Ильяс Султанов d0112657b8 fix(auth): живая сессия на устройстве — рефреш на холодном старте, grace-окно ротации, без логаута при временных ошибках
- /api/auth/me при 401 делает одну попытку refresh (раньше refresh-retry был
  отключён для всех /api/auth/* — холодный старт после 15 мин простоя = логаут)
- ротация: повтор старого refresh-токена в пределах RACE_TOLERANCE_MS (5 мин)
  выдаёт новую пару от successor вместо deny; cookie больше не стираются при
  stale-токенах (разлогинивались все вкладки устройства); reuse после окна —
  revoke family как раньше (тесты обновлены)
- refreshSession различает 401/403/400 (сессия мертва) vs 429/5xx/сеть
  (transient — нет logout, отложенный retry)
- единый рефреш: useAuth keep-alive и useOfflineSync переведены на refreshSession;
  межвкладочная дедупликация через BroadcastChannel('auth-refresh')
- refreshLimiter: keyGenerator buildRateLimitKey (per-user, не общий IP-бакет офиса)
2026-09-17 21:59:51 +03:00

iistwin

CI Node.js License PostgreSQL PRs Welcome

A multitenant corporate iistwin platform with a React frontend and an Express backend. It provides organizations with independent management of users, projects, and tasks on shared infrastructure, featuring data isolation, real-time communication, and customizable workflow automation.

Quickstart

cp .env.example .env   # fill in DATABASE_URL, JWT_SECRET, SESSION_SECRET
npm install && npm run db:push && npm run dev

The app will be available at http://localhost:5000.

Key Features

  • Custom forms with configurable statuses, transitions, and conditional approvals
  • Hierarchical subtasks with unlimited nesting
  • Real-time chat with @mentions and Server-Sent Events
  • Inline-editable data tables with Excel import/export
  • JavaScript-powered custom tabs and layout components
  • Event-driven notification system (in-app, email, push)
  • Multi-tenant billing management
  • Progressive Web App (PWA) support

Getting Started

Prerequisites

  • Node.js 20+
  • PostgreSQL 15+ (or use the built-in Docker Postgres profile — see below)

Local development (without Docker)

  1. Copy the environment template and fill in the required values:

    cp .env.example .env
    
  2. Install dependencies:

    npm install
    
  3. Push the database schema:

    npm run db:push
    
  4. Start the development server:

    npm run dev
    

    The app will be available at http://localhost:5000.

Running with Docker

For Docker-based setup (including a built-in managed Postgres option), see DOCKER.md.

It covers:

  • Mode 1 — connecting to an external database (e.g. Neon Cloud)
  • Mode 2 — letting Docker spin up a local Postgres 16 container alongside the app

Environment Variables

See .env.example for all required environment variables. At minimum you will need:

Variable Description
DATABASE_URL PostgreSQL connection string
JWT_SECRET Secret used to sign access tokens
SESSION_SECRET Secret used for session cookies
VAPID_PUBLIC_KEY Web Push VAPID public key
VAPID_PRIVATE_KEY Web Push VAPID private key

Super Admin

A system-level super admin panel is available at /superadmin. The first super admin account can be created via POST /api/superadmin/seed (optionally protected by the SUPERADMIN_SEED_TOKEN environment variable).

Description
iistwin CRM — зеркало исходников (хранение в РФ, реестр Минцифры)
Readme 23 MiB
Languages
TypeScript 98.1%
CSS 0.8%
JavaScript 0.7%
Shell 0.2%
Python 0.1%