mirror of
https://github.com/R0m1k3/PleinR.git
synced 2026-10-11 17:27:54 +02:00
Durcissement (lot A) : seed sûr et vide par défaut, mots de passe temporaires affichés une seule fois (#4)
Durcissement (lot A) : seed sûr et vide par défaut, mots de passe temporaires affichés une seule fois
This commit is contained in:
26 files changed
+2154
-327
No files matched your search
+10
-1
@@ -23,8 +23,17 @@ AUTH_URL=
|
||||
|
||||
# ---- First admin user (created by the seed script) ----
|
||||
SEED_ADMIN_EMAIL=admin@plein-r.fr
|
||||
SEED_ADMIN_PASSWORD=changeme123
|
||||
# Laissez vide : un mot de passe aléatoire est généré au premier démarrage,
|
||||
# affiché UNE FOIS dans les journaux, et doit être changé à la première connexion.
|
||||
SEED_ADMIN_PASSWORD=
|
||||
SEED_ADMIN_NAME=Administrateur Plein R
|
||||
# Données de démonstration (adhérents, promotions, demandes, journal et
|
||||
# comptes au mot de passe connu de tous) : uniquement sur un poste de
|
||||
# développement, jamais en production. Par défaut la base reste vide, avec le
|
||||
# référentiel des catégories et le compte administrateur seulement.
|
||||
# Pour retirer des données de démo déjà en base : npm run db:purge-demo
|
||||
# (ou, dans le conteneur : node dist/purge-demo.cjs).
|
||||
SEED_DEMO=false
|
||||
|
||||
# ---- App ----
|
||||
NODE_ENV=production
|
||||
|
||||
@@ -23,7 +23,8 @@ npm run dev # dev server
|
||||
npm run build # production build
|
||||
npm run db:generate # regenerate SQL after editing src/db/schema.ts
|
||||
npm run db:migrate # apply migrations
|
||||
npm run db:seed # seed demo data
|
||||
npm run db:seed # catégories + admin initial ; données de démo si SEED_DEMO=true
|
||||
npm run db:purge-demo # retire les données de démo d'une base qui les a reçues
|
||||
docker compose up --build # full stack
|
||||
```
|
||||
|
||||
@@ -97,6 +98,20 @@ site sans traitement supplémentaire.
|
||||
- La CSP à nonce est posée par `src/middleware.ts`. Elle impose un rendu
|
||||
dynamique : `export const dynamic = "force-dynamic"` est dans `app/layout.tsx`,
|
||||
un HTML pré-généré ne pouvant pas porter de nonce.
|
||||
- Les mots de passe temporaires (création d'adhérent, réinitialisation,
|
||||
invitation staff) ne sont **jamais stockés** : l'action les renvoie et le
|
||||
composant `OneTimeCredentials` les affiche une seule fois, sans redirection.
|
||||
`users.must_change_password` seul persiste.
|
||||
- Le seed ne crée en production que le référentiel des catégories et
|
||||
l'administrateur initial, avec un mot de passe aléatoire affiché une fois
|
||||
dans les journaux (ou `SEED_ADMIN_PASSWORD`) et un changement obligatoire à
|
||||
la première connexion. Toutes les données de démonstration (adhérents,
|
||||
promotions, demandes, journal, comptes `changeme123`) vivent dans
|
||||
`src/db/demo-data.ts`, exigent `SEED_DEMO=true`, et `npm run db:purge-demo`
|
||||
les retire d'une base existante.
|
||||
- Sessions JWT limitées à 7 jours (`auth.config.ts`), HSTS et suppression de
|
||||
`X-Powered-By` dans `next.config.mjs`. Le port Postgres de `docker-compose`
|
||||
n'est publié que sur `127.0.0.1`.
|
||||
- `npm test` verrouille ces protections (`tests/security.test.ts`).
|
||||
|
||||
## Roles
|
||||
|
||||
+3
-3
@@ -1,13 +1,13 @@
|
||||
# syntax=docker/dockerfile:1
|
||||
|
||||
# ---- deps: install all dependencies ----
|
||||
FROM node:20-alpine AS deps
|
||||
FROM node:22-alpine AS deps
|
||||
WORKDIR /app
|
||||
COPY package.json package-lock.json* ./
|
||||
RUN npm ci
|
||||
|
||||
# ---- builder: build Next.js (standalone) + bundle db scripts ----
|
||||
FROM node:20-alpine AS builder
|
||||
FROM node:22-alpine AS builder
|
||||
WORKDIR /app
|
||||
COPY --from=deps /app/node_modules ./node_modules
|
||||
COPY . .
|
||||
@@ -16,7 +16,7 @@ RUN npm run build
|
||||
RUN npm run build:scripts
|
||||
|
||||
# ---- runner: minimal production image ----
|
||||
FROM node:20-alpine AS runner
|
||||
FROM node:22-alpine AS runner
|
||||
WORKDIR /app
|
||||
ENV NODE_ENV=production \
|
||||
NEXT_TELEMETRY_DISABLED=1 \
|
||||
|
||||
+9
-3
@@ -16,8 +16,9 @@ services:
|
||||
volumes:
|
||||
- pgdata:/var/lib/postgresql/data
|
||||
ports:
|
||||
# Host port rarely used (container stays on 5432). Change the left side if needed.
|
||||
- "54329:5432"
|
||||
# Lié à 127.0.0.1 : la base ne doit jamais être joignable depuis le réseau.
|
||||
# Retirez le préfixe uniquement pour un accès distant volontaire (et protégé).
|
||||
- "127.0.0.1:54329:5432"
|
||||
healthcheck:
|
||||
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-pleinr} -d ${POSTGRES_DB:-pleinr}"]
|
||||
interval: 5s
|
||||
@@ -61,7 +62,12 @@ services:
|
||||
LINKEDIN_API_VERSION: ${LINKEDIN_API_VERSION:-}
|
||||
SEED_ON_START: ${SEED_ON_START:-true}
|
||||
SEED_ADMIN_EMAIL: ${SEED_ADMIN_EMAIL:-admin@plein-r.fr}
|
||||
SEED_ADMIN_PASSWORD: ${SEED_ADMIN_PASSWORD:-changeme123}
|
||||
# Vide = un mot de passe aléatoire est généré au premier démarrage et
|
||||
# affiché une seule fois dans les journaux du conteneur.
|
||||
SEED_ADMIN_PASSWORD: ${SEED_ADMIN_PASSWORD:-}
|
||||
# Données de démonstration (adhérents, promotions, comptes au mot de
|
||||
# passe connu) : jamais en production. Base vide par défaut.
|
||||
SEED_DEMO: ${SEED_DEMO:-false}
|
||||
SEED_ADMIN_NAME: ${SEED_ADMIN_NAME:-Administrateur Plein R}
|
||||
ports:
|
||||
# Host port rarely used (container stays on 3000). App reachable at http://HOST:8413
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
ALTER TABLE "users" DROP COLUMN "temp_password";
|
||||
File diff suppressed because it is too large.
Load diff
@@ -78,6 +78,13 @@
|
||||
"when": 1784972681534,
|
||||
"tag": "0010_woozy_luminals",
|
||||
"breakpoints": true
|
||||
},
|
||||
{
|
||||
"idx": 11,
|
||||
"version": "7",
|
||||
"when": 1788512273181,
|
||||
"tag": "0011_drop_temp_password",
|
||||
"breakpoints": true
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -2,6 +2,8 @@
|
||||
const nextConfig = {
|
||||
output: "standalone",
|
||||
reactStrictMode: true,
|
||||
// Pas d'en-tête X-Powered-By : inutile de renseigner un attaquant sur la pile.
|
||||
poweredByHeader: false,
|
||||
experimental: {
|
||||
// Les images d'entête/logo sont envoyées en data-URL via server action.
|
||||
serverActions: { bodySizeLimit: "4mb" },
|
||||
@@ -11,6 +13,12 @@ const nextConfig = {
|
||||
{
|
||||
source: "/:path*",
|
||||
headers: [
|
||||
// HSTS : une fois le site vu en HTTPS, le navigateur refuse le HTTP
|
||||
// clair pendant un an. Sans effet tant que le site est servi en HTTP.
|
||||
{
|
||||
key: "Strict-Transport-Security",
|
||||
value: "max-age=31536000; includeSubDomains",
|
||||
},
|
||||
// Empêche l'interprétation d'une réponse selon un type deviné.
|
||||
{ key: "X-Content-Type-Options", value: "nosniff" },
|
||||
// Le site ne doit pas être encadré par un tiers (clickjacking).
