Application complète SLUC Business Club (React + Express + PostgreSQL, Docker)

Implémente l'intégralité de la maquette « SLUC Business Club.dc.html » :
- Site public : accueil (héro administrable, carrousel membres, agenda avec
  inscription en ligne, rencontres passées, demande d'adhésion), annuaire
  avec recherche/filtres/fiche détaillée, page association
- Espace membre : connexion, édition de fiche avec aperçu direct, upload
  logo/photo, statut d'adhésion par saison, changement de mot de passe
- Espace admin : tableau de bord, membres (validation par saison),
  rencontres (CRUD + inscrits + impression + export Excel), inscriptions,
  catégories, contenu du site

Architecture : 3 conteneurs Docker Compose — PostgreSQL 16 (réseau interne,
rôle applicatif restreint), API Express (non-root, read-only fs), nginx
non privilégié (frontend React + reverse-proxy + CSP stricte).

Sécurité : requêtes 100 % paramétrées, bcrypt + JWT httpOnly SameSite=Strict,
vérification d'Origin (CSRF), validation zod, rate limiting, uploads vérifiés
par octets magiques avec noms aléatoires, aucun secret committé.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
This commit is contained in:
Claude committed 2026-07-10 19:43:07 +00:00
commit 96dca2a802
50 files changed
+6887

No files matched your search

+26
View File
@@ -0,0 +1,26 @@
# Copy this file to .env and fill in strong secrets before running.
# cp .env.example .env
# openssl rand -hex 32 # use for JWT_SECRET
# openssl rand -hex 24 # use for each DB password
# PostgreSQL superuser password (used only inside the db container)
POSTGRES_PASSWORD=change-me-postgres-superuser
# Password of the restricted application role (sbc_app) the API connects with
APP_DB_PASSWORD=change-me-app-db-password
# Secret used to sign session tokens (JWT). MUST be long and random.
JWT_SECRET=change-me-64-hex-chars-min
# Initial password of the admin account (admin@sluc-businessclub.fr).
# Applied/updated at API startup. Change it after first login.
ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026!
# Initial password given to every seeded member account (demo data only)
MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026!
# Set to "true" when serving over HTTPS (adds Secure flag on cookies)
COOKIE_SECURE=false
# Public port of the web frontend
WEB_PORT=8080