Commit Graph
84 Commits
Author SHA1 Message Date
Claude d0f63c68e4 feat(legal): servir les pages /terms et /privacy exigées par TikTok
L'audit de l'application développeur TikTok impose une URL publique pour
les conditions d'utilisation et pour la politique de confidentialité, et
les relecteurs les ouvrent réellement.

Les pages sont rendues en HTML côté serveur, sans authentification, pour
rester lisibles par un robot qui n'exécute pas le JavaScript du client.
La politique décrit précisément ce que l'intégration fait : données reçues
de TikTok (open_id, nom d'affichage, avatar, jetons), finalité de
publication, chiffrement des jetons au repos, suppression à la
déconnexion et marche à suivre pour retirer l'autorisation.

Les mentions de l'exploitant se configurent via LEGAL_COMPANY_NAME,
LEGAL_COMPANY_ADDRESS et LEGAL_CONTACT_EMAIL.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018uUPZ1GNpEkYB1dpXHYPek
2026-08-11 16:14:13 +00:00
Claude b95cd23ebc feat(tiktok): publier les reels sur les comptes TikTok des magasins
Ajoute la gestion multi-comptes TikTok et permet d'envoyer la même vidéo
sur plusieurs pages Facebook ET plusieurs comptes TikTok en une seule
publication.

Un compte TikTok vit dans social_pages comme une page Facebook : il hérite
donc des permissions par utilisateur, de la planification et du calendrier.

Trois particularités de l'API TikTok structurent l'implémentation :
- pas de jeton saisi à la main : chaque compte passe par OAuth, et
  l'access token (24h) est renouvelé via le refresh token (1 an) avant
  chaque publication ;
- la publication est asynchrone : l'upload rend un publish_id, et un
  poller récupère l'identifiant définitif du post ;
- creator_info doit être interrogé avant chaque envoi pour ne demander
  qu'un niveau de confidentialité réellement autorisé sur le compte.

Serveur :
- service TikTok (OAuth, creator_info, upload FILE_UPLOAD par chunks,
  suivi de statut) et routes de connexion/configuration
- schéma : platform 'tiktok', refresh token et scopes sur social_pages,
  publish_id/publish_status sur scheduled_posts, table tiktok_config
- routage par plateforme dans les deux flux de reels et le planificateur
- cron de suivi des publications, token manager et analytics adaptés

Client :
- connexion et reconnexion des comptes TikTok depuis « Pages gérées »
- sélection combinée pages Facebook / comptes TikTok à la publication
- configuration de l'application TikTok dans les paramètres (admin)

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018uUPZ1GNpEkYB1dpXHYPek
2026-08-11 14:29:38 +00:00
Michael 72b13b3e42 Add Google Gemini TTS as alternative to Edge TTS
- Store Gemini API key globally in appConfig (single key for all users)
- Add /api/settings/gemini GET/POST/DELETE routes for API key management
- Backend: add tts_engine parameter ("edge" or "gemini") to FFmpeg service
- Backend: add generate_tts_gemini() using Google Cloud TTS REST API
- Frontend: Settings page shows Google Gemini API key input card
- Frontend: new-reel, mobile/new-reel, remotion-video, mobile/remotion-video
  pages now have Edge/Gemini engine toggle and French voice selector
- Fix tts-preview route to extract ttsVoice from req.body instead of
  undefined voice variable
2026-05-19 12:17:42 +02:00
Michael 59bc56aedc refactor: remove Piper TTS, keep edge_tts only
- Remove piper_url from ReelRequest model and all function signatures
- Remove generate_tts_piper() function and Piper branch in generate_tts_with_subs()
- Remove /api/piper/config routes from server/routes.ts
- Remove piperConfig table, schemas and storage methods
- Remove piper_config migration
- Remove Piper TTS settings UI card
- Update "Piper TTS" labels to "TTS — voix activée"

edge_tts is now the only TTS engine, using precise word-boundary timing
2026-05-19 10:55:01 +02:00
MichaelandClaude Sonnet 4.6 797e12dde5 refactor(tts): replace Minimax+Freesound with Piper TTS
Remove Minimax Speech API and Freesound integrations entirely.
Add Piper TTS as the sole TTS provider via configurable HTTP URL.

