From 747469bc4c521d2e9e8505ec2c052f0bd282c82d Mon Sep 17 00:00:00 2001 From: michaelschal <35957947-michaelschal@users.noreply.replit.com> Date: Wed, 8 Oct 2025 13:30:19 +0000 Subject: [PATCH] Improve session management by persisting user sessions in production Update server configuration to use connect-pg-simple for PostgreSQL session storage in production environments and MemoryStore for development. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/G8GuKB7 --- .replit | 4 ---- replit.md | 7 ++++++- server/index.ts | 15 +++++++++++++++ 3 files changed, 21 insertions(+), 5 deletions(-) diff --git a/.replit b/.replit index 8146a74..518307b 100644 --- a/.replit +++ b/.replit @@ -22,10 +22,6 @@ externalPort = 3002 localPort = 37659 externalPort = 4200 -[[ports]] -localPort = 38617 -externalPort = 3003 - [[ports]] localPort = 40537 externalPort = 3000 diff --git a/replit.md b/replit.md index 50e51ee..80479af 100644 --- a/replit.md +++ b/replit.md @@ -37,6 +37,9 @@ Preferred communication style: Simple, everyday language. - sameSite: 'lax' pour prévention CSRF - Durée de session: 7 jours - Secret de session via variable d'environnement `SESSION_SECRET` +- Store de session: + - **Production**: PostgreSQL via connect-pg-simple (table `session` auto-créée) + - **Développement**: MemoryStore (par défaut) **Protection des routes**: - Backend: Middleware `requireAuth` pour routes utilisateur, `requireAdmin` pour routes admin @@ -94,7 +97,9 @@ Preferred communication style: Simple, everyday language. - Scheduler service running every minute to check for pending posts - Automated post publication to social media platforms -**Session Management**: Stateless authentication with session cookies (connect-pg-simple for PostgreSQL session store) +**Session Management**: +- Développement: MemoryStore (sessions en mémoire) +- Production: connect-pg-simple (sessions persistées dans PostgreSQL, table `session`) **Key Architectural Patterns**: - Service layer pattern (OpenRouterService, CloudinaryService, SchedulerService) diff --git a/server/index.ts b/server/index.ts index 0b1ff63..bf61ba0 100644 --- a/server/index.ts +++ b/server/index.ts @@ -1,5 +1,7 @@ import express, { type Request, Response, NextFunction } from "express"; import session from "express-session"; +import connectPgSimple from "connect-pg-simple"; +import pg from "pg"; import passport from "./auth"; import { registerRoutes } from "./routes"; import { setupVite, serveStatic, log } from "./vite"; @@ -7,6 +9,7 @@ import { schedulerService } from "./services/scheduler"; import { ensureAdminUserExists } from "./init-admin"; const app = express(); +const PgSession = connectPgSimple(session); declare module 'http' { interface IncomingMessage { @@ -28,7 +31,19 @@ if (!process.env.SESSION_SECRET) { // Déterminer si on utilise HTTPS basé sur APP_URL const isHttps = process.env.APP_URL?.startsWith('https://') || false; +// Configuration du store de session pour production +const sessionStore = process.env.NODE_ENV === 'production' && process.env.DATABASE_URL + ? new PgSession({ + pool: new pg.Pool({ + connectionString: process.env.DATABASE_URL, + }), + tableName: 'session', + createTableIfMissing: true, + }) + : undefined; // MemoryStore par défaut en dev + app.use(session({ + store: sessionStore, secret: process.env.SESSION_SECRET || 'your-secret-key-change-me', resave: false, saveUninitialized: false,