Merge pull request #83 from R0m1k3/dev

Dev
This commit is contained in:
LogiFlow authored and GitHub committed 2025-10-28 16:23:09 +01:00
commit 24c707e47f
4 files changed
+67 -31

No files matched your search

+12 -15
View File
@@ -137,15 +137,15 @@ export function DateTimePicker({ value, onChange, occupiedDates = [], placeholde
</PopoverTrigger>
<PopoverContent className="w-auto p-0" align="start">
<div className="flex">
<ScrollArea className="h-60">
<div className="p-2">
<div className="text-xs font-semibold mb-2 px-2 text-muted-foreground">Heures</div>
<ScrollArea className="h-48">
<div className="p-1.5">
<div className="text-[10px] font-semibold mb-1.5 px-1.5 text-muted-foreground">Heures</div>
{hours.map((hour) => (
<Button
key={hour}
variant="ghost"
className={cn(
"w-full justify-center mb-1",
"w-full justify-center mb-0.5 h-9 text-xs",
selectedHour === hour && "bg-primary text-primary-foreground",
isOptimalHour(hour) && selectedHour !== hour && "bg-green-500/20 text-green-700 dark:text-green-300 font-semibold hover:bg-green-500/30"
)}
@@ -160,15 +160,15 @@ export function DateTimePicker({ value, onChange, occupiedDates = [], placeholde
))}
</div>
</ScrollArea>
<ScrollArea className="h-60 border-l">
<div className="p-2">
<div className="text-xs font-semibold mb-2 px-2 text-muted-foreground">Minutes</div>
<ScrollArea className="h-48 border-l">
<div className="p-1.5">
<div className="text-[10px] font-semibold mb-1.5 px-1.5 text-muted-foreground">Minutes</div>
{minutes.map((minute) => (
<Button
key={minute}
variant="ghost"
className={cn(
"w-full justify-center mb-1",
"w-full justify-center mb-0.5 h-9 text-xs",
selectedMinute === minute && "bg-primary text-primary-foreground"
)}
onClick={() => handleTimeChange(selectedHour, minute)}
@@ -180,16 +180,13 @@ export function DateTimePicker({ value, onChange, occupiedDates = [], placeholde
</div>
</ScrollArea>
</div>
<div className="p-3 border-t bg-muted/50">
<div className="flex items-center gap-2 mb-1">
<div className="w-2 h-2 rounded-full bg-green-500"></div>
<span className="text-[10px] font-semibold text-green-600 dark:text-green-400">
<div className="p-2 border-t bg-muted/50">
<div className="flex items-center gap-1.5">
<div className="w-1.5 h-1.5 rounded-full bg-green-500"></div>
<span className="text-[9px] font-semibold text-green-600 dark:text-green-400">
Heures optimales (8h, 12h-13h, 18h-20h)
</span>
</div>
<p className="text-[9px] text-muted-foreground">
Ces créneaux maximisent l'engagement
</p>
</div>
</PopoverContent>
</Popover>
+2 -1
View File
@@ -11,7 +11,8 @@ Preferred communication style: Simple, everyday language.
## Recent Changes
### October 28, 2025
- **Interactive Calendar with Visual Indicators**: Replaced native datetime-local input with custom DateTimePicker component featuring visual planning aids. Calendar displays occupied dates with red background (bg-red-500/20) to prevent scheduling conflicts. Time selector highlights optimal posting hours (8h, 12h-13h, 18h-20h) with green background (bg-green-500/20) and sparkle emoji to maximize audience engagement. Component includes clear button (X icon) to quickly return to immediate publishing, useEffect synchronization for external state updates, and French locale support via date-fns. Mobile calendar list still displays today's date first for quick access.
- **Scheduled Posts Page-Level Filtering Security Fix**: Fixed security vulnerability where users could see occupied dates from all pages in the DateTimePicker, including pages they don't have access to. Added new storage method `getScheduledPostsByPages()` that filters scheduled posts directly in database using SQL WHERE IN clause with authorized page IDs. Modified GET `/api/scheduled-posts` endpoint to use getUserAccessiblePages for standard users (only their assigned pages) and all pages for admins. This eliminates temporary exposure of sensitive data in memory and improves performance by querying only authorized posts from the database.
- **Interactive Calendar with Visual Indicators**: Replaced native datetime-local input with custom DateTimePicker component featuring visual planning aids. Calendar displays occupied dates with red background (bg-red-500/20) to prevent scheduling conflicts. Time selector highlights optimal posting hours (8h, 12h-13h, 18h-20h) with green background (bg-green-500/20) and sparkle emoji to maximize audience engagement. Component includes clear button (X icon) to quickly return to immediate publishing, useEffect synchronization for external state updates, and French locale support via date-fns. Time selector optimized for compactness: ScrollArea height reduced from 240px to 192px (20% smaller), button height set to 36px for touch accessibility, tighter padding and margins throughout. Mobile calendar list still displays today's date first for quick access.