- Add piper_config DB table (url field, per-user)
- Add GET/POST /api/piper/config routes
- Python: replace generate_tts_minimax with generate_tts_piper (GET ?text=, WAV→MP3)
- Simplify generate_tts_with_subs: piper_url param replaces tts_provider+minimax fields
- Drop ttsVoice/ttsProvider from all UI, API, and background job params
- Settings page: replace Minimax+Freesound cards with single Piper URL input
- Remove freeSoundService init from server startup and CSP headers

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-19 09:15:26 +02:00
Michael 35cf21209f fix(settings): prevent empty string API keys from being saved or preserved
- Add .min(1) validation to insertOpenrouterConfigSchema
- Strip empty/whitespace-only apiKey before fallback to existing key
- Return 400 if resulting apiKey is empty (forces user to enter valid key)
2026-05-18 12:32:11 +02:00
Michael b7ef4940f7 feat: add Minimax Speech as alternative TTS provider for Reels
- Add minimax_config table (migration + schema + storage CRUD)
- Add GET/POST /api/minimax/config routes
- Pass tts_provider + minimax_api_key through ffmpeg service
- Add generate_tts_minimax() in Python using Minimax T2A v2 API
- Fall back to ffsubsync for subtitle sync (no WordBoundary events)
- Add Minimax config card in Settings page
- Add provider toggle (Edge TTS / Minimax) + French voices in new-reel
2026-05-18 11:55:07 +02:00
MichaelandClaude Sonnet 4.6 391acfdb83 feat: add external API for publishing posts with image URL and scheduling
- New POST /api/v1/publish endpoint: download image from URL, create post and schedule it per page
- New GET /api/v1/pages endpoint: list available pages for external callers
- API key auth via X-API-Key header, configurable from admin settings (stored in DB)
- New app_config table (migration included) to store the external API key
- Admin-only settings section (desktop + mobile) to set/revoke the key
- Fallback to EXTERNAL_API_KEY env var if no DB key is configured

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-06 13:12:27 +02:00
Michael 3122e162cc feat: implement user authentication and management routes with multer file upload support 2026-03-30 11:30:56 +02:00
MichaelandClaude Sonnet 4.6 a40a5a500e fix: read logo file from disk before uploading (multer uses diskStorage)
req.file.buffer is undefined with diskStorage — must read the temp file
from req.file.path using fs.readFileSync instead.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 11:14:17 +01:00
MichaelandClaude Sonnet 4.6 545dfec17f fix: add migration endpoint to convert absolute localhost media URLs to relative
Images uploaded between the local storage switch and the relative URL
fix have http://hostname/uploads/... stored in DB, which is blocked by
CSP. POST /api/media/fix-urls (admin only) updates all affected rows
to use relative /uploads/... paths.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 09:26:43 +01:00
MichaelandClaude Sonnet 4.6 7733acbc22 feat: Replace external storage with local file storage + auto cleanup
Media is now stored directly on the server disk (no external service).
Files are served via Express static middleware at /uploads/*.

Cleanup rules:
- Videos deleted immediately after successful publish to Facebook/Instagram
- Videos older than 7 days purged daily by cron job
- Images older than 30 days purged daily by cron job

Changes:
- server/services/minio.ts: replaced S3 client with local fs read/write
- server/index.ts: added static serving for /uploads/media, /logos, /stories
- server/services/media-purge.ts: new rules (images 30d, videos 7d)
- server/services/scheduler.ts: delete local videos after successful publish
- docker-compose.yml: add media_uploads, logos_uploads, stories_uploads volumes
- settings UI: removed credentials card, shows local storage info
- package.json: removed googleapis (unneeded)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-25 07:35:27 +01:00
MichaelandClaude Sonnet 4.6 ba94e7cc7d feat: Add MinIO endpoint/public URL configuration via settings UI
Store endpointUrl and publicUrl in cloudinary_config DB table so
MinIO connection can be fully configured from the app settings
without needing environment variables.

- DB migration: adds endpoint_url and public_url columns
- Schema: adds endpointUrl/publicUrl to cloudinaryConfig table
- MinIO service: reads endpoint from DB (falls back to MINIO_ENDPOINT env)
- buildMinioUrl: accepts optional publicUrl override from DB config
- All routes updated to pass config.publicUrl to buildMinioUrl
- Settings UI (desktop + mobile): adds Endpoint URL and Public URL fields

