mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Limit SAV ticket creation to administrative roles
Adjust SAV ticket creation permissions on both frontend and backend to restrict the 'employee' role, allowing only 'admin', 'directeur', and 'manager' roles to create tickets. Replit-Commit-Author: Agent Replit-Commit-Session-Id: f9197b9b-a5b3-4469-a27d-930a9e9ee736 Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/f9197b9b-a5b3-4469-a27d-930a9e9ee736/i2gFnxm
This commit is contained in:
1 parent
2ff22c4821
commit
2028f761f3
2 files changed
+4
-3
No files matched your search
@@ -259,6 +259,7 @@ export default function SavTickets() {
|
||||
|
||||
// Check permissions AFTER all hooks are called
|
||||
const canView = ['admin', 'directeur', 'manager', 'employee'].includes(user?.role || '');
|
||||
const canCreate = ['admin', 'directeur', 'manager'].includes(user?.role || ''); // Employee can only view
|
||||
const canModify = ['admin', 'directeur', 'manager'].includes(user?.role || '');
|
||||
const canDelete = ['admin', 'directeur'].includes(user?.role || '');
|
||||
|
||||
@@ -436,7 +437,7 @@ export default function SavTickets() {
|
||||
<h1 className="text-2xl sm:text-3xl font-bold text-gray-900">Service Après-Vente</h1>
|
||||
<p className="text-gray-600 mt-1">Gestion des tickets SAV et suivi des réparations</p>
|
||||
</div>
|
||||
{canModify && (
|
||||
{canCreate && (
|
||||
<Dialog open={showCreateModal} onOpenChange={setShowCreateModal}>
|
||||
<DialogTrigger asChild>
|
||||
<Button className="w-full sm:w-auto">
|
||||
|
||||
+2
-2
@@ -2688,8 +2688,8 @@ RÉSUMÉ DU SCAN
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
// Check permissions: admin, manager, directeur, employee can create
|
||||
if (!['admin', 'manager', 'directeur', 'employee'].includes(user.role)) {
|
||||
// Check permissions: admin, manager, directeur can create (employee can only view)
|
||||
if (!['admin', 'manager', 'directeur'].includes(user.role)) {
|
||||
return res.status(403).json({ message: "Insufficient permissions to create tickets" });
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user