mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Update delivery notes with improved permission and group access controls
Add a new PUT endpoint '/api/deliveries/:id/notes' to allow authenticated users with 'edit' permissions to update delivery notes, including validation for notes length and group access checks. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869 Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869/yiEpJFx
This commit is contained in:
1 parent
fc7fdb00db
commit
69c668853b
1 file changed
+47
@@ -1326,6 +1326,53 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
}
|
||||
});
|
||||
|
||||
// Route pour mettre à jour uniquement les notes d'une livraison
|
||||
app.put('/api/deliveries/:id/notes', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
|
||||
if (!user) {
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
const id = parseInt(req.params.id);
|
||||
const delivery = await storage.getDelivery(id);
|
||||
|
||||
if (!delivery) {
|
||||
return res.status(404).json({ message: "Delivery not found" });
|
||||
}
|
||||
|
||||
// Check edit permissions
|
||||
if (!hasPermission(user.role, 'deliveries', 'edit')) {
|
||||
return res.status(403).json({ message: "Insufficient permissions to edit deliveries" });
|
||||
}
|
||||
|
||||
// Check group access
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = (user as any).userGroups?.map((ug: any) => ug.groupId) || [];
|
||||
if (!userGroupIds.includes(delivery.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied" });
|
||||
}
|
||||
}
|
||||
|
||||
const { notes } = req.body;
|
||||
|
||||
// Validate notes length
|
||||
if (notes && notes.length > 500) {
|
||||
return res.status(400).json({ message: "Commentaire trop long (maximum 500 caractères)" });
|
||||
}
|
||||
|
||||
console.log('📝 Updating delivery notes:', { id, notes: notes ? notes.slice(0, 50) + '...' : 'empty', user: user.id });
|
||||
|
||||
// Update only the notes field
|
||||
const updatedDelivery = await storage.updateDelivery(id, { notes });
|
||||
|
||||
res.json(updatedDelivery);
|
||||
} catch (error) {
|
||||
console.error("Error updating delivery notes:", error);
|
||||
res.status(500).json({ message: "Failed to update delivery notes" });
|
||||
}
|
||||
});
|
||||
|
||||
// Route de vérification de facture NocoDB
|
||||
app.post('/api/deliveries/:id/verify-invoice', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
|
||||
Reference in new issue
Block a user