From 8a4fd1341f69ea616aad42e10ab0b6754848a6a4 Mon Sep 17 00:00:00 2001 From: michaelschal <35957947-michaelschal@users.noreply.replit.com> Date: Fri, 10 Oct 2025 16:19:17 +0000 Subject: [PATCH] Add an endpoint to retrieve advertisements based on user roles and filters Create a new GET endpoint `/api/publicities` to fetch advertisements, supporting filtering by year and storeId, with access control based on user roles (admin vs. non-admin). Replit-Commit-Author: Agent Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/WkQ9cok --- server/routes.ts | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/server/routes.ts b/server/routes.ts index de4d2a9..6d69470 100644 --- a/server/routes.ts +++ b/server/routes.ts @@ -3573,6 +3573,41 @@ export async function registerRoutes(app: Express): Promise { } }); + // Get all publicities (with optional year and store filtering) + app.get('/api/publicities', isAuthenticated, async (req: any, res) => { + try { + const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id); + if (!user) { + return res.status(404).json({ message: "User not found" }); + } + + const { year, storeId } = req.query; + let groupIds: number[] | undefined; + + // Determine which groups to filter by + if (user.role === 'admin') { + // Admins can filter by specific store or see all + groupIds = storeId ? [parseInt(storeId as string)] : undefined; + } else { + // Non-admins see only their assigned groups + const userGroupIds = user.userGroups.map(ug => ug.groupId); + if (storeId && userGroupIds.includes(parseInt(storeId as string))) { + groupIds = [parseInt(storeId as string)]; + } else { + groupIds = userGroupIds; + } + } + + const yearNum = year ? parseInt(year as string) : undefined; + const publicities = await storage.getPublicities(yearNum, groupIds); + + res.json(publicities); + } catch (error) { + console.error("Error fetching publicities:", error); + res.status(500).json([]); + } + }); + app.post('/api/publicities', isAuthenticated, async (req: any, res) => { try { const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);