mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Enable employees to create and edit customer orders with correct permissions
Update permission checks for creating and editing customer orders in the backend, ensuring role-based access control is correctly enforced for employee roles. Replit-Commit-Author: Agent Replit-Commit-Session-Id: b163d4c0-de5e-4f4e-a9c0-aed4c7049718 Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/b163d4c0-de5e-4f4e-a9c0-aed4c7049718/zYx3zXF
This commit is contained in:
1 parent
7239b97c8c
commit
aa63fdcbe2
5 files changed
+12
-5
No files matched your search
Binary file not shown.
|
After Width: | Height: | Size: 310 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 406 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 389 KiB |
+12
-2
@@ -1940,12 +1940,17 @@ RÉSUMÉ DU SCAN
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
// Check permissions for customer-orders create
|
||||
if (!hasPermission(user.role, 'customer-orders', 'create')) {
|
||||
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
|
||||
}
|
||||
|
||||
const data = insertCustomerOrderSchema.parse(req.body);
|
||||
console.log("Parsed data:", data);
|
||||
|
||||
// Check if user has access to the specified group
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups.map(ug => ug.groupId);
|
||||
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
|
||||
if (!userGroupIds.includes(data.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied to this group" });
|
||||
}
|
||||
@@ -1980,8 +1985,13 @@ RÉSUMÉ DU SCAN
|
||||
return res.status(404).json({ message: "Customer order not found" });
|
||||
}
|
||||
|
||||
// Check edit permissions
|
||||
if (!hasPermission(user.role, 'customer-orders', 'edit')) {
|
||||
return res.status(403).json({ message: "Insufficient permissions to edit customer orders" });
|
||||
}
|
||||
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups.map(ug => ug.groupId);
|
||||
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
|
||||
if (!userGroupIds.includes(existingOrder.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied" });
|
||||
}
|
||||
|
||||
@@ -500,9 +500,6 @@ export type Task = typeof tasks.$inferSelect;
|
||||
export type InsertTask = z.infer<typeof insertTaskSchema>;
|
||||
|
||||
// Complex types with relations
|
||||
export type UserWithGroups = User & {
|
||||
groups: Group[];
|
||||
};
|
||||
|
||||
export type OrderWithRelations = Order & {
|
||||
supplier: Supplier;
|
||||
|
||||
Reference in new issue
Block a user