fix(workshop): restrict workshop/mechanic views to only 'autorizada' status
Some checks failed
CI / lint-and-test (3.11) (push) Has been cancelled
CI / lint-and-test (3.13) (push) Has been cancelled

This commit is contained in:
2026-07-02 14:38:29 +00:00
parent f42910f4f6
commit c226b1cf77
3 changed files with 39 additions and 7 deletions

View File

@@ -48,6 +48,9 @@ _MECHANIC_HIDDEN_STATUSES = {
'por_facturar', 'facturada'
}
# Statuses visible to workshop/mechanic accounts (taller only works on authorized orders).
_TALLER_ALLOWED_STATUSES = {'autorizada'}
def _can_view_workshop():
return g.employee_role in _WORKSHOP_VIEW_ROLES or 'workshop.view' in g.permissions
@@ -143,11 +146,10 @@ def list_orders():
)
if _is_restricted_workshop_viewer():
result['data'] = [_redact_order_for_mechanic(o) for o in result.get('data', [])]
# Shared mechanic account can see all orders except commercial/closed statuses.
if g.employee_role == 'mechanic':
# Workshop/mechanic accounts only see orders ready to be worked on.
result['data'] = [
o for o in result.get('data', [])
if o.get('status') not in _MECHANIC_HIDDEN_STATUSES
if o.get('status') in _TALLER_ALLOWED_STATUSES
]
return jsonify(result)
finally:
@@ -237,8 +239,8 @@ def get_order(so_id):
order = get_service_order(conn, so_id)
if not order:
return jsonify({'error': 'Service order not found'}), 404
# Shared mechanic account cannot view commercial/closed statuses.
if g.employee_role == 'mechanic' and order.get('status') in _MECHANIC_HIDDEN_STATUSES:
# Workshop/mechanic accounts can only view orders that are ready to be worked on.
if _is_restricted_workshop_viewer() and order.get('status') not in _TALLER_ALLOWED_STATUSES:
return jsonify({'error': 'No tienes acceso a esta orden'}), 403
return jsonify(_redact_order_for_mechanic(order))
finally:

View File

@@ -196,6 +196,14 @@ var Workshop = (function() {
document.querySelectorAll('.restricted-hide').forEach(function(el) { el.style.display = 'none'; });
var searchInput = document.getElementById('filterSearch');
if (searchInput) searchInput.placeholder = 'Buscar orden';
// Limit status filter to the only status taller accounts can see.
var statusSel = document.getElementById('filterStatus');
if (statusSel) {
Array.from(statusSel.options).forEach(function(opt) {
if (opt.value && opt.value !== 'autorizada') opt.remove();
});
statusSel.value = 'autorizada';
}
}
if (hidePrices) {
var btnCatalog = document.getElementById('btnCatalog');
@@ -251,6 +259,22 @@ var Workshop = (function() {
fetch(API + '/kanban/summary', {headers: headers()})
.then(function(r) { return r.json(); })
.then(function(d) {
var cards = document.querySelectorAll('#statsRow .summary-card');
if (isRestricted) {
// Taller accounts only see authorized orders.
cards.forEach(function(card, idx) {
if (idx === 0) {
card.style.display = '';
var label = card.querySelector('.summary-card__label');
if (label) label.textContent = 'Autorizadas';
} else {
card.style.display = 'none';
}
});
document.getElementById('statReceived').textContent = fmt(d.autorizada || 0);
return;
}
cards.forEach(function(card) { card.style.display = ''; });
document.getElementById('statReceived').textContent = fmt(d.por_revisar || 0);
document.getElementById('statRepair').textContent = fmt((d.en_reparacion || 0) + (d.en_revision || 0) + (d.revisada || 0) + (d.cotizada || 0) + (d.por_autorizar || 0));
document.getElementById('statReady').textContent = fmt(d.por_entregar || 0);
@@ -379,7 +403,13 @@ var Workshop = (function() {
function renderKanban() {
var board = document.getElementById('kanbanBoard');
board.innerHTML = '';
var hiddenCols = isMechanic ? ['cotizada','por_autorizar','autorizada','autorizacion_parcial','por_facturar','facturada'] : [];
var hiddenCols = [];
if (isRestricted) {
// Taller accounts only see the "autorizada" column.
hiddenCols = COLUMNS.filter(function(c) { return c.key !== 'autorizada'; }).map(function(c) { return c.key; });
} else if (isMechanic) {
hiddenCols = ['cotizada','por_autorizar','autorizada','autorizacion_parcial','por_facturar','facturada'];
}
COLUMNS.filter(function(col) { return hiddenCols.indexOf(col.key) === -1; }).forEach(function(col) {
var colOrders = orders.filter(function(o) { return o.status === col.key; });
var colEl = document.createElement('div');

View File

@@ -499,7 +499,7 @@
<script src="/pos/static/js/pos-utils.js?v=33" defer></script>
<script src="/pos/static/js/sidebar.js?v=44" defer></script>
<script src="/pos/static/js/offline-banner.js" defer></script>
<script src="/pos/static/js/workshop.js?v=55" defer></script>
<script src="/pos/static/js/workshop.js?v=56" defer></script>
<script>if('serviceWorker' in navigator){navigator.serviceWorker.register('/pos/sw.js',{scope:'/pos/'});}</script>
<script src="/pos/static/js/pwa-install.js" defer></script>
<script src="/pos/static/js/chat.js" defer></script>