48 Commits
Author SHA1 Message Date
cedric 926fecd125 feat: add ayisyen
Déploiement API BETA / build (push) Successful in 2m23s
Déploiement API PROD / build (push) Successful in 2m26s
Déploiement API BETA / deploy (push) Successful in 1m16s
Déploiement API PROD / deploy (push) Successful in 1m48s
2026-08-11 07:25:55 +04:00
cedric ba5792517b Merge pull request 'Ajouter les premières langues africaines (traduction)' (#6) from feat/africa into master
Déploiement API BETA / build (push) Successful in 2m22s
Déploiement API PROD / build (push) Successful in 2m23s
Déploiement API BETA / deploy (push) Successful in 45s
Déploiement API PROD / deploy (push) Successful in 52s
Reviewed-on: #6
2026-07-05 22:08:54 +00:00
cedric b01132f104 feat: ajouter 14 langues africaines (dont le yoruba, hors DeepL)
Déploiement API BETA / build (push) Successful in 2m26s
Déploiement API BETA / deploy (push) Successful in 47s
Vérification PR / build (pull_request) Successful in 2m21s
Vérification PR / deploy-beta (pull_request) Successful in 43s
2026-07-06 00:05:33 +04:00
cedric 821b9b96aa feat: mettre en avant les langues asiatiques dans l'ordre des traductions
Déploiement API BETA / build (push) Successful in 2m22s
Déploiement API PROD / build (push) Successful in 2m23s
Déploiement API BETA / deploy (push) Successful in 48s
Déploiement API PROD / deploy (push) Successful in 55s
2026-07-05 22:28:27 +04:00
cedric 842e87543c revert: garder les mentions dans les commentaires importés
Déploiement API BETA / build (push) Successful in 2m22s
Déploiement API PROD / deploy (push) Successful in 54s
Déploiement API PROD / build (push) Successful in 2m23s
Déploiement API BETA / deploy (push) Successful in 44s
2026-07-05 20:10:51 +04:00
cedric ecbcf5d86e fix: retirer la mention initiale des commentaires importés
Déploiement API BETA / build (push) Successful in 2m16s
Déploiement API PROD / build (push) Successful in 2m24s
Déploiement API BETA / deploy (push) Successful in 44s
Déploiement API PROD / deploy (push) Successful in 53s
2026-07-05 19:39:33 +04:00
cedric 128c027af1 fix: extraire l'id de la relation avant de la déréférencer
Déploiement API BETA / build (push) Successful in 2m27s
Déploiement API PROD / build (push) Successful in 2m21s
Déploiement API BETA / deploy (push) Successful in 47s
Déploiement API PROD / deploy (push) Successful in 53s
2026-07-05 19:22:29 +04:00
cedric 29bdf72640 fix: réparer la relation commentaire.parole / parole.commentaires
Déploiement API BETA / build (push) Successful in 2m25s
Déploiement API PROD / build (push) Successful in 2m22s
Déploiement API BETA / deploy (push) Successful in 46s
Déploiement API PROD / deploy (push) Successful in 53s
2026-07-05 19:04:39 +04:00
cedric fb60226bd4 fix: publier les commentaires bokante importés
Déploiement API BETA / build (push) Successful in 2m22s
Déploiement API PROD / build (push) Successful in 2m23s
Déploiement API BETA / deploy (push) Successful in 47s
Déploiement API PROD / deploy (push) Successful in 52s
2026-07-05 18:39:01 +04:00
cedric 34f3a7783b docs: documenter les commentaires fédérés (bokante)
Déploiement API BETA / build (push) Successful in 2m20s
Déploiement API PROD / build (push) Successful in 2m21s
Déploiement API BETA / deploy (push) Successful in 44s
Déploiement API PROD / deploy (push) Successful in 56s
2026-07-05 02:06:23 +04:00
cedric 03960cc952 Merge pull request 'Commentaires fédérés via Mastodon (bokante.o-k-i.net) — backend' (#5) from feat/comment-fedi into master
Déploiement API BETA / build (push) Successful in 2m20s
Déploiement API PROD / build (push) Successful in 2m24s
Déploiement API BETA / deploy (push) Successful in 44s
Déploiement API PROD / deploy (push) Successful in 53s
Reviewed-on: #5
2026-07-04 21:24:31 +00:00
cedric 719b4c7905 chore: régénérer les types Strapi (champs bokante)
Déploiement API BETA / build (push) Successful in 2m20s
Vérification PR / build (pull_request) Successful in 2m23s
Déploiement API BETA / deploy (push) Successful in 46s
Vérification PR / deploy-beta (pull_request) Successful in 47s
2026-07-05 01:18:44 +04:00
cedric e416f94061 feat: backfiller le catalogue existant, une parole/heure 2026-07-05 01:07:31 +04:00
cedric 26471d8b0e fix: déplacer le miroir bokante de beforeUpdate vers afterCreate
Avec draftAndPublish sur Strapi 5, publier une entrée crée une
nouvelle ligne (document-service publishEntry -> createEntry) au lieu
de mettre à jour la ligne existante : beforeUpdate ne se déclenche
donc jamais sur une vraie action Publier, seulement sur l'édition
d'une entrée déjà publiée. Le miroir bokante est maintenant posté
dans afterCreate, sur la condition result.publishedAt, avec
synchronisation brouillon/publié pour rester idempotent à travers les
cycles dépublier/republier.
2026-07-05 00:59:59 +04:00
cedric 861e75fde2 feat: planifier l'import des commentaires bokante (20 min) 2026-07-04 23:39:25 +04:00
cedric 6c828a2394 feat: importer les réponses bokante en commentaires 2026-07-04 23:38:41 +04:00
cedric 2a4cea0854 feat: publier un statut miroir bokante à la publication 2026-07-04 23:37:15 +04:00
cedric 648e51fe3c feat: client HTTP minimal pour l'API Mastodon de bokante 2026-07-04 23:33:57 +04:00
cedric 0043a07ec1 feat: schéma pour les commentaires fédérés 2026-07-04 23:31:09 +04:00
cedric 7e705d3976 Merge pull request 'Audit sécurité/qualité : corrections critiques, tests, CI et lint' (#4) from fix/audit-2026-07-04 into master
Déploiement API BETA / deploy (push) Successful in 45s
Déploiement API PROD / deploy (push) Successful in 1m25s
Déploiement API BETA / build (push) Successful in 2m19s
Déploiement API PROD / build (push) Successful in 2m27s
Reviewed-on: #4
2026-07-04 17:01:30 +00:00
cedric 2c84ea0f25 fix: corriger les erreurs ESLint restantes après activation
Déploiement API BETA / build (push) Successful in 2m24s
Déploiement API BETA / deploy (push) Successful in 1m37s
Vérification PR / build (pull_request) Successful in 2m23s
Vérification PR / deploy-beta (pull_request) Successful in 48s
- retirer les paramètres/variables inutilisés (result, ctx/next, qs)
- corriger l'indentation tabs/espaces mélangés dans src/admin/app.js
- retirer les échappements regex inutiles dans stripMarkdown
- remplacer while(true) par for(;;) (faux positif no-constant-condition)
2026-07-04 20:01:16 +04:00
cedric 2224c8f3bb chore: activer ESLint sur le backend
Installe eslint, ajoute le script lint, modernise le parser
(retrait de babel-eslint obsolète) et applique l'autofix
(points-virgules manquants sur l'ensemble du code, conformément
à la règle "semi" déjà présente dans .eslintrc mais jamais
appliquée faute d'ESLint installé et d'un script pour l'exécuter).
2026-07-04 20:00:51 +04:00
cedric 90c048a282 fix: whitelister les champs autorisés sur create/update (mass assignment) 2026-07-04 15:08:19 +04:00
cedric 1d54d287e1 fix: retirer createdBy/updatedBy du payload dans beforeUpdate 2026-07-04 15:04:18 +04:00
cedric 3b9b28d326 fix: ne plus écraser les commentaires existants d'une parole 2026-07-04 14:59:58 +04:00
cedric 4ee7ed3e5e fix: corriger la signature de parole.findOne (ctx au lieu de documentId) 2026-07-04 14:58:43 +04:00
cedric 0afa9251d6 ci: exécuter les tests dans deploy-beta et deploy-prod 2026-07-04 11:39:53 +04:00
cedric 250ae822ea chore: retirer les secrets de fallback hardcodés dans admin.js 2026-07-04 11:39:45 +04:00
cedric b36f53f022 chore: supprimer les dossiers legacy extensions/ et components/ 2026-07-04 11:39:36 +04:00
cedric e4187a697a fix: envoyer le commentaire en texte brut (éviter l'injection HTML) 2026-07-04 11:38:56 +04:00
cedric c0d6834178 feat: implémenter réellement la sauvegarde hebdomadaire de la base 2026-07-04 11:38:26 +04:00
cedric 6f77c17003 fix: valider data.user/data.artistes avant déréférencement 2026-07-04 11:38:02 +04:00
cedric c4f45f712a fix: éviter un crash sur updatedBy non peuplé 2026-07-04 11:37:40 +04:00
cedric c66c972a93 fix: réparer la cascade de renommage des slugs d'artiste 2026-07-04 11:37:20 +04:00
cedric 85ecdf3072 fix: retirer l'override register qui exposait le hash de mot de passe 2026-07-04 11:36:50 +04:00
cedric 291aa54912 fix: corriger l'IDOR sur update/delete (parole, artiste, commentaire) 2026-07-04 11:36:20 +04:00
cedric bc5d0fb498 fix: refuser par défaut is-payload-owner sans en-tête Authorization 2026-07-04 11:35:41 +04:00
cedric e515944fb9 refactor: extraire la vérification JWT/payload en policy partagée 2026-07-04 10:04:00 +04:00
cedric 1562ecd706 ci: exécuter les tests avant le build sur chaque PR 2026-07-04 09:56:26 +04:00
cedric 416032942a fix: restreindre bulk-translate aux appels par token API 2026-07-04 09:55:45 +04:00
cedric 9fa37c516c chore: retirer la config rest-cache (plugin non installé, incompatible v5) 2026-07-04 09:54:39 +04:00
cedric d87ab299c4 chore: déclarer axios comme dépendance directe 2026-07-04 09:52:36 +04:00
cedric 4c13f47156 fix: ne pas bloquer la publication si Telegram/Revolt échoue 2026-07-04 09:51:10 +04:00
cedric 36917d79b4 fix: ajouter un timeout DeepL et isoler les échecs par langue 2026-07-04 09:47:26 +04:00
cedric ddb6d3f2f0 fix: corriger les mauvais identifiants utilisés (id vs documentId) 2026-07-04 09:43:28 +04:00
cedric 8b17882d6b fix: corriger le ReferenceError dans artiste.create 2026-07-04 09:37:37 +04:00
cedric f592d4ded7 fix: stopper l'exécution après un refus d'autorisation dans parole.create 2026-07-04 09:36:17 +04:00
cedric 796b4379fd test: ajouter Vitest au backend 2026-07-04 09:36:01 +04:00
65 changed files with 3098 additions and 3274 deletions
+2 -6
View File
@@ -1,17 +1,13 @@
{ {
"parser": "babel-eslint",
"extends": "eslint:recommended", "extends": "eslint:recommended",
"env": { "env": {
"commonjs": true, "commonjs": true,
"es6": true, "es2022": true,
"node": true, "node": true,
"browser": false "browser": false
}, },
"parserOptions": { "parserOptions": {
"ecmaFeatures": { "ecmaVersion": 2022,
"experimentalObjectRestSpread": true,
"jsx": false
},
"sourceType": "module" "sourceType": "module"
}, },
"globals": { "globals": {
+3
View File
@@ -22,6 +22,9 @@ jobs:
- name: Installer les dépendances - name: Installer les dépendances
run: yarn install --frozen-lockfile run: yarn install --frozen-lockfile
- name: Lancer les tests
run: yarn test
- name: Build Strapi - name: Build Strapi
run: yarn build run: yarn build
+3
View File
@@ -20,6 +20,9 @@ jobs:
- name: Installer les dépendances - name: Installer les dépendances
run: yarn install --frozen-lockfile run: yarn install --frozen-lockfile
- name: Lancer les tests
run: yarn test
- name: Build Strapi - name: Build Strapi
run: yarn build run: yarn build
+3
View File
@@ -22,6 +22,9 @@ jobs:
- name: Installer les dépendances - name: Installer les dépendances
run: yarn install --frozen-lockfile run: yarn install --frozen-lockfile
- name: Lancer les tests
run: yarn test
- name: Build Strapi - name: Build Strapi
run: yarn build run: yarn build
+1
View File
@@ -70,6 +70,7 @@ $RECYCLE.BIN/
*.sql *.sql
*.sqlite *.sqlite
*.sqlite3 *.sqlite3
backups/
############################ ############################
+31
View File
@@ -163,6 +163,37 @@ curl -H "Authorization: Bearer <token>" \
-o dataset.jsonl -o dataset.jsonl
``` ```
## Commentaires fédérés (Mastodon / bokante.o-k-i.net)
Chaque parole publiée peut obtenir un statut miroir sur l'instance Mastodon de
l'organisation, [bokante.o-k-i.net](https://bokante.o-k-i.net), et les réponses reçues
sur ce statut sont importées comme commentaires. Voir le RFC dédié pour le détail de la
conception (`RFC-commentaires-activitypub-2026-07-04.md`, à la racine du dossier
`PAWOL.NU`).
**Variables d'environnement :**
| Variable | Obligatoire | Description |
|---|---|---|
| `BOKANTE_ACCESS_TOKEN` | Oui, pour activer la fonctionnalité | Jeton d'application Mastodon (scopes `write:statuses`, `read:statuses`) d'un compte bot dédié sur bokante.o-k-i.net |
| `BOKANTE_INSTANCE_URL` | Non | Instance Mastodon cible (défaut : `https://bokante.o-k-i.net`) |
| `BOKANTE_BACKFILL_CRON` | Non | Règle cron du backfill du catalogue existant (défaut : `0 * * * *`, une parole/heure) |
Sans `BOKANTE_ACCESS_TOKEN`, toute la fonctionnalité (publication du miroir, import des
réponses, backfill) est un no-op silencieux — comme les intégrations Telegram/Revolt.
**Comment obtenir le jeton :** créer un compte bot dédié sur bokante.o-k-i.net, puis dans
*Préférences → Développement → Nouvelle application*, cocher uniquement `write:statuses`
et `read:statuses`. Le jeton d'accès est affiché directement sur la page de l'application
créée.
**Tâches planifiées (cron) :**
- Publication du miroir : déclenchée à chaque publication d'une parole (pas de cron).
- Import des réponses : toutes les 20 minutes.
- Backfill du catalogue existant : une parole par exécution (la plus ancienne sans
miroir en premier), au rythme défini par `BOKANTE_BACKFILL_CRON`. S'arrête de
lui-même une fois le catalogue rattrapé.
