Merge pull request #54 from R0m1k3/dev

Dev
This commit is contained in:
LogiFlow authored and GitHub committed 2025-10-10 09:52:17 +02:00
commit b3ec919553
5 files changed
+36 -6

No files matched your search

+4
View File
@@ -38,6 +38,10 @@ externalPort = 4200
localPort = 38631
externalPort = 8080
[[ports]]
localPort = 39065
externalPort = 8081
[[ports]]
localPort = 40537
externalPort = 3000
+1 -1
View File
@@ -69,7 +69,7 @@ function Router() {
<Route path="/calendar">{() => <ProtectedRoute component={Calendar} />}</Route>
<Route path="/media">{() => <ProtectedRoute component={Media} />}</Route>
<Route path="/pages">{() => <ProtectedRoute component={PagesManagement} />}</Route>
<Route path="/ai">{() => <ProtectedRoute component={AI} />}</Route>
<Route path="/ai">{() => <ProtectedRoute component={AI} adminOnly />}</Route>
<Route path="/history">{() => <ProtectedRoute component={History} />}</Route>
<Route path="/settings">{() => <ProtectedRoute component={Settings} adminOnly />}</Route>
<Route path="/sql">{() => <ProtectedRoute component={SqlAdmin} adminOnly />}</Route>
+24 -1
View File
@@ -63,7 +63,6 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
{ icon: PlusCircle, label: "Nouvelle publication", href: "/new", badge: null },
{ icon: Calendar, label: "Calendrier", href: "/calendar", badge: null },
{ icon: Images, label: "Médiathèque", href: "/media", badge: null },
{ icon: Bot, label: "Assistant IA", href: "/ai", badge: null },
];
const statsItems = [
@@ -212,6 +211,30 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
</div>
)}
</a>
<a
href="/ai"
onClick={(e) => handleLinkClick("/ai", e)}
className={`
flex items-center gap-3 px-4 py-3 rounded-xl transition-all relative group cursor-pointer
${location === "/ai"
? 'bg-gradient-to-r from-primary/10 to-secondary/10 text-primary shadow-sm'
: 'text-muted-foreground hover:bg-sidebar-accent hover:text-foreground'
}
${isCollapsed ? 'justify-center' : ''}
`}
data-testid="link-assistant-ia"
>
{location === "/ai" && (
<div className="absolute left-0 top-1/2 -translate-y-1/2 w-1 h-8 gradient-primary rounded-r-full" />
)}
<Bot className="w-5 h-5" />
{!isCollapsed && <span>Assistant IA</span>}
{isCollapsed && (
<div className="absolute left-full ml-2 px-3 py-2 bg-popover text-popover-foreground text-sm rounded-lg shadow-lg opacity-0 invisible group-hover:opacity-100 group-hover:visible transition-all whitespace-nowrap z-50">
Assistant IA
</div>
)}
</a>
<a
href="/users"
onClick={(e) => handleLinkClick("/users", e)}
+4 -1
View File
@@ -10,6 +10,9 @@ Preferred communication style: Simple, everyday language.
## Recent Changes
### October 10, 2025
- **AI Assistant Admin-Only Access**: Restricted access to AI Assistant to administrators only. Route `/ai` now requires admin role with `adminOnly` prop. Sidebar moved "Assistant IA" link to Administration section (visible only to admins). Backend endpoints (`/api/ai/models`, `/api/ai/generate`, `/api/ai/generations`) protected with `requireAdmin` middleware. Standard users attempting to access AI features see "Accès refusé" message and receive 403 responses.
### October 9, 2025
- **AI Variants Position**: Repositioned AI-generated text variations to display after "Contenu" card and before "Texte de la publication" card in new-post page for better workflow
- **Calendar Auto-Refresh**: Fixed calendar not updating after creating a new scheduled post. Added `queryClient.invalidateQueries` with `refetchType: 'all'` in `createPostMutation.onSuccess` to force cache invalidation and immediate refetch
@@ -47,7 +50,7 @@ These transformation URLs are stored in the database (`facebookLandscapeUrl`, `f
### Authentication & Authorization
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access and `user` limited to publishing features. Session management is via `express-session` with HTTP-only cookies, `sameSite: 'lax'`, and a 7-day duration, secured by a `SESSION_SECRET` environment variable. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component).
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access and `user` limited to publishing features (posts, calendar, media, history). The **AI Assistant** is restricted to administrators only. Session management is via `express-session` with HTTP-only cookies, `sameSite: 'lax'`, and a 7-day duration, secured by a `SESSION_SECRET` environment variable. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component with optional `adminOnly` prop).
### UI/UX Decisions
+3 -3
View File
@@ -424,7 +424,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
});
// Get available AI models from OpenRouter
app.get("/api/ai/models", requireAuth, async (req, res) => {
app.get("/api/ai/models", requireAdmin, async (req, res) => {
try {
const models = await openRouterService.getAvailableModels();
res.json({ models });
@@ -435,7 +435,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
});
// AI text generation
app.post("/api/ai/generate", requireAuth, async (req, res) => {
app.post("/api/ai/generate", requireAdmin, async (req, res) => {
try {
const user = req.user as User;
const userId = user.id;
@@ -937,7 +937,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
});
// AI Generations
app.get("/api/ai/generations", requireAuth, async (req, res) => {
app.get("/api/ai/generations", requireAdmin, async (req, res) => {
try {
const user = req.user as User;
const userId = user.id;