From 88a0d066b5710e17d6aa3d93bc9590fa21c5e800 Mon Sep 17 00:00:00 2001 From: michaelschal <35957947-michaelschal@users.noreply.replit.com> Date: Wed, 8 Oct 2025 14:34:58 +0000 Subject: [PATCH] Improve page access control for administrators and regular users Update routes.ts to differentiate page access based on user role, allowing admins to view all pages and regular users to see only their accessible pages. Replit-Commit-Author: Agent Replit-Commit-Session-Id: ae4037a0-2a6f-4530-9bac-79b543286bda Replit-Commit-Checkpoint-Type: intermediate_checkpoint Replit-Commit-Screenshot-Url: https://storage.googleapis.com/screenshot-production-us-central1/397bca8c-984f-43ff-841a-10897aeb8140/ae4037a0-2a6f-4530-9bac-79b543286bda/u2SCNAb --- server/routes.ts | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/server/routes.ts b/server/routes.ts index 18edc6b..69c74bd 100644 --- a/server/routes.ts +++ b/server/routes.ts @@ -8,7 +8,7 @@ import passport from "./auth"; import { z } from "zod"; import { openRouterService } from "./services/openrouter"; import { cloudinaryService } from "./services/cloudinary"; -import { insertPostSchema, insertScheduledPostSchema, insertSocialPageSchema, insertAiGenerationSchema, insertCloudinaryConfigSchema, updateCloudinaryConfigSchema, insertOpenrouterConfigSchema, updateOpenrouterConfigSchema, insertUserSchema, postMedia } from "@shared/schema"; +import { insertPostSchema, insertScheduledPostSchema, insertSocialPageSchema, insertAiGenerationSchema, insertCloudinaryConfigSchema, updateCloudinaryConfigSchema, insertOpenrouterConfigSchema, updateOpenrouterConfigSchema, insertUserSchema, postMedia, type SocialPage } from "@shared/schema"; import type { User, InsertUser } from "@shared/schema"; const upload = multer({ storage: multer.memoryStorage() }); @@ -625,7 +625,21 @@ export async function registerRoutes(app: Express): Promise { try { const user = req.user as User; const userId = user.id; - const pages = await storage.getSocialPages(userId); + + let pages: SocialPage[]; + + if (user.role === 'admin') { + // Les admins voient toutes les pages de tous les utilisateurs + const allUsers = await storage.getAllUsers(); + const allPages = await Promise.all( + allUsers.map(u => storage.getSocialPages(u.id)) + ); + pages = allPages.flat(); + } else { + // Les utilisateurs normaux voient uniquement les pages auxquelles ils ont accès + pages = await storage.getUserAccessiblePages(userId); + } + res.json(pages); } catch (error) { console.error("Error fetching pages:", error);