mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Fix issue preventing employees from creating customer orders
Address an issue where employee users could not create customer orders due to incorrect group ID type comparison in the `registerRoutes.ts` file. The fix ensures that the `groupId` is correctly parsed as an integer before comparison, resolving the access denial for employees in their assigned groups. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 31f9bd88-0285-4787-81b3-31ceeea5a08b Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/31f9bd88-0285-4787-81b3-31ceeea5a08b/hI0UUHG
This commit is contained in:
1 parent
bce8f91e77
commit
2da7a21908
3 files changed
+240
-3
No files matched your search
+231
@@ -0,0 +1,231 @@
|
||||
Registries
|
||||
|
||||
Logs
|
||||
|
||||
Notifications
|
||||
|
||||
Settings
|
||||
|
||||
New version available 2.27.9
|
||||
DismissSee what's new
|
||||
Community Edition
|
||||
2.27.6 LTS
|
||||
Containers>logiflow-logiflow-1>Logs
|
||||
Container logs
|
||||
|
||||
|
||||
admin
|
||||
Log viewer settings
|
||||
Auto-refresh logs
|
||||
Wrap lines
|
||||
Display timestamps
|
||||
Fetch
|
||||
All logs
|
||||
Search
|
||||
Filter...
|
||||
Lines
|
||||
100
|
||||
Actions
|
||||
|
||||
|
||||
|
||||
|
||||
Customer Orders API called with: { groupIds: [ 2 ], userRole: 'admin' }
|
||||
|
||||
Orders API called with: {
|
||||
|
||||
startDate: undefined,
|
||||
|
||||
endDate: undefined,
|
||||
|
||||
storeId: '2',
|
||||
|
||||
userRole: 'admin'
|
||||
|
||||
}
|
||||
|
||||
Admin filtering with groupIds: [ 2 ]
|
||||
|
||||
Fetching all orders
|
||||
|
||||
GET /api/publicities 304 in 33ms
|
||||
|
||||
Customer Orders returned: 25 items
|
||||
|
||||
GET /api/customer-orders 304 in 43ms
|
||||
|
||||
🔗 PRODUCTION: getOrders() récupéré 18 commandes avec relations
|
||||
|
||||
Orders returned: 18 items
|
||||
|
||||
GET /api/orders 304 in 59ms
|
||||
|
||||
🔗 PRODUCTION: getDeliveries() récupéré 38 livraisons avec relations
|
||||
|
||||
Deliveries returned: 38 items
|
||||
|
||||
GET /api/deliveries 304 in 65ms
|
||||
|
||||
GET /api/groups 200 in 5ms
|
||||
|
||||
POST /api/logout 302 in 4ms
|
||||
|
||||
📄 SPA: Serving index.html for /auth
|
||||
|
||||
📄 SPA: Serving index.html for /auth
|
||||
|
||||
GET /api/user 401 in 1ms
|
||||
|
||||
GET /api/user 401 in 0ms
|
||||
|
||||
GET /api/default-credentials-check 304 in 1ms
|
||||
|
||||
🔐 comparePasswords: {
|
||||
|
||||
supplied: 'HIDDEN',
|
||||
|
||||
stored: 'b23ec450a63faf3957a1...',
|
||||
|
||||
hasFormat: true
|
||||
|
||||
}
|
||||
|
||||
🔐 Password comparison result: true
|
||||
|
||||
POST /api/login 200 in 51ms
|
||||
|
||||
GET /api/user 200 in 3ms
|
||||
|
||||
GET /api/user 304 in 4ms
|
||||
|
||||
📊 Calcul statistiques mensuelles: {
|
||||
|
||||
year: 2025,
|
||||
|
||||
month: 8,
|
||||
|
||||
startDate: '2025-08-01',
|
||||
|
||||
endDate: '2025-09-01',
|
||||
|
||||
groupIds: [ 2 ]
|
||||
|
||||
}
|
||||
|
||||
Orders API called with: {
|
||||
|
||||
startDate: undefined,
|
||||
|
||||
endDate: undefined,
|
||||
|
||||
storeId: undefined,
|
||||
|
||||
userRole: 'employee'
|
||||
|
||||
}
|
||||
|
||||
Non-admin filtering with groupIds: [ 2 ]
|
||||
|
||||
Deliveries API called with: {
|
||||
|
||||
startDate: undefined,
|
||||
|
||||
endDate: undefined,
|
||||
|
||||
storeId: undefined,
|
||||
|
||||
withBL: undefined,
|
||||
|
||||
userRole: 'employee'
|
||||
|
||||
}
|
||||
|
||||
Non-admin filtering deliveries with groupIds: [ 2 ]
|
||||
|
||||
🔗 PRODUCTION: getOrders() récupéré 18 commandes avec relations
|
||||
|
||||
Orders returned: 18 items
|
||||
|
||||
GET /api/orders 200 in 54ms
|
||||
|
||||
Customer Orders API called with: { groupIds: [ 2 ], userRole: 'employee' }
