Restrict director access to only their assigned groups

Update the application logic to filter deliveries, allowing only administrators to view all data, while directors can only access deliveries within their assigned groups.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 28b81ac1-a55f-409c-b6a9-88ad420d8a9a
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/28b81ac1-a55f-409c-b6a9-88ad420d8a9a/hAUonZr
This commit is contained in:
michaelschal committed 2025-09-03 09:11:45 +00:00
1 parent a30ff58b7a
commit 2d5725f45b
1 file changed
+4 -4
+4 -4
View File
@@ -678,15 +678,15 @@ export async function registerRoutes(app: Express): Promise<Server> {
console.log('Deliveries API called with:', { startDate, endDate, storeId, withBL, userRole: user.role });
if (user.role === 'admin' || user.role === 'directeur') {
if (user.role === 'admin') {
let groupIds: number[] | undefined;
// If admin/directeur selected a specific store, filter by it
// If admin selected a specific store, filter by it
if (storeId) {
groupIds = [parseInt(storeId as string)];
console.log('🔍 Admin/Directeur deliveries filtering by store:', { storeId, groupIds, role: user.role });
console.log('🔍 Admin deliveries filtering by store:', { storeId, groupIds, role: user.role });
} else {
console.log('🔍 Admin/Directeur deliveries - showing all stores', { role: user.role });
console.log('🔍 Admin deliveries - showing all stores', { role: user.role });
}
// Only filter by date if both startDate and endDate are provided