Add an endpoint to retrieve advertisements based on user roles and filters

Create a new GET endpoint `/api/publicities` to fetch advertisements, supporting filtering by year and storeId, with access control based on user roles (admin vs. non-admin).

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/WkQ9cok
This commit is contained in:
michaelschal committed 2025-10-10 16:19:17 +00:00
1 parent 1b0208e4b5
commit 8a4fd1341f
1 file changed
+35
+35
View File
@@ -3573,6 +3573,41 @@ export async function registerRoutes(app: Express): Promise<Server> {
}
});
// Get all publicities (with optional year and store filtering)
app.get('/api/publicities', isAuthenticated, async (req: any, res) => {
try {
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
if (!user) {
return res.status(404).json({ message: "User not found" });
}
const { year, storeId } = req.query;
let groupIds: number[] | undefined;
// Determine which groups to filter by
if (user.role === 'admin') {
// Admins can filter by specific store or see all
groupIds = storeId ? [parseInt(storeId as string)] : undefined;
} else {
// Non-admins see only their assigned groups
const userGroupIds = user.userGroups.map(ug => ug.groupId);
if (storeId && userGroupIds.includes(parseInt(storeId as string))) {
groupIds = [parseInt(storeId as string)];
} else {
groupIds = userGroupIds;
}
}
const yearNum = year ? parseInt(year as string) : undefined;
const publicities = await storage.getPublicities(yearNum, groupIds);
res.json(publicities);
} catch (error) {
console.error("Error fetching publicities:", error);
res.status(500).json([]);
}
});
app.post('/api/publicities', isAuthenticated, async (req: any, res) => {
try {
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);