Commit Graph
10 Commits
Author SHA1 Message Date
Michael f8ddb44e38 feat(analytics): Implement Analytics Dashboard and Token Management 2026-01-20 13:49:24 +01:00
Michael 55c2bfdeb7 fix: add trust proxy for nginx reverse proxy support 2026-01-07 15:02:40 +01:00
Michael 633875e8ec feat(security): implement security fixes - Add AES-256-GCM encryption for Facebook/Instagram tokens - Add helmet for HTTP security headers - Add rate limiting (5 login attempts, 100 req/15min) - Add file upload validation (50MB max, MIME type whitelist) - Secure SQL console endpoint (disabled in production) - Enforce SESSION_SECRET in production 2026-01-07 14:57:36 +01:00
michaelschal 747469bc4c Improve session management by persisting user sessions in production
Update server configuration to use connect-pg-simple for PostgreSQL session storage in production environments and MemoryStore for development.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/G8GuKB7
2025-10-08 13:30:19 +00:00
michaelschal 7fa93b11e3 Improve logging by excluding specific unauthenticated session requests
Exclude logging of 401 status codes for the /api/auth/session endpoint in the request logger middleware.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/wfvl0l3
2025-10-04 11:37:55 +00:00
michaelschal df8d3d4190 Ensure secure session cookies are only sent over HTTPS connections
Update session cookie configuration to conditionally set the 'secure' flag based on the application's URL protocol (HTTPS). This change ensures that session cookies are only transmitted over secure HTTPS connections in production environments, enhancing security.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/Tstc8oV
2025-10-02 07:13:13 +00:00
michaelschal 04b19e74ca Ensure admin user is created before the server starts
Move the `ensureAdminUserExists` call to before `server.listen` in `server/index.ts`.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/COxOmlM
2025-10-02 06:34:11 +00:00
michaelschal 1355385bf2 Add default admin user creation for new installations
Creates an admin user with default credentials ('admin'/'admin') if one does not exist upon server startup, ensuring initial access for new deployments.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/COxOmlM
2025-10-02 06:30:23 +00:00
michaelschal 5ee75edf8c Add user authentication and admin roles to manage application access
Implement user login, session management, and role-based access control for users and administrators. Includes new admin pages for user management and SQL query execution.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/HPCBgsr
2025-10-01 16:48:20 +00:00
michaelschal f881f668a6 Add Docker support and installation guide for easy server deployment
Includes a Dockerfile for building the application image and an INSTALLATION.md file detailing the setup process, prerequisites, and helpful commands for managing the application on a private server.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/ds3R7vP
2025-10-01 09:52:59 +00:00