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-24 21:19:49 +01:00
MichaelandClaude Sonnet 4.6 e39fa1026d feat: replace Cloudinary with MinIO for all media storage
- Create server/services/minio.ts: S3-compatible service (same interface as
  cloudinaryService) using @aws-sdk/client-s3 and MINIO_ENDPOINT env var
- Replace all cloudinaryService imports with minioService across routes.ts,
  routes/reels.ts, routes/remotion.ts, services/media-purge.ts
- Replace Cloudinary logo URL pattern (res.cloudinary.com/...) with
  buildMinioUrl() helper throughout all server routes
- GET /api/cloudinary/config now returns a logoUrl field (full MinIO URL)
  so clients never need to build the URL themselves
- Update settings pages (desktop + mobile): labels changed to MinIO
  (Bucket Name, Access Key, Secret Key)
- Update image-editor.tsx: remove Cloudinary URL transformation, use logoUrl
- Update media-utils.ts: simplify getVideoThumbnailUrl (no URL transforms)
- Add MINIO_ENDPOINT and MINIO_PUBLIC_URL to docker-compose.yml + .env.example
- DB table reuse: cloudinary_config.cloud_name = bucket, api_key = access key,
  api_secret = secret key — no migration needed

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-03-24 21:05:37 +01:00
Michael abfb958340 deps: Add music-metadata dependency. 2026-03-24 16:55:18 +01:00
Michael e41c43c1da feat: Implement Remotion video generation with dedicated client UI, components, and server-side rendering. 2026-03-24 12:35:52 +01:00
Michael a01194cc79 fix(cloudinary): correct method name to getCloudinaryConfig across backend 2026-03-04 14:45:38 +01:00
Michael f6376cb470 Merge branch 'main' of https://github.com/R0m1k3/Socialflow 2026-03-04 14:25:06 +01:00
Michael 82befb2264 feat: Implement analytics, media management, and third-party service configurations with new settings pages. 2026-03-04 14:25:02 +01:00
Michael 4e189e7797 feat: add core API routes for authentication, user management, and file upload handling. 2026-03-02 14:16:19 +01:00
Michael 7e5c73cad9 feat: establish server API routes for authentication, user management, and media processing. 2026-03-02 13:33:23 +01:00
Michael 94429e86df feat: Initialize the core Express server with security, session management, and service integrations, and add a Docker volume for audio file persistence. 2026-03-02 13:21:05 +01:00
Michael 04373d2881 feat: introduce audio administration, reel generation, and enhanced analytics with new database schema and API routes. 2026-03-02 13:11:37 +01:00
Michael 9e9eb7d1bb feat: implement multi-step reel creation flow with video upload, music selection, text generation, and scheduling. 2026-03-02 12:10:50 +01:00
Michael 0e9622b5eb feat: Implement internal MP3 management and logo overlay functionality for Reels. 2026-03-02 11:33:22 +01:00
Michael 62562d37f1 feat: Implement dynamic Freesound configuration (DB, API, UI) 2026-02-03 15:45:08 +01:00
Michael 891b374500 feat: support large file uploads up to 4GB (disk storage + streaming) 2026-01-23 16:27:27 +01:00
Michael a512084f1b fixing sql conrole 2026-01-22 16:10:54 +01:00
Michael ba81447d10 fix authentification 2026-01-22 14:41:03 +01:00
Michael 4903aa5555 fix: Improve Reel text generation and add FFmpeg settings - Fix generate-text to use productInfo as ProductInfo object - Add FFmpeg API configuration section in Settings page - Add /api/ffmpeg/config GET/POST routes 2026-01-22 12:07:58 +01:00
Michael 3d494d4056 feat: Add Facebook Reels with music and text overlay - Add ffmpeg.ts service for Docker FFmpeg API integration - Add jamendo.ts service for royalty-free music search - Add publishReel methods to facebook.ts - Add reels API routes (music search, AI text generation, create/preview) - Add new-reel.tsx frontend with 4-step workflow - Add 'reel' type to postTypeEnum - Update navigation with Nouveau Reel link 2026-01-22 11:57:27 +01:00
Michael c37a56b366 fix: reset token status on update and suppress metric errors 2026-01-21 16:14:08 +01:00
Michael f8ddb44e38 feat(analytics): Implement Analytics Dashboard and Token Management 2026-01-20 13:49:24 +01:00
Michael 6c299b954a fix: auto-rotate images based on EXIF data 2026-01-07 20:51:56 +01:00
Michael 633875e8ec feat(security): implement security fixes - Add AES-256-GCM encryption for Facebook/Instagram tokens - Add helmet for HTTP security headers - Add rate limiting (5 login attempts, 100 req/15min) - Add file upload validation (50MB max, MIME type whitelist) - Secure SQL console endpoint (disabled in production) - Enforce SESSION_SECRET in production 2026-01-07 14:57:36 +01:00
michaelschal 2c2e3822f6 Correctly display the Euro symbol with product prices
Fix an issue where the Euro symbol was misplaced when saving product images, ensuring it appears after the price consistently.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Event-Id: e8c912ba-b86c-4da3-954c-070906550761
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/ltYxoh9
2025-11-22 11:13:41 +00:00
michaelschal 3d26473967 Update token expiration calculation to 60 days for managed pages