|
||||
|
||||
Generated
+52
-52
@@ -11,9 +11,9 @@
|
||||
"bcryptjs": "^2.4.3",
|
||||
"dotenv": "^16.4.7",
|
||||
"drizzle-orm": "^0.45.2",
|
||||
"next": "^15.5.21",
|
||||
"next": "^15.5.25",
|
||||
"next-auth": "^5.0.0-beta.32",
|
||||
"pg": "^8.13.1",
|
||||
"pg": "^8.23.0",
|
||||
"react": "19.0.0",
|
||||
"react-dom": "19.0.0",
|
||||
"zod": "^3.24.1"
|
||||
@@ -1044,15 +1044,15 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/env": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/env/-/env-15.5.21.tgz",
|
||||
"integrity": "sha512-hjJI/GfrjWHgNguRIBzItjRRu0m3Nrz17GhxsjuHfjIvg9hyg3239REd2dpI+bpMTFuVrVprHzEQ19m++cDtbw==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/env/-/env-15.5.25.tgz",
|
||||
"integrity": "sha512-42h1lLr07vl4gawALP1hsgRZjHB1xYa58JfUfHwr0f7jG/zhPakh5GHkADHXOC9ZxUvlQFOPIrp7s6qX4DezPQ==",
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/@next/swc-darwin-arm64": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-darwin-arm64/-/swc-darwin-arm64-15.5.21.tgz",
|
||||
"integrity": "sha512-ZfjqPEdi6TRC/fWx7UDbwb1fbVgyh2uD5tVTRKIDZDlYM+UNuE/LafDG2fwuAoZilADpABh46OY/F5qf9JjqLQ==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-darwin-arm64/-/swc-darwin-arm64-15.5.25.tgz",
|
||||
"integrity": "sha512-w+RR0v/QuApnWEjRGm1z6gcObKwGMb5YPA7V3bzBEVSBpMFUXprer0tS27UxjUcEnqbhL7Zuzohej79B6rYmBg==",
|
||||
"cpu": [
|
||||
"arm64"
|
||||
],
|
||||
@@ -1066,9 +1066,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-darwin-x64": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-darwin-x64/-/swc-darwin-x64-15.5.21.tgz",
|
||||
"integrity": "sha512-TlCf1NpxgQLzTrexuev75xwmNCJMd1/qkJpTVP1GRRcih93hlIBn1P72hkh8T0gnRFr6BmWksQtbyG3jT6jnww==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-darwin-x64/-/swc-darwin-x64-15.5.25.tgz",
|
||||
"integrity": "sha512-QiGGBUSakt8S1H4Lt9Ehsh6Ja87axiBnQQgysOObvCbI7iUfJnRGntF1P64S4/ijuHFnSB8KLsEddkY3nN26uw==",
|
||||
"cpu": [
|
||||
"x64"
|
||||
],
|
||||
@@ -1082,9 +1082,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-linux-arm64-gnu": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-arm64-gnu/-/swc-linux-arm64-gnu-15.5.21.tgz",
|
||||
"integrity": "sha512-LXRsq1p+HvHSi7ygwNcSEEcK0zuo5jS75ZlqFHtOH+LF7qntXAJVJxah+1Pi/GyBm7EpkwU7m4EgbvIKrMqm9A==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-arm64-gnu/-/swc-linux-arm64-gnu-15.5.25.tgz",
|
||||
"integrity": "sha512-ehLos/66zo0d/mJCU5u96a/VDcr01aaUrX0o/i16UdInxz8qPTCDSxGtjk/Lps1sIr1RJFdiX3hxc0fxJo+cPA==",
|
||||
"cpu": [
|
||||
"arm64"
|
||||
],
|
||||
@@ -1098,9 +1098,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-linux-arm64-musl": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-arm64-musl/-/swc-linux-arm64-musl-15.5.21.tgz",
|
||||
"integrity": "sha512-hyGixhFxpDKjqoev6l4KlcRBlt9AXWrGhDZwmwg49sMJM5tnKQPSi+SEj9+e5n+l/bthRGZUdh59GKIs6lQPRw==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-arm64-musl/-/swc-linux-arm64-musl-15.5.25.tgz",
|
||||
"integrity": "sha512-ZVMrqLiJ7DiChgmbkQwFtdhAnUkSH/4p7tB29QY+giATb0Q/XGHNRSKAb/B8XGDHRUaA67NepOW5W8u3ZRJBAA==",
|
||||
"cpu": [
|
||||
"arm64"
|
||||
],
|
||||
@@ -1114,9 +1114,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-linux-x64-gnu": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-x64-gnu/-/swc-linux-x64-gnu-15.5.21.tgz",
|
||||
"integrity": "sha512-qfE+YfOba6S2+13e8qn1/UozDVNZ2clBlrs8UtDoax4s8ediu6sq93z66OEHUYlb69Tffh5JTNkgtsAKiSuugg==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-x64-gnu/-/swc-linux-x64-gnu-15.5.25.tgz",
|
||||
"integrity": "sha512-UOewtDGkTMJTiODrEdeLZ50yGb59xCZSriNpXkfPMxRRgwDkGc7i8mLWqV5076wEdb+Ca/XN7MhJyM3CupyNyQ==",
|
||||
"cpu": [
|
||||
"x64"
|
||||
],
|
||||
@@ -1130,9 +1130,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-linux-x64-musl": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-x64-musl/-/swc-linux-x64-musl-15.5.21.tgz",
|
||||
"integrity": "sha512-BXLGG+EvIwp/Rrgl6HY8sqvD6BOUOIRz8/naDbeLNX7mlA5H2XRcL6MW/0IGnJISfj5BA9gNhFyJj5yOoiIDJQ==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-linux-x64-musl/-/swc-linux-x64-musl-15.5.25.tgz",
|
||||
"integrity": "sha512-UBHwA8AhkCZgtRfU1aJpunuAJe/6gZv6jDESQe4p5MjTb5V0YEeJBWCdNqx15Vj3x+5jmauRfeMJSjfQj9HGFQ==",
|
||||
"cpu": [
|
||||
"x64"
|
||||
],
|
||||
@@ -1146,9 +1146,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-win32-arm64-msvc": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-win32-arm64-msvc/-/swc-win32-arm64-msvc-15.5.21.tgz",
|
||||
"integrity": "sha512-tNGNOlT0Wn7E4IMsSnufjXN/l2L2/AGdLLpa2vzS89SYCBuihgLn3ngLsIrvndAnWo9nAkus+4gZHTI/Ijx9HA==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-win32-arm64-msvc/-/swc-win32-arm64-msvc-15.5.25.tgz",
|
||||
"integrity": "sha512-QcFcPRr16djk5IqK5+e8O80eZfgWzIvVBXfitIq0tQ/uc+eyfdoZ0NmKc0cnbIJyfVwREapKuG97YcxWA9gcpA==",
|
||||
"cpu": [
|
||||
"arm64"
|
||||
],
|
||||
@@ -1162,9 +1162,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@next/swc-win32-x64-msvc": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-win32-x64-msvc/-/swc-win32-x64-msvc-15.5.21.tgz",
|
||||
"integrity": "sha512-DmIdWmC9p4rdNIiQqo8ap0+Cnj6kKtTZnuSCxoYydSc8sgpDgAg9wFhxplunak9imLV0pTvc5WVCOHwm5eHLtQ==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/@next/swc-win32-x64-msvc/-/swc-win32-x64-msvc-15.5.25.tgz",
|
||||
"integrity": "sha512-zREeykps3ndWr9egJgvJKqVkkDuaw6Zrrg23cYBos0ygydFkAWYU4+PaPVwXzP1eAYQJe53ShSK45iDM529BOg==",
|
||||
"cpu": [
|
||||
"x64"
|
||||
],
|
||||
@@ -1615,9 +1615,9 @@
|
||||
"peer": true
|
||||
},
|
||||
"node_modules/nanoid": {
|
||||
"version": "3.3.16",
|
||||
"resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.16.tgz",
|
||||
"integrity": "sha512-bzlKTyNJ7+LdGIIwy8ijFpIqEQIvafahV7eYykJ8Cvh42EdJeODoJ6gUJXpQJvej1BddH8OqTXZNE/KfbWAu8Q==",
|
||||
"version": "3.3.18",
|
||||
"resolved": "https://registry.npmjs.org/nanoid/-/nanoid-3.3.18.tgz",
|
||||
"integrity": "sha512-DTg4MJbGMWkfi6VZFdNt2/caMbQy4Ou+Op/hJQvGEWcnVfoA1QA+xzRKAzw9jD6+GVOOeYr/mIcuDSdug6F6+w==",
|
||||
"funding": [
|
||||
{
|
||||
"type": "github",
|
||||
@@ -1633,12 +1633,12 @@
|
||||
}
|
||||
},
|
||||
"node_modules/next": {
|
||||
"version": "15.5.21",
|
||||
"resolved": "https://registry.npmjs.org/next/-/next-15.5.21.tgz",
|
||||
"integrity": "sha512-/TsdBtkWLhkl+NVL3Uqws2UphNd6IPzOtzSk1fHaf+0P7GQKLZDUytyhns/Ykbzdy9+YRjwG7ONvrHaaTDdFqQ==",
|
||||
"version": "15.5.25",
|
||||
"resolved": "https://registry.npmjs.org/next/-/next-15.5.25.tgz",
|
||||
"integrity": "sha512-OMWNulIIqKM2ykvC2qMjIt0IoavB4UB2SCs4iXJ6z6847FvyH8jBmBWcvrF5iuhTu8Przh20Fo/aoszIdqx4PA==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@next/env": "15.5.21",
|
||||
"@next/env": "15.5.25",
|
||||
"@swc/helpers": "0.5.15",
|
||||
"caniuse-lite": "^1.0.30001579",
|
||||
"postcss": "8.4.31",
|
||||
@@ -1651,15 +1651,15 @@
|
||||
"node": "^18.18.0 || ^19.8.0 || >= 20.0.0"
|
||||
},
|
||||
"optionalDependencies": {
|
||||
"@next/swc-darwin-arm64": "15.5.21",
|
||||
"@next/swc-darwin-x64": "15.5.21",
|
||||
"@next/swc-linux-arm64-gnu": "15.5.21",
|
||||
"@next/swc-linux-arm64-musl": "15.5.21",
|
||||
"@next/swc-linux-x64-gnu": "15.5.21",
|
||||
"@next/swc-linux-x64-musl": "15.5.21",
|
||||
"@next/swc-win32-arm64-msvc": "15.5.21",
|
||||
"@next/swc-win32-x64-msvc": "15.5.21",
|
||||
"sharp": "^0.34.3"
|
||||
"@next/swc-darwin-arm64": "15.5.25",
|
||||
"@next/swc-darwin-x64": "15.5.25",
|
||||
"@next/swc-linux-arm64-gnu": "15.5.25",
|
||||
"@next/swc-linux-arm64-musl": "15.5.25",
|
||||
"@next/swc-linux-x64-gnu": "15.5.25",
|
||||
"@next/swc-linux-x64-musl": "15.5.25",
|
||||
"@next/swc-win32-arm64-msvc": "15.5.25",
|
||||
"@next/swc-win32-x64-msvc": "15.5.25",
|
||||
"sharp": "^0.34.3 || ^0.35.4"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@opentelemetry/api": "^1.1.0",
|
||||
@@ -1721,14 +1721,14 @@
|
||||
}
|
||||
},
|
||||
"node_modules/pg": {
|
||||
"version": "8.22.0",
|
||||
"resolved": "https://registry.npmjs.org/pg/-/pg-8.22.0.tgz",
|
||||
"integrity": "sha512-8wih1vVIBMxoUM2oB4soJsD9tDnDpLv4OXBJ+EJzFsvycD+lfyIreC2gGHq78f8jbLLt+bvlPTFdFZfJkOuzAA==",
|
||||
"version": "8.23.0",
|
||||
"resolved": "https://registry.npmjs.org/pg/-/pg-8.23.0.tgz",
|
||||
"integrity": "sha512-Ip2EQCngowJLGOfCwkFhPXU7/ljlhn6Rxlmy4XYfL2Y+vyRM59+8uR2xqRWKdYmbXmxCFOAmKxBuSUCdF34qLg==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"pg-connection-string": "^2.14.0",
|
||||
"pg-pool": "^3.14.0",
|
||||
"pg-protocol": "^1.15.0",
|
||||
"pg-protocol": "^1.16.0",
|
||||
"pg-types": "2.2.0",
|
||||
"pgpass": "1.0.5"
|
||||
},
|
||||
@@ -1779,9 +1779,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/pg-protocol": {
|
||||
"version": "1.15.0",
|
||||
"resolved": "https://registry.npmjs.org/pg-protocol/-/pg-protocol-1.15.0.tgz",
|
||||
"integrity": "sha512-cq9sECI5s0+uPUXjbz8ioyPJni6RzsRib0US67i5IoTZKw8fNeYlVE7u8F4dG7vEJJtc5wdD1K189lCCUwqWTQ==",
|
||||
"version": "1.16.0",
|
||||
"resolved": "https://registry.npmjs.org/pg-protocol/-/pg-protocol-1.16.0.tgz",
|
||||
"integrity": "sha512-sILXutLVjCLjcDuOmvhX5e2Z4cS5qG/6Bu3VkpFwdf/633ElGLpEh9bgmuI5I4sqKqkifQiGyiCcx1HdtrK7tg==",
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/pg-types": {
|
||||
|
||||
+4
-3
@@ -10,16 +10,17 @@
|
||||
"db:generate": "drizzle-kit generate",
|
||||
"db:migrate": "tsx src/db/migrate.ts",
|
||||
"db:seed": "tsx src/db/seed.ts",
|
||||
"build:scripts": "esbuild src/db/migrate.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/migrate.cjs --external:pg-native && esbuild src/db/seed.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/seed.cjs --external:pg-native",
|
||||
"db:purge-demo": "tsx src/db/purge-demo.ts",
|
||||
"build:scripts": "esbuild src/db/migrate.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/migrate.cjs --external:pg-native && esbuild src/db/seed.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/seed.cjs --external:pg-native && esbuild src/db/purge-demo.ts --bundle --platform=node --target=node20 --format=cjs --outfile=dist/purge-demo.cjs --external:pg-native",
|
||||
"test": "tsx --test tests/**/*.test.ts"
|
||||
},
|
||||
"dependencies": {
|
||||
"bcryptjs": "^2.4.3",
|
||||
"dotenv": "^16.4.7",
|
||||
"drizzle-orm": "^0.45.2",
|
||||
"next": "^15.5.21",
|
||||
"next": "^15.5.25",
|
||||
"next-auth": "^5.0.0-beta.32",
|
||||
"pg": "^8.13.1",
|
||||
"pg": "^8.23.0",
|
||||
"react": "19.0.0",
|
||||
"react-dom": "19.0.0",
|
||||
"zod": "^3.24.1"
|
||||
|
||||
+40
-25
@@ -405,7 +405,19 @@ export async function publishPromo(formData: FormData) {
|
||||
}
|
||||
|
||||
// ---- Members CRUD ----
|
||||
export async function addMember(formData: FormData): Promise<number | undefined> {
|
||||
/**
|
||||
* Identifiants d'un compte qui vient d'être créé ou réinitialisé.
