This commit updates various route handlers in the management and inventory modules to include permission checks using the `checkPermissions` middleware. The changes ensure that access to properties, values, and search functionalities for different entities (e.g., users, products, tax rates) is properly restricted based on user permissions. This enhancement improves the security and integrity of the application by enforcing role-based access control across multiple routes.
This commit introduces a caching mechanism for user permissions using Redis, enhancing performance by reducing database queries. The `permissions.js` file has been updated to include functions for saving and retrieving user permissions from Redis, as well as middleware for checking permissions in various routes. Additionally, tests have been added to ensure the correctness of the permission logic and caching behavior, improving the overall security and efficiency of the application.
This update introduces a new utility function, `getSort`, to validate and apply sorting based on allowed sorters across multiple routes in the inventory and management modules. The function is integrated into route handlers for invoices, payments, tax records, filament stocks, order items, part stocks, product stocks, purchase orders, shipments, and various management entities. This enhancement improves the flexibility and consistency of sorting operations throughout the application.
This update introduces new functions such as `getRefModelEntryFromPrefix`, `stripPrefixFromOperand`, and `getRefModelEntryForToken` to streamline the processing of reference models and tokens. Additionally, the `resolveRefLeaf` and `resolveRefCondition` functions have been refactored to utilize these enhancements, improving the overall efficiency and clarity of the filtering and reference resolution processes. Minor formatting adjustments were also made in orderitems.js for consistency.
This update introduces several utility functions in `utils.js` to improve the handling of ObjectId paths, schema types, and filtering logic. Key additions include `isObjectIdPath`, `getBaseProperty`, and `getFilterFieldKind`, which enhance the flexibility of property handling. Additionally, all route handlers in the finance and inventory modules have been refactored to support asynchronous operations, ensuring better performance and responsiveness when processing requests.
- Introduced a new 'name' field as a required attribute in the order item schema.
- Added invoicing-related fields: 'invoicedAmountWithTax', 'invoicedAmount', 'invoicedQuantity', 'invoicedAmountRemaining', 'invoicedAmountWithTaxRemaining', and 'invoicedQuantityRemaining' to track invoicing status.
- Updated route handlers to accommodate the new 'name' field in order item creation and editing processes.
- Enhanced the recalculation logic to include remaining invoiced amounts and quantities.