mirror of
https://github.com/donpat1to/Schichtenplaner.git
synced 2025-12-01 06:55:45 +01:00
settings works for every user
This commit is contained in:
@@ -372,6 +372,15 @@ export const changePassword = async (req: AuthRequest, res: Response): Promise<v
|
||||
const { id } = req.params;
|
||||
const { currentPassword, newPassword } = req.body;
|
||||
|
||||
// Get the current user from the auth middleware
|
||||
const currentUser = (req as AuthRequest).user;
|
||||
|
||||
// Check if user is changing their own password or is an admin
|
||||
if (currentUser?.userId !== id && currentUser?.role !== 'admin') {
|
||||
res.status(403).json({ error: 'You can only change your own password' });
|
||||
return;
|
||||
}
|
||||
|
||||
// Check if employee exists and get password
|
||||
const employee = await db.get<{ password: string }>('SELECT password FROM employees WHERE id = ?', [id]);
|
||||
if (!employee) {
|
||||
@@ -379,10 +388,18 @@ export const changePassword = async (req: AuthRequest, res: Response): Promise<v
|
||||
return;
|
||||
}
|
||||
|
||||
// Verify current password
|
||||
const isValidPassword = await bcrypt.compare(currentPassword, employee.password);
|
||||
if (!isValidPassword) {
|
||||
res.status(400).json({ error: 'Current password is incorrect' });
|
||||
// For non-admin users, verify current password
|
||||
if (currentUser?.role !== 'admin') {
|
||||
const isValidPassword = await bcrypt.compare(currentPassword, employee.password);
|
||||
if (!isValidPassword) {
|
||||
res.status(400).json({ error: 'Current password is incorrect' });
|
||||
return;
|
||||
}
|
||||
}
|
||||
|
||||
// Validate new password
|
||||
if (!newPassword || newPassword.length < 6) {
|
||||
res.status(400).json({ error: 'New password must be at least 6 characters long' });
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -681,7 +681,7 @@ async function generateScheduledShifts(planId: string, startDate: string, endDat
|
||||
}
|
||||
}
|
||||
|
||||
export const getTemplates = async (req: Request, res: Response): Promise<void> => {
|
||||
/*export const getTemplates = async (req: Request, res: Response): Promise<void> => {
|
||||
try {
|
||||
console.log('🔍 Lade Vorlagen...');
|
||||
|
||||
@@ -707,7 +707,7 @@ export const getTemplates = async (req: Request, res: Response): Promise<void> =
|
||||
console.error('Error fetching templates:', error);
|
||||
res.status(500).json({ error: 'Internal server error' });
|
||||
}
|
||||
};
|
||||
};*/
|
||||
|
||||
// Neue Funktion: Create from Template
|
||||
/*export const createFromTemplate = async (req: Request, res: Response): Promise<void> => {
|
||||
|
||||
Reference in New Issue
Block a user