|
||||
*
|
||||
* Le mot de passe temporaire n'est **jamais stocké** : il n'existe qu'en
|
||||
* mémoire le temps de la réponse et n'est montré qu'une seule fois, à l'écran
|
||||
* qui a déclenché l'action. Un export de la base ne peut donc plus révéler de
|
||||
* mot de passe utilisable.
|
||||
*/
|
||||
export type IssuedCredentials = { email: string; tempPassword: string };
|
||||
|
||||
export type CreatedMemberAccount = IssuedCredentials & { memberId: number };
|
||||
|
||||
export async function addMember(formData: FormData): Promise<CreatedMemberAccount | undefined> {
|
||||
const { role } = await requireRole();
|
||||
if (!can(role, "manageMembers")) throw new Error("Accès refusé");
|
||||
|
||||
@@ -436,7 +448,6 @@ export async function addMember(formData: FormData): Promise<number | undefined>
|
||||
role: "member",
|
||||
memberId: newMember.id,
|
||||
passwordHash: await bcrypt.hash(tempPassword, 10),
|
||||
tempPassword,
|
||||
mustChangePassword: true,
|
||||
});
|
||||
|
||||
@@ -445,13 +456,14 @@ export async function addMember(formData: FormData): Promise<number | undefined>
|
||||
revalidatePath("/backend/adherents");
|
||||
revalidatePath("/backend");
|
||||
revalidatePath("/");
|
||||
return newMember.id;
|
||||
return { memberId: newMember.id, email, tempPassword };
|
||||
}
|
||||
|
||||
// Crée des comptes de connexion pour les adhérents existants qui n'en ont pas
|
||||
// encore (ceux ajoutés avant l'arrivée des comptes adhérent). Chaque compte
|
||||
// reçoit un mot de passe temporaire à changer à la première connexion.
|
||||
export async function createMissingMemberAccounts() {
|
||||
// reçoit un mot de passe temporaire à changer à la première connexion. Les
|
||||
// identifiants sont renvoyés pour un affichage unique : rien n'est conservé.
|
||||
export async function createMissingMemberAccounts(): Promise<(IssuedCredentials & { name: string })[]> {
|
||||
const { role } = await requireRole();
|
||||
if (!can(role, "manageMembers")) throw new Error("Accès refusé");
|
||||
|
||||
@@ -465,7 +477,7 @@ export async function createMissingMemberAccounts() {
|
||||
const takenEmails = new Set(allUsers.map((u) => u.email.toLowerCase()));
|
||||
const linkedMemberIds = new Set(allUsers.map((u) => u.memberId).filter((x): x is number => x != null));
|
||||
|
||||
let created = 0;
|
||||
const created: (IssuedCredentials & { name: string })[] = [];
|
||||
for (const m of allMembers) {
|
||||
if (linkedMemberIds.has(m.id)) continue;
|
||||
const email = (m.email ?? "").trim().toLowerCase();
|
||||
@@ -478,27 +490,27 @@ export async function createMissingMemberAccounts() {
|
||||
role: "member",
|
||||
memberId: m.id,
|
||||
passwordHash: await bcrypt.hash(tempPassword, 10),
|
||||
tempPassword,
|
||||
mustChangePassword: true,
|
||||
});
|
||||
takenEmails.add(email);
|
||||
created++;
|
||||
created.push({ name: m.name, email, tempPassword });
|
||||
}
|
||||
|
||||
if (created > 0) {
|
||||
await logActivity(`${created} compte(s) adhérent créé(s) pour les fiches existantes`, "#2C6FB3");
|
||||
if (created.length > 0) {
|
||||
await logActivity(`${created.length} compte(s) adhérent créé(s) pour les fiches existantes`, "#2C6FB3");
|
||||
}
|
||||
revalidatePath("/backend/adherents");
|
||||
return created;
|
||||
}
|
||||
|
||||
// Réinitialise le mot de passe d'un adhérent : nouveau mot de passe temporaire
|
||||
// visible par l'admin jusqu'à la prochaine connexion de l'adhérent.
|
||||
export async function resetMemberPassword(formData: FormData) {
|
||||
// Réinitialise le mot de passe d'un adhérent : le nouveau mot de passe
|
||||
// temporaire est renvoyé pour un affichage unique, puis oublié.
|
||||
export async function resetMemberPassword(formData: FormData): Promise<IssuedCredentials | undefined> {
|
||||
const { role } = await requireRole();
|
||||
if (!can(role, "manageMembers")) throw new Error("Accès refusé");
|
||||
|
||||
const memberId = Number(formData.get("memberId"));
|
||||
if (!memberId) return;
|
||||
if (!memberId) return undefined;
|
||||
|
||||
const [u] = await db.select().from(users).where(eq(users.memberId, memberId));
|
||||
if (!u) throw new Error("Aucun compte de connexion lié à cet adhérent.");
|
||||
@@ -508,7 +520,6 @@ export async function resetMemberPassword(formData: FormData) {
|
||||
.update(users)
|
||||
.set({
|
||||
passwordHash: await bcrypt.hash(tempPassword, 10),
|
||||
tempPassword,
|
||||
mustChangePassword: true,
|
||||
// Coupe les sessions ouvertes avec l'ancien mot de passe.
|
||||
sessionVersion: (u.sessionVersion ?? 0) + 1,
|
||||
@@ -516,6 +527,7 @@ export async function resetMemberPassword(formData: FormData) {
|
||||
.where(eq(users.id, u.id));
|
||||
|
||||
revalidatePath(`/backend/adherents/${memberId}`);
|
||||
return { email: u.email, tempPassword };
|
||||
}
|
||||
|
||||
export async function updateMember(formData: FormData) {
|
||||
@@ -568,31 +580,35 @@ export async function deleteMember(formData: FormData) {
|
||||
}
|
||||
|
||||
// ---- Admins ----
|
||||
export async function inviteAdmin(formData: FormData) {
|
||||
export async function inviteAdmin(formData: FormData): Promise<IssuedCredentials | undefined> {
|
||||
const { role } = await requireRole();
|
||||
if (!can(role, "manageAdmins")) throw new Error("Accès refusé");
|
||||
|
||||
const name = String(formData.get("name") ?? "").trim();
|
||||
if (!name) return;
|
||||
if (!name) return undefined;
|
||||
const email = String(formData.get("email") ?? "").trim().toLowerCase();
|
||||
if (!email) return;
|
||||
if (!email) return undefined;
|
||||
const roleLabel = String(formData.get("role") ?? "Administrateur");
|
||||
const newRole: AppRole = LABEL_TO_ROLE[roleLabel] ?? "editor";
|
||||
|
||||
const existing = await db.select().from(users).where(eq(users.email, email));
|
||||
if (existing.length > 0) return;
|
||||
if (existing.length > 0) throw new Error("Un compte existe déjà avec cet e-mail.");
|
||||
|
||||
// Temporary password — the invitee resets it on first login (out of scope here).
|
||||
// Mot de passe temporaire montré une seule fois à l'inviteur, à changer à
|
||||
// la première connexion. Auparavant il n'était ni conservé ni affiché :
|
||||
// l'invité ne pouvait pas se connecter.
|
||||
const tempPassword = generateTempPassword();
|
||||
await db.insert(users).values({
|
||||
name,
|
||||
email,
|
||||
role: newRole,
|
||||
passwordHash: await bcrypt.hash(tempPassword, 10),
|
||||
mustChangePassword: true,
|
||||
});
|
||||
|
||||
await logActivity(`<strong>${name}</strong> a été invité comme ${roleLabel}`, "#2C6FB3");
|
||||
revalidatePath("/backend/administrateurs");
|
||||
return { email, tempPassword };
|
||||
}
|
||||
|
||||
export async function removeAdmin(formData: FormData) {
|
||||
@@ -1056,7 +1072,6 @@ export async function changeOwnPassword(formData: FormData) {
|
||||
.update(users)
|
||||
.set({
|
||||
passwordHash: await bcrypt.hash(password, 10),
|
||||
tempPassword: null,
|
||||
mustChangePassword: false,
|
||||
// Invalide toutes les autres sessions ouvertes sur ce compte.
|
||||
sessionVersion: (user!.sessionVersion ?? 0) + 1,
|
||||
@@ -1104,8 +1119,9 @@ export async function updateOwnProfile(formData: FormData) {
|
||||
}
|
||||
|
||||
// Approuve une demande d'adhésion ET crée directement l'adhérent + son compte
|
||||
// de connexion (mot de passe temporaire). Renvoie l'id du nouvel adhérent.
|
||||
export async function approveMembershipRequest(formData: FormData): Promise<number | undefined> {
|
||||
// de connexion. Renvoie l'id du nouvel adhérent et ses identifiants, à
|
||||
// afficher une seule fois.
