Implémente l'intégralité de la maquette « SLUC Business Club.dc.html » : - Site public : accueil (héro administrable, carrousel membres, agenda avec inscription en ligne, rencontres passées, demande d'adhésion), annuaire avec recherche/filtres/fiche détaillée, page association - Espace membre : connexion, édition de fiche avec aperçu direct, upload logo/photo, statut d'adhésion par saison, changement de mot de passe - Espace admin : tableau de bord, membres (validation par saison), rencontres (CRUD + inscrits + impression + export Excel), inscriptions, catégories, contenu du site Architecture : 3 conteneurs Docker Compose — PostgreSQL 16 (réseau interne, rôle applicatif restreint), API Express (non-root, read-only fs), nginx non privilégié (frontend React + reverse-proxy + CSP stricte). Sécurité : requêtes 100 % paramétrées, bcrypt + JWT httpOnly SameSite=Strict, vérification d'Origin (CSRF), validation zod, rate limiting, uploads vérifiés par octets magiques avec noms aléatoires, aucun secret committé. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
33 lines
1.4 KiB
JavaScript
33 lines
1.4 KiB
JavaScript
import bcrypt from 'bcryptjs';
|
|
import { query } from './db.js';
|
|
import { config } from './config.js';
|
|
|
|
// Seeded accounts carry the unusable placeholder hash '*seed*'.
|
|
// On startup we give them a real bcrypt hash from environment variables —
|
|
// but never overwrite a password that has already been changed.
|
|
export async function applyInitialPasswords() {
|
|
if (config.adminInitialPassword) {
|
|
const hash = await bcrypt.hash(config.adminInitialPassword, 12);
|
|
const r = await query(
|
|
`UPDATE users SET password_hash = $1 WHERE role = 'admin' AND password_hash = '*seed*'`,
|
|
[hash]
|
|
);
|
|
if (r.rowCount > 0) console.log(`Initialized password for ${r.rowCount} admin account(s).`);
|
|
}
|
|
if (config.memberInitialPassword) {
|
|
const hash = await bcrypt.hash(config.memberInitialPassword, 12);
|
|
const r = await query(
|
|
`UPDATE users SET password_hash = $1 WHERE role = 'member' AND password_hash = '*seed*'`,
|
|
[hash]
|
|
);
|
|
if (r.rowCount > 0) console.log(`Initialized password for ${r.rowCount} member account(s).`);
|
|
}
|
|
const locked = await query(`SELECT COUNT(*)::int AS n FROM users WHERE password_hash = '*seed*'`);
|
|
if (locked.rows[0].n > 0) {
|
|
console.warn(
|
|
`${locked.rows[0].n} account(s) still locked (no initial password provided). ` +
|
|
'Set ADMIN_INITIAL_PASSWORD / MEMBER_INITIAL_PASSWORD to activate them.'
|
|
);
|
|
}
|
|
}
|