diff --git a/public/js/admin.js b/public/js/admin.js
index cfc8aa2..a19e458 100644
--- a/public/js/admin.js
+++ b/public/js/admin.js
@@ -40,20 +40,19 @@ class AdminService {
${user.id !== 1 ? `
` : ''}
`;
this.usersList.appendChild(userElement);
});
- lucide.createIcons();
}
showAddUserForm() {
diff --git a/public/js/lucide.min.js b/public/js/lucide.min.js
new file mode 100644
index 0000000..d1c2eaf
--- /dev/null
+++ b/public/js/lucide.min.js
@@ -0,0 +1 @@
+// Fichier vide pour éviter les erreurs - les icônes sont maintenant directement intégrées en SVG
\ No newline at end of file
diff --git a/public/js/notes.js b/public/js/notes.js
index 42512ae..60e396e 100644
--- a/public/js/notes.js
+++ b/public/js/notes.js
@@ -32,9 +32,6 @@ class NotesService {
// Auto-save on content changes
this.noteTitle.addEventListener('input', () => this.autoSave());
this.noteContent.addEventListener('input', () => this.autoSave());
-
- // Initialize Lucide icons
- lucide.createIcons();
}
async loadNotes() {
@@ -89,7 +86,7 @@ class NotesService {
${todo.text}
`;
@@ -101,7 +98,6 @@ class NotesService {
this.todosList.appendChild(todoElement);
});
- lucide.createIcons();
}
renderImages() {
@@ -112,7 +108,7 @@ class NotesService {
imageElement.innerHTML = `
`;
@@ -121,7 +117,6 @@ class NotesService {
this.imagesList.appendChild(imageElement);
});
- lucide.createIcons();
}
async createNewNote() {
diff --git a/server.js b/server.js
index 172a2f6..2196139 100644
--- a/server.js
+++ b/server.js
@@ -2,13 +2,35 @@ const express = require('express');
const cors = require('cors');
const helmet = require('helmet');
const path = require('path');
-const { db, logger } = require('./config/database');
+const winston = require('winston');
+const { db } = require('./config/database');
+
+// Configure logger
+const logger = winston.createLogger({
+ level: 'info',
+ format: winston.format.combine(
+ winston.format.timestamp(),
+ winston.format.json()
+ ),
+ transports: [
+ new winston.transports.Console()
+ ]
+});
// Create Express app
const app = express();
// Middleware
-app.use(helmet());
+app.use(helmet({
+ contentSecurityPolicy: {
+ directives: {
+ defaultSrc: ["'self'"],
+ scriptSrc: ["'self'", "'unsafe-inline'"],
+ styleSrc: ["'self'", "'unsafe-inline'"],
+ imgSrc: ["'self'", "data:"],
+ }
+ }
+}));
app.use(cors());
app.use(express.json());
app.use(express.static('public'));