|
||||
export async function approveMembershipRequest(formData: FormData): Promise<CreatedMemberAccount | undefined> {
|
||||
const { role } = await requireRole();
|
||||
if (!can(role, "manageMembers")) throw new Error("Accès refusé");
|
||||
|
||||
@@ -1137,7 +1153,6 @@ export async function approveMembershipRequest(formData: FormData): Promise<numb
|
||||
role: "member",
|
||||
memberId: newMember.id,
|
||||
passwordHash: await bcrypt.hash(tempPassword, 10),
|
||||
tempPassword,
|
||||
mustChangePassword: true,
|
||||
});
|
||||
|
||||
@@ -1148,7 +1163,7 @@ export async function approveMembershipRequest(formData: FormData): Promise<numb
|
||||
revalidatePath("/backend/adherents");
|
||||
revalidatePath("/backend");
|
||||
revalidatePath("/");
|
||||
return newMember.id;
|
||||
return { memberId: newMember.id, email, tempPassword };
|
||||
}
|
||||
|
||||
// ---- Inbox: membership requests + contact messages ----
|
||||
|
||||
@@ -1,9 +1,11 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { useRouter } from "next/navigation";
|
||||
import { BASSIN_POMPEY_COMMUNES } from "@/lib/communes";
|
||||
import { addMember } from "../actions";
|
||||
import { OneTimeCredentials } from "@/components/OneTimeCredentials";
|
||||
import { addMember, type CreatedMemberAccount } from "../actions";
|
||||
|
||||
export function AddMemberPanel({
|
||||
categories,
|
||||
@@ -11,10 +13,19 @@ export function AddMemberPanel({
|
||||
categories: { id: number; label: string }[];
|
||||
}) {
|
||||
const [open, setOpen] = useState(false);
|
||||
const [created, setCreated] = useState<CreatedMemberAccount | null>(null);
|
||||
const router = useRouter();
|
||||
|
||||
return (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 0 }}>
|
||||
{created && (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 8, marginBottom: 14 }}>
|
||||
<OneTimeCredentials items={[created]} title="Adhérent créé — identifiants à transmettre" />
|
||||
<Link href={`/backend/adherents/${created.memberId}`} style={{ color: "#2C6FB3", fontWeight: 700, fontSize: 13, textDecoration: "none" }}>
|
||||
Ouvrir la fiche adhérent →
|
||||
</Link>
|
||||
</div>
|
||||
)}
|
||||
<div style={{ display: "flex", justifyContent: "flex-end" }}>
|
||||
<button
|
||||
onClick={() => setOpen((o) => !o)}
|
||||
@@ -28,10 +39,12 @@ export function AddMemberPanel({
|
||||
{open && (
|
||||
<form
|
||||
action={async (fd) => {
|
||||
const id = await addMember(fd);
|
||||
const result = await addMember(fd);
|
||||
setOpen(false);
|
||||
// Redirige vers la fiche : le login + mot de passe temporaire y sont affichés.
|
||||
if (id) router.push(`/backend/adherents/${id}`);
|
||||
// On reste sur la page : le mot de passe temporaire n'est affiché
|
||||
// qu'ici, une seule fois, et n'est conservé nulle part.
|
||||
setCreated(result ?? null);
|
||||
router.refresh();
|
||||
}}
|
||||
style={{ background: "#fff", border: "1px solid #e6dcc6", borderRadius: 16, padding: 22, marginTop: 14 }}
|
||||
>
|
||||
@@ -76,7 +89,7 @@ export function AddMemberPanel({
|
||||
</div>
|
||||
<div style={{ marginTop: 14, fontSize: 12.5, color: "#9a8d72" }}>
|
||||
Un compte de connexion est créé automatiquement. Le mot de passe temporaire s'affiche
|
||||
sur la fiche de l'adhérent jusqu'à sa première connexion.
|
||||
une seule fois, juste après l'enregistrement : notez-le avant de quitter la page.
|
||||
</div>
|
||||
<button
|
||||
type="submit"
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { useRouter } from "next/navigation";
|
||||
import { OneTimeCredentials, type IssuedCredentialsItem } from "@/components/OneTimeCredentials";
|
||||
import { createMissingMemberAccounts } from "../actions";
|
||||
|
||||
export function BackfillAccountsForm({ missingAccounts }: { missingAccounts: number }) {
|
||||
const [issued, setIssued] = useState<IssuedCredentialsItem[] | null>(null);
|
||||
const [pending, setPending] = useState(false);
|
||||
const router = useRouter();
|
||||
|
||||
if (issued) {
|
||||
return (
|
||||
<OneTimeCredentials
|
||||
items={issued.map((i) => ({ label: i.label, email: i.email, tempPassword: i.tempPassword }))}
|
||||
title={`${issued.length} compte(s) créé(s) — identifiants à transmettre`}
|
||||
/>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<form
|
||||
action={async () => {
|
||||
setPending(true);
|
||||
try {
|
||||
const created = await createMissingMemberAccounts();
|
||||
setIssued(created.map((c) => ({ label: c.name, email: c.email, tempPassword: c.tempPassword })));
|
||||
router.refresh();
|
||||
} finally {
|
||||
setPending(false);
|
||||
}
|
||||
}}
|
||||
style={{ background: "#fbeede", border: "1px solid #ecd8b8", borderRadius: 12, padding: "14px 18px", display: "flex", alignItems: "center", justifyContent: "space-between", gap: 14, flexWrap: "wrap" }}
|
||||
>
|
||||
<div style={{ fontSize: 13.5, color: "#9a6638" }}>
|
||||
<strong>{missingAccounts}</strong> adhérent(s) avec un e-mail n'ont pas encore de compte de connexion.
|
||||
</div>
|
||||
<button
|
||||
type="submit"
|
||||
disabled={pending}
|
||||
className="font-display"
|
||||
style={{ border: "none", background: "#9a6638", color: "#fff", fontWeight: 700, fontSize: 13.5, padding: "10px 18px", borderRadius: 10, cursor: "pointer", whiteSpace: "nowrap" }}
|
||||
>
|
||||
{pending ? "Création…" : "Créer les comptes manquants"}
|
||||
</button>
|
||||
</form>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,36 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { OneTimeCredentials } from "@/components/OneTimeCredentials";
|
||||
import { resetMemberPassword, type IssuedCredentials } from "../actions";
|
||||
|
||||
export function ResetPasswordButton({ memberId }: { memberId: number }) {
|
||||
const [issued, setIssued] = useState<IssuedCredentials | null>(null);
|
||||
const [pending, setPending] = useState(false);
|
||||
|
||||
return (
|
||||
<div style={{ marginTop: 14, display: "flex", flexDirection: "column", gap: 12 }}>
|
||||
{issued && <OneTimeCredentials items={[issued]} title="Nouveau mot de passe temporaire" />}
|
||||
<form
|
||||
action={async (fd) => {
|
||||
setPending(true);
|
||||
try {
|
||||
const result = await resetMemberPassword(fd);
|
||||
setIssued(result ?? null);
|
||||
} finally {
|
||||
setPending(false);
|
||||
}
|
||||
}}
|
||||
>
|
||||
<input type="hidden" name="memberId" value={memberId} />
|
||||
<button
|
||||
type="submit"
|
||||
disabled={pending}
|
||||
style={{ border: "1px solid #d8cdb4", background: "#fff", color: "#6f6450", fontWeight: 600, fontSize: 13, padding: "9px 15px", borderRadius: 9, cursor: "pointer" }}
|
||||
>
|
||||
{pending ? "Réinitialisation…" : "Réinitialiser le mot de passe"}
|
||||
</button>
|
||||
</form>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -8,7 +8,8 @@ import { can } from "@/lib/rbac";
|
||||
import { ImageField } from "@/components/ImageField";
|
||||
import { HoursEditor } from "@/components/HoursEditor";
|
||||
import { communeOptions } from "@/lib/communes";
|
||||
import { deleteMember, resetMemberPassword, updateMember } from "../../actions";
|
||||
import { deleteMember, updateMember } from "../../actions";
|
||||
import { ResetPasswordButton } from "../ResetPasswordButton";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -35,7 +36,7 @@ export default async function EditMemberPage({
|
||||
.orderBy(asc(categories.sort));
|
||||
|
||||
const [account] = await db
|
||||
.select({ email: users.email, tempPassword: users.tempPassword, mustChange: users.mustChangePassword })
|
||||
.select({ email: users.email, mustChange: users.mustChangePassword })
|
||||
.from(users)
|
||||
.where(eq(users.memberId, memberId));
|
||||
|
||||
@@ -53,14 +54,6 @@ export default async function EditMemberPage({
|
||||
redirect("/backend/adherents");
|
||||
}
|
||||
|
||||
async function handleReset() {
|
||||
"use server";
|
||||
const fd = new FormData();
|
||||
fd.set("memberId", String(memberId));
|
||||
await resetMemberPassword(fd);
|
||||
redirect(`/backend/adherents/${memberId}`);
|
||||
}
|
||||
|
||||
return (
|
||||
<div style={{ maxWidth: 720 }}>
|
||||
<Link href="/backend/adherents" style={{ textDecoration: "none", color: "#6f6450", fontSize: 13.5, fontWeight: 600 }}>
|
||||
@@ -172,12 +165,11 @@ export default async function EditMemberPage({
|
||||
<div style={{ fontSize: 13.5, color: "#5a5040", marginBottom: 10 }}>
|
||||
Identifiant : <strong>{account.email}</strong>
|
||||
</div>
|
||||
{account.tempPassword ? (
|
||||
{account.mustChange ? (
|
||||
<div style={{ background: "#fbeede", border: "1px solid #ecd8b8", borderRadius: 10, padding: "11px 14px", fontSize: 13.5, color: "#9a6638" }}>
|
||||
Mot de passe temporaire :{" "}
|
||||
<strong style={{ fontFamily: "monospace", fontSize: 15 }}>{account.tempPassword}</strong>
|
||||
En attente de première connexion : l'adhérent devra changer son mot de passe temporaire.
|
||||
<div style={{ fontSize: 12, marginTop: 4 }}>
|
||||
Communiquez-le à l'adhérent. Il disparaît dès sa première connexion (changement obligatoire).
|
||||
Mot de passe égaré ? Réinitialisez-le : un nouveau vous sera montré une seule fois.
|
||||
</div>
|
||||
</div>
|
||||
) : (
|
||||
@@ -185,14 +177,7 @@ export default async function EditMemberPage({
|
||||
✓ L'adhérent a défini son propre mot de passe.
