mirror of
https://github.com/R0m1k3/LogiFlow.git
synced 2026-10-11 17:27:31 +02:00
Allow employees to create customer orders and fix SAV ticket visibility
Enable employees to create customer orders by adjusting permission checks for their assigned groups, and ensure SAV ticket detail and edit buttons are visible and functional based on user roles. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 31f9bd88-0285-4787-81b3-31ceeea5a08b Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/31f9bd88-0285-4787-81b3-31ceeea5a08b/hI0UUHG
This commit is contained in:
1 parent
e8e2bc0b12
commit
bce8f91e77
2 files changed
+35
-1
No files matched your search
+22
-1
@@ -1385,11 +1385,32 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
};
|
||||
|
||||
// Check if user has access to the group
|
||||
console.log('🔍 CUSTOMER ORDER PERMISSION DEBUG:', {
|
||||
userRole: user.role,
|
||||
userId: user.id,
|
||||
userGroups: user.userGroups,
|
||||
requestedGroupId: data.groupId,
|
||||
requestedGroupIdType: typeof data.groupId
|
||||
});
|
||||
|
||||
if (user.role !== 'admin') {
|
||||
const userGroupIds = user.userGroups.map(ug => ug.groupId);
|
||||
const userGroupIds = user.userGroups ? user.userGroups.map(ug => ug.groupId) : [];
|
||||
console.log('🔍 CUSTOMER ORDER - User group IDs:', userGroupIds);
|
||||
console.log('🔍 CUSTOMER ORDER - Requested group ID:', data.groupId);
|
||||
|
||||
// Allow managers, directeurs, and employees to create orders in their assigned groups
|
||||
if (!['manager', 'directeur', 'employee'].includes(user.role)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: Invalid role for customer orders');
|
||||
return res.status(403).json({ message: "Insufficient permissions to create customer orders" });
|
||||
}
|
||||
|
||||
if (!userGroupIds.includes(data.groupId)) {
|
||||
console.log('❌ CUSTOMER ORDER - Access denied: User not in requested group');
|
||||
console.log('🔍 Available groups:', userGroupIds, 'Requested:', data.groupId);
|
||||
return res.status(403).json({ message: "Access denied to this group" });
|
||||
}
|
||||
|
||||
console.log('✅ CUSTOMER ORDER - Permission granted for user role:', user.role);
|
||||
}
|
||||
|
||||
const customerOrder = await storage.createCustomerOrder(data);
|
||||
|
||||
Reference in new issue
Block a user