Files
SBC/server/src/bootstrap.js
T
Claude 96dca2a802 Application complète SLUC Business Club (React + Express + PostgreSQL, Docker)
Implémente l'intégralité de la maquette « SLUC Business Club.dc.html » :
- Site public : accueil (héro administrable, carrousel membres, agenda avec
  inscription en ligne, rencontres passées, demande d'adhésion), annuaire
  avec recherche/filtres/fiche détaillée, page association
- Espace membre : connexion, édition de fiche avec aperçu direct, upload
  logo/photo, statut d'adhésion par saison, changement de mot de passe
- Espace admin : tableau de bord, membres (validation par saison),
  rencontres (CRUD + inscrits + impression + export Excel), inscriptions,
  catégories, contenu du site

Architecture : 3 conteneurs Docker Compose — PostgreSQL 16 (réseau interne,
rôle applicatif restreint), API Express (non-root, read-only fs), nginx
non privilégié (frontend React + reverse-proxy + CSP stricte).

Sécurité : requêtes 100 % paramétrées, bcrypt + JWT httpOnly SameSite=Strict,
vérification d'Origin (CSRF), validation zod, rate limiting, uploads vérifiés
par octets magiques avec noms aléatoires, aucun secret committé.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
2026-07-10 19:43:07 +00:00

33 lines
1.4 KiB
JavaScript

import bcrypt from 'bcryptjs';
import { query } from './db.js';
import { config } from './config.js';
// Seeded accounts carry the unusable placeholder hash '*seed*'.
// On startup we give them a real bcrypt hash from environment variables —
// but never overwrite a password that has already been changed.
export async function applyInitialPasswords() {
if (config.adminInitialPassword) {
const hash = await bcrypt.hash(config.adminInitialPassword, 12);
const r = await query(
`UPDATE users SET password_hash = $1 WHERE role = 'admin' AND password_hash = '*seed*'`,
[hash]
);
if (r.rowCount > 0) console.log(`Initialized password for ${r.rowCount} admin account(s).`);
}
if (config.memberInitialPassword) {
const hash = await bcrypt.hash(config.memberInitialPassword, 12);
const r = await query(
`UPDATE users SET password_hash = $1 WHERE role = 'member' AND password_hash = '*seed*'`,
[hash]
);
if (r.rowCount > 0) console.log(`Initialized password for ${r.rowCount} member account(s).`);
}
const locked = await query(`SELECT COUNT(*)::int AS n FROM users WHERE password_hash = '*seed*'`);
if (locked.rows[0].n > 0) {
console.warn(
`${locked.rows[0].n} account(s) still locked (no initial password provided). ` +
'Set ADMIN_INITIAL_PASSWORD / MEMBER_INITIAL_PASSWORD to activate them.'
);
}
}