|
||||
</div>
|
||||
)}
|
||||
<form action={handleReset} style={{ marginTop: 14 }}>
|
||||
<button
|
||||
type="submit"
|
||||
style={{ border: "1px solid #d8cdb4", background: "#fff", color: "#6f6450", fontWeight: 600, fontSize: 13, padding: "9px 15px", borderRadius: 9, cursor: "pointer" }}
|
||||
>
|
||||
Réinitialiser le mot de passe
|
||||
</button>
|
||||
</form>
|
||||
<ResetPasswordButton memberId={memberId} />
|
||||
</>
|
||||
) : (
|
||||
<div style={{ fontSize: 13.5, color: "#a99c82" }}>
|
||||
|
||||
@@ -5,8 +5,8 @@ import { getSession } from "@/lib/session";
|
||||
import { db } from "@/db";
|
||||
import { categories, members, users } from "@/db/schema";
|
||||
import { can } from "@/lib/rbac";
|
||||
import { createMissingMemberAccounts } from "../actions";
|
||||
import { AddMemberPanel } from "./AddMemberPanel";
|
||||
import { BackfillAccountsForm } from "./BackfillAccountsForm";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -59,31 +59,9 @@ export default async function AdherentsPage({
|
||||
return !!e && !takenEmails.has(e);
|
||||
}).length;
|
||||
|
||||
async function handleBackfill() {
|
||||
"use server";
|
||||
await createMissingMemberAccounts();
|
||||
redirect("/backend/adherents");
|
||||
}
|
||||
|
||||
return (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 18 }}>
|
||||
{missingAccounts > 0 && (
|
||||
<form
|
||||
action={handleBackfill}
|
||||
style={{ background: "#fbeede", border: "1px solid #ecd8b8", borderRadius: 12, padding: "14px 18px", display: "flex", alignItems: "center", justifyContent: "space-between", gap: 14, flexWrap: "wrap" }}
|
||||
>
|
||||
<div style={{ fontSize: 13.5, color: "#9a6638" }}>
|
||||
<strong>{missingAccounts}</strong> adhérent(s) avec un e-mail n'ont pas encore de compte de connexion.
|
||||
</div>
|
||||
<button
|
||||
type="submit"
|
||||
className="font-display"
|
||||
style={{ border: "none", background: "#9a6638", color: "#fff", fontWeight: 700, fontSize: 13.5, padding: "10px 18px", borderRadius: 10, cursor: "pointer", whiteSpace: "nowrap" }}
|
||||
>
|
||||
Créer les comptes manquants
|
||||
</button>
|
||||
</form>
|
||||
)}
|
||||
{missingAccounts > 0 && <BackfillAccountsForm missingAccounts={missingAccounts} />}
|
||||
|
||||
<AddMemberPanel categories={cats} />
|
||||
|
||||
|
||||
@@ -0,0 +1,66 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import { useRouter } from "next/navigation";
|
||||
import { OneTimeCredentials } from "@/components/OneTimeCredentials";
|
||||
import { inviteAdmin, type IssuedCredentials } from "../actions";
|
||||
|
||||
export function InviteAdminForm() {
|
||||
const [issued, setIssued] = useState<IssuedCredentials | null>(null);
|
||||
const [error, setError] = useState<string | null>(null);
|
||||
const [pending, setPending] = useState(false);
|
||||
const router = useRouter();
|
||||
|
||||
return (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 14 }}>
|
||||
{issued && <OneTimeCredentials items={[issued]} title="Compte créé — identifiants à transmettre" />}
|
||||
{error && (
|
||||
<div role="alert" style={{ background: "#fdecea", border: "1px solid #f1c4bd", borderRadius: 10, padding: "10px 14px", fontSize: 13, color: "#a3372e" }}>
|
||||
{error}
|
||||
</div>
|
||||
)}
|
||||
<form
|
||||
action={async (fd) => {
|
||||
setPending(true);
|
||||
setError(null);
|
||||
try {
|
||||
const result = await inviteAdmin(fd);
|
||||
setIssued(result ?? null);
|
||||
router.refresh();
|
||||
} catch {
|
||||
// Next masque le détail des erreurs serveur en production.
|
||||
setError("Impossible de créer ce compte : vérifiez que l'e-mail n'est pas déjà utilisé.");
|
||||
} finally {
|
||||
setPending(false);
|
||||
}
|
||||
}}
|
||||
>
|
||||
<label className="field-label">Nom complet</label>
|
||||
<input name="name" required placeholder="ex : Julie Bernard" className="field" style={{ marginBottom: 14 }} />
|
||||
|
||||
<label className="field-label">E-mail</label>
|
||||
<input name="email" type="email" required placeholder="prenom@plein-r.fr" className="field" style={{ marginBottom: 14 }} />
|
||||
|
||||
<label className="field-label">Rôle</label>
|
||||
<select name="role" defaultValue="Administrateur" className="field" style={{ marginBottom: 18 }}>
|
||||
<option>Administrateur</option>
|
||||
<option>Modérateur</option>
|
||||
<option>Éditeur</option>
|
||||
</select>
|
||||
|
||||
<button
|
||||
type="submit"
|
||||
disabled={pending}
|
||||
className="font-display"
|
||||
style={{ width: "100%", border: "none", background: "#13324F", color: "#fff", fontWeight: 700, fontSize: 14.5, padding: 13, borderRadius: 11, cursor: "pointer" }}
|
||||
>
|
||||
{pending ? "Création…" : "Créer le compte"}
|
||||
</button>
|
||||
</form>
|
||||
<p style={{ fontSize: 11.5, color: "#a99c82", margin: 0, lineHeight: 1.5 }}>
|
||||
Un mot de passe temporaire est généré et affiché une seule fois ici. L'invité devra le
|
||||
changer à sa première connexion.
|
||||
</p>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -4,7 +4,8 @@ import { getSession } from "@/lib/session";
|
||||
import { db } from "@/db";
|
||||
import { users } from "@/db/schema";
|
||||
import { can, ROLE_LABELS, STAFF_ROLES } from "@/lib/rbac";
|
||||
import { inviteAdmin, removeAdmin } from "../actions";
|
||||
import { removeAdmin } from "../actions";
|
||||
import { InviteAdminForm } from "./InviteAdminForm";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -70,32 +71,7 @@ export default async function AdminsPage() {
|
||||
<h3 className="font-display" style={{ fontWeight: 700, fontSize: 16, margin: "0 0 16px", color: "#26201a" }}>
|
||||
Inviter un administrateur
|
||||
</h3>
|
||||
<form action={inviteAdmin}>
|
||||
<label className="field-label">Nom complet</label>
|
||||
<input name="name" required placeholder="ex : Julie Bernard" className="field" style={{ marginBottom: 14 }} />
|
||||
|
||||
<label className="field-label">E-mail</label>
|
||||
<input name="email" type="email" required placeholder="prenom@plein-r.fr" className="field" style={{ marginBottom: 14 }} />
|
||||
|
||||
<label className="field-label">Rôle</label>
|
||||
<select name="role" defaultValue="Administrateur" className="field" style={{ marginBottom: 18 }}>
|
||||
<option>Administrateur</option>
|
||||
<option>Modérateur</option>
|
||||
<option>Éditeur</option>
|
||||
</select>
|
||||
|
||||
<button
|
||||
type="submit"
|
||||
className="font-display"
|
||||
style={{ width: "100%", border: "none", background: "#13324F", color: "#fff", fontWeight: 700, fontSize: 14.5, padding: 13, borderRadius: 11, cursor: "pointer" }}
|
||||
>
|
||||
Envoyer l'invitation
|
||||
</button>
|
||||
</form>
|
||||
<p style={{ fontSize: 11.5, color: "#a99c82", marginTop: 12, lineHeight: 1.5 }}>
|
||||
Un mot de passe temporaire est généré. L'invité pourra le réinitialiser à la première
|
||||
connexion.
|
||||
</p>
|
||||
<InviteAdminForm />
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
|
||||
@@ -0,0 +1,55 @@
|
||||
"use client";
|
||||
|
||||
import { useState } from "react";
|
||||
import Link from "next/link";
|
||||
import { useRouter } from "next/navigation";
|
||||
import { OneTimeCredentials } from "@/components/OneTimeCredentials";
|
||||
import { approveMembershipRequest, type CreatedMemberAccount } from "../actions";
|
||||
|
||||
/**
|
||||
* Approuve une demande et affiche une seule fois les identifiants du compte
|
||||
* créé. On reste sur la page : une redirection ferait perdre le mot de passe,
|
||||
* qui n'est conservé nulle part.
|
||||
*/
|
||||
export function ApproveRequestForm({ requestId }: { requestId: number }) {
|
||||
const [created, setCreated] = useState<CreatedMemberAccount | null>(null);
|
||||
const [pending, setPending] = useState(false);
|
||||
const router = useRouter();
|
||||
|
||||
if (created) {
|
||||
return (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 8, minWidth: 260 }}>
|
||||
<OneTimeCredentials items={[created]} title="Adhérent créé — identifiants à transmettre" />
|
||||
<Link href={`/backend/adherents/${created.memberId}`} style={{ color: "#2C6FB3", fontWeight: 700, fontSize: 13, textDecoration: "none" }}>
|
||||
Ouvrir la fiche adhérent →
|
||||
</Link>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
|
||||
return (
|
||||
<form
|
||||
action={async (fd) => {
|
||||
setPending(true);
|
||||
try {
|
||||
const result = await approveMembershipRequest(fd);
|
||||
if (result) {
|
||||
setCreated(result);
|
||||
router.refresh();
|
||||
}
|
||||
} finally {
|
||||
setPending(false);
|
||||
}
|
||||
}}
|
||||
>
|
||||
<input type="hidden" name="id" value={requestId} />
|
||||
<button
|
||||
type="submit"
|
||||
disabled={pending}
|
||||
style={{ border: "1px solid #1f8a5b", color: "#1f8a5b", background: "#fff", fontWeight: 700, fontSize: 12.5, padding: "7px 12px", borderRadius: 8, cursor: "pointer", whiteSpace: "nowrap" }}
|
||||
>
|
||||
{pending ? "Création…" : "Approuver & créer"}
|
||||
</button>
|
||||
</form>
|
||||
);
|
||||
}
|
||||
@@ -4,7 +4,8 @@ import { getSession } from "@/lib/session";
|
||||
import { db } from "@/db";
|
||||
import { contactMessages, membershipRequests } from "@/db/schema";
|
||||
import { can } from "@/lib/rbac";
|
||||
import { approveMembershipRequest, setContactStatus, setRequestStatus } from "../actions";
|
||||
import { setContactStatus, setRequestStatus } from "../actions";
|
||||
import { ApproveRequestForm } from "./ApproveRequestForm";
|
||||
|
||||
export const dynamic = "force-dynamic";
|
||||
|
||||
@@ -51,14 +52,6 @@ export default async function DemandesPage() {
|
||||
db.select().from(contactMessages).orderBy(desc(contactMessages.createdAt)),
|
||||
]);
|
||||
|
||||
// Approuver = créer l'adhérent + son compte, puis aller sur sa fiche
|
||||
// (login + mot de passe temporaire y sont affichés).