## License ## License
Copyright (C) 2024 Cédric Famibelle-Pronzola & ORGANISATION KA INTERNATIONALE (OKI) Copyright (C) 2024 Cédric Famibelle-Pronzola & ORGANISATION KA INTERNATIONALE (OKI)
-29
View File
@@ -1,29 +0,0 @@
{
"collectionName": "components_store_stores",
"info": {
"name": "Album",
"icon": "music",
"description": ""
},
"options": {},
"attributes": {
"url": {
"type": "string",
"required": true
},
"boutik": {
"type": "enumeration",
"enum": [
"Tidal",
"Spotify",
"Deezer",
"Qobuz",
"Youtubemusic",
"Applemusic",
"Amazon",
"Soundcloud"
],
"required": true
}
}
}
-26
View File
@@ -1,26 +0,0 @@
{
"collectionName": "components_trad_traductions",
"info": {
"name": "traductions",
"icon": "spell-check",
"description": ""
},
"options": {},
"attributes": {
"francais": {
"type": "richtext"
},
"english": {
"type": "richtext"
},
"espagnol": {
"type": "richtext"
},
"deutsch": {
"type": "richtext"
},
"italiano": {
"type": "richtext"
}
}
}
-28
View File
@@ -1,28 +0,0 @@
{
"collectionName": "components_url_liens",
"info": {
"name": "liens",
"icon": "link",
"description": ""
},
"options": {},
"attributes": {
"url": {
"type": "string",
"required": true
},
"sit": {
"type": "enumeration",
"enum": [
"Youtube",
"Peertube",
"Dailymotion",
"Vimeo",
"File",
"Lbry",
"Rumble"
],
"required": true
}
}
}
+2 -2
View File
@@ -4,10 +4,10 @@ const forgotPasswordTemplate = require('./email-templates/forgot-password');
module.exports = ({ env }) => ({ module.exports = ({ env }) => ({
url: env('STRAPI_ADMIN_URL', '/admin'), url: env('STRAPI_ADMIN_URL', '/admin'),
apiToken: { apiToken: {
salt: env('API_TOKEN_SALT', 'd9b0df66ff97a666027e665707b4e3e7'), salt: env('API_TOKEN_SALT'),
}, },
auth: { auth: {
secret: env('ADMIN_JWT_SECRET', '77b2c87dbab4e1697bec244226fbd1b3'), secret: env('ADMIN_JWT_SECRET'),
}, },
forgotPassword: { forgotPassword: {
from: env('SMTP_FROM'), from: env('SMTP_FROM'),
+50 -1
View File
@@ -1,9 +1,58 @@
const path = require('path');
const {backupDatabase} = require('../src/utils/backup-database');
const {importBokanteComments} = require('../src/utils/import-bokante-comments');
const {backfillBokanteMirror} = require('../src/utils/backfill-bokante-mirrors');
module.exports = { module.exports = {
myJob: { myJob: {
task: ({ strapi }) => {console.log('TODO > save db')}, task: ({ strapi }) => {
const dbPath = path.join(__dirname, '..', process.env.DATABASE_FILENAME || '.tmp/data.db');
const backupsDir = path.join(__dirname, '..', 'backups');
const backupPath = backupDatabase({dbPath, backupsDir});
if (backupPath) {
strapi.log.info(`Sauvegarde de la base effectuée : ${backupPath}`);
} else {
strapi.log.warn(`Sauvegarde de la base ignorée : fichier introuvable (${dbPath})`);
}
},
options: { options: {
rule: '0 0 * * SUN', rule: '0 0 * * SUN',
tz: 'Indian/Reunion', tz: 'Indian/Reunion',
}, },
}, },
importBokanteComments: {
task: async ({ strapi }) => {
if (!process.env.BOKANTE_ACCESS_TOKEN) {
return;
}
const {imported} = await importBokanteComments({strapi});
if (imported > 0) {
strapi.log.info(`Import bokante : ${imported} commentaire(s) importé(s).`);
}
},
options: {
rule: '*/20 * * * *',
tz: 'Indian/Reunion',
},
},
backfillBokanteMirror: {
task: async ({ strapi }) => {
if (!process.env.BOKANTE_ACCESS_TOKEN) {
return;
}
const {backfilled, slug} = await backfillBokanteMirror({strapi});
if (backfilled) {
strapi.log.info(`Backfill bokante : parole "${slug}" publiée.`);
}
},
options: {
rule: process.env.BOKANTE_BACKFILL_CRON || '0 * * * *',
tz: 'Indian/Reunion',
},
},
}; };
+1 -1
View File
@@ -1,4 +1,4 @@
const subject = `Réinitialiser le mot de passe`; const subject = 'Réinitialiser le mot de passe';
const html = `<p>Bèl bonjou <%= user.firstname %></p> const html = `<p>Bèl bonjou <%= user.firstname %></p>
<p>Nous avons appris que tu a perdu ton mot de passe. Nous en sommes désolés ! </p> <p>Nous avons appris que tu a perdu ton mot de passe. Nous en sommes désolés ! </p>
+1 -20
View File
@@ -16,23 +16,4 @@ module.exports = ({env}) => ({
defaultReplyTo: env('SMTP_REPLY_TO'), defaultReplyTo: env('SMTP_REPLY_TO'),
}, },
}, },
'rest-cache': { });
config: {
provider: {
name: 'memory',
options: {
max: 32767,
maxAge: 3600
}
},
strategy: {
contentTypes: [
'api::artiste.artiste',
'api::parole.parole'
],
debug: true,
hitpass: false
}
}
},
})
+1 -1
View File
@@ -1,4 +1,4 @@
const cronTasks = require("./cron-task"); const cronTasks = require('./cron-task');
module.exports = ({ env }) => ({ module.exports = ({ env }) => ({
host: env('HOST', '0.0.0.0'), host: env('HOST', '0.0.0.0'),
View File
@@ -1,43 +0,0 @@
{
"openapi": "3.0.0",
"info": {
"version": "1.0.0",
"title": "#OKi API Dokiman",
"description": "",
"termsOfService": null,
"contact": {
"name": "#OKi",
"email": "kontak@o-k-i.net",
"url": "https://o-k-i.net"
},
"license": null
},
"x-strapi-config": {
"path": "/dokiman",
"showGeneratedFiles": true,
"pluginsForWhichToGenerateDoc": []
},
"servers": [
{
"url": "https://api.o-k-i.net",
"description": "Production server"
},
{
"url": "http://localhost:1337",
"description": "Development server"
},
{
"url": "http://localhost:1337",
"description": "Staging server"
}
],
"externalDocs": null,
"security": [
{
"bearerAuth": []
}
],
"paths": {},
"tags": [],
"components": {}
}
File diff suppressed because it is too large Load Diff
File diff suppressed because one or more lines are too long
-136
View File
@@ -1,136 +0,0 @@
<!DOCTYPE html><html><head>
<title>Login - Documentation</title>
<link href="https://fonts.googleapis.com/css?family=Lato:400,700" rel="stylesheet">
<style>
html {
font-size: 62.5%;
height: 100%;
margin: 0;
padding: 0;
}
body {
height: 100%;
margin: 0;
background-color: #ffffff;
font-family: 'Lato';
font-size: 1.4rem;
font-weight: 400;
text-rendering: optimizeLegibility;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
}
.login {
height: 100%;
background-color: #F6F9FC;
}
.login .login-form {
height: calc(100% - 70px);
padding: 68px 0 0;
text-align: center;
}
.login .login-form form {
position: relative;
max-width: 460px;
padding: 26px 30px;
margin: 55px auto 0;
background-color: #ffffff;
border-radius: 3px;
box-shadow: 0px 2px 4px rgba(91, 107, 174, .15);
text-align: center;
}
.login .login-form form:before {
position: absolute;
content: '';
top: 0px;
left: 0;
display: inline-block;
width: 100%;
height: 2px;
background-color: #2B66CC;
}
.login .login-form form .error {
display: block;
color: #FF4E00;
padding-bottom: 20px;
}
.login .login-form .sub-title {
margin-top: 35px;
font-size: 1.6rem;
font-weight: 400;
}
.login .login-form .logo{
max-height: 40px;
}
.login .login-form form label {
display: block;
margin-bottom: 18px;
width: 100%;
text-align: left;
font-weight: 600;
}
.login .login-form form input {
outline: none;
width: calc(100% - 30px);
height: 36px;
padding: 0 15px;
border: 1px solid #ECECEC;
border-radius: 2px;
margin-bottom: 20px;
line-height: 36px;
text-align: left;
}
.login .login-form form input[type=submit] {
cursor: pointer;
display: inline-block;
width: auto;
margin: 12px auto 0;
padding: 0 75px;
background: transparent;
border-radius: 36px;
border: 1px solid #2B66CC;
color: #2B66CC;
text-transform: uppercase;
font-size: 1.4rem;
font-weight: 700;
transition: all .2s ease-out;
}
.login .login-form form input[type=submit]:hover {
background: #2B66CC;
color: #ffffff;
}
</style>
</head>
<body>
<div class="login">
<section class="login-form">
<div class="container">
<div class="row">
<div class="col-lg-6 col-lg-offset-3 col-md-12">
<img alt="Strapi logo" class="logo" src="https://strapi.io/assets/images/logo_login.png">
<h2 class="sub-title">Enter the password to access the documentation.</h2>
<form method="post" action="/dokiman/login">
<span class="error">Wrong password...</span>
<label>Password</label>
<input type="password" name="password" placeholder="•••••••••">
<input type="submit" value="Login">
</form>
</div>
</div>
</div>
</section>
</div>
</body></html>
@@ -1,3 +0,0 @@
module.exports = {
jwtSecret: process.env.JWT_SECRET || '3527426b-d513-44a5-b4c8-ee16494bab0d'
};
@@ -1,78 +0,0 @@
{
"kind": "collectionType",
"collectionName": "users-permissions_user",
"info": {
"name": "user",
"description": ""
},
"options": {
"draftAndPublish": false,
"timestamps": true,
"privateAttributes": [
"createdAt",
"updatedAt",
"created_at",
"updated_at"
]
},
"attributes": {
"username": {
"type": "string",
"minLength": 3,
"unique": true,
"configurable": false,
"required": true
},
"email": {
"type": "email",
"minLength": 6,
"configurable": false,
"required": true,
"private": true
},
"provider": {
"type": "string",
"configurable": false,
"private": true
},
"password": {
"type": "password",
"minLength": 6,
"configurable": false,
"private": true
},
"resetPasswordToken": {
"type": "string",
"configurable": false,
"private": true
},
"confirmationToken": {
"type": "string",
"configurable": false,
"private": true
},
"confirmed": {
"type": "boolean",
"default": false,
"configurable": false,
"private": true
},
"blocked": {
"type": "boolean",
"default": false,
"configurable": false,
"private": true
},
"role": {
"model": "role",
"via": "users",
"plugin": "users-permissions",
"configurable": false,
"private": true
},
"canAutoTranslate": {
"type": "boolean",
"private": false
}
}
}
+8 -2
View File
@@ -17,13 +17,19 @@
"dev": "strapi develop", "dev": "strapi develop",
"start": "strapi start", "start": "strapi start",
"build": "strapi build", "build": "strapi build",
"strapi": "strapi" "strapi": "strapi",
"test": "vitest run",
"lint": "eslint ."
},
"devDependencies": {
"eslint": "^8.7.0",
"vitest": "^4.1.9"
}, },
"devDependencies": {},
"dependencies": { "dependencies": {
"@strapi/plugin-users-permissions": "5.44.0", "@strapi/plugin-users-permissions": "5.44.0",
"@strapi/provider-email-nodemailer": "^4.26.1", "@strapi/provider-email-nodemailer": "^4.26.1",
"@strapi/strapi": "5.44.0", "@strapi/strapi": "5.44.0",
"axios": "1.15.1",
"better-sqlite3": "^12.9.0", "better-sqlite3": "^12.9.0",
"diff": "^5.1.0", "diff": "^5.1.0",
"react": "^18.0.0", "react": "^18.0.0",
@@ -0,0 +1,66 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
async function loadLifecycles(strapiMock) {
vi.resetModules();
global.strapi = strapiMock;
const mod = await import('../lifecycles.js');
return mod;
}
describe('artiste afterUpdate — cascade de renommage des slugs', () => {
afterEach(() => {
delete global.strapi;
});
it('renomme le slug des paroles de l\'artiste quand son alias change', async () => {
const artisteFindOne = vi.fn(async () => ({
id: 5,
paroles: [{id: 10}, {id: 11}]
}));
const paroleFindMany = vi.fn(async () => [
{id: 10, titre: 'Titre 1', slug: 'ancien-alias-titre-1', artistes: [{alias: 'nouvel-alias'}]},
{id: 11, titre: 'Titre 2', slug: 'nouvel-alias-titre-2', artistes: [{alias: 'nouvel-alias'}]}
]);
const paroleUpdate = vi.fn(async () => {});
const strapiMock = {
db: {
query: vi.fn(uid => {
if (uid === 'api::artiste.artiste') return {findOne: artisteFindOne};
if (uid === 'api::parole.parole') return {findMany: paroleFindMany, update: paroleUpdate};
throw new Error(`unexpected uid: ${uid}`);
})
}
};
const {afterUpdate} = await loadLifecycles(strapiMock);
await afterUpdate({result: {id: 5}});
expect(artisteFindOne).toHaveBeenCalledWith({where: {id: 5}, populate: ['paroles']});
expect(paroleFindMany).toHaveBeenCalledWith({where: {id: {$in: [10, 11]}}, populate: ['artistes']});
expect(paroleUpdate).toHaveBeenCalledTimes(1);
expect(paroleUpdate).toHaveBeenCalledWith({where: {id: 10}, data: {slug: 'nouvel-alias-titre-1'}});
});
it('ne fait rien quand l\'artiste n\'a aucune parole', async () => {
const artisteFindOne = vi.fn(async () => ({id: 5, paroles: []}));
const paroleFindMany = vi.fn();
const strapiMock = {
db: {
query: vi.fn(uid => {
if (uid === 'api::artiste.artiste') return {findOne: artisteFindOne};
if (uid === 'api::parole.parole') return {findMany: paroleFindMany};
throw new Error(`unexpected uid: ${uid}`);
})
}
};
const {afterUpdate} = await loadLifecycles(strapiMock);
await afterUpdate({result: {id: 5}});
expect(paroleFindMany).not.toHaveBeenCalled();
});
});
@@ -1,54 +1,60 @@
'use strict'; 'use strict';
const { ApplicationError } = require("@strapi/utils").errors const { ApplicationError } = require('@strapi/utils').errors;
const slugify = require('slugify') const slugify = require('slugify');
const jwennTeksEpiId = async data => { const jwennTeksEpiId = async ids => {
const paroles = await strapi.db.query('api::parole.parole').find({id_in: data}) const paroles = await strapi.db.query('api::parole.parole').findMany({
return paroles where: {id: {$in: ids}},
} populate: ['artistes']
});
return paroles;
};
const jwennAwtisEpiId = async id => { const jwennAwtisEpiId = async id => {
const artiste = await strapi.db.query('api::artiste.artiste').findOne({id}) const artiste = await strapi.db.query('api::artiste.artiste').findOne({
return artiste where: {id},
} populate: ['paroles']
});
return artiste;
};
const validateArtiste = alias => { const validateArtiste = alias => {
if (!alias || alias.trim().length === 0) { if (!alias || alias.trim().length === 0) {
throw new ApplicationError('Champ obligatoire. Veuillez choisir un alias.'); throw new ApplicationError('Champ obligatoire. Veuillez choisir un alias.');
} }
} };
module.exports = { module.exports = {
beforeUpdate: async event => { beforeUpdate: async event => {
let {data} = event.params let {data} = event.params;
if(!data.publishedAt) { if(!data.publishedAt) {
validateArtiste(data.alias) validateArtiste(data.alias);
if (!data.slug || data.slug !== slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g})) { if (!data.slug || data.slug !== slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g})) {
data.slug = slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g}) data.slug = slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g});
} }
} }
}, },
beforeCreate: async event => { beforeCreate: async event => {
let {data} = event.params let {data} = event.params;
validateArtiste(data.alias) validateArtiste(data.alias);
data.slug = slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g}) data.slug = slugify(data.alias, {lower: true, remove: /[*#+~.()'"!:@]/g});
}, },
afterUpdate: async event => { afterUpdate: async event => {
let {data} = event.params const {result} = event;
const {id} = data const artiste = await jwennAwtisEpiId(result.id);
const artiste = await jwennAwtisEpiId(id)
if (artiste.paroles && artiste.paroles.length >= 1) { if (artiste.paroles && artiste.paroles.length >= 1) {
const paroles = await jwennTeksEpiId(artiste.paroles) const paroleIds = artiste.paroles.map(({id}) => id);
Promise.all(paroles.map(async t => { const paroles = await jwennTeksEpiId(paroleIds);
const {id, titre, slug, artiste} = t await Promise.all(paroles.map(async t => {
const alias = artiste.map(a => a.alias).join('-') const {id, titre, slug, artistes} = t;
const slugUpdated = slugify(`${alias}-${titre}`, {lower: true, remove: /[*#+~.()'"!:@]/g}) const alias = artistes.map(a => a.alias).join('-');
const slugUpdated = slugify(`${alias}-${titre}`, {lower: true, remove: /[*#+~.()'"!:@]/g});
if (slug !== slugUpdated) { if (slug !== slugUpdated) {
await strapi.db.query('api::parole.parole').update({ await strapi.db.query('api::parole.parole').update({
@@ -56,9 +62,9 @@ module.exports = {
data: { data: {
slug: slugUpdated slug: slugUpdated
} }
}) });
} }
})) }));
} }
} }
} };
@@ -0,0 +1,91 @@
import {describe, it, expect, vi} from 'vitest';
const {default: createController} = await import('../artiste.js');
function buildStrapi({dbUser, existingArtiste = null}) {
const dbQuery = {
findOne: vi.fn(async () => existingArtiste)
};
const artisteDocuments = {
create: vi.fn(async ({data}) => ({id: 42, ...data}))
};
const userDocuments = {
findOne: vi.fn(async () => dbUser)
};
const strapi = {
contentType: vi.fn(() => ({uid: 'api::artiste.artiste', kind: 'collectionType'})),
db: {
query: vi.fn(() => dbQuery)
},
documents: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return userDocuments;
if (uid === 'api::artiste.artiste') return artisteDocuments;
throw new Error(`unexpected uid: ${uid}`);
})
};
return {strapi, artisteDocuments};
}
function buildCtx(data) {
return {
request: {
body: {data},
header: {authorization: 'Bearer faketoken'}
},
badRequest: vi.fn(),
notFound: vi.fn()
};
}
const dbUser = {id: 1, documentId: 'user-doc-1', username: 'foo', email: 'foo@bar.com'};
function buildData(overrides = {}) {
return {
alias: 'Test Artist',
user: {...dbUser},
...overrides
};
}
describe('artiste.create', () => {
it('crée l\'artiste quand le user existe et que l\'alias est nouveau', async () => {
const {strapi, artisteDocuments} = buildStrapi({dbUser});
const controller = createController({strapi});
const ctx = buildCtx(buildData());
await controller.create(ctx);
expect(artisteDocuments.create).toHaveBeenCalled();
});
it('refuse sans planter quand data.user est absent', async () => {
const {strapi} = buildStrapi({dbUser});
const controller = createController({strapi});
const ctx = buildCtx(buildData({user: undefined}));
await controller.create(ctx);
expect(ctx.badRequest).toHaveBeenCalled();
expect(strapi.documents).not.toHaveBeenCalled();
});
it('ignore les champs non autorisés du payload (mass assignment)', async () => {
const {strapi, artisteDocuments} = buildStrapi({dbUser});
const controller = createController({strapi});
const ctx = buildCtx(buildData({
isExclusiveArtist: true,
userAdmin: {id: 999}
}));
await controller.create(ctx);
expect(artisteDocuments.create).toHaveBeenCalledWith({
data: {
alias: 'Test Artist',
user: dbUser.id
}
});
});
});
+17 -26
View File
@@ -1,57 +1,48 @@
'use strict'; 'use strict';
const { createCoreController } = require('@strapi/strapi').factories; const { createCoreController } = require('@strapi/strapi').factories;
const slugify = require('slugify') const slugify = require('slugify');
const getSlug = text => { const getSlug = text => {
return slugify(text, {lower: true, remove: /[*#+~.()'"!:@]/g}) return slugify(text, {lower: true, remove: /[*#+~.()'"!:@]/g});
} };
module.exports = createCoreController('api::artiste.artiste', ({strapi}) => ({ module.exports = createCoreController('api::artiste.artiste', ({strapi}) => ({
async create(ctx) { async create(ctx) {
const {body} = ctx.request const {body} = ctx.request;
let {data} = body let {data} = body;
if (ctx.request && ctx.request.header && ctx.request.header.authorization) { if (!data?.user?.documentId) {
try { return ctx.badRequest('Informations manquantes.');
const {id} = await strapi.plugins[
'users-permissions'
].services.jwt.getToken(ctx)
if (id !== data.user.id) {
throw new UnauthorizedError('Opération non autorisée')
}
} catch (err) {
throw new UnauthorizedError(ctx, err, 'Opération non autorisée')
}
} }
const user = await strapi.documents('plugin::users-permissions.user').findOne({ const user = await strapi.documents('plugin::users-permissions.user').findOne({
documentId: body.data.user.documentId documentId: body.data.user.documentId
}) });
if (!user) { if (!user) {
throw new NotFoundError('Utilisateur introuvable.') return ctx.notFound('Utilisateur introuvable.');
} }
if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) { if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) {
ctx.badRequest('Informations non valides.') return ctx.badRequest('Informations non valides.');
} }
const artiste = await strapi.db.query('api::artiste.artiste').findOne({ const artiste = await strapi.db.query('api::artiste.artiste').findOne({
where: {slug: getSlug(data.alias)} where: {slug: getSlug(data.alias)}
}) });
if (artiste) { if (artiste) {
return artiste return artiste;
} else { } else {
const newArtiste = await strapi.documents('api::artiste.artiste').create({ const newArtiste = await strapi.documents('api::artiste.artiste').create({
data: { data: {
...data alias: data.alias,
user: user.id
} }
}) });
return newArtiste return newArtiste;
} }
} }
})) }));
+13 -1
View File
@@ -2,4 +2,16 @@
const { createCoreRouter } = require('@strapi/strapi').factories; const { createCoreRouter } = require('@strapi/strapi').factories;
module.exports = createCoreRouter('api::artiste.artiste') module.exports = createCoreRouter('api::artiste.artiste', {
config: {
create: {
policies: ['global::is-payload-owner']
},
update: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::artiste.artiste'}}]
},
delete: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::artiste.artiste'}}]
}
}
});
@@ -0,0 +1,59 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
async function loadLifecycles(strapiMock) {
vi.resetModules();
global.strapi = strapiMock;
const mod = await import('../lifecycles.js');
return mod;
}
describe('commentaire afterCreate — notification email', () => {
afterEach(() => {
delete global.strapi;
});
it('envoie le contenu en texte brut, jamais comme HTML non échappé', async () => {
const emailSend = vi.fn();
const strapiMock = {
db: {
query: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return {findOne: vi.fn(async () => ({id: 1, username: 'foo'}))};
if (uid === 'api::parole.parole') return {findOne: vi.fn(async () => ({id: 7, titre: 'Mon titre'}))};
throw new Error(`unexpected uid: ${uid}`);
})
},
plugins: {email: {services: {email: {send: emailSend}}}}
};
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate({params: {data: {user: {connect: [{id: 1}]}, parole: {connect: [{id: 7}]}, contenu: '<img src=x onerror=alert(1)>'}}});
expect(emailSend).toHaveBeenCalledTimes(1);
const [payload] = emailSend.mock.calls[0];
expect(payload.text).toBe('<img src=x onerror=alert(1)>');
expect(payload.html).toBeUndefined();
});
it('extrait l\'id de la relation quelle que soit sa forme (connect, set, id brut)', async () => {
const paroleFindOne = vi.fn(async ({where}) => ({id: where.id, titre: 'Mon titre'}));
const strapiMock = {
db: {
query: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return {findOne: vi.fn(async () => null)};
if (uid === 'api::parole.parole') return {findOne: paroleFindOne};
throw new Error(`unexpected uid: ${uid}`);
})
},
plugins: {email: {services: {email: {send: vi.fn()}}}}
};
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate({params: {data: {parole: {set: [{id: 7}]}, contenu: 'ok'}}});
expect(paroleFindOne).toHaveBeenCalledWith({where: {id: 7}});
await afterCreate({params: {data: {parole: 7, contenu: 'ok'}}});
expect(paroleFindOne).toHaveBeenCalledWith({where: {id: 7}});
});
});
@@ -1,57 +1,68 @@
'use strict'; 'use strict';
const { ApplicationError, NotFoundError } = require("@strapi/utils").errors const { ApplicationError, NotFoundError } = require('@strapi/utils').errors;
// Le Document Service transforme les relations en { connect: [{id}] } ou
// { set: [{id}] } avant que les hooks bas niveau (beforeCreate/afterCreate)
// ne reçoivent `data` : un id brut n'est plus systématiquement garanti ici.
