diff --git a/attached_assets/image_1752103355483.png b/attached_assets/image_1752103355483.png new file mode 100644 index 0000000..c98b375 Binary files /dev/null and b/attached_assets/image_1752103355483.png differ diff --git a/client/src/components/Administration.tsx b/client/src/components/Administration.tsx index 8a95a7b..92a5bfc 100644 --- a/client/src/components/Administration.tsx +++ b/client/src/components/Administration.tsx @@ -253,7 +253,15 @@ export default function Administration() { }; const onEditUser = async (data: EditUserData) => { - await updateUserMutation.mutateAsync(data); + const isEditingSelf = editingUser?.id === currentUser?.id; + + // Si on modifie son propre profil, on ne doit pas envoyer le champ role + if (isEditingSelf) { + const { role, ...dataWithoutRole } = data; + await updateUserMutation.mutateAsync(dataWithoutRole); + } else { + await updateUserMutation.mutateAsync(data); + } }; const onCreateStore = async (data: z.infer) => { @@ -862,26 +870,35 @@ export default function Administration() { ( - - Magasin - - - - )} + render={({ field }) => { + const isEditingSelf = editingUser?.id === currentUser?.id; + return ( + + Magasin + + {isEditingSelf && ( +

+ En tant qu'administrateur, vous pouvez accéder à tous les magasins +

+ )} + +
+ ); + }} />
diff --git a/server/routes.ts b/server/routes.ts index 7c4d3eb..d83d456 100644 --- a/server/routes.ts +++ b/server/routes.ts @@ -295,7 +295,7 @@ export async function registerRoutes(app: Express): Promise { const userData = insertUserSchema.partial().parse(req.body); // Protection spécifique pour le rôle seulement - if (userData.role) { + if (userData.role !== undefined) { // Protection : empêcher un admin de changer son propre rôle par accident if (userId === currentUser?.id && userData.role !== 'administrator') { return res.status(400).json({