- Fichiers statiques servis avant la session (plus de requêtes SQL par
asset), /assets en cache immuable 1 an, index.html en no-cache, et
compression gzip/brotli des réponses (dépendance compression, externe
dans le bundle esbuild du Dockerfile).
- req.user (déjà chargé par deserializeUser) réutilisé dans les handlers
au lieu de relire l'utilisateur et ses magasins à chaque appel ;
GET /api/user ne refait plus de requête.
- Listes : le magasin joint est réduit aux champs lus par l'interface
(plus de logo base64 ni de configuration SMTP/NocoDB dans chaque ligne),
plus aucune empreinte de mot de passe dans les créateurs/auteurs ni dans
/api/users.
- N+1 supprimés (/api/users, annonces, historique SAV, caches de
vérification des factures), requêtes indépendantes en parallèle (stats,
analytics, météo, getDelivery, getUserWithGroups), jointure
multiplicative des statistiques par magasin corrigée.
- Échéancier limité au magasin demandé ; filtre status sur
GET /api/deliveries.
- Index de performance créés en arrière-plan au démarrage
(CREATE INDEX CONCURRENTLY, reliquats invalides purgés sans verrou
exclusif).
- La connexion n'attend plus la sauvegarde quotidienne ; purge du cache
des factures active en production ; logs volumineux retirés des
chemins chauds ; NODE_ENV fixé dans l'image.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MsDJjQrAggcJwbbBtKhgyb
- manualChunks separates react/wouter, react-query, recharts and lucide
from application code: the main bundle drops from 1.73 MB to 1.08 MB and
vendor chunks stay browser-cached across deployments since they only
change on dependency upgrades
- esbuild "pure" removes console.log/console.debug from production builds
(console.warn/error kept); the Dockerfile now builds the frontend with
NODE_ENV=production so the setting actually applies — this silences the
debug-log flood users saw in the browser console in production
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
Replaces the mailto: link with a server-side send, so the message carries the
store's signature and logo instead of depending on each workstation's Outlook.
Store record (groups):
- address, phone and logo (data URI, 200 KB cap) feed the mail signature
- per-store SMTP settings: host, port, SSL/STARTTLS, credentials, sender
address and display name, with an enable switch
- "test connection" button verifies the server without sending anything
- the empty-form literal, previously repeated five times, becomes one constant
Sending:
- nodemailer transport built per store from its own settings
- multipart mail: plain-text alternative plus HTML whose signature embeds the
logo as an inline CID attachment, which Outlook renders without the remote
image blocking that a data: URI would hit
- delivery details are HTML-escaped
- Reply-To set to the store address; the row shows a spinner and refuses a
second click while a send is in flight
Credentials:
- the SMTP password is never returned to the client; a response-layer
sanitizer strips it from every /api payload and replaces it with a
smtpPasswordSet flag, covering the ten-plus queries that join full group
rows into deliveries, orders and user relations
- an empty password field on save keeps the stored one rather than clearing it
Verified end-to-end against a local SMTP server: transport, auth, From/Reply-To,
multipart structure and the inline logo attachment.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01FHdE9nEh8zHhQNGpCgrtYe
Update Dockerfile to correctly copy and execute the entrypoint script, revert CMD to node dist/index.js, and update the SOLUTION_IMMEDIATE.md and add fix-docker-entrypoint.sh to address the 'exec /app/scripts/docker-entrypoint.sh: no such file or directory' error by manually applying database migrations for DLC products.
Replit-Commit-Author: Agent
Replit-Commit-Session-Id: f9197b9b-a5b3-4469-a27d-930a9e9ee736
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/f9197b9b-a5b3-4469-a27d-930a9e9ee736/i2gFnxm