+16
-5
@@ -15,6 +15,14 @@ function getSap() {
|
||||
if (!_sapSvc) _sapSvc = require('../services/sapServiceLayer');
|
||||
return _sapSvc;
|
||||
}
|
||||
const appSettings = () => require('../services/appSettingsStore');
|
||||
|
||||
// admin/sap_adder/system_admin may push directly and approve/reject others'
|
||||
// submissions. Kept as one helper so the client (public/approvals.html's
|
||||
// canManageItems()) and server always agree on who this is.
|
||||
function isItemApprover(user) {
|
||||
return user?.role === 'admin' || user?.role === 'sap_adder' || user?.role === 'system_admin';
|
||||
}
|
||||
|
||||
const cq = (req) => req.query?.company || req.body?.company || null;
|
||||
|
||||
@@ -110,8 +118,11 @@ function buildSapPayload(data) {
|
||||
}
|
||||
|
||||
// ── POST /api/item-approvals/submit ─────────────────────────────────────────
|
||||
// admin/sap_adder → push directly to SAP (no approval queue)
|
||||
// all other roles → save as PENDING for admin review
|
||||
// admin/sap_adder/system_admin → push directly to SAP (no approval queue)
|
||||
// all other roles → save as PENDING for admin review
|
||||
// Admin → System Settings → "Item Approval Workflow": when OFF, the whole
|
||||
// queue is bypassed and EVERYONE pushes directly (there's no one left who'd
|
||||
// review a pending item) — same as an approver submitting, regardless of role.
|
||||
router.post('/submit', verifyToken, async (req, res) => {
|
||||
try {
|
||||
const store = getStore();
|
||||
@@ -130,7 +141,7 @@ router.post('/submit', verifyToken, async (req, res) => {
|
||||
company: company || '',
|
||||
};
|
||||
|
||||
if (req.user.role === 'admin' || req.user.role === 'sap_adder') {
|
||||
if (isItemApprover(req.user) || !appSettings().itemApprovalEnabled()) {
|
||||
const payload = await pushItemToSap(itemData, co);
|
||||
const logEntry = {
|
||||
username: req.user.username, name: req.user.name || req.user.username,
|
||||
@@ -187,8 +198,8 @@ router.get('/:id', verifyToken, async (req, res) => {
|
||||
// action: 'approve' | 'reject'
|
||||
// Admin can also pass editedData to override item fields before pushing
|
||||
router.patch('/:id/action', verifyToken, async (req, res) => {
|
||||
if (req.user.role !== 'admin' && req.user.role !== 'sap_adder') {
|
||||
return res.status(403).json({ success: false, message: 'Only admin can approve items' });
|
||||
if (!isItemApprover(req.user)) {
|
||||
return res.status(403).json({ success: false, message: 'Only admin/SAP Adder/system admin can approve items' });
|
||||
}
|
||||
try {
|
||||
const store = getStore();
|
||||
|
||||
Reference in New Issue
Block a user