const idRelasyonAn = valè => {
if (valè == null || typeof valè !== 'object') {
return valè;
}
return valè.connect?.[0]?.id ?? valè.set?.[0]?.id ?? null;
};
const jwennUserEpiId = async userId => { const jwennUserEpiId = async userId => {
if (!userId) { if (!userId) {
return null return null;
} }
const user = await strapi.db.query('plugin::users-permissions.user').findOne({ const user = await strapi.db.query('plugin::users-permissions.user').findOne({
where: {id: userId} where: {id: userId}
}) });
return user return user;
} };
const jwennParoleEpiId = async paroleId => { const jwennParoleEpiId = async paroleId => {
if (!paroleId) { if (!paroleId) {
return null return null;
} }
const parole = await strapi.db.query('api::parole.parole').findOne({ const parole = await strapi.db.query('api::parole.parole').findOne({
where: {id: paroleId} where: {id: paroleId}
}) });
return parole return parole;
} };
const validateCommentaire = data => { const validateCommentaire = data => {
if (!data.contenu && !data.datePublication) { if (!data.contenu && !data.datePublication) {
throw new ApplicationError('Mauvaise requête, contenu et datePublication sont obligatoires') throw new ApplicationError('Mauvaise requête, contenu et datePublication sont obligatoires');
} }
if (!data.contenu || data.contenu.trim().length === 0) { if (!data.contenu || data.contenu.trim().length === 0) {
throw new ApplicationError('Champ obligatoire. Veuillez renseigner le contenu du commentaire.') throw new ApplicationError('Champ obligatoire. Veuillez renseigner le contenu du commentaire.');
} }
if (data.contenu.trim().length > 500) { if (data.contenu.trim().length > 500) {
throw new ApplicationError('Le commentaire doit contenir 500 caractères maximum.') throw new ApplicationError('Le commentaire doit contenir 500 caractères maximum.');
} }
} };
module.exports = { module.exports = {
beforeCreate: async event => { beforeCreate: async event => {
const {data} = event.params const {data} = event.params;
validateCommentaire(data) validateCommentaire(data);
}, },
afterCreate: async event => { afterCreate: async event => {
const {data, result} = event.params const {data} = event.params;
const user = await jwennUserEpiId(data.user) const user = await jwennUserEpiId(idRelasyonAn(data.user));
const parole = await jwennParoleEpiId(data.parole) const parole = await jwennParoleEpiId(idRelasyonAn(data.parole));
if (!parole) { if (!parole) {
throw new NotFoundError('Texte introuvable.') throw new NotFoundError('Texte introuvable.');
} }
if (user) { if (user) {
@@ -59,8 +70,8 @@ module.exports = {
from: process.env.SMTP_FROM, from: process.env.SMTP_FROM,
to: process.env.SMTP_SEND_TO, to: process.env.SMTP_SEND_TO,
subject: `Commentaire de ${user.username} sur "${parole.titre}"`, subject: `Commentaire de ${user.username} sur "${parole.titre}"`,
html: data.contenu text: data.contenu
}) });
} }
} }
}; };
@@ -27,8 +27,34 @@
}, },
"parole": { "parole": {
"type": "relation", "type": "relation",
"relation": "oneToOne", "relation": "manyToOne",
"target": "api::parole.parole" "target": "api::parole.parole",
"inversedBy": "commentaires"
},
"origine": {
"type": "enumeration",
"enum": ["local", "activitypub"],
"default": "local",
"required": true
},
"auteurNom": {
"type": "string"
},
"auteurHandle": {
"type": "string"
},
"auteurAvatarUrl": {
"type": "string"
},
"auteurProfilUrl": {
"type": "string"
},
"remoteId": {
"type": "string",
"unique": true
},
"remoteUrl": {
"type": "string"
} }
} }
} }
@@ -0,0 +1,119 @@
import {describe, it, expect, vi} from 'vitest';
const {default: createController} = await import('../commentaire.js');
const dbUser = {id: 1, username: 'foo', email: 'foo@bar.com'};
const dbParole = {id: 7, documentId: 'parole-doc-7'};
function buildStrapi({existingParole = dbParole} = {}) {
const commentaireDocuments = {
create: vi.fn(async ({data}) => ({id: 99, ...data}))
};
const paroleDocuments = {
update: vi.fn(async () => {})
};
const userDbQuery = {
findOne: vi.fn(async ({where}) => (where.id === dbUser.id ? dbUser : null))
};
const paroleDbQuery = {
findOne: vi.fn(async ({where}) => (where.id === existingParole?.id ? existingParole : null))
};
const strapi = {
contentType: vi.fn(() => ({uid: 'api::commentaire.commentaire', kind: 'collectionType'})),
db: {
query: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return userDbQuery;
if (uid === 'api::parole.parole') return paroleDbQuery;
throw new Error(`unexpected uid: ${uid}`);
})
},
documents: vi.fn(uid => {
if (uid === 'api::commentaire.commentaire') return commentaireDocuments;
if (uid === 'api::parole.parole') return paroleDocuments;
throw new Error(`unexpected uid: ${uid}`);
})
};
return {strapi, commentaireDocuments, paroleDocuments, userDbQuery, paroleDbQuery};
}
function buildCtx(data) {
return {
request: {
body: {data},
header: {authorization: 'Bearer faketoken'}
}
};
}
function buildData(overrides = {}) {
return {
contenu: 'Un commentaire',
datePublication: '2026-07-04',
parole: dbParole.id,
user: {...dbUser},
...overrides
};
}
describe('commentaire.create', () => {
it('retrouve la parole par son id (pas par le documentId du user) et l\'associe correctement', async () => {
const {strapi, commentaireDocuments, paroleDocuments, paroleDbQuery} = buildStrapi();
const controller = createController({strapi});
const ctx = buildCtx(buildData());
await controller.create(ctx);
expect(paroleDbQuery.findOne).toHaveBeenCalledWith({where: {id: dbParole.id}});
expect(commentaireDocuments.create).toHaveBeenCalled();
expect(paroleDocuments.update).toHaveBeenCalledWith({
documentId: dbParole.documentId,
data: {commentaires: {connect: [99]}}
});
});
it('rejette quand la parole ciblée n\'existe pas', async () => {
const {strapi, commentaireDocuments} = buildStrapi({existingParole: null});
const controller = createController({strapi});
const ctx = buildCtx(buildData());
await expect(controller.create(ctx)).rejects.toThrow('Texte introuvable.');
expect(commentaireDocuments.create).not.toHaveBeenCalled();
});
it('refuse sans planter quand data.user est absent', async () => {
const {strapi, userDbQuery} = buildStrapi();
const controller = createController({strapi});
const ctx = buildCtx(buildData({user: undefined}));
await expect(controller.create(ctx)).rejects.toThrow('Informations manquantes.');
expect(userDbQuery.findOne).not.toHaveBeenCalled();
});
it('refuse sans planter quand data.parole est absent', async () => {
const {strapi, paroleDbQuery} = buildStrapi();
const controller = createController({strapi});
const ctx = buildCtx(buildData({parole: undefined}));
await expect(controller.create(ctx)).rejects.toThrow('Informations manquantes.');
expect(paroleDbQuery.findOne).not.toHaveBeenCalled();
});
it('ignore les champs non autorisés du payload (mass assignment)', async () => {
const {strapi, commentaireDocuments} = buildStrapi();
const controller = createController({strapi});
const ctx = buildCtx(buildData({publishedAt: '2020-01-01'}));
await controller.create(ctx);
expect(commentaireDocuments.create).toHaveBeenCalledWith({
data: {
contenu: 'Un commentaire',
datePublication: '2026-07-04',
user: dbUser.id,
parole: dbParole.id
}
});
});
});
+24 -33
View File
@@ -1,63 +1,54 @@
'use strict'; 'use strict';
const { createCoreController } = require('@strapi/strapi').factories; const { createCoreController } = require('@strapi/strapi').factories;
const { ApplicationError, NotFoundError, UnauthorizedError } = require("@strapi/utils").errors const { ApplicationError, NotFoundError } = require('@strapi/utils').errors;
module.exports = createCoreController('api::commentaire.commentaire', ({strapi}) => ({ module.exports = createCoreController('api::commentaire.commentaire', ({strapi}) => ({
async create(ctx) { async create(ctx) {
const {body} = ctx.request const {body} = ctx.request;
let {data} = body let {data} = body;
if (ctx.request && ctx.request.header && ctx.request.header.authorization) { if (!data?.user?.id || !data?.parole) {
try { throw new ApplicationError('Informations manquantes.');
const {id} = await strapi.plugins[ }
'users-permissions'
].services.jwt.getToken(ctx)
if (id !== data.user.id) { const user = await strapi.db.query('plugin::users-permissions.user').findOne({
throw new UnauthorizedError('Opération non autorisée') where: {id: data.user.id}
} });
} catch (err) {
throw new UnauthorizedError(ctx, err, 'Opération non autorisée')
}
}
const user = await strapi.documents('plugin::users-permissions.user').findOne({
documentId: data.user.documentId
})
if (!user) { if (!user) {
throw new NotFoundError('Utilisateur introuvable.') throw new NotFoundError('Utilisateur introuvable.');
} }
if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) { if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) {
throw new ApplicationError('Informations non valides.') throw new ApplicationError('Informations non valides.');
} }
data.user = user.id const parole = await strapi.db.query('api::parole.parole').findOne({
where: {id: data.parole}
const parole = await strapi.documents('api::parole.parole').findOne({ });
documentId: user.documentId,
fields: ['id']
})
if (!parole) { if (!parole) {
throw new NotFoundError('Texte introuvable.') throw new NotFoundError('Texte introuvable.');
} }
const newCommentaire = await strapi.documents('api::commentaire.commentaire').create({ const newCommentaire = await strapi.documents('api::commentaire.commentaire').create({
data: { data: {
...data contenu: data.contenu,
datePublication: data.datePublication,
user: user.id,
parole: parole.id
} }
}) });
await strapi.documents('api::parole.parole').update({ await strapi.documents('api::parole.parole').update({
documentId: user.documentId, documentId: parole.documentId,
data: { data: {
commentaires: [newCommentaire.id] commentaires: {connect: [newCommentaire.id]}
} }
}) });
return newCommentaire; return newCommentaire;
} }
})) }));
+13 -1
View File
@@ -2,4 +2,16 @@
const { createCoreRouter } = require('@strapi/strapi').factories; const { createCoreRouter } = require('@strapi/strapi').factories;
module.exports = createCoreRouter('api::commentaire.commentaire') module.exports = createCoreRouter('api::commentaire.commentaire', {
config: {
create: {
policies: ['global::is-payload-owner']
},
update: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::commentaire.commentaire'}}]
},
delete: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::commentaire.commentaire'}}]
}
}
});
@@ -0,0 +1,285 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
async function loadLifecycles(strapiMock) {
vi.resetModules();
global.strapi = strapiMock;
const mod = await import('../lifecycles.js');
return mod;
}
describe('afterCreate — notification au soumetteur', () => {
afterEach(() => {
delete global.strapi;
});
it('recherche le user par id (pas par un champ "user" inexistant) et envoie le mail', async () => {
const userFindOne = vi.fn(async ({where}) => {
if (where.id === 5) return {id: 5, username: 'foo', email: 'foo@bar.com'};
return null;
});
const emailSend = vi.fn();
const strapiMock = {
db: {
query: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return {findOne: userFindOne};
return {findOne: vi.fn(async () => null)};
})
},
plugins: {
email: {services: {email: {send: emailSend}}}
}
};
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate({params: {data: {titre: 'Titre', user: {id: 5}}}});
expect(userFindOne).toHaveBeenCalledWith({where: {id: 5}});
expect(emailSend).toHaveBeenCalled();
});
});
describe('beforeUpdate — notifications Telegram/Revolt', () => {
const originalEnv = {...process.env};
const axios = require('axios');
const originalPost = axios.post;
function buildStrapi(previous) {
const dbQuery = {
findOne: vi.fn(async () => previous),
updateMany: vi.fn()
};
return {
db: {query: vi.fn(() => dbQuery)},
plugins: {email: {services: {email: {send: vi.fn()}}}},
log: {error: vi.fn()}
};
}
function buildEvent(overrides = {}) {
return {
state: {},
params: {
data: {documentId: 'doc-1', publishedAt: '2026-07-04T00:00:00.000Z', ...overrides}
}
};
}
afterEach(() => {
process.env = {...originalEnv};
axios.post = originalPost;
delete global.strapi;
});
it('n\'interrompt pas la publication quand Telegram échoue, et encode le message', async () => {
process.env.TELEGRAM_API_TOKEN = 'fake-token';
process.env.TELEGRAM_CHAN_ID = 'fake-chan';
delete process.env.REVOLT_TOKEN;
axios.post = vi.fn(async () => {
throw new Error('boom');
});
const previous = {publishedAt: null, slug: 'foo&bar', titre: 'Mon titre', user: null, userAdmin: null, artistes: []};
const strapiMock = buildStrapi(previous);
const {beforeUpdate} = await loadLifecycles(strapiMock);
await beforeUpdate(buildEvent());
expect(axios.post).toHaveBeenCalledTimes(1);
const [calledUrl] = axios.post.mock.calls[0];
expect(calledUrl).toContain('text=');
expect(calledUrl.split('text=')[1]).not.toContain('&bar');
expect(strapiMock.log.error).toHaveBeenCalledWith(expect.stringContaining('Telegram'));
});
it('n\'interrompt pas la publication quand Revolt échoue', async () => {
delete process.env.TELEGRAM_API_TOKEN;
process.env.REVOLT_TOKEN = 'fake-token';
process.env.REVOLT_TARGET = 'fake-target';
process.env.REVOLT_BOT_ID = 'fake-bot';
axios.post = vi.fn(async () => {
throw new Error('boom');
});
const previous = {publishedAt: null, slug: 'mon-titre', titre: 'Mon titre', user: null, userAdmin: null, artistes: []};
const strapiMock = buildStrapi(previous);
const {beforeUpdate} = await loadLifecycles(strapiMock);
await beforeUpdate(buildEvent());
expect(axios.post).toHaveBeenCalledTimes(1);
expect(strapiMock.log.error).toHaveBeenCalledWith(expect.stringContaining('Revolt'));
});
});
describe('afterCreate — publication miroir bokante', () => {
const originalEnv = {...process.env};
const bokanteMastodon = require('../../../../../utils/bokante-mastodon');
const originalCreateStatus = bokanteMastodon.createStatus;
function buildStrapi() {
const dbQuery = {
findOne: vi.fn(async () => null),
updateMany: vi.fn()
};
return {
db: {query: vi.fn(() => dbQuery)},
plugins: {email: {services: {email: {send: vi.fn()}}}},
log: {error: vi.fn()}
};
}
function buildEvent(resultOverrides = {}) {
return {
params: {data: {titre: 'Mon titre'}},
result: {
documentId: 'doc-1',
titre: 'Mon titre',
slug: 'mon-titre',
publishedAt: '2026-07-04T00:00:00.000Z',
bokanteStatusId: null,
...resultOverrides
}
};
}
afterEach(() => {
process.env = {...originalEnv};
bokanteMastodon.createStatus = originalCreateStatus;
delete global.strapi;
});
it('publie un statut miroir et synchronise bokanteStatusId sur le documentId', async () => {
process.env.BOKANTE_ACCESS_TOKEN = 'fake-token';
bokanteMastodon.createStatus = vi.fn(async () => ({id: '112233'}));
const strapiMock = buildStrapi();
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate(buildEvent());
expect(bokanteMastodon.createStatus).toHaveBeenCalledTimes(1);
expect(bokanteMastodon.createStatus.mock.calls[0][0]).toContain('Mon titre');
expect(strapiMock.db.query('api::parole.parole').updateMany).toHaveBeenCalledWith({
where: {documentId: 'doc-1'},
data: {bokanteStatusId: '112233'}
});
});
it('ne publie rien si la ligne créée n\'est pas publiée (simple brouillon)', async () => {
process.env.BOKANTE_ACCESS_TOKEN = 'fake-token';
bokanteMastodon.createStatus = vi.fn(async () => ({id: '999'}));
const strapiMock = buildStrapi();
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate(buildEvent({publishedAt: null}));
