Commit Graph
17 Commits
Author SHA1 Message Date
Claude a5785f0244 perf(serveur): réponses API allégées, compression, cache des assets et index
- Fichiers statiques servis avant la session (plus de requêtes SQL par
  asset), /assets en cache immuable 1 an, index.html en no-cache, et
  compression gzip/brotli des réponses (dépendance compression, externe
  dans le bundle esbuild du Dockerfile).
- req.user (déjà chargé par deserializeUser) réutilisé dans les handlers
  au lieu de relire l'utilisateur et ses magasins à chaque appel ;
  GET /api/user ne refait plus de requête.
- Listes : le magasin joint est réduit aux champs lus par l'interface
  (plus de logo base64 ni de configuration SMTP/NocoDB dans chaque ligne),
  plus aucune empreinte de mot de passe dans les créateurs/auteurs ni dans
  /api/users.
- N+1 supprimés (/api/users, annonces, historique SAV, caches de
  vérification des factures), requêtes indépendantes en parallèle (stats,
  analytics, météo, getDelivery, getUserWithGroups), jointure
  multiplicative des statistiques par magasin corrigée.
- Échéancier limité au magasin demandé ; filtre status sur
  GET /api/deliveries.
- Index de performance créés en arrière-plan au démarrage
  (CREATE INDEX CONCURRENTLY, reliquats invalides purgés sans verrou
  exclusif).
- La connexion n'attend plus la sauvegarde quotidienne ; purge du cache
  des factures active en production ; logs volumineux retirés des
  chemins chauds ; NODE_ENV fixé dans l'image.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
2026-10-03 04:29:51 +00:00
Claude 0a816fa881 fix(securite): lock down the two unauthenticated emergency endpoints
- POST /api/emergency-admin-reset accepted a fallback secret hardcoded in
  the repository, letting anyone who read the source reset the production
  admin account to admin/admin (EMERGENCY_SECRET is not set in the shipped
  docker-compose, so the fallback was live). The route now returns 404
  unless EMERGENCY_SECRET is explicitly configured, and invalid attempts
  are logged.
- POST /api/admin/emergency-migration ran database migrations with no
  authentication at all; it now requires an authenticated admin.

A sweep of the remaining API surface found no other unauthenticated
mutation or read routes beyond /api/health. .env.example documents
EMERGENCY_SECRET and ENCRYPTION_KEY.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
2026-08-14 16:21:40 +00:00
michaelschal c851aacb28 Fix automatic database backup system for production
Resolves an issue where the automatic backup service was not initialized in the production environment, preventing daily backups. Updates `docker-compose.yml` to include a backup directory and volume, modifies `index.production.ts` to import and initialize the backup service, and enhances `replit.md` with details of the fix. A new verification script `scripts/verify-backup-system.sh` is added to confirm the system's functionality.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: cc2d271b-82f0-4d6a-9302-a0b067ffb429
Replit-Commit-Checkpoint-Type: full_checkpoint
2025-08-18 12:06:40 +00:00
michaelschal 62803e7b39 Restrict weather data access to administrators only
Remove direct weather data access for all users and enforce administrator-only viewing of weather information by implementing role-based access control on the API endpoint. Refactor weather system initialization to use a new auto-configuration module that fetches API keys from environment variables.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d43bd811-9372-45a7-8ac9-4a954c0538e1
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d43bd811-9372-45a7-8ac9-4a954c0538e1/cp1Ryg6
2025-08-15 08:14:23 +00:00
michaelschal 37092a95ba Enable automatic database updates for production environments
Adds automatic execution of database migrations, including schema modifications for the Service After-Sales (SAV) module, upon server startup.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 31f9bd88-0285-4787-81b3-31ceeea5a08b
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/31f9bd88-0285-4787-81b3-31ceeea5a08b/EXHO0Ia
2025-08-14 09:24:47 +00:00
michaelschal a55f75a438 Fix issue preventing delivery validation and update admin password reset
Resolve production authentication error preventing users from validating deliveries, and enhance the admin password reset mechanism for improved security.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 7c468936-2a88-4686-ac0a-84921a45222d
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/7c468936-2a88-4686-ac0a-84921a45222d/jMd9JtM
2025-08-13 14:40:25 +00:00
michaelschal d7241e857e Fixes server build issues and resolves duplicate variable declarations
