Проблема: прямое скачивание /api/files/<key> с X-Api-Key давало 403 (файловые эндпоинты принимали только JWT), а get_task_file отвечал «не отслеживается» — 77 файлов со старыми АБСОЛЮТНЫМИ URL (https://iistwin.ru/api/files/...) не попадали в file_uploads: startup-backfill понимал только относительные ссылки. - tryPresignedOrAuth: ветка X-Api-Key — resolve ключа, req.apiKey/organizationId, tenant-контекст; владение проверяет canAccessFile, скоупы форм — новый checkApiKeyFileScope (файл привязан к задаче → форма должна быть разрешена ключом); - /api/files/:key/presigned теперь тоже через tryPresignedOrAuth (боты могут выпускать presigned-ссылки); - server/utils/file-tracking.ts: trackFileOnDemand — догрузка по требованию из task_field_values/task_messages по ссылке любого вида; используется в canAccessFile и MCP get_task_file; - startup-backfill: паттерны покрывают абсолютные URL (substring FROM regex).
iistwin
A multitenant corporate iistwin platform with a React frontend and an Express backend. It provides organizations with independent management of users, projects, and tasks on shared infrastructure, featuring data isolation, real-time communication, and customizable workflow automation.
Quickstart
cp .env.example .env # fill in DATABASE_URL, JWT_SECRET, SESSION_SECRET
npm install && npm run db:push && npm run dev
The app will be available at http://localhost:5000.
Key Features
- Custom forms with configurable statuses, transitions, and conditional approvals
- Hierarchical subtasks with unlimited nesting
- Real-time chat with
@mentionsand Server-Sent Events - Inline-editable data tables with Excel import/export
- JavaScript-powered custom tabs and layout components
- Event-driven notification system (in-app, email, push)
- Multi-tenant billing management
- Progressive Web App (PWA) support
Getting Started
Prerequisites
- Node.js 20+
- PostgreSQL 15+ (or use the built-in Docker Postgres profile — see below)
Local development (without Docker)
-
Copy the environment template and fill in the required values:
cp .env.example .env -
Install dependencies:
npm install -
Push the database schema:
npm run db:push -
Start the development server:
npm run devThe app will be available at
http://localhost:5000.
Running with Docker
For Docker-based setup (including a built-in managed Postgres option), see DOCKER.md.
It covers:
- Mode 1 — connecting to an external database (e.g. Neon Cloud)
- Mode 2 — letting Docker spin up a local Postgres 16 container alongside the app
Environment Variables
See .env.example for all required environment variables. At minimum you will need:
| Variable | Description |
|---|---|
DATABASE_URL |
PostgreSQL connection string |
JWT_SECRET |
Secret used to sign access tokens |
SESSION_SECRET |
Secret used for session cookies |
VAPID_PUBLIC_KEY |
Web Push VAPID public key |
VAPID_PRIVATE_KEY |
Web Push VAPID private key |
Super Admin
A system-level super admin panel is available at /superadmin. The first super admin account can be created via POST /api/superadmin/seed (optionally protected by the SUPERADMIN_SEED_TOKEN environment variable).