|
||||
async function handleApprove(fd: FormData) {
|
||||
"use server";
|
||||
const id = await approveMembershipRequest(fd);
|
||||
redirect(id ? `/backend/adherents/${id}` : "/backend/demandes");
|
||||
}
|
||||
|
||||
return (
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 26 }}>
|
||||
{/* ---- Demandes d'adhésion ---- */}
|
||||
@@ -80,10 +73,7 @@ export default async function DemandesPage() {
|
||||
</div>
|
||||
<StatusPill map={REQ_STATUS} status={r.status} />
|
||||
<div style={{ display: "flex", gap: 8 }}>
|
||||
<form action={handleApprove}>
|
||||
<input type="hidden" name="id" value={r.id} />
|
||||
<ActionBtn color="#1f8a5b">Approuver & créer</ActionBtn>
|
||||
</form>
|
||||
<ApproveRequestForm requestId={r.id} />
|
||||
<form action={setRequestStatus}>
|
||||
<input type="hidden" name="id" value={r.id} />
|
||||
<input type="hidden" name="status" value="rejected" />
|
||||
|
||||
@@ -13,6 +13,10 @@ export const authConfig = {
|
||||
},
|
||||
session: {
|
||||
strategy: "jwt",
|
||||
// 7 jours et non 30 : un jeton dérobé sur un poste partagé vaut d'autant
|
||||
// moins longtemps. La révocation immédiate reste assurée par
|
||||
// `users.session_version` (src/lib/session.ts).
|
||||
maxAge: 7 * 24 * 60 * 60,
|
||||
},
|
||||
trustHost: true,
|
||||
callbacks: {
|
||||
|
||||
@@ -0,0 +1,49 @@
|
||||
"use client";
|
||||
|
||||
/**
|
||||
* Affichage unique d'identifiants fraîchement émis.
|
||||
*
|
||||
* Le mot de passe temporaire n'est stocké nulle part : il n'existe que dans
|
||||
* l'état de ce composant, le temps que le staff le relève. Un rechargement de
|
||||
* la page le fait disparaître définitivement (il reste possible de
|
||||
* réinitialiser le mot de passe pour en obtenir un nouveau).
|
||||
*/
|
||||
export type IssuedCredentialsItem = { label?: string; email: string; tempPassword: string };
|
||||
|
||||
export function OneTimeCredentials({
|
||||
items,
|
||||
title = "Identifiants à transmettre",
|
||||
}: {
|
||||
items: IssuedCredentialsItem[];
|
||||
title?: string;
|
||||
}) {
|
||||
if (items.length === 0) return null;
|
||||
return (
|
||||
<div
|
||||
role="status"
|
||||
style={{ background: "#fbeede", border: "1px solid #ecd8b8", borderRadius: 12, padding: "14px 18px", fontSize: 13.5, color: "#9a6638" }}
|
||||
>
|
||||
<div className="font-display" style={{ fontWeight: 700, fontSize: 14.5, marginBottom: 8 }}>
|
||||
{title}
|
||||
</div>
|
||||
<div style={{ display: "flex", flexDirection: "column", gap: 8 }}>
|
||||
{items.map((item) => (
|
||||
<div key={item.email} style={{ display: "flex", flexWrap: "wrap", gap: "4px 14px", alignItems: "baseline" }}>
|
||||
{item.label && <span style={{ fontWeight: 700, color: "#6f4b23" }}>{item.label}</span>}
|
||||
<span>
|
||||
Identifiant : <strong>{item.email}</strong>
|
||||
</span>
|
||||
<span>
|
||||
Mot de passe temporaire :{" "}
|
||||
<strong style={{ fontFamily: "monospace", fontSize: 15, userSelect: "all" }}>{item.tempPassword}</strong>
|
||||
</span>
|
||||
</div>
|
||||
))}
|
||||
</div>
|
||||
<div style={{ fontSize: 12, marginTop: 10, lineHeight: 1.5 }}>
|
||||
Notez-le maintenant : il n'est affiché qu'une seule fois et n'est conservé nulle part.
|
||||
Un changement de mot de passe sera exigé à la première connexion.
|
||||
</div>
|
||||
</div>
|
||||
);
|
||||
}
|
||||
@@ -0,0 +1,137 @@
|
||||
/**
|
||||
* Données de démonstration.
|
||||
*
|
||||
* Elles ne sont insérées que par `npm run db:seed` avec `SEED_DEMO=true`, et
|
||||
* `npm run db:purge-demo` sait les retirer d'une base qui les a reçues. Tout
|
||||
* ce qui identifie ces enregistrements (e-mails, titres, noms, messages) vit
|
||||
* ici pour que les deux scripts restent alignés.
|
||||
*/
|
||||
|
||||
export const DEMO_PASSWORD = "changeme123";
|
||||
|
||||
export function demoMembers(catId: (slug: string) => number | null) {
|
||||
return [
|
||||
{
|
||||
name: "Au Bon Pain",
|
||||
email: "contact@aubonpain.fr",
|
||||
categoryId: catId("boulangerie"),
|
||||
city: "Frouard",
|
||||
address: "12 rue de la République",
|
||||
postalCode: "54390",
|
||||
phone: "03 83 49 00 00",
|
||||
website: "https://www.aubonpain-frouard.fr",
|
||||
memberSince: 2021,
|
||||
tags: "Levain naturel, Produits locaux, Fait maison, Sans conservateur",
|
||||
hours: "Mardi – Vendredi|7h – 19h30\nSamedi|7h – 19h\nDimanche|7h – 13h\nLundi|Fermé",
|
||||
description:
|
||||
"Boulangerie artisanale familiale installée au cœur de Frouard depuis trois générations. Nous travaillons chaque jour des farines locales et un levain naturel pour vous proposer pains, viennoiseries et pâtisseries faits maison.\nNotre équipe vous accueille du mardi au dimanche matin. Spécialités : pain au levain, baguette de tradition, kouglof et tartes aux fruits de saison.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Café des Arts",
|
||||
email: "hello@cafedesarts.fr",
|
||||
categoryId: catId("restauration"),
|
||||
city: "Pompey",
|
||||
address: "3 place Stanislas",
|
||||
postalCode: "54340",
|
||||
phone: "03 83 24 00 00",
|
||||
memberSince: 2019,
|
||||
tags: "Cuisine de saison, Brunch, Terrasse, Produits frais",
|
||||
hours: "Lundi – Vendredi|9h – 18h\nSamedi|9h – 19h\nDimanche|10h – 15h",
|
||||
description: "Cuisine de saison, brunch le dimanche, terrasse au cœur du bourg.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Atelier Émilie",
|
||||
email: "emilie@atelier.fr",
|
||||
categoryId: catId("mode-beaute"),
|
||||
city: "Champigneulles",
|
||||
address: "7 av. des Tilleuls",
|
||||
description: "Salon de coiffure & soins, sur rendez-vous du mardi au samedi.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Garage Moderne",
|
||||
email: "contact@garagemoderne.fr",
|
||||
categoryId: catId("services"),
|
||||
city: "Custines",
|
||||
description: "Entretien et réparation toutes marques.",
|
||||
status: "active" as const,
|
||||
},
|
||||
{
|
||||
name: "Boutique Indigo",
|
||||
email: "indigo@boutique.fr",
|
||||
categoryId: catId("mode-beaute"),
|
||||
city: "Liverdun",
|
||||
description: "Prêt-à-porter et accessoires.",
|
||||
status: "pending" as const,
|
||||
},
|
||||
{
|
||||
name: "Fleurs & Sens",
|
||||
email: "contact@fleursetsens.fr",
|
||||
categoryId: catId("artisanat"),
|
||||
city: "Pompey",
|
||||
description: "Compositions florales, fleurs de saison cueillies localement.",
|
||||
status: "active" as const,
|
||||
},
|
||||
{
|
||||
name: "La Cave Gourmande",
|
||||
email: "bonjour@cavegourmande.fr",
|
||||
categoryId: catId("alimentation"),
|
||||
city: "Frouard",
|
||||
description: "Fromages fermiers, vins et produits du terroir.",
|
||||
status: "active" as const,
|
||||
},
|
||||
];
|
||||
}
|
||||
|
||||
export function demoPromotions(memberId: (name: string) => number | null) {
|
||||
return [
|
||||
{ title: "Le 13e pain offert", text: "Sur présentation de votre carte adhérent, profitez d'une réduction sur nos pains au levain.", category: "Boulangerie", badge: "-20%", memberId: memberId("Au Bon Pain"), status: "live" as const, validUntil: "Valable jusqu'au 30 juin" },
|
||||
{ title: "Formule midi du marché", text: "Entrée + plat + café à 15€ tous les midis de semaine. Produits frais et locaux.", category: "Restauration", badge: "Menu 15€", memberId: memberId("Café des Arts"), status: "live" as const, validUntil: "Du lundi au vendredi" },
|
||||
{ title: "Soin offert dès 2 prestations", text: "Profitez de -30% sur le 2e soin réservé dans le mois. Sur rendez-vous.", category: "Beauté", badge: "-30%", memberId: memberId("Atelier Émilie"), status: "pending" as const, validUntil: "Jusqu'au 15 juillet" },
|
||||
{ title: "Révision auto à prix réseau", text: "15€ de remise sur votre forfait révision pour tous les adhérents Plein R.", category: "Services", badge: "-15€", memberId: memberId("Garage Moderne"), status: "pending" as const, validUntil: "Toute l'année" },
|
||||
{ title: "Bouquet du mois en promo", text: "-25% sur la composition florale du mois. Fleurs de saison, cueillies localement.", category: "Artisanat", badge: "-25%", memberId: memberId("Fleurs & Sens"), status: "live" as const, validUntil: "Jusqu'au 30 juin" },
|
||||
{ title: "2 fromages achetés, 1 offert", text: "Sur une sélection de fromages fermiers. L'occasion de découvrir nos producteurs.", category: "Alimentation", badge: "2+1", memberId: memberId("La Cave Gourmande"), status: "live" as const, validUntil: "Ce week-end" },
|
||||
];
|
||||
}
|
||||
|
||||
export const demoRequests = [
|
||||
{ name: "Boutique Indigo", email: "indigo@boutique.fr", message: "Souhaite rejoindre le réseau." },
|
||||
{ name: "Pizzeria Bella", email: "contact@bella.fr", message: "Demande d'adhésion." },
|
||||
{ name: "Coworking La Ruche", email: "hello@laruche.fr", message: "Espace de travail partagé." },
|
||||
];
|
||||
|
||||
export const demoActivity = [
|
||||
{ dot: "#1f8a5b", message: "<strong>Atelier Émilie</strong> a publié une promotion « Soin offert dès 2 prestations »" },
|
||||
{ dot: "#E0A63C", message: "<strong>Garage Moderne</strong> a soumis une promotion en attente de validation" },
|
||||
{ dot: "#2C6FB3", message: "Nouvelle demande d'adhésion : <strong>Boutique Indigo</strong>" },
|
||||
{ dot: "#9a6638", message: "<strong>Café des Arts</strong> a mis à jour sa fiche annuaire" },
|
||||
];
|
||||
|
||||
export function demoUsers(memberId: (name: string) => number | null) {
|
||||
return [
|
||||
{ email: "claire@plein-r.fr", name: "Claire Martin", role: "admin" as const, memberId: null },
|
||||
{ email: "thomas@plein-r.fr", name: "Thomas Petit", role: "moderator" as const, memberId: null },
|
||||
{ email: "sophie@plein-r.fr", name: "Sophie Aubert", role: "editor" as const, memberId: null },
|
||||
{ email: "contact@aubonpain.fr", name: "Au Bon Pain", role: "member" as const, memberId: memberId("Au Bon Pain") },
|
||||
];
|
||||
}
|
||||
|
||||
/** E-mails des fiches adhérent de démonstration. */
|
||||
export function demoMemberEmails(): string[] {
|
||||
return demoMembers(() => null).map((m) => m.email);
|
||||
}
|
||||
|
||||
/** Titres des promotions de démonstration. */
|
||||
export function demoPromotionTitles(): string[] {
|
||||
return demoPromotions(() => null).map((p) => p.title);
|
||||
}
|
||||
|
||||
/** E-mails des comptes de démonstration. */
|
||||
export function demoUserEmails(): string[] {
|
||||
return demoUsers(() => null).map((u) => u.email);
|
||||
}
|
||||
@@ -0,0 +1,110 @@
|
||||
import "dotenv/config";
|
||||
import { Pool } from "pg";
|
||||
import { drizzle } from "drizzle-orm/node-postgres";
|
||||
import { and, inArray, isNull } from "drizzle-orm";
|
||||
import * as schema from "./schema";
|
||||
import {
|
||||
demoActivity,
|
||||
demoMemberEmails,
|
||||
demoPromotionTitles,
|
||||
demoRequests,
|
||||
demoUserEmails,
|
||||
} from "./demo-data";
|
||||
|
||||
const { activityLog, imageConsents, meetingRegistrations, members, membershipRequests, promotions, users } = schema;
|
||||
|
||||
/**
|
||||
* Retire les données de démonstration d'une base qui les a reçues (anciens
|
||||
* déploiements où le seed les insérait à chaque démarrage).
