mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
Improve security and filtering for scheduled posts across user pages
Adds a `getScheduledPostsByPages` method to storage, enabling efficient filtering of scheduled posts by authorized page IDs. Updates API routes to correctly retrieve posts based on user roles (admin vs. standard user) and accessible pages, enhancing data security and user experience. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/77tIrOr
This commit is contained in:
1 parent
1a16c71a41
commit
6014c4e083
3 files changed
+54
-15
No files matched your search
@@ -11,6 +11,7 @@ Preferred communication style: Simple, everyday language.
|
||||
## Recent Changes
|
||||
|
||||
### October 28, 2025
|
||||
- **Scheduled Posts Page-Level Filtering Security Fix**: Fixed security vulnerability where users could see occupied dates from all pages in the DateTimePicker, including pages they don't have access to. Added new storage method `getScheduledPostsByPages()` that filters scheduled posts directly in database using SQL WHERE IN clause with authorized page IDs. Modified GET `/api/scheduled-posts` endpoint to use getUserAccessiblePages for standard users (only their assigned pages) and all pages for admins. This eliminates temporary exposure of sensitive data in memory and improves performance by querying only authorized posts from the database.
|
||||
- **Interactive Calendar with Visual Indicators**: Replaced native datetime-local input with custom DateTimePicker component featuring visual planning aids. Calendar displays occupied dates with red background (bg-red-500/20) to prevent scheduling conflicts. Time selector highlights optimal posting hours (8h, 12h-13h, 18h-20h) with green background (bg-green-500/20) and sparkle emoji to maximize audience engagement. Component includes clear button (X icon) to quickly return to immediate publishing, useEffect synchronization for external state updates, and French locale support via date-fns. Time selector optimized for compactness: ScrollArea height reduced from 240px to 192px (20% smaller), button height set to 36px for touch accessibility, tighter padding and margins throughout. Mobile calendar list still displays today's date first for quick access.
|
||||
- **Facebook Video Story Publishing Fix**: Fixed critical bug preventing video story publication. Facebook Graph API requires a 3-phase upload process for video stories: (1) START phase - initialize upload session and get `video_id` + `upload_url`, (2) UPLOAD phase - POST video to rupload.facebook.com endpoint with `file_url` header and OAuth authorization, (3) FINISH phase - finalize and publish story with `video_id`. Previous implementation incorrectly attempted direct upload to `/video_stories` endpoint with `file_url` parameter, causing "#100 The parameter upload_phase is required" error. Fixed by implementing proper 3-phase workflow using remote URL upload method (file_url header), avoiding need for binary chunked uploads.
|
||||
|
||||
|
||||
+17
-14
@@ -991,24 +991,27 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
let scheduledPosts;
|
||||
|
||||
if (user.role === 'admin') {
|
||||
// Admin voit tous les posts programmés
|
||||
const allUsers = await storage.getAllUsers();
|
||||
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
|
||||
const allPostsArrays = await Promise.all(allPostsPromises);
|
||||
scheduledPosts = allPostsArrays.flat();
|
||||
// Admin voit tous les posts programmés - on récupère toutes les pages
|
||||
const allPages = await storage.getAllUsers().then(users =>
|
||||
Promise.all(users.map(u => storage.getSocialPages(u.id)))
|
||||
).then(pagesArrays => pagesArrays.flat());
|
||||
const allPageIds = allPages.map(p => p.id);
|
||||
|
||||
if (allPageIds.length > 0) {
|
||||
scheduledPosts = await storage.getScheduledPostsByPages(allPageIds, start, end);
|
||||
} else {
|
||||
scheduledPosts = [];
|
||||
}
|
||||
} else {
|
||||
// User voit tous les posts programmés sur les pages qui lui sont attribuées (peu importe qui les a créés)
|
||||
// User voit uniquement les posts programmés sur les pages qui lui sont attribuées
|
||||
const accessiblePages = await storage.getUserAccessiblePages(userId);
|
||||
const accessiblePageIds = accessiblePages.map(p => p.id);
|
||||
|
||||
// Récupérer tous les posts programmés de tous les utilisateurs
|
||||
const allUsers = await storage.getAllUsers();
|
||||
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
|
||||
const allPostsArrays = await Promise.all(allPostsPromises);
|
||||
const allScheduledPosts = allPostsArrays.flat();
|
||||
|
||||
// Filtrer uniquement les posts des pages accessibles
|
||||
scheduledPosts = allScheduledPosts.filter(sp => accessiblePageIds.includes(sp.pageId));
|
||||
if (accessiblePageIds.length > 0) {
|
||||
scheduledPosts = await storage.getScheduledPostsByPages(accessiblePageIds, start, end);
|
||||
} else {
|
||||
scheduledPosts = [];
|
||||
}
|
||||
}
|
||||
|
||||
res.json(scheduledPosts);
|
||||
|
||||
+36
-1
@@ -30,7 +30,7 @@ import {
|
||||
type InsertUserPagePermission,
|
||||
} from "@shared/schema";
|
||||
import { db } from "./db";
|
||||
import { eq, and, gte, lte, desc, asc, isNull } from "drizzle-orm";
|
||||
import { eq, and, gte, lte, desc, asc, isNull, inArray } from "drizzle-orm";
|
||||
|
||||
export interface IStorage {
|
||||
// Users
|
||||
@@ -66,6 +66,7 @@ export interface IStorage {
|
||||
|
||||
// Scheduled Posts
|
||||
getScheduledPosts(userId: string, startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
|
||||
getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
|
||||
getScheduledPost(id: string): Promise<ScheduledPost | undefined>;
|
||||
getScheduledPostsByPost(postId: string): Promise<ScheduledPost[]>;
|
||||
createScheduledPost(scheduledPost: InsertScheduledPost): Promise<ScheduledPost>;
|
||||
@@ -260,6 +261,40 @@ export class DatabaseStorage implements IStorage {
|
||||
}));
|
||||
}
|
||||
|
||||
async getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<any[]> {
|
||||
if (pageIds.length === 0) {
|
||||
return [];
|
||||
}
|
||||
|
||||
let query = db
|
||||
.select()
|
||||
.from(scheduledPosts)
|
||||
.innerJoin(posts, eq(scheduledPosts.postId, posts.id))
|
||||
.leftJoin(socialPages, eq(scheduledPosts.pageId, socialPages.id))
|
||||
.where(inArray(scheduledPosts.pageId, pageIds));
|
||||
|
||||
if (startDate && endDate) {
|
||||
const results = await query;
|
||||
return results
|
||||
.filter(r => {
|
||||
const scheduledAt = new Date(r.scheduled_posts.scheduledAt);
|
||||
return scheduledAt >= startDate && scheduledAt <= endDate;
|
||||
})
|
||||
.map(r => ({
|
||||
...r.scheduled_posts,
|
||||
post: r.posts,
|
||||
page: r.social_pages,
|
||||
}));
|
||||
}
|
||||
|
||||
const results = await query;
|
||||
return results.map(r => ({
|
||||
...r.scheduled_posts,
|
||||
post: r.posts,
|
||||
page: r.social_pages,
|
||||
}));
|
||||
}
|
||||
|
||||
async getScheduledPost(id: string): Promise<ScheduledPost | undefined> {
|
||||
const [scheduledPost] = await db.select().from(scheduledPosts).where(eq(scheduledPosts.id, id));
|
||||
return scheduledPost || undefined;
|
||||
|
||||
Reference in new issue
Block a user