Adjusted the token expiration calculation from 90 days to 60 days in server/routes.ts for both new page registrations and access token updates.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 8f8a8bbf-c2e3-4e22-b512-22aeb9e46ecf
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/C5fWcTz
2025-11-18 19:05:33 +00:00
michaelschal c15cc72cd1 Update logo sizing to allow larger logos on images
Modify client-side and server-side logic to adjust logo size constraints, ensuring logos adhere to a maximum percentage of image dimensions and incorporate padding for better placement.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: aee6d999-ad55-471c-8c9a-6033843f313e
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/L05E01m
2025-11-18 09:27:20 +00:00
michaelschal 225e4f2292 Add ability to upload and apply custom logos to social media posts
Implement functionality for uploading, applying, and deleting custom logos as overlays on images, along with backend processing and UI updates.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Event-Id: 91999614-5187-4902-b7a1-bf9e372de9c8
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/JgqpaNl
2025-11-18 08:47:42 +00:00
michaelschal 1f58e88d30 Update token expiration to 90 days and recalculate upon update
Adjusted access token expiration to 90 days in POST and PUT routes, updating shared/schema.ts and client/src/pages/pages.tsx.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Event-Id: 9b68577b-34d3-49be-8a1f-69c8bcb3cdb3
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/5aomXd9
2025-11-17 15:38:55 +00:00
michaelschal c47722134b Add token expiration date to social media pages for managed accounts
Update schema and routes to include a `tokenExpiresAt` field, setting it to 60 days after creation for social media page tokens.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Event-Id: a818a1ee-3b1a-48f9-9639-24fc156db095
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/5aomXd9
2025-11-17 15:21:27 +00:00
michaelschal 6014c4e083 Improve security and filtering for scheduled posts across user pages
Adds a `getScheduledPostsByPages` method to storage, enabling efficient filtering of scheduled posts by authorized page IDs. Updates API routes to correctly retrieve posts based on user roles (admin vs. standard user) and accessible pages, enhancing data security and user experience.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/77tIrOr
2025-10-28 15:20:15 +00:00
michaelschal 82846ab633 Ensure users can only post to pages they have access to
Add access control to the posting route in server/routes.ts to verify user permissions against specified pageIds, preventing unauthorized posts.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/tWDOGLP
2025-10-14 14:11:16 +00:00
michaelschal f2672727b8 Allow all users to generate AI text for posts
Change API endpoint `/api/ai/generate` from `requireAdmin` to `requireAuth` middleware and update OpenRouterService to use shared admin configuration instead of per-user config.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/tWDOGLP
2025-10-14 13:58:28 +00:00
michaelschal 3175ffee31 Allow users to upload photos using shared Cloudinary configuration
Update routes to use a shared Cloudinary configuration for media uploads and adjust CloudinaryService to fetch any available config instead of user-specific config.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/vZocxw2
2025-10-14 10:26:14 +00:00
michaelschal f98da13491 Allow users to upload photos using an admin's Cloudinary configuration
Update Cloudinary configuration retrieval to use an admin's settings for all users and modify media upload to utilize the admin's user ID.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/vZocxw2
2025-10-14 10:18:31 +00:00
michaelschal dd43753d6d Update image editor to display currency symbol correctly after price
Remove ribbon generation functionality and adjust currency symbol placement in image editor.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/mIWJXC9
2025-10-11 11:33:30 +00:00
michaelschal bf07167663 Update how image URLs are stored to preserve edits
Adjust image URL storage to consistently use the original URL for all formats when edited images with overlays are present.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/Hpj2VzR
2025-10-11 09:54:10 +00:00
michaelschal 523412bce4 Update ribbon overlay to position text accurately at all corners
Refactor ribbon overlay positioning logic in `routes.ts` to use specific polygon and text coordinates for improved accuracy across all four corners (north_west, north_east, south_west, south_east).

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/Hpj2VzR
2025-10-11 09:51:02 +00:00
michaelschal 773ca663f9 Add ability to apply image overlays on the server
Introduces a new POST endpoint `/api/media/apply-overlays` that uses Sharp to apply customizable ribbon and price badge overlays to images server-side.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/Hpj2VzR
2025-10-11 09:41:32 +00:00