mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Restrict task visibility based on user roles and group assignments
Update task retrieval logic to filter tasks based on user's assigned groups and roles. Admins can view all tasks or filter by store, while non-admins can only see tasks from their explicitly assigned groups, ensuring data segregation. Replit-Commit-Author: Agent Replit-Commit-Session-Id: a3de0820-9397-41b2-b000-7931ee9c29de Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a3de0820-9397-41b2-b000-7931ee9c29de/b8xUC40
This commit is contained in:
1 parent
75b353153f
commit
7595727b0a
1 file changed
+22
-4
+22
-4
@@ -1204,19 +1204,37 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
let groupIds: number[] | undefined;
|
||||
|
||||
if (user.role === 'admin') {
|
||||
// Admin can see all tasks or filter by specific store
|
||||
groupIds = storeId ? [parseInt(storeId as string)] : undefined;
|
||||
} else {
|
||||
// Non-admin users can only see tasks from their assigned groups
|
||||
const userGroupIds = user.userGroups.map(ug => ug.groupId);
|
||||
if (storeId && userGroupIds.includes(parseInt(storeId as string))) {
|
||||
groupIds = [parseInt(storeId as string)];
|
||||
|
||||
if (storeId) {
|
||||
// If a specific store is requested, verify user has access to it
|
||||
const requestedStoreId = parseInt(storeId as string);
|
||||
if (userGroupIds.includes(requestedStoreId)) {
|
||||
groupIds = [requestedStoreId];
|
||||
} else {
|
||||
// User doesn't have access to this store, return empty array
|
||||
return res.json([]);
|
||||
}
|
||||
} else {
|
||||
// No specific store requested, return tasks from user's groups only
|
||||
groupIds = userGroupIds;
|
||||
}
|
||||
}
|
||||
|
||||
console.log('Tasks API called with:', { groupIds, userRole: user.role });
|
||||
console.log('🔍 Tasks API called with:', {
|
||||
groupIds,
|
||||
userRole: user.role,
|
||||
userId: user.id,
|
||||
requestedStoreId: storeId,
|
||||
userGroups: user.role !== 'admin' ? user.userGroups.map(ug => ug.groupId) : 'all'
|
||||
});
|
||||
|
||||
const tasks = await storage.getTasks(groupIds);
|
||||
console.log('Tasks returned:', tasks.length, 'items');
|
||||
console.log('📋 Tasks returned:', tasks.length, 'items for user:', user.id);
|
||||
res.json(tasks);
|
||||
} catch (error) {
|
||||
console.error("Error fetching tasks:", error);
|
||||
|
||||
Reference in new issue
Block a user