mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Restrict director access to assigned groups only
Update route protection logic to ensure directors can only access deliveries within their assigned groups. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 28b81ac1-a55f-409c-b6a9-88ad420d8a9a Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/28b81ac1-a55f-409c-b6a9-88ad420d8a9a/6PoDWd4
This commit is contained in:
1 parent
1a0171c49e
commit
510a62915b
1 file changed
+1
-1
+1
-1
@@ -1022,7 +1022,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
return res.status(403).json({ message: "Insufficient permissions" });
|
||||
}
|
||||
|
||||
if (user.role !== 'admin' && user.role !== 'directeur') {
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
|
||||
if (!userGroupIds.includes(delivery.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied to this group" });
|
||||
|
||||
Reference in new issue
Block a user