Application complète SLUC Business Club (React + Express + PostgreSQL, Docker)
Implémente l'intégralité de la maquette « SLUC Business Club.dc.html » : - Site public : accueil (héro administrable, carrousel membres, agenda avec inscription en ligne, rencontres passées, demande d'adhésion), annuaire avec recherche/filtres/fiche détaillée, page association - Espace membre : connexion, édition de fiche avec aperçu direct, upload logo/photo, statut d'adhésion par saison, changement de mot de passe - Espace admin : tableau de bord, membres (validation par saison), rencontres (CRUD + inscrits + impression + export Excel), inscriptions, catégories, contenu du site Architecture : 3 conteneurs Docker Compose — PostgreSQL 16 (réseau interne, rôle applicatif restreint), API Express (non-root, read-only fs), nginx non privilégié (frontend React + reverse-proxy + CSP stricte). Sécurité : requêtes 100 % paramétrées, bcrypt + JWT httpOnly SameSite=Strict, vérification d'Origin (CSRF), validation zod, rate limiting, uploads vérifiés par octets magiques avec noms aléatoires, aucun secret committé. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
This commit is contained in:
50 files changed
+6887
No files matched your search
@@ -0,0 +1,26 @@
|
||||
# Copy this file to .env and fill in strong secrets before running.
|
||||
# cp .env.example .env
|
||||
# openssl rand -hex 32 # use for JWT_SECRET
|
||||
# openssl rand -hex 24 # use for each DB password
|
||||
|
||||
# PostgreSQL superuser password (used only inside the db container)
|
||||
POSTGRES_PASSWORD=change-me-postgres-superuser
|
||||
|
||||
# Password of the restricted application role (sbc_app) the API connects with
|
||||
APP_DB_PASSWORD=change-me-app-db-password
|
||||
|
||||
# Secret used to sign session tokens (JWT). MUST be long and random.
|
||||
JWT_SECRET=change-me-64-hex-chars-min
|
||||
|
||||
# Initial password of the admin account (admin@sluc-businessclub.fr).
|
||||
# Applied/updated at API startup. Change it after first login.
|
||||
ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026!
|
||||
|
||||
# Initial password given to every seeded member account (demo data only)
|
||||
MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026!
|
||||
|
||||
# Set to "true" when serving over HTTPS (adds Secure flag on cookies)
|
||||
COOKIE_SECURE=false
|
||||
|
||||
# Public port of the web frontend
|
||||
WEB_PORT=8080
|
||||
Reference in new issue
Block a user