expect(bokanteMastodon.createStatus).not.toHaveBeenCalled();
});
it('ne republie pas si bokanteStatusId existe déjà', async () => {
process.env.BOKANTE_ACCESS_TOKEN = 'fake-token';
bokanteMastodon.createStatus = vi.fn(async () => ({id: '999'}));
const strapiMock = buildStrapi();
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate(buildEvent({bokanteStatusId: '112233'}));
expect(bokanteMastodon.createStatus).not.toHaveBeenCalled();
});
it('ne publie rien si BOKANTE_ACCESS_TOKEN n\'est pas configuré', async () => {
delete process.env.BOKANTE_ACCESS_TOKEN;
bokanteMastodon.createStatus = vi.fn(async () => ({id: '999'}));
const strapiMock = buildStrapi();
const {afterCreate} = await loadLifecycles(strapiMock);
await afterCreate(buildEvent());
expect(bokanteMastodon.createStatus).not.toHaveBeenCalled();
});
it('n\'interrompt pas la création quand bokante échoue', async () => {
process.env.BOKANTE_ACCESS_TOKEN = 'fake-token';
bokanteMastodon.createStatus = vi.fn(async () => {
throw new Error('boom');
});
const strapiMock = buildStrapi();
const {afterCreate} = await loadLifecycles(strapiMock);
await expect(afterCreate(buildEvent())).resolves.not.toThrow();
expect(strapiMock.log.error).toHaveBeenCalledWith(expect.stringContaining('bokante'));
expect(strapiMock.db.query('api::parole.parole').updateMany).not.toHaveBeenCalled();
});
});
describe('beforeUpdate — createdBy/updatedBy', () => {
afterEach(() => {
delete global.strapi;
});
it('retire createdBy/updatedBy du payload avant la mise à jour', async () => {
const dbQuery = {findOne: vi.fn(async () => ({publishedAt: null, artistes: []}))};
const strapiMock = {db: {query: vi.fn(() => dbQuery)}};
const {beforeUpdate} = await loadLifecycles(strapiMock);
const event = {
state: {},
params: {
data: {documentId: 'doc-1', createdBy: 999, updatedBy: 999}
}
};
await beforeUpdate(event);
expect(event.params.data.createdBy).toBeUndefined();
expect(event.params.data.updatedBy).toBeUndefined();
});
});
describe('afterUpdate — historique de différence', () => {
afterEach(() => {
delete global.strapi;
});
it('n\'échoue pas quand updatedBy n\'est pas peuplé', async () => {
const entityServiceUpdate = vi.fn(async () => {});
const strapiMock = {
entityService: {update: entityServiceUpdate}
};
const {afterUpdate} = await loadLifecycles(strapiMock);
const event = {
result: {id: 1, difference: [], updatedBy: undefined},
state: {diff: {path: 'transcription', jsonDiff: []}}
};
await afterUpdate(event);
expect(entityServiceUpdate).toHaveBeenCalledWith('api::parole.parole', 1, {
data: {
difference: [{
admin_user: null,
paroles: 'transcription',
jsonDiff: [],
date: expect.any(Date),
sources: 'transcription'
}]
}
});
});
});
+118 -84
View File
@@ -1,22 +1,23 @@
'use strict'; 'use strict';
const slugify = require('slugify') const slugify = require('slugify');
const axios = require('axios') const axios = require('axios');
const bokanteMastodon = require('../../../../utils/bokante-mastodon');
const utils = require('@strapi/utils') const utils = require('@strapi/utils');
const { ApplicationError } = utils.errors const { ApplicationError } = utils.errors;
const TELEGRAM_API_URL = 'https://api.telegram.org' const TELEGRAM_API_URL = 'https://api.telegram.org';
const TELEGRAM_CHAN_ID = process.env.TELEGRAM_CHAN_ID || null const TELEGRAM_CHAN_ID = process.env.TELEGRAM_CHAN_ID || null;
const TELEGRAM_API_TOKEN = process.env.TELEGRAM_API_TOKEN || null const TELEGRAM_API_TOKEN = process.env.TELEGRAM_API_TOKEN || null;
const MESSAGE_URL = `${TELEGRAM_API_URL}/bot${TELEGRAM_API_TOKEN}/sendMessage?chat_id=${TELEGRAM_CHAN_ID}&parse_mode=html` const MESSAGE_URL = `${TELEGRAM_API_URL}/bot${TELEGRAM_API_TOKEN}/sendMessage?chat_id=${TELEGRAM_CHAN_ID}&parse_mode=html`;
const REVOLT_BOT_ID = process.env.REVOLT_BOT_ID || null const REVOLT_BOT_ID = process.env.REVOLT_BOT_ID || null;
const REVOLT_TARGET = process.env.REVOLT_TARGET || null const REVOLT_TARGET = process.env.REVOLT_TARGET || null;
const REVOLT_TOKEN = process.env.REVOLT_TOKEN || null const REVOLT_TOKEN = process.env.REVOLT_TOKEN || null;
const getSlug = (artiste, parole) => { const getSlug = (artiste, parole) => {
return slugify(`${artiste}-${parole}`, {lower: true, remove: /[*#+~.()'"!:@]/g}) return slugify(`${artiste}-${parole}`, {lower: true, remove: /[*#+~.()'"!:@]/g});
} };
const isSlugExists = async existingSlug => { const isSlugExists = async existingSlug => {
const slugs = await strapi.db.query('api::parole.parole').count({ const slugs = await strapi.db.query('api::parole.parole').count({
@@ -25,10 +26,10 @@ const isSlugExists = async existingSlug => {
$eq: existingSlug $eq: existingSlug
} }
} }
}) });
return Boolean(slugs) return Boolean(slugs);
} };
const jwennAwtisEpiId = async artistesIds => { const jwennAwtisEpiId = async artistesIds => {
if (!artistesIds || artistesIds.length === 0) { if (!artistesIds || artistesIds.length === 0) {
@@ -42,30 +43,30 @@ const jwennAwtisEpiId = async artistesIds => {
$in: artistesIds.map(id => id) $in: artistesIds.map(id => id)
} }
} }
}) });
return artistes.map(a => a.alias).join('-') return artistes.map(a => a.alias).join('-');
} };
const jwennUserEpiId = async userId => { const jwennUserEpiId = async userId => {
if (!userId) { if (!userId) {
return null return null;
} }
const user = await strapi.db.query('plugin::users-permissions.user').findOne({ const user = await strapi.db.query('plugin::users-permissions.user').findOne({
where: {user: userId} where: {id: userId}
}) });
if (!user) { if (!user) {
throw new ApplicationError('Utilisateur introuvable.') throw new ApplicationError('Utilisateur introuvable.');
} }
return user return user;
} };
const jwennUserAdminEpiId = async userAdminId => { const jwennUserAdminEpiId = async userAdminId => {
if (!userAdminId) { if (!userAdminId) {
return null return null;
} }
const userAdmin = await strapi.db.query('admin::user').findOne({ const userAdmin = await strapi.db.query('admin::user').findOne({
@@ -83,14 +84,14 @@ const jwennUserAdminEpiId = async userAdminId => {
} }
] ]
} }
}) });
return userAdmin return userAdmin;
} };
const jwennSuperAdminEpiId = async userAdminId => { const jwennSuperAdminEpiId = async userAdminId => {
if (!userAdminId) { if (!userAdminId) {
return null return null;
} }
const userAdmin = await strapi.db.query('admin::user').findOne({ const userAdmin = await strapi.db.query('admin::user').findOne({
@@ -108,87 +109,91 @@ const jwennSuperAdminEpiId = async userAdminId => {
} }
] ]
} }
}) });
return userAdmin return userAdmin;
} };
module.exports = { module.exports = {
beforeCreate: async event => { beforeCreate: async event => {
let {data} = event.params let {data} = event.params;
delete data.createdBy delete data.createdBy;
delete data.updatedBy delete data.updatedBy;
strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription) strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription);
let artistesIds = [] let artistesIds = [];
if (data?.artistes?.connect?.length) { if (data?.artistes?.connect?.length) {
artistesIds = data.artistes.connect.map(a => a.id) artistesIds = data.artistes.connect.map(a => a.id);
if (data.titre && !data.forceSlug) { if (data.titre && !data.forceSlug) {
const artiste = await jwennAwtisEpiId(artistesIds) const artiste = await jwennAwtisEpiId(artistesIds);
data.slug = getSlug(artiste, data.titre) data.slug = getSlug(artiste, data.titre);
} }
const getSlugExistance = await isSlugExists(data.slug) const getSlugExistance = await isSlugExists(data.slug);
if (getSlugExistance) { if (getSlugExistance) {
throw new ApplicationError('Un morceau du même artiste existe déjà.') throw new ApplicationError('Un morceau du même artiste existe déjà.');
} }
} }
}, },
beforeUpdate: async event => { beforeUpdate: async event => {
const {state} = event const {state} = event;
let {data} = event.params let {data} = event.params;
const {documentId} = data
delete data.createdBy;
delete data.updatedBy;
const {documentId} = data;
if (data.isNewRelease === true) { if (data.isNewRelease === true) {
await strapi.db.query('api::parole.parole').updateMany({ await strapi.db.query('api::parole.parole').updateMany({
where: { isNewRelease: true }, where: { isNewRelease: true },
data: { isNewRelease: false }, data: { isNewRelease: false },
}) });
} }
const previousParoles = await strapi.db.query('api::parole.parole').findOne({ const previousParoles = await strapi.db.query('api::parole.parole').findOne({
where: {documentId}, where: {documentId},
populate: {difference: true, artistes: true} populate: {difference: true, artistes: true}
}) });
if (data.transcription && previousParoles.publishedAt) { if (data.transcription && previousParoles.publishedAt) {
const difference = strapi.service('api::parole.parole').parolesDiff(data.titre, previousParoles.transcription, data.transcription) const difference = strapi.service('api::parole.parole').parolesDiff(data.titre, previousParoles.transcription, data.transcription);
state.diff = difference state.diff = difference;
} }
if(!data.publishedAt && data.titre && data.transcription) { if(!data.publishedAt && data.titre && data.transcription) {
strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription) strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription);
if (data.titre && !data.forceSlug) { if (data.titre && !data.forceSlug) {
let artistes let artistes;
if (data.artistes.connect.length === 0) { if (data.artistes.connect.length === 0) {
artistes = previousParoles.artistes.map(a => a.alias).join('-') artistes = previousParoles.artistes.map(a => a.alias).join('-');
} else { } else {
let artistesIds = [] let artistesIds = [];
artistesIds = data.artistes.connect.map(a => a.id) artistesIds = data.artistes.connect.map(a => a.id);
artistes = await jwennAwtisEpiId(artistesIds) artistes = await jwennAwtisEpiId(artistesIds);
} }
data.slug = getSlug(artistes, data.titre) data.slug = getSlug(artistes, data.titre);
} }
} }
if (data.publishedAt != null) { if (data.publishedAt != null) {
const previousData = await strapi.db.query('api::parole.parole').findOne({ const previousData = await strapi.db.query('api::parole.parole').findOne({
where: {documentId} where: {documentId}
}) });
const previousPublishedAt = previousData.publishedAt const previousPublishedAt = previousData.publishedAt;
const currentPublished_at = data.publishedAt const currentPublished_at = data.publishedAt;
if (currentPublished_at != previousPublishedAt) { if (currentPublished_at != previousPublishedAt) {
const message = `<b>Nouvelle publication</b> ❤️ const message = `<b>Nouvelle publication</b> ❤️
\n${process.env.WEBSITE_URL}/paroles/${previousData.slug}` \n${process.env.WEBSITE_URL}/paroles/${previousData.slug}`;
if (previousData.user) { if (previousData.user) {
strapi.plugins['email'].services.email.send({ strapi.plugins['email'].services.email.send({
from: process.env.SMTP_FROM, from: process.env.SMTP_FROM,
@@ -199,7 +204,7 @@ module.exports = {
Merci pour votre contribution ❤️`, Merci pour votre contribution ❤️`,
html: `<p>Le titre que vous avez soumis, <strong>"${previousData.titre}"</strong> a été publié sur le site.</p> html: `<p>Le titre que vous avez soumis, <strong>"${previousData.titre}"</strong> a été publié sur le site.</p>
<p>Vous pouvez le trouver à l'adresse <a href="${process.env.WEBSITE_URL}/paroles/${previousData.slug}">${process.env.WEBSITE_URL}/paroles/${previousData.slug}</a>.</p><p>Merci pour votre contribution ❤️</p>` <p>Vous pouvez le trouver à l'adresse <a href="${process.env.WEBSITE_URL}/paroles/${previousData.slug}">${process.env.WEBSITE_URL}/paroles/${previousData.slug}</a>.</p><p>Merci pour votre contribution ❤️</p>`
}) });
} }
if (previousData.userAdmin) { if (previousData.userAdmin) {
@@ -212,35 +217,43 @@ module.exports = {
Merci pour votre contribution ❤️`, Merci pour votre contribution ❤️`,
html: `<p>Le titre que vous avez soumis, <strong>"${previousData.titre}"</strong> a été publié sur le site.</p> html: `<p>Le titre que vous avez soumis, <strong>"${previousData.titre}"</strong> a été publié sur le site.</p>
<p>Vous pouvez le trouver à l'adresse <a href="${process.env.WEBSITE_URL}/paroles/${previousData.slug}">${process.env.WEBSITE_URL}/paroles/${previousData.slug}</a>.</p><p>Merci pour votre contribution ❤️</p>` <p>Vous pouvez le trouver à l'adresse <a href="${process.env.WEBSITE_URL}/paroles/${previousData.slug}">${process.env.WEBSITE_URL}/paroles/${previousData.slug}</a>.</p><p>Merci pour votre contribution ❤️</p>`
}) });
} }
if (TELEGRAM_API_TOKEN) { if (TELEGRAM_API_TOKEN) {
await axios.post(`${MESSAGE_URL}&text=${message}`) try {
await axios.post(`${MESSAGE_URL}&text=${encodeURIComponent(message)}`);
} catch (err) {
strapi.log.error(`Notification Telegram : ${err.message}`);
}
} }
if (REVOLT_TOKEN && REVOLT_TARGET && REVOLT_BOT_ID) { if (REVOLT_TOKEN && REVOLT_TARGET && REVOLT_BOT_ID) {
const revoltMessage = `Nouvelle publication const revoltMessage = `Nouvelle publication
\n${process.env.WEBSITE_URL}/paroles/${previousData.slug}` \n${process.env.WEBSITE_URL}/paroles/${previousData.slug}`;
const targetChannel = REVOLT_TARGET const targetChannel = REVOLT_TARGET;
const botToken = REVOLT_TOKEN const botToken = REVOLT_TOKEN;
const url = `https://api.revolt.chat/channels/${targetChannel}/messages` const url = `https://api.revolt.chat/channels/${targetChannel}/messages`;
const config = { const config = {
headers: { headers: {
'X-Bot-Token': botToken, 'X-Bot-Token': botToken,
'Content-Type': 'application/json' 'Content-Type': 'application/json'
} }
} };
await axios.post(url, {content: revoltMessage}, config) try {
await axios.post(url, {content: revoltMessage}, config);
} catch (err) {
strapi.log.error(`Notification Revolt : ${err.message}`);
}
} }
} }
} }
}, },
afterUpdate: async event => { afterUpdate: async event => {
const {result, state} = event const {result, state} = event;
if (state.diff) { if (state.diff) {
await strapi.entityService.update('api::parole.parole', result.id, { await strapi.entityService.update('api::parole.parole', result.id, {
@@ -248,22 +261,43 @@ module.exports = {
difference: [ difference: [
...result.difference, ...result.difference,
{ {
admin_user: result.updatedBy.id, admin_user: result.updatedBy?.id ?? null,
paroles: state.diff.path, paroles: state.diff.path,
jsonDiff: state.diff.jsonDiff, jsonDiff: state.diff.jsonDiff,
date: new Date(), date: new Date(),
sources: 'transcription' sources: 'transcription'
}] }]
} }
}) });
} }
}, },
afterCreate: async event => { afterCreate: async event => {
const {data} = event.params const {data} = event.params;
const user = await jwennUserEpiId(data?.user?.id)
const userAdmin = await jwennUserAdminEpiId(data?.createdBy) // Avec draftAndPublish, "publier" crée une nouvelle ligne (la version publiée)
const superAdmin = await jwennSuperAdminEpiId(data?.createdBy) // au lieu de mettre à jour la ligne existante : c'est ici, et non dans
const traductionsId = data?.traductions?.id // beforeUpdate, qu'un événement de publication est détectable.
if (event.result?.publishedAt && !event.result?.bokanteStatusId && process.env.BOKANTE_ACCESS_TOKEN) {
try {
const status = await bokanteMastodon.createStatus(
`"${event.result.titre}" — nouvelle parole sur pawol.nu\n${process.env.WEBSITE_URL}/paroles/${event.result.slug}`
);
// Synchronise brouillon et version publiée pour éviter une republication
// en double au prochain cycle dépublier/republier (qui recrée la ligne
// publiée à partir du brouillon).
