- Fichiers statiques servis avant la session (plus de requêtes SQL par
asset), /assets en cache immuable 1 an, index.html en no-cache, et
compression gzip/brotli des réponses (dépendance compression, externe
dans le bundle esbuild du Dockerfile).
- req.user (déjà chargé par deserializeUser) réutilisé dans les handlers
au lieu de relire l'utilisateur et ses magasins à chaque appel ;
GET /api/user ne refait plus de requête.
- Listes : le magasin joint est réduit aux champs lus par l'interface
(plus de logo base64 ni de configuration SMTP/NocoDB dans chaque ligne),
plus aucune empreinte de mot de passe dans les créateurs/auteurs ni dans
/api/users.
- N+1 supprimés (/api/users, annonces, historique SAV, caches de
vérification des factures), requêtes indépendantes en parallèle (stats,
analytics, météo, getDelivery, getUserWithGroups), jointure
multiplicative des statistiques par magasin corrigée.
- Échéancier limité au magasin demandé ; filtre status sur
GET /api/deliveries.
- Index de performance créés en arrière-plan au démarrage
(CREATE INDEX CONCURRENTLY, reliquats invalides purgés sans verrou
exclusif).
- La connexion n'attend plus la sauvegarde quotidienne ; purge du cache
des factures active en production ; logs volumineux retirés des
chemins chauds ; NODE_ENV fixé dans l'image.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
- POST /api/emergency-admin-reset accepted a fallback secret hardcoded in
the repository, letting anyone who read the source reset the production
admin account to admin/admin (EMERGENCY_SECRET is not set in the shipped
docker-compose, so the fallback was live). The route now returns 404
unless EMERGENCY_SECRET is explicitly configured, and invalid attempts
are logged.
- POST /api/admin/emergency-migration ran database migrations with no
authentication at all; it now requires an authenticated admin.
A sweep of the remaining API surface found no other unauthenticated
mutation or read routes beyond /api/health. .env.example documents
EMERGENCY_SECRET and ENCRYPTION_KEY.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
Resolves an issue where the automatic backup service was not initialized in the production environment, preventing daily backups. Updates `docker-compose.yml` to include a backup directory and volume, modifies `index.production.ts` to import and initialize the backup service, and enhances `replit.md` with details of the fix. A new verification script `scripts/verify-backup-system.sh` is added to confirm the system's functionality.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: cc2d271b-82f0-4d6a-9302-a0b067ffb429
Replit-Commit-Checkpoint-Type: full_checkpoint
Remove direct weather data access for all users and enforce administrator-only viewing of weather information by implementing role-based access control on the API endpoint. Refactor weather system initialization to use a new auto-configuration module that fetches API keys from environment variables.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d43bd811-9372-45a7-8ac9-4a954c0538e1
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d43bd811-9372-45a7-8ac9-4a954c0538e1/cp1Ryg6
Add diagnostic scripts and enhance server configuration to better identify and resolve production issues, including 502 errors and static file serving problems.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 54292eb6-296c-47a3-8f4e-c9967863556c
Replit-Commit-Checkpoint-Type: full_checkpoint
Implement an emergency endpoint for resetting the admin password in production, and enhance the default admin user creation logic to handle password migrations and force resets. Also, introduce a new script for resetting the admin password.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 54292eb6-296c-47a3-8f4e-c9967863556c
Replit-Commit-Checkpoint-Type: full_checkpoint
Revert and adjust TypeScript configurations, refine server route types, and update database connection handling for better performance and compatibility.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 2743061c-c65e-41ed-bf21-8da6d73315e6
Replit-Commit-Checkpoint-Type: full_checkpoint