Enable employees to create and edit customer orders with correct permissions

Update permission checks for creating and editing customer orders in the backend, ensuring role-based access control is correctly enforced for employee roles.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: b163d4c0-de5e-4f4e-a9c0-aed4c7049718
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/b163d4c0-de5e-4f4e-a9c0-aed4c7049718/zYx3zXF
This commit is contained in:
michaelschal committed 2025-08-12 13:55:00 +00:00
1 parent 7239b97c8c
commit aa63fdcbe2
5 files changed
+12 -5

No files matched your search

Binary file not shown.

After

Width:  |  Height:  |  Size: 310 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 406 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 389 KiB

+12 -2
View File
@@ -1940,12 +1940,17 @@ RÉSUMÉ DU SCAN
return res.status(404).json({ message: "User not found" });
}
// Check permissions for customer-orders create
if (!hasPermission(user.role, 'customer-orders', 'create')) {
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
}
const data = insertCustomerOrderSchema.parse(req.body);
console.log("Parsed data:", data);
// Check if user has access to the specified group
if (user.role !== 'admin') {
const userGroupIds = user.userGroups.map(ug => ug.groupId);
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
if (!userGroupIds.includes(data.groupId)) {
return res.status(403).json({ message: "Access denied to this group" });
}
@@ -1980,8 +1985,13 @@ RÉSUMÉ DU SCAN
return res.status(404).json({ message: "Customer order not found" });
}
// Check edit permissions
if (!hasPermission(user.role, 'customer-orders', 'edit')) {
return res.status(403).json({ message: "Insufficient permissions to edit customer orders" });
}
if (user.role !== 'admin') {
const userGroupIds = user.userGroups.map(ug => ug.groupId);
const userGroupIds = user.userGroups?.map((ug: any) => ug.groupId) || [];
if (!userGroupIds.includes(existingOrder.groupId)) {
return res.status(403).json({ message: "Access denied" });
}
-3
View File
@@ -500,9 +500,6 @@ export type Task = typeof tasks.$inferSelect;
export type InsertTask = z.infer<typeof insertTaskSchema>;
// Complex types with relations
export type UserWithGroups = User & {
groups: Group[];
};
export type OrderWithRelations = Order & {
supplier: Supplier;