mirror of
https://github.com/R0m1k3/Regisflow.git
synced 2026-10-11 17:29:48 +02:00
Update sales history to immediately display newly created sales data
Modify sales history to automatically refresh after sales creation and fix store ID access control. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 91318273-c764-4fd4-be04-bdc12c38af32 Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/0715008c-7244-40f4-befc-26c014852236/056e12e0-54e7-4791-91f8-f567295f6d37.jpg
This commit is contained in:
1 parent
b71148da46
commit
4d4ad93e5d
2 files changed
+14
-11
No files matched your search
@@ -33,8 +33,8 @@ export default function SalesHistory({ canDelete = false }: SalesHistoryProps) {
|
||||
if (startDate) params.append('startDate', startDate);
|
||||
if (endDate) params.append('endDate', endDate);
|
||||
|
||||
// Add storeId for admin users
|
||||
if (user?.role === 'admin' && selectedStoreId) {
|
||||
// Always add storeId for queries
|
||||
if (selectedStoreId) {
|
||||
params.append('storeId', selectedStoreId.toString());
|
||||
}
|
||||
|
||||
@@ -42,7 +42,9 @@ export default function SalesHistory({ canDelete = false }: SalesHistoryProps) {
|
||||
const response = await apiRequest(`/api/sales${queryString ? `?${queryString}` : ''}`);
|
||||
return response.json();
|
||||
},
|
||||
enabled: !!selectedStoreId, // Only run query when store is selected
|
||||
enabled: !!selectedStoreId && !!user, // Only run query when store is selected and user is loaded
|
||||
refetchOnMount: true, // Always refetch when component mounts
|
||||
refetchOnWindowFocus: false, // Don't refetch on window focus
|
||||
});
|
||||
|
||||
const sales = Array.isArray(salesData) ? salesData : [];
|
||||
|
||||
+9
-8
@@ -149,16 +149,17 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
|
||||
// Determine which store to query
|
||||
let targetStoreId: number;
|
||||
if (user.role === 'admin') {
|
||||
if (storeId) {
|
||||
// Admin querying a specific store
|
||||
targetStoreId = parseInt(storeId as string);
|
||||
} else {
|
||||
// Admin without specific store - should not happen with the new frontend
|
||||
return res.status(400).json({ error: "Store ID required for admin queries" });
|
||||
|
||||
if (storeId) {
|
||||
// storeId provided in query
|
||||
targetStoreId = parseInt(storeId as string);
|
||||
|
||||
// For non-admin users, verify they can only access their own store
|
||||
if (user.role !== 'admin' && targetStoreId !== user.storeId) {
|
||||
return res.status(403).json({ error: "Access denied to this store" });
|
||||
}
|
||||
} else {
|
||||
// Non-admin users can only query their own store
|
||||
// No storeId provided - use user's assigned store for non-admin
|
||||
if (!user.storeId) {
|
||||
return res.status(400).json({ error: "User has no assigned store" });
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user