await strapi.db.query('api::parole.parole').updateMany({
where: {documentId: event.result.documentId},
data: {bokanteStatusId: status.id}
});
} catch (err) {
strapi.log.error(`Publication bokante : ${err.message}`);
}
}
const user = await jwennUserEpiId(data?.user?.id);
const userAdmin = await jwennUserAdminEpiId(data?.createdBy);
const superAdmin = await jwennSuperAdminEpiId(data?.createdBy);
const traductionsId = data?.traductions?.id;
if (traductionsId) { if (traductionsId) {
const result = await strapi.db.query('api::parole.parole').findOne({ const result = await strapi.db.query('api::parole.parole').findOne({
@@ -275,15 +309,15 @@ module.exports = {
} }
}, },
populate: {traductions: true, artistes: true} populate: {traductions: true, artistes: true}
}) });
if (superAdmin && data.traductionAuto && result.traductions.francais && (!result.traductions.anglais || !result.traductions.espagnol || !result.traductions.allemand || !result.traductions.italien)) { if (superAdmin && data.traductionAuto && result.traductions.francais && (!result.traductions.anglais || !result.traductions.espagnol || !result.traductions.allemand || !result.traductions.italien)) {
const traductions = await strapi.service('api::parole.parole').translateLyrics(result.traductions.francais) const traductions = await strapi.service('api::parole.parole').translateLyrics(result.traductions.francais);
await strapi.entityService.update('api::parole.parole', result.id, { await strapi.entityService.update('api::parole.parole', result.id, {
data: { data: {
traductions traductions
} }
}) });
} }
} }
@@ -294,7 +328,7 @@ module.exports = {
subject: `Nouveau texte de ${user.username} : "${data.titre}" (site)`, subject: `Nouveau texte de ${user.username} : "${data.titre}" (site)`,
text: `Le titre "${data.titre}" a été soumis depuis le site.`, text: `Le titre "${data.titre}" a été soumis depuis le site.`,
html: `Le titre <strong>"${data.titre}"</strong> a été soumis depuis le site.` html: `Le titre <strong>"${data.titre}"</strong> a été soumis depuis le site.`
}) });
} }
if (userAdmin) { if (userAdmin) {
@@ -304,7 +338,7 @@ module.exports = {
subject: `Nouveau texte de ${userAdmin.firstname} : "${data.titre}" (site)`, subject: `Nouveau texte de ${userAdmin.firstname} : "${data.titre}" (site)`,
text: `Le titre "${data.titre}" a été soumis depuis le site.`, text: `Le titre "${data.titre}" a été soumis depuis le site.`,
html: `Le titre <strong>"${data.titre}"</strong> a été soumis depuis le site.` html: `Le titre <strong>"${data.titre}"</strong> a été soumis depuis le site.`
}) });
} }
} }
} };
@@ -8,7 +8,8 @@
"description": "" "description": ""
}, },
"options": { "options": {
"draftAndPublish": true "draftAndPublish": true,
"populateCreatorFields": true
}, },
"pluginOptions": {}, "pluginOptions": {},
"attributes": { "attributes": {
@@ -81,7 +82,8 @@
"commentaires": { "commentaires": {
"type": "relation", "type": "relation",
"relation": "oneToMany", "relation": "oneToMany",
"target": "api::commentaire.commentaire" "target": "api::commentaire.commentaire",
"mappedBy": "parole"
}, },
"prioriteArtistes": { "prioriteArtistes": {
"type": "string" "type": "string"
@@ -157,6 +159,9 @@
"type": "component", "type": "component",
"component": "kit.lyen", "component": "kit.lyen",
"repeatable": true "repeatable": true
},
"bokanteStatusId": {
"type": "string"
} }
} }
} }
@@ -0,0 +1,170 @@
import {describe, it, expect, vi} from 'vitest';
const {default: createController} = await import('../parole.js');
function buildStrapi({dbUser, artiste}) {
const paroleDocuments = {
findMany: vi.fn(async () => []),
create: vi.fn(async ({data}) => ({id: 42, ...data})),
update: vi.fn(async ({data}) => ({id: 42, ...data}))
};
const userDocuments = {
findOne: vi.fn(async () => dbUser),
update: vi.fn(async () => {})
};
const artisteDocuments = {
findOne: vi.fn(async () => artiste)
};
const strapi = {
contentType: vi.fn(() => ({uid: 'api::parole.parole', kind: 'collectionType'})),
service: vi.fn(() => ({
validateParoles: vi.fn(),
translateLyrics: vi.fn()
})),
documents: vi.fn(uid => {
if (uid === 'plugin::users-permissions.user') return userDocuments;
if (uid === 'api::artiste.artiste') return artisteDocuments;
if (uid === 'api::parole.parole') return paroleDocuments;
throw new Error(`unexpected uid: ${uid}`);
})
};
return {strapi, paroleDocuments, userDocuments, artisteDocuments};
}
function buildCtx(data) {
return {
request: {
body: {data},
header: {authorization: 'Bearer faketoken'}
},
badRequest: vi.fn(),
notFound: vi.fn()
};
}
const dbUser = {id: 1, documentId: 'user-doc-1', username: 'foo', email: 'foo@bar.com'};
const artiste = {id: 9, documentId: 'artiste-doc-1'};
function buildData(overrides = {}) {
return {
titre: 'Test',
transcription: 'Paroles...',
user: {...dbUser},
artistes: [{documentId: 'artiste-doc-1'}],
...overrides
};
}
describe('parole.findOne', () => {
it('interroge avec le documentId venant de ctx.params.id, pas avec ctx lui-même', async () => {
const paroleDocuments = {
findOne: vi.fn(async ({documentId}) => ({id: 1, documentId, titre: 'Test'}))
};
const strapi = {
contentType: vi.fn(() => ({uid: 'api::parole.parole', kind: 'collectionType'})),
documents: vi.fn(uid => {
if (uid === 'api::parole.parole') return paroleDocuments;
throw new Error(`unexpected uid: ${uid}`);
})
};
const controller = createController({strapi});
const ctx = {params: {id: 'doc-123'}};
const result = await controller.findOne(ctx);
expect(paroleDocuments.findOne).toHaveBeenCalledWith({
documentId: 'doc-123',
populate: ['artistes']
});
expect(result).toEqual({id: 1, documentId: 'doc-123', titre: 'Test'});
});
});
describe('parole.create', () => {
it('crée la parole quand le user et l\'artiste existent', async () => {
const {strapi, paroleDocuments} = buildStrapi({dbUser, artiste});
const controller = createController({strapi});
const ctx = buildCtx(buildData());
await controller.create(ctx);
expect(paroleDocuments.create).toHaveBeenCalled();
});
it('refuse sans planter quand data.user est absent', async () => {
const {strapi, userDocuments} = buildStrapi({dbUser, artiste});
const controller = createController({strapi});
const ctx = buildCtx(buildData({user: undefined}));
await controller.create(ctx);
expect(ctx.badRequest).toHaveBeenCalled();
expect(userDocuments.findOne).not.toHaveBeenCalled();
});
it('refuse sans planter quand data.artistes est vide', async () => {
const {strapi, artisteDocuments} = buildStrapi({dbUser, artiste});
const controller = createController({strapi});
const ctx = buildCtx(buildData({artistes: []}));
await controller.create(ctx);
expect(ctx.badRequest).toHaveBeenCalled();
expect(artisteDocuments.findOne).not.toHaveBeenCalled();
});
it('ignore les champs non autorisés du payload (mass assignment)', async () => {
const {strapi, paroleDocuments} = buildStrapi({dbUser, artiste});
const controller = createController({strapi});
const ctx = buildCtx(buildData({
userAdmin: {id: 999},
isNewRelease: true,
difference: [{fake: true}]
}));
await controller.create(ctx);
expect(paroleDocuments.create).toHaveBeenCalledWith({
data: {
titre: 'Test',
transcription: 'Paroles...',
traductions: undefined,
traductionAuto: undefined,
artistes: [artiste.id],
user: dbUser.id
}
});
});
});
describe('parole.update', () => {
it('ignore les champs non autorisés du payload (mass assignment)', async () => {
const {strapi, paroleDocuments} = buildStrapi({dbUser, artiste});
const controller = createController({strapi});
const ctx = buildCtx({
documentId: 'doc-1',
titre: 'Nouveau titre',
transcription: 'Nouveau texte',
traductions: {francais: 'salut'},
traductionAuto: true,
artistes: [9],
userAdmin: {id: 999},
user: {id: 999}
});
await controller.update(ctx);
expect(paroleDocuments.update).toHaveBeenCalledWith({
documentId: 'doc-1',
data: {
titre: 'Nouveau titre',
transcription: 'Nouveau texte',
traductions: {francais: 'salut'},
traductionAuto: true,
artistes: [9]
}
});
});
});
+53 -52
View File
@@ -2,29 +2,29 @@
const { createCoreController } = require('@strapi/strapi').factories; const { createCoreController } = require('@strapi/strapi').factories;
const VALID_LANGS = new Set(['fr', 'en', 'es', 'de', 'it']) const VALID_LANGS = new Set(['fr', 'en', 'es', 'de', 'it']);
module.exports = createCoreController('api::parole.parole', ({strapi}) => ({ module.exports = createCoreController('api::parole.parole', ({strapi}) => ({
async export(ctx) { async export(ctx) {
const { type = 'pairs', lang, format = 'jsonl' } = ctx.query const { type = 'pairs', lang, format = 'jsonl' } = ctx.query;
const langs = lang const langs = lang
? lang.split(',').map(l => l.trim()).filter(l => VALID_LANGS.has(l)) ? lang.split(',').map(l => l.trim()).filter(l => VALID_LANGS.has(l))
: null : null;
if (lang && (!langs || langs.length === 0)) { if (lang && (!langs || langs.length === 0)) {
return ctx.badRequest('Langue(s) invalide(s). Valeurs acceptées : fr, en, es, de, it.') return ctx.badRequest('Langue(s) invalide(s). Valeurs acceptées : fr, en, es, de, it.');
} }
if (!['pairs', 'instruct'].includes(type)) { if (!['pairs', 'instruct'].includes(type)) {
return ctx.badRequest('type invalide. Valeurs acceptées : pairs, instruct.') return ctx.badRequest('type invalide. Valeurs acceptées : pairs, instruct.');
} }
const paroles = await strapi.service('api::parole.parole').fetchAllParoles() const paroles = await strapi.service('api::parole.parole').fetchAllParoles();
const { metadata, pairs } = strapi.service('api::parole.parole').buildExport(paroles, type, langs) const { metadata, pairs } = strapi.service('api::parole.parole').buildExport(paroles, type, langs);
if (format === 'json') { if (format === 'json') {
return ctx.send({ metadata, data: pairs }) return ctx.send({ metadata, data: pairs });
} }
// JSONL : première ligne = métadonnées, suivies des exemples d'entraînement. // JSONL : première ligne = métadonnées, suivies des exemples d'entraînement.
@@ -32,77 +32,73 @@ module.exports = createCoreController('api::parole.parole', ({strapi}) => ({
const lines = [ const lines = [
JSON.stringify({ _metadata: true, ...metadata }), JSON.stringify({ _metadata: true, ...metadata }),
...pairs.map(p => JSON.stringify(p)), ...pairs.map(p => JSON.stringify(p)),
] ];
ctx.set('Content-Type', 'application/x-ndjson') ctx.set('Content-Type', 'application/x-ndjson');
ctx.set('Content-Disposition', `attachment; filename="pawol-nu-export-${Date.now()}.jsonl"`) ctx.set('Content-Disposition', `attachment; filename="pawol-nu-export-${Date.now()}.jsonl"`);
ctx.body = lines.join('\n') ctx.body = lines.join('\n');
}, },
async bulkTranslate(ctx) { async bulkTranslate(ctx) {
const result = await strapi.service('api::parole.parole').bulkTranslateMissing() const result = await strapi.service('api::parole.parole').bulkTranslateMissing();
return ctx.send(result) return ctx.send(result);
}, },
async findOne(documentId) { async findOne(ctx) {
const {id: documentId} = ctx.params;
const parole = await strapi.documents('api::parole.parole').findOne({ const parole = await strapi.documents('api::parole.parole').findOne({
documentId, documentId,
populate: ['artistes'] populate: ['artistes']
}) });
return parole return parole;
}, },
async update(ctx) { async update(ctx) {
const {body} = ctx.request const {body} = ctx.request;
const {data} = body const {data} = body;
const updatedParole = await strapi.documents('api::parole.parole').update({ const updatedParole = await strapi.documents('api::parole.parole').update({
documentId: data.documentId, documentId: data.documentId,
data: { data: {
...data titre: data.titre,
transcription: data.transcription,
traductions: data.traductions,
traductionAuto: data.traductionAuto,
artistes: data.artistes
} }
}) });
return updatedParole return updatedParole;
}, },
async create(ctx) { async create(ctx) {
const {body} = ctx.request const {body} = ctx.request;
const {data} = body const {data} = body;
strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription)
if (ctx.request && ctx.request.header && ctx.request.header.authorization) { if (!data?.user?.documentId || !data?.artistes?.[0]?.documentId) {
try { return ctx.badRequest('Informations manquantes.');
const {id} = await strapi.plugins[ }
'users-permissions'
].services.jwt.getToken(ctx)
if (id !== data.user.id) { strapi.service('api::parole.parole').validateParoles(data.titre, data.transcription);
ctx.unauthorized('Opération non autorisée')
}
} catch (err) {
ctx.unauthorized(ctx, err, 'Opération non autorisée')
}
}
const user = await strapi.documents('plugin::users-permissions.user').findOne({ const user = await strapi.documents('plugin::users-permissions.user').findOne({
documentId: body.data.user.documentId documentId: body.data.user.documentId
}) });
if (!user) { if (!user) {
ctx.notFound('Utilisateur introuvable.') return ctx.notFound('Utilisateur introuvable.');
} }
if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) { if (user.id !== data.user.id || user.username !== data.user.username || user.email !== data.user.email) {
ctx.badRequest('Informations non valides.') return ctx.badRequest('Informations non valides.');
} }
const artiste = await strapi.documents('api::artiste.artiste').findOne({ const artiste = await strapi.documents('api::artiste.artiste').findOne({
documentId: data.artistes[0].documentId documentId: data.artistes[0].documentId
}) });
if (!artiste) { if (!artiste) {
ctx.notFound('Artiste introuvable.') return ctx.notFound('Artiste introuvable.');
} }
const currentUserParole = await strapi.documents('api::parole.parole').findMany({ const currentUserParole = await strapi.documents('api::parole.parole').findMany({
@@ -117,22 +113,27 @@ module.exports = createCoreController('api::parole.parole', ({strapi}) => ({
$eq: null $eq: null
} }
} }
}) });
if (user && user.canAutoTranslate && data.traductionAuto && data.traductions.francais && (!data.traductions.anglais || !data.traductions.espagnol || !data.traductions.allemand || !data.traductions.italien)) { if (user && user.canAutoTranslate && data.traductionAuto && data.traductions.francais && (!data.traductions.anglais || !data.traductions.espagnol || !data.traductions.allemand || !data.traductions.italien)) {
const translated = await strapi.service('api::parole.parole').translateLyrics(data.traductions.francais) const translated = await strapi.service('api::parole.parole').translateLyrics(data.traductions.francais);
data.traductions = translated data.traductions = translated;
} }
const newParole = await strapi.documents('api::parole.parole').create({ const newParole = await strapi.documents('api::parole.parole').create({
data: { data: {
...data titre: data.titre,
transcription: data.transcription,
traductions: data.traductions,
traductionAuto: data.traductionAuto,
artistes: [artiste.id],
user: user.id
} }
}) });
const parolesIds = currentUserParole.map(({id}) => id) const parolesIds = currentUserParole.map(({id}) => id);
parolesIds.push(newParole.id) parolesIds.push(newParole.id);
await strapi.documents('plugin::users-permissions.user').update({ await strapi.documents('plugin::users-permissions.user').update({
documentId: user.documentId, documentId: user.documentId,
@@ -140,8 +141,8 @@ module.exports = createCoreController('api::parole.parole', ({strapi}) => ({
data: { data: {
paroles: parolesIds paroles: parolesIds
} }
}) });
return newParole return newParole;
} }
})) }));
@@ -0,0 +1,19 @@
import {describe, it, expect} from 'vitest';
import isApiToken from '../is-api-token.js';
describe('is-api-token policy', () => {
it('autorise une requête authentifiée par token API', () => {
const ctx = {state: {auth: {strategy: {name: 'api-token'}}}};
expect(isApiToken(ctx)).toBe(true);
});
it('refuse une requête authentifiée autrement (ex: JWT utilisateur)', () => {
const ctx = {state: {auth: {strategy: {name: 'users-permissions'}}}};
expect(isApiToken(ctx)).toBe(false);
});
it('refuse une requête non authentifiée', () => {
const ctx = {state: {}};
expect(isApiToken(ctx)).toBe(false);
});
});
+5
View File
@@ -0,0 +1,5 @@
'use strict';
module.exports = policyContext => {
return policyContext.state?.auth?.strategy?.name === 'api-token';
};
+1 -1
View File
@@ -12,7 +12,7 @@ module.exports = {
method: 'POST', method: 'POST',
path: '/paroles/bulk-translate', path: '/paroles/bulk-translate',
handler: 'parole.bulkTranslate', handler: 'parole.bulkTranslate',
config: { policies: [], middlewares: [] }, config: { policies: ['api::parole.is-api-token'], middlewares: [] },
}, },
], ],
}; };
+13 -1
View File
@@ -2,4 +2,16 @@
const { createCoreRouter } = require('@strapi/strapi').factories; const { createCoreRouter } = require('@strapi/strapi').factories;
module.exports = createCoreRouter('api::parole.parole') module.exports = createCoreRouter('api::parole.parole', {
config: {
create: {
policies: ['global::is-payload-owner']
},
update: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::parole.parole'}}]
},
delete: {
policies: [{name: 'global::is-document-owner', config: {uid: 'api::parole.parole'}}]
}
}
});
@@ -0,0 +1,84 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
const {default: createService} = await import('../parole.js');
function fakeDeeplResponse(text) {
return {
ok: true,
json: async () => ({translations: [{text}]})
};
}
describe('Translator (DeepL)', () => {
const originalFetch = global.fetch;
afterEach(() => {
global.fetch = originalFetch;
vi.restoreAllMocks();
});
it('attache un timeout à la requête DeepL', async () => {
global.fetch = vi.fn(async () => fakeDeeplResponse('hello'));
const strapi = {contentType: vi.fn(() => ({uid: 'api::parole.parole', kind: 'collectionType'}))};
const service = createService({strapi});
await service.translate('FR', 'EN', 'bonjour');
const [, options] = global.fetch.mock.calls[0];
expect(options.signal).toBeInstanceOf(AbortSignal);
});
});
describe('translateLyrics', () => {
const originalFetch = global.fetch;
afterEach(() => {
global.fetch = originalFetch;
vi.restoreAllMocks();
});
it('continue les autres langues quand une traduction DeepL échoue', async () => {
global.fetch = vi.fn(async (_url, options) => {
const {target_lang: target} = JSON.parse(options.body);
if (target === 'ES') {
return {ok: false, status: 500, text: async () => 'boom'};
}
return fakeDeeplResponse(`traduit-${target}`);
});
const strapi = {
contentType: vi.fn(() => ({uid: 'api::parole.parole', kind: 'collectionType'})),
log: {error: vi.fn()}
};
const service = createService({strapi});
const result = await service.translateLyrics('Bonjour le monde');
expect(result.anglais).toContain('traduit-EN');
expect(result.espagnol).toBeUndefined();
});
it('traduit les langues africaines ajoutées, sans appeler DeepL pour le yoruba', async () => {
global.fetch = vi.fn(async (_url, options) => {
const {target_lang: target} = JSON.parse(options.body);
return fakeDeeplResponse(`traduit-${target}`);
});
const strapi = {
contentType: vi.fn(() => ({uid: 'api::parole.parole', kind: 'collectionType'})),
log: {error: vi.fn()}
};
const service = createService({strapi});
const result = await service.translateLyrics('Bonjour le monde');
expect(result.swahili).toContain('traduit-SW');
expect(result.lingala).toContain('traduit-LN');
expect(result.wolof).toContain('traduit-WO');
expect(result.hausa).toContain('traduit-HA');
expect(result.yoruba).toBeUndefined();
const calledTargets = global.fetch.mock.calls.map(([, options]) => JSON.parse(options.body).target_lang);
expect(calledTargets).not.toContain('YO');
expect(calledTargets).not.toContain(undefined);
});
});
+126 -104
View File
@@ -1,56 +1,72 @@
'use strict'; 'use strict';
const qs = require('qs') const Diff = require('diff');
const Diff = require('diff')
const { createCoreService } = require('@strapi/strapi').factories; const { createCoreService } = require('@strapi/strapi').factories;
const { ApplicationError } = require("@strapi/utils").errors const { ApplicationError } = require('@strapi/utils').errors;
const LANG_MAP = { const LANG_MAP = {
fr: { field: 'francais', targetLang: 'fr', userPrompt: 'Tradui an fransé' }, fr: { field: 'francais', targetLang: 'fr', userPrompt: 'Tradui an fransé' },
// Pas de code DeepL pour le yoruba : traduction manuelle uniquement.
