Improve security and filtering for scheduled posts across user pages

Adds a `getScheduledPostsByPages` method to storage, enabling efficient filtering of scheduled posts by authorized page IDs. Updates API routes to correctly retrieve posts based on user roles (admin vs. standard user) and accessible pages, enhancing data security and user experience.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/77tIrOr
This commit is contained in:
michaelschal committed 2025-10-28 15:20:15 +00:00
1 parent 1a16c71a41
commit 6014c4e083
3 files changed
+54 -15

No files matched your search

+1
View File
@@ -11,6 +11,7 @@ Preferred communication style: Simple, everyday language.
## Recent Changes ## Recent Changes
### October 28, 2025 ### October 28, 2025
- **Scheduled Posts Page-Level Filtering Security Fix**: Fixed security vulnerability where users could see occupied dates from all pages in the DateTimePicker, including pages they don't have access to. Added new storage method `getScheduledPostsByPages()` that filters scheduled posts directly in database using SQL WHERE IN clause with authorized page IDs. Modified GET `/api/scheduled-posts` endpoint to use getUserAccessiblePages for standard users (only their assigned pages) and all pages for admins. This eliminates temporary exposure of sensitive data in memory and improves performance by querying only authorized posts from the database.
- **Interactive Calendar with Visual Indicators**: Replaced native datetime-local input with custom DateTimePicker component featuring visual planning aids. Calendar displays occupied dates with red background (bg-red-500/20) to prevent scheduling conflicts. Time selector highlights optimal posting hours (8h, 12h-13h, 18h-20h) with green background (bg-green-500/20) and sparkle emoji to maximize audience engagement. Component includes clear button (X icon) to quickly return to immediate publishing, useEffect synchronization for external state updates, and French locale support via date-fns. Time selector optimized for compactness: ScrollArea height reduced from 240px to 192px (20% smaller), button height set to 36px for touch accessibility, tighter padding and margins throughout. Mobile calendar list still displays today's date first for quick access. - **Interactive Calendar with Visual Indicators**: Replaced native datetime-local input with custom DateTimePicker component featuring visual planning aids. Calendar displays occupied dates with red background (bg-red-500/20) to prevent scheduling conflicts. Time selector highlights optimal posting hours (8h, 12h-13h, 18h-20h) with green background (bg-green-500/20) and sparkle emoji to maximize audience engagement. Component includes clear button (X icon) to quickly return to immediate publishing, useEffect synchronization for external state updates, and French locale support via date-fns. Time selector optimized for compactness: ScrollArea height reduced from 240px to 192px (20% smaller), button height set to 36px for touch accessibility, tighter padding and margins throughout. Mobile calendar list still displays today's date first for quick access.
- **Facebook Video Story Publishing Fix**: Fixed critical bug preventing video story publication. Facebook Graph API requires a 3-phase upload process for video stories: (1) START phase - initialize upload session and get `video_id` + `upload_url`, (2) UPLOAD phase - POST video to rupload.facebook.com endpoint with `file_url` header and OAuth authorization, (3) FINISH phase - finalize and publish story with `video_id`. Previous implementation incorrectly attempted direct upload to `/video_stories` endpoint with `file_url` parameter, causing "#100 The parameter upload_phase is required" error. Fixed by implementing proper 3-phase workflow using remote URL upload method (file_url header), avoiding need for binary chunked uploads. - **Facebook Video Story Publishing Fix**: Fixed critical bug preventing video story publication. Facebook Graph API requires a 3-phase upload process for video stories: (1) START phase - initialize upload session and get `video_id` + `upload_url`, (2) UPLOAD phase - POST video to rupload.facebook.com endpoint with `file_url` header and OAuth authorization, (3) FINISH phase - finalize and publish story with `video_id`. Previous implementation incorrectly attempted direct upload to `/video_stories` endpoint with `file_url` parameter, causing "#100 The parameter upload_phase is required" error. Fixed by implementing proper 3-phase workflow using remote URL upload method (file_url header), avoiding need for binary chunked uploads.
