mirror of
https://github.com/R0m1k3/Socialflow.git
synced 2026-10-11 17:26:45 +02:00
Improve post preview visibility for different user roles
Update the post preview logic in `server/routes.ts` to allow admins and post owners to see previews, while also enabling standard users to see posts from pages assigned to them. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: full_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/1VOBLTw
This commit is contained in:
1 parent
f21e7e5f18
commit
4127f9fc55
2 files changed
+22
-3
No files matched your search
Binary file not shown.
|
After Width: | Height: | Size: 263 KiB |
+22
-3
@@ -685,11 +685,30 @@ export async function registerRoutes(app: Express): Promise<Server> {
|
||||
return res.status(404).json({ error: "Post not found" });
|
||||
}
|
||||
|
||||
if (postWithMedia.post.userId !== userId) {
|
||||
return res.status(403).json({ error: "Unauthorized" });
|
||||
// Admin peut voir tous les posts
|
||||
if (user.role === 'admin') {
|
||||
return res.json(postWithMedia);
|
||||
}
|
||||
|
||||
res.json(postWithMedia);
|
||||
// Propriétaire peut voir son propre post
|
||||
if (postWithMedia.post.userId === userId) {
|
||||
return res.json(postWithMedia);
|
||||
}
|
||||
|
||||
// Utilisateur standard peut voir les posts des pages qui lui sont assignées
|
||||
const scheduledPostsForPost = await storage.getScheduledPostsByPost(id);
|
||||
if (scheduledPostsForPost.length > 0) {
|
||||
const accessiblePages = await storage.getUserAccessiblePages(userId);
|
||||
const accessiblePageIds = accessiblePages.map(p => p.id);
|
||||
|
||||
// Vérifier si au moins une page du post est accessible
|
||||
const hasAccess = scheduledPostsForPost.some(sp => accessiblePageIds.includes(sp.pageId));
|
||||
if (hasAccess) {
|
||||
return res.json(postWithMedia);
|
||||
}
|
||||
}
|
||||
|
||||
return res.status(403).json({ error: "Unauthorized" });
|
||||
} catch (error) {
|
||||
console.error("Error fetching post:", error);
|
||||
res.status(500).json({ error: "Failed to fetch post" });
|
||||
|
||||
Reference in new issue
Block a user