yo: { field: 'yoruba', targetLang: 'yo', userPrompt: 'Translate to Yoruba' },
ln: { field: 'lingala', targetLang: 'ln', userPrompt: 'Translate to Lingala', deeplTarget: 'LN', suffix: '\n\n (DeepL)' },
wo: { field: 'wolof', targetLang: 'wo', userPrompt: 'Translate to Wolof', deeplTarget: 'WO', suffix: '\n\n (DeepL)' },
sw: { field: 'swahili', targetLang: 'sw', userPrompt: 'Translate to Swahili', deeplTarget: 'SW', suffix: '\n\n (DeepL)' },
ha: { field: 'hausa', targetLang: 'ha', userPrompt: 'Translate to Hausa', deeplTarget: 'HA', suffix: '\n\n (DeepL)' },
ar: { field: 'arabe', targetLang: 'ar', userPrompt: 'Translate to Arabic', deeplTarget: 'AR', suffix: '\n\n (DeepL)' },
om: { field: 'oromo', targetLang: 'om', userPrompt: 'Translate to Oromo', deeplTarget: 'OM', suffix: '\n\n (DeepL)' },
ig: { field: 'igbo', targetLang: 'ig', userPrompt: 'Translate to Igbo', deeplTarget: 'IG', suffix: '\n\n (DeepL)' },
zu: { field: 'zoulou', targetLang: 'zu', userPrompt: 'Translate to Zulu', deeplTarget: 'ZU', suffix: '\n\n (DeepL)' },
mg: { field: 'malgache', targetLang: 'mg', userPrompt: 'Translate to Malagasy', deeplTarget: 'MG', suffix: '\n\n (DeepL)' },
xh: { field: 'xhosa', targetLang: 'xh', userPrompt: 'Translate to Xhosa', deeplTarget: 'XH', suffix: '\n\n (DeepL)' },
tn: { field: 'tswana', targetLang: 'tn', userPrompt: 'Translate to Tswana', deeplTarget: 'TN', suffix: '\n\n (DeepL)' },
ts: { field: 'tsonga', targetLang: 'ts', userPrompt: 'Translate to Tsonga', deeplTarget: 'TS', suffix: '\n\n (DeepL)' },
st: { field: 'sesotho', targetLang: 'st', userPrompt: 'Translate to Sesotho', deeplTarget: 'ST', suffix: '\n\n (DeepL)' },
ja: { field: 'japonais', targetLang: 'ja', userPrompt: '日本語に翻訳して', deeplTarget: 'JA', suffix: '\n\n (DeepLによる翻訳)' },
ko: { field: 'coreen', targetLang: 'ko', userPrompt: '한국어로 번역해줘', deeplTarget: 'KO', suffix: '\n\n (DeepL 번역)' },
en: { field: 'anglais', targetLang: 'en', userPrompt: 'Translate to English', deeplTarget: 'EN', suffix: '\n\n (Translated by DeepL)' }, en: { field: 'anglais', targetLang: 'en', userPrompt: 'Translate to English', deeplTarget: 'EN', suffix: '\n\n (Translated by DeepL)' },
es: { field: 'espagnol', targetLang: 'es', userPrompt: 'Traduce al español', deeplTarget: 'ES', suffix: '\n\n (Traducido por DeepL)' }, es: { field: 'espagnol', targetLang: 'es', userPrompt: 'Traduce al español', deeplTarget: 'ES', suffix: '\n\n (Traducido por DeepL)' },
de: { field: 'allemand', targetLang: 'de', userPrompt: 'Übersetze auf Deutsch', deeplTarget: 'DE', suffix: '\n\n (Übersetzt von DeepL)' }, de: { field: 'allemand', targetLang: 'de', userPrompt: 'Übersetze auf Deutsch', deeplTarget: 'DE', suffix: '\n\n (Übersetzt von DeepL)' },
it: { field: 'italien', targetLang: 'it', userPrompt: 'Traduci in italiano', deeplTarget: 'IT', suffix: '\n\n (Tradotto da DeepL)' }, it: { field: 'italien', targetLang: 'it', userPrompt: 'Traduci in italiano', deeplTarget: 'IT', suffix: '\n\n (Tradotto da DeepL)' },
pt: { field: 'portugais', targetLang: 'pt', userPrompt: 'Traduza para o português', deeplTarget: 'PT-BR', suffix: '\n\n (Traduzido pela DeepL)' }, pt: { field: 'portugais', targetLang: 'pt', userPrompt: 'Traduza para o português', deeplTarget: 'PT-BR', suffix: '\n\n (Traduzido pela DeepL)' },
ja: { field: 'japonais', targetLang: 'ja', userPrompt: '日本語に翻訳して', deeplTarget: 'JA', suffix: '\n\n (DeepLによる翻訳)' }, };
ko: { field: 'coreen', targetLang: 'ko', userPrompt: '한국어로 번역해줘', deeplTarget: 'KO', suffix: '\n\n (DeepL 번역)' },
}
const ALL_LANGS = Object.keys(LANG_MAP) const ALL_LANGS = Object.keys(LANG_MAP);
// Langues suivies (schéma + export) mais sans traduction automatique DeepL.
const NO_AUTO_TRANSLATE = new Set(['fr', 'yo']);
function stripMarkdown(text) { function stripMarkdown(text) {
if (!text) return '' if (!text) return '';
return text return text
.replace(/#{1,6}\s+/g, '') .replace(/#{1,6}\s+/g, '')
.replace(/\*\*(.*?)\*\*/gs, '$1') .replace(/\*\*(.*?)\*\*/gs, '$1')
.replace(/\*(.*?)\*/gs, '$1') .replace(/\*(.*?)\*/gs, '$1')
.replace(/__(.*?)__/gs, '$1') .replace(/__(.*?)__/gs, '$1')
.replace(/_(.*?)_/gs, '$1') .replace(/_(.*?)_/gs, '$1')
.replace(/\[([^\]]+)\]\([^\)]+\)/g, '$1') .replace(/\[([^\]]+)\]\([^)]+\)/g, '$1')
.replace(/^[>\-\*\+]\s+/gm, '') .replace(/^[>\-*+]\s+/gm, '')
.replace(/\n{3,}/g, '\n\n') .replace(/\n{3,}/g, '\n\n')
.trim() .trim();
} }
// Détecte si une transcription est probablement en français plutôt qu'en KA. // Détecte si une transcription est probablement en français plutôt qu'en KA.
// Heuristique : si les pronoms personnels français représentent > 4 % des mots. // Heuristique : si les pronoms personnels français représentent > 4 % des mots.
const FR_PRONOUNS = new Set(['je', 'tu', 'il', 'elle', 'nous', 'vous', 'ils', 'elles']) const FR_PRONOUNS = new Set(['je', 'tu', 'il', 'elle', 'nous', 'vous', 'ils', 'elles']);
function suspectFrench(text) { function suspectFrench(text) {
if (!text) return false if (!text) return false;
const words = text.toLowerCase().match(/\b[a-zàâäéèêëîïôöùûüç]+\b/g) || [] const words = text.toLowerCase().match(/\b[a-zàâäéèêëîïôöùûüç]+\b/g) || [];
if (words.length < 10) return false if (words.length < 10) return false;
const frCount = words.filter(w => FR_PRONOUNS.has(w)).length const frCount = words.filter(w => FR_PRONOUNS.has(w)).length;
return frCount / words.length > 0.04 return frCount / words.length > 0.04;
} }
const sleep = ms => new Promise(resolve => setTimeout(resolve, ms)) const sleep = ms => new Promise(resolve => setTimeout(resolve, ms));
class Translator { class Translator {
constructor() { constructor() {
this.deeplApi = process.env.DEEPL_URL || 'api-free.deepl.com' this.deeplApi = process.env.DEEPL_URL || 'api-free.deepl.com';
this.deeplKey = process.env.DEEPL_KEY this.deeplKey = process.env.DEEPL_KEY;
this.urlRequest = `https://${this.deeplApi}/v2/translate` this.urlRequest = `https://${this.deeplApi}/v2/translate`;
} }
async get(origin, target, text) { async get(origin, target, text) {
@@ -64,37 +80,42 @@ class Translator {
text: Array.isArray(text) ? text : [text], text: Array.isArray(text) ? text : [text],
source_lang: origin, source_lang: origin,
target_lang: target, target_lang: target,
}) }),
}) signal: AbortSignal.timeout(15_000)
});
if (!response.ok) { if (!response.ok) {
const body = await response.text() const body = await response.text();
console.error('DeepL error:', body) console.error('DeepL error:', body);
throw new Error(`DeepL ${response.status}: ${body}`) throw new Error(`DeepL ${response.status}: ${body}`);
} }
return await response.json() return await response.json();
} }
} }
const translator = new Translator() const translator = new Translator();
module.exports = createCoreService('api::parole.parole', ({strapi}) => ({ module.exports = createCoreService('api::parole.parole', ({strapi}) => ({
async translate(origin, target, text) { async translate(origin, target, text) {
const data = await translator.get(origin, target, text) const data = await translator.get(origin, target, text);
return data.translations[0].text return data.translations[0].text;
}, },
async translateLyrics(parolesFR) { async translateLyrics(parolesFR) {
const result = { francais: parolesFR } const result = { francais: parolesFR };
for (const lang of ALL_LANGS) { for (const lang of ALL_LANGS) {
if (lang === 'fr') continue if (NO_AUTO_TRANSLATE.has(lang)) continue;
const { field, deeplTarget, suffix } = LANG_MAP[lang] const { field, deeplTarget, suffix } = LANG_MAP[lang];
const translated = await this.translate('FR', deeplTarget, parolesFR) try {
result[field] = translated + suffix const translated = await this.translate('FR', deeplTarget, parolesFR);
result[field] = translated + suffix;
} catch (err) {
strapi.log.error(`DeepL (${deeplTarget}): ${err.message}`);
}
} }
return result return result;
}, },
validateParoles(titre, transcription) { validateParoles(titre, transcription) {
if (!titre || titre.trim().length === 0) { if (!titre || titre.trim().length === 0) {
@@ -102,77 +123,77 @@ module.exports = createCoreService('api::parole.parole', ({strapi}) => ({
} }
if (!transcription || transcription.trim().length === 0) { if (!transcription || transcription.trim().length === 0) {
throw new ApplicationError('Champ obligatoire. Veuillez renseigner la transcription.') throw new ApplicationError('Champ obligatoire. Veuillez renseigner la transcription.');
} }
if (transcription.trim().length < 10) { if (transcription.trim().length < 10) {
throw new ApplicationError('La transcription doit contenir au moins 10 caractères.') throw new ApplicationError('La transcription doit contenir au moins 10 caractères.');
} }
}, },
async fetchAllParoles() { async fetchAllParoles() {
const pageSize = 100 const pageSize = 100;
let start = 0 let start = 0;
const all = [] const all = [];
while (true) { for (;;) {
const batch = await strapi.documents('api::parole.parole').findMany({ const batch = await strapi.documents('api::parole.parole').findMany({
status: 'published', status: 'published',
populate: ['artistes', 'traductions'], populate: ['artistes', 'traductions'],
fields: ['documentId', 'titre', 'slug', 'transcription', 'annee', 'langueSource'], fields: ['documentId', 'titre', 'slug', 'transcription', 'annee', 'langueSource'],
limit: pageSize, limit: pageSize,
start, start,
}) });
all.push(...batch) all.push(...batch);
if (batch.length < pageSize) break if (batch.length < pageSize) break;
start += pageSize start += pageSize;
} }
return all return all;
}, },
buildExport(paroles, type, langs) { buildExport(paroles, type, langs) {
const targetLangs = langs && langs.length ? langs : ALL_LANGS const targetLangs = langs && langs.length ? langs : ALL_LANGS;
const pairs = [] const pairs = [];
const missing = [] const missing = [];
const nonKa = [] const nonKa = [];
const langCounts = {} const langCounts = {};
for (const parole of paroles) { for (const parole of paroles) {
const source = stripMarkdown(parole.transcription) const source = stripMarkdown(parole.transcription);
const sourceLang = parole.langueSource || 'ka' const sourceLang = parole.langueSource || 'ka';
const artists = (parole.artistes || []).map(a => a.alias) const artists = (parole.artistes || []).map(a => a.alias);
const paroleMeta = { title: parole.titre, artists } const paroleMeta = { title: parole.titre, artists };
if (sourceLang !== 'ka') { if (sourceLang !== 'ka') {
nonKa.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, suspected_lang: sourceLang }) nonKa.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, suspected_lang: sourceLang });
} else if (suspectFrench(source)) { } else if (suspectFrench(source)) {
nonKa.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, suspected_lang: 'fr' }) nonKa.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, suspected_lang: 'fr' });
} }
const missingLangs = ALL_LANGS.filter(lang => !parole.traductions?.[LANG_MAP[lang].field]) const missingLangs = ALL_LANGS.filter(lang => !parole.traductions?.[LANG_MAP[lang].field]);
if (missingLangs.length > 0) { if (missingLangs.length > 0) {
missing.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, missing: missingLangs }) missing.push({ documentId: parole.documentId, slug: parole.slug, ...paroleMeta, missing: missingLangs });
} }
for (const lang of targetLangs) { for (const lang of targetLangs) {
const { field, targetLang, userPrompt } = LANG_MAP[lang] const { field, targetLang, userPrompt } = LANG_MAP[lang];
if (lang === sourceLang) continue if (lang === sourceLang) continue;
const target = stripMarkdown(parole.traductions?.[field]) const target = stripMarkdown(parole.traductions?.[field]);
if (!target) continue if (!target) continue;
langCounts[lang] = (langCounts[lang] || 0) + 1 langCounts[lang] = (langCounts[lang] || 0) + 1;
if (type === 'instruct') { if (type === 'instruct') {
const systemPrompt = sourceLang === 'ka' const systemPrompt = sourceLang === 'ka'
? 'Tu es un expert en langue KA (créole guadeloupéen/martiniquais). Traduis le texte KA suivant.' ? 'Tu es un expert en langue KA (créole guadeloupéen/martiniquais). Traduis le texte KA suivant.'
