mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
Improve security and filtering for scheduled posts across user pages
Adds a `getScheduledPostsByPages` method to storage, enabling efficient filtering of scheduled posts by authorized page IDs. Updates API routes to correctly retrieve posts based on user roles (admin vs. standard user) and accessible pages, enhancing data security and user experience. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/77tIrOr
This commit is contained in:
1 parent
1a16c71a41
commit
6014c4e083
3 files changed
+54
-15
No files matched your search
+17
-14
@@ -991,24 +991,27 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
let scheduledPosts;
|
||||
|
||||
if (user.role === 'admin') {
|
||||
// Admin voit tous les posts programmés
|
||||
const allUsers = await storage.getAllUsers();
|
||||
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
|
||||
const allPostsArrays = await Promise.all(allPostsPromises);
|
||||
scheduledPosts = allPostsArrays.flat();
|
||||
// Admin voit tous les posts programmés - on récupère toutes les pages
|
||||
const allPages = await storage.getAllUsers().then(users =>
|
||||
Promise.all(users.map(u => storage.getSocialPages(u.id)))
|
||||
).then(pagesArrays => pagesArrays.flat());
|
||||
const allPageIds = allPages.map(p => p.id);
|
||||
|
||||
if (allPageIds.length > 0) {
|
||||
scheduledPosts = await storage.getScheduledPostsByPages(allPageIds, start, end);
|
||||
} else {
|
||||
scheduledPosts = [];
|
||||
}
|
||||
} else {
|
||||
// User voit tous les posts programmés sur les pages qui lui sont attribuées (peu importe qui les a créés)
|
||||
// User voit uniquement les posts programmés sur les pages qui lui sont attribuées
|
||||
const accessiblePages = await storage.getUserAccessiblePages(userId);
|
||||
const accessiblePageIds = accessiblePages.map(p => p.id);
|
||||
|
||||
// Récupérer tous les posts programmés de tous les utilisateurs
|
||||
const allUsers = await storage.getAllUsers();
|
||||
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end));
|
||||
const allPostsArrays = await Promise.all(allPostsPromises);
|
||||
const allScheduledPosts = allPostsArrays.flat();
|
||||
|
||||
// Filtrer uniquement les posts des pages accessibles
|
||||
scheduledPosts = allScheduledPosts.filter(sp => accessiblePageIds.includes(sp.pageId));
|
||||
if (accessiblePageIds.length > 0) {
|
||||
scheduledPosts = await storage.getScheduledPostsByPages(accessiblePageIds, start, end);
|
||||
} else {
|
||||
scheduledPosts = [];
|
||||
}
|
||||
}
|
||||
|
||||
res.json(scheduledPosts);
|
||||
|
||||
+36
-1
@@ -30,7 +30,7 @@ import {
|
||||
type InsertUserPagePermission,
|
||||
} from "@shared/schema";
|
||||
import { db } from "./db";
|
||||
import { eq, and, gte, lte, desc, asc, isNull } from "drizzle-orm";
|
||||
import { eq, and, gte, lte, desc, asc, isNull, inArray } from "drizzle-orm";
|
||||
|
||||
export interface IStorage {
|
||||
// Users
|
||||
@@ -66,6 +66,7 @@ export interface IStorage {
|
||||
|
||||
// Scheduled Posts
|
||||
getScheduledPosts(userId: string, startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
|
||||
getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
|
||||
getScheduledPost(id: string): Promise<ScheduledPost | undefined>;
|
||||
getScheduledPostsByPost(postId: string): Promise<ScheduledPost[]>;
|
||||
createScheduledPost(scheduledPost: InsertScheduledPost): Promise<ScheduledPost>;
|
||||
@@ -260,6 +261,40 @@ export class DatabaseStorage implements IStorage {
|
||||
}));
|
||||
}
|
||||
|
||||
async getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<any[]> {
|
||||
if (pageIds.length === 0) {
|
||||
return [];
|
||||
}
|
||||
|
||||
let query = db
|
||||
.select()
|
||||
.from(scheduledPosts)
|
||||
.innerJoin(posts, eq(scheduledPosts.postId, posts.id))
|
||||
.leftJoin(socialPages, eq(scheduledPosts.pageId, socialPages.id))
|
||||
.where(inArray(scheduledPosts.pageId, pageIds));
|
||||
|
||||
if (startDate && endDate) {
|
||||
const results = await query;
|
||||
return results
|
||||
.filter(r => {
|
||||
const scheduledAt = new Date(r.scheduled_posts.scheduledAt);
|
||||
return scheduledAt >= startDate && scheduledAt <= endDate;
|
||||
})
|
||||
.map(r => ({
|
||||
...r.scheduled_posts,
|
||||
post: r.posts,
|
||||
page: r.social_pages,
|
||||
}));
|
||||
}
|
||||
|
||||
const results = await query;
|
||||
return results.map(r => ({
|
||||
...r.scheduled_posts,
|
||||
post: r.posts,
|
||||
page: r.social_pages,
|
||||
}));
|
||||
}
|
||||
|
||||
async getScheduledPost(id: string): Promise<ScheduledPost | undefined> {
|
||||
const [scheduledPost] = await db.select().from(scheduledPosts).where(eq(scheduledPosts.id, id));
|
||||
return scheduledPost || undefined;
|
||||
|
||||
Reference in new issue
Block a user