From 30988c8be3c975f1040d4ad1f5c6d12b982ce45b Mon Sep 17 00:00:00 2001 From: michaelschal <35957947-michaelschal@users.noreply.replit.com> Date: Mon, 8 Sep 2025 18:15:54 +0000 Subject: [PATCH] Add endpoint to verify credit note invoices using NocoDB integration Add a POST route '/api/avoirs/:id/verify-invoice' to the backend for verifying credit note invoices. This endpoint integrates with NocoDB, checks user permissions and group associations, and uses the invoiceVerificationService to validate invoices based on a provided reference. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869 Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869/GlyTlJp --- server/routes.ts | 78 ++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 78 insertions(+) diff --git a/server/routes.ts b/server/routes.ts index 320b74d..ac2d8f4 100644 --- a/server/routes.ts +++ b/server/routes.ts @@ -2600,6 +2600,84 @@ export async function registerRoutes(app: Express): Promise { } }); + // Route de vĂ©rification de facture NocoDB pour les avoirs + app.post('/api/avoirs/:id/verify-invoice', isAuthenticated, async (req: any, res) => { + try { + const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id); + if (!user) { + return res.status(404).json({ message: "User not found" }); + } + + const avoirId = parseInt(req.params.id); + const avoir = await storage.getAvoir(avoirId); + + if (!avoir) { + return res.status(404).json({ message: "Avoir not found" }); + } + + // Check permissions + if (!hasPermission(user.role, 'avoirs', 'view')) { + return res.status(403).json({ message: "Insufficient permissions" }); + } + + // Only admin have access to all avoirs, others must be in the same group + if (user.role !== 'admin') { + const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || []; + if (!userGroupIds.includes(avoir.groupId)) { + console.log('đŸš« Access denied - User groups check:', { + userId: user.id, + userRole: user.role, + userGroupIds, + avoirGroupId: avoir.groupId, + avoirSupplier: avoir.supplier?.name + }); + return res.status(403).json({ message: "Access denied to this group" }); + } + } + + const { invoiceReference, forceRefresh } = req.body; + + if (!avoir.supplier || !avoir.group) { + console.log('❌ Avoir manque informations:', { + avoirId, + hasSupplier: !!avoir.supplier, + hasGroup: !!avoir.group + }); + return res.status(400).json({ message: "Avoir missing supplier or group information" }); + } + + // VĂ©rifier que la rĂ©fĂ©rence facture est prĂ©sente + if (!invoiceReference || !invoiceReference.trim()) { + return res.status(400).json({ message: "RĂ©fĂ©rence de facture requise" }); + } + + console.log('🔍 VĂ©rification facture avoir:', { + avoirId, + invoiceReference, + supplier: avoir.supplier?.name, + group: avoir.group?.name, + groupId: avoir.groupId + }); + + // VĂ©rifier par rĂ©fĂ©rence de facture uniquement + const result = await invoiceVerificationService.verifyInvoice( + invoiceReference, + avoir.groupId, + forceRefresh || false, + false // Les avoirs ne sont pas "rĂ©conciliĂ©s" comme les livraisons + ); + + console.log('✅ RĂ©sultat vĂ©rification avoir:', result); + res.json(result); + } catch (error) { + console.error("Error verifying avoir invoice:", error); + res.status(500).json({ + message: "Failed to verify avoir invoice", + error: error instanceof Error ? error.message : 'Unknown error' + }); + } + }); + // Avoir status update routes app.put('/api/avoirs/:id/webhook-status', isAuthenticated, async (req: any, res) => { try {