|
||||
|
||||
📊 Statistiques calculées: {
|
||||
|
||||
ordersCount: 8,
|
||||
|
||||
deliveriesCount: 21,
|
||||
|
||||
pendingOrdersCount: 4,
|
||||
|
||||
averageDeliveryTime: 0.17647058823529413,
|
||||
|
||||
totalPalettes: 57,
|
||||
|
||||
totalPackages: 17
|
||||
|
||||
}
|
||||
|
||||
GET /api/stats/monthly 200 in 62ms
|
||||
|
||||
Tasks API called with: { groupIds: [ 2 ], userRole: 'employee' }
|
||||
|
||||
Customer Orders returned: 25 items
|
||||
|
||||
GET /api/customer-orders 200 in 76ms
|
||||
|
||||
Tasks returned: 9 items
|
||||
|
||||
GET /api/dlc-products/stats 200 in 80ms
|
||||
|
||||
GET /api/tasks 200 in 78ms
|
||||
|
||||
GET /api/publicities 304 in 84ms
|
||||
|
||||
GET /api/user 304 in 40ms
|
||||
|
||||
🔗 PRODUCTION: getDeliveries() récupéré 38 livraisons avec relations
|
||||
|
||||
Deliveries returned: 38 items
|
||||
|
||||
GET /api/deliveries 200 in 93ms
|
||||
|
||||
GET /api/user 304 in 5ms
|
||||
|
||||
GET /api/publicities 304 in 8ms
|
||||
|
||||
GET /api/groups 200 in 6ms
|
||||
|
||||
GET /api/user 304 in 7ms
|
||||
|
||||
GET /api/suppliers 304 in 6ms
|
||||
|
||||
GET /api/user 304 in 4ms
|
||||
|
||||
🔍 CUSTOMER ORDER PERMISSION DEBUG: {
|
||||
|
||||
userRole: 'employee',
|
||||
|
||||
userId: '_1753266816257',
|
||||
|
||||
userGroups: [ { userId: '_1753266816257', groupId: 2, group: [Object] } ],
|
||||
|
||||
requestedGroupId: 1,
|
||||
|
||||
requestedGroupIdType: 'number'
|
||||
|
||||
}
|
||||
|
||||
🔍 CUSTOMER ORDER - User group IDs: [ 2 ]
|
||||
|
||||
🔍 CUSTOMER ORDER - Requested group ID: 1
|
||||
|
||||
❌ CUSTOMER ORDER - Access denied: User not in requested group
|
||||
|
||||
🔍 Available groups: [ 2 ] Requested: 1
|
||||
|
||||
POST /api/customer-orders 403 in 7ms
|
||||
|
||||
HEAD /api/health 200 in 0ms
|
||||
|
||||
HEAD /api/health 200 in 1ms
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 271 KiB |
+9
-3
@@ -1384,7 +1384,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
createdBy: user.id,
|
||||
};
|
||||
|
||||
// Check if user has access to the group
|
||||
// Check if user has access to the group - PRODUCTION DEBUG
|
||||
console.log('🔍 CUSTOMER ORDER PERMISSION DEBUG:', {
|
||||
userRole: user.role,
|
||||
userId: user.id,
|
||||
@@ -1398,15 +1398,21 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
console.log('🔍 CUSTOMER ORDER - User group IDs:', userGroupIds);
|
||||
console.log('🔍 CUSTOMER ORDER - Requested group ID:', data.groupId);
|
||||
|
||||
// Convert data.groupId to number if it's a string
|
||||
const requestedGroupId = typeof data.groupId === 'string' ? parseInt(data.groupId) : data.groupId;
|
||||
console.log('🔍 CUSTOMER ORDER - Converted group ID:', requestedGroupId);
|
||||
|
||||
// Allow managers, directeurs, and employees to create orders in their assigned groups
|
||||
if (!['manager', 'directeur', 'employee'].includes(user.role)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: Invalid role for customer orders');
|
||||
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
|
||||
}
|
||||
|
||||
if (!userGroupIds.includes(data.groupId)) {
|
||||
if (!userGroupIds.includes(requestedGroupId)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: User not in requested group');
|
||||
console.log('🔍 Available groups:', userGroupIds, 'Requested:', data.groupId);
|
||||
console.log('🔍 Available groups:', userGroupIds, 'Requested:', requestedGroupId);
|
||||
console.log('🔍 Type check - userGroupIds types:', userGroupIds.map(id => typeof id));
|
||||
console.log('🔍 Type check - requestedGroupId type:', typeof requestedGroupId);
|
||||
return res.status(403).json({ message: "Access denied to this group" });
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user