mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Fix issue preventing employees from creating customer orders
Address an issue where employee users could not create customer orders due to incorrect group ID type comparison in the `registerRoutes.ts` file. The fix ensures that the `groupId` is correctly parsed as an integer before comparison, resolving the access denial for employees in their assigned groups. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 31f9bd88-0285-4787-81b3-31ceeea5a08b Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/31f9bd88-0285-4787-81b3-31ceeea5a08b/hI0UUHG
This commit is contained in:
1 parent
bce8f91e77
commit
2da7a21908
3 files changed
+240
-3
No files matched your search
+9
-3
@@ -1384,7 +1384,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
createdBy: user.id,
|
||||
};
|
||||
|
||||
// Check if user has access to the group
|
||||
// Check if user has access to the group - PRODUCTION DEBUG
|
||||
console.log('🔍 CUSTOMER ORDER PERMISSION DEBUG:', {
|
||||
userRole: user.role,
|
||||
userId: user.id,
|
||||
@@ -1398,15 +1398,21 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
console.log('🔍 CUSTOMER ORDER - User group IDs:', userGroupIds);
|
||||
console.log('🔍 CUSTOMER ORDER - Requested group ID:', data.groupId);
|
||||
|
||||
// Convert data.groupId to number if it's a string
|
||||
const requestedGroupId = typeof data.groupId === 'string' ? parseInt(data.groupId) : data.groupId;
|
||||
console.log('🔍 CUSTOMER ORDER - Converted group ID:', requestedGroupId);
|
||||
|
||||
// Allow managers, directeurs, and employees to create orders in their assigned groups
|
||||
if (!['manager', 'directeur', 'employee'].includes(user.role)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: Invalid role for customer orders');
|
||||
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
|
||||
}
|
||||
|
||||
if (!userGroupIds.includes(data.groupId)) {
|
||||
if (!userGroupIds.includes(requestedGroupId)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: User not in requested group');
|
||||
console.log('🔍 Available groups:', userGroupIds, 'Requested:', data.groupId);
|
||||
console.log('🔍 Available groups:', userGroupIds, 'Requested:', requestedGroupId);
|
||||
console.log('🔍 Type check - userGroupIds types:', userGroupIds.map(id => typeof id));
|
||||
console.log('🔍 Type check - requestedGroupId type:', typeof requestedGroupId);
|
||||
return res.status(403).json({ message: "Access denied to this group" });
|
||||
}
|
||||
|
||||
|
||||
Reference in new issue
Block a user