mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Merge pull request #39 from R0m1k3/1.1
Allow all users to create new DLC products
This commit is contained in:
1 file changed
+6
-11
+6
-11
@@ -2173,7 +2173,7 @@ RÉSUMÉ DU SCAN
|
||||
});
|
||||
|
||||
// DLC Products routes
|
||||
app.get('/api/dlc-products', isAuthenticated, requirePermission('dlc', 'view'), async (req: any, res) => {
|
||||
app.get('/api/dlc-products', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const userId = req.user.claims ? req.user.claims.sub : req.user.id;
|
||||
const user = await storage.getUserWithGroups(userId);
|
||||
@@ -2220,7 +2220,7 @@ RÉSUMÉ DU SCAN
|
||||
}
|
||||
});
|
||||
|
||||
app.get('/api/dlc-products/stats', isAuthenticated, requirePermission('dlc', 'view'), async (req: any, res) => {
|
||||
app.get('/api/dlc-products/stats', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const userId = req.user.claims ? req.user.claims.sub : req.user.id;
|
||||
const user = await storage.getUserWithGroups(userId);
|
||||
@@ -2249,7 +2249,7 @@ RÉSUMÉ DU SCAN
|
||||
}
|
||||
});
|
||||
|
||||
app.get('/api/dlc-products/:id', isAuthenticated, requirePermission('dlc', 'view'), async (req: any, res) => {
|
||||
app.get('/api/dlc-products/:id', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
const id = parseInt(req.params.id);
|
||||
const dlcProduct = await storage.getDlcProduct(id);
|
||||
@@ -2276,7 +2276,7 @@ RÉSUMÉ DU SCAN
|
||||
}
|
||||
});
|
||||
|
||||
app.post('/api/dlc-products', isAuthenticated, requirePermission('dlc', 'create'), async (req: any, res) => {
|
||||
app.post('/api/dlc-products', isAuthenticated, async (req: any, res) => {
|
||||
try {
|
||||
console.log('📨 POST /api/dlc-products - Request body:', JSON.stringify(req.body, null, 2));
|
||||
|
||||
@@ -2287,13 +2287,8 @@ RÉSUMÉ DU SCAN
|
||||
return res.status(404).json({ message: "User not found" });
|
||||
}
|
||||
|
||||
// Validate access to the specified group
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups.map(ug => ug.group.id);
|
||||
if (!userGroupIds.includes(req.body.groupId)) {
|
||||
return res.status(403).json({ message: "Access denied to this store" });
|
||||
}
|
||||
}
|
||||
// REMOVED: All role restrictions - tous les rôles peuvent créer des DLC
|
||||
console.log("Creating DLC product - no role restrictions:", { userId, userRole: user.role, groupId: req.body.groupId });
|
||||
|
||||
const validatedData = insertDlcProductFrontendSchema.parse({
|
||||
...req.body,
|
||||
|
||||
Reference in new issue
Block a user