+17 -14
View File
@@ -991,24 +991,27 @@ export async function registerRoutes(app: Express): Promise<Server> {
let scheduledPosts; let scheduledPosts;
if (user.role === 'admin') { if (user.role === 'admin') {
// Admin voit tous les posts programmés // Admin voit tous les posts programmés - on récupère toutes les pages
const allUsers = await storage.getAllUsers(); const allPages = await storage.getAllUsers().then(users =>
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end)); Promise.all(users.map(u => storage.getSocialPages(u.id)))
const allPostsArrays = await Promise.all(allPostsPromises); ).then(pagesArrays => pagesArrays.flat());
scheduledPosts = allPostsArrays.flat(); const allPageIds = allPages.map(p => p.id);
if (allPageIds.length > 0) {
scheduledPosts = await storage.getScheduledPostsByPages(allPageIds, start, end);
} else { } else {
// User voit tous les posts programmés sur les pages qui lui sont attribuées (peu importe qui les a créés) scheduledPosts = [];
}
} else {
// User voit uniquement les posts programmés sur les pages qui lui sont attribuées
const accessiblePages = await storage.getUserAccessiblePages(userId); const accessiblePages = await storage.getUserAccessiblePages(userId);
const accessiblePageIds = accessiblePages.map(p => p.id); const accessiblePageIds = accessiblePages.map(p => p.id);
// Récupérer tous les posts programmés de tous les utilisateurs if (accessiblePageIds.length > 0) {
const allUsers = await storage.getAllUsers(); scheduledPosts = await storage.getScheduledPostsByPages(accessiblePageIds, start, end);
const allPostsPromises = allUsers.map(u => storage.getScheduledPosts(u.id, start, end)); } else {
const allPostsArrays = await Promise.all(allPostsPromises); scheduledPosts = [];
const allScheduledPosts = allPostsArrays.flat(); }
// Filtrer uniquement les posts des pages accessibles
scheduledPosts = allScheduledPosts.filter(sp => accessiblePageIds.includes(sp.pageId));
} }
res.json(scheduledPosts); res.json(scheduledPosts);
+36 -1
View File
@@ -30,7 +30,7 @@ import {
type InsertUserPagePermission, type InsertUserPagePermission,
} from "@shared/schema"; } from "@shared/schema";
import { db } from "./db"; import { db } from "./db";
import { eq, and, gte, lte, desc, asc, isNull } from "drizzle-orm"; import { eq, and, gte, lte, desc, asc, isNull, inArray } from "drizzle-orm";
export interface IStorage { export interface IStorage {
// Users // Users
@@ -66,6 +66,7 @@ export interface IStorage {
// Scheduled Posts // Scheduled Posts
getScheduledPosts(userId: string, startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>; getScheduledPosts(userId: string, startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<ScheduledPost[]>;
getScheduledPost(id: string): Promise<ScheduledPost | undefined>; getScheduledPost(id: string): Promise<ScheduledPost | undefined>;
getScheduledPostsByPost(postId: string): Promise<ScheduledPost[]>; getScheduledPostsByPost(postId: string): Promise<ScheduledPost[]>;
createScheduledPost(scheduledPost: InsertScheduledPost): Promise<ScheduledPost>; createScheduledPost(scheduledPost: InsertScheduledPost): Promise<ScheduledPost>;
@@ -260,6 +261,40 @@ export class DatabaseStorage implements IStorage {
})); }));
} }
async getScheduledPostsByPages(pageIds: string[], startDate?: Date, endDate?: Date): Promise<any[]> {
if (pageIds.length === 0) {
return [];
}
let query = db
.select()
.from(scheduledPosts)
.innerJoin(posts, eq(scheduledPosts.postId, posts.id))
.leftJoin(socialPages, eq(scheduledPosts.pageId, socialPages.id))
.where(inArray(scheduledPosts.pageId, pageIds));
if (startDate && endDate) {
const results = await query;
return results
.filter(r => {
const scheduledAt = new Date(r.scheduled_posts.scheduledAt);
return scheduledAt >= startDate && scheduledAt <= endDate;
})
.map(r => ({
...r.scheduled_posts,
post: r.posts,
page: r.social_pages,
}));
}
const results = await query;
return results.map(r => ({
...r.scheduled_posts,
post: r.posts,
page: r.social_pages,
}));
}
async getScheduledPost(id: string): Promise<ScheduledPost | undefined> { async getScheduledPost(id: string): Promise<ScheduledPost | undefined> {
const [scheduledPost] = await db.select().from(scheduledPosts).where(eq(scheduledPosts.id, id)); const [scheduledPost] = await db.select().from(scheduledPosts).where(eq(scheduledPosts.id, id));
return scheduledPost || undefined; return scheduledPost || undefined;