mirror of
https://github.com/R0m1k3/Regisflow.git
synced 2026-10-11 17:29:48 +02:00
Improve user editing, allowing admins access to all stores without assignment
Updates user editing logic to handle admin roles and store access, with schema changes. Replit-Commit-Author: Agent Replit-Commit-Session-Id: 91318273-c764-4fd4-be04-bdc12c38af32 Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/0715008c-7244-40f4-befc-26c014852236/9d9e1107-c416-4124-a939-a91c612c56a1.jpg
This commit is contained in:
1 parent
bedb7bd4cc
commit
4dbdda2071
3 files changed
+39
-22
No files matched your search
Binary file not shown.
|
After Width: | Height: | Size: 61 KiB |
@@ -253,7 +253,15 @@ export default function Administration() {
|
||||
};
|
||||
|
||||
const onEditUser = async (data: EditUserData) => {
|
||||
await updateUserMutation.mutateAsync(data);
|
||||
const isEditingSelf = editingUser?.id === currentUser?.id;
|
||||
|
||||
// Si on modifie son propre profil, on ne doit pas envoyer le champ role
|
||||
if (isEditingSelf) {
|
||||
const { role, ...dataWithoutRole } = data;
|
||||
await updateUserMutation.mutateAsync(dataWithoutRole);
|
||||
} else {
|
||||
await updateUserMutation.mutateAsync(data);
|
||||
}
|
||||
};
|
||||
|
||||
const onCreateStore = async (data: z.infer<typeof insertStoreSchema>) => {
|
||||
@@ -862,26 +870,35 @@ export default function Administration() {
|
||||
<FormField
|
||||
control={editUserForm.control}
|
||||
name="storeId"
|
||||
render={({ field }) => (
|
||||
<FormItem>
|
||||
<FormLabel>Magasin</FormLabel>
|
||||
<Select value={field.value?.toString()} onValueChange={(value) => field.onChange(value ? parseInt(value) : undefined)}>
|
||||
<FormControl>
|
||||
<SelectTrigger>
|
||||
<SelectValue placeholder="Sélectionner un magasin" />
|
||||
</SelectTrigger>
|
||||
</FormControl>
|
||||
<SelectContent>
|
||||
{stores.map((store) => (
|
||||
<SelectItem key={store.id} value={store.id.toString()}>
|
||||
{store.name}
|
||||
</SelectItem>
|
||||
))}
|
||||
</SelectContent>
|
||||
</Select>
|
||||
<FormMessage />
|
||||
</FormItem>
|
||||
)}
|
||||
render={({ field }) => {
|
||||
const isEditingSelf = editingUser?.id === currentUser?.id;
|
||||
return (
|
||||
<FormItem>
|
||||
<FormLabel>Magasin</FormLabel>
|
||||
<Select value={field.value?.toString() || "none"} onValueChange={(value) => field.onChange(value === "none" ? undefined : parseInt(value))}>
|
||||
<FormControl>
|
||||
<SelectTrigger>
|
||||
<SelectValue placeholder="Sélectionner un magasin" />
|
||||
</SelectTrigger>
|
||||
</FormControl>
|
||||
<SelectContent>
|
||||
<SelectItem value="none">Aucun magasin (accès à tous)</SelectItem>
|
||||
{stores.map((store) => (
|
||||
<SelectItem key={store.id} value={store.id.toString()}>
|
||||
{store.name}
|
||||
</SelectItem>
|
||||
))}
|
||||
</SelectContent>
|
||||
</Select>
|
||||
{isEditingSelf && (
|
||||
<p className="text-sm text-muted-foreground">
|
||||
En tant qu'administrateur, vous pouvez accéder à tous les magasins
|
||||
</p>
|
||||
)}
|
||||
<FormMessage />
|
||||
</FormItem>
|
||||
);
|
||||
}}
|
||||
/>
|
||||
</div>
|
||||
<div className="flex justify-end space-x-2">
|
||||
|
||||
+1
-1
@@ -295,7 +295,7 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
const userData = insertUserSchema.partial().parse(req.body);
|
||||
|
||||
// Protection spécifique pour le rôle seulement
|
||||
if (userData.role) {
|
||||
if (userData.role !== undefined) {
|
||||
// Protection : empêcher un admin de changer son propre rôle par accident
|
||||
if (userId === currentUser?.id && userData.role !== 'administrator') {
|
||||
return res.status(400).json({
|
||||
|
||||
Reference in new issue
Block a user