mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Fix issue preventing administrators from deleting advertisements
Improve the publicity deletion endpoint by adding comprehensive logging for debugging, ensuring correct role-based access control, and refining the database deletion logic to include participations for data integrity. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 1e4433b5-47ab-464c-b663-fea2e53367dd Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/1e4433b5-47ab-464c-b663-fea2e53367dd/BADbf74
This commit is contained in:
1 parent
b1a7ef235a
commit
9ad2afaf90
4 files changed
+41
-5
No files matched your search
Binary file not shown.
|
After Width: | Height: | Size: 280 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 280 KiB |
+21
-3
@@ -3525,23 +3525,41 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
});
|
||||
|
||||
app.delete('/api/publicities/:id', isAuthenticated, async (req: any, res) => {
|
||||
const publicityId = req.params.id;
|
||||
console.log(`🗑️ [API] DELETE request received for publicity ID: ${publicityId}`);
|
||||
console.log(`🗑️ [API] User info:`, {
|
||||
hasUser: !!req.user,
|
||||
userId: req.user?.id || req.user?.claims?.sub,
|
||||
method: req.method,
|
||||
url: req.url,
|
||||
headers: { 'content-type': req.headers['content-type'] }
|
||||
});
|
||||
|
||||
try {
|
||||
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
|
||||
if (!user) {
|
||||
console.log(`❌ [API] User not found for publicity deletion: ${publicityId}`);
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
console.log(`🗑️ [API] User found:`, { id: user.id, role: user.role, name: user.name });
|
||||
|
||||
// Check permissions (admin only for deletion)
|
||||
if (user.role !== 'admin') {
|
||||
console.log(`❌ [API] Insufficient permissions for publicity deletion: ${publicityId}, user role: ${user.role}`);
|
||||
return res.status(403).json({ message: "Insufficient permissions" });
|
||||
}
|
||||
|
||||
const id = parseInt(req.params.id);
|
||||
const id = parseInt(publicityId);
|
||||
console.log(`🗑️ [API] Admin ${user.name} (${user.id}) attempting to delete publicity ${id}`);
|
||||
|
||||
await storage.deletePublicity(id);
|
||||
|
||||
console.log(`✅ [API] Successfully deleted publicity ${id} by admin ${user.name}`);
|
||||
res.json({ message: "Publicity deleted successfully" });
|
||||
} catch (error) {
|
||||
console.error("Error deleting publicity:", error);
|
||||
res.status(500).json({ message: "Failed to delete publicity" });
|
||||
console.error(`❌ [API] Error deleting publicity ${publicityId}:`, error);
|
||||
res.status(500).json({ message: "Failed to delete publicity", error: error.message });
|
||||
}
|
||||
});
|
||||
|
||||
|
||||
+20
-2
@@ -1479,8 +1479,26 @@ export class DatabaseStorage implements IStorage {
|
||||
}
|
||||
|
||||
async deletePublicity(id: number): Promise<void> {
|
||||
await db.delete(publicityParticipations).where(eq(publicityParticipations.publicityId, id));
|
||||
await db.delete(publicities).where(eq(publicities.id, id));
|
||||
console.log(`🗑️ [DELETION] Starting deletion of publicity ID: ${id}`);
|
||||
|
||||
try {
|
||||
// First, delete all participations (defensive approach for production DB constraints)
|
||||
const deletedParticipations = await db.delete(publicityParticipations).where(eq(publicityParticipations.publicityId, id)).returning();
|
||||
console.log(`🗑️ [DELETION] Deleted ${deletedParticipations.length} participations for publicity ${id}`);
|
||||
|
||||
// Then delete the publicity itself
|
||||
const deletedPublicity = await db.delete(publicities).where(eq(publicities.id, id)).returning();
|
||||
console.log(`🗑️ [DELETION] Deleted publicity ${id}, found: ${deletedPublicity.length > 0 ? 'YES' : 'NO'}`);
|
||||
|
||||
if (deletedPublicity.length === 0) {
|
||||
throw new Error(`Publicity with ID ${id} not found`);
|
||||
}
|
||||
|
||||
console.log(`✅ [DELETION] Successfully deleted publicity ID: ${id}`);
|
||||
} catch (error) {
|
||||
console.error(`❌ [DELETION] Failed to delete publicity ID: ${id}`, error);
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
async getPublicityParticipations(publicityId: number): Promise<PublicityParticipation[]> {
|
||||
|
||||
Reference in new issue
Block a user