mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
5 files changed
+36
-6
No files matched your search
@@ -38,6 +38,10 @@ externalPort = 4200
|
||||
localPort = 38631
|
||||
externalPort = 8080
|
||||
|
||||
[[ports]]
|
||||
localPort = 39065
|
||||
externalPort = 8081
|
||||
|
||||
[[ports]]
|
||||
localPort = 40537
|
||||
externalPort = 3000
|
||||
|
||||
+1
-1
@@ -69,7 +69,7 @@ function Router() {
|
||||
<Route path="/calendar">{() => <ProtectedRoute component={Calendar} />}</Route>
|
||||
<Route path="/media">{() => <ProtectedRoute component={Media} />}</Route>
|
||||
<Route path="/pages">{() => <ProtectedRoute component={PagesManagement} />}</Route>
|
||||
<Route path="/ai">{() => <ProtectedRoute component={AI} />}</Route>
|
||||
<Route path="/ai">{() => <ProtectedRoute component={AI} adminOnly />}</Route>
|
||||
<Route path="/history">{() => <ProtectedRoute component={History} />}</Route>
|
||||
<Route path="/settings">{() => <ProtectedRoute component={Settings} adminOnly />}</Route>
|
||||
<Route path="/sql">{() => <ProtectedRoute component={SqlAdmin} adminOnly />}</Route>
|
||||
|
||||
@@ -63,7 +63,6 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
|
||||
{ icon: PlusCircle, label: "Nouvelle publication", href: "/new", badge: null },
|
||||
{ icon: Calendar, label: "Calendrier", href: "/calendar", badge: null },
|
||||
{ icon: Images, label: "Médiathèque", href: "/media", badge: null },
|
||||
{ icon: Bot, label: "Assistant IA", href: "/ai", badge: null },
|
||||
];
|
||||
|
||||
const statsItems = [
|
||||
@@ -212,6 +211,30 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
|
||||
</div>
|
||||
)}
|
||||
</a>
|
||||
<a
|
||||
href="/ai"
|
||||
onClick={(e) => handleLinkClick("/ai", e)}
|
||||
className={`
|
||||
flex items-center gap-3 px-4 py-3 rounded-xl transition-all relative group cursor-pointer
|
||||
${location === "/ai"
|
||||
? 'bg-gradient-to-r from-primary/10 to-secondary/10 text-primary shadow-sm'
|
||||
: 'text-muted-foreground hover:bg-sidebar-accent hover:text-foreground'
|
||||
}
|
||||
${isCollapsed ? 'justify-center' : ''}
|
||||
`}
|
||||
data-testid="link-assistant-ia"
|
||||
>
|
||||
{location === "/ai" && (
|
||||
<div className="absolute left-0 top-1/2 -translate-y-1/2 w-1 h-8 gradient-primary rounded-r-full" />
|
||||
)}
|
||||
<Bot className="w-5 h-5" />
|
||||
{!isCollapsed && <span>Assistant IA</span>}
|
||||
{isCollapsed && (
|
||||
<div className="absolute left-full ml-2 px-3 py-2 bg-popover text-popover-foreground text-sm rounded-lg shadow-lg opacity-0 invisible group-hover:opacity-100 group-hover:visible transition-all whitespace-nowrap z-50">
|
||||
Assistant IA
|
||||
</div>
|
||||
)}
|
||||
</a>
|
||||
<a
|
||||
href="/users"
|
||||
onClick={(e) => handleLinkClick("/users", e)}
|
||||
|
||||
@@ -10,6 +10,9 @@ Preferred communication style: Simple, everyday language.
|
||||
|
||||
## Recent Changes
|
||||
|
||||
### October 10, 2025
|
||||
- **AI Assistant Admin-Only Access**: Restricted access to AI Assistant to administrators only. Route `/ai` now requires admin role with `adminOnly` prop. Sidebar moved "Assistant IA" link to Administration section (visible only to admins). Backend endpoints (`/api/ai/models`, `/api/ai/generate`, `/api/ai/generations`) protected with `requireAdmin` middleware. Standard users attempting to access AI features see "Accès refusé" message and receive 403 responses.
|
||||
|
||||
### October 9, 2025
|
||||
- **AI Variants Position**: Repositioned AI-generated text variations to display after "Contenu" card and before "Texte de la publication" card in new-post page for better workflow
|
||||
- **Calendar Auto-Refresh**: Fixed calendar not updating after creating a new scheduled post. Added `queryClient.invalidateQueries` with `refetchType: 'all'` in `createPostMutation.onSuccess` to force cache invalidation and immediate refetch
|
||||
@@ -47,7 +50,7 @@ These transformation URLs are stored in the database (`facebookLandscapeUrl`, `f
|
||||
|
||||
### Authentication & Authorization
|
||||
|
||||
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access and `user` limited to publishing features. Session management is via `express-session` with HTTP-only cookies, `sameSite: 'lax'`, and a 7-day duration, secured by a `SESSION_SECRET` environment variable. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component).
|
||||
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access and `user` limited to publishing features (posts, calendar, media, history). The **AI Assistant** is restricted to administrators only. Session management is via `express-session` with HTTP-only cookies, `sameSite: 'lax'`, and a 7-day duration, secured by a `SESSION_SECRET` environment variable. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component with optional `adminOnly` prop).
|
||||
|
||||
### UI/UX Decisions
|
||||
|
||||
|
||||
+3
-3
@@ -424,7 +424,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// Get available AI models from OpenRouter
|
||||
app.get("/api/ai/models", requireAuth, async (req, res) => {
|
||||
app.get("/api/ai/models", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const models = await openRouterService.getAvailableModels();
|
||||
res.json({ models });
|
||||
@@ -435,7 +435,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// AI text generation
|
||||
app.post("/api/ai/generate", requireAuth, async (req, res) => {
|
||||
app.post("/api/ai/generate", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const user = req.user as User;
|
||||
const userId = user.id;
|
||||
@@ -937,7 +937,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// AI Generations
|
||||
app.get("/api/ai/generations", requireAuth, async (req, res) => {
|
||||
app.get("/api/ai/generations", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const user = req.user as User;
|
||||
const userId = user.id;
|
||||
|
||||
Reference in new issue
Block a user