Improve delivery access control with enhanced user group verification

Update server/routes.ts to refine access control for deliveries based on user roles and group memberships, adding console logs for debugging denied and granted access scenarios.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 28b81ac1-a55f-409c-b6a9-88ad420d8a9a
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/28b81ac1-a55f-409c-b6a9-88ad420d8a9a/6PoDWd4
This commit is contained in:
michaelschal committed 2025-09-03 09:04:22 +00:00
1 parent 74a1d4d7f5
commit 90cec2124f
2 files changed
+15

No files matched your search

Binary file not shown.

After

Width:  |  Height:  |  Size: 159 KiB

+15
View File
@@ -1038,11 +1038,26 @@ export async function registerRoutes(app: Express): Promise<Server> {
return res.status(403).json({ message: "Insufficient permissions" });
}
// Admin has access to all deliveries, others must be in the same group
if (user.role !== 'admin') {
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
if (!userGroupIds.includes(delivery.groupId)) {
console.log('🚫 Access denied - User groups check:', {
userId: user.id,
userRole: user.role,
userGroupIds,
deliveryGroupId: delivery.groupId,
deliverySupplier: delivery.supplier?.name
});
return res.status(403).json({ message: "Access denied to this group" });
}
} else {
console.log('✅ Admin access granted for delivery:', {
userId: user.id,
deliveryId: delivery.id,
deliveryGroupId: delivery.groupId,
deliverySupplier: delivery.supplier?.name
});
}
const { invoiceReference, blNumber, forceRefresh } = req.body;