Ильяс Султанов 06bfd2aa75
Some checks are pending
Branch Check / Type Check & Build (push) Waiting to run
feat(auth): шаг 0.6 — TTL access 15 минут + хэширование refresh/reset-токенов в БД
- server/utils/jwt.ts: дефолт JWT_ACCESS_EXPIRES 30d → 15m (env сохранено), hashToken() (sha256 hex)
- migrations/0082_token_hashes.sql: *_hash колонки в user_sessions/users, DELETE FROM user_sessions (глобальный разлогин), legacy plain-колонки сохранены, но не пишутся
- storage: lookup/отзыв сессий и reset-токенов по хэшу; markSessionReplaced по id сессии
- auth.service: ротация в rotateFamilySession(), grace-period ротирует активную сессию вместо возврата plain-токена
- auth.core.routes: forgot/reset-password пишут/ищут sha256-хэш, plain только в письме
- tests/token-security.test.ts: 12 тестов (выпуск по хэшу, ротация, reuse detection, grace, reset)
- .env.example, swagger, IMPLEMENTATION_LOG.md обновлены

Проверки: npm run check чисто, vitest 118/118, lint 0 errors, build собирается
2026-09-08 11:35:32 +03:00

iistwin

CI Node.js License PostgreSQL PRs Welcome

A multitenant corporate iistwin platform with a React frontend and an Express backend. It provides organizations with independent management of users, projects, and tasks on shared infrastructure, featuring data isolation, real-time communication, and customizable workflow automation.

Quickstart

cp .env.example .env   # fill in DATABASE_URL, JWT_SECRET, SESSION_SECRET
npm install && npm run db:push && npm run dev

The app will be available at http://localhost:5000.

Key Features

  • Custom forms with configurable statuses, transitions, and conditional approvals
  • Hierarchical subtasks with unlimited nesting
  • Real-time chat with @mentions and Server-Sent Events
  • Inline-editable data tables with Excel import/export
  • JavaScript-powered custom tabs and layout components
  • Event-driven notification system (in-app, email, push)
  • Multi-tenant billing management
  • Progressive Web App (PWA) support

Getting Started

Prerequisites

  • Node.js 20+
  • PostgreSQL 15+ (or use the built-in Docker Postgres profile — see below)

Local development (without Docker)

  1. Copy the environment template and fill in the required values:

    cp .env.example .env
    
  2. Install dependencies:

    npm install
    
  3. Push the database schema:

    npm run db:push
    
  4. Start the development server:

    npm run dev
    

    The app will be available at http://localhost:5000.

Running with Docker

For Docker-based setup (including a built-in managed Postgres option), see DOCKER.md.

It covers:

  • Mode 1 — connecting to an external database (e.g. Neon Cloud)
  • Mode 2 — letting Docker spin up a local Postgres 16 container alongside the app

Environment Variables

See .env.example for all required environment variables. At minimum you will need:

Variable Description
DATABASE_URL PostgreSQL connection string
JWT_SECRET Secret used to sign access tokens
SESSION_SECRET Secret used for session cookies
VAPID_PUBLIC_KEY Web Push VAPID public key
VAPID_PRIVATE_KEY Web Push VAPID private key

Super Admin

A system-level super admin panel is available at /superadmin. The first super admin account can be created via POST /api/superadmin/seed (optionally protected by the SUPERADMIN_SEED_TOKEN environment variable).

Description
iistwin CRM — зеркало исходников (хранение в РФ, реестр Минцифры)
Readme 23 MiB
Languages
TypeScript 98.1%
CSS 0.8%
JavaScript 0.7%
Shell 0.2%
Python 0.1%