Restrict weather endpoint access to administrators

Add role-based access control to the /api/weather/current endpoint in server/routes.ts, ensuring only admin users can access it.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: d43bd811-9372-45a7-8ac9-4a954c0538e1
Replit-Commit-Checkpoint-Type: full_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/d43bd811-9372-45a7-8ac9-4a954c0538e1/zF4XCWA
This commit is contained in:
michaelschal committed 2025-08-15 08:11:55 +00:00
1 parent 654062bd88
commit c6b2120f06
2 files changed
+207

No files matched your search

+5
View File
@@ -2849,6 +2849,11 @@ RÉSUMÉ DU SCAN
app.get('/api/weather/current', isAuthenticated, async (req: any, res) => {
try {
const user = await storage.getUserWithGroups(req.user.claims ? req.user.claims.sub : req.user.id);
if (!user || user.role !== 'admin') {
return res.status(403).json({ message: "Access denied - Admin only" });
}
const settings = await storage.getWeatherSettings();
if (!settings || !settings.isActive) {