Files
PleinR/docker-compose.yml
T
Claude e3a4771edf Refonte du bloc infos pratiques, suspension des promos et publication réseaux
Bloc « Informations pratiques » (fiche adhérent)
- Suppression des dégradés hors palette (radial doré de la section, dégradés
  crème/bleu des deux sous-cartes) au profit du vocabulaire visuel du site :
  carte blanche bordée, sous-cartes plates sur le fond de champ, variables CSS.
- La pastille « Préparer votre visite » devient une puce arrondie identique aux
  badges du reste du site ; le chip d'ouverture reprend les teintes de statut.
- Les glyphes texte ◷ et ↗ sont remplacés par des icônes SVG cohérentes.

Suspension des promotions
- Nouveau statut `suspended` + colonnes `suspended_by` / `suspended_by_id` /
  `suspended_at`.
- L'adhérent suspend et réactive ses propres promotions depuis Mon espace ;
  l'association suspend et réactive n'importe laquelle depuis le backoffice.
- Une suspension décidée par l'association ne peut pas être levée par
  l'adhérent : le motif est affiché dans son espace.
- Les lectures publiques filtrant déjà sur `live`, une promo suspendue quitte
  immédiatement l'accueil, l'annuaire et la fiche.

Publication Facebook / LinkedIn
- `src/lib/social.ts` : publication d'une promo en ligne sur la page Facebook
  (Graph API, upload multipart car les images sont en data-URI) et sur la page
  LinkedIn (Posts API + Images API en trois étapes).
- Jetons d'accès exclusivement en variables d'environnement ; un réseau non
  configuré masque son bouton.
- Table `social_posts` : chaque tentative est tracée, un échec est rattrapé et
  affiché sur la carte de la promo sans interrompre le backoffice.
- Nouvelle capacité RBAC `publishSocial` (admin + modérateur).

Liens sociaux publics
- Réglages `association_facebook` / `association_linkedin` éditables dans
  Paramètres, préremplis avec les pages de l'association.
- Section « Plein R sur les réseaux » sur l'accueil et icônes dans le pied de
  page, masquées si le réglage est vide.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QXNXRC4j5VLfKvpyyisrnb
2026-07-24 22:20:51 +00:00

90 lines
3.6 KiB
YAML

# Plein R — single application container + external Postgres container.
#
# The app (Next.js) runs in ONE container. Postgres runs as a SEPARATE
# (external) container. For a managed/already-existing Postgres, delete the
# `postgres` service below and point DATABASE_URL at your instance.
services:
postgres:
image: postgres:16-alpine
container_name: pleinr-postgres
restart: unless-stopped
environment:
POSTGRES_USER: ${POSTGRES_USER:-pleinr}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-pleinr}
POSTGRES_DB: ${POSTGRES_DB:-pleinr}
volumes:
- pgdata:/var/lib/postgresql/data
ports:
# Host port rarely used (container stays on 5432). Change the left side if needed.
- "54329:5432"
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-pleinr} -d ${POSTGRES_DB:-pleinr}"]
interval: 5s
timeout: 5s
retries: 12
networks:
- internal
app:
build: .
container_name: pleinr-app
restart: unless-stopped
depends_on:
postgres:
condition: service_healthy
environment:
# Use the UNIQUE container name (not the generic "postgres" alias) to avoid
# name collisions with other "postgres" containers on the shared proxy
# network. pleinr-postgres only exists on our internal network.
DATABASE_URL: postgres://${POSTGRES_USER:-pleinr}:${POSTGRES_PASSWORD:-pleinr}@pleinr-postgres:5432/${POSTGRES_DB:-pleinr}
# Optional: if left empty, the container generates and persists one
# automatically (see docker-entrypoint.sh + the app-data volume).
AUTH_SECRET: ${AUTH_SECRET:-}
# IMPORTANT behind a reverse proxy: set AUTH_URL to your public URL so the
# login redirect points to the right host, e.g.
# AUTH_URL=https://pleinr.ffnancy.fr
AUTH_URL: ${AUTH_URL:-}
# Lets Auth.js trust the X-Forwarded-* headers from the proxy.
AUTH_TRUST_HOST: "true"
# URL publique, reprise dans le texte des posts Facebook / LinkedIn.
NEXT_PUBLIC_SITE_URL: ${NEXT_PUBLIC_SITE_URL:-}
# Publication des promotions sur les réseaux (facultatif — voir .env.example).
FACEBOOK_PAGE_ID: ${FACEBOOK_PAGE_ID:-}
FACEBOOK_PAGE_ACCESS_TOKEN: ${FACEBOOK_PAGE_ACCESS_TOKEN:-}
FACEBOOK_GRAPH_VERSION: ${FACEBOOK_GRAPH_VERSION:-}
LINKEDIN_ORGANIZATION_URN: ${LINKEDIN_ORGANIZATION_URN:-}
LINKEDIN_ORGANIZATION_ID: ${LINKEDIN_ORGANIZATION_ID:-}
LINKEDIN_ACCESS_TOKEN: ${LINKEDIN_ACCESS_TOKEN:-}
LINKEDIN_API_VERSION: ${LINKEDIN_API_VERSION:-}
SEED_ON_START: ${SEED_ON_START:-true}
SEED_ADMIN_EMAIL: ${SEED_ADMIN_EMAIL:-admin@plein-r.fr}
SEED_ADMIN_PASSWORD: ${SEED_ADMIN_PASSWORD:-changeme123}
SEED_ADMIN_NAME: ${SEED_ADMIN_NAME:-Administrateur Plein R}
ports:
# Host port rarely used (container stays on 3000). App reachable at http://HOST:8413
- "8413:3000"
volumes:
# Persists the auto-generated AUTH_SECRET across restarts.
- appdata:/app/data
networks:
# "internal" is shared with Postgres; "proxy" is the external network
# shared with the reverse proxy (e.g. Nginx Proxy Manager) so it can reach
# the app by name: forward to pleinr-app:3000
- internal
- proxy
volumes:
pgdata:
appdata:
networks:
# Private network for app <-> Postgres communication.
internal:
driver: bridge
proxy:
# The reverse proxy's existing network. Must already exist (created by the
# NPM/nginx stack). Override the name with PROXY_NETWORK if it differs.
external: true
name: ${PROXY_NETWORK:-nginx_default}