Files
sap-erp/dist-1/public/company-list.js
T
John 69b4e68baf
SAP-ERP Portal CI/CD / build (push) Failing after 5m20s
first commit
2026-09-23 17:31:02 +05:30

50 lines
2.6 KiB
JavaScript

// company-list.js — shared helper: fetch the LIVE SAP company list once,
// cached for the page's lifetime. Backed by GET /api/companies (server
// scans SQL Server for company databases, no hardcoded list — public/no-auth
// since register.html/vendor-register.html use it before login too).
//
// Admin → user → "Displayed SAP Company" can restrict which of those
// companies a given user sees: filtered HERE, client-side, against the
// logged-in user's allowedCompanies (baked into portal_user at login/refresh
// — see server.js buildAuthPayload). Empty/absent = no restriction (sees
// everything the server found), same as unauthenticated pages. This is a
// display-level filter only, matching how Issue Items/Man Power/OEE tab
// restrictions work elsewhere in this app — it doesn't block API calls made
// with an explicit company param.
(function(){
let _p = null;
window.fetchCompanyList = function(){
if(_p) return _p;
_p = fetch('/api/companies').then(r=>r.json()).then(d=>{
const all=d.success?(d.data||[]):[];
let allowed=null;
try{
const u=JSON.parse(sessionStorage.getItem('portal_user')||'null');
if(u&&Array.isArray(u.allowedCompanies)&&u.allowedCompanies.length) allowed=new Set(u.allowedCompanies.map(String));
}catch(_e){}
return allowed?all.filter(c=>allowed.has(String(c.value))):all;
}).catch(()=>[]);
return _p;
};
// Every page initializes its working company as `let _co=window.__DEFAULT_
// COMPANY__` (the .env SAP_B1_COMPANY, injected server-side into EVERY
// page for EVERY user — see server.js's static-file middleware). That's
// fine for an unrestricted user, but a user restricted to specific
// companies (Admin → user → "Displayed SAP Company") would still silently
// default to and fetch data from the .env company, even when it's NOT in
// their allowed list — the restriction only ever filtered the DROPDOWN,
// never the actual starting selection. Fixed here, synchronously, before
// any page's own inline script runs (this file is always loaded in <head>,
// ahead of the page body): if the user has a non-empty allowedCompanies
// list that does NOT include the .env default, swap window.__DEFAULT_
// COMPANY__ to their first allowed company so every page's `_co` picks up
// the corrected value with no per-page changes needed.
try{
const u=JSON.parse(sessionStorage.getItem('portal_user')||'null');
if(u&&Array.isArray(u.allowedCompanies)&&u.allowedCompanies.length&&!u.allowedCompanies.includes(window.__DEFAULT_COMPANY__)){
window.__DEFAULT_COMPANY__=u.allowedCompanies[0];
}
}catch(_e){}
})();