clauses, improving performance and simplifying query construction by removing parameterized queries in server/storage.ts. Also, update user group filtering logic in server/routes.ts to correctly handle optional user groups.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/P1V76jG
Update routes to use a new method for fetching a single reconciliation comment by ID, replacing the previous approach of fetching all comments and filtering client-side. This change is reflected in both `routes.ts` and `storage.ts`, where a new `getReconciliationCommentById` method is introduced in the `IStorage` interface and implemented in `DatabaseStorage` and `MemStorage`.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/waxFZ5i
Correct the webhook URL for BAP configuration in multiple files (client, server, migrations). Adjust server startup logic to prevent crashes due to database migration failures in production, and add more verbose logging for environment and database connection status. Reorder integrations in `.replit` file.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: cfbfe47c-0c9a-4ebf-8a41-2937407eccff
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/cfbfe47c-0c9a-4ebf-8a41-2937407eccff/qkkp1hi
Update client-side and server-side logic to correctly process and store date values, ensuring compatibility with PostgreSQL timestamp types. This includes converting string dates to Date objects before insertion and ensuring string IDs are converted to numbers for API calls.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: f2b9c241-9fdd-4abd-9041-720afc8b27d6
Replit-Commit-Checkpoint-Type: full_checkpoint
Update the server-side storage logic in `server/storage.ts` to correctly filter DLC products based on various expiry date statuses ('expires_soon', 'expires', 'en_cours', 'valides'), addressing an issue where certain products were not being displayed in empty lists.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: f2b9c241-9fdd-4abd-9041-720afc8b27d6
Replit-Commit-Checkpoint-Type: full_checkpoint