: `Tu es un expert en traduction. Traduis le texte suivant (langue source : ${sourceLang}).` : `Tu es un expert en traduction. Traduis le texte suivant (langue source : ${sourceLang}).`;
pairs.push({ pairs.push({
messages: [ messages: [
{ role: 'system', content: systemPrompt }, { role: 'system', content: systemPrompt },
{ role: 'user', content: `${userPrompt} :\n\n${source}` }, { role: 'user', content: `${userPrompt} :\n\n${source}` },
{ role: 'assistant', content: target }, { role: 'assistant', content: target },
], ],
}) });
} else { } else {
pairs.push({ pairs.push({
source_lang: sourceLang, source_lang: sourceLang,
@@ -180,7 +201,7 @@ module.exports = createCoreService('api::parole.parole', ({strapi}) => ({
source, source,
target, target,
...paroleMeta, ...paroleMeta,
}) });
} }
} }
} }
@@ -192,60 +213,61 @@ module.exports = createCoreService('api::parole.parole', ({strapi}) => ({
languages: langCounts, languages: langCounts,
missing_translations: missing, missing_translations: missing,
non_ka_transcriptions: nonKa, non_ka_transcriptions: nonKa,
} };
return { metadata, pairs } return { metadata, pairs };
}, },
async bulkTranslateMissing() { async bulkTranslateMissing() {
const TARGET_LANGS = ALL_LANGS const TARGET_LANGS = ALL_LANGS
.filter(lang => lang !== 'fr') .filter(lang => !NO_AUTO_TRANSLATE.has(lang))
.map(lang => ({ lang, ...LANG_MAP[lang] })) .map(lang => ({ lang, ...LANG_MAP[lang] }));
const pageSize = 100 const pageSize = 100;
let start = 0 let start = 0;
const all = [] const all = [];
while (true) { for (;;) {
const batch = await strapi.documents('api::parole.parole').findMany({ const batch = await strapi.documents('api::parole.parole').findMany({
status: 'published', status: 'published',
populate: ['traductions'], populate: ['traductions'],
fields: ['documentId', 'slug', 'titre', 'transcription', 'langueSource'], fields: ['documentId', 'slug', 'titre', 'transcription', 'langueSource'],
limit: pageSize, limit: pageSize,
start, start,
}) });
all.push(...batch) all.push(...batch);
if (batch.length < pageSize) break if (batch.length < pageSize) break;
start += pageSize start += pageSize;
} }
const translated = [] const translated = [];
const skipped = [] const skipped = [];
const errors = [] const errors = [];
for (const parole of all) { for (const parole of all) {
const sourceFR = parole.traductions?.francais const sourceFR = parole.traductions?.francais
|| (parole.langueSource === 'fr' ? parole.transcription : null) || (parole.langueSource === 'fr' ? parole.transcription : null);
if (!sourceFR) { skipped.push(parole.slug); continue } if (!sourceFR) { skipped.push(parole.slug); continue; }
const missing = TARGET_LANGS.filter(({ field }) => !parole.traductions?.[field]) const missing = TARGET_LANGS.filter(({ field }) => !parole.traductions?.[field]);
if (missing.length === 0) { skipped.push(parole.slug); continue } if (missing.length === 0) { skipped.push(parole.slug); continue; }
const { id: _id, ...tradData } = parole.traductions || {} // eslint-disable-next-line no-unused-vars -- id exclu intentionnellement du spread
const updatedTrad = { ...tradData } const { id: _id, ...tradData } = parole.traductions || {};
const addedLangs = [] const updatedTrad = { ...tradData };
const addedLangs = [];
for (const { lang, field, deeplTarget, suffix } of missing) { for (const { lang, field, deeplTarget, suffix } of missing) {
try { try {
await sleep(700) await sleep(700);
const result = await translator.get('FR', deeplTarget, sourceFR) const result = await translator.get('FR', deeplTarget, sourceFR);
const text = result?.translations?.[0]?.text const text = result?.translations?.[0]?.text;
if (text) { if (text) {
updatedTrad[field] = text + suffix updatedTrad[field] = text + suffix;
addedLangs.push(lang) addedLangs.push(lang);
} }
} catch (err) { } catch (err) {
errors.push({ slug: parole.slug, lang: deeplTarget, error: err.message }) errors.push({ slug: parole.slug, lang: deeplTarget, error: err.message });
} }
} }
@@ -253,28 +275,28 @@ module.exports = createCoreService('api::parole.parole', ({strapi}) => ({
await strapi.documents('api::parole.parole').update({ await strapi.documents('api::parole.parole').update({
documentId: parole.documentId, documentId: parole.documentId,
data: { traductions: updatedTrad }, data: { traductions: updatedTrad },
}) });
await strapi.documents('api::parole.parole').publish({ await strapi.documents('api::parole.parole').publish({
documentId: parole.documentId, documentId: parole.documentId,
}) });
translated.push({ slug: parole.slug, langs: addedLangs }) translated.push({ slug: parole.slug, langs: addedLangs });
} }
} }
return { translated, skipped, errors } return { translated, skipped, errors };
}, },
parolesDiff(titre = '', oldString, newString) { parolesDiff(titre = '', oldString, newString) {
const patch = Diff.createPatch(titre, oldString, newString, 'supprimée', 'ajoutée') const patch = Diff.createPatch(titre, oldString, newString, 'supprimée', 'ajoutée');
const parsePatch = Diff.parsePatch(patch) const parsePatch = Diff.parsePatch(patch);
if (parsePatch[0].hunks.length > 0) { if (parsePatch[0].hunks.length > 0) {
const jsonDiff = Diff.diffWords(oldString, newString) const jsonDiff = Diff.diffWords(oldString, newString);
return { return {
patch, patch,
jsonDiff jsonDiff
} };
} }
} }
})); }));
+5 -5
View File
@@ -1,15 +1,15 @@
'use strict'; 'use strict';
module.exports = { module.exports = {
async count(ctx, next) { async count() {
const countArtiste = await strapi.documents('api::artiste.artiste').count({ const countArtiste = await strapi.documents('api::artiste.artiste').count({
publicationState: 'live' publicationState: 'live'
}) });
const countParole = await strapi.documents('api::parole.parole').count({ const countParole = await strapi.documents('api::parole.parole').count({
publicationState: 'live' publicationState: 'live'
}) });
return {countArtiste, countParole} return {countArtiste, countParole};
} }
} };
+1 -1
View File
@@ -9,4 +9,4 @@ module.exports = {
} }
} }
] ]
} };
+51 -6
View File
@@ -7,9 +7,60 @@
}, },
"options": {}, "options": {},
"attributes": { "attributes": {
"ayisyen": {
"type": "richtext"
},
"francais": { "francais": {
"type": "richtext" "type": "richtext"
}, },
"yoruba": {
"type": "richtext"
},
"lingala": {
"type": "richtext"
},
"wolof": {
"type": "richtext"
},
"swahili": {
"type": "richtext"
},
"hausa": {
"type": "richtext"
},
"arabe": {
"type": "richtext"
},
"oromo": {
"type": "richtext"
},
"igbo": {
"type": "richtext"
},
"zoulou": {
"type": "richtext"
},
"malgache": {
"type": "richtext"
},
"xhosa": {
"type": "richtext"
},
"tswana": {
"type": "richtext"
},
"tsonga": {
"type": "richtext"
},
"sesotho": {
"type": "richtext"
},
"japonais": {
"type": "richtext"
},
"coreen": {
"type": "richtext"
},
"anglais": { "anglais": {
"type": "richtext" "type": "richtext"
}, },
@@ -24,12 +75,6 @@
}, },
"portugais": { "portugais": {
"type": "richtext" "type": "richtext"
},
"japonais": {
"type": "richtext"
},
"coreen": {
"type": "richtext"
} }
} }
} }
@@ -1,87 +0,0 @@
'use strict';
const yup = require('yup');
module.exports = (plugin) => {
/**
* Validation custom (équivalent Strapi)
*/
const registerSchema = yup.object({
username: yup.string().required(),
email: yup.string().email().required(),
password: yup.string().min(6).required(),
});
const validateRegisterBody = async (data) => {
try {
return await registerSchema.validate(data, {
abortEarly: false,
stripUnknown: true,
});
} catch (err) {
const message = err.errors.join(', ');
throw new Error(message);
}
};
/**
* Override du controller register
*/
plugin.controllers.auth.register = async (ctx) => {
const { body } = ctx.request;
// 🔒 1. Validation
let params;
try {
params = await validateRegisterBody(body);
} catch (err) {
return ctx.badRequest(err.message);
}
const { email, username, password } = params;
// 🔎 2. Vérifier si user existe déjà
const userService = strapi.service('plugin::users-permissions.user');
const existingUser = await userService.fetchAll({
filters: {
$or: [{ email }, { username }],
},
});
if (existingUser.length > 0) {
return ctx.badRequest('Email or Username already taken');
}
// ⚙️ 3. Récupérer rôle "authenticated"
const role = await strapi
.query('plugin::users-permissions.role')
.findOne({ where: { type: 'authenticated' } });
if (!role) {
return ctx.badRequest('Default role not found');
}
// 👤 4. Création user
const newUser = await userService.add({
username,
email,
password,
role: role.id,
confirmed: false,
});
// 🔑 5. Générer JWT
const jwtService = strapi.service('plugin::users-permissions.jwt');
const token = jwtService.issue({ id: newUser.id });
// 📤 6. Réponse
ctx.send({
jwt: token,
user: newUser,
});
};
return plugin;
};
@@ -0,0 +1,73 @@
import {describe, it, expect, vi} from 'vitest';
const {default: isDocumentOwner} = await import('../is-document-owner.js');
function buildStrapi({jwtUserId, document}) {
const dbQuery = {
findOne: vi.fn(async () => document)
};
return {
plugins: {
'users-permissions': {
services: {
jwt: {
getToken: vi.fn(async () => ({id: jwtUserId}))
}
}
}
},
db: {
query: vi.fn(() => dbQuery)
},
dbQuery
};
}
function buildPolicyContext({authorization = 'Bearer faketoken', paramId, bodyDocumentId} = {}) {
return {
params: paramId ? {id: paramId} : {},
request: {
header: authorization ? {authorization} : {},
body: {data: {documentId: bodyDocumentId}}
}
};
}
describe('is-document-owner policy', () => {
it('refuse quand aucun en-tête d\'autorisation n\'est présent', async () => {
const strapi = buildStrapi({jwtUserId: 1, document: {documentId: 'doc-1', user: {id: 1}}});
const policyContext = buildPolicyContext({authorization: null, paramId: 'doc-1'});
await expect(isDocumentOwner(policyContext, {uid: 'api::parole.parole'}, {strapi})).rejects.toThrow('Opération non autorisée');
});
it('autorise quand le user du JWT est le propriétaire du document (id dans les params)', async () => {
const strapi = buildStrapi({jwtUserId: 1, document: {documentId: 'doc-1', user: {id: 1}}});
const policyContext = buildPolicyContext({paramId: 'doc-1'});
await expect(isDocumentOwner(policyContext, {uid: 'api::parole.parole'}, {strapi})).resolves.toBe(true);
expect(strapi.dbQuery.findOne).toHaveBeenCalledWith({where: {documentId: 'doc-1'}, populate: {user: true}});
});
it('autorise quand le documentId vient du corps de la requête (cas du contrôleur parole.update)', async () => {
const strapi = buildStrapi({jwtUserId: 1, document: {documentId: 'doc-1', user: {id: 1}}});
const policyContext = buildPolicyContext({bodyDocumentId: 'doc-1'});
await expect(isDocumentOwner(policyContext, {uid: 'api::parole.parole'}, {strapi})).resolves.toBe(true);
});
it('refuse quand le user du JWT n\'est pas le propriétaire du document', async () => {
const strapi = buildStrapi({jwtUserId: 999, document: {documentId: 'doc-1', user: {id: 1}}});
const policyContext = buildPolicyContext({paramId: 'doc-1'});
await expect(isDocumentOwner(policyContext, {uid: 'api::parole.parole'}, {strapi})).rejects.toThrow('Opération non autorisée');
});
it('refuse quand le document ciblé n\'existe pas', async () => {
const strapi = buildStrapi({jwtUserId: 1, document: null});
const policyContext = buildPolicyContext({paramId: 'doc-inconnu'});
await expect(isDocumentOwner(policyContext, {uid: 'api::parole.parole'}, {strapi})).rejects.toThrow('Ressource introuvable.');
});
});
@@ -0,0 +1,68 @@
import {describe, it, expect, vi} from 'vitest';
const {default: isPayloadOwner} = await import('../is-payload-owner.js');
function buildStrapi(jwtUserId) {
return {
plugins: {
'users-permissions': {
services: {
jwt: {
getToken: vi.fn(async () => ({id: jwtUserId}))
}
}
}
}
};
}
function buildPolicyContext({authorization, payloadUserId}) {
return {
request: {
header: authorization ? {authorization} : {},
body: {data: {user: {id: payloadUserId}}}
}
};
}
describe('is-payload-owner policy', () => {
it('refuse quand aucun en-tête d\'autorisation n\'est présent', async () => {
const strapi = buildStrapi(999);
const policyContext = buildPolicyContext({authorization: undefined, payloadUserId: 1});
await expect(isPayloadOwner(policyContext, {}, {strapi})).rejects.toThrow('Opération non autorisée');
});
it('autorise quand le user du JWT correspond au user du payload', async () => {
const strapi = buildStrapi(1);
const policyContext = buildPolicyContext({authorization: 'Bearer faketoken', payloadUserId: 1});
await expect(isPayloadOwner(policyContext, {}, {strapi})).resolves.toBe(true);
});
it('refuse quand le user du JWT ne correspond pas au user du payload', async () => {
const strapi = buildStrapi(999);
const policyContext = buildPolicyContext({authorization: 'Bearer faketoken', payloadUserId: 1});
await expect(isPayloadOwner(policyContext, {}, {strapi})).rejects.toThrow('Opération non autorisée');
});
it('refuse quand le token est invalide', async () => {
const strapi = {
plugins: {
'users-permissions': {
services: {
jwt: {
getToken: vi.fn(async () => {
throw new Error('Invalid token.');
})
}
}
}
}
};
const policyContext = buildPolicyContext({authorization: 'Bearer faketoken', payloadUserId: 1});
await expect(isPayloadOwner(policyContext, {}, {strapi})).rejects.toThrow('Opération non autorisée');
});
});
+35
View File
@@ -0,0 +1,35 @@
'use strict';
const { UnauthorizedError, NotFoundError } = require('@strapi/utils').errors;
module.exports = async (policyContext, config, {strapi}) => {
const {request, params} = policyContext;
if (!request?.header?.authorization) {
throw new UnauthorizedError('Opération non autorisée');
}
let jwtUserId;
try {
({id: jwtUserId} = await strapi.plugins['users-permissions'].services.jwt.getToken(policyContext));
} catch (err) {
throw new UnauthorizedError('Opération non autorisée');
}
const documentId = params?.id ?? request.body?.data?.documentId;
const document = await strapi.db.query(config.uid).findOne({
where: {documentId},
populate: {user: true}
});
if (!document) {
throw new NotFoundError('Ressource introuvable.');
}
if (document.user?.id !== jwtUserId) {
throw new UnauthorizedError('Opération non autorisée');
}
return true;
};
+23
View File
@@ -0,0 +1,23 @@
'use strict';
const { UnauthorizedError } = require('@strapi/utils').errors;
module.exports = async (policyContext, config, {strapi}) => {
const {request} = policyContext;
if (!request?.header?.authorization) {
throw new UnauthorizedError('Opération non autorisée');
}
try {
const {id} = await strapi.plugins['users-permissions'].services.jwt.getToken(policyContext);
if (id !== request.body?.data?.user?.id) {
throw new UnauthorizedError('Opération non autorisée');
}
} catch (err) {
throw new UnauthorizedError('Opération non autorisée');
}
return true;
};
@@ -0,0 +1,75 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
import {backfillBokanteMirror} from '../backfill-bokante-mirrors.js';
const bokanteMastodon = require('../bokante-mastodon.js');
function buildStrapi({paroles = []} = {}) {
const updateMany = vi.fn();
return {
db: {
query: () => ({
findMany: vi.fn(async ({where, orderBy, limit}) => {
expect(where).toEqual({
publishedAt: {$notNull: true},
bokanteStatusId: {$null: true}
});
expect(orderBy).toEqual({publishedAt: 'asc'});
expect(limit).toBe(1);
return paroles.slice(0, limit);
}),
updateMany
})
},
log: {error: vi.fn(), info: vi.fn()}
};
}
describe('backfillBokanteMirror', () => {
const originalCreateStatus = bokanteMastodon.createStatus;
afterEach(() => {
bokanteMastodon.createStatus = originalCreateStatus;
});
it('publie le miroir pour la parole publiée la plus ancienne sans bokanteStatusId', async () => {
bokanteMastodon.createStatus = vi.fn(async () => ({id: '112233'}));
const parole = {documentId: 'doc-1', titre: 'Vieux titre', slug: 'vieux-titre'};
const strapi = buildStrapi({paroles: [parole]});
const result = await backfillBokanteMirror({strapi});
expect(bokanteMastodon.createStatus).toHaveBeenCalledTimes(1);
expect(bokanteMastodon.createStatus.mock.calls[0][0]).toContain('Vieux titre');
expect(bokanteMastodon.createStatus.mock.calls[0][0]).not.toContain('nouvelle parole');
expect(strapi.db.query().updateMany).toHaveBeenCalledWith({
where: {documentId: 'doc-1'},
data: {bokanteStatusId: '112233'}
});
expect(result).toEqual({backfilled: true, slug: 'vieux-titre'});
});
it('ne fait rien si le catalogue est déjà rattrapé', async () => {
bokanteMastodon.createStatus = vi.fn();
const strapi = buildStrapi({paroles: []});
const result = await backfillBokanteMirror({strapi});
expect(bokanteMastodon.createStatus).not.toHaveBeenCalled();
expect(result).toEqual({backfilled: false});
});
it('n\'interrompt rien si bokante échoue, et ne marque pas la parole comme traitée', async () => {
bokanteMastodon.createStatus = vi.fn(async () => {
throw new Error('boom');
});
const parole = {documentId: 'doc-1', titre: 'Titre', slug: 'titre'};
const strapi = buildStrapi({paroles: [parole]});
const result = await backfillBokanteMirror({strapi});
expect(strapi.log.error).toHaveBeenCalledWith(expect.stringContaining('titre'));
expect(strapi.db.query().updateMany).not.toHaveBeenCalled();
expect(result).toEqual({backfilled: false});
});
});
@@ -0,0 +1,62 @@
import {describe, it, expect, afterEach} from 'vitest';
import fs from 'fs';
import os from 'os';
import path from 'path';
import {backupDatabase} from '../backup-database.js';
const tmpDirs = [];
function makeTmpDir() {
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'backup-database-test-'));
tmpDirs.push(dir);
return dir;
}
