Improve page access control for administrators and regular users

Update routes.ts to differentiate page access based on user role, allowing admins to view all pages and regular users to see only their accessible pages.

Replit-Commit-Author: Agent
Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda
Replit-Commit-Checkpoint-Type: intermediate_checkpoint
Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/u2SCNAb
This commit is contained in:
michaelschal committed 2025-10-08 14:34:58 +00:00
1 parent d711bdfc81
commit 88a0d066b5
1 file changed
+16 -2
+16 -2
View File
@@ -8,7 +8,7 @@ import passport from "./auth";
import { z } from "zod";
import { openRouterService } from "./services/openrouter";
import { cloudinaryService } from "./services/cloudinary";
import { insertPostSchema, insertScheduledPostSchema, insertSocialPageSchema, insertAiGenerationSchema, insertCloudinaryConfigSchema, updateCloudinaryConfigSchema, insertOpenrouterConfigSchema, updateOpenrouterConfigSchema, insertUserSchema, postMedia } from "@shared/schema";
import { insertPostSchema, insertScheduledPostSchema, insertSocialPageSchema, insertAiGenerationSchema, insertCloudinaryConfigSchema, updateCloudinaryConfigSchema, insertOpenrouterConfigSchema, updateOpenrouterConfigSchema, insertUserSchema, postMedia, type SocialPage } from "@shared/schema";
import type { User, InsertUser } from "@shared/schema";
const upload = multer({ storage: multer.memoryStorage() });
@@ -625,7 +625,21 @@ export async function registerRoutes(app: Express): Promise<Server> {
try {
const user = req.user as User;
const userId = user.id;
const pages = await storage.getSocialPages(userId);
let pages: SocialPage[];
if (user.role === 'admin') {
// Les admins voient toutes les pages de tous les utilisateurs
const allUsers = await storage.getAllUsers();
const allPages = await Promise.all(
allUsers.map(u => storage.getSocialPages(u.id))
);
pages = allPages.flat();
} else {
// Les utilisateurs normaux voient uniquement les pages auxquelles ils ont accès
pages = await storage.getUserAccessiblePages(userId);
}
res.json(pages);
} catch (error) {
console.error("Error fetching pages:", error);