mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Enable specific user roles to validate products in the DLC module
Update DLC validation permissions to allow admin, director, and manager roles, and add console logs for validation attempts. Replit-Commit-Author: Agent Replit-Commit-Session-Id: a3de0820-9397-41b2-b000-7931ee9c29de Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/a3de0820-9397-41b2-b000-7931ee9c29de/T1jqUpI
This commit is contained in:
1 parent
7595727b0a
commit
7e7b2ec9ea
2 files changed
+19
-3
No files matched your search
+17
-2
@@ -1169,6 +1169,11 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
// Check if user has permission to validate DLC products (admin, directeur, manager)
|
||||
if (!['admin', 'directeur', 'manager'].includes(user.role)) {
|
||||
return res.status(403).json({ message: "Insufficient permissions to validate DLC products" });
|
||||
}
|
||||
|
||||
const id = parseInt(req.params.id);
|
||||
const dlcProduct = await storage.getDlcProduct(id);
|
||||
|
||||
@@ -1176,15 +1181,25 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
return res.status(404).json({ message: "DLC Product not found" });
|
||||
}
|
||||
|
||||
// Check permissions
|
||||
// For non-admin users, check if they have access to the product's group
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups.map(ug => ug.groupId);
|
||||
if (!userGroupIds.includes(dlcProduct.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied" });
|
||||
return res.status(403).json({ message: "Access denied to this group's DLC products" });
|
||||
}
|
||||
}
|
||||
|
||||
console.log('🔍 DLC Validation attempt:', {
|
||||
userId: user.id,
|
||||
userRole: user.role,
|
||||
dlcProductId: id,
|
||||
dlcGroupId: dlcProduct.groupId,
|
||||
userGroups: user.role !== 'admin' ? user.userGroups.map(ug => ug.groupId) : 'all'
|
||||
});
|
||||
|
||||
const validatedProduct = await storage.validateDlcProduct(id, user.id);
|
||||
console.log('✅ DLC Product validated successfully by:', user.role, user.id);
|
||||
|
||||
res.json(validatedProduct);
|
||||
} catch (error) {
|
||||
console.error("Error validating DLC product:", error);
|
||||
|
||||
Reference in new issue
Block a user