Restrict task visibility based on user roles and group assignments

Update task retrieval logic to filter tasks based on user's assigned groups and roles. Admins can view all tasks or filter by store, while non-admins can only see tasks from their explicitly assigned groups, ensuring data segregation.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: a3de0820-9397-41b2-b000-7931ee9c29de
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a3de0820-9397-41b2-b000-7931ee9c29de/b8xUC40
This commit is contained in:
michaelschal committed 2025-08-15 14:07:25 +00:00
1 parent 75b353153f
commit 7595727b0a
1 file changed
+22 -4
+22 -4
View File
@@ -1204,19 +1204,37 @@ export async function registerRoutes(app: Express): Promise<Server> {
let groupIds: number[] | undefined;
if (user.role === 'admin') {
// Admin can see all tasks or filter by specific store
groupIds = storeId ? [parseInt(storeId as string)] : undefined;
} else {
// Non-admin users can only see tasks from their assigned groups
const userGroupIds = user.userGroups.map(ug => ug.groupId);
if (storeId && userGroupIds.includes(parseInt(storeId as string))) {
groupIds = [parseInt(storeId as string)];
if (storeId) {
// If a specific store is requested, verify user has access to it
const requestedStoreId = parseInt(storeId as string);
if (userGroupIds.includes(requestedStoreId)) {
groupIds = [requestedStoreId];
} else {
// User doesn't have access to this store, return empty array
return res.json([]);
}
} else {
// No specific store requested, return tasks from user's groups only
groupIds = userGroupIds;
}
}
console.log('Tasks API called with:', { groupIds, userRole: user.role });
console.log('🔍 Tasks API called with:', {
groupIds,
userRole: user.role,
userId: user.id,
requestedStoreId: storeId,
userGroups: user.role !== 'admin' ? user.userGroups.map(ug => ug.groupId) : 'all'
});
const tasks = await storage.getTasks(groupIds);
console.log('Tasks returned:', tasks.length, 'items');
console.log('📋 Tasks returned:', tasks.length, 'items for user:', user.id);
res.json(tasks);
} catch (error) {
console.error("Error fetching tasks:", error);