Restrict managers from changing status and uploading files via webhooks

Prevent 'manager' role users from setting 'avoir' status to 'Reçu'. Modify SelectItem visibility in Avoirs.tsx to conditionally render the 'Reçu' option based on user role.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: 9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/1957c339-2757-4d1f-8e92-e9f71a1ce58e/9fcf4b21-eb0c-4e53-a567-e2ce4a6ad869/7eY9Hl8
This commit is contained in:
michaelschal committed 2025-09-08 20:58:58 +00:00
1 parent 01b3e8288e
commit ee5c122664
1 file changed
+13 -1
+13 -1
View File
@@ -446,6 +446,16 @@ export default function Avoirs() {
// Handle status change
const handleStatusChange = (avoirId: number, newStatus: string) => {
// Empêcher les managers de mettre le statut en "Reçu"
if ((user as any)?.role === 'manager' && newStatus === 'Reçu') {
toast({
title: "Accès refusé",
description: "Vous n'avez pas les permissions pour marquer un avoir comme reçu",
variant: "destructive",
});
return;
}
const avoir = avoirs?.find(a => a?.id === avoirId);
if (avoir && avoir.supplierId && avoir.groupId) {
editAvoirMutation.mutate({
@@ -969,7 +979,9 @@ export default function Avoirs() {
<SelectContent>
<SelectItem value="En attente de demande">En attente de demande</SelectItem>
<SelectItem value="Demandé">Demandé</SelectItem>
<SelectItem value="Reçu">Reçu</SelectItem>
{(user as any)?.role !== 'manager' && (
<SelectItem value="Reçu">Reçu</SelectItem>
)}
</SelectContent>
</Select>
</td>