Benutzer, Ticketzuweißungen
This commit is contained in:
@@ -20,3 +20,12 @@ export function requireAdmin(req, res, next) {
|
||||
}
|
||||
next();
|
||||
}
|
||||
|
||||
/** Maschinen, Tickets, Events, Anhänge bearbeiten (nicht: nur Viewer). */
|
||||
export function requireCrmEdit(req, res, next) {
|
||||
const r = req.session?.role;
|
||||
if (r === 'admin' || r === 'after_sales') {
|
||||
return next();
|
||||
}
|
||||
return res.status(403).json({ message: 'Keine Bearbeitungsrechte.' });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user