mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Update order and delivery views to allow director access
Remove specific permission checks from order and delivery API endpoints, relying on a centralized permission system. Replit-Commit-Author: Agent Replit-Commit-Session-Id: b163d4c0-de5e-4f4e-a9c0-aed4c7049718 Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/b163d4c0-de5e-4f4e-a9c0-aed4c7049718/50k5WjY
This commit is contained in:
1 parent
55b3aaa9e1
commit
8cb0b3dffc
1 file changed
+2
-2
+2
-2
@@ -311,7 +311,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// Orders routes
|
||||
app.get('/api/orders', isAuthenticated, requirePermission('orders', 'view'), async (req: any, res) => {
|
||||
app.get('/api/orders', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
|
||||
if (!user) {
|
||||
@@ -584,7 +584,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
// Deliveries routes
|
||||
app.get('/api/deliveries', isAuthenticated, requirePermission('deliveries', 'view'), async (req: any, res) => {
|
||||
app.get('/api/deliveries', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
|
||||
if (!user) {
|
||||
|
||||
Reference in new issue
Block a user