Fix issue preventing employees from creating customer orders

Address an issue where employee users could not create customer orders due to incorrect group ID type comparison in the `registerRoutes.ts` file. The fix ensures that the `groupId` is correctly parsed as an integer before comparison, resolving the access denial for employees in their assigned groups.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 31f9bd88-0285-4787-81b3-31ceeea5a08b
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/31f9bd88-0285-4787-81b3-31ceeea5a08b/hI0UUHG
This commit is contained in:
michaelschal committed 2025-08-14 11:27:24 +00:00
1 parent bce8f91e77
commit 2da7a21908
3 files changed
+240 -3

No files matched your search

+9 -3
View File
@@ -1384,7 +1384,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
createdBy: user.id,
};
// Check if user has access to the group
// Check if user has access to the group - PRODUCTION DEBUG
console.log('🔍 CUSTOMER ORDER PERMISSION DEBUG:', {
userRole: user.role,
userId: user.id,
@@ -1398,15 +1398,21 @@ export async function registerRoutes(app: Express): Promise<Server> {
console.log('🔍 CUSTOMER ORDER - User group IDs:', userGroupIds);
console.log('🔍 CUSTOMER ORDER - Requested group ID:', data.groupId);
// Convert data.groupId to number if it's a string
const requestedGroupId = typeof data.groupId === 'string' ? parseInt(data.groupId) : data.groupId;
console.log('🔍 CUSTOMER ORDER - Converted group ID:', requestedGroupId);
// Allow managers, directeurs, and employees to create orders in their assigned groups
if (!['manager', 'directeur', 'employee'].includes(user.role)) {
console.log('❌ CUSTOMER ORDER - Access denied: Invalid role for customer orders');
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
}
if (!userGroupIds.includes(data.groupId)) {
if (!userGroupIds.includes(requestedGroupId)) {
console.log('❌ CUSTOMER ORDER - Access denied: User not in requested group');
console.log('🔍 Available groups:', userGroupIds, 'Requested:', data.groupId);
console.log('🔍 Available groups:', userGroupIds, 'Requested:', requestedGroupId);
console.log('🔍 Type check - userGroupIds types:', userGroupIds.map(id => typeof id));
console.log('🔍 Type check - requestedGroupId type:', typeof requestedGroupId);
return res.status(403).json({ message: "Access denied to this group" });
}