mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
Restrict AI features to administrators only for improved control
Update routes and sidebar to enforce admin-only access for AI features, including model retrieval, text generation, and history viewing. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/G1P4XGr
This commit is contained in:
1 parent
e74ff88a07
commit
f291fc000b
4 files changed
+32
-5
No files matched your search
@@ -38,6 +38,10 @@ externalPort = 4200
|
||||
localPort = 38631
|
||||
externalPort = 8080
|
||||
|
||||
[[ports]]
|
||||
localPort = 39065
|
||||
externalPort = 8081
|
||||
|
||||
[[ports]]
|
||||
localPort = 40537
|
||||
externalPort = 3000
|
||||
|
||||
+1
-1
@@ -69,7 +69,7 @@ function Router() {
|
||||
<Route path="/calendar">{() => <ProtectedRoute component={Calendar} />}</Route>
|
||||
<Route path="/media">{() => <ProtectedRoute component={Media} />}</Route>
|
||||
<Route path="/pages">{() => <ProtectedRoute component={PagesManagement} />}</Route>
|
||||
<Route path="/ai">{() => <ProtectedRoute component={AI} />}</Route>
|
||||
<Route path="/ai">{() => <ProtectedRoute component={AI} adminOnly />}</Route>
|
||||
<Route path="/history">{() => <ProtectedRoute component={History} />}</Route>
|
||||
<Route path="/settings">{() => <ProtectedRoute component={Settings} adminOnly />}</Route>
|
||||
<Route path="/sql">{() => <ProtectedRoute component={SqlAdmin} adminOnly />}</Route>
|
||||
|
||||
@@ -63,7 +63,6 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
|
||||
{ icon: PlusCircle, label: "Nouvelle publication", href: "/new", badge: null },
|
||||
{ icon: Calendar, label: "Calendrier", href: "/calendar", badge: null },
|
||||
{ icon: Images, label: "Médiathèque", href: "/media", badge: null },
|
||||
{ icon: Bot, label: "Assistant IA", href: "/ai", badge: null },
|
||||
];
|
||||
|
||||
const statsItems = [
|
||||
@@ -212,6 +211,30 @@ export default function Sidebar({ onLinkClick }: SidebarProps = {}) {
|
||||
</div>
|
||||
)}
|
||||
</a>
|
||||
<a
|
||||
href="/ai"
|
||||
onClick={(e) => handleLinkClick("/ai", e)}
|
||||
className={`
|
||||
flex items-center gap-3 px-4 py-3 rounded-xl transition-all relative group cursor-pointer
|
||||
${location === "/ai"
|
||||
? 'bg-gradient-to-r from-primary/10 to-secondary/10 text-primary shadow-sm'
|
||||
: 'text-muted-foreground hover:bg-sidebar-accent hover:text-foreground'
|
||||
}
|
||||
${isCollapsed ? 'justify-center' : ''}
|
||||
`}
|
||||
data-testid="link-assistant-ia"
|
||||
>
|
||||
{location === "/ai" && (
|
||||
<div className="absolute left-0 top-1/2 -translate-y-1/2 w-1 h-8 gradient-primary rounded-r-full" />
|
||||
)}
|
||||
<Bot className="w-5 h-5" />
|
||||
{!isCollapsed && <span>Assistant IA</span>}
|
||||
{isCollapsed && (
|
||||
<div className="absolute left-full ml-2 px-3 py-2 bg-popover text-popover-foreground text-sm rounded-lg shadow-lg opacity-0 invisible group-hover:opacity-100 group-hover:visible transition-all whitespace-nowrap z-50">
|
||||
Assistant IA
|
||||
</div>
|
||||
)}
|
||||
</a>
|
||||
<a
|
||||
href="/users"
|
||||
onClick={(e) => handleLinkClick("/users", e)}
|
||||
|
||||
+3
-3
@@ -424,7 +424,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// Get available AI models from OpenRouter
|
||||
app.get("/api/ai/models", requireAuth, async (req, res) => {
|
||||
app.get("/api/ai/models", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const models = await openRouterService.getAvailableModels();
|
||||
res.json({ models });
|
||||
@@ -435,7 +435,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// AI text generation
|
||||
app.post("/api/ai/generate", requireAuth, async (req, res) => {
|
||||
app.post("/api/ai/generate", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const user = req.user as User;
|
||||
const userId = user.id;
|
||||
@@ -937,7 +937,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// AI Generations
|
||||
app.get("/api/ai/generations", requireAuth, async (req, res) => {
|
||||
app.get("/api/ai/generations", requireAdmin, async (req, res) => {
|
||||
try {
|
||||
const user = req.user as User;
|
||||
const userId = user.id;
|
||||
|
||||
Reference in new issue
Block a user