Allow all users to generate AI text for posts

Change API endpoint `/api/ai/generate` from `requireAdmin` to `requireAuth` middleware and update OpenRouterService to use shared admin configuration instead of per-user config.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/tWDOGLP
This commit is contained in:
michaelschal committed 2025-10-14 13:58:28 +00:00
1 parent ec2e634956
commit f2672727b8
4 files changed
+12 -5

No files matched your search

+2 -1
View File
@@ -11,6 +11,7 @@ Preferred communication style: Simple, everyday language.
## Recent Changes
### October 14, 2025
- **AI Generation Permissions Fix**: Enabled AI text generation for all authenticated users (previously admin-only). Changed `/api/ai/generate` endpoint from `requireAdmin` to `requireAuth` middleware. Added `getAnyOpenrouterConfig()` method in storage layer to retrieve first available OpenRouter config, enabling shared credentials across all users (same pattern as Cloudinary). Updated `OpenRouterService.generatePostText()` to use shared config instead of per-user lookup. Standard users can now generate AI-powered post text using admin's OpenRouter configuration.
- **Cloudinary Upload Permissions Fix**: Fixed critical bug preventing non-admin users from uploading media. Problem: System searched for user-specific Cloudinary config (only admins can configure). Solution: Added `getAnyCloudinaryConfig()` method in storage layer to retrieve first available config, enabling shared Cloudinary credentials across all users. Updated `cloudinaryService.uploadMedia()` and `deleteMedia()` to use shared config internally while maintaining userId for media ownership. Upload and image editor endpoints now verify shared config exists before processing. Standard users can now upload media successfully using admin's Cloudinary configuration.
- **Android Camera Upload Fix**: Fixed critical Android camera capture bug where uploads failed with 400 error. Android devices send captured files with invalid names (empty, 'blob', etc.) that Multer rejects. Solution: `handleCameraCapture` now detects invalid filenames and creates new File object with generated name `camera-${timestamp}.${extension}` while preserving MIME type. Applied to both new-post and media-upload components. iPhone functionality unaffected.
- **Mobile Performance Optimizations**: Implemented comprehensive mobile speed optimizations for "Nouvelle publication" and "Médiathèque" pages. Changes include: (1) Adaptive initial loading - 6 media items on mobile (<768px), 12 on desktop; (2) Optimized thumbnail URLs - replaced `originalUrl` with `facebookFeedUrl` (1080x1080 Cloudinary transformed images) for 70-90% reduction in data transfer while keeping `originalUrl` for zoom/preview quality; (3) Native lazy loading - added `loading="lazy"` attribute to all `<img>` tags for deferred off-screen image loading; (4) Responsive grid layout - 2 columns on mobile, 3 on desktop (sm:grid-cols-3) for better touch targets. Expected impact: Initial load time reduced from 3-5s to <1s on mobile devices.
@@ -37,7 +38,7 @@ The platform leverages **Cloudinary** for cloud-based image and video storage an
### Authentication & Authorization
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access and `user` limited to publishing features. The **AI Assistant** is restricted to administrators only. Session management is via `express-session` with HTTP-only cookies and a 7-day duration. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component).
Authentication uses **Passport.js** with local strategy and `bcrypt` for password hashing. User roles (`admin`, `user`) control access, with `admin` having full access to configuration settings (Cloudinary, OpenRouter, user management) and `user` limited to publishing features. **AI text generation is available to all authenticated users** using shared admin OpenRouter configuration. Session management is via `express-session` with HTTP-only cookies and a 7-day duration. Routes are protected on both the backend (middleware `requireAuth`, `requireAdmin`) and frontend (`ProtectedRoute` component).
### UI/UX Decisions
+1 -1
View File
@@ -435,7 +435,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
});
// AI text generation
app.post("/api/ai/generate", requireAdmin, async (req, res) => {
app.post("/api/ai/generate", requireAuth, async (req, res) => {
try {
const user = req.user as User;
const userId = user.id;
+3 -3
View File
@@ -18,11 +18,11 @@ export class OpenRouterService {
private baseUrl = "https://openrouter.ai/api/v1/chat/completions";
async generatePostText(productInfo: ProductInfo, userId: string, modelOverride?: string): Promise<GeneratedText[]> {
// Get user's OpenRouter configuration
const config = await storage.getOpenrouterConfig(userId);
// Get any available OpenRouter configuration (shared across all users)
const config = await storage.getAnyOpenrouterConfig();
if (!config) {
throw new Error('Configuration OpenRouter non trouvée. Veuillez configurer OpenRouter dans les paramètres.');
throw new Error('Configuration OpenRouter non trouvée. Veuillez demander à un administrateur de configurer OpenRouter dans les Paramètres.');
}
const prompt = this.buildPrompt(productInfo, config.systemPrompt);
+6
View File
@@ -85,6 +85,7 @@ export interface IStorage {
// OpenRouter Config
getOpenrouterConfig(userId: string): Promise<OpenrouterConfig | undefined>;
getAnyOpenrouterConfig(): Promise<OpenrouterConfig | undefined>;
createOpenrouterConfig(config: InsertOpenrouterConfig): Promise<OpenrouterConfig>;
updateOpenrouterConfig(userId: string, config: Partial<InsertOpenrouterConfig>): Promise<OpenrouterConfig>;
@@ -336,6 +337,11 @@ export class DatabaseStorage implements IStorage {
return config || undefined;
}
async getAnyOpenrouterConfig(): Promise<OpenrouterConfig | undefined> {
const [config] = await db.select().from(openrouterConfig).limit(1);
return config || undefined;
}
async createOpenrouterConfig(config: InsertOpenrouterConfig): Promise<OpenrouterConfig> {
const [newConfig] = await db.insert(openrouterConfig).values(config).returning();
return newConfig;