describe('backupDatabase', () => {
afterEach(() => {
for (const dir of tmpDirs.splice(0)) {
fs.rmSync(dir, {recursive: true, force: true});
}
});
it('ne fait rien quand le fichier de base n\'existe pas', () => {
const root = makeTmpDir();
const result = backupDatabase({
dbPath: path.join(root, 'inexistant.db'),
backupsDir: path.join(root, 'backups')
});
expect(result).toBeNull();
expect(fs.existsSync(path.join(root, 'backups'))).toBe(false);
});
it('copie le fichier de base dans le dossier de sauvegardes', () => {
const root = makeTmpDir();
const dbPath = path.join(root, 'data.db');
fs.writeFileSync(dbPath, 'contenu-de-la-base');
const backupsDir = path.join(root, 'backups');
const result = backupDatabase({dbPath, backupsDir});
expect(result).not.toBeNull();
expect(fs.existsSync(result)).toBe(true);
expect(fs.readFileSync(result, 'utf8')).toBe('contenu-de-la-base');
});
it('ne conserve que les 8 sauvegardes les plus récentes', () => {
const root = makeTmpDir();
const dbPath = path.join(root, 'data.db');
fs.writeFileSync(dbPath, 'contenu');
const backupsDir = path.join(root, 'backups');
fs.mkdirSync(backupsDir, {recursive: true});
for (let i = 0; i < 10; i++) {
fs.writeFileSync(path.join(backupsDir, `data-2020-01-0${i}.db`), 'ancien');
}
backupDatabase({dbPath, backupsDir});
const remaining = fs.readdirSync(backupsDir).filter(name => name.startsWith('data-'));
expect(remaining).toHaveLength(8);
});
});
@@ -0,0 +1,73 @@
import {describe, it, expect, vi, afterEach, beforeEach} from 'vitest';
import {createStatus, getStatusContext} from '../bokante-mastodon.js';
describe('bokante-mastodon', () => {
const originalFetch = global.fetch;
const originalEnv = {...process.env};
beforeEach(() => {
process.env.BOKANTE_INSTANCE_URL = 'https://bokante.o-k-i.net';
process.env.BOKANTE_ACCESS_TOKEN = 'test-token';
});
afterEach(() => {
global.fetch = originalFetch;
process.env = {...originalEnv};
vi.restoreAllMocks();
});
describe('createStatus', () => {
it('poste le statut avec le bon endpoint, jeton et corps', async () => {
global.fetch = vi.fn(async () => ({
ok: true,
json: async () => ({id: '112233', url: 'https://bokante.o-k-i.net/@paroles/112233'})
}));
const result = await createStatus('Nouvelle parole : "Titre"');
const [url, options] = global.fetch.mock.calls[0];
expect(url).toBe('https://bokante.o-k-i.net/api/v1/statuses');
expect(options.method).toBe('POST');
expect(options.headers.Authorization).toBe('Bearer test-token');
expect(JSON.parse(options.body)).toEqual({
status: 'Nouvelle parole : "Titre"',
visibility: 'public'
});
expect(result).toEqual({id: '112233', url: 'https://bokante.o-k-i.net/@paroles/112233'});
});
it('lève une erreur claire sur réponse HTTP non-ok', async () => {
global.fetch = vi.fn(async () => ({
ok: false,
status: 422,
text: async () => 'Validation Failed'
}));
await expect(createStatus('texte')).rejects.toThrow('Mastodon 422: Validation Failed');
});
});
describe('getStatusContext', () => {
it('récupère le contexte du statut avec le bon endpoint et jeton', async () => {
const context = {ancestors: [], descendants: [{id: '1', content: '<p>coucou</p>'}]};
global.fetch = vi.fn(async () => ({ok: true, json: async () => context}));
const result = await getStatusContext('112233');
const [url, options] = global.fetch.mock.calls[0];
expect(url).toBe('https://bokante.o-k-i.net/api/v1/statuses/112233/context');
expect(options.headers.Authorization).toBe('Bearer test-token');
expect(result).toEqual(context);
});
it('lève une erreur claire sur réponse HTTP non-ok', async () => {
global.fetch = vi.fn(async () => ({
ok: false,
status: 404,
text: async () => 'Record not found'
}));
await expect(getStatusContext('inconnu')).rejects.toThrow('Mastodon 404: Record not found');
});
});
});
@@ -0,0 +1,133 @@
import {describe, it, expect, vi, afterEach} from 'vitest';
import {importBokanteComments} from '../import-bokante-comments.js';
const bokanteMastodon = require('../bokante-mastodon.js');
function buildStatus(overrides = {}) {
return {
id: 'status-1',
content: '<p>Trè bèl parol !</p>',
created_at: '2026-07-04T12:00:00.000Z',
url: 'https://bokante.o-k-i.net/@quelqun/status-1',
account: {
display_name: 'Quelqu\'un',
acct: 'quelqun@mastodon.social',
avatar: 'https://mastodon.social/avatars/quelqun.png',
url: 'https://mastodon.social/@quelqun'
},
...overrides
};
}
function buildStrapi({paroles, existingRemoteIds = [], createImpl}) {
const commentaireDocuments = {
create: createImpl || vi.fn(async ({data}) => ({id: Math.floor(Math.random() * 10_000), ...data}))
};
const paroleDocuments = {update: vi.fn(async () => ({}))};
return {
db: {
query: uid => {
if (uid === 'api::parole.parole') {
return {findMany: vi.fn(async () => paroles)};
}
if (uid === 'api::commentaire.commentaire') {
return {
findOne: vi.fn(async ({where}) => (existingRemoteIds.includes(where.remoteId) ? {id: 1} : null))
};
}
return {};
}
},
documents: uid => {
if (uid === 'api::commentaire.commentaire') return commentaireDocuments;
if (uid === 'api::parole.parole') return paroleDocuments;
return {};
},
log: {error: vi.fn()}
};
}
describe('importBokanteComments', () => {
const originalGetStatusContext = bokanteMastodon.getStatusContext;
afterEach(() => {
bokanteMastodon.getStatusContext = originalGetStatusContext;
});
it('importe les nouveaux commentaires et les connecte à la parole', async () => {
bokanteMastodon.getStatusContext = vi.fn(async () => ({descendants: [buildStatus()]}));
const paroles = [{id: 7, documentId: 'doc-7', slug: 'mon-titre', bokanteStatusId: '112233'}];
const strapi = buildStrapi({paroles});
const result = await importBokanteComments({strapi});
expect(bokanteMastodon.getStatusContext).toHaveBeenCalledWith('112233');
expect(strapi.documents('api::commentaire.commentaire').create).toHaveBeenCalledWith({
status: 'published',
data: expect.objectContaining({
contenu: 'Trè bèl parol !',
origine: 'activitypub',
auteurNom: 'Quelqu\'un',
auteurHandle: '@quelqun@mastodon.social',
auteurAvatarUrl: 'https://mastodon.social/avatars/quelqun.png',
auteurProfilUrl: 'https://mastodon.social/@quelqun',
remoteId: 'status-1',
remoteUrl: 'https://bokante.o-k-i.net/@quelqun/status-1',
parole: 7
})
});
expect(strapi.documents('api::parole.parole').update).toHaveBeenCalledWith({
documentId: 'doc-7',
status: 'published',
data: {commentaires: {connect: expect.any(Array)}}
});
expect(result.imported).toBe(1);
});
it('n\'importe pas un commentaire déjà présent (déduplication par remoteId)', async () => {
bokanteMastodon.getStatusContext = vi.fn(async () => ({descendants: [buildStatus({id: 'deja-la'})]}));
const paroles = [{id: 7, documentId: 'doc-7', slug: 'mon-titre', bokanteStatusId: '112233'}];
const strapi = buildStrapi({paroles, existingRemoteIds: ['deja-la']});
const result = await importBokanteComments({strapi});
expect(strapi.documents('api::commentaire.commentaire').create).not.toHaveBeenCalled();
expect(strapi.documents('api::parole.parole').update).not.toHaveBeenCalled();
expect(result.imported).toBe(0);
});
it('ignore les statuts marqués sensitive', async () => {
bokanteMastodon.getStatusContext = vi.fn(async () => ({descendants: [buildStatus({sensitive: true})]}));
const paroles = [{id: 7, documentId: 'doc-7', slug: 'mon-titre', bokanteStatusId: '112233'}];
const strapi = buildStrapi({paroles});
const result = await importBokanteComments({strapi});
expect(strapi.documents('api::commentaire.commentaire').create).not.toHaveBeenCalled();
expect(result.imported).toBe(0);
});
it('continue les autres paroles quand une requête bokante échoue', async () => {
bokanteMastodon.getStatusContext = vi.fn(async statusId => {
if (statusId === 'echoue') {
throw new Error('Mastodon 500: boom');
}
return {descendants: [buildStatus({id: 'ok-1'})]};
});
const paroles = [
{id: 1, documentId: 'doc-1', slug: 'echoue', bokanteStatusId: 'echoue'},
{id: 2, documentId: 'doc-2', slug: 'reussi', bokanteStatusId: 'ok'}
];
const strapi = buildStrapi({paroles});
const result = await importBokanteComments({strapi});
expect(strapi.log.error).toHaveBeenCalledWith(expect.stringContaining('echoue'));
expect(result.imported).toBe(1);
});
});
+36
View File
@@ -0,0 +1,36 @@
'use strict';
const bokanteMastodon = require('./bokante-mastodon');
async function backfillBokanteMirror({strapi}) {
const [parole] = await strapi.db.query('api::parole.parole').findMany({
where: {
publishedAt: {$notNull: true},
bokanteStatusId: {$null: true}
},
orderBy: {publishedAt: 'asc'},
limit: 1
});
if (!parole) {
return {backfilled: false};
}
try {
const status = await bokanteMastodon.createStatus(
`"${parole.titre}" — à (re)découvrir sur pawol.nu\n${process.env.WEBSITE_URL}/paroles/${parole.slug}`
);
await strapi.db.query('api::parole.parole').updateMany({
where: {documentId: parole.documentId},
data: {bokanteStatusId: status.id}
});
return {backfilled: true, slug: parole.slug};
} catch (err) {
strapi.log.error(`Backfill bokante (${parole.slug}) : ${err.message}`);
return {backfilled: false};
}
}
module.exports = {backfillBokanteMirror};
+31
View File
@@ -0,0 +1,31 @@
'use strict';
const fs = require('fs');
const path = require('path');
const RETENTION = 8;
function backupDatabase({dbPath, backupsDir}) {
if (!fs.existsSync(dbPath)) {
return null;
}
fs.mkdirSync(backupsDir, {recursive: true});
const timestamp = new Date().toISOString().replace(/[:.]/g, '-');
const backupPath = path.join(backupsDir, `data-${timestamp}.db`);
fs.copyFileSync(dbPath, backupPath);
const backups = fs.readdirSync(backupsDir)
.filter(name => name.startsWith('data-') && name.endsWith('.db'))
.sort();
const toDelete = backups.slice(0, Math.max(backups.length - RETENTION, 0));
for (const name of toDelete) {
fs.unlinkSync(path.join(backupsDir, name));
}
return backupPath;
}
module.exports = {backupDatabase};
+44
View File
@@ -0,0 +1,44 @@
'use strict';
function getConfig() {
return {
instanceUrl: process.env.BOKANTE_INSTANCE_URL || 'https://bokante.o-k-i.net',
accessToken: process.env.BOKANTE_ACCESS_TOKEN
};
}
async function mastodonFetch(url, options) {
const {accessToken} = getConfig();
const response = await fetch(url, {
...options,
headers: {
Authorization: `Bearer ${accessToken}`,
...options.headers
}
});
if (!response.ok) {
const body = await response.text();
throw new Error(`Mastodon ${response.status}: ${body}`);
}
return response.json();
}
async function createStatus(text, {visibility = 'public'} = {}) {
const {instanceUrl} = getConfig();
return mastodonFetch(`${instanceUrl}/api/v1/statuses`, {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({status: text, visibility})
});
}
async function getStatusContext(statusId) {
const {instanceUrl} = getConfig();
return mastodonFetch(`${instanceUrl}/api/v1/statuses/${statusId}/context`, {
method: 'GET'
});
}
module.exports = {createStatus, getStatusContext};
+71
View File
@@ -0,0 +1,71 @@
'use strict';
const bokanteMastodon = require('./bokante-mastodon');
function stripHtml(html) {
return (html || '').replace(/<[^>]*>/g, '').trim();
}
async function importBokanteComments({strapi}) {
const paroles = await strapi.db.query('api::parole.parole').findMany({
where: {bokanteStatusId: {$notNull: true}}
});
let imported = 0;
for (const parole of paroles) {
let context;
try {
context = await bokanteMastodon.getStatusContext(parole.bokanteStatusId);
} catch (err) {
strapi.log.error(`Import bokante (${parole.slug}) : ${err.message}`);
continue;
}
const newCommentIds = [];
for (const status of context.descendants || []) {
if (status.sensitive) {
continue;
}
const exists = await strapi.db.query('api::commentaire.commentaire').findOne({
where: {remoteId: status.id}
});
if (exists) {
continue;
}
const commentaire = await strapi.documents('api::commentaire.commentaire').create({
status: 'published',
data: {
contenu: stripHtml(status.content),
datePublication: status.created_at,
origine: 'activitypub',
auteurNom: status.account?.display_name,
auteurHandle: status.account?.acct ? `@${status.account.acct}` : undefined,
auteurAvatarUrl: status.account?.avatar,
auteurProfilUrl: status.account?.url,
remoteId: status.id,
remoteUrl: status.url,
parole: parole.id
}
});
newCommentIds.push(commentaire.id);
imported += 1;
}
if (newCommentIds.length > 0) {
await strapi.documents('api::parole.parole').update({
documentId: parole.documentId,
status: 'published',
data: {commentaires: {connect: newCommentIds}}
});
}
}
return {imported};
}
module.exports = {importBokanteComments};
+15
View File
@@ -109,12 +109,27 @@ export interface TradTraductions extends Struct.ComponentSchema {
attributes: { attributes: {
allemand: Schema.Attribute.RichText; allemand: Schema.Attribute.RichText;
anglais: Schema.Attribute.RichText; anglais: Schema.Attribute.RichText;
arabe: Schema.Attribute.RichText;
ayisyen: Schema.Attribute.RichText;
coreen: Schema.Attribute.RichText; coreen: Schema.Attribute.RichText;
espagnol: Schema.Attribute.RichText; espagnol: Schema.Attribute.RichText;
francais: Schema.Attribute.RichText; francais: Schema.Attribute.RichText;
hausa: Schema.Attribute.RichText;
igbo: Schema.Attribute.RichText;
italien: Schema.Attribute.RichText; italien: Schema.Attribute.RichText;
japonais: Schema.Attribute.RichText; japonais: Schema.Attribute.RichText;
lingala: Schema.Attribute.RichText;
malgache: Schema.Attribute.RichText;
oromo: Schema.Attribute.RichText;
portugais: Schema.Attribute.RichText; portugais: Schema.Attribute.RichText;
sesotho: Schema.Attribute.RichText;
swahili: Schema.Attribute.RichText;
tsonga: Schema.Attribute.RichText;
tswana: Schema.Attribute.RichText;
wolof: Schema.Attribute.RichText;
xhosa: Schema.Attribute.RichText;
yoruba: Schema.Attribute.RichText;
zoulou: Schema.Attribute.RichText;
}; };
} }
+14 -5
View File
@@ -488,6 +488,10 @@ export interface ApiCommentaireCommentaire extends Struct.CollectionTypeSchema {
draftAndPublish: true; draftAndPublish: true;
}; };
attributes: { attributes: {
auteurAvatarUrl: Schema.Attribute.String;
auteurHandle: Schema.Attribute.String;
auteurNom: Schema.Attribute.String;
auteurProfilUrl: Schema.Attribute.String;
contenu: Schema.Attribute.RichText & Schema.Attribute.Required; contenu: Schema.Attribute.RichText & Schema.Attribute.Required;
createdAt: Schema.Attribute.DateTime; createdAt: Schema.Attribute.DateTime;
createdBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> & createdBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> &
@@ -499,8 +503,13 @@ export interface ApiCommentaireCommentaire extends Struct.CollectionTypeSchema {
'api::commentaire.commentaire' 'api::commentaire.commentaire'
> & > &
Schema.Attribute.Private; Schema.Attribute.Private;
parole: Schema.Attribute.Relation<'oneToOne', 'api::parole.parole'>; origine: Schema.Attribute.Enumeration<['local', 'activitypub']> &
Schema.Attribute.Required &
Schema.Attribute.DefaultTo<'local'>;
parole: Schema.Attribute.Relation<'manyToOne', 'api::parole.parole'>;
publishedAt: Schema.Attribute.DateTime; publishedAt: Schema.Attribute.DateTime;
remoteId: Schema.Attribute.String & Schema.Attribute.Unique;
remoteUrl: Schema.Attribute.String;
updatedAt: Schema.Attribute.DateTime; updatedAt: Schema.Attribute.DateTime;
updatedBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> & updatedBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> &
Schema.Attribute.Private; Schema.Attribute.Private;
@@ -521,18 +530,19 @@ export interface ApiParoleParole extends Struct.CollectionTypeSchema {
}; };
options: { options: {
draftAndPublish: true; draftAndPublish: true;
populateCreatorFields: true;
}; };
attributes: { attributes: {
annee: Schema.Attribute.Integer; annee: Schema.Attribute.Integer;
artistes: Schema.Attribute.Relation<'manyToMany', 'api::artiste.artiste'>; artistes: Schema.Attribute.Relation<'manyToMany', 'api::artiste.artiste'>;
bokanteStatusId: Schema.Attribute.String;
commentaires: Schema.Attribute.Relation< commentaires: Schema.Attribute.Relation<
'oneToMany', 'oneToMany',
'api::commentaire.commentaire' 'api::commentaire.commentaire'
>; >;
couverture: Schema.Attribute.Media<'images'>; couverture: Schema.Attribute.Media<'images'>;
createdAt: Schema.Attribute.DateTime; createdAt: Schema.Attribute.DateTime;
createdBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> & createdBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'>;
Schema.Attribute.Private;
creativeCommons: Schema.Attribute.Enumeration< creativeCommons: Schema.Attribute.Enumeration<
['BY', 'BY-SA', 'BY-ND', 'BY-NC', 'BY-NC-SA', 'BY-NC-ND'] ['BY', 'BY-SA', 'BY-ND', 'BY-NC', 'BY-NC-SA', 'BY-NC-ND']
>; >;
@@ -576,8 +586,7 @@ export interface ApiParoleParole extends Struct.CollectionTypeSchema {
traductions: Schema.Attribute.Component<'trad.traductions', false>; traductions: Schema.Attribute.Component<'trad.traductions', false>;
transcription: Schema.Attribute.RichText & Schema.Attribute.Required; transcription: Schema.Attribute.RichText & Schema.Attribute.Required;
updatedAt: Schema.Attribute.DateTime; updatedAt: Schema.Attribute.DateTime;
updatedBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'> & updatedBy: Schema.Attribute.Relation<'oneToOne', 'admin::user'>;
Schema.Attribute.Private;
user: Schema.Attribute.Relation< user: Schema.Attribute.Relation<
'oneToOne', 'oneToOne',
'plugin::users-permissions.user' 'plugin::users-permissions.user'
+7
View File
@@ -0,0 +1,7 @@
import {defineConfig} from 'vitest/config'
export default defineConfig({
test: {
environment: 'node',
},
})
+769 -12
View File
File diff suppressed because it is too large Load Diff