- **Facebook Video Story Publishing Fix**: Fixed critical bug preventing video story publication. Facebook Graph API requires a 3-phase upload process for video stories: (1) START phase - initialize upload session and get `video_id` + `upload_url`, (2) UPLOAD phase - POST video to rupload.facebook.com endpoint with `file_url` header and OAuth authorization, (3) FINISH phase - finalize and publish story with `video_id`. Previous implementation incorrectly attempted direct upload to `/video_stories` endpoint with `file_url` parameter, causing "#100 The parameter upload_phase is required" error. Fixed by implementing proper 3-phase workflow using remote URL upload method (file_url header), avoiding need for binary chunked uploads.
### October 17, 2025
+17 -14
View File
@@ -991,24 +991,27 @@ export async function registerRoutes(app: Express): Promise<Server> {
let scheduledPosts;
if (user.role === 'admin') {
// Admin voit tous les posts programmés
const allUsers = await storage.getAllUsers();
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
const allPostsArrays = await Promise.all(allPostsPromises);
scheduledPosts = allPostsArrays.flat();
// Admin voit tous les posts programmés - on récupère toutes les pages
const allPages = await storage.getAllUsers().then(users =>
Promise.all(users.map(u => storage.getSocialPages(u.id)))
).then(pagesArrays => pagesArrays.flat());
const allPageIds = allPages.map(p => p.id);
if (allPageIds.length > 0) {
scheduledPosts = await storage.getScheduledPostsByPages(allPageIds, start, end);
} else {
scheduledPosts = [];
}
} else {
// User voit tous les posts programmés sur les pages qui lui sont attribuées (peu importe qui les a créés)
// User voit uniquement les posts programmés sur les pages qui lui sont attribuées
const accessiblePages = await storage.getUserAccessiblePages(userId);
const accessiblePageIds = accessiblePages.map(p => p.id);
// Récupérer tous les posts programmés de tous les utilisateurs
const allUsers = await storage.getAllUsers();
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
const allPostsArrays = await Promise.all(allPostsPromises);
const allScheduledPosts = allPostsArrays.flat();
// Filtrer uniquement les posts des pages accessibles
scheduledPosts = allScheduledPosts.filter(sp => accessiblePageIds.includes(sp.pageId));
if (accessiblePageIds.length > 0) {
scheduledPosts = await storage.getScheduledPostsByPages(accessiblePageIds, start, end);
} else {
scheduledPosts = [];
}
}
res.json(scheduledPosts);
+36 -1
View File
@@ -30,7 +30,7 @@ import {
type InsertUserPagePermission,
} from "@shared/schema";
import { db } from "./db";
import { eq, and, gte, lte, desc, asc, isNull } from "drizzle-orm";
import { eq, and, gte, lte, desc, asc, isNull, inArray } from "drizzle-orm";
export interface IStorage {
// Users
@@ -66,6 +66,7 @@ export interface IStorage {
// Scheduled Posts
getScheduledPosts(userId: string, startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
getScheduledPost(id: string): Promise<ScheduledPost | undefined>;
getScheduledPostsByPost(postId: string): Promise<ScheduledPost[]>;
createScheduledPost(scheduledPost: InsertScheduledPost): Promise<ScheduledPost>;
@@ -260,6 +261,40 @@ export class DatabaseStorage implements IStorage {
}));
}
async getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<any[]> {
if (pageIds.length === 0) {
return [];
}
let query = db
.select()
.from(scheduledPosts)
.innerJoin(posts, eq(scheduledPosts.postId, posts.id))
.leftJoin(socialPages, eq(scheduledPosts.pageId, socialPages.id))
.where(inArray(scheduledPosts.pageId, pageIds));
if (startDate && endDate) {
const results = await query;
return results
.filter(r => {
const scheduledAt = new Date(r.scheduled_posts.scheduledAt);
return scheduledAt >= startDate && scheduledAt <= endDate;
})
.map(r => ({
...r.scheduled_posts,
post: r.posts,
page: r.social_pages,
}));
}
const results = await query;
return results.map(r => ({
...r.scheduled_posts,
post: r.posts,
page: r.social_pages,
}));
}
async getScheduledPost(id: string): Promise<ScheduledPost | undefined> {
const [scheduledPost] = await db.select().from(scheduledPosts).where(eq(scheduledPosts.id, id));
return scheduledPost || undefined;