|
||||
*
|
||||
* Seuls les enregistrements du jeu de démonstration sont touchés, reconnus par
|
||||
* leur e-mail, leur titre, leur nom ou leur message exacts. Tout ce qui a été
|
||||
* saisi par l'association reste en place, y compris les catégories et le
|
||||
* compte administrateur.
|
||||
*
|
||||
* npm run db:purge-demo (poste de développement)
|
||||
* docker compose exec app node dist/purge-demo.cjs (conteneur)
|
||||
*/
|
||||
async function main() {
|
||||
const connectionString = process.env.DATABASE_URL;
|
||||
if (!connectionString) throw new Error("DATABASE_URL is not set");
|
||||
|
||||
const pool = new Pool({ connectionString, max: 1 });
|
||||
const db = drizzle(pool, { schema });
|
||||
|
||||
const memberEmails = demoMemberEmails();
|
||||
const promoTitles = demoPromotionTitles();
|
||||
const userEmails = demoUserEmails();
|
||||
const requestNames = demoRequests.map((r) => r.name);
|
||||
const activityMessages = demoActivity.map((a) => a.message);
|
||||
|
||||
const removed = await db.transaction(async (tx) => {
|
||||
const demoMemberRows = await tx
|
||||
.select({ id: members.id })
|
||||
.from(members)
|
||||
.where(inArray(members.email, memberEmails));
|
||||
const memberIds = demoMemberRows.map((m) => m.id);
|
||||
|
||||
// Comptes de démonstration (staff et adhérent).
|
||||
const deletedUsers = await tx
|
||||
.delete(users)
|
||||
.where(inArray(users.email, userEmails))
|
||||
.returning({ id: users.id });
|
||||
|
||||
let deletedPromos: { id: number }[] = [];
|
||||
let deletedMembers: { id: number }[] = [];
|
||||
if (memberIds.length > 0) {
|
||||
// Un compte réel rattaché par erreur à une fiche de démo est détaché,
|
||||
// pas supprimé.
|
||||
await tx.update(users).set({ memberId: null }).where(inArray(users.memberId, memberIds));
|
||||
await tx.delete(imageConsents).where(inArray(imageConsents.memberId, memberIds));
|
||||
await tx
|
||||
.update(meetingRegistrations)
|
||||
.set({ memberId: null })
|
||||
.where(inArray(meetingRegistrations.memberId, memberIds));
|
||||
// Les publications réseaux liées suivent (clé étrangère en cascade).
|
||||
deletedPromos = await tx
|
||||
.delete(promotions)
|
||||
.where(inArray(promotions.memberId, memberIds))
|
||||
.returning({ id: promotions.id });
|
||||
deletedMembers = await tx
|
||||
.delete(members)
|
||||
.where(inArray(members.id, memberIds))
|
||||
.returning({ id: members.id });
|
||||
}
|
||||
|
||||
// Promotions de démo sans fiche (seed antérieur, fiche déjà retirée).
|
||||
const orphanPromos = await tx
|
||||
.delete(promotions)
|
||||
.where(and(inArray(promotions.title, promoTitles), isNull(promotions.memberId)))
|
||||
.returning({ id: promotions.id });
|
||||
|
||||
const deletedRequests = await tx
|
||||
.delete(membershipRequests)
|
||||
.where(inArray(membershipRequests.name, requestNames))
|
||||
.returning({ id: membershipRequests.id });
|
||||
|
||||
const deletedActivity = await tx
|
||||
.delete(activityLog)
|
||||
.where(inArray(activityLog.message, activityMessages))
|
||||
.returning({ id: activityLog.id });
|
||||
|
||||
return {
|
||||
comptes: deletedUsers.length,
|
||||
adherents: deletedMembers.length,
|
||||
promotions: deletedPromos.length + orphanPromos.length,
|
||||
demandes: deletedRequests.length,
|
||||
journal: deletedActivity.length,
|
||||
};
|
||||
});
|
||||
|
||||
console.log("Données de démonstration retirées :");
|
||||
for (const [key, count] of Object.entries(removed)) console.log(` ${key} : ${count}`);
|
||||
|
||||
await pool.end();
|
||||
}
|
||||
|
||||
main().catch((err) => {
|
||||
console.error("Purge failed:", err);
|
||||
process.exit(1);
|
||||
});
|
||||
+2
-1
@@ -80,8 +80,9 @@ export const users = pgTable(
|
||||
passwordHash: varchar("password_hash", { length: 255 }).notNull(),
|
||||
role: roleEnum("role").notNull().default("member"),
|
||||
memberId: integer("member_id").references(() => members.id),
|
||||
// Le mot de passe temporaire n'est plus stocké (ni en clair ni chiffré) :
|
||||
// il est montré une seule fois à la création / réinitialisation.
|
||||
mustChangePassword: boolean("must_change_password").notNull().default(false),
|
||||
tempPassword: varchar("temp_password", { length: 60 }),
|
||||
// Incrémenté pour invalider les jetons déjà émis (changement ou
|
||||
// réinitialisation de mot de passe).
|
||||
sessionVersion: integer("session_version").notNull().default(0),
|
||||
|
||||
+92
-147
@@ -2,8 +2,17 @@ import "dotenv/config";
|
||||
import { Pool } from "pg";
|
||||
import { drizzle } from "drizzle-orm/node-postgres";
|
||||
import bcrypt from "bcryptjs";
|
||||
import { randomInt } from "node:crypto";
|
||||
import { eq } from "drizzle-orm";
|
||||
import * as schema from "./schema";
|
||||
import {
|
||||
DEMO_PASSWORD,
|
||||
demoActivity,
|
||||
demoMembers,
|
||||
demoPromotions,
|
||||
demoRequests,
|
||||
demoUsers,
|
||||
} from "./demo-data";
|
||||
|
||||
const {
|
||||
categories,
|
||||
@@ -14,6 +23,14 @@ const {
|
||||
activityLog,
|
||||
} = schema;
|
||||
|
||||
// Mot de passe initial lisible, tiré avec un aléa cryptographique.
|
||||
function randomPassword(length = 16): string {
|
||||
const alphabet = "ABCDEFGHJKMNPQRSTUVWXYZabcdefghijkmnpqrstuvwxyz23456789";
|
||||
let out = "";
|
||||
for (let i = 0; i < length; i++) out += alphabet[randomInt(alphabet.length)];
|
||||
return out;
|
||||
}
|
||||
|
||||
async function main() {
|
||||
const connectionString = process.env.DATABASE_URL;
|
||||
if (!connectionString) throw new Error("DATABASE_URL is not set");
|
||||
@@ -117,157 +134,85 @@ async function main() {
|
||||
const cats = await db.select().from(categories);
|
||||
const catId = (slug: string) => cats.find((c) => c.slug === slug)?.id ?? null;
|
||||
|
||||
// ---- Members (adhérents) ----
|
||||
const memberData = [
|
||||
{
|
||||
name: "Au Bon Pain",
|
||||
email: "contact@aubonpain.fr",
|
||||
categoryId: catId("boulangerie"),
|
||||
city: "Frouard",
|
||||
address: "12 rue de la République",
|
||||
postalCode: "54390",
|
||||
phone: "03 83 49 00 00",
|
||||
website: "https://www.aubonpain-frouard.fr",
|
||||
memberSince: 2021,
|
||||
tags: "Levain naturel, Produits locaux, Fait maison, Sans conservateur",
|
||||
hours: "Mardi – Vendredi|7h – 19h30\nSamedi|7h – 19h\nDimanche|7h – 13h\nLundi|Fermé",
|
||||
description:
|
||||
"Boulangerie artisanale familiale installée au cœur de Frouard depuis trois générations. Nous travaillons chaque jour des farines locales et un levain naturel pour vous proposer pains, viennoiseries et pâtisseries faits maison.\nNotre équipe vous accueille du mardi au dimanche matin. Spécialités : pain au levain, baguette de tradition, kouglof et tartes aux fruits de saison.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Café des Arts",
|
||||
email: "hello@cafedesarts.fr",
|
||||
categoryId: catId("restauration"),
|
||||
city: "Pompey",
|
||||
address: "3 place Stanislas",
|
||||
postalCode: "54340",
|
||||
phone: "03 83 24 00 00",
|
||||
memberSince: 2019,
|
||||
tags: "Cuisine de saison, Brunch, Terrasse, Produits frais",
|
||||
hours: "Lundi – Vendredi|9h – 18h\nSamedi|9h – 19h\nDimanche|10h – 15h",
|
||||
description: "Cuisine de saison, brunch le dimanche, terrasse au cœur du bourg.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Atelier Émilie",
|
||||
email: "emilie@atelier.fr",
|
||||
categoryId: catId("mode-beaute"),
|
||||
city: "Champigneulles",
|
||||
address: "7 av. des Tilleuls",
|
||||
description: "Salon de coiffure & soins, sur rendez-vous du mardi au samedi.",
|
||||
status: "active" as const,
|
||||
highlighted: true,
|
||||
},
|
||||
{
|
||||
name: "Garage Moderne",
|
||||
email: "contact@garagemoderne.fr",
|
||||
categoryId: catId("services"),
|
||||
city: "Custines",
|
||||
description: "Entretien et réparation toutes marques.",
|
||||
status: "active" as const,
|
||||
},
|
||||
{
|
||||
name: "Boutique Indigo",
|
||||
email: "indigo@boutique.fr",
|
||||
categoryId: catId("mode-beaute"),
|
||||
city: "Liverdun",
|
||||
description: "Prêt-à-porter et accessoires.",
|
||||
status: "pending" as const,
|
||||
},
|
||||
{
|
||||
name: "Fleurs & Sens",
|
||||
email: "contact@fleursetsens.fr",
|
||||
categoryId: catId("artisanat"),
|
||||
city: "Pompey",
|
||||
description: "Compositions florales, fleurs de saison cueillies localement.",
|
||||
status: "active" as const,
|
||||
},
|
||||
{
|
||||
name: "La Cave Gourmande",
|
||||
email: "bonjour@cavegourmande.fr",
|
||||
categoryId: catId("alimentation"),
|
||||
city: "Frouard",
|
||||
description: "Fromages fermiers, vins et produits du terroir.",
|
||||
status: "active" as const,
|
||||
},
|
||||
];
|
||||
|
||||
for (const m of memberData) {
|
||||
const existing = await db.select().from(members).where(eq(members.email, m.email));
|
||||