Resolves build failures in production by fixing duplicate variable declarations in `server/index.production.ts` and ensuring successful esbuild compilation, eliminating TypeScript errors.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 7c468936-2a88-4686-ac0a-84921a45222d
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/7c468936-2a88-4686-ac0a-84921a45222d/cH9Kvea
2025-08-13 13:11:14 +00:00
michaelschal 1745e73b52 Resolve production errors and improve system stability and reliability
Fix critical production errors, including Bad Gateway issues and TypeScript compilation failures, by implementing comprehensive route registration, correcting service configurations, and ensuring production build success.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 7c468936-2a88-4686-ac0a-84921a45222d
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/7c468936-2a88-4686-ac0a-84921a45222d/cH9Kvea
2025-08-13 13:00:39 +00:00
michaelschal b079805288 Add missing API routes and improve system stability for production
Add missing API routes (/api/users, /api/roles, /api/deliveries) and resolve 404 errors in production, alongside improvements to authentication and core routing.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 54292eb6-296c-47a3-8f4e-c9967863556c
Replit-Commit-Checkpoint-Type: full_checkpoint
2025-08-11 16:13:12 +00:00
michaelschal 464eb0bfad Improve production environment diagnostics and error handling
Add diagnostic scripts and enhance server configuration to better identify and resolve production issues, including 502 errors and static file serving problems.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 54292eb6-296c-47a3-8f4e-c9967863556c
Replit-Commit-Checkpoint-Type: full_checkpoint
2025-08-11 16:00:33 +00:00
michaelschal a6efc91d14 Add emergency admin password reset and improve default admin setup
Implement an emergency endpoint for resetting the admin password in production, and enhance the default admin user creation logic to handle password migrations and force resets. Also, introduce a new script for resetting the admin password.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 54292eb6-296c-47a3-8f4e-c9967863556c
Replit-Commit-Checkpoint-Type: full_checkpoint
2025-08-11 15:53:01 +00:00
michaelschal 97f6217dcc Update server configuration and types for improved stability
Revert and adjust TypeScript configurations, refine server route types, and update database connection handling for better performance and compatibility.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 2743061c-c65e-41ed-bf21-8da6d73315e6
Replit-Commit-Checkpoint-Type: full_checkpoint
2025-08-11 15:23:06 +00:00
michaelschal 22a6c5d7f6 Configure production database connection for increased reliability
Updates the server-side database configuration to use standard PostgreSQL for production environments, ensuring a more robust and reliable connection. Previously, it might have defaulted to a different setup or encountered connection issues.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d396e5bd-e32d-4a20-9e7d-71e7102ddc6c
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d396e5bd-e32d-4a20-9e7d-71e7102ddc6c/CrwFq15
2025-08-11 15:12:54 +00:00
michaelschal 2aecaa2672 Adapt application to serve static files directly in production
Remove Vite dependency in production Dockerfile and server configuration, and serve static assets and SPA fallback from the built distribution directory.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d396e5bd-e32d-4a20-9e7d-71e7102ddc6c
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d396e5bd-e32d-4a20-9e7d-71e7102ddc6c/CrwFq15
2025-08-11 15:07:28 +00:00
michaelschal c764fe6c15 Prepare application for production deployment with robust authentication and routing
Introduce production-specific server entry point, setup local authentication with PostgreSQL sessions, and expose the application port in the Dockerfile.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d396e5bd-e32d-4a20-9e7d-71e7102ddc6c
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d396e5bd-e32d-4a20-9e7d-71e7102ddc6c/CrwFq15
2025-08-11 15:05:19 +00:00
michaelschal 7e6dccfadf Update dependencies and production setup for enhanced security and stability
Add bcrypt and encoding libraries, update iconv-lite, and refactor production authentication and database initialization to use native Node.js crypto and improve security.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d396e5bd-e32d-4a20-9e7d-71e7102ddc6c
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d396e5bd-e32d-4a20-9e7d-71e7102ddc6c/kxiUCTd
2025-08-11 14:50:55 +00:00
LogiFlow 2485f71dd7 latest 2025-08-11 14:43:48 +00:00