if (existing.length === 0) await db.insert(members).values(m);
|
||||
}
|
||||
const allMembers = await db.select().from(members);
|
||||
const memberId = (name: string) => allMembers.find((m) => m.name === name)?.id ?? null;
|
||||
|
||||
// ---- Promotions ----
|
||||
const promoData = [
|
||||
{ title: "Le 13e pain offert", text: "Sur présentation de votre carte adhérent, profitez d'une réduction sur nos pains au levain.", category: "Boulangerie", badge: "-20%", memberId: memberId("Au Bon Pain"), status: "live" as const, validUntil: "Valable jusqu'au 30 juin" },
|
||||
{ title: "Formule midi du marché", text: "Entrée + plat + café à 15€ tous les midis de semaine. Produits frais et locaux.", category: "Restauration", badge: "Menu 15€", memberId: memberId("Café des Arts"), status: "live" as const, validUntil: "Du lundi au vendredi" },
|
||||
{ title: "Soin offert dès 2 prestations", text: "Profitez de -30% sur le 2e soin réservé dans le mois. Sur rendez-vous.", category: "Beauté", badge: "-30%", memberId: memberId("Atelier Émilie"), status: "pending" as const, validUntil: "Jusqu'au 15 juillet" },
|
||||
{ title: "Révision auto à prix réseau", text: "15€ de remise sur votre forfait révision pour tous les adhérents Plein R.", category: "Services", badge: "-15€", memberId: memberId("Garage Moderne"), status: "pending" as const, validUntil: "Toute l'année" },
|
||||
{ title: "Bouquet du mois en promo", text: "-25% sur la composition florale du mois. Fleurs de saison, cueillies localement.", category: "Artisanat", badge: "-25%", memberId: memberId("Fleurs & Sens"), status: "live" as const, validUntil: "Jusqu'au 30 juin" },
|
||||
{ title: "2 fromages achetés, 1 offert", text: "Sur une sélection de fromages fermiers. L'occasion de découvrir nos producteurs.", category: "Alimentation", badge: "2+1", memberId: memberId("La Cave Gourmande"), status: "live" as const, validUntil: "Ce week-end" },
|
||||
];
|
||||
|
||||
for (const p of promoData) {
|
||||
const existing = await db.select().from(promotions).where(eq(promotions.title, p.title));
|
||||
if (existing.length === 0) await db.insert(promotions).values(p);
|
||||
}
|
||||
|
||||
// ---- Membership requests ----
|
||||
const requestData = [
|
||||
{ name: "Boutique Indigo", email: "indigo@boutique.fr", message: "Souhaite rejoindre le réseau." },
|
||||
{ name: "Pizzeria Bella", email: "contact@bella.fr", message: "Demande d'adhésion." },
|
||||
{ name: "Coworking La Ruche", email: "hello@laruche.fr", message: "Espace de travail partagé." },
|
||||
];
|
||||
for (const r of requestData) {
|
||||
const existing = await db.select().from(membershipRequests).where(eq(membershipRequests.name, r.name));
|
||||
if (existing.length === 0) await db.insert(membershipRequests).values(r);
|
||||
}
|
||||
|
||||
// ---- Activity log ----
|
||||
const activityData = [
|
||||
{ dot: "#1f8a5b", message: "<strong>Atelier Émilie</strong> a publié une promotion « Soin offert dès 2 prestations »" },
|
||||
{ dot: "#E0A63C", message: "<strong>Garage Moderne</strong> a soumis une promotion en attente de validation" },
|
||||
{ dot: "#2C6FB3", message: "Nouvelle demande d'adhésion : <strong>Boutique Indigo</strong>" },
|
||||
{ dot: "#9a6638", message: "<strong>Café des Arts</strong> a mis à jour sa fiche annuaire" },
|
||||
];
|
||||
const existingActivity = await db.select().from(activityLog);
|
||||
if (existingActivity.length === 0) {
|
||||
for (const a of activityData) await db.insert(activityLog).values(a);
|
||||
}
|
||||
|
||||
// ---- Admin + sample staff/member users ----
|
||||
const adminEmail = process.env.SEED_ADMIN_EMAIL ?? "admin@plein-r.fr";
|
||||
const adminPassword = process.env.SEED_ADMIN_PASSWORD ?? "changeme123";
|
||||
const adminName = process.env.SEED_ADMIN_NAME ?? "Administrateur Plein R";
|
||||
|
||||
const seedUsers = [
|
||||
{ email: adminEmail, name: adminName, password: adminPassword, role: "admin" as const, memberId: null },
|
||||
{ email: "claire@plein-r.fr", name: "Claire Martin", password: "changeme123", role: "admin" as const, memberId: null },
|
||||
{ email: "thomas@plein-r.fr", name: "Thomas Petit", password: "changeme123", role: "moderator" as const, memberId: null },
|
||||
{ email: "sophie@plein-r.fr", name: "Sophie Aubert", password: "changeme123", role: "editor" as const, memberId: null },
|
||||
{ email: "contact@aubonpain.fr", name: "Au Bon Pain", password: "changeme123", role: "member" as const, memberId: memberId("Au Bon Pain") },
|
||||
];
|
||||
|
||||
for (const u of seedUsers) {
|
||||
const existing = await db.select().from(users).where(eq(users.email, u.email));
|
||||
if (existing.length === 0) {
|
||||
await db.insert(users).values({
|
||||
email: u.email,
|
||||
name: u.name,
|
||||
passwordHash: await bcrypt.hash(u.password, 10),
|
||||
role: u.role,
|
||||
memberId: u.memberId,
|
||||
});
|
||||
// ---- Données de démonstration (SEED_DEMO=true uniquement) ----
|
||||
//
|
||||
// Par défaut la base reste vide : seuls le référentiel des catégories et le
|
||||
// compte administrateur initial sont créés. Les adhérents, promotions,
|
||||
// demandes, entrées de journal et comptes de démonstration ne servent qu'à
|
||||
// un poste de développement.
|
||||
const demo = (process.env.SEED_DEMO ?? "").trim().toLowerCase() === "true";
|
||||
if (demo) {
|
||||
for (const m of demoMembers(catId)) {
|
||||
const existing = await db.select().from(members).where(eq(members.email, m.email));
|
||||
if (existing.length === 0) await db.insert(members).values(m);
|
||||
}
|
||||
const allMembers = await db.select().from(members);
|
||||
const memberId = (name: string) => allMembers.find((m) => m.name === name)?.id ?? null;
|
||||
|
||||
for (const p of demoPromotions(memberId)) {
|
||||
const existing = await db.select().from(promotions).where(eq(promotions.title, p.title));
|
||||
if (existing.length === 0) await db.insert(promotions).values(p);
|
||||
}
|
||||
|
||||
for (const r of demoRequests) {
|
||||
const existing = await db.select().from(membershipRequests).where(eq(membershipRequests.name, r.name));
|
||||
if (existing.length === 0) await db.insert(membershipRequests).values(r);
|
||||
}
|
||||
|
||||
const existingActivity = await db.select().from(activityLog);
|
||||
if (existingActivity.length === 0) {
|
||||
for (const a of demoActivity) await db.insert(activityLog).values(a);
|
||||
}
|
||||
|
||||
for (const u of demoUsers(memberId)) {
|
||||
const existing = await db.select({ id: users.id }).from(users).where(eq(users.email, u.email));
|
||||
if (existing.length === 0) {
|
||||
await db.insert(users).values({
|
||||
email: u.email,
|
||||
name: u.name,
|
||||
passwordHash: await bcrypt.hash(DEMO_PASSWORD, 10),
|
||||
role: u.role,
|
||||
memberId: u.memberId,
|
||||
});
|
||||
}
|
||||
}
|
||||
console.log(` Données de démonstration insérées (SEED_DEMO=true) ; comptes de démo : mot de passe « ${DEMO_PASSWORD} ».`);
|
||||
}
|
||||
|
||||
// ---- Comptes de connexion ----
|
||||
//
|
||||
// Le seed tourne à chaque démarrage du conteneur (SEED_ON_START). Il ne doit
|
||||
// donc jamais créer en production de compte dont le mot de passe est connu
|
||||
// de tous : les comptes de démonstration sont réservés à SEED_DEMO=true, et
|
||||
// l'administrateur initial reçoit un mot de passe aléatoire (affiché une
|
||||
// seule fois ici) à changer à la première connexion, sauf si
|
||||
// SEED_ADMIN_PASSWORD est fourni explicitement.
|
||||
const adminEmail = (process.env.SEED_ADMIN_EMAIL ?? "admin@plein-r.fr").trim().toLowerCase();
|
||||
const adminName = process.env.SEED_ADMIN_NAME ?? "Administrateur Plein R";
|
||||
const providedAdminPassword = (process.env.SEED_ADMIN_PASSWORD ?? "").trim();
|
||||
|
||||
const [existingAdmin] = await db.select({ id: users.id }).from(users).where(eq(users.email, adminEmail));
|
||||
if (!existingAdmin) {
|
||||
const generated = !providedAdminPassword;
|
||||
const adminPassword = providedAdminPassword || randomPassword();
|
||||
await db.insert(users).values({
|
||||
email: adminEmail,
|
||||
name: adminName,
|
||||
passwordHash: await bcrypt.hash(adminPassword, 10),
|
||||
role: "admin",
|
||||
memberId: null,
|
||||
mustChangePassword: true,
|
||||
});
|
||||
if (generated) {
|
||||
console.log(" Compte administrateur créé. Mot de passe initial (affiché une seule fois) :");
|
||||
console.log(` ${adminEmail} / ${adminPassword}`);
|
||||
} else {
|
||||
console.log(` Compte administrateur créé : ${adminEmail} (mot de passe fourni par SEED_ADMIN_PASSWORD).`);
|
||||
}
|
||||
console.log(" Un changement de mot de passe sera exigé à la première connexion.");
|
||||
}
|
||||
|
||||
console.log("Seed complete.");
|
||||
console.log(` Admin login: ${adminEmail} / ${adminPassword}